Building AI Products & WorkflowsGovernance, adoption and scaling · Lesson 17 of 18

AI regulation for product teams (2026 update)

Article · 14 min · 9 min lecture

Video lecture

AI regulation for product teams (2026 update)

15 chapters · about 9 min · full transcript

Coming soon

Chapter 1 of 15

AI regulation for product teams

  • From principles to obligations
  • The landscape, Sept 2026
  • A screen for every feature

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

What product teams need to know (and what to ask counsel)

AI regulation is moving from principles to enforceable obligations, at different speeds in different places. Product teams do not need to become lawyers, but they must know enough to ask the right questions early, build the right evidence, and avoid designs that will need expensive rework. This lesson summarises the landscape as of September 2026 for the regions our learners work in. It is not legal advice: laws change, and details depend on your role, sector and use case.

The EU AI Act: where things stand

The EU AI Act applies a risk-based approach and reaches providers and deployers outside the EU when AI systems or their outputs are used in the EU. Key milestones:

ObligationStatus (as of Sept 2026)
Prohibited practices (for example manipulative techniques causing harm, social scoring, certain biometric uses)Applying since 2 February 2025; the 2026 amendments added a prohibition on AI systems that generate non-consensual intimate imagery and child sexual abuse material
General-purpose AI model obligations (documentation, copyright policy, and more for systemic-risk models)Applying since 2 August 2025
Transparency obligations (Article 50): tell people they are interacting with AI, mark synthetic content in a machine-readable way, disclose deepfakes and certain AI-generated textApplying since 2 August 2026; for generative systems already on the market before that date, the machine-readable marking requirement has a transition to 2 December 2026
High-risk systems in Annex III areas (for example employment, education, access to essential services, credit scoring)Postponed by the Digital Omnibus on AI (in force since late July 2026) to 2 December 2027
High-risk AI embedded in regulated products (Annex I)Postponed to 2 August 2028

Implications for product teams: if your feature talks to people, generates media or text published to inform the public, or is used in hiring, education, credit or essential services, you likely have obligations now or soon. Build disclosure, logging, human oversight, data governance and documentation into designs now; retrofitting them is harder.

The UK

The UK has no single AI act. Existing regulators (for example the ICO for data protection, the FCA for financial services, the CMA for competition and consumer law, the ASA for advertising) apply existing law to AI under cross-sector principles such as safety, transparency, fairness, accountability and contestability. UK GDPR applies to personal data processing; the Data (Use and Access) Act 2025 revised the rules on automated decision-making, and the ICO publishes guidance on AI and data protection. Advertising rules apply to AI-generated ads and influencer content.

The United States

There is no comprehensive federal AI law. Federal agencies enforce existing laws (for example the FTC on deceptive claims about AI and unfair practices). States are active: for example, Colorado replaced its 2024 AI Act in 2026 with a narrower automated decision-making transparency law due to take effect in January 2027, and other states regulate specific uses such as AI in hiring, chatbot disclosure or deepfakes. Map obligations by state and use case with counsel.

The Gulf and Pakistan

  • UAE: the federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and free-zone regimes (DIFC and ADGM have their own data protection laws; DIFC's rules include specific provisions for autonomous and semi-autonomous systems). National AI strategy and ethics guidelines set expectations for responsible use.
  • Saudi Arabia: the Personal Data Protection Law (enforced since September 2024) with its implementing regulations, and SDAIA's AI Ethics Principles and guidance on generative AI.
  • Pakistan: the federal cabinet approved a National AI Policy in July 2025 (skills, ecosystem, regulatory sandboxes and responsible use). Comprehensive personal data protection legislation has been in draft for several years; check its current status before relying on it.

Turning regulation into product requirements

Regulatory themeProduct requirement
TransparencyDisclose AI interactions; label AI-generated media and, where required, mark it machine-readably; explain what data the feature uses
Human oversightReview and override mechanisms; escalation to people; no fully automated significant decisions without safeguards
Data protectionLawful basis, minimisation, retention, rights handling, DPIAs for high-risk processing, cross-border transfer checks
Accuracy and robustnessEvaluation evidence, monitoring, incident handling
Documentation and recordsAI register, data flow maps, evaluation reports, logs retained appropriately
FairnessTests across user groups for features that affect people's opportunities
Advertising and consumer lawNo misleading AI claims ("100% accurate"); disclose sponsored and AI-generated ad content per platform and regulator rules

Hands-on: a regulatory applicability screen

Run this screen for each AI feature at the idea stage and before launch; bring the output to counsel.

REGULATORY SCREEN — <feature>                                   Date: ____
Markets where the feature or its outputs are used: [ ] EU  [ ] UK  [ ] US (states: __)  [ ] UAE  [ ] KSA  [ ] PK  [ ] other
Our role: [ ] we build the AI system (provider)  [ ] we use a third-party AI system (deployer)  [ ] both
1. Does it interact directly with people who may not realise it is AI?            -> disclosure design
2. Does it generate images, audio, video or published text?                       -> labelling / marking
3. Is it used in employment, education, credit, insurance, housing, health,
   essential services, law enforcement or migration?                              -> possible high-risk regime
4. Does it make or materially influence decisions with legal or similar effects
   on individuals?                                                                  -> automated decision rules
5. What personal data (and special categories) does it process? Where?          -> DPIA, transfers
6. Does it use biometric data or emotion recognition?                            -> check prohibitions/limits
7. Is any output used in advertising or influencer content?                      -> ad disclosure rules
8. Sector regulators involved (finance, health, telecoms, education)?            -> sector rules
Evidence we already have: register entry / data flow / eval report / DPIA / oversight design
Open questions for counsel: ______________________________________________

And a disclosure template to adapt (keep it short and honest):

You're chatting with [Brand]'s AI assistant. It can answer questions about [scope] and may make
mistakes, so please check important details. A member of our team can take over at any time:
[link/button]. We process your messages to provide this service as described in our privacy notice.

Go deeper

Go deeper: AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001 covers the regulatory frameworks and management systems in depth.

Key takeaways

  • The EU AI Act phases in: prohibitions since Feb 2025, GPAI duties since Aug 2025, transparency from Aug 2026, high-risk deadlines postponed to Dec 2027 and Aug 2028.
  • The UK regulates AI through existing regulators and laws; the US through agencies and a growing patchwork of state laws.
  • UAE, KSA and Pakistan combine data protection laws, AI ethics guidance and national AI policies; check current status with counsel.
  • Translate regulation into product requirements early: disclosure, oversight, data protection, evidence, documentation and fairness.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. A chatbot for EU customers could be mistaken for a human. Which obligation is most directly relevant from August 2026?
  2. What did the 2026 Digital Omnibus on AI do to Annex III high-risk obligations?
  3. Which is the best way for a product team to handle regulatory uncertainty?

Put it into practice

Run the regulatory screen on one AI feature, list the product requirements it implies, and write three specific questions for your legal or compliance adviser.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.