AI regulation for businesses: what applies now, what is coming, and what to do about it
A plain-English guide to the UK, EU and US rules for companies that use AI in everyday work rather than build it.
Most businesses using AI today are not building it. They are using a chatbot to draft documents, generating images for a brochure, running software that scores job applicants, or installing cameras that flag safety incidents.
Regulation applies to that ordinary use, and the rules depend on where your customers and staff are, and, above all, on what the AI is actually doing. This guide sets out where things stand in September 2026. Several dates moved this year, so earlier reading may be out of date.
Start with what the AI does, not where you are
The UK, the EU and the US have taken different routes, but they worry about the same things: decisions about people (hiring, pay, credit, monitoring), personal data, being honest with the public about what is real and what is AI, keeping a human in charge, and a short list of uses that are simply banned. A useful rule of thumb: the closer AI gets to a decision about an individual, or to persuading a customer, the more the law cares.
Figure 1. The same tool can sit at different points on this scale depending on how it is used.
An engineering firm that uses AI to search its own manuals is at the low end. The same firm publishing AI-generated photos of "completed projects" has moved into advertising law; using AI to shortlist CVs puts it at the high end, where the laws that barely touched the first use apply in full.
United Kingdom: no AI Act, but plenty of law
The UK has not passed a single AI statute. It relies on existing law and regulators, with the Information Commissioner's Office (ICO) doing most of the work. That feels lighter than the EU, but the obligations are real.
The foundation is data protection. Any personal data that goes into an AI tool, whether customer details, staff records or CVs, needs a lawful basis, and higher-risk uses need a written data protection impact assessment (DPIA). The Data (Use and Access) Act 2025 changed the rules on automated decisions from 5 February 2026: decisions made solely by a machine with significant effects are now permitted more widely, but only with safeguards. You must tell the person, let them ask for a human to reconsider, and make that review meaningful rather than a rubber stamp.
Recruitment is the ICO's declared priority. In March 2026 it reported that many employers who described their AI tools as "decision support" were in practice letting the tool decide, and it wrote to named organisations asking them to change. A statutory code of practice on AI and automated decision-making is being drafted for 2027. The Equality Act still applies: a biased algorithm is discrimination, and the employer is liable, not the vendor.
Marketing is governed by rules that predate AI but bite hard on it. The Advertising Standards Authority's codes require that adverts do not mislead, whatever made them. The Digital Markets, Competition and Consumers Act 2024 made fake reviews a consumer-law offence from April 2025, and an AI-written review is a fake review.
Typical UK examples
European Union: the AI Act, and why it reaches UK companies
The EU AI Act applies to any company that puts an AI system on the EU market or whose AI produces outputs used there. So it catches UK exporters, firms with EU staff, and anyone whose EU customers meet an AI-driven service.
The Act sorts uses into tiers. A short list is banned outright, including emotion recognition in the workplace; those bans have applied since February 2025. A longer list is "high-risk": recruitment and worker management, credit scoring, and AI acting as a safety component in regulated products such as machinery. High-risk systems need risk management, documentation, logging, human oversight and, for products, conformity assessment. Below that, transparency duties apply: people must be told when they are dealing with AI, and AI-generated or manipulated images, audio and video that look real must be labelled as such, including in marketing. Everything else is largely untouched.
Separately, since February 2025 every business using AI in the EU has had a duty to make sure the staff using it are adequately trained.
The timetable changed this summer. The "Digital Omnibus" (Regulation 2026/1744), in force from 27 July 2026, deferred the high-risk obligations: stand-alone uses such as hiring now apply from 2 December 2027, AI embedded in regulated products from 2 August 2028. The transparency duties were not deferred and have applied since 2 August 2026.
Figure 2. EU AI Act dates as amended by the Digital Omnibus, July 2026. Solid markers have already passed.
Typical EU examples
United States: no federal law, a patchwork of states
There is still no comprehensive US federal AI statute. The White House issued an executive order in December 2025 directing agencies to challenge state AI laws it considers burdensome and to push Congress for a national framework that would override them, but no such law has passed. Until it does, state laws stand, and existing federal rules apply to AI as to anything else. The Federal Trade Commission's 2024 rule banning fake reviews covers AI-generated ones explicitly, and the FTC has pursued companies for overstating what their "AI-powered" products do.
The states are where the detail lives, and it keeps changing. Colorado passed the first broad AI law in 2024, then repealed and replaced it in May 2026 with a narrower statute (SB 26-189) on automated decisions, effective 1 January 2027: pre-use notices, explanations of adverse outcomes, a route to human review. Illinois requires employers to notify applicants when AI is used in hiring. Texas has banned specific harmful uses since January 2026. California has automated decision-making rules phasing in from 2027 and its own transparency requirements for AI-generated content.
Typical US examples
The three regimes side by side
| United Kingdom | European Union | United States | |
|---|---|---|---|
| Single AI law? | No. Existing law plus regulators, led by the ICO. | Yes. The AI Act, phased in 2025–2028. | No federal law. State laws vary. |
| AI in hiring | Permitted with safeguards since Feb 2026. ICO priority. | High-risk. Full duties from 2 Dec 2027. | Notice required in several states; Colorado adds explanations from Jan 2027. |
| Must you say it is AI? | Yes where personal data or decisions are involved. | Yes, since Aug 2026, plus labelling of realistic AI content. | Depends on state and use. |
| AI in marketing | Must not mislead (ASA); fake reviews banned since Apr 2025. | Realistic AI imagery labelled; chatbots disclosed. | FTC: no fake reviews, no false AI claims. |
| Staff monitoring | Proportionality, DPIA, consultation. | High-risk; emotion recognition banned. | State by state. |
| Next date to watch | ICO code of practice, 2027. | 2 Dec 2027. | 1 Jan 2027 (Colorado, California). |
What this means in practice
The dates move, but the direction has been consistent: be honest about what is AI, keep a human genuinely in charge of decisions about people, and be able to show your workings. Five things put a business in reasonable shape in all three jurisdictions.
Keep a list of every AI tool in the business, including the ones staff adopted on their own.
Most uses will be low-risk. The few that decide about people or monitor them need a written impact assessment before use, not after.
Configure tools so your data is not used for training, and give staff a short, plain-English policy on what may and may not go in.
Where AI influences a decision about a person, a named individual must be able to overrule it, and must actually do so sometimes. Regulators on both sides of the Channel have said a rubber stamp does not count.
Disclose AI use, label realistic AI-generated imagery, never publish an AI-written review, and keep a log of which tool was used, on what data, with what controls. That record turns a regulator's question into a short conversation.
None of this needs an AI department. It is the discipline a business already applies to health and safety: know what you have, assess the risky parts, control them, keep evidence.
Do that now and the 2027 and 2028 deadlines become checkpoints rather than emergencies.
This article is general information based on the position in September 2026 and is not legal advice. Key sources: UK Data (Use and Access) Act 2025, Digital Markets, Competition and Consumers Act 2024 and ICO guidance on automated decision-making (2026); Regulation (EU) 2024/1689 (AI Act) as amended by Regulation (EU) 2026/1744; Colorado SB 26-189 (2026); US FTC Rule on Consumer Reviews and Testimonials (2024). Have a qualified lawyer review anything you rely on.
More insights
Not sure where your AI use sits?
Book a free opportunity review — we will map what you are using, sort it by risk, and tell you what needs doing before the next deadline.
