The EU AI Act & UK AI Policy: A Full Briefing for Marketing Teams
Prepared by: David Chadderton, The STAR Framework Date: June 2026 Version: 1.0
Prepared by: David Chadderton, The STAR Framework Date: June 2026 Version: 1.0
Executive Summary
The regulatory landscape for artificial intelligence is shifting beneath the feet of every marketing team in Europe. The EU AI Act, the world’s first comprehensive legal framework for AI, entered into force on 1 August 2024 and is now rolling out in phases, with the most significant enforcement deadline arriving on 2 August 2026. On that date, transparency obligations under Article 50 take effect, and the rules governing high-risk AI systems come into force.
The UK, meanwhile, has chosen a fundamentally different path: no single AI Act, no centralised risk classification, and no prescriptive legislative framework. Instead, existing regulators — the ICO, ASA, Ofcom, and others — are applying their existing mandates to AI within their respective domains, guided by five cross-cutting principles.
For marketing teams operating across both jurisdictions, or targeting audiences in both markets, the practical reality is this: you are likely subject to both frameworks simultaneously, and the compliance burden is about to increase sharply.
This briefing covers what you need to know, what you need to do, and what to watch for next.
Part One: The EU AI Act
1.1 What Is It?
The EU AI Act (Regulation (EU) 2024/1689) is a horizontal, legally binding regulation that establishes a comprehensive framework for the development, placement on the market, putting into service, and use of AI systems within the European Union. It applies to:
- Providers who place AI systems on the EU market (including those based outside the EU)
- Deployers who use AI systems in the course of their professional activities within the EU
- Importers and distributors of AI systems
- Authorised representatives of non-EU providers
The key point for UK-based marketing teams: if your AI systems affect people in the EU, the Act applies to you regardless of where you are based.
1.2 Risk Classification: The Four Tiers
The EU AI Act classifies all AI systems into four risk categories, each with escalating obligations:
Tier 1: Unacceptable Risk (Prohibited)
These AI practices are banned outright. They include:
- AI systems using subliminal, manipulative, or deceptive techniques that materially distort behaviour and cause significant harm
- AI systems exploiting vulnerabilities related to age, disability, or social/economic situation
- Social scoring systems that classify or evaluate people based on social behaviour or personal traits
- Real-time remote biometric identification in publicly accessible spaces (with limited law enforcement exceptions)
- Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases
- AI systems inferring emotions in workplaces and educational settings (with medical/safety exceptions)
- Biometric categorisation to infer sensitive attributes such as race, political opinions, or sexual orientation
- From 2 December 2026: AI systems generating child sexual abuse material or non-consensual intimate imagery
Marketing relevance: If your targeting strategies involve profiling individuals based on sensitive attributes, or your AI systems use techniques that could be characterised as manipulative or exploitative, you are operating in prohibited territory. This includes certain forms of behavioural micro-targeting that exploit cognitive vulnerabilities.
Tier 2: High Risk
High-risk AI systems are not banned but are subject to stringent requirements before they can be placed on the market. They typically fall into two groups:
- AI systems as safety components of regulated products (medical devices, aviation, vehicles, etc.)
- AI systems used in specific domains listed in Annex III, including:
- Biometric identification and categorisation
- Critical infrastructure management
- Education and vocational training
- Employment, worker management, and recruitment
- Access to essential services (credit scoring, insurance, healthcare)
- Law enforcement and criminal justice
- Migration and border control
- Administration of justice and democratic processes
Marketing relevance: Most marketing AI systems will not fall into the high-risk category directly. However, if your organisation uses AI for recruitment, credit assessment, or customer profiling that determines access to essential services, those systems may be classified as high-risk. The obligations include:
- Comprehensive risk management systems
- High-quality training data with documented provenance
- Detailed technical documentation
- Human oversight mechanisms
- Accuracy, robustness, and cybersecurity standards
- Registration in the EU database
Important note: The “AI Act Omnibus” agreement (May 2026) has proposed extending compliance deadlines for high-risk systems in Annex III to 2 December 2027, and for high-risk systems embedded in regulated products (Annex I) to 2 August 2028. This proposal needs formal adoption before 2 August 2026 to take legal effect.
Tier 3: Limited Risk
These systems present lower levels of risk but are subject to specific transparency requirements. This is where most marketing AI systems will sit. Examples include:
- Chatbots and virtual assistants
- Emotion recognition systems (in non-prohibited contexts)
- Systems generating deepfakes or synthetic content
- AI-generated text, images, audio, or video used in advertising
Obligations: Providers must ensure that humans are informed when they are interacting with an AI or viewing AI-generated content.
Tier 4: Minimal or No Risk
The vast majority of AI systems, including spam filters, AI-enabled video games, and basic product recommendation engines. No mandatory obligations apply, though voluntary codes of conduct are encouraged.
1.3 The August 2026 Deadline: Article 50 Transparency Obligations
This is the deadline that matters most for marketing teams. On 2 August 2026, the transparency obligations under Article 50 of the EU AI Act come into force. These requirements apply to all deployers of AI systems that generate or manipulate content, not just those classified as high-risk.
What Article 50 requires:
-
AI-Generated Content Disclosure: Any content that has been generated or substantially manipulated by AI must be clearly and prominently disclosed to the person encountering it. This applies to:
- Synthetic images (including AI-generated product imagery, lifestyle scenes, virtual models)
- AI-generated or AI-edited video content
- AI-generated text (where it could be mistaken for human-authored content)
- AI-generated or AI-manipulated audio
- Deepfakes
-
Deepfake Labelling: The Act defines deepfakes as AI-generated or manipulated image, audio, or video content that resembles existing persons, objects, places, or events and would falsely appear authentic. Content that is clearly fantastical (e.g., dragons, impossible scenarios) is generally excluded. Deepfakes must be clearly labelled as AI-generated or manipulated.
-
Chatbot Disclosure: If an AI system directly interacts with a user, it must clearly inform the user that they are interacting with an AI, unless this is obvious to a reasonably well-informed person.
-
Machine-Readable Marking: Providers of AI systems that generate synthetic content (images, audio, video) are required to mark their outputs in a machine-readable format to ensure detectability. This includes watermarking and metadata tagging.
-
Method of Disclosure: The disclosure must be:
- Clear and prominent
- Presented at the time the person encounters the content
- Not buried in terms and conditions or general AI notices
- Acceptable methods include persistent visual labels, opening disclaimers for videos, and audible warnings for audio
-
Artistic Exception: For deepfakes that are part of evidently artistic, creative, satirical, fictional, or analogous works, the transparency obligation is limited to disclosure in a manner that does not hinder the display or enjoyment of the work.
What this means in practice for marketing teams:
- Every piece of AI-generated creative used in campaigns targeting EU audiences must be disclosed
- Chatbots and AI customer service tools must identify themselves
- Virtual influencers, AI-generated product imagery, and synthetic lifestyle content all require labelling
- You cannot offload this obligation to your tooling vendors — as the deployer, you carry the duty to disclose
1.4 Penalties and Fines
The EU AI Act establishes a three-tiered penalty structure:
| Violation Type | Maximum Fine |
|---|---|
| Non-compliance with prohibited AI practices (Article 5) | €35 million or 7% of global annual turnover (whichever is higher) |
| Non-compliance with high-risk obligations or GPAI model requirements | €15 million or 3% of global annual turnover |
| Supply of incorrect or misleading information to authorities | €7.5 million or 1% of global annual turnover |
For SMEs, fines are capped at the lower of the fixed amount or the percentage of turnover.
1.5 Implementation Timeline
| Date | What Comes Into Force |
|---|---|
| 1 August 2024 | AI Act enters into force |
| 2 February 2025 | Prohibited AI practices and AI literacy obligations |
| 2 August 2025 | Rules for general-purpose AI (GPAI) models and governance |
| 2 August 2026 | High-risk AI systems (Annex III) and transparency obligations (Article 50) |
| 2 December 2026 | New prohibitions on CSAM/non-consensual imagery generators; watermarking obligations |
| 2 December 2027 | Proposed extended deadline for Annex III high-risk systems (pending Omnibus adoption) |
| 2 August 2028 | Proposed extended deadline for Annex I high-risk systems (pending Omnibus adoption) |
1.6 How the EU AI Act Applies to Specific Marketing Channels
Google Ads
- AI-Generated Creative: Any ad creative generated or substantially modified by AI must be disclosed. This includes AI-generated copy, images, and video.
- Google’s Updated Terms: Effective 1 July 2026, Google’s ad terms authorise automation to generate ad destinations. This does not remove your disclosure obligation as the advertiser.
- Targeting and Profiling: AI-powered targeting must not rely on prohibited practices (social scoring, exploitation of vulnerabilities, inference of sensitive attributes). You must also comply with GDPR requirements for personal data processing.
- Accountability: You, the advertiser, carry the disclosure obligation. You cannot rely on Google or your AI tools to do it for you.
Paid Social
- AI-Generated Creative Disclosure: Same requirements as Google Ads. All synthetic images, videos, and text must be disclosed.
- Prohibition on Manipulative Practices: The Act explicitly forbids AI-generated fake reviews, testimonials, and any methods using AI to manipulate customer behaviour.
- Chatbot Disclosure: Any AI-powered chatbot interactions in paid social contexts must identify themselves as AI.
- Data Usage: AI-powered profiling for targeting must be transparent and comply with data protection standards.
Organic Social
- Content Disclosure: Marketers using generative AI to create organic social content must disclose its AI origin. This may require disclaimers within campaigns.
- Deepfake Labelling: Any AI-generated or manipulated visual or audio content that could be mistaken for authentic must be labelled.
- Chatbot Disclosure: AI-powered customer interaction tools on organic channels must disclose their nature.
- Platform Accountability: Social media platforms themselves may face heightened obligations as high-risk AI systems, particularly around recommendation algorithms and content moderation.
Part Two: UK AI Policy
2.1 The UK Approach: Principles Over Prescriptions
The UK has deliberately chosen not to create an EU AI Act equivalent. Instead, the government’s March 2023 White Paper, “A Pro-Innovation Approach to AI Regulation,” established a framework built on five cross-cutting principles, to be applied by existing sector-specific regulators:
- Safety, security, and robustness
- Transparency and explainability
- Fairness
- Accountability and governance
- Contestability and redress
These are not legally binding in themselves. They are implemented through guidance issued by regulators within their existing mandates, not through new AI-specific legislation.
The critical distinction: Where the EU has a single Act with a centralised risk classification, the UK has a decentralised system where each regulator interprets and applies the five principles within their domain.
2.2 The Key Regulators for Marketing Teams
Information Commissioner’s Office (ICO)
The ICO is the primary regulator for AI concerning personal data, operating under the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.
Current status (June 2026):
- From 12 May 2026, the ICO has a statutory duty to develop a comprehensive Code of Practice on AI and automated decision-making
- In April 2026, the ICO launched a consultation on draft guidance for automated decision-making (closed May 2026), with final guidance expected summer 2026
- The full Code of Practice is expected in 2027
- In May 2026, the ICO advised the government on potential revisions to PECR Regulation 6 (Privacy and Electronic Communications Regulations), differentiating between lower-risk advertising practices and more intrusive tracking
- From 19 June 2026, new rules require businesses to provide clear avenues for data protection complaints, acknowledge within 30 days, investigate promptly, and communicate outcomes
Marketing relevance: The ICO’s focus on automated decision-making, profiling, and targeted advertising means that AI-powered marketing systems that process personal data are firmly within scope. The emerging Code of Practice will likely impose transparency and governance obligations that parallel elements of the EU AI Act, but through the lens of data protection law.
Advertising Standards Authority (ASA)
The ASA regulates AI in advertising through its existing, media-neutral codes: the CAP Code (non-broadcast) and the BCAP Code (broadcast). These codes apply regardless of whether content is human-generated or AI-generated.
Current status (June 2026):
- The ASA’s AI-powered Active Ad Monitoring System (AAMS) is projected to review 40 million online advertisements in 2026
- The ASA has already issued rulings against misleading AI-generated content, including AI fitness influencers and images deemed to objectify individuals
- CAP advises advertisers to disclose the use of AI if its omission could mislead consumers
- Further CAP guidance on AI in advertising is expected throughout 2026
Marketing relevance: The ASA’s approach is straightforward: advertisers are responsible for all AI-generated content, and it must not be misleading, harmful, offensive, or socially irresponsible. There is no separate AI-specific code, but the existing codes are being applied to AI content with increasing vigour.
Ofcom
Ofcom’s AI role stems from its oversight of telecoms networks (Telecoms Security Act 2021) and online services (Online Safety Act 2023).
Current status (June 2026):
- Published its AI Strategy for 2026/27 on 4 June 2026, adopting a technology-neutral, outcomes-focused approach
- Plans to release a draft Fraudulent Advertising Code of Practice in summer 2026, informed by research into deepfake fraud
- Actively monitoring consumer trust in AI chatbots and the impact of AI on customer experience
- Research findings expected in the second half of 2026
Marketing relevance: Ofcom’s focus is primarily on the infrastructure and online safety dimensions rather than direct advertising regulation. However, the Fraudulent Advertising Code of Practice could have implications for AI-generated advertising that appears on Ofcom-regulated platforms.
Digital Regulation Cooperation Forum (DRCF)
The DRCF coordinates cross-regulatory AI activities between the ICO, CMA (Competition and Markets Authority), Ofcom, and FCA. This is the closest the UK gets to a unified AI governance body, though it coordinates rather than regulates directly.
2.3 The UK Regulatory Gap: What Is Missing
The UK’s approach has notable gaps compared to the EU AI Act:
-
No risk classification system: There is no UK equivalent of the four-tier risk hierarchy. Regulators assess AI risk within their existing mandates, which means there is no unified standard for what constitutes “high-risk” AI across sectors.
-
No comprehensive transparency obligations: While the ICO and ASA both address transparency in their respective domains, there is no single, legally binding requirement equivalent to Article 50 of the EU AI Act.
-
No prohibited practices list: The UK has not legislated specific AI practices as prohibited. Harmful uses of AI are addressed through existing law (data protection, consumer protection, equality law) rather than a dedicated AI framework.
-
No centralised enforcement: Enforcement is fragmented across multiple regulators, each with different powers, penalties, and approaches.
-
No mandatory AI literacy obligations: The EU AI Act requires organisations to ensure a sufficient level of AI literacy among their staff. The UK has no equivalent requirement.
-
Uncertain legislative future: The government has signalled intent to introduce AI legislation, with a decision expected by autumn 2026. An anticipated AI Bill has not materialised, and the legislative timetable remains unclear.
2.4 Existing UK Law That Already Applies to AI in Marketing
Even without a dedicated AI Act, UK marketing teams are already subject to:
- UK GDPR and Data Protection Act 2018: Automated decision-making, profiling, and data processing requirements
- Data (Use and Access) Act 2025: Amends data protection law and grants the ICO new powers for AI oversight
- Consumer Rights Act 2015: Unfair terms, misleading actions, and consumer protection
- Consumer Protection from Unfair Trading Regulations 2008 (CPRs): Prohibition on misleading actions and aggressive practices
- Equality Act 2010: Discrimination in AI-powered targeting and decision-making
- PECR (Privacy and Electronic Communications Regulations): Rules on electronic marketing, cookies, and tracking
- CAP and BCAP Codes: Advertising standards applicable to all content regardless of origin
- Online Safety Act 2023: Obligations on platforms regarding harmful content, including AI-generated content
Part Three: EU vs UK — Similarities, Differences, and Practical Implications
3.1 Where They Align
| Area | EU AI Act | UK Approach |
|---|---|---|
| Transparency | Article 50 mandates disclosure of AI-generated content | ICO and ASA both require transparency, though through different mechanisms |
| Accountability | Deployers carry disclosure obligations | Advertisers responsible for all AI-generated content (ASA) |
| Consumer Protection | Prohibited practices include manipulation and exploitation | Consumer protection law prohibits misleading and aggressive practices |
| Data Protection | GDPR applies alongside the AI Act | UK GDPR and DPA 2018 apply |
| Deepfake Disclosure | Explicit labelling requirements | ASA guidance requires disclosure where omission would mislead |
| Chatbot Disclosure | Mandatory under Article 50 | ICO and ASA guidance both address this |
3.2 Where They Diverge
| Area | EU AI Act | UK Approach |
|---|---|---|
| Legislative Framework | Single, comprehensive, legally binding Act | No dedicated AI legislation; principles-based, regulator-led |
| Risk Classification | Four-tier system (unacceptable, high, limited, minimal) | No unified risk classification |
| Prohibited Practices | Explicit list of banned AI practices | No dedicated prohibited practices list; addressed through existing law |
| Enforcement | Centralised under national AI authorities with EU coordination | Fragmented across ICO, ASA, Ofcom, CMA, FCA |
| Penalties | Defined fine structure (up to €35m / 7% turnover) | Varies by regulator; ICO fines up to £17.5m / 4% turnover under UK GDPR |
| Transparency Obligations | Legally binding, specific, and detailed (Article 50) | Guidance-based, interpreted by each regulator |
| AI Literacy | Mandatory for all organisations deploying AI | No equivalent requirement |
| Registration | High-risk systems must be registered in EU database | No centralised registration requirement |
| Scope | Applies to anyone affecting EU individuals | Applies to UK-regulated activities |
3.3 The Extraterritorial Problem
This is the practical reality that many UK marketing teams have not yet absorbed: the EU AI Act applies extraterritorially. If your AI systems affect individuals in the EU, you are subject to the Act regardless of where you are based.
This means:
- A UK company running Google Ads campaigns targeting EU audiences must comply with Article 50
- A UK SaaS platform whose AI tools are used by EU deployers must comply with provider obligations
- A UK marketing agency creating AI-generated content for clients with EU customers must ensure disclosure
You do not need an EU office to be caught by this. The Act follows the individual, not the company’s jurisdiction.
3.4 Compliance Matrix: What Applies Where
| Scenario | EU AI Act | UK Regulations |
|---|---|---|
| UK company, UK audience only | ❌ Not directly applicable | ✅ UK GDPR, ASA codes, PECR, Consumer Rights Act |
| UK company, EU audience | ✅ Full EU AI Act applies | ✅ UK regulations also apply |
| UK company, UK + EU audiences | ✅ Full EU AI Act for EU portion | ✅ Full UK regulations |
| EU-based company, UK audience | ❌ EU AI Act applies to EU operations | ✅ UK regulations apply to UK targeting |
| AI tool provider (UK), used by EU deployers | ✅ Provider obligations apply | ✅ UK regulations for UK operations |
Part Four: Do’s and Don’ts for Marketing Teams
4.1 Do’s
-
Audit your AI stack now. Identify every AI tool in your marketing workflow: creative generation, copywriting, targeting, personalisation, chatbots, analytics, A/B testing. Document what each does, what data it processes, and where it operates.
-
Disclose AI-generated content proactively. If in doubt, disclose. The cost of disclosure is minimal; the cost of non-compliance is not. For EU-facing content, assume Article 50 applies.
-
Implement AI content labelling. Develop a standardised approach to labelling AI-generated or AI-assisted content across all channels. This should be visible, prominent, and consistent.
-
Review your targeting strategies. Ensure your AI-powered targeting does not rely on prohibited practices: social scoring, exploitation of vulnerabilities, inference of sensitive attributes, or subliminal manipulation.
-
Train your team on AI literacy. While the UK does not mandate this, the EU does for organisations operating in EU markets. Build AI literacy into your team development regardless of jurisdiction.
-
Document your AI decision-making. Maintain records of how AI tools are used in your marketing processes, what data they access, and what decisions they influence. This supports accountability under both frameworks.
-
Review vendor contracts. Ensure your AI tool providers are meeting their obligations under the EU AI Act (provider responsibilities) and that your contracts clearly allocate compliance responsibilities.
-
Prepare for the ICO Code of Practice. The ICO’s Code on AI and automated decision-making is expected in 2027. Start aligning with the draft guidance now rather than waiting for final publication.
-
Monitor the UK legislative timetable. A decision on UK AI legislation is expected by autumn 2026. Be prepared for the possibility that the UK introduces more prescriptive requirements.
-
Build compliance into your creative workflow. AI disclosure should not be an afterthought added at the end of the creative process. It should be a standard step in content production.
4.2 Don’ts
-
Don’t assume the UK is exempt from the EU AI Act. If you touch EU audiences, you are in scope. Full stop.
-
Don’t bury AI disclosures. A disclaimer hidden in terms and conditions does not satisfy Article 50. Disclosure must be clear, prominent, and presented at the point of encounter.
-
Don’t use AI to generate fake reviews or testimonials. This is explicitly prohibited under the EU AI Act and is likely to be addressed by UK regulators as well.
-
Don’t rely on platform tools to handle compliance for you. Google, Meta, and other platforms are updating their terms, but the disclosure obligation sits with you, the deployer. Platforms provide tools; you provide compliance.
-
Don’t assume AI-generated content is “obviously” AI-generated. If it could be mistaken for authentic by a reasonable person, it requires disclosure.
-
Don’t ignore the ASA. The ASA’s Active Ad Monitoring System is reviewing 40 million ads in 2026. AI-generated content that is misleading, harmful, or socially irresponsible will be caught and ruled against.
-
Don’t conflate “principles-based” with “optional.” The UK’s approach may be less prescriptive than the EU AI Act, but the existing regulations carry real enforcement powers. ICO fines can reach £17.5 million or 4% of global turnover.
-
Don’t wait for final guidance before acting. The direction of travel is clear in both jurisdictions. Compliance costs are lower when built in early rather than retrofitted.
-
Don’t assume minimal-risk AI systems are entirely unregulated. While the EU AI Act does not impose specific obligations on minimal-risk systems, they remain subject to existing consumer protection, data protection, and advertising law in both jurisdictions.
-
Don’t forget your supply chain. If you use third-party AI tools, your compliance depends on theirs. Vet your providers.
Part Five: Things to Think About
5.1 The Trust Deficit
The regulatory response to AI in marketing is not happening in a vacuum. Consumer trust in advertising is already low, and the proliferation of AI-generated content is accelerating the erosion. The ASA’s proactive monitoring and the EU’s transparency requirements are both responses to a consumer protection problem that the market has not self-corrected.
For marketing teams, this is not just a compliance question. It is a strategic one. Brands that embrace transparency and build trust through honest disclosure will outperform those that treat AI disclosure as a box-ticking exercise.
5.2 The Competitive Implications
The EU AI Act creates a competitive asymmetry. Companies that comply early will build consumer trust and regulatory goodwill. Those that delay face both legal risk and reputational damage. The ASA’s willingness to name and rule against brands, combined with the EU’s substantial fine structure, means the cost of non-compliance is both financial and public.
5.3 The UK Legislative Horizon
The UK government’s autumn 2026 decision on AI legislation will be the defining moment for UK AI policy. If the UK introduces a more prescriptive framework, the current regulatory patchwork could be consolidated into something closer to the EU model. If it does not, the fragmented approach will continue, and UK businesses operating in EU markets will continue to be caught by both systems.
5.4 The Generative AI Supply Chain
Most marketing teams do not build their own AI systems. They use tools provided by third parties: Google’s Performance Max, Meta’s Advantage+, ChatGPT, Midjourney, and others. This creates a complex supply chain of obligations:
- Providers (tool vendors) have obligations around training data, documentation, watermarking, and machine-readable marking
- Deployers (you) have obligations around disclosure, transparency, and accountability
- The compliance boundary is not always clear, and contracts should explicitly address it
5.5 The Intersection with Data Protection
AI regulation does not exist in isolation. It intersects with GDPR/UK GDPR in critical ways:
- AI profiling for targeting involves personal data processing
- Automated decision-making rights under Article 22 GDPR apply to AI-driven marketing decisions
- Consent requirements for tracking and profiling remain unchanged by the AI Act
- The Data (Use and Access) Act 2025 adds new dimensions to UK data protection law that interact with AI regulation
Part Six: Key Dates to Watch
| Date | Event | Relevance |
|---|---|---|
| Now | ASA Active Ad Monitoring at full capacity | AI-generated ads being reviewed at scale |
| 19 June 2026 | New ICO complaint handling rules | Data protection complaint obligations for AI-related data processing |
| 1 July 2026 | Google Ads updated terms | Authorises automation; advertiser disclosure obligations unchanged |
| 2 August 2026 | EU AI Act Article 50 enforcement | Transparency obligations for AI-generated content become enforceable |
| Summer 2026 | ICO draft automated decision-making guidance (final) | Expected to set direction for UK AI regulation |
| Summer 2026 | Ofcom Fraudulent Advertising Code (draft) | Implications for AI-generated advertising on regulated platforms |
| Autumn 2026 | UK government decision on AI legislation | Could fundamentally reshape UK AI regulatory landscape |
| 2 December 2026 | New EU prohibitions + watermarking obligations | CSAM/non-consensual imagery bans; enhanced marking requirements |
| 2027 | ICO Code of Practice on AI | Comprehensive UK AI governance framework |
| 2 December 2027 | Proposed extended Annex III deadline (pending Omnibus) | High-risk AI system compliance deadline (if adopted) |
Appendix: Glossary of Key Terms
| Term | Definition |
|---|---|
| AI System | A machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments |
| Deployer | Any natural or legal person, including a public authority, agency or other body, using an AI system under its authority (i.e., you, the marketing team using the tool) |
| Provider | Any natural or legal person that develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark (i.e., the tool vendor) |
| Deepfake | AI-generated or manipulated image, audio, or video content that resembles existing persons, objects, places, or events and would falsely appear authentic or truthful |
| General-Purpose AI (GPAI) | AI systems that can be used for a wide range of purposes, including large language models and image generators |
| High-Risk AI System | An AI system classified under the Act’s Annex III categories or as a safety component of regulated products, subject to stringent obligations |
| Machine-Readable Marking | Technical measures (watermarking, metadata, cryptographic signatures) that enable the identification of AI-generated content by automated systems |
| Article 50 | The section of the EU AI Act establishing transparency obligations for AI-generated content, chatbots, deepfakes, and emotion recognition systems |
| Omnibus | The proposed amendments to the AI Act (May 2026) extending compliance deadlines for high-risk systems |
This briefing is current as of June 2026. The regulatory landscape is evolving rapidly. This document should be reviewed and updated as new guidance, legislation, and enforcement actions emerge.
David Chadderton is the creator of the STAR Framework and the author of three books: The STAR Framework: Rewriting the Rules of Consumer Engagement (NYC Big Book Award 2025), The STAR Operating System: Decode Mindset, Understand Motivation, Transform Human Behaviour, and Dear Algorithm, It’s Not Me, It’s You. He spent his twenties and thirties teaching people how to make life-or-death decisions at forty thousand feet. He now applies the same principles to consumer psychology, which, depending on the brief, can feel equally high-stakes. By day, a Chief Marketing Officer. By night, a behavioural science obsessive who writes The Unoptimised Human because he can’t stop thinking about why people do what they does.
The STAR Framework
If you enjoyed this essay, you'll find the full argument — and the framework behind it — in the book.