The EU AI Act explained: what applies to UK businesses and when
The EU AI Act explained for UK businesses: what already applies, the high-risk dates moved to 2027 and 2028 by the Digital Omnibus, penalties and the authorised representative duty.
UK data protection, GDPR, DPIAs, international transfers, data protection for AI-enabled products
The EU AI Act explained for UK businesses: what already applies, the high-risk dates moved to 2027 and 2028 by the Digital Omnibus, penalties and the authorised representative duty.
In short: three tests answer “does the Online Safety Act apply to my service?” as at 28 August 2026: whether the service enables user-generated content, includes a search engine or publishes pornographic content (ss 3 and 80); whether it has links with the UK (s 4, or s 80(4) for pornography providers); and whether an…
In short: the Digital Omnibus on AI, Regulation (EU) 2026/1744, has been in force since 27 July 2026. It moves the EU AI Act’s high-risk obligations to 2 December 2027 for AI in listed uses such as recruitment and credit scoring, and to 2 August 2028 for AI built into a regulated product. The Article…
In short: Bulk email data protection falls within the security duty in section 40 of the Data Protection Act 2018, which the Information Commissioner applied to the Metropolitan Police in a reprimand and enforcement notice dated 27 July 2026. Telling staff to use BCC was not a sufficient measure, and unevidenced training infringed section 40…
In short: the objective test for data subject consent means a data controller proves consent by what the data subject did, not by what was in their mind. In RTM v Bonne Terre [2026] EWCA Civ 488, handed down on 21 April 2026, the Court of Appeal reversed the subjective test the High Court had…
In short: The ICO’s reprimand for cyber security failings, issued to ACRO Criminal Records Office on 7 August 2026, turns on named ownership of patch management and monitoring of security alerts under UK GDPR Article 32. A hacker held access to ACRO’s website for seven months, exposing sensitive data for up to 10,920 people. The…
In short: AI Office enforcement covers a company only where it built the AI system on its own general-purpose AI model, or where the system operates inside a platform designated under the Digital Services Act. Every other business remains subject to national regulation. The difference matters, because the AI Office can enter and seal premises…
In short: GPAI enforcement began on 2 August 2026. If you build a product on someone else’s AI model, the duties in Articles 53 to 55 of the EU AI Act apply to that supplier and not to you. They still matter, because they entitle you to information from your supplier, and because very substantial…
In short: The Information Commission is the statutory board that will replace the Information Commissioner as the UK data protection regulator. Sections 117 to 119 of the Data (Use and Access) Act 2025 abolish the Commissioner as a corporation sole and vest its functions in a body corporate led by a chair, chief executive and…
In short: The EDPB AMLA guidelines will set out how AML information sharing partnerships work under GDPR once Article 75 of the EU AML Regulation takes effect on 10 July 2027. The EDPB and AMLA announced the joint drafting project on 1 July 2026, with a draft consultation due in the first half of 2027….
In short: the AI transparency code of practice is now the EU-wide route to demonstrating compliance with Articles 50(2), (4) and (5) of the EU AI Act. The European Commission concluded on 8 July 2026 that the code is adequate, and the AI Board agreed on 9 July 2026. Signing is not a safe harbour,…
In short: Web scraping for AI training is lawful under the GDPR only where a data controller has a lawful basis for it, and in practice that means the three-part legitimate interest test in Article 6(1)(f). On 8 July 2026 the European Data Protection Board adopted draft guidelines on web scraping for generative AI, out…