Menu

AI resource centre

AI hub

Discover the latest AI developments from Mishcon de Reya

Find an expert   Get in touch

Welcome to Mishcon de Reya's AI resource centre, our suite of key resources including insightful articles, upcoming events, and practical handbooks and guides that are tailored to help you understand the implications and opportunities of AI in today's dynamic regulatory environment.

The EU AI Act tracker

The EU AI Act entered into force on 1 August 2024. You can find the latest update on our tracker. 

Find out more

The UK regulatory approach

The UK has adopted a pro-innovation, principles-based framework involving individual regulators interpreting and applying those principles in relation to their specific areas.

Find out more

Useful resources

Our resources include guides, handbooks, and our frequently updated Generative AI Intellectual property cases and policy tracker.

View resources

The EU AI Act tracker

Law enters into force 1 Aug 2024
Ban on AI systems with unacceptable risk. Rules on AI Literacy come into effect 2 Feb 2025
AI Office Codes of Practice required to be ready 2 May 2025
General Purpose AI (GPAI) models must comply¹ 2 Aug 2025
Majority of AI Act rules come into force² 2 Aug 2026
New prohibitions against AI systems³ 2 Dec 2026
Rules for high-risk AI systems in Annex III apply 2 Dec 2027
Rules for high-risk AI embedded in regulated products covered by Annex I apply 2 Aug 2028
1
Subject to grandfathering provisions. Rules on penalties, governance and notification come into force 2 August 2025.
2
and enforcement starts for applicable rules
3
generating non-consensual sexual deepfakes and child sexual abuse material; and transitional deadline for certain transparency obligations

Law enters into force

1 August 2024

The EU AI Act enters into force on 1 August 2024, 20 days after its publication in the Official Journal of the EU. Entering into force is an administrative milestone which does not create any immediate legal obligations for providers or deployers of AI systems. The first legal obligations under the Act will come into effect on 2 February 2025 (6 months from entering into force) – the effect of this will be to ban AI systems with an unacceptable risk.

For more information on who the EU AI Act applies to, see our article here. For assistance with AI system risk categorisation, or to discuss our approach to compliance, download our guide or reach out to a member of the team.

Ban on AI systems with unacceptable risk. Rules on AI Literacy come into effect

2 February 2025

AI Literacy Rules

Providers and deployers of AI systems must now implement measures to ensure that personnel and other persons dealing with the operation and use of AI systems possess adequate AI literacy in order to do so in an informed way. The threshold for AI literacy should take into account the context the AI systems are to be used in and the groups of people on whom the systems are to be used.

Unacceptable Risk Ban

The Act enforces a prohibition on AI systems identified as posing an "unacceptable risk" in accordance with Article 5. The Act prohibits systems which have the consequence of undermining fundamental human rights. AI systems prohibited since 2 February 2025 include those which have the following functions or characteristics:

  • Engage in deception, manipulation, or use subliminal techniques;
  • Use social scoring for public or private purposes;
  • Exploit biometric data in real-time or for categorisation purposes (i.e. to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs or sexual orientation);
  • Scrape internet or CCTV for facial images to build-up or expand databases;
  • Recognise emotions in the workplace and education institutions;
  • Conduct certain types of predictive risk profiling; and
  • Exploit vulnerable persons;

The maximum penalty for breaches in respect of prohibited AI systems is the higher of: (a) EUR 35 million, or (b) up to 7% of worldwide annual turnover.

While the provisions in relation to these prohibitions came into effect on 2 February 2025, the penalties will not apply until 2 August 2025. The EU Commission conducted a consultation on prohibitions and AI system definitions under the Act in late 2024 and early 2025, and published draft Guidelines on 4 February 2025 (which are approved by the EU Commission but not yet adopted).

AI Office Codes of Practice required to be ready

2 May 2025

The final draft of the General-Purpose AI Code of Practice (the Code) was due to be presented for approval on 2 May 2025. The Code, which has undergone an iterative drafting process involving nearly 1000 stakeholders and three previous drafts, is intended to facilitate the proper application of the EU AI Act's rules for general-purpose AI models, including transparency and copyright-related rules, risk assessment, and mitigation measures. The final version was, in the end, presented for approval in July 2025.

Details of the Code

The Code will be an important tool for General-Purpose AI providers to demonstrate their compliance with the AI Act (whilst not providing a presumption of conformity). However, not all GPAI providers are prepared to confirm that they will sign the Code. Given the evolving state of AI, the drafting of the Code aims to strike a balance between clear commitments and the flexibility to adapt as AI technology evolves, but its passage to date has been controversial. Article 56 EU AI Act outlines the key issues addressed in the Code. These include:

  • the means to ensure that information is kept up to date in light of market and technological developments (transparency);
  • the adequate level of detail for the summary about the content used for training (copyright);
  • the identification or the type and nature of the systemic risks, including, where appropriate, their sources (risk assessment); and
  • the measures, procedures and modalities for the assessment and management of the systemic risks identified above (mitigation measures).

We have analysed the final version of the Code here.

General Purpose AI (GPAI) models must comply (subject to grandfathering provisions). Rules on penalties, governance and notification come into force

2 August 2025

From 2 August 2025, a number of provisions in the EU AI Act begin to apply. In particular, providers of General Purpose AI (GPAI) models put on the market in the EU on or after that date must comply with certain rules and obligations. For GPAI models placed on the EU market before 2 August 2025, however, the deadline for compliance is 2 August 2027. Supervision and enforcement by the AI Office for compliance with the rules for GPAI models (including issuing of penalties) will start as of 2 August 2026. However, other penalties can now be imposed by the Office.

Rules on GPAI models

These include:

  • Technical documentation: Providers of GPAI models must prepare detailed technical documentation and other information about their model which must be kept up-to-date and demonstrate compliance with the Act.
  • Copyright compliance: Providers of GPAI models must implement policies for compliance with EU copyright law, in particularly identifying and respecting reservations of rights expressed by rights holders. Summaries of the content used for training GPAI models must be made publicly available.
  • Risk assessment for GPAI models with systemic risk: For GPAI models with systemic risk, providers must perform model evaluation; assess and mitigate possible systemic risks at the EU level; document and report any serious incidents to the AI Office and national authorities; and ensure an adequate level of cybersecurity protection.
  • Appointment of authorised EU representative: Providers of GPAI models established outside of the EU must appoint an 'authorised representative' within the EU before placing the model on the market. This representative shall cooperate with local authorities and is responsible for verifying technical documentation has been drawn up and made available.

Materials have been published to assist GPAI model providers in compliance with their obligations including:

  • A voluntary Code of Practice which will not provide a presumption of conformity but will provide 'increased legal certainty' – discussed in our article here. The Commission has confirmed providers who sign the Code will benefit in effect from a grace period to demonstrate 'good faith' adherence. 
  • Guidelines on the scope of obligations for GPAI model providers – discussed in our article here.
  • Mandatory Template for disclosing summaries of training data – discussed in our article here.
Penalties and enforcement

The AI Act's tiered approach to penalties also applies from 2 August 2025 - non-compliance with the Act's provisions could potentially result in substantial fines, for example up to €35 million or 7% of global annual turnover, whichever is higher in respect of prohibited AI practices.

However, fines against providers of GPAI models (which are a maximum of €15 million or 3% of global annual turnover, whichever is higher) will not start to apply until 2 August 2026.

Other provisions

This date will also see the establishment of the respective national competent authorities (Chapter VII, Article 70), who will be responsible for supervising the application of the Act on a national level.

Majority of AI Act rules come into force and enforcement starts for applicable rules

2 August 2026

Extension of compliance deadlines for Annex III High Risk Systems

2 August 2026 is a key compliance milestone for the EU AI Act. However, compliance deadlines in relation to high-risk systems have been extended under the Digital AI Omnibus, as follows:

  • 2 December 2027:  implementation of provisions relating to standalone high-risk AI systems listed in Annex III of the Act (for example, those used in employment, education, biometrics, critical infrastructure, and migration and border contexts).
  • 2 August 2028: implementation of provisions relating to high-risk AI systems embedded in products covered by EU product-safety regimes listed in Annex I.

Guidelines on the classification of high-risk systems under the Act remain to be finalised. Although the Omnibus delays the high-risk obligations, it does not remove the need to prepare effectively and the additional time provided will likely raise the bar for what regulators consider acceptable preparedness.

Our article on the AI Omnibus discusses the implications of the extensions to the compliance deadlines for high-risk systems and also other changes that will be introduced. The other key compliance deadlines that will apply under the AI Omnibus include:

  • 2 December 2026:
    • New prohibition on AI systems used to generate non-consensual intimate imagery and child sex abuse material
    • Marking and detection obligation on providers of AI systems (re AI-generated content) will apply for AI systems placed on the EU market before 2 August 2026 (see further below re transparency obligations)
Transparency obligations on providers and deployers

On 2 August 2026, key obligations come into effect on providers and deployers of AI systems in relation to transparency requirements (pursuant to Article 50 EU AI Act), as set out below.  Fines for breaches of the transparency obligations can be up to 15 million Euros or 3% of annual worldwide turnover.

Providers of AI systems (including those that have an AI system developed and placed on the EU market under their own name or trade mark)
  • Interactive AI systems: providers of AI systems that interact directly with natural persons, such as chatbots, AI agents and avatars, must ensure that those persons are informed they are interacting with AI from the start of the first interaction in a clear and distinguishable manner, and complying with accessibility requirements.

There are four cumulative criteria that clarify when the obligation will apply:

  • The system is an AI system
  • It is designed for a genuine two-way exchange with people
  • The interaction is direct (i.e., the AI itself communicates with the person, not through a human intermediary)
  • The interaction is with natural persons, such as consumers and also professionals

The obligation will not apply when it is obvious to the person that they are interacting with an AI system (to be assessed by reference to an average person who is reasonably well-informed, circumspect, and observant).

  • Marking and detection of AI-generated content: providers must ensure that outputs from their generative AI systems are marked with effective, reliable, robust and interoperable machine-readable marking to enable outputs to be detected as generated or manipulated by AI systems (subject to the limited extension until 2 December 2026 in respect of AI systems placed on the EU market before 2 August 2026).

There are certain exceptions in terms of the outputs in scope, standard editing functionality, and a narrow exception in relation to certain B2B contexts.  

Deployers of AI systems
  • Emotion recognition and biometric systems: deployers must inform people when they are exposed to emotion recognition and biometric systems.
  • Labelling of deepfakes and AI-generated/manipulated text on matters of public interest: deployers must clearly label deepfakes upon first exposure by a natural person, and AI-generated or manipulated text on matters of public interest without human review or editorial content.

There are three cumulative criteria for assessing whether something is a 'deepfake':

  • Resemblance: high level of similarity between the deepfake and the simulated subject
  • Existing: simulated persons, objects, places, entities or events must resemble someone or something that exists, can plausibly exist or could have plausibly existed
  • False appearance as authentic or truthful: capacity to potentially deceive or mislead a person regarding the authenticity or truthfulness of the content. On this point, deployers can take into account certain factors which may mean that the intended audience doe not expect the content to be authentic or truthful (e.g., background scenes, special effects etc).

Whilst content generated before 2 August 2026 does not need to be labelled retroactively, the Commission has encouraged relevant deployers to do so, where possible.

Where deepfakes form part of evidently artistic, creative, satirical, fictional or analogous works or programmes, the transparency obligation is limited to disclosing the deepfake content in an appropriate manner that doesn't hamper the display or enjoyment of the work.

Materials relating to transparency obligations

The following materials have been published to assist providers and deployers comply with their transparency obligations:

  • Code of Practice on Transparency of AI-generated Content: the Code is a voluntary tool setting out practical steps for providers and deployers to demonstrate compliance with their obligations in relation to detection and marking, and labelling of AI-generated content. Signing the Code will assist providers and deployers to demonstrate compliance with their transparency obligations, and give them the benefit of a streamlined compliance pathway. If a provider or deployer does not sign the Code, however, they will need to demonstrate compliance with their transparency obligations through other means.
  • Guidelines on Transparency Obligations for Providers and Deployers of Certain AI Systems: the Guidelines address the full scope of Article 50, including additionally: Article 50(1) (re interactive AI systems) and Article 50(3) (re emotion recognition and biometric categorisation systems). Providers and deployers subject to these obligations must look to the Guidelines, not the Code, for practical guidance.
Enforcement

Enforcement of the AI Act begins at national and EU-level in relation to general-purpose AI (GPAI) models, prohibitions, transparency rules and AI literacy.

New prohibitions against AI systems generating non-consensual sexual deepfakes and child sexual abuse material; and transitional deadline for certain transparency obligations

2 December 2026

Rules for high-risk AI systems in Annex III apply

2 December 2027

Rules for high-risk AI embedded in regulated products covered by Annex I apply

2 August 2028

EU AI Act updates

On 2 August 2025, providers of certain General Purpose AI models (GPAI models) were made subject to a number of requirements under the EU AI Act. Partner Ashley Williams explains.

On 2 February 2025, provisions in the EU AI Act banning AI systems posing an 'unacceptable risk' came into force.  What does this mean for businesses in the UK? Managing Associate Raj Shah explains.

Useful resources

Generative AI | Intellectual property cases and policy tracker

Explore the latest insights on the various intellectual property cases relating to generative AI, as well as anticipated policy and legislative developments.

View the tracker

Generative AI: Key risk and mitigation steps for businesses Download our guide
Generative AI and IP: Navigating opportunities and risk Download our guide
Founders Handbook Download our guide
AI at the Helm: Boardroom Enquiries for Smart Integration and Strategic Success Download our guide

Virtual pop-ups

If you’re bringing AI technology to market or want to integrate AI and machine learning technologies into your existing business, this is your opportunity to spend 30 minutes discussing anything AI related with our expert team.

Find out more

Mishcon de Reya AI team

Our experience

We specialise in guiding businesses through the technical and strategic implementation of artificial intelligence and machine learning. From proof of concept phase to final deployment, we're here to support businesses  while ensuring compliance by design every step of the way.

Meet our team

Ashley Williams Partner
James Boyle Partner
Nina O'Sullivan Client Engagement Partner, Knowledge Lawyer
Anne Rose Legal Director
Raj Shah Managing Associate
How can we help you?
Help

How can we help you?

Subscribe: I'd like to keep in touch

If your enquiry is urgent please call +44 20 3321 7000

I'm a client

I'm looking for advice

Something else