Skip to content

The UK's Pro-Innovation Approach: Five Principles, No Statute

8 min read · updated August 11, 2026

The UK does not have an AI act, and until 2023 that looked like an absence. The white paper made it a design: five principles, no statute, no new regulator, and enforcement left entirely to whichever existing body already had jurisdiction over the harm.

The instrument and its status

The document is A pro-innovation approach to AI regulation, command paper CP 815, published by the Department for Science, Innovation and Technology on 29 March 2023. Its consultation closed on 21 June 2023 and the government response was published on 6 February 2024. It is a policy document. It creates no rights, imposes no duties, and has no commencement date, and every statement in it about what organisations should do is addressed to regulators rather than to firms. It is published on gov.uk.

Because the white paper is not law, nothing in it can be complied with or breached directly. Your obligations come from the statutes and rules the regulators administer. This page is not legal advice; if you are trying to work out what applies to a specific system, start from the sector regulator, not from the white paper.

The five principles

The framework sets out five cross-sectoral principles that regulators are asked to apply within their remits, on a non-statutory footing initially with the possibility of a statutory duty to have due regard to them later.

  • Safety, security and robustness. AI systems should function robustly and securely throughout their lifecycle, with risks continually identified, assessed and managed.
  • Appropriate transparency and explainability. Note “appropriate”: the principle is calibrated to context rather than absolute, and the white paper expressly declines to require a uniform level of explanation.
  • Fairness. AI should not undermine the legal rights of individuals or organisations, discriminate unfairly, or create unfair market outcomes — a formulation that leans on existing equality and consumer law rather than defining fairness afresh.
  • Accountability and governance. Governance measures should ensure effective oversight, with clear lines of accountability across the lifecycle.
  • Contestability and redress. Where appropriate, users and affected third parties should be able to contest a harmful outcome or decision through existing routes.

Deliberately, these attach to the use of a system in a context, not to the system itself. There is no equivalent of a product classification, which is the structural difference from the EU’s risk tiers.

Delivery through existing regulators

The framework asks each regulator to interpret and apply the principles within its own domain, using powers it already has. In February 2024 the government asked a set of regulators to publish their approach by 30 April 2024, and several did: the FCA published its AI Update, the ICO its strategic approach, and Ofcom, the CMA, the MHRA, the Equality and Human Rights Commission and others published theirs. Central support functions sit in DSIT: monitoring risk, horizon scanning, coordination across regulators, and support for regulator capability, alongside a multi-agency advisory service piloted for firms navigating overlapping remits.

This is why a UK firm’s AI obligations are found in a handbook and not in an AI act. For financial services that means the provisions set out in the FCA and PRA approach; for personal data it means the ICO’s guidance; for platforms it means the Online Safety Act.

The practical consequence for a compliance function is that there is no single register to consult and no completeness test. You establish which regulators have jurisdiction over the activity — which for a consumer fintech with a chatbot is at least the FCA, the ICO and, depending on how it advertises, the CMA and the Advertising Standards Authority — and then read each one’s published approach. Two regulators can reach different conclusions about the same system without either being wrong, because they are applying different statutes to different aspects of it. The government response of February 2024 acknowledged the coordination problem and answered it with a central function in DSIT rather than with a tie-breaker.

What it deliberately does not do

The omissions are the argument, and each was defended in the document rather than left implicit.

  • No cross-sector AI statute. The government’s stated reason is that legislating early risks fixing rules against a technology that is moving, and that existing regulators already cover most harms.
  • No AI regulator. Creating one would, on the white paper’s reasoning, duplicate expertise that sits with sector regulators and introduce boundary disputes.
  • No legal definition of AI. The paper uses adaptivity and autonomy as characteristics rather than defining a regulated object. Nothing turns on whether a system is “AI” because no obligation attaches to that label.
  • No obligations on model developers as such. There is no UK analogue to the EU’s general-purpose AI obligations; a developer’s duties arise only where its own conduct falls within a regulator’s remit.
  • No conformity assessment, marking or registration. Nothing to notify, nothing to certify, no database.

The identified weakness follows directly: where no regulator has jurisdiction, nothing applies. The white paper acknowledges gaps and proposes to monitor them rather than to close them in advance, and the House of Commons Science, Innovation and Technology Committee and others have pressed on exactly that point.

Where the position stands

Two developments are worth stating with their status. The AI Safety Institute was established in November 2023 as a directorate within DSIT to evaluate advanced models; it was renamed the AI Security Institute in February 2025. It is a research and evaluation body with no regulatory powers, and its model access arrangements are voluntary.

The framework is also not a shield from other jurisdictions. A UK developer or deployer placing a system on the EU market, or whose output is used in the Union, can be caught by the EU AI Act’s extraterritorial provisions regardless of the UK’s own approach, which is why several UK firms are running an EU-shaped compliance programme with no UK obligation behind it. Read the white paper as describing what the UK will require of you, not as describing the total set of requirements you face.

Legislation on the most powerful models has been signalled repeatedly — including in the King’s Speech of July 2024, which referred to establishing appropriate requirements for those developing the most powerful AI models — without a government bill being introduced and passed at the time of writing. A private member’s bill, the Artificial Intelligence (Regulation) Bill introduced in the Lords by Lord Holmes of Richmond, proposed an AI Authority and fell when Parliament was dissolved. Anyone planning around a future UK AI statute should note that no such statute has been enacted, and should say “proposed” when describing one.