Digital Marketing

AI Laws Are Changing Fast: What Every Business Needs to Know in 2026

28 May 2026  ·  Wayne Bromiley  ·  11 min read

Businesses have spent the last two years adopting AI as fast as possible. Now the law is catching up — and it is moving faster than most people realise. In May 2026 alone, the EU and European Parliament reached a landmark agreement to reshape AI rules, a US jury ordered Meta to pay $375 million for algorithmic harm to children, and deepfake labelling requirements moved from draft to near-binding across three major jurisdictions. If you are using AI in your business — for content, marketing, customer service, or anything else — the legal landscape you are operating in changed significantly in the last six months.

The $375 Million Verdict That Every Business Using AI Should Know About

In March 2026, a New Mexico jury ordered Meta to pay $375 million after finding the company misled users about the safety of its platforms for children. The jury concluded that Meta failed to adequately protect young users from harmful content and recommendation systems while publicly presenting its platforms as safe for teenagers. Weeks later, a California jury found Meta and YouTube liable for harm caused by addictive platform design — concluding that the companies knowingly developed features encouraging excessive use, failed to warn users of associated risks, and contributed to serious psychological harm including anxiety, body dysmorphia, and suicidal thoughts.

These cases concern social media platforms and recommendation algorithms, not AI products per se. But the legal principles they establish have direct implications for anyone deploying AI systems that influence user behaviour, personalise content, or make automated decisions. The question they raise — can a company be held liable for the way its algorithm affects users, even if no individual piece of content is illegal? — is now being actively discussed by European legal practitioners, and the answer emerging from multiple jurisdictions is yes.

Under the EU’s updated Product Liability Directive, which came into force in October 2024, defectiveness in a product — including a digital product or AI system — can now be presumed where a defendant fails to comply with a court-ordered disclosure obligation. Courts can also ease the burden of proof where technical complexity makes establishing causation difficult. This is a significant shift. It means that the practical difficulty of proving that an algorithm caused harm is no longer the protection for companies that it once was.

What the EU Just Changed in May 2026

On 7 May 2026, the Council of the European Union and the European Parliament reached a provisional agreement under the “Omnibus VII” package — a sweeping simplification and amendment of the EU’s digital regulatory framework. For businesses using or developing AI, several changes are immediately relevant.

New Prohibited Practice: Non-Consensual Intimate Content

The agreement introduces a new category of prohibited AI practice: AI systems that generate non-consensual intimate images or child sexual abuse material. This was already illegal under national laws across EU member states, but the explicit prohibition at AI Act level means it is now a regulated AI risk category — with enforcement through the AI Act’s oversight mechanisms, not just national criminal law. For platforms and tools that include image generation capabilities, this creates a new compliance obligation.

High-Risk AI Registration Reinstated

The agreement reinstates the obligation for providers to register certain high-risk AI systems in the EU database — including where providers believe their systems should not qualify as high-risk. This matters because it removes a loophole: companies can no longer simply self-assess out of registration obligations. If your system could arguably qualify as high-risk under the AI Act’s Annex III categories (which include AI used in employment, education, essential services, and law enforcement), you need to register.

The Key Deadlines: 2027 and 2028

Implementation timelines have been extended — but not indefinitely. Obligations for autonomous high-risk AI systems now apply from 2 December 2027. For high-risk AI systems integrated into physical products, the deadline is 2 August 2028. These deadlines were pushed back from August 2026, giving businesses more runway — but also creating a risk of complacency. Two years sounds like a long time until it arrives.

GDPR Scope Is Being Narrowed

The Omnibus package is also likely to narrow the definition of what qualifies as “personal data” under GDPR, and may merge or repeal several digital regulations including the Data Governance Act. For AI developers, a narrower GDPR definition could ease data processing constraints — but legal practitioners are warning it may also make it easier to train powerful generative models on Europeans’ data, potentially increasing the volume and quality of AI-generated synthetic content. The practical consequence: more deepfakes, better deepfakes, less friction in creating them.

Deepfakes Are Now a Compliance Issue — Not Just an Ethical One

If you produce video content, use AI tools to generate images, or work in marketing where synthetic media is becoming standard practice, the EU’s incoming Code of Practice on AI-Generated Content directly affects how you must operate.

Expected to be finalised in mid-2026 and designed to operate alongside the AI Act’s transparency obligations (which come into force August 2026), the Code establishes specific disclosure requirements based on content type:

  • Real-time video: A persistent, non-intrusive icon plus a disclaimer at the beginning of the content
  • Non-real-time video: Opening disclaimer, persistent icon throughout, and end credits disclosure
  • Images: A clearly visible, fixed icon
  • Audio-only content: Audible disclaimers, repeated for longer formats, with visual cues where a screen is available

The Code draws a critical distinction between providers (companies that build and market AI systems — developers, AI platform vendors) and deployers (businesses and individuals who use AI systems in professional activities). If you are a marketing agency using an AI image generation tool in client campaigns, you are a deployer. You are responsible for disclosure — not just the tool vendor.

Importantly, purely personal use is excluded: private individuals generating AI content for personal use, even when posting it online, are not subject to the labelling requirements. Responsibility in that case lies with the platform. But any professional use — which includes freelancers, consultants, and sole traders — falls within scope.

Content that is clearly artistic, satirical, or fictional requires only minimal and non-intrusive disclosure. But the burden of demonstrating that characterisation is on the person creating and publishing it — not the regulator.

The US Picture: Every State, Federal Law, and Converging Standards

European businesses operating in or marketing to the US face an additional layer. In 2025, lawmakers in every US state introduced some form of deepfake legislation. Most focus on two areas: sexual deepfake content (non-consensual intimate imagery and child abuse material) and political deepfake advertising (requiring disclaimers on digitally manipulated campaign content). Several of these state laws have already faced constitutional challenges on free speech grounds — California had two deepfake laws struck down by federal judges — but the direction of travel is clear: more regulation, broader scope, and faster enforcement.

At federal level, the Take It Down Act now requires online platforms to remove AI-generated or AI-modified non-consensual sexual content. Looking ahead to 2026, US legislators are expected to expand their focus beyond individual creators and distributors to include the infrastructure that enables deepfake production: generative AI platforms, payment processors, hosting services, and cloud providers. If your business sits anywhere in that supply chain, this is a trend worth monitoring closely.

The convergence between US and EU approaches is notable. Both are moving toward watermarking and provenance standards — the EU via its Code of Practice on AI-Generated Content, the US potentially through frameworks developed by the National Institute of Standards and Technology (NIST) and the Coalition for Content Provenance and Authenticity (C2PA). The practical implication for global businesses: compliance with one jurisdiction’s standards is increasingly likely to support compliance with the other.

The AI Law Timeline: What Is Happening and When

Here is the timeline that matters for businesses operating now:

  • August 2026: EU AI Act transparency obligations come into force — including requirements for providers to ensure machine-readable marking and detectability of AI-generated content
  • Mid-2026: EU Code of Practice on AI-Generated Content expected to be finalised — disclosure standards for deepfakes and synthetic media
  • June 2026: EU AI Act’s FAQ rich result reporting ends — data on AI-influenced search features becomes unavailable (separate but related regulatory shift)
  • December 2027: Obligations for autonomous high-risk AI systems under the AI Act apply
  • August 2028: Obligations for high-risk AI integrated into physical products apply
  • Ongoing 2026: US state-level deepfake legislation expanding, with federal framework expected to broaden scope to include AI platforms and hosting services

What Businesses Using AI Need to Do Right Now

The gap between “we use AI tools” and “we are compliant with AI regulation” is closing faster than most business owners appreciate. Here is what the current regulatory trajectory means in practical terms:

1. Audit where AI appears in your outputs

Do you use AI to generate images for social media, blog posts, or advertising? Do you use AI voice generation, video editing, or synthetic avatars? Are any of your customer-facing communications drafted, personalised, or selected by AI systems? Map it out. The August 2026 transparency obligations apply to all of these — and the Code of Practice disclosure requirements mean you need to know exactly where AI-generated content appears in your professional output before regulators ask.

2. Understand whether you are a provider or a deployer

Under EU AI Act definitions, if you use an AI tool built and marketed by someone else, you are a deployer. The disclosure obligation for synthetic content rests with you, not just the tool vendor. This is not a technicality — it is the primary compliance exposure for most businesses, agencies, and freelance practitioners. You cannot contract your way out of it by pointing to the AI platform’s terms of service.

3. Start thinking about liability in your AI use cases

The Meta and YouTube verdicts are not directly precedent in UK or EU courts, but the legal trajectory they represent is. If your business uses an AI system that makes recommendations, personalises content, or influences user behaviour, the question of whether you would be able to demonstrate the system operated as intended — and did not cause foreseeable harm — is worth putting to your legal team now, before a claim arrives. The EU’s updated Product Liability Directive makes algorithmic causation easier for claimants to establish, not harder.

4. Watch the algorithmic discrimination front

This is the area receiving least mainstream attention but likely to generate significant litigation in Europe over the next three years. AI systems used in recruitment, credit scoring, pricing, or customer segmentation carry real risk of reproducing or amplifying existing biases. The AI Act’s provisions on high-risk AI specifically target these use cases. If your business uses AI for any decision-making that affects people’s access to services or opportunities, this needs to be on your compliance radar now.

5. Do not wait for 2027 to start preparing

The December 2027 deadline for autonomous high-risk AI obligations sounds distant. It is not. Compliance with the AI Act for high-risk systems requires documentation, testing, human oversight mechanisms, and often structural changes to how those systems operate. Organisations that wait until 2027 to begin that work will find themselves in the same position as those that waited until the final weeks before GDPR came into force in 2018 — scrambling, expensive remediation, and material non-compliance risk. The businesses that start now will be better positioned, less exposed, and ahead of competitors who are still waiting to be told what to do.

The Broader Picture

Two trends are running in parallel and accelerating toward each other: the rapid adoption of AI across every business function, and the accelerating development of legal frameworks to govern that adoption. The collision was always inevitable. What has changed in 2026 is the speed. The $375 million verdict, the EU Omnibus agreement, the deepfake labelling code, the Take It Down Act — these are not distant signals. They are the early cases and early rules of a legal landscape that will look substantially different by 2028.

The businesses that treat AI compliance as a legal and operational priority now — not a future problem — will be the ones best positioned when the full force of these frameworks arrives. The question is not whether regulation is coming. It is whether you are ready for it.

If you want to understand how the emerging AI regulatory landscape affects your specific digital marketing and content strategy, get in touch. Getting ahead of the compliance curve is significantly cheaper than responding to it after the fact.