The European Union's AI Act has recently entered another key phase of implementation. From 2 August 2026, new transparency obligations apply to many AI systems that interact with people. But what does that mean for UK businesses, and what other laws govern AI used in customer interactions?
Britain has deliberately chosen not to introduce its own AI Act, yet organisations deploying customer-facing AI are far from operating in a legal vacuum. Many will still fall within the scope of the EU AI Act while also navigating a growing body of UK legislation, regulatory guidance and common law. This guide explains how those rules fit together, where legal responsibility lies, and the practical steps businesses should take.
The regulation myth
Your chatbot promises a customer a refund they aren't entitled to. An AI email assistant invents a delivery guarantee. A generative support agent gives incorrect advice about cancelling a contract. Can your business blame the AI? Probably not.
Many UK organisations assume that Brexit means the EU AI Act doesn't affect them, or that the UK's lack of an AI Act leaves AI largely unregulated. Both assumptions are wrong. The EU AI Act will still apply to some UK companies, regardless of where they are headquartered. Moreover, every UK business deploying AI that talks to customers, whether or not the EU Act applies to it, already carries duties drawn from consumer protection, data protection, equality and common law.
Instead of examining each law in isolation, this article shows how they work together when AI interacts with customers. Written for CX leaders rather than lawyers, it focuses on where legal risks arise and how businesses can manage them.
At a glance AI that talks to UK customers sits under two overlapping frameworks: ● EU AI Act – applies to many UK organisations serving EU customers; introduces AI-specific duties such as transparency and AI literacy. ● UK law – applies regardless of the EU AI Act; spans common law, data protection, consumer protection, equality and online safety. The practical challenge is understanding where those two frameworks overlap and which rules apply in each situation. |
The UK and EU have taken different approaches to AI regulation
The EU AI Act, in force since August 2024, is comprehensive, AI-specific legislation that applies a risk-based framework harmonised across all Member States. Some obligations have since been delayed under the EU's Omnibus simplification package, but transparency requirements for many AI tools used in customer service have now come into effect. For a closer look at the practical implications, explore what the EU AI Act means for customer experience leaders.
Since Brexit, the UK has deliberately positioned itself as a more innovation-friendly environment for AI than the EU. Rather than introducing a single AI Act, it has chosen to adapt current laws and empower regulators, including the Information Commissioner's Office (ICO), the Competition and Markets Authority (CMA), the Financial Conduct Authority (FCA) and Ofcom, to oversee AI within their own sectors.
That doesn’t mean AI sits outside the law. The UK Jurisdiction Taskforce (UKJT), an industry-led initiative, published a Legal Statement on Liability for AI Harms in July 2026. According to the Statement, English common law is already well equipped to handle AI liability without new legislation.
The UK hasn't avoided AI regulation. It has distributed it across legislation, regulatory guidance and common law. Different regulatory models do not necessarily mean different expectations of responsible AI. Whether liability flows from an EU compliance regime or an English negligence claim, the underlying question CX leaders should ask is the same. Did the business take reasonable care?
When does the EU AI Act apply to UK businesses?
The AI Act has extraterritorial reach. A UK business may still be subject to the EU AI Act even without an EU office, by serving EU customers, deploying AI whose outputs are used in the EU, or supplying AI-enabled products into European markets. What matters is where the AI's outputs are used, not where the business is incorporated.
Most UK businesses using third-party AI tools, such as a chatbot platform or an AI-assisted routing system, sit in the Act's deployer category rather than the more heavily regulated provider category, with narrower but still meaningful obligations around oversight and monitoring.
For AI that talks to customers, two elements matter most: transparency obligations under Article 50, requiring that people are told when they are interacting with an AI system rather than a human, and a requirement for sufficient AI literacy among staff who oversee those systems. Most CX tools, such as service chatbots and virtual agents, sit in the Act's limited-risk category rather than the high-risk tier, making transparency and literacy the most immediate practical concern. It is worth investigating what customers actually expect from AI transparency before assuming a brief disclosure is enough.
Why this matters for CX leaders
Unlike internal AI tools that support employees behind the scenes, AI that talks to customers communicates directly with them, creates expectations, shapes contractual relationships and may make representations on behalf of the business, whether recommending compensation, negotiating a refund, rescheduling a delivery, or acting autonomously on a customer's behalf without a human in the loop. That makes customer experience one of the first areas where AI governance becomes a board-level issue, not just an operational one. Our guide sets out what every company needs for AI governance in customer experience.
The UK legal framework for customer-facing AI
For CX teams in the UK, the clearest way to understand obligations is through the risks created when AI interacts with customers.

When AI makes a promise
The UKJT's Legal Statement sets out a central principle that CX leaders should take seriously. If an organisation presents a chatbot as communicating on its behalf, English courts are likely to treat its statements as those of the business. Liability for negligent misrepresentation may arise where customers are led to believe the chatbot's statements are accurate.
In practice, an AI assistant that promises a refund it cannot honour, quotes the wrong price or misdescribes a cancellation policy is not a technical glitch to be quietly fixed. It can be treated in law much like a human employee making the same statement, engaging doctrines including negligent misrepresentation and agency.
Disclaimers are not a reliable shield. Stating that a chatbot “may make mistakes” is unlikely, alone, to eliminate liability. What matters is whether it genuinely resets a reasonable customer's expectations, rather than sitting buried in terms nobody reads.
Perhaps the most important lesson from the Statement is that courts will examine governance, not just outcomes. They’ll look at whether the company tested the system, red-teamed it for foreseeable failure modes, built in guardrails, monitored live outputs and documented that process, rather than whether the AI hallucinated. For a practical breakdown, see how AI guardrails keep customer-facing AI safe.
None of this can be outsourced to a software vendor. Customers have a relationship with the business, not the underlying model provider, so if an AI system causes loss, the deploying organisation may remain liable regardless of its vendor contract. Recovering costs from the vendor afterwards is a separate, and often harder, question.
When AI makes a decision
A second category of risk arises when AI is used to make or materially influence decisions about customers, such as refusing a refund, locking an account, prioritising a complaint, flagging suspected fraud or assessing eligibility for a product.
Under the Data (Use and Access) Act 2025, which from February 2026 replaced Article 22 of the UK GDPR with a revised regime, businesses can rely on a wider range of lawful bases for automated decisions that do not involve special category data. That flexibility comes with conditions attached, not a removal of them. The Information Commissioner's Office (ICO) has said companies remain responsible for complying with data protection law whatever automated tools they use.
Where a decision is based solely on automated processing and has a legal or similarly significant effect, businesses must still provide meaningful information about it, and let the customer make representations, obtain human intervention and contest the outcome. “Meaningful human involvement” is the test. A token sign-off that never changes an outcome is unlikely to satisfy it.
When AI treats customers unfairly
A third risk category runs across several laws that protect customers from unfair treatment, whether or not it stems from AI. The Consumer Rights Act 2015 requires goods, digital content and services to be as described, engaged where an AI assistant hallucinates a policy or misstates a product's features. The Digital Markets, Competition and Consumers Act 2024 lets the CMA act against misleading automated interactions with customers. The Equality Act 2010 prohibits discrimination arising from biased AI outputs, an increasingly live issue where voice AI performs worse for certain accents, or triage systems produce unequal outcomes across protected characteristics.
A chatbot that invents a return policy, or a triage tool that produces skewed outcomes for a protected group, can each trigger liability under current statutes, entirely independent of the EU AI Act. AI does not need its own law to create legal liability. Existing consumer protection, competition and equality laws already apply.
When AI causes harm
The legal risks of AI extend well beyond customer conversations. The Online Safety Act 2023 is relevant where generative AI produces unsafe or inappropriate outputs. Defamation law can apply where AI-generated statements damage a third party's reputation. The UKJT Statement suggests businesses deploying AI to publish content will generally be treated as commercial publishers, and that common defences may not be available for wholly AI-generated statements published without human review. Confidentiality can be breached where an AI system leaks sensitive information, and copyright issues can arise where AI-generated content draws too closely on protected material.
What CX leaders should do next
This is a practical governance checklist rather than a compliance exercise to be completed once and forgotten.
Know your AI
● Identify every AI system that talks to customers, including tools individual teams introduced informally.
● Ask one simple question for each. Does this AI ever interact with customers in the EU?
● Make sure every system has an accountable owner.
Test before launch
● Evaluate systems for hallucinations and foreseeable failure modes before launch, not just after a customer complains.
● Test edge cases and adversarial inputs, not only the happy path.
● Monitor live outputs on an ongoing basis, and keep evidence of that testing.
Protect customers
● Use clear, prominent disclosures when customers are talking to AI, rather than a single mention buried in terms and conditions.
● Offer a genuine route to human escalation, not a loop back to the same automated system.
● Review any automated decision with real consequences for a customer, and keep the knowledge behind AI assistants current.
Keep governance current
● Train staff on responsible AI use.
● Keep an eye on regulatory developments on both sides of the Channel.
● Review supplier contracts and liability provisions. A vendor's terms will not determine what a business owes its own customers.
Final Thoughts
Different doesn't mean deregulated. The UK's decision not to introduce an AI Act was never a decision to leave AI unregulated. The framework already exists. It’s spread across legislation, regulatory guidance and common law rather than gathered into a single statute, and it applies whether or not the EU AI Act does too.
For CX leaders, the challenge is not keeping pace with one new law. It is understanding how multiple legal obligations come together every time AI interacts with a customer. Businesses that get this right will not just reduce risk. They’ll build the trust that successful AI adoption depends on.
References and Further Reading
This article is based on UK and EU legislation, regulatory guidance and legal analysis in force at the time of publication. It is intended for general information only and does not constitute legal advice. Readers should consult the original sources and seek professional advice where appropriate.
Primary legislation
● UK GDPR

