From the journal

UK CMA Issues Guidance on Consumer Law Compliance for AI Agent Deployments, March 2026

The UK Competition and Markets Authority published non-statutory guidance in March 2026 on how existing consumer protection law applies when businesses deploy AI agents to interact with customers. The CMA holds businesses accountable for AI agent conduct as they would be for employee conduct, and may impose fines up to 10% of worldwide turnover for non-compliance under the Digital Markets, Competition and Consumers Act 2024.

2 min read

The UK Competition and Markets Authority published 'Complying with consumer law when using AI agents' in March 2026. The document is final, non-statutory guidance issued under the CMA's statutory consumer protection function. It sets out the CMA's enforcement position on how the Consumer Rights Act 2015 and the Digital Markets, Competition and Consumers Act 2024 apply to businesses that deploy AI agents in consumer-facing commercial transactions.

The Consumer Rights Act 2015, Part 2, prohibits unfair terms in consumer contracts. The Digital Markets, Competition and Consumers Act 2024, Part 4 and Schedule 18, prohibits unfair commercial practices and grants the CMA direct enforcement powers without a court order. The guidance applies those prohibitions to AI agent conduct and states that businesses bear liability for AI agent actions under the same principal-agent doctrine that applies to employee conduct. Specific obligations cover accuracy of product search results with transparent disclosure of coverage and ranking methodology, pricing completeness requiring all unavoidable charges to be disclosed, and ongoing supervisory review of AI agent responses by a qualified person.

UK retailers, financial services firms, telecoms operators, and travel platforms that deploy AI agents in consumer-facing interactions must assess whether their systems meet the guidance's accuracy, disclosure, and supervisory requirements. The CMA can enforce consumer protection law directly against firms without a court order under powers granted by the Digital Markets, Competition and Consumers Act 2024. Non-compliant businesses face fines up to 10% of worldwide annual turnover and may be required to compensate consumers who suffered harm.

The guidance applies to consumer-facing deployments only and does not cover B2B AI agent interactions. The CMA does not address the guidance's relationship to the EU AI Act 2024/1689, which imposes separate obligations on AI system providers and deployers in the European Union. Businesses serving both UK and EU consumers may face overlapping disclosure and supervisory obligations under distinct legal instruments.

Licentium advises digital businesses on UK and EU consumer protection and competition law, including AI agent deployment compliance. For matters requiring UK-qualified counsel, we coordinate through our partner network. To discuss how the CMA guidance applies to your AI product, contact us. Work we undertake includes: consumer law compliance audits, AI deployment regulatory reviews, unfair commercial practices assessments, Digital Markets Act compliance, and multi-jurisdictional regulatory strategy.

Source: UK Competition and Markets Authority, Complying with consumer law when using AI agents (March 2026)

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).

Illia Prokopiev

Stablecoin regulation in the US, Hong Kong and Singapore

Stablecoin and digital-token regulation now combines market-entry authorization with continuous financial-crime controls in daily operations. The question is whether the United States’ proposed payment-stablecoin customer identification program, Hong Kong’s narrow first licensing round, and Singapore’s digital payment token (DPT) directory support a bank-like compliance characterization. They do, with material limits. The more accurate proposition is that compliance is moving beyond approval into continuous financial-institution-grade operations.