The EU AI Act's First Rules Are Now in Force: 5 Steps Every UK Business Should Take

Fresh Mango AI
The EU AI Act's First Rules Are Now in Force: 5 Steps Every UK Business Should Take

The EU AI Act has moved from a future compliance concern to an operational issue.

From 2 August 2026, the Act's Article 50 transparency obligations apply to certain AI systems. The European Commission, national market surveillance authorities and other supervisory bodies can now enforce these rules. For companies, penalties may reach €15 million or 3% of global annual turnover, with proportionality taken into account for small and medium-sized organisations.

The UK is not part of the EU. That does not mean UK businesses can ignore the Act.

If your organisation offers AI systems to people in the EU, deploys AI there, serves EU customers or publishes AI-generated content for EU audiences, you may have responsibilities under the regulation. The exact position depends on your role, system, users and territorial activity, so this article is practical guidance rather than legal advice.

The wider lesson is more immediate: AI governance is a today-problem, not a project to start after adoption has scaled.

What changed on 2 August 2026?

The new rules focus on transparency. In practical terms, people should be able to recognise when:

  • They are interacting with an AI system, such as a chatbot, AI agent or avatar.
  • Images, audio or video have been artificially generated or manipulated.
  • AI-generated text is being published to inform the public about matters of public interest without human editorial review.
  • They are exposed to emotion recognition or biometric categorisation systems.

The Commission has published guidelines on Article 50 transparency obligations, alongside information about the wider AI Act regulatory framework.

The rules are not limited to large technology companies. A UK business using an AI chatbot for EU customers, publishing AI-generated marketing material to EU audiences or deploying biometric categorisation in an EU location may need to assess its position.

For some existing generative AI systems, the machine-readable marking requirement has a later transition point, currently understood to run to 2 December 2026. That should not be treated as a general grace period. Other transparency duties may apply from 2 August, and new systems placed on the EU market after that date may need to comply from launch.

The sensible response is not to panic or stop using AI. It is to establish what applies, assign responsibility and create evidence that your controls operate in practice.

Business professionals reviewing an AI readiness assessment and business data in a modern workplace

1. Establish whether your organisation is in scope

Purpose: determine where the AI Act creates a direct obligation for your organisation.

Start with a simple scope review. Document:

  • Which AI systems your organisation provides or sells.
  • Which systems your staff deploy in EU locations.
  • Which services interact with EU customers, employees or visitors.
  • Which content is generated, manipulated or published for EU audiences.
  • Which suppliers provide the models, applications or infrastructure involved.

Do not assume that using a familiar platform removes your responsibility. A supplier may provide certain technical controls, but your organisation still needs to understand how the system is configured and used.

For example, a general-purpose chatbot may have its own disclosure features. Your business must still check whether the disclosure appears at the right point, is clear to the user and remains present in the relevant customer journey.

The same principle applies to generated content. If your marketing team creates an AI-generated image or video and publishes it to an EU-facing campaign, you need a process for determining whether disclosure or machine-readable marking applies.

A useful first output is an AI register containing:

  • System or tool name.
  • Business owner.
  • Supplier and model information.
  • Users and locations.
  • Data accessed.
  • Content produced.
  • EU exposure.
  • Applicable controls.
  • Review date.

This register is the foundation of an AI governance framework for business. Without it, obligations remain scattered across procurement records, IT systems and individual teams.

2. Map the AI interactions and content that need transparency

Purpose: identify exactly where a person could be misled about the role of AI.

Review each customer, employee and public-facing workflow. Pay particular attention to:

Chatbots and AI agents

Users should be clearly informed when they are interacting with an AI system rather than a person. The notice should appear no later than the first interaction unless the nature of the system is already obvious in context.

Check the complete experience, not only the chatbot window. A disclosure can be missed if it is hidden in a privacy policy or displayed only after a user has started asking questions.

Generated images, audio and video

Identify whether your organisation creates or publishes content that resembles real people, objects, places or events. Deepfake-related content requires particularly careful review because it can create risks of impersonation, fraud and consumer deception.

AI-generated public-interest text

If AI generates text intended to inform the public about matters of public interest, assess whether the content requires disclosure. Human editorial review may affect the analysis, but it should be documented rather than assumed.

Emotion recognition and biometric categorisation

These systems require specific attention because they affect people directly. Document the purpose, legal basis, location, affected individuals, notice mechanism and human oversight.

This review should involve marketing, customer service, HR, operations, IT, security and legal or compliance stakeholders where relevant. AI governance fails when it is treated as an IT-only issue.

3. Put notices, labels and controls into the workflow

Purpose: make compliance part of how work is performed rather than a policy document that staff must remember.

For each in-scope workflow, define:

  • What disclosure is required.
  • Who owns the wording.
  • Where the notice appears.
  • Which technical control creates the machine-readable mark.
  • How staff identify and escalate exceptions.
  • What evidence is retained.
  • How often the control is tested.

A chatbot notice may be a product configuration. A public-interest article may require an editorial checklist. A synthetic video may need a visible label and machine-readable metadata. These are different controls and should not be treated as one generic "AI policy".

The technical implementation should be tested with real user journeys. Check whether:

  • The notice appears at first interaction or exposure.
  • The language is clear and distinguishable.
  • Labels remain attached when content is downloaded, edited or republished.
  • Accessibility requirements are met.
  • Content created before 2 August but published afterwards is handled correctly.
  • Suppliers can provide evidence of their marking and detection methods.

The European Commission's 2 August 2026 announcement provides a useful summary of the transparency duties and enforcement position.

Leadership team collaborating on data, risk and performance decisions in a corporate office

4. Create ownership, evidence and an escalation route

Purpose: ensure your organisation can demonstrate control when something goes wrong or a regulator asks questions.

A policy alone is not a governance framework. You need named owners and a repeatable review process.

At a minimum, assign responsibility for:

  • Maintaining the AI register.
  • Approving new AI use cases.
  • Reviewing supplier terms and technical assurances.
  • Managing data access and permissions.
  • Confirming transparency notices and labels.
  • Investigating incidents or complaints.
  • Reporting status to leadership.
  • Reviewing controls after significant system changes.

Keep proportionate evidence. This may include:

  • Approved use-case records.
  • Risk assessments.
  • Supplier documentation.
  • Screenshots of notices and labels.
  • Test results.
  • Training records.
  • Audit and access logs.
  • Incident and escalation records.
  • Review dates and named approvers.

For UK businesses, this is also good operational practice even where the AI Act does not directly apply. Clear ownership reduces uncontrolled experimentation, improves client due diligence responses and supports wider UK data protection and security obligations.

Fix permissions first where AI can search organisational content. AI assistants can expose information that was already overshared. Broad links, stale guest accounts, inherited permissions and unclassified sensitive files become more visible when an assistant can retrieve them in seconds.

Our AI Governance & Security Project reviews these areas and produces a governance action plan, AI usage policy, access review summary and prioritised security recommendations.

5. Treat compliance as part of a measured AI adoption programme

Purpose: avoid building controls that sit separately from the business results AI is meant to deliver.

Compliance is necessary, but it is not the only reason to improve governance. A controlled environment makes it easier to adopt useful AI without creating unacceptable exposure.

Fresh Mango AI uses a six-stage methodology:

  1. Assess: map processes, data, risks and realistic opportunities.
  2. Govern: establish policies, ownership, access controls and risk management.
  3. Enable: train teams with role-based guidance and approved prompt libraries.
  4. Build: develop purpose-specific agents and assistants where the use case is defined.
  5. Sustain: review adoption, value and governance regularly.
  6. Transform: assess wider automation, AI and robotics opportunities when the foundations are sound.

This sequence matters. Building an agent before confirming its knowledge sources and permissions creates avoidable risk. Buying licences before identifying the right workflows creates disappointing adoption. Training staff without defining approved data handling leaves the organisation exposed.

The outcome should be measured in operational terms:

  • Hours released from repetitive work.
  • Faster document or approval cycles.
  • Fewer manual hand-offs.
  • Reduced response times.
  • Improved consistency.
  • Lower exception volumes.
  • Evidence of controlled and appropriate use.

Our AI Productivity & Readiness Assessment helps establish the baseline and prioritised roadmap. Once adoption begins, the Quarterly AI Success Review keeps usage, value and governance under review.

What UK businesses should do next

In the next 30 days, leadership teams should aim to:

  • Confirm whether the organisation has EU-facing AI activity.
  • Create or update an AI register.
  • Identify chatbots, AI agents and generated content workflows.
  • Review current supplier controls and documentation.
  • Check permissions before enabling AI search across business data.
  • Assign an executive owner and operational owners.
  • Record the actions required before the 2 December 2026 marking milestone where relevant.
  • Set a review date and report progress to management.

Doing nothing is not a neutral position. Staff may already be using unapproved tools, suppliers may change AI features without your internal policy keeping pace, and data-access weaknesses remain unresolved whether or not you formally adopt AI.

The right approach is proportionate. Not every organisation needs a large compliance programme. Every organisation does need to understand what AI is doing, who is accountable, what data it can access and how benefits will be measured.

A practical next step

If you are unsure whether your organisation is ready, a focused review can reduce uncertainty without committing you to a wider implementation programme.

You can book a free 30-minute discovery session with a Fresh Mango AI consultant to discuss your objectives, EU exposure, current controls and the most suitable next step.

There is no obligation. If a different route is more appropriate, we will say so.

Book a free 30-minute discovery session

Discuss your EU AI Act exposure, current AI governance and the most practical next steps for your organisation. No obligation.

Your next step

Not Sure Where to Start?

Whether you're exploring AI for the first time or looking to scale existing AI initiatives, our specialists can help you identify practical opportunities and avoid common pitfalls.

Fresh Mango AI specialists reviewing an AI adoption plan with a business client
Book Free Discovery Session