Two regimes, one policy

The UK loosened automated decision-making this February while the EU tightened on a delayed timetable, so a single AI policy will be wrong somewhere.

In 2026 the UK and the EU moved in opposite directions on automated decision-making. The UK relaxed the rule that everyone quotes. The EU kept tightening, but pushed its hardest deadlines back by more than a year. If you write one global AI policy and apply it everywhere, you will either over-comply in the UK, which costs you speed and credibility with the business, or under-comply in the EU, which costs you more than that. The way out is not two policies. It is one policy with a single set of principles and obligations that switch on according to where the output lands.

I am not a lawyer and this is not legal advice. What follows is what I have had to understand to write internal guidance that works.

The UK loosened the rule everyone quotes

The Data (Use and Access) Act 2025 came in stages. The date that matters for workplace AI is 5 February 2026 (ICO guidance on what the Act means for organisations).

From that date, the restriction on solely automated decision-making applies only where the decision is based entirely or partly on special category data. For everything else, the full range of lawful bases is available for significant automated decisions, including legitimate interests (Clifford Chance on the provisions taking effect).

That is a genuine change in posture, and a lot of internal policy still reflects the old one. Four safeguards remain mandatory: tell people automated decision-making is being used, allow them to make representations, provide meaningful human intervention, and allow the decision to be contested (ICO). The Act also introduced recognised legitimate interests as a lawful basis with no balancing test, expanded the ICO’s enforcement powers, and raised PECR fines from £500,000 to £17.5 million or 4% of global annual turnover. A later tranche, in force from 19 June 2026, requires controllers to facilitate data subject complaints, acknowledge them within 30 days and respond without undue delay.

The ICO’s draft guidance on automated decision-making and profiling describes the shift precisely: from a prohibition with exceptions to a right of challenge with safeguards. It is also blunt about what human involvement has to mean: active rather than tokenistic, carried out by trained and qualified reviewers who understand the system’s logic and its limitations (ICO consultation page). That consultation ran from 31 March to 29 May 2026 and is closed. The final guidance has not been published, so treat it as a strong signal and not as settled.

The practical read for a UK-only process: your problem is no longer the lawful basis. It is evidencing that the human in the loop is real. A reviewer who approves everything put in front of them is not meaningful human intervention. Everyone in the room knows it.

There is no UK AI Act, and that is the position

There is no mention of AI, artificial intelligence, AI regulation or regulatory sandboxes anywhere in the King’s Speech of 13 May 2026 (the speech). Planning on the basis that a UK AI Act is coming shortly is planning on a wish.

In a Lords debate on an AI Regulation Bill, the minister described AI as a general-purpose technology with a wide range of applications. It should be regulated at the point of use, through sector regulators under existing law. Peers noted that this departs from the 2024 manifesto commitment to binding cross-sector regulation (Hansard).

There is no single statute to map controls against, so the obligations arrive through data protection, employment law, equality law and whatever your sector regulator says. A policy organised around AI as a category will miss most of them. A policy organised around use cases will not.

The Regulating for Growth Bill, announced in the same speech, puts regulatory sandboxes on a statutory footing so businesses can test AI products in a real-world setting, including cross-cutting AI sandboxes (the speech). The ICO’s pipeline matters more day to day: guidance on agentic AI is in drafting with no public consultation planned, expected Winter 2026, and foundation models guidance is expected Summer 2026 (ICO guidance plans). If you are deploying agents in the UK, the agentic AI guidance is the document that will change your controls, and you will not get a consultation to prepare for it.

The EU moved its dates, and most published guidance has not caught up

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted on 8 July 2026 and entered into force on 27 July 2026, amending the AI Act (Official Journal, Orrick’s summary of the changes). It changed the timetable that most compliance plans were built against.

Obligation Original date Now
High-risk standalone systems, Annex III (includes employment and worker management) 2 August 2026 2 December 2027
High-risk embedded systems, Annex I 2 August 2027 2 August 2028
AI regulatory sandboxes operational 2 August 2026 2 August 2027

Those postponements are set out by the Future of Privacy Forum and Gibson Dunn.

What did not move is the transparency layer. Article 50 took effect on 2 August 2026 and is live now (Jones Walker’s summary). It requires five things:

  1. Tell people they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person.
  2. Mark synthetic audio, image, video and text in machine-readable form, to the extent technically feasible.
  3. Inform people exposed to emotion recognition or biometric categorisation.
  4. Disclose deepfake content, with exceptions for artistic and creative work.
  5. Disclose AI-generated text published on matters of public interest, except where there is human review or editorial control.

Penalties in the Article 50 context run up to €15 million or 3% of total worldwide annual turnover, whichever is higher, with lower caps for smaller organisations.

On 2 December 2026 a new Article 5 prohibition takes effect, and the transitional marking obligation under Article 50(2) begins to bite for systems placed on the market before 2 August 2026. Article 4 on AI literacy has been in force since 2 February 2025. The omnibus softened it. The duty is now to support the development of AI literacy, not to guarantee any particular level of it (Orrick). Softened is not removed, and it applies today.

Now check your own materials. When I looked on 8 August 2026, the widely cited AI Act tracker that half the market links to still showed the pre-omnibus dates. If your internal briefing or your supplier’s compliance pack was built from a secondary tracker, assume it is wrong on dates until proven otherwise.

The EU regime reaches a UK enterprise anyway

Article 2 applies the Act to providers placing AI systems on the EU market, irrespective of whether those providers are established within the Union or in a third country. It also applies to third-country providers and deployers where the output produced by the AI system is used in the Union (Article 2).

Output used in the Union is the phrase that catches people. A UK-headquartered organisation running a screening process from London, whose output decides something for a person in Dublin, is in scope. The question is not where the system runs. It is where the output lands.

HR is where the two regimes collide

Employment and worker management sit in Annex III, so those obligations are now on the 2 December 2027 date, not August 2026 (Future of Privacy Forum). For a UK enterprise with European operations, that is the planning date for HR-related AI. A reprieve, not a reversal.

The Department for Business and Trade opened a consultation on workplace monitoring technologies on 8 July 2026. It closes at 11:59pm on 30 September 2026 and is open now (the consultation). Its scope explicitly covers AI and algorithmic management, and one of the three options being tested is a legislative duty requiring employers to consult and negotiate with workers on monitoring technologies (A&O Shearman’s analysis). There is no such duty today.

The ICO’s guidance on monitoring workers, last updated 16 June 2026, now carries a notice that it is under review because of the Data (Use and Access) Act. It states that consent is not usually appropriate in the employment context, because of the imbalance of power between employer and worker. Workers must be told about monitoring in a way that is accessible and easy to understand. A data protection impact assessment is mandatory before any processing likely to cause high risk (ICO).

So HR is the least stable part of the map. Draft it so the controls can tighten without a rewrite.

What to write down

One document.

The principles are short and should not read like law. What the organisation will not use AI to decide on its own. What has to be disclosed to the person on the other end. Who is accountable when an output is wrong. What evidence a reviewer leaves behind. Two pages is enough, and two pages get read.

Obligations go in a schedule, keyed to the trigger rather than to the tool. If the output affects a person in the EU, the EU schedule applies, whatever the system is and wherever it runs. If the decision touches special category data, the UK restriction on solely automated decision-making still bites. If the use case is employment or worker management, treat it as the tightest case in the building.

Then a register, because both regimes assume you can produce one. Which systems, which use cases, which outputs go where, who owns each. Most organisations do not have this, and it is what turns the document into a control.

Two things to keep out of it. First, do not write that a supplier’s certification covers you. Microsoft holds ISO/IEC 42001 certification covering Microsoft 365 Copilot among other products, and says customers can use it in their own compliance assessment. It is also explicit that you remain responsible for engaging an assessor to evaluate the controls and processes within your own organisation (Microsoft). Second, do not write that ISO/IEC 42001 makes you AI Act compliant. It is not part of the EU harmonisation process, and providers relying on it alone retain the full evidentiary burden if challenged. The standard expected to carry presumption of conformity is prEN 18286 (Cloud Security Alliance research note). ISO/IEC 42001 certifies a management system. The AI Act regulates each high-risk system as a product.

If you only change one thing this month, check the dates in whatever your programme is planning against. A material number of AI governance plans currently in flight are working from a timetable that stopped being correct on 27 July 2026.

CRAIG STANLEY

Written 8 August 2026 in the North East of England. If something here is wrong, tell me and I will correct it on the page rather than quietly.