I want to be honest with you about something. I did not build Human Heartbeat AI because a regulator told me to.
I built it because I believed — and still believe — that AI without human accountability is AI without a foundation. That belief came before any legislation. It came from watching how decisions actually get made inside businesses under pressure. It came from knowing that the moment you remove the human from the loop, you do not just lose oversight. You lose the thing that makes a decision defensible.
But the legislation is now here. And most UK business owners have not been told the full picture. I have spent the last several months reading the regulatory landscape carefully. Not because I enjoy compliance frameworks — I do not — but because I owe it to the businesses I work with to understand what is actually coming and what is already in force.
What I found surprised me. Not the direction of travel. That was always predictable. What surprised me was how much is already live, and how little of it has landed in the conversations most UK founders are having. There is a gap. A significant one. Between what most UK SME owners believe about AI regulation and what is actually in force right now. And that gap has consequences.
So let me be specific. Here is what is already law — not coming, not proposed, already in force:
Already in force
| Obligation | In force since | Who it affects |
|---|---|---|
| Prohibited AI practices (social scoring; subliminal manipulation; real-time biometric surveillance in public) | 2 February 2025 | Any organisation deploying AI in or into the EU |
| AI literacy obligation — employers must ensure staff using AI have adequate AI literacy | 2 February 2025 | Any organisation with employees using AI tools |
| GPAI model transparency and copyright compliance rules | 2 August 2025 | Developers and deployers of general-purpose AI models |
| UK data protection law applied to AI and automated decisions | Ongoing — enforced now | Any UK business using AI that processes personal data |
| UK Equality Act obligations applied to AI-assisted decisions | Ongoing — enforced now | Any UK employer using AI in hiring or performance management |
And here is what is on its way:
Coming next
| Obligation | Deadline | Who it affects |
|---|---|---|
| High-risk AI systems (standalone) — full compliance required | December 2027 | Businesses deploying AI in recruitment; credit; education; critical infrastructure |
| High-risk AI embedded in regulated products | August 2028 | Manufacturers and deployers in healthcare; automotive; industrial sectors |
| UK ICO statutory Code of Practice on AI and automated decision-making | Summer/Autumn 2026 | All UK businesses using AI that touches personal data or automated decisions |
The August 2026 deadline for high-risk systems was extended by a political agreement in May 2026. That extension is real. But the obligations in the first table were not extended. They are live right now.
I am not going to list every provision and penalty tier here. /articles/what-governed-ai-actually-means What I want to say to you, as a founder to a founder, is simpler than that.
The businesses that are going to navigate this period well are not the ones with the most sophisticated AI systems. They are the ones where someone — a specific, named person — has sat down and asked the questions that governance requires. What are we actually using? What decisions is it influencing? Who is accountable if it goes wrong?
Most businesses have not asked those questions yet. Not because they are reckless. Because they are busy. Because AI tools arrived quickly and the governance conversation arrived slowly. Because no one sent a letter. That is exactly the environment in which quiet harm happens. Not through bad intent. Through a lack of structure.
I built Human Heartbeat AI around a simple principle: diagnostic before operational. We do not recommend AI implementation until we understand the business case, the risk, and the human decision points. Every AI Worker we deploy operates within a framework that preserves human authority over the final judgement. That is not a feature. That is the architecture.
And it turns out, it is also increasingly what the law requires. The OSCAR Diagnostic exists because I believe every business deserves an honest picture before any commitment is made. Not a sales pitch. Not a roadmap built on assumptions. An honest picture of where AI genuinely helps, where it creates exposure, and what must be governed before anything else is touched.

If you are a UK business owner using AI tools — in any form, for any purpose — the time to build that picture is now. Not because a deadline is imminent. Because the structure you build now is the structure that protects you when the enforcement environment tightens, as it will. AI can surface signals, patterns, options, and pressure points. But the final judgement must remain human. That is not a limitation of AI.
That is the standard I hold myself to. And it is the standard I believe every UK business owner should be holding their AI adoption to right now. Because the regulation is already here. The question is whether your business is ready to meet it.
Pass the argument to someone who should be part of it.
Continue through the Founder Notes series.



