AI, data, and digital innovation

Four developments affecting AI use, automated decisions and the future use of financial data.

Continue reading

AI regulation is beginning to translate into direct merchant obligations. EU transparency rules now apply to certain customer-facing AI, while UK consumer law applies when businesses use AI agents to interact with customers. Changes to automated decision-making rules create greater flexibility but retain safeguards, while open finance remains a longer-term opportunity rather than an immediate compliance requirement.

Developments covered

EU AI Act: transparency now, high-risk deferred

Learn more

Agentic AI and consumers

Learn more

Open finance roadmap and open banking framework

Learn more

ICO automated decision-making regime

Learn more

EU AI Act: transparency now, high-risk deferred

EU transparency requirements are beginning to apply, while key obligations for high-risk AI systems have been deferred.

The EU AI Act’s transparency requirements have applied since 2 August 2026. Among them, people must generally be informed when they are interacting directly with an AI system, such as a chatbot, unless this is obvious from the circumstances. Separate requirements apply to the marking and labelling of certain AI-generated or manipulated content, including deepfakes. For merchants operating in the EU, the practical issue is customer-facing AI. Businesses should identify where chatbots or other interactive AI systems are deployed and check whether the required disclosure is clear and timely. The rules can also be relevant where merchants publish AI-generated or manipulated content in circumstances covered by Article 50.

Key dates

  • 2 February 2025: prohibited AI practices apply.
  • 29 June 2026: Council gives final approval to the Digital Omnibus on AI.
  • 2 August 2026: Article 50 transparency obligations apply.
  • 2 December 2027: high-risk obligations for standalone Annex III systems, deferred from August 2026.
  • 2 August 2028: high-risk obligations for AI embedded in regulated products under Annex I.

Legal issue/risk

  • Live now for EU-facing merchants. A shopping assistant or support chatbot that does not disclose it is a machine is non-compliant today.
  • Synthetic product imagery, AI-generated video and voice must be labelled. Marketing output is in scope, not just checkout.
  • Penalties for transparency breaches reach €15 million or 3% of global turnover, whichever is higher.
  • Automated creditworthiness assessment is Annex III high-risk. If you offer point-of-sale credit in the EU, that regime reaches you from December 2027.
  • The deferral bought preparation time, not a reprieve. Conformity assessment, logging and human oversight for high-risk systems take longer than the sixteen months gained.

Next steps

  • Audit every customer-facing AI surface on your EU sites for the machine-disclosure requirement now.
  • Label AI-generated marketing and product content.
  • If you offer EU point-of-sale credit, map your decisioning against Annex III before the December 2027 date.

Source

The ICO guidance plans confirming winter 2026 publication.

Agentic AI and consumers

Existing consumer law applies when merchants use AI agents in customer interactions and transactions.

The CMA published guidance on agentic AI and consumer law in March 2026. Its central point is straightforward: UK consumer law applies whether relevant decisions and interactions are carried out by people or AI. Businesses therefore remain responsible for ensuring that customer-facing AI complies with existing consumer protection requirements. For merchants, that matters where AI agents provide product information, make recommendations, present prices or offers, handle complaints or refunds, or take other actions affecting consumers. The CMA recommends appropriate training, monitoring and refinement of systems, supported by human oversight. The enforcement consequences are significant. Under the DMCC regime, the CMA can impose penalties of up to 10% of global annual turnover for breaches of relevant consumer protection law. That is a maximum enforcement penalty, however, not an automatic consequence whenever an AI system makes an error.

Key dates

  • 6 April 2025: CMA direct consumer-enforcement powers in force.
  • 9 March 2026: CMA business guidance on AI agents published.
  • 6 July 2026: FCA Mills Review published, declining to recommend AI-specific regulation.
  • Ongoing: enforcement, with no grace period announced.

Legal issue/risk

  • Autonomy is no defence. A misleading agent output on price, reviews, availability or refunds is your misleading output.
  • Requires meaningful human oversight, a documented escalation route and evidence of both.
  • Exposure runs inbound too: customer agents that misread your prices, data or terms still transact.
  • Direct CMA enforcement, no grace period announced.
  • Push indemnities and audit rights into agent vendor contracts. The regulatory liability stays with you.
  • Periodic sign-off is not oversight. The CMA, the FCA and the ICO have each landed on continuous, evidenced human control.

Next steps

  • Map any AI agent at your checkout, covering pricing, recommendations and refunds, against your existing consumer-law obligations.
  • Keep meaningful human oversight and a clear escalation route for agent errors.
  • Do not treat autonomous agent behaviour as a defence; the liability sits with you.

Source

CMA agentic AI and consumers research and the FCA Mills Review.

ComplyAdvantage insight

Open finance roadmap and open banking framework

Open banking reform is the nearer-term development, while open finance remains a longer-term strategic programme.

The FCA published its Open Finance Roadmap on 14 April 2026. During 2026 it is prioritising high-impact use cases, starting with SME lending and consumer access to mortgages, and plans to invite views through a discussion paper on the first open finance scheme. In 2027 it intends to focus on framework design and coordination, followed by scaling and delivery between 2028 and 2030. For merchants, the rules can be relevant where automated systems make significant decisions about customers, for example in fraud controls, eligibility or access to services. Businesses still need an appropriate lawful basis and safeguards where the statutory provisions apply, including routes for individuals to challenge decisions and seek human intervention. The ICO consulted on updated automated decision-making and profiling guidance in 2026. Final guidance is currently expected in winter 2026.

Key dates

  • 14 April 2026: FCA open finance roadmap published.
  • Q3 2026: open banking interface rules consultation signalled.
  • 2026: FCA plans a discussion paper on the first open finance scheme.
  • Before end 2026: consultation on the long-term open banking framework.
  • 2028 to 2030: scaling and delivery of sustainable open finance schemes.

Legal issue/risk

  • Nothing binds you. What is being set now is who pays when an account-to-account payment fails.
  • The first scheme framework fixes liability allocation, dispute handling and consumer protection between participants.
  • Merchants routing volume onto these rails inherit that model without a seat at the table.
  • Open finance sits behind open banking, so nearer slippage moves everything later.
  • Live schemes are 2029 to 2030. This half is representation, not build.

Next steps

  • Track the open banking framework consultation as the nearer-term item that affects the A2A rails you use.
  • Watch the Q4 2026 discussion paper for the first scheme's scope.

Source

FCA open finance roadmap.

ICO automated decision-making regime

Significant solely automated decisions are now subject to new safeguards, including rights to human intervention and challenge.

The Data (Use and Access) Act 2025 (DUAA) rewrote Article 22 of the UK GDPR from 5 February 2026, replacing the previous restrictions on solely automated significant decisions involving non-special-category data with a more permissive, safeguard-led regime. A decision is solely automated where there is no meaningful human involvement, and significant where it produces a legal or similarly significant effect. Where these provisions apply, individuals must be informed about the decision, able to make representations, obtain human intervention and contest the outcome. For merchants, this can reach automated fraud blocks, credit or eligibility decisions and other significant decisions within customer and payment journeys. Special-category data remains subject to tighter restrictions. The ICO consulted on updated automated decision-making and profiling guidance until 29 May 2026, with final guidance expected in winter 2026. The detail of how the revised regime should be applied in practice is therefore still developing.

Key dates

  • 5 February 2026: DUAA automated decision-making reforms in force (Articles 22A to 22D).
  • Winter 2026: final ADM guidance expected.

Legal issue/risk

  • Binds you directly. Fraud scoring, credit eligibility, and dynamic risk decisions are in scope where solely automated and significant.
  • Requires transparency, a risk assessment, records, and a human review route with real authority.
  • Rubber-stamp or after-the-fact review leaves the decision solely automated and the safeguards unmet. Most common failure mode.
  • Special category data stays tightly restricted, outside the relaxed regime.
  • Inventory now. Hold design changes until final guidance in winter 2026.

Next steps

  • Inventory the solely-automated decisions in your payment flows and flag those with a significant customer effect.
  • Check that human review is genuinely meaningful and made before the decision takes effect, not a token sign-off.
  • Wait for the final guidance in winter 2026 before locking design.

Source

The ICO guidance plans confirming winter 2026 publication.

Crypto, stablecoins and CBDCs

Previous page

Consumer protection, conduct and governance

Next page