This article is general information, not legal advice. It reflects our understanding of the position on 8 October 2026. Rules and guidance in this area change often, so take professional advice on your own circumstances.
There is no single UK AI Act
Many business leaders expect the UK to follow the EU and pass one law covering AI. It hasn't done so, and nothing suggests it will soon. The King's Speech on 13 May 2026 included no dedicated AI bill. It did announce a Regulating for Growth Bill, which would give the government powers to set up cross-economy regulatory sandboxes. In those sandboxes, firms could test new products, AI-enabled ones included, under controlled conditions where some rules are temporarily relaxed.
The UK approach still rests on the 2023 white paper, A pro-innovation approach to AI regulation. It set five cross-sector principles: safety, security and robustness; transparency and explainability; fairness; accountability and governance; and contestability and redress. Existing regulators apply these principles within their own remits, using powers they already hold.
In practice, your AI system is regulated through whatever already governs your activity: data protection, consumer law, financial services rules, medical device law, online safety, equality law and so on.
Key point
No AI Act doesn't mean no AI rules. If you use personal data, deal with consumers or work in a regulated sector, the rules you already follow apply to your AI systems too, and regulators expect you to show how you meet them.
The sector-regulator model
On 28 January 2026, the Secretaries of State for Science, Innovation and Technology and for Business and Trade wrote jointly to 19 regulators. They asked each one to publish, by May 2026, a plan for enabling safe AI-powered innovation, and to report on progress every year. The letter asked regulators to explain how existing rules apply to AI, to make approval processes work for AI products that change after approval, and to consider sandboxes. So expect more sector-specific AI guidance, not less.
The regulators most business leaders will meet are these:
| Regulator | Where it bites on AI | Recent signals |
|---|---|---|
| ICO (Information Commissioner's Office) | Any AI that processes personal data: training, inputs, outputs, profiling and automated decisions. | Draft automated decision-making guidance consulted on March–May 2026; now under a statutory duty to produce an AI and ADM code of practice. |
| FCA (Financial Conduct Authority) | AI used by authorised firms: advice, credit, pricing, claims, fraud and customer service. | No new AI-specific rules. It relies on the Consumer Duty, the Senior Managers and Certification Regime and existing governance rules. It runs AI Live Testing, and in January 2026 launched the Mills Review into AI's long-term effect on retail financial services. |
| CMA (Competition and Markets Authority) | Consumer-facing AI, including chatbots and AI agents, plus competition in AI markets. | Since 6 April 2025 it can fine directly for consumer law breaches, up to 10% of global turnover. In March 2026 it published guidance on using AI agents in line with consumer law. |
| MHRA (Medicines and Healthcare products Regulatory Agency) | AI that qualifies as a medical device, such as diagnostic or triage software. | The AI Airlock regulatory sandbox for AI medical devices, which received multi-year funding in 2026. |
| Ofcom | Online services within the Online Safety Act, including generative AI and chatbot features that let users share content. | A November 2024 open letter confirmed that the Act covers many generative AI and chatbot services. |
Two points from this map stand out. First, the CMA's agentic AI guidance is clear that a business stays responsible for what its AI agent tells or does to customers, even when a third party built the agent. Make sure customers aren't misled into thinking they're dealing with a person, build statutory rights into the agent's instructions, and keep humans overseeing decisions with financial or contractual consequences. Second, financial regulators have said they don't need new rules because accountability already sits with named senior managers. If you are an FCA-regulated firm, somebody senior should own each material AI use case.
UK GDPR, the Data (Use and Access) Act and automated decisions
For most organisations, data protection law matters most. The UK GDPR applies whenever an AI system processes personal data. The usual duties apply: a lawful basis, transparency, data minimisation, accuracy, security, and a data protection impact assessment (DPIA) where processing is likely to be high risk.
The biggest recent change concerns automated decision-making (ADM). Section 80 of the Data (Use and Access) Act 2025 came into force on 5 February 2026. It replaced the old Article 22 of the UK GDPR with new Articles 22A to 22D. Under the old rule, solely automated decisions with legal or similarly significant effects were broadly prohibited unless one of a few narrow exceptions applied. The new rules work like this:
- Definitions. A decision is "based solely on automated processing" when there is no meaningful human involvement in taking it. A "significant decision" is one that produces a legal effect for the person or a similarly significant effect.
- A narrower restriction. The tighter limits now apply mainly where a significant decision is based wholly or partly on special category data, such as health or biometric data. In those cases, a solely automated decision is allowed only with the person's explicit consent, or where it is needed for a contract or required by law and a substantial public interest condition applies.
- Mandatory safeguards. For any solely automated significant decision, you must have safeguards. People must be told about such decisions, be able to make representations, be able to get human intervention, and be able to contest the decision.
- Room for change. The Secretary of State can use regulations to say what counts as meaningful human involvement, which decisions have similarly significant effects, and what extra safeguards apply.
In practice, many more organisations can now lawfully use solely automated decisions with ordinary personal data, relying on any lawful basis, including legitimate interests. That's a real relaxation. But the safeguards are now mandatory, so you need processes to explain decisions, take representations and route challenges to a person with authority to change the outcome.
Key point
A person who rubber-stamps a model's output does not make a decision "not solely automated". The ICO's draft guidance says human involvement must be active and meaningful, not a token step. If your process depends on a human in the loop, make sure that person has the time, information and authority to disagree with the system.
The ICO's draft ADM guidance and statutory code
The ICO consulted on draft updated guidance on automated decision-making and profiling from 31 March to 29 May 2026. The draft is aimed at data protection officers, compliance teams and technical leads. It covers when ADM is permitted, what restrictions apply and what safeguards must be in place. The ICO also published a report on ADM in recruitment. Its main finding was that many employers don't recognise they are carrying out ADM at all, so they lack safeguards such as transparency and bias monitoring. As of writing, the consultation page gives no firm date for the final guidance, and commentators' expectations vary. Treat the draft as the best current indication of the ICO's thinking.
Separately, the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 came into force on 12 May 2026. They require the Information Commissioner to prepare a code of practice on good practice when processing personal data to develop and use AI, and for automated decision-making. The code must include guidance on children's personal data. A statutory code must go through a formal preparation and parliamentary process, and no publication date has been set. When it arrives, it will set out the ICO's expectations, and courts and the ICO can take it into account. The underlying legal duties already apply, so there's no reason to wait for the code.
The AI Security Institute
The AI Security Institute (AISI) was called the AI Safety Institute until February 2025, when the government renamed it to reflect its focus on security and misuse risks. It is a research organisation within the Department for Science, Innovation and Technology. It evaluates advanced AI models, studies risks and safeguards, and advises government and international partners.
AISI is not a regulator. It doesn't license AI systems, inspect businesses or issue fines, and most firms will never deal with it directly.
The EU AI Act for UK firms selling into the EU
Since Brexit the EU AI Act (Regulation (EU) 2024/1689) is not UK law, but it reaches across borders. It applies to providers that place AI systems or general-purpose AI models on the EU market wherever they are based, and to providers and deployers outside the EU where the AI system's output is used in the EU. A UK company with EU customers or EU-facing products may well be in scope. The highest fines, for prohibited practices, reach €35 million or 7% of worldwide annual turnover, whichever is higher.
The timeline changed in 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was adopted on 8 July 2026 and entered into force on 27 July 2026. It deferred the main high-risk obligations, but other obligations stayed on their original dates:
| Date | What applies | Status |
|---|---|---|
| 2 February 2025 | Prohibited practices (Article 5) and the AI literacy duty (Article 4) | Original timeline; applying now |
| 2 August 2025 | Obligations for providers of general-purpose AI models | Original timeline; applying now |
| 2 August 2026 | Article 50 transparency duties, such as telling people they are interacting with AI and disclosing deepfakes | Original timeline; applying now |
| 2 December 2026 | New prohibitions on AI that generates non-consensual intimate imagery or child sexual abuse material. Deadline for systems already on the market before 2 August 2026 to meet Article 50(2) marking of AI-generated content | Added by the Omnibus |
| 2 December 2027 | High-risk obligations for Annex III systems, for example in employment, education, credit scoring, biometrics and critical infrastructure | Deferred from 2 August 2026 |
| 2 August 2028 | High-risk obligations for AI in products covered by EU product-safety legislation (Annex I) | Deferred |
The Omnibus also changed the AI literacy duty, so organisations must now take measures to support AI literacy rather than ensure a sufficient level of it. It extended some simplifications to small mid-cap companies and strengthened the EU AI Office's supervisory powers. The high-risk requirements themselves are unchanged and still cover risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness and cybersecurity. Only the deadlines moved.
Key point
The deferral gives you time; it doesn't remove obligations. If you build or sell AI used in hiring, education, credit or other Annex III areas for EU customers, December 2027 is not far off for documentation-heavy work. Meanwhile, transparency duties and prohibitions already apply.
Standards: ISO/IEC 42001
ISO/IEC 42001:2023, published in December 2023, is the international standard for an AI management system. It sets out how an organisation should establish, run and keep improving policies, risk management, impact assessments, life-cycle controls and supplier oversight for AI. It shares its high-level structure with ISO/IEC 27001, so firms already certified for information security can extend their existing system. Accredited third-party bodies can certify against it.
No UK law requires 42001 certification. It is still useful as a structured way to show regulators and customers that you have governance in place, and it covers much of the groundwork the UK principles and the EU AI Act expect. Treat it as a framework for organising your work, not as a substitute for meeting specific legal duties.
A practical checklist
If you are deciding whether and how to deploy AI, these steps cover most of what UK regulators currently expect:
- Inventory your AI. List every AI system in use or in development, including AI features inside software you buy. Record its purpose, owner, data sources and who it affects.
- Map each use case to its regulators. For each system, note which regimes apply: UK GDPR, consumer law, FCA rules, medical device law, the Online Safety Act or equality law.
- Find your significant decisions. Identify any decisions about people that are solely automated and have legal or similarly significant effects. Check whether any rely on special category data, which still faces tighter limits.
- Build the Article 22C safeguards. Tell people about automated decisions, let them make representations, and give them a working route to human review and challenge. Test that the route actually works.
- Make human oversight real. Where a human is in the loop, give them the information, time and authority to override the system, and record when they do.
- Run a DPIA before deploying AI that processes personal data in high-risk ways, and update it when the model or its use changes.
- Be open with customers. Label chatbots and AI agents so nobody thinks they are talking to a person. Make sure agents respect statutory consumer rights.
- Assign accountability. Name a senior owner for each material AI system. In FCA-regulated firms, align this with your SM&CR responsibilities.
- Check your EU exposure. If you sell into the EU or your AI's output is used there, decide whether you are a provider or a deployer. Check prohibited practices and Article 50 transparency now, and plan for 2 December 2027 if you have Annex III use cases.
- Review supplier contracts. Get documentation, testing evidence, data-handling terms and incident notification commitments from AI vendors. Responsibility for what an AI system does stays with you.
- Train your people. Give staff who use or oversee AI practical training on its limits, which also supports EU AI literacy expectations.
- Monitor and log. Track accuracy, drift, bias indicators and complaints after launch. Keep records you could show to a regulator.
- Watch for changes. Track the final ICO ADM guidance, the statutory AI and ADM code, your sector regulator's AI plan and the progress of the Regulating for Growth Bill.
- Consider ISO/IEC 42001 as the framework that ties this together, especially if enterprise customers ask about it.
UK AI regulation doesn't ask businesses to tick boxes on a new form. It asks them to show that the duties they already have still hold when a model is making or shaping decisions.
If you'd like help mapping your AI use cases against these obligations, or designing a system with oversight and documentation built in from the start, talk to us.
Sources
- Data (Use and Access) Act 2025, section 80 — legislation.gov.uk
- The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 — legislation.gov.uk
- The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 — legislation.gov.uk
- ICO consultation on the draft guidance about automated decision-making, including profiling — ICO
- UK ICO consults on draft automated decision-making guidance and sets expectations for ADM in recruitment — Covington (Inside Privacy)
- UK's data protection reforms take effect: a new era for automated decision-making — Travers Smith
- How will regulators support safe AI-powered innovation: joint letter from DSIT and DBT — GOV.UK
- King's Speech 2026: commercial, technology and regulatory developments — Lewis Silkin
- A pro-innovation approach to AI regulation: government response — GOV.UK
- UK financial services regulators' approach to artificial intelligence in 2026 — Covington (Global Policy Watch)
- AI agents: CMA publishes guidance on complying with consumer law — Taylor Wessing
- A new age dawns for consumer protection in the UK — Slaughter and May
- MHRA AI Airlock: from pilot sandbox to scaling regulatory pathway — Fieldfisher
- Open letter to UK online service providers regarding generative AI and chatbots — Ofcom
- AI Security Institute — AISI
- Written statement on the AI Security Institute — UK Parliament
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) — EUR-Lex
- EU Digital Omnibus on AI enters into force — Hunton
- The Digital Omnibus on AI enters into force today — Lewis Silkin
- ISO/IEC 42001:2023 — AI management systems — ISO