LEGAL
WHAT THE EU AI ACT MEANS FOR UK CLINICS
Ellen Cummings speaks to AI strategist Marnie Willis and dives into how the new EU AI rules could affect some UK aesthetic businesses
The new requirements under the European Union’s AI Act are putting greater emphasis on transparency around how artificial intelligence is used. Although the legislation applies in the EU, some UK businesses can fall within its territorial scope, while its requirements are also likely to influence international software platforms used by British clinics and salons.
Meanwhile, the UK is developing its own approach to AI governance, with existing regulators including the Information Commissioner’s Office (ICO) and Advertising Standards Authority (ASA) already addressing areas such as AI, personal data, automated decision-making and advertising.
WHAT IS THE EU AI ACT?
The EU AI Act is a wide-ranging regulatory framework governing the development and use of artificial intelligence within the European Union.
AI literacy requirements began applying in February 2025, with Article 50 transparency obligations taking effect on August 2, 2026.
These transparency requirements cover particular uses of AI rather than every occasion on which a business uses an AI tool.
For example, providers of AI systems designed to interact directly with people are required to ensure users are informed that they are interacting with AI unless this is already obvious.
Using AI to assist with everyday marketing does not automatically mean content requires an “AI-generated” label; requirements depend on the type of content and how AI has been used.
DOES THE EU AI ACT APPLY TO THE UK?
The Act has some extraterritorial reach. Its scope includes certain providers and deployers established outside the EU where the output produced by an AI system is intended to be used within the Union.
Marnie Wills, AI strategist and trainer at Business With AI Strategist, says this is one reason UK businesses should understand the legislation rather than assuming it stops at the border.
“The Act reaches beyond the EU’s borders, so a UK business can be in scope even without an EU office or subsidiary,” she explains.
Exactly when a UK business falls within the Act’s territorial scope will depend on the circumstances, so businesses with European operations, partners, customers or AI deployments should take specific legal advice where necessary.
However, direct legal exposure is only part of the picture. Wills expects the legislation to have an indirect impact on UK businesses.
“Regardless of a company’s individual exposure, most AI vendors – booking platforms, chatbot providers, marketing tools – sell into the EU as a matter of course,” she says.
“They build transparency, disclosure and data-handling features to EU AI Act standards by default, because building two versions of a product costs more than building one to the highest standard.”
For UK clinics, that could mean seeing new AI disclosures, settings, data controls or governance features appearing within existing software.
AUDITING AI SYSTEMS
One of the challenges for businesses is that AI is no longer confined to standalone tools such as ChatGPT. AI functionality can increasingly be embedded within software businesses already use.
Wills recommends starting with an audit of existing systems.
“Start with an honest audit – not of ‘have I bought AI’ but of ‘what has AI been switched on inside’,” she says.
“List every piece of software the business uses and check the settings and update notes for anything described as ‘AI’, ‘smart’, ‘automated’ or ‘assistant’.”
An audit can also identify cases of shadow AI, where employees use tools independently without formal approval from the business.
“The biggest mistake is adopting tools because they’re available, not because there’s a clear use case,” says Wills.
“Close behind is shadow AI, where staff use consumer tools the business never approved or knew about, often with patient data going in without anyone realising.”
DO CLINICS NEED TO TELL PATIENTS WHEN THEY ARE TALKING TO AI?
Transparency becomes particularly important where AI interacts directly with patients. Under Article 50 of the EU AI Act, providers of qualifying AI systems designed for direct interaction with people must ensure that users are informed that they are interacting with AI unless this is obvious from the context.
The European Commission says this information should be provided from the beginning of the first interaction in a clear and distinguishable way.
For a clinic using a third-party chatbot or AI receptionist, the precise legal responsibility may sit differently depending on whether the business is the provider or deployer of the system. Nevertheless, owners should check that customer-facing technology provides appropriate disclosure rather than assuming the software supplier has dealt with it.
Wills recommends making the wording straightforward.
“Something as simple as ‘You’re chatting with our AI assistant’ at the very start of a conversation does the job,” she says.
DO AI-GENERATED SOCIAL POSTS AND MARKETING NEED TO BE LABELLED?
This is one area where businesses should avoid overinterpreting the new rules.
Using AI to brainstorm ideas, edit copy or improve wording does not automatically mean content requires an AI label. Wills suggests distinguishing between AI-assisted work and content substantially generated by AI.
There are additional requirements under the EU Act for certain synthetic content and deepfakes, while the rules around AI-generated text focus specifically on content published to inform the public on matters of public interest.
For UK businesses, meanwhile, there is currently no blanket ASA requirement to label every advert created using AI.
However, existing advertising standards still apply regardless of how an advert was produced. That is especially important in aesthetics, where visual results can directly influence purchasing decisions.
The ASA has warned that AI-generated imagery showing effects a cosmetic product cannot genuinely achieve could be misleading. Existing advertising rules still apply regardless of how content is produced.
For aesthetics businesses, this means an AI disclosure cannot make an otherwise misleading claim acceptable.
WHAT ABOUT PATIENT DATA AND AI?
Existing UK data protection rules therefore remain relevant when AI is introduced into processes that handle patient data.
The ICO already provides guidance on applying UK GDPR principles to AI and automated decision-making.
Wills recommends asking suppliers key questions around data use and storage, model training and opt-outs, data retention, legal responsibility, AI accuracy and bias, and data processing agreements before allowing AI features to process business or patient information.
Staff using public generative AI platforms should also understand what information they are permitted to enter.
“Personal data needs extra care and, generally, shouldn’t be pasted into a public tool at all,” says Wills.
“The dividing line I’d give a clinic owner is: does this AI output reach a real person – patient or candidate – without a human checking it first? If yes, that’s where the oversight needs to sit.”
UK regulators are also paying attention to automated recruitment. The ICO has been examining AI and automated decision-making in hiring and consulted on updated guidance in 2026.
For an aesthetic business, using generative AI simply to improve the wording of a job advert is therefore very different from allowing software to autonomously score or reject applicants.
AI LITERACY
Staff AI training is becoming a business responsibility
Another part of the EU AI Act that is easy to overlook is AI literacy.
Requirements relating to AI literacy began applying in February 2025. The European Commission says providers and deployers should take measures to support an appropriate level of AI literacy among staff and others using AI systems on their behalf, taking their knowledge, experience and circumstances into account.
This does not mean every member of staff needs to become an AI specialist.
Staff should understand which tools they are permitted to use, what information they should never upload, when an AI output needs checking and how to report problems, she adds.
“A 30–60 minute session covering exactly this, repeated when tools change, does more good than a generic ‘AI awareness’ course.”
IS THE UK LIKELY TO FOLLOW?
The UK is moving towards greater AI governance, but it is not currently following the EU by introducing an identical AI Act.
Instead, the Government has continued to pursue a more regulator-led and pro-innovation approach.
In October 2025, the Government announced a blueprint for AI regulation, where products are tested within controlled regulatory environments. Wills expects that pattern to continue. “Rather than one law with one risk-tiering system, the UK is stitching AI expectations into what already exists,” she says.
“It’s less tidy on paper than the EU’s model, but it means businesses are already, in effect, under AI-relevant scrutiny today through regulators they already deal with – they just haven’t necessarily clocked it as ‘AI regulation’ yet.”
The ICO is also developing a statutory code of practice covering AI and automated decision-making, intended to provide organisations with practical guidance on areas including transparency, explainability and people’s rights.
As Wills puts it, “None of this requires waiting for UK law to catch up – it’s what ‘wellrun’ already looks like.”
TOP TIPS
Wills recommends four immediate actions:
1. Map where AI is being used
List software and tools across booking, customer service, marketing, HR and operations, and establish which include AI-powered functions.
2. Question your suppliers
Find out what data AI features access, how that information is processed, whether it is used for model training, what controls are available and where responsibility sits when something goes wrong.
3. Introduce a simple AI policy
“It doesn’t need to be – and shouldn’t be – a 40-page compliance manual,” says Wills. She recommends covering approved tools, prohibited data, human review, disclosure wording, responsibility for approving tools and a date for reviewing the policy.
4. Give one person responsibility for AI
This is Wills’s biggest recommendation for SMEs.
“Name one person who owns it. Not a policy, not a tool, not a training course first – a person,” she says. “Almost every governance gap I see in small businesses traces back to the same root cause: nobody is actually accountable for AI, so nothing gets reviewed, questioned or fixed.”