EU AI Regulation in 2027

UK and EU AI Regulation in 2027: Why the Rule That Moved Publisher Leverage Names One Company

THE SHORT VERSION

Two dates, opposite outcomes. On 2 August 2026 the EU AI Act’s transparency layer became applicable across 27 member states. On 3 June 2026 the UK’s competition regulator imposed one rule on one company. The second changed what British site owners can do; the first did not.

The reason is structural. The AI Act is product regulation: it places duties on AI providers and deployers and creates no individual rights. A conduct requirement under the Digital Markets, Competition and Consumers Act 2024 creates a duty that section 101 treats as owed to any person affected by a breach — and that person can sue.

What arrives on 3 December 2026. Google must give publishers directory- and page-level controls over AI grounding and model training, must not downrank anyone for using them, and must report AI Overviews and AI Mode impressions, clicks and click-through rate.

“Publisher” means any party that makes content available on the web. The CMA’s own summary says so. This is not a news-industry remedy with a wide preamble; a 40-page B2B site in Leeds is inside the class.

The trap. Anything a regulator compels for free stops being sellable inside the bound set. The compelled fraction rises towards one for Google in the UK and stays at zero for every engine that was never designated.

Three instruments below: THE BOUND SET, THE COMPELLED FRACTION and THE FILING WINDOW.

Two regulatory events, three months apart, pointing in opposite directions

On 2 August 2026, Article 50 of the EU AI Act became generally applicable and enforceable by national competent authorities. Chatbot disclosure, synthetic-content marking, emotion-recognition notices and deepfake labelling are now live obligations rather than future milestones. The Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July — deferred the Act’s high-risk obligations to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for embedded Annex I systems, but left Article 50 exactly where it was. The one concession was a four-month runway to 2 December 2026 for marking output from generative systems already on the market. Anyone who read the word “delay” in the headlines and stood down was reading about a different part of the statute. For a publisher the practical upshot is a labelling regime for machine-generated output, which changes what appears on a page and nothing at all about who may use yours.

Three months earlier, on 3 June 2026, the Competition and Markets Authority imposed its publisher conduct requirement on Google. It requires Google to give publishers effective controls over the use of their content in generative AI, to publish how that content is used, to report engagement metrics for AI search features, and to take reasonable steps to attribute content clearly with a route back to the source. It applies to one company, in one country, with a compliance date and a private right of action attached.

Set the two side by side and the scoreboard reading of AI regulation falls apart. The United Kingdom has no AI statute. No AI bill sits before Parliament; the House of Commons Library’s own briefing records that the UK has no AI-specific legislation covering AI as a technology, and the AI Safety Institute was renamed the AI Security Institute as the policy language moved from safety to growth. The European Union has the most comprehensive AI regulation in the world, now amended once. The jurisdiction with no AI law produced the first enforceable publisher control over AI search anywhere; the jurisdiction with the AI law produced labelling duties aimed at the users of AI systems.

Most 2027 regulatory round-ups treat this as a race — how much AI law has each bloc passed, and how fast. That framing hides the only variable that predicts whether an instrument will ever change your position. It is not volume, and it is not speed. It is whether the instrument binds a category or a company.

What is a conduct requirement?

A conduct requirement is a rule the CMA imposes on one named firm under section 19 of the Digital Markets, Competition and Consumers Act 2024 (DMCCA, the UK’s digital competition statute), after designating that firm as having strategic market status — substantial, entrenched market power — in a specific digital activity. Google was designated in general search and search advertising on 10 October 2025. The requirement binds Google and nobody else, and lapses if the designation does.

A rule binds a category; a requirement binds a company

The AI Act’s architecture explains why it could never have delivered what British publishers received. It is product regulation. It classifies applications by risk of harm and places duties on providers and on organisations deploying AI in a professional context. It does not create individual rights. There is no claimant in it. A site owner whose pages are being summarised is neither a provider nor a deployer of the engine doing the summarising, so the Act has nothing to say to that site owner except as a member of the public reading a label.

Now read the British instrument. Section 101 of the DMCCA states that a relevant requirement “is to be treated as a duty owed by the person that is subject to the requirement to any other person (‘P’) who may be affected by a breach”. Where a breach causes P loss or damage, P may bring civil proceedings for damages, an injunction, or any other appropriate relief, before the appropriate court or the Competition Appeal Tribunal. Section 101(4)(a) makes a conduct requirement under section 19 a relevant requirement. Section 102 makes final CMA breach decisions binding on the courts, and a standalone claim needs no prior CMA finding at all — a claimant can prove the breach itself.

So the same substantive grievance — my pages are being used to produce answers that replace the visit — has two completely different legal shapes depending on which side of the Channel you file it. In Brussels it is a complaint to a regulator that has discretion over whether to act and no obligation to reach a decision on your timetable. In London it is a statutory duty owed to you personally by a named company, actionable in the High Court. That difference has nothing to do with how strongly either jurisdiction feels about AI and everything to do with the instrument class each one reached for.

INSTRUMENT 1 — THE BOUND SET

For every regulatory instrument you are tracking, write down four things and nothing else:

1. Who is bound. The named firm, or the class of persons on whom the duty falls.

2. Who is owed. The person who can enforce it. Not the person it was drafted to help — the person with a cause of action or a right to a decision.

3. Where it runs. Territory, and which of the counterparty’s products fall inside.

4. From when. The compliance date, not the date of adoption.

The rule: if line 2 is empty, the instrument is a compliance cost for somebody else. It may be excellent policy. It is not a lever, and it does not deserve a line in your plan or an hour of your week.

What the UK actually imposed, and on whom

The publisher conduct requirement is the first conduct requirement the CMA has ever imposed under the new regime, which makes its detail worth reading rather than summarising from press coverage. It has three limbs.

Control. Google must provide publishers with controls to withhold their content from training its generative models, used inside and outside search, and from grounding — formulating and fact-checking — responses in its generative AI features both inside search, meaning AI Overviews and AI Mode, and outside it, meaning the Gemini assistant. After consultation feedback the CMA also required an opt-out from fine-tuning. The controls covering grounding inside search must be offered at directory and page level. And Google must not penalise publishers for using them, for example by downranking them in the rest of Search. Separating the training control from the grounding control matters, because they are different decisions with different costs, and collapsing them into one switch is the commonest error in training-source strategy.

Transparency. Google must publish clear information on what the controls cover and how they work, and on how publisher content is used to train and ground its generative AI services. It must supply transparency metrics for search AI features — impressions, clicks and click-through rate, aggregated across features such as AI Overviews and AI Mode — plus referral data so publishers can assess the quality of the traffic those features send.

Attribution. Google must take reasonable steps to ensure publisher content in generative AI search features is clearly and accurately attributed, with a clear way for users to reach the original source, and must publish how content is selected for attribution, how attribution accuracy is monitored, how it approaches factuality, and how publishers can flag inaccurate or missing attribution.

Google has until 3 December 2026 to comply, with a further three months to develop and roll out the page-level control, and must file compliance reports every six months initially. The CMA has said it expects changes sooner and is actively monitoring the rollout.

The definition is the remedy

The most consequential sentence in the CMA’s summary is not a duty at all. It is the gloss on who benefits: publishers, meaning any party that makes content available on the web. There is no news carve-out, no circulation threshold, no requirement to be a member of a trade body. A specialist trade site, a documentation subdomain, a comparison directory and a national newspaper are all inside the same class. Most coverage framed this as a newspaper story because newspapers led the lobbying, and that framing has caused a great many site owners to conclude the remedy is not theirs. It is.

The second most consequential provision is the no-penalisation clause, and it is the actual innovation. Until now the only reliable way to keep your content out of AI answers was to block Googlebot, which meant leaving search — the reason every survey of publisher sentiment described the existing opt-outs as theoretical. Decoupling AI use from search inclusion is what converts a nominal control into a usable one, and it is the single change most likely to alter how UK site owners think about crawler-level access decisions over the next year.

Set the four live instruments against the bound-set test and the asymmetry is stark.

InstrumentWho is boundWho is owed a dutyWhat it changes for a site owner
EU AI Act, Art. 50 (as amended by Reg (EU) 2026/1744)Providers and deployers of AI systems, EU-wideNobody — the Act creates no individual rightsLabels on AI output. No control, no metrics, no attribution duty
DMCCA publisher conduct requirement (s.19)Google alone, United Kingdom onlyAny person affected by a breach (s.101)Page-level grounding opt-out, AI-feature metrics, attribution duty, no-downrank guarantee
Art. 102 TFEU investigation, opened 9 Dec 2025Google, EU-wide, if abuse is provenComplainants, with no right to any particular remedyPossibly commitments or a fine, years away
Digital Fairness Act (proposal expected Q4 2026)Traders dealing with EU consumersConsumersNothing before 2028 on current timetables

One row has an entry in the third column that names you. That is the whole finding.

What the EU produced instead — and where its publisher remedy is actually coming from

The Digital Omnibus was the EU’s big 2026 move, and it was a simplification measure. Parliament approved it on 16 June 2026, the Council adopted it on 29 June, it was signed on 8 July and entered into force on 27 July. It deferred high-risk deadlines, added a prohibition on AI systems for producing non-consensual intimate imagery and child sexual abuse material from 2 December 2026, expanded the AI Office’s supervisory powers, and softened the AI literacy duty. It did not touch the risk-based architecture, and it did not give any content owner a right against any engine.

The Digital Fairness Act, the instrument most marketing teams have on their radar, is not law and will not be for years. The Commission’s consultation closed on 24 October 2025; the proposal is expected in the fourth quarter of 2026; negotiation runs through 2027 with adoption realistically late in that year and staggered application across 2028 to 2030. Its subject matter is dark patterns, influencer marketing, addictive design and unfair personalisation. It is consumer protection, drafted for consumers, and it has nothing to say about who must attribute your pages. Treat it as a 2028 planning input, not a 2027 one.

Meanwhile the EU’s actual publisher remedy is being built in the same place the British one was: competition law. On 9 December 2025 the Commission opened a formal antitrust investigation into whether Google breached Article 102 TFEU by using web publishers’ content, and content uploaded to YouTube, for AI purposes — specifically whether it generated AI Overviews and AI Mode from publisher content without appropriate compensation and without the possibility of refusing without losing access to Google Search, and whether it granted itself privileged access to content while barring rival model developers. The European Publishers Council filed a formal complaint on 10 February 2026, citing AI Overviews appearing on more than 40 per cent of informational results and AI Mode interfaces producing an external click on fewer than 5 per cent of queries. French newspapers filed their own complaint in August 2026, attributing a 38 per cent traffic loss to AI summaries. In July 2026 Google was separately ordered to share search data with rivals and open Android to competing AI services, days after losing its final appeal against the €4.1 billion Android fine. Those displacement figures deserve reading against wider 2026 measurement baselines, since complaint documents cite the most dramatic numbers available and regulators discount accordingly.

Why an AI statute could not have produced the British remedy

Three reasons, and the third is the one worth keeping. First, risk-based product regulation asks whether a system is dangerous, not whether a bargain is unfair; a page-level grounding control is not a safety measure and has no home in that taxonomy. Second, a rule of general application can only impose duties every member of the class can discharge, and “provide directory- and page-level controls, report AI Mode click-through rate, and publish your attribution methodology” is not a duty a twelve-person model startup can discharge. Third, and generally:

the finer the remedy, the fewer parties it can bind. Resolution and reach trade off against each other. To cover everyone, a rule has to be coarse enough for the smallest party in the class to satisfy — which is why symmetric instruments produce labels, notices and disclosures, and almost never produce controls, metrics or guarantees. The publisher conduct requirement is the highest-resolution content remedy in existence anywhere, and it exists precisely because it only ever had to fit one company’s engineering.

Key takeaway. Judge an instrument by its bound set, not its ambition. Symmetric rules of general application are the reason the EU produced labelling and the UK produced control: generality forces coarseness. If you want a remedy with resolution, you have to want one that names a firm — and accept that it stops at that firm’s edge.

The compelled fraction: why winning the rule can destroy the price

Publisher trade bodies spent two years asking for three things: compelled opt-outs, compelled attribution and compelled reporting. In the UK, from one regulator, they got all three. Now the awkward arithmetic that nobody in the celebration coverage ran.

A behaviour a counterparty is legally obliged to supply you for nothing has a bilateral price of nothing. If you were preparing to sell grounding rights, attribution or usage reporting to Google in the United Kingdom, you are not any more. Those things arrive on 3 December 2026 whether you sign anything or not, and a negotiator cannot charge for a duty the other side already owes. This is not an argument against the conduct requirement. It is an argument about where your commercial attention should go the morning after it lands.

INSTRUMENT 2 — THE COMPELLED FRACTION (κ)

For a behaviour B you hoped to sell to counterparty C, let κ be the share of B that C is now legally obliged to supply you for free.

Negotiable value ≈ V × (1 − κ), where V is what B would fetch in an unregulated bilateral deal.

Run it per counterparty, never per behaviour. The same asset has as many κ values as you have counterparties, because κ is a property of the bound set, not of the content.

Then reprice in the direction κ is lowest. The counterparties worth negotiating with are the ones no regulator has named.

Work it. Thackray Index is a Leeds business-to-business publisher covering construction materials pricing: roughly 1,900 URLs, a UK-heavy audience, and a small licensing conversation open with two large model providers. It values a bundle of grounding rights, attribution commitments and usage reporting at £48,000 a year per engine — a figure derived from what its subscription tier earns from the same data.

For Google in the UK after 3 December 2026, κ is roughly 0.85. Grounding control, training control, attribution and engagement reporting are all compelled; what survives as sellable is the residue the requirement does not name — exclusivity, freshness guarantees, historical depth, and structured machine-readable feeds that go beyond what a crawler can assemble. Negotiable value falls to about £7,200. For any engine that was never designated, κ is zero and the number stays at £48,000. Same asset, same week, a sixfold difference in price, decided entirely by whether the counterparty happens to have been named by a British regulator.

Two consequences follow, and both are counter-intuitive. The first is that the conduct requirement is a reason to move commercial effort away from Google rather than towards it: the value there is now a utility you receive rather than an asset you trade. The second is that if you have a live content licensing or pay-per-crawl negotiation with Google covering UK rights, its December value is materially lower than its August value, and the difference is not recoverable. Signatures before the compliance date are worth more than signatures after it.

Key takeaway. A regulatory win converts an asset into a utility inside the bound set. Bank the utility, then reprice the asset wherever the utility does not reach. Publishers who read the CMA decision as a green light to open harder negotiations with Google have the direction exactly backwards.

Where the boundary falls, and the exit paradox it creates

The bound set here is narrow and worth stating precisely: one company, one country, its search AI features, plus grounding for its assistant outside search. That last element is broader than most commentary registered — the controls reach content used to ground Gemini, not merely AI Overviews — and it is the part with the most durable value, because assistant grounding is where agentic and assistant-mediated sessions are heading.

Everything outside that set is untouched. No duty binds OpenAI, Anthropic, Perplexity or Microsoft Copilot, because none of them has been designated in general search — the CMA’s fourth strategic market status investigation is into Microsoft’s business software ecosystem, not its search or assistant products. So from December a UK site owner will have page-level control and reported click-through rate for one engine, and neither for every other engine reading its pages. If your traffic profile already leans towards chat and browser-embedded assistants rather than Google’s AI features, the conduct requirement gives you transparency about the smaller half of your exposure.

The exit paradox

The control’s most obvious use is its worst. Withdrawing from AI Overviews and AI Mode withdraws you from the only engine legally required to attribute you clearly and to tell you what your content earned. You would be exiting the transparent venue and staying in every opaque one. A publisher that opts out of grounding on 4 December keeps its reported metrics, loses its AI Mode citations, and changes precisely nothing about how Copilot or Perplexity treat the same pages.

Which means the control is worth more unexercised than exercised. The CMA said as much when it framed the remedy as putting publishers in a stronger position to negotiate content deals: the point of a credible refusal is that you do not have to use it. An unexercised right with a private cause of action behind it is a priced instrument. An exercised one is a withdrawal, and withdrawals from zero-click surfaces have historically been very hard to reverse, because the citation graph reforms around whoever stayed.

There is a jurisdictional edge too. The requirement runs in the United Kingdom. A publisher with a UK-registered domain and a mostly American audience gets the control over UK-served AI features and nothing over the same engine’s behaviour elsewhere, which makes multi-market content strategy a compliance question as well as a growth one for the first time.

The strongest objection: the remedy is defined by the firm it constrains

The serious criticism of the publisher conduct requirement is not that it is too weak. It is that it outsources its own content. Cloudflare’s consultation response of 25 February 2026 put it most sharply: the requirement delegates the definition and implementation of publisher rights back to Google, a company with a vested interest in maintaining its data pipeline, and stops short of addressing the structural root — the dual-purpose search crawler that collects for ranking and for generation in the same pass. If Google decides what “effective controls” means, the argument runs, the remedy is whatever Google ships.

That objection has institutional weight behind it. On 10 July 2026 a coalition of the Independent Media Association, the Independent Publishers Alliance, Impress Media and the Movement for an Open Web wrote to the CMA’s search case team through Preiskel & Co, arguing that the imposed requirements leave the underlying two-sided-market problem unresolved. The Knight-Georgetown Institute argued that without confronting default distribution the requirements risk preserving the market power they are meant to constrain. The Movement for an Open Web welcomed the decision in principle while saying plainly that it feared the measures would prove ineffective in practice. These are the people who filed the original complaint, and they are not satisfied.

The objection is right about the mechanism and wrong about the conclusion, for three reasons.

  1. The transparency limb is unconditional. Impressions, clicks and click-through rate for AI Overviews and AI Mode, plus referral data, arrive whether or not you touch a control and whether or not the controls work as advertised. That number has never existed for any publisher in any market. Measurement does not depend on Google’s good faith about opt-outs, and a baseline you can audit is the precondition for every other decision here.
  2. Section 101 moves the argument out of the consultation. Whether a control is “effective” stops being a policy question the CMA alone can press and becomes a justiciable one, contestable by any affected person in the High Court or the Tribunal, with or without a prior regulatory finding. The set of people who can force the definition is now much larger than the set who can write a consultation response.
  3. The remedy may not stay British. Google has indicated it will test the new controls with a subset of site owners before a wider rollout. If a UK-mandated control ships globally, κ rises towards one everywhere, and the repricing argument above stops being a UK planning note and becomes the central fact of every content licensing conversation in the world.

The honest residual: none of this is worth much if six-monthly compliance reports are the only monitoring and the CMA has to fight every definitional battle itself. The regime’s credibility rests on its first breach decision, and there has not been one. A remedy imposed in June 2026 with a December compliance date has not yet been tested by anything. Publishers who want a position that does not depend on Google’s implementation at all still have to hold their own evidence of origin, which is what content credentials were built to carry.

The filing window: what an ordinary site owner can actually do

The practical difference between symmetric and asymmetric instruments is that asymmetric ones have dockets, and dockets have addresses. The CMA’s own conduct requirement summary invites comments on your experience of Google’s changes, directly or through a trade association, at a published email address. That is more access than most regulatory processes give anyone, and almost nobody outside the trade bodies uses it.

INSTRUMENT 3 — THE FILING WINDOW

Three questions per live proceeding:

1. Is there an open docket with a published channel? A consultation, a compliance-monitoring process, a case team email. If not, you are a spectator.

2. Am I inside the class the instrument is drafted for? Read the definition, not the press release. “Any party that makes content available on the web” includes you; “providers and deployers of AI systems” does not.

3. Is there a date before which my evidence can still change the outcome? Evidence filed before a decision shapes it. Evidence filed after it is a complaint.

Three yeses: an afternoon spent assembling logs beats a year spent reading analysis. One no: close the tab.

The 2027 diary, in date order rather than by jurisdiction:

  • 2 December 2026 — AI Act Article 50(2) marking obligations reach generative systems already on the EU market on 2 August 2026, and the new prohibition on systems for producing non-consensual intimate imagery and CSAM takes effect.
  • 3 December 2026 — Google’s compliance deadline for the publisher conduct requirement; roughly 3 March 2027 for the page-level grounding control.
  • Q4 2026 — the Commission is expected to table the Digital Fairness Act. Adoption realistically late 2027; application staggered to 2030.
  • Still open — the CMA’s user choice conduct requirement, consulted on in January 2026 alongside the three imposed in June, has not been imposed. It is the live docket with the shortest queue.
  • Rolling — the Commission’s Article 102 investigation opened 9 December 2025, and Google’s six-monthly compliance reports to the CMA.
  • 2 December 2027 and 2 August 2028 — AI Act Annex III and Annex I high-risk obligations, as deferred by the Digital Omnibus.

A worked micro-example of what filing looks like at small scale. A sixty-page software documentation site logs, from 3 December, every AI Mode answer that reproduces its pricing table without naming it, capturing query, feature, answer text and whether any link resolved. Three months of that is not commentary; it is the evidentiary record a breach decision would need, and it is also the raw material for attribution recovery work and for a defensible measurement of how much authority the site is actually being credited with. Most of the capture can be automated inside the monitoring stack most site owners already run.

The Monday checklist

  1. Write your bound set for the four instruments in the table above. Delete every line where nobody is owed a duty, and delete the tracking effort that went with it.
  2. Instrument your own baseline this month. AI-feature impressions and clicks become reported data in December; you want a pre-requirement comparison that you controlled and that nobody can revise.
  3. Decide the opt-out question in writing before 3 December — grounding, training, both or neither, at directory or page level — and record the traffic figure that would reverse the decision.
  4. Do not opt out of anything until you have seen one full reporting cycle. You are being handed data you have never had; spending the option before reading it is the one clearly wrong move.
  5. Run κ per counterparty. One number for Google-UK, one for each undesignated engine. If the spread is large, your commercial priority order just changed.
  6. Get signatures before December on anything a UK regulator is about to make free.
  7. Keep an attribution log from the compliance date: query, feature, whether you were named, whether the link resolved. Use the flagging route the requirement forces Google to publish, and keep the ticket numbers.
  8. Put the user choice requirement and the Article 102 investigation on a watch list with a named owner and a filing date, not on a newsletter subscription. Regulatory milestones are also the most reliable newsworthy hooks a specialist site gets, and the coverage window opens when the decision lands, not when it is announced.
  9. Build one original asset off the new data. From December, UK publishers will hold AI-feature engagement figures nobody else has published. A study or a calculator built on that data is the most defensible earned-link play available in 2027, and it fits the wider earned-authority strategies that survive when referral traffic does not.

The lesson generalises past this one requirement. When the next AI instrument is announced, do not ask how strict it is. Ask who is bound, who is owed, where it runs and from when. Instruments that name a class produce labels; instruments that name a company produce leverage — and only one of those two ever has your name in the third column. Regulation has changed what the largest engine owes a British site owner. It has not changed what earns a citation in the first place.

Leave a Reply

Your email address will not be published. Required fields are marked *

Right to Be Cited Previous post The Right to Be Cited: Attribution Law and Publisher Leverage in 2027
Agent Liability and Brand Risk Next post Agent Liability and Brand Risk: Who’s Accountable When an Agent Errs