By Terence Walsh | TWDA Design | Northumberland web design
Reading time: ~7 minutes | Category: Business Tips
Most small businesses we work with now use ChatGPT, Copilot or Gemini for something: drafting a Facebook post, tidying up a product description, generating a picture for a Christmas menu. It saves hours. It also, since this summer, sits inside a set of rules that didn’t exist a year ago, and the questions we’re getting have changed from “should I use it?” to “am I going to get fined?”
The short answer for most Northumberland and North East businesses is no, provided you follow a few plain rules. The longer answer is that there are now four separate things to think about: the EU’s AI Act, which started applying to AI-generated content on 2 August 2026; the UK’s advertising rules, which haven’t changed but are being enforced more actively; the UK ban on fake reviews, which is the one most likely to catch a small business out; and the ordinary data protection and copyright law that applied all along.
This post walks through each of them in plain English, then gives you a simple house policy that covers the lot. Two honest caveats first: we’re web designers, not solicitors, so treat this as a practical guide rather than legal advice; and this area is moving quickly, so check the linked sources if you’re reading it much after September 2026.
“Nobody is going to fine a Hexham café for using ChatGPT to draft a post about its Sunday lunch.
The real risks are narrower: publishing an AI image that looks like a real photo of something that isn’t real, letting AI write ‘reviews’, pasting customer details into a public chatbot, and claiming things in AI-written copy that you can’t back up.
Avoid those four, keep a human in the loop, and you’re in good shape.”
The EU’s Artificial Intelligence Act is the big one in the headlines, and its transparency rules (Article 50) began applying on 2 August 2026. It is EU law, and the UK has no equivalent. But it doesn’t stop neatly at the Channel, it applies to businesses outside the EU when the AI output is used in the EU. If you’re a holiday let that markets to Dutch and German visitors, or a shop that ships to Ireland, it is worth understanding. If you only sell to people in the UK, it’s mostly background.
What it actually requires of a business using AI tools (a “deployer”, in the Act’s language) comes down to two things.
First, if you publish an AI-generated or AI-altered image, video or audio that looks like a real person, place, object or event and could be taken as genuine, you have to make clear it’s artificial. The Act calls this a deepfake, and the definition is broad: an AI-generated “photo” of your restaurant’s terrace with a sunset it’s never had, or a “customer” enjoying a pint, is exactly what it means. Obviously illustrative or cartoon-style imagery isn’t caught. The European Commission has published guidelines and a code of practice for how the label should look: visible without clicking, and there from the moment someone sees the content.
Second, if you publish AI-written text that informs the public on a matter of public interest (health, consumer safety, the environment, finance, and so on), it needs to be labelled as AI-generated unless a person has properly reviewed it and takes editorial responsibility. The guidance is explicit that a quick spell-check doesn’t count; a real read and edit does. An ordinary marketing post about your opening hours isn’t “public interest” text, but a blog post giving health or financial guidance might be.
The penalties for getting Article 50 wrong are up to €15 million or 3% of worldwide turnover, whichever is higher, which is the sort of figure written with Meta and Google in mind rather than a guesthouse in Rothbury. The practical point for a small UK business marketing to EU customers is to label realistic AI images and to make sure a human edits anything substantial before it goes out.
Checklist:
The UK’s advertising rulebook, the CAP Code, doesn’t have an AI section, and there’s no UK law that requires you to say a post was written with AI. What the Code does say applies whatever tool you used: ads must not mislead by inaccuracy, exaggeration or omission, and you have to be able to back up any claim you make.
This is where AI writing tools quietly cause trouble. Ask ChatGPT for a punchy description of your B&B and it will cheerfully write “award-winning breakfasts” and “Northumberland’s best-loved”. If those aren’t true, or you can’t evidence them, that’s a breach of the Code, and the fact that a machine wrote it is no defence. The same applies to AI-generated images used in ads: a picture of a room, a dish or a finished job that is better than reality is misleading whether it was Photoshop or Midjourney.
The Advertising Standards Authority has said it expects to review around 40 million ads in 2026 using its own AI monitoring, rather than waiting for complaints, so “nobody will notice” is a weaker bet than it was.
Checklist:
If there’s one rule in this post to remember, it’s this. Since 6 April 2025, under the Digital Markets, Competition and Consumers Act, it has been illegal in the UK to write, commission or publish fake reviews, or to hide that a review was incentivised. The CMA’s guidance defines a fake review as one that “purports to be, but is not, based on a person’s genuine experience”. The Competition and Markets Authority can now fine businesses directly, up to 10% of global turnover, without going to court, and in 2026 it opened its first investigations against household names for suppressing bad reviews and rewarding good ones.
Asking an AI tool to “write me five customer testimonials for my website” produces fake reviews, full stop. So does polishing a real review until it says something the customer didn’t. So does a staff member posting a five-star Google review of their own workplace. The AI part is new; the rule isn’t, but the tools make it very easy to break.
If you show reviews on your own website, the CMA also expects you to have a simple policy on preventing and removing fake ones and to take reasonable steps in proportion to your size. For a small business that usually means: only publish reviews you know are real, keep a note of where each one came from, and take one down if you can’t stand it up.
Checklist:
Under UK GDPR you’re responsible for personal data you hold about customers, and pasting it into a public AI tool is a disclosure to a third party. “Write a reply to this complaint” with the customer’s name, email and booking details pasted in is the everyday version of this. On the free tiers of most AI tools, what you type can be used to train the model and can’t easily be recalled.
The Information Commissioner’s Office has been clear that the ordinary rules apply to AI tools. The fix is simple and costs nothing: strip names and contact details out before you paste, use a business account with training switched off if you use these tools a lot, and never put in anything you’d be uncomfortable seeing on a screen in a stranger’s office.
Checklist:
Two points here, and both are slightly counter-intuitive.
The first is that purely AI-generated content in the UK probably has no copyright owner at all. The government’s March 2026 report on copyright and AI concluded that works created solely by AI aren’t protected under current law, and that the old provision covering “computer-generated works” is likely to be repealed. In practice that means an AI-generated logo, image or slogan you use can be copied by a competitor and there’s little you can do about it. If it matters, get a person to make it.
The second is that AI tools can produce content that infringes someone else’s rights: an image “in the style of” a living illustrator, a paragraph lifted from a competitor’s site, a likeness of a real person, a brand’s logo in the background. The tool doesn’t carry the risk; you do, because you published it.
Checklist:
Separately from the law, Facebook, Instagram, Google and the rest have policies. Meta now applies an “AI info” label when its own tools or detectable third-party tools significantly generate or alter an image or video, and asks advertisers to disclose realistic AI-generated content themselves. Google, for its part, says it doesn’t mind how content was produced as long as it’s useful and accurate, but it does penalise pages churned out at scale with no value in them, which is what a lot of cheap “AI content” services produce. Breaking a platform’s rules doesn’t get you fined; it gets your post pulled or your page restricted, which for a small business can hurt more.
Checklist:
You don’t need a 20-page AI policy. You need six lines that everyone who posts for the business has read:
The first line does more work than it looks: a real human edit is exactly what takes AI-written text out of the EU labelling requirement, and it’s what stops most of the advertising and accuracy problems before they start. It’s also how we work on our own blog and content writing for clients.
“AI detection” tools. They’re unreliable, they flag plenty of human writing, and no UK regulator is running your posts through one. The question regulators ask is “is this true and fair?”, not “did a machine type it?”.
Labelling every post. Unless you’re publishing realistic AI imagery, or public-interest text for an EU audience without editing it, there’s no rule in the UK or EU that says a Facebook post drafted with ChatGPT has to say so. Being open about it is a good look; it isn’t a legal requirement.
Reading this, and writing your six-line policy, is half an hour. The habits (edit before you post, strip customer data, don’t fake reviews) cost nothing once they’re habits. If you’d like us to check your website’s reviews and images against the rules above, or add the “AI-generated” labels and a review policy to your site, it’s a small job we can fold into a website maintenance plan.
Send it over and we’ll give you a straight answer. And keep an eye on our Latest News for more practical guides.