TL;DR: The €15m EU AI act fine that made the headlines this summer was written mostly for the companies that build the large AI models, not for the businesses that use them.

The real duties for an average business are short. They sort into three lists.

  • Always: tell people when they are dealing with an AI, not a human.

  • Never: read your own staff's emotions, that one is banned outright.

  • Watch: anything that decides who gets hired or lent to, where stricter rules land in 2027.

And in the UK, "no AI Act" has never meant "no rules" - the data duties were there all along.

What you always do: say it's an AI

One rule touches almost every business that puts an agent in front of people. From 2 August 2026, if an AI system talks to someone, that person has to be told they are dealing with a machine, at the start, in plain sight. That is Article 50 of the Act, and the European Commission's own guidance confirms it covers voice agents and website chatbots alike.

On the phone, that is a line in the greeting, before the agent asks for a name or an account number. Something like: "Hello, you're speaking with the AI assistant at Miller and Co." Modern voices are convincing enough that "well, they'd surely realise" is not a defence worth leaning on. Saying what the assistant handles, and how to reach a person, is good manners as much as law.

On a website, the same idea: the notice belongs in the chat window itself, in or before the first message, not three clicks deep in a privacy policy.

Two things that are not caught. A plain contact form, or a fixed "press 1 for sales" menu, is not an AI system, so the rule leaves it alone. And when a colleague takes over from the bot, or the bot from a colleague, a quick word to say so is enough. For most firms the transparency duty ends there. One honest sentence, per channel.

What you never do: the short banned list

A separate set of rules has been in force since early 2025, and these are outright bans rather than paperwork. Most cover behaviour a normal business would never go near: social scoring of customers, scraping faces off the internet to build a recognition database, systems built to manipulate people who are vulnerable. The European Commission lists nine of them.

One is easier to walk into by accident, and it is worth knowing about: reading your own staff's emotions. Software that infers how employees feel from their voice or their face, the "sentiment scoring" some call-centre tools advertise, is banned in the workplace, other than for genuine medical or safety reasons, under Article 5 of the Act. The ban lands on the business using the tool, even where the vendor's contract happily allowed it. The supplier's small print is not a shield.

So if a tool offers to flag which of your agents sounded stressed today, that is the one to decline.

What you watch: anything that decides about people

Between "always" and "never" sits a middle group. The moment AI starts making, or heavily shaping, decisions about people, who gets hired, who gets credit, who gets managed out, who reaches an essential service, it moves into a stricter "high-risk" bracket that does come with real paperwork.

The reprieve is that those duties were pushed back to December 2027 for most cases. So a business can pilot AI in recruitment or lending today. The sensible way is with a person in the loop making the call, rather than the model deciding on its own. Build it like that from the start, and the 2027 deadline arrives as a formality instead of a scramble.

The British footnote worth getting right

All of that is European law. Britain never passed an AI Act and has no plan to. It is tempting to read that as "no rules here," which would be the wrong lesson.

The Information Commissioner's Office has governed how businesses handle personal data all along, and an AI agent that listens, transcribes, and stores a call is handling personal data like anything else. Telling callers it's an AI helps on that front too, but it does not replace the call-recording and privacy notices, which are a separate job. Lighter on paper, then, but the data duties never left.

Two closing practicalities. The European rules reach across the Channel the moment an EU customer uses the chatbot or an EU caller reaches the line, wherever the company itself sits. And for smaller firms the fines are capped at the lower of the two figures, not the headline one. If a business does touch the EU at all, the tidy approach is one set of notes built to the stricter European standard and reused, rather than two regimes running side by side.

To sum up

Say it's an AI when it's a customer communication (live now). Don't point it at your own people's feelings; that one is already banned. Keep a human in the loop wherever it decides something that matters, since the heavy rules land in 2027. Everything else is mostly the data hygiene the business already owed.

Recommended for you

View all
caret-right