Skip to content

The UK's Sector-Regulator Approach

10 min read · updated August 4, 2026

The United Kingdom has not enacted a cross-cutting AI statute. Its approach, set out in a 2023 white paper and confirmed in the government’s 2024 response, is that existing regulators apply five non-statutory principles within their existing remits. So the question “what does UK AI law require?” resolves into “which regulator has jurisdiction over what you do, and what have they said?”

Information, not legal advice. Reviewed 4 August 2026. The position described here — no general AI statute, principles applied by sectoral regulators — has been stable since 2023, but successive governments have signalled an intention to legislate for frontier models, and regulator publications are updated frequently. Check each regulator’s own site rather than relying on a summary of it.

There is no UK AI Act

This needs saying flatly because a great deal of writing implies otherwise. As at this review date there is no Act of Parliament creating general obligations for the development or deployment of AI in the United Kingdom. There is no UK equivalent of risk tiers, no conformity assessment, no CE-style marking, no registration database and no AI-specific regulator with cross-sectoral powers.

What there is: a policy framework, regulators applying existing powers, a research body, and a great deal of law that was never about AI and binds it anyway.

The five principles, and their legal status

The March 2023 white paper “A pro-innovation approach to AI regulation” set five cross-sectoral principles. The government’s response in February 2024 kept them non-statutory and asked key regulators to publish their approach to implementing them by 30 April 2024.

PrincipleDescription
Safety, security and robustnessSystems should function robustly and securely throughout their lifecycle, with risks continually identified, assessed and managed.
Appropriate transparency and explainabilityEnough information about a system, in the right form, for the people affected and for the regulator.
FairnessSystems should not undermine the legal rights of individuals or organisations, discriminate unfairly, or create unfair market outcomes.
Accountability and governanceGovernance measures with clear lines of accountability across the lifecycle.
Contestability and redressRoutes for affected parties to contest a harmful outcome or decision.

Their legal status is: none, directly. They do not create rights or duties. They matter because regulators use them to structure guidance issued under powers they already have, and that guidance is often relevant to whether you have met a statutory standard — whether your processing was fair under data protection law, whether your product was safe, whether your conduct met the Consumer Duty.

What each regulator has published

This is the part that actually answers the question, because the regulator with jurisdiction over you is the one whose publications bind your practice.

RegulatorDescription
Information Commissioner's OfficeThe most consequential for most companies. Ran a consultation series on generative AI and data protection through 2024 covering lawful basis for web-scraped training data, purpose limitation across the model lifecycle, accuracy, and controller-processor allocation across the supply chain, and published its outcomes. Also maintains longer-standing guidance on AI and data protection and on explaining decisions made with AI, the latter produced with the Alan Turing Institute.
Financial Conduct AuthorityPosition is that the existing framework — the Senior Managers and Certification Regime, the Consumer Duty, operational resilience rules — already covers AI, and that no new AI rulebook is needed. Published an AI update in 2024 and subsequently opened supervised testing arrangements for firms deploying AI.
Bank of England and Prudential Regulation AuthorityModel risk management principles for banks apply directly to models used in regulated activities. The Bank and the FCA run a periodic joint survey of AI use in UK financial services; the third edition, published in 2024, reported that a large majority of responding firms were using AI in some form.
Competition and Markets AuthorityReviewed foundation models from 2023 and published an update in 2024 setting out principles aimed at competition and consumer outcomes — access to inputs, diversity of models, choice for businesses, fair dealing, transparency and accountability.
OfcomOnline Safety Act duties reach generative AI where a service allows user-generated content sharing or search. Ofcom has stated publicly that chatbots and generative tools can fall within scope, which surprises a lot of product teams who assumed the Act was about social networks.
MHRARegulates AI as a medical device under the existing device framework, and runs a regulatory sandbox for AI-enabled devices to work through evidence questions before a submission.
Equality and Human Rights CommissionEnforces the Equality Act 2010, which applies to discriminatory outcomes from automated systems exactly as to any other cause.

The law that already binds you

Absence of an AI act is not absence of law. The instruments below apply to AI systems without mentioning them, and they are what a UK claim would actually be brought under.

  • UK GDPR and the Data Protection Act 2018. Lawful basis, fairness, purpose limitation, accuracy, data subject rights, and rules on solely automated decisions with legal or similarly significant effects. This is the framework with the largest fine ceiling and the most enforcement history.
  • Equality Act 2010. Direct and indirect discrimination, and the public sector equality duty. A model that produces a disparate outcome on a protected characteristic is a discrimination question, not an AI question.
  • Consumer Protection from Unfair Trading Regulations, and now the Digital Markets, Competition and Consumers Act 2024. The DMCC’s consumer protection regime commenced in April 2025 and gives the CMA the power to determine breaches and impose penalties directly, up to a percentage of global turnover. Overstated AI claims sit here. See enforcement against exaggerated AI claims.
  • Online Safety Act 2023. Duties on user-to-user and search services, which can capture generative features.
  • Copyright, Designs and Patents Act 1988. The text and data mining exception in section 29A covers non-commercial research only, which is the crux of the UK training data question.
  • Sector rules. FCA Handbook, PRA Rulebook, medical device regulations, and the general law of negligence and contract.

The Data (Use and Access) Act 2025

The one significant statutory change in this area is the Data (Use and Access) Act 2025, which received Royal Assent in June 2025. It amends UK data protection law in several ways, and the change that matters most for AI is the reworking of the rules on solely automated decision-making.

Broadly, the previous position was a general prohibition on solely automated decisions producing legal or similarly significant effects, with narrow exceptions. The Act restructures this so that such decisions are permitted more widely, subject to safeguards — information for the individual, the ability to make representations, to obtain human intervention and to contest the decision — with tighter rules retained where special category data is involved. This page does not give a section number for those provisions; take the Act’s own text from legislation.gov.uk and read the safeguards in full, because the safeguards, not the permission, are where the compliance work sits.

Note the direction of travel this creates: on automated decisions, UK and EU law are now less aligned than they were, which is a live question for anyone relying on the UK’s adequacy status.

Bills, and why none of them is law

Several attempts to legislate have been made and none has produced a statute of general application:

  • Private members’ bills, including an Artificial Intelligence (Regulation) Bill introduced in the House of Lords and reintroduced in later sessions, proposing an AI Authority and statutory principles. Private members’ bills without government support rarely progress, and these did not.
  • A government AI bill has been trailed repeatedly, aimed at the most capable frontier models rather than at applications generally. As at this review date no such bill had been enacted.

The institutional development that did happen: the AI Safety Institute, established in 2023, was renamed the AI Security Institute in early 2025. It evaluates frontier models. It is not a regulator, has no enforcement powers, and cannot approve or prohibit a system.

If you sell into the EU as well

Most UK companies of any size do, and the practical consequence is usually that the EU AI Act sets the ceiling and the UK position sets nothing. Article 2 of the EU Act reaches providers placing systems on the Union market wherever they are established, and providers and deployers in third countries where the system’s output is used in the Union.

The efficient plan for a UK company with EU customers is therefore to build to the EU classification and treat the UK principles as satisfied by the same work, while watching two UK-specific divergences: the automated decision rules above, and the copyright position on training data, which is more restrictive in the UK than in the EU rather than less.