decrypted · 2 august 2026 · vulnerabilities and patching · uk policy and law · ai and llm security

The AI Act deadline nobody delayed, and why UK firms are in scope

Today, 2 August 2026, is a deadline that has had less attention than the one everyone thought was coming. The EU AI Act's high-risk conformity rules, the ones requiring audits and technical files, were pushed back in May to December 2027 and August 2028. What has not moved is Article 50: from today, anyone whose chatbot, voice agent or AI-generated content reaches a user in the EU has to tell them they are dealing with a machine. That includes UK companies with no EU office and no EU staff, because the Act follows where the output lands, not where the company is registered. Two smaller stories from the past few days make the same point from a different angle: telling users what a system is doing, and building a system that can't quietly leak, are the same discipline wearing different clothes.

What actually lands today

Article 50 covers four situations, and none of them wait for a high-risk classification. Providers of chatbots and voice agents must make it obvious, before or at the start of an exchange, that the user is talking to AI, unless that is already obvious from context. Providers of generative tools must mark synthetic audio, image, video and text with machine-readable signals so the output can be detected as artificial. Deployers running emotion-recognition or biometric categorisation on people have to tell them it is happening. And anyone publishing an AI-generated deepfake or AI-written text on a matter of public interest, politics, health, the courts, must label it, unless a human has actually edited it and taken editorial responsibility. Fines run to €15 million or 3% of global turnover, whichever is greater, enforced by national market surveillance bodies rather than Brussels directly.

The extraterritorial catch

The Act reaches UK organisations the way GDPR did: through where the output lands, not where the company is registered. A UK software firm with a support chatbot used by customers in Dublin or Berlin is in scope. So is a UK agency generating AI video for a European client. Lawyers have been telling firms to map every AI touchpoint that reaches an EU user and document it, because "we did not think of it as regulated" will not satisfy a market surveillance authority.

The design lesson

Article 50 is a Secure by Design question wearing legal language: does your system know, structurally, whether it is talking to a human, and can it prove it said so? Firms that treated AI disclosure as a banner bolted onto one website will find it breaks the moment the same chatbot gets embedded in a partner's site, a messaging app or a phone line, none of which inherit a webpage's small print. The fix is the one that works for every disclosure requirement: put the flag in the system itself, at the point a session starts, not in a policy document that assumes a single channel.

Also this week

Analog Devices, the US chipmaker whose analogue and mixed-signal parts sit inside a large share of the world's cars, medical devices and industrial controllers, disclosed that unauthorised access to its systems in June led to file exfiltration. The extortion group ExfilSquad, the same one behind the Department for Education breach we covered days ago, listed Analog Devices on its leak site claiming to hold 570,000 customer records, an unverified claim, then delisted the company, a pattern typical of ransom negotiation rather than resolution. No encryption was involved and Analog Devices says operations were unaffected. That is the point: groups that only steal data do not trip the alarms built to catch ransomware, which is why the defence has to be data-centric, segmentation and egress monitoring, rather than backup-centric.

Check Point confirmed in the final days of July that an authentication bypass in its SmartConsole management interface, CVE-2026-16232, was being actively exploited. The flaw lets an unauthenticated attacker obtain a login token and log in with full administrator rights, but only where a Security Management Server has been left reachable from the internet with no restriction on which clients can connect. Check Point says a small number of customers were affected and a patch is available. It is the third internet-facing management console to make this newsletter in two weeks. The lesson does not change with repetition: a management plane with no business being reachable from the open internet eventually gets reached.

Sources

If you want a second pair of eyes on where your AI systems and vendors actually stand, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.