Responsible AI now decides two things for UK companies: whether customers trust you enough to buy, and whether your own teams trust the tools enough to use them. Harvard Business Review calls it a growth strategy. Fair. But the version that pays off fastest happens inside your company, and almost nobody talks about that part.
By Toni Dos Santos, Co-Founder, Spicy Advisory. Published 4 August 2026, two days after the EU AI Act's transparency duties took effect.
Key Takeaways
- 2 August 2026 happened. The EU AI Act's Article 50 transparency duties are live: telling users they are talking to a machine, labelling AI-generated content, marking deepfakes. The Digital Omnibus did not move that date.
- What did move is high-risk. Annex III systems (recruitment screening, credit scoring, education) shifted to 2 December 2027, and AI embedded in regulated products to 2 August 2028.
- The EU Act does not care where you are registered. Article 2 was not narrowed. If your AI system or its output reaches people in the EU, you are in scope with no EU entity and no EU servers.
- The UK still has no single AI law, and that is not a break. Five principles applied by the ICO, FCA, CMA and Ofcom, plus the Data (Use and Access) Act 2025, which has regulated solely automated decisions since 5 February 2026.
- The expensive gap is internal. Around 91% of companies invest in AI. Around 21% of employees use those tools in real work. The 70-point gap is a trust problem, not a compliance one.
- Three moves cover most of it: inventory every tool in use, publish a one-page guideline, train on real use cases. In that order.
Not sure what AI is already running inside your company?
Run the free AI diagnostic →Book 30 minutes10 minutes, no signup wall. A maturity score plus the three highest-value workflows for your firm.
What HBR actually said
In July 2026, Michael Wade and Jochen Wirtz argued in Harvard Business Review that trust is becoming a competitive advantage as AI gets embedded in products, services and decisions. Their point: Corporate Digital Responsibility has to grow up from a compliance exercise into a strategic capability.
The playbook has three stages. Know every AI system you run. Build governance in from the design stage. Then make your responsible practices visible to customers and regulators.
The examples they open with are the kind that end up in board papers:
- A robot toy maker fined by the FTC for harvesting children's location data without parental consent.
- SiriusXM facing a lawsuit over an AI hiring tool that allegedly screened out Black applicants using proxies like postcode and university, before any human saw a CV.
- Two Australian retailers caught running facial recognition on shoppers without proper notice.
Good article. One gap, though. It treats trust as something you build for customers and regulators. In every AI Diagnosis we run, the first people who need to trust your AI are your own employees. Miss that and the rest is theoretical, because there is no AI usage to be responsible about.
Where UK companies stand in August 2026
Short answer: the UK still has no single AI law, and you are still not off the hook. Three regimes apply at once, and they moved at different speeds this year.
1. The UK's own principles-based approach
Five principles (safety, transparency, fairness, accountability, contestability), applied by the regulators you already know: ICO, FCA, CMA, Ofcom. Each reads AI through its own lens. A lender answers to the FCA, a health tech to the MHRA. No single checklist, no single deadline, which sounds comfortable until you realise it means five rulebooks instead of one. Our guide to what the ICO expects on AI governance covers the baseline that applies to everyone.
2. The Data (Use and Access) Act 2025
The domestic change most UK companies underestimated. Since 5 February 2026, solely automated high-impact decisions are permitted on ordinary personal data, but only with four safeguards: notice, the ability to make representations, human intervention, and a right to contest. Special category data stays restricted. From 19 June 2026, every organisation needs a compliant complaints process. We broke the timetable down in our guide to the Data (Use and Access) Act and AI.
3. The EU AI Act, which reaches you anyway
If your AI system or its output reaches people in the EU (a customer, a candidate, a user of your SaaS), you are in scope. No EU entity, no EU servers, does not matter. The test is where your outputs land, not where your company sits. UK teams who lived through GDPR will recognise the pattern.
And the dates moved this summer, in both directions, when Regulation (EU) 2026/1744 (the Digital Omnibus on AI) entered into force on 27 July 2026. We covered exactly what the Digital Omnibus changed. The short version:
| Date | What applies | Status |
|---|---|---|
| 2 February 2025 | Prohibited practices (Article 5), AI literacy duty (Article 4) | In force |
| 2 August 2025 | General-purpose AI model obligations, governance, most penalties | In force |
| 2 August 2026 | Article 50 transparency duties, general application of the Act, AI Office enforcement powers over GPAI providers | Live since last Saturday |
| 2 December 2026 | Machine-readable marking for generative systems already on the market, two new prohibitions | Upcoming |
| 2 December 2027 | Annex III high-risk systems: recruitment, credit scoring, education | Delayed (was 2 August 2026) |
| 2 August 2028 | High-risk AI embedded in Annex I regulated products | Delayed (was 2 August 2027) |
The penalty regime is active alongside it: up to €35M or 7% of global turnover for prohibited practices, €15M or 3% for other breaches. For most UK mid-market firms the ceiling is theoretical. The real cost is switching off a customer-facing service while you fix it.
So the honest summary for a UK mid-market company: three regimes, deadlines that moved twice in one year, and regulators on both sides of the Channel now expecting you to know what AI you run and to say so out loud.
My take: trust is an adoption problem before it is a legal one
The pattern we see in AI Diagnosis missions, again and again. Companies buy the licences: around 91% invest in AI. Then roughly 21% of employees use those tools in their actual work. The 70-point gap in between is where governance quietly decides everything.
Because when there are no rules, two things happen.
Your careful people do nothing. They would rather skip the tool than get in trouble for pasting client data into a chatbot, so the licence sits there, paid and unused.
Your less careful people use whatever they want on personal accounts, which is how you get shadow AI, zero oversight, and exactly the incidents the silence was supposed to prevent.
Both outcomes are worse than the risk. And both are fixed by the same thing HBR is asking for. It is the first structural cause we find when AI adoption fails in a company: it is almost never the tool.
That is why I read their playbook as an adoption playbook wearing a legal costume. An AI inventory tells your teams what is approved. Governance by design tells them what is safe. Visibility tells customers you are not hiding anything. Same three moves, double payoff: one for the regulator, one for your Monday morning usage stats.
“An AI policy does not create trust. It removes the reason to be afraid. That is a different thing, and it is enough to unblock usage.” — Toni Dos Santos, Co-Founder, Spicy Advisory
What the law actually says about training, precisely
Worth being exact here, because a lot of coverage has been wrong since July. Article 4 of the EU AI Act required, from February 2025, that deployers ensure a sufficient level of AI literacy among the people using these systems. The Digital Omnibus rewrote it into a duty to take measures to support the development of that literacy.
An obligation of effort, where there was an obligation of result. It still binds every deployer in scope, including a forty-person company, and national supervision starts on 3 August 2026. You still have to show your work. Our piece on the Article 4 AI literacy obligation sets out the evidence to keep.
What has not changed: training your people stopped being a nice-to-have the moment your chatbot answered a customer in Lyon.
How many AI licences are you paying for that nobody opens?
Measure your licence-to-usage gap →Talk it through in 30 minutesThe AI Diagnosis measures real usage team by team, the workflows eating the most time, and the shadow AI nobody mentions.
What this looks like in practice: four moves
1. Inventory everything, amnesty first
One spreadsheet, one afternoon per department. Every AI tool in use, including the ones IT does not know about.
You will only get honest answers if the exercise is framed as “we want to make this safe to use”, not “we are checking who broke the rules”. Say it explicitly, in writing, before you start. The shadow AI list is the most valuable page of the whole exercise, because it shows you what your teams actually want, and therefore which use cases deserve an official version.
2. Write guidelines a human would read
One page. What is approved, what data never leaves the building, who to ask when unsure.
A 40-page AI policy signed in the onboarding portal protects the lawyers and changes nothing else. The one-pager on the wall changes behaviour. If your policy does not fit on a page, it is not describing rules, it is describing anxiety.
3. Train on real work, not on tools
Sessions built on the team's own use cases: the sales follow-up, the monthly report, the candidate shortlist.
Fold the “why” of the rules into the training and you cover the Article 4 duty on the way, instead of running a separate legal webinar everyone mutes. Start with the executive team: C-suite AI literacy sets the speed of everything downstream.
4. Say it out loud
A responsible AI page on your site, a paragraph in your sales deck, an answer ready for the procurement questionnaire.
UK buyers ask now. In competitive RFPs, the supplier who can explain their AI governance in plain English wins against the one who says “we take this very seriously” and goes quiet. This is the point where the HBR thesis turns into a revenue line rather than a cost line.
Where this bites first for UK companies
| Use case | What applies | When it becomes a problem |
|---|---|---|
| Recruitment screening | Annex III high-risk under the EU Act, UK GDPR, DUAA safeguards | The first rejected candidate who asks why |
| Customer-facing chatbots | Article 50 disclosure, live since 2 August 2026 | Now |
| Credit and affordability decisions | FCA Consumer Duty, DUAA automated-decision safeguards | At the next supervisory review |
| Employee monitoring | ICO employment practices guidance, UK GDPR | On deployment, not in 2027 |
| AI-generated marketing content | Article 50 labelling and deepfake marking | Now |
The part nobody budgets for
A governance document does not create trust. Behaviour does.
AI adoption is a behaviour change problem, and behaviour does not change because a PDF got signed. It changes when someone shows a team, on their own work, what safe and useful looks like. That line item appears in no compliance budget, and it is the one that determines the return on your licences.
Next Thursday, ask five people from five different teams which AI tools they used this week, and whether they would tell their manager. The answers are your real responsible AI status, whatever the policy folder says.
Find out where you actually stand
Most companies know they have AI licences. Far fewer know which teams use them, on what data, with what rules. Our free diagnostic gives you a readiness score and the three highest-value workflows for your firm in under ten minutes. Or bring your situation to a call and we will tell you straight whether you have an adoption problem or a governance one.
Run the free AI diagnostic Book a 30-minute callFrequently Asked Questions
Does the EU AI Act apply to UK companies?
Yes, whenever your AI system or its output reaches people in the EU. A UK SaaS with no EU entity is in scope if EU customers use its AI features, and the Digital Omnibus did not narrow Article 2. The test is market impact, not where you are registered. UK-only businesses fall under the UK's sector-led regime instead, with the ICO, FCA, CMA and Ofcom applying existing law, plus the Data (Use and Access) Act 2025.
What changed on 2 August 2026?
The EU AI Act's transparency duties under Article 50 became enforceable: chatbot disclosure, labelling AI-generated content, marking deepfakes. It is also the date of general application of the Act and the point at which the AI Office gained full enforcement powers over general-purpose AI model providers. The penalty regime, up to €35M or 7% of global turnover for prohibited practices, is active. High-risk system obligations were delayed to 2 December 2027.
Do we legally have to train employees on AI?
If you are in scope of the EU AI Act, yes. Article 4 has applied to deployers since February 2025, and the Digital Omnibus rewrote it in July 2026 into a duty to take measures to support the development of AI literacy: an obligation of effort rather than result, with national supervision starting 3 August 2026. The duty still applies and you still need to evidence what you did. Even outside EU scope, training is the cheapest way to close the gap between AI licences bought and AI actually used.
What does the Data (Use and Access) Act 2025 require for AI decisions?
Since 5 February 2026, solely automated decisions with a significant effect on people are permitted on ordinary personal data, provided four safeguards are in place: informing the person, letting them make representations, offering human intervention, and giving them a route to contest the outcome. Special category data remains restricted. From 19 June 2026, organisations also need a compliant complaints process. A statutory ICO code of practice on AI is mandated but is unlikely before 2027.
Does the delay to December 2027 change anything short term?
Not much, for three reasons. Article 50 transparency duties already apply. UK GDPR, the DUAA and employment law already govern recruitment screening and employee monitoring. And private litigation, like the SiriusXM case in the US, does not wait for regulatory deadlines. A system deployed in 2026 will still be in production in 2027: the delay moves the compliance date, not the date you need to design it properly.
Is responsible AI just compliance with a nicer name?
No. Compliance is the floor. The business case is trust: customers and procurement teams increasingly choose suppliers who can explain their AI practices, and employees only adopt tools they have clear, safe rules for. Companies treating governance as an enablement exercise get adoption; companies treating it as policing get shadow AI.
Where should a UK mid-market company start?
Three steps in order: inventory every AI tool in use, including unofficial ones; publish a one-page usage guideline; then train teams on their real use cases. That sequence covers most of the HBR playbook, the Article 4 AI literacy duty, and the adoption gap at the same time. An external AI diagnosis speeds up step one, because honest answers come more easily to someone who is not your manager.