The United Kingdom has no AI Act, and no government bill to create one. It has instead left AI oversight to the regulators that already hold each sector, applying the powers they already had. For deployers, that makes the compliance question not "what does the AI Act require" but "which of my existing obligations does this AI system engage, and which regulator will ask about it". The answer changed materially in February 2026, when the automated decision-making provisions of UK data protection law were replaced. This analysis maps what is actually binding, and separates it from what is only guidance.
Key takeaways
- The UK has not passed an AI statute and no government bill proposes one. The only live AI bill is Lord Holmes of Richmond's Artificial Intelligence (Regulation) Bill, a private member's bill that has sat at first reading in the Lords since 4 March 2025.
- The most consequential UK change is not AI-specific. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 UK GDPR with Articles 22A to 22D, fully in force 5 February 2026. Solely automated significant decisions are no longer broadly restricted; the restriction now bites where special category data is involved, and other significant decisions are permitted subject to safeguards.
- The FCA has stated publicly that it does not plan to introduce extra regulations for AI, relying on Consumer Duty, the Principles for Businesses and SM and CR instead. Treat its AI material as supervisory expectation, not as a rulebook.
- The AI Security Institute, renamed from the AI Safety Institute on 14 February 2025, says on its own pages that it is not a regulator and will not determine government regulation. It evaluates advanced models. It does not supervise deployers.
- The binding instruments a UK deployer actually answers to are UK GDPR and the Data Protection Act 2018, the FCA Handbook for regulated firms, PRA supervisory statement SS1/23 for banks with internal model approval, the Online Safety Act 2023 for user-to-user services, and the Medical Devices Regulations 2002 for clinical AI. Everything else is guidance.
The structural choice: sectors over a statute
On 29 March 2023, the UK government published "AI regulation: a pro-innovation approach", from what was then the Department for Science, Innovation and Technology and the Office for Artificial Intelligence. It set out five cross-sectoral principles: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. It assigned responsibility for applying them to existing sector regulators rather than creating a single AI regulator or a comprehensive statute.
The document that actually operationalised this was the government response, published 6 February 2024. It asked regulators to publish updates outlining their strategic approach to AI by 30 April 2024. Those updates are the reason the ICO, FCA, CMA and others each have an AI position at all, and they are the right place to look for what a given regulator will ask about.
The AI Opportunities Action Plan followed on 13 January 2025, setting out fifty recommendations to grow the UK AI sector and drive adoption across the economy. It is an industrial strategy document rather than a regulatory one. It does not announce a decision against legislating, and this guide previously said it did.
Three years on, the position is unchanged in the only sense that matters legally. Parliament's own bill records show no government AI bill and no AI Act. The Artificial Intelligence (Regulation) Bill, introduced by Lord Holmes of Richmond, has been at first reading in the Lords since 4 March 2025 and has not progressed. A private member's bill at first reading is not a signal of imminent law.
The practical consequence for deployers is that there is no single compliance checklist for the UK. There is a set of sector-specific expectations, each shaped by the regulator responsible for that sector, each enforced through that regulator's existing tools and powers. A financial services firm deploying AI in client risk scoring faces a different regulatory conversation than a healthcare technology company using AI in clinical decision support, even though both are deploying high-consequence AI systems.
The change that actually mattered: automated decisions after the Data (Use and Access) Act
The Data (Use and Access) Act 2025, 2025 c. 18, received Royal Assent on 19 June 2025. Section 80 removed Article 22 UK GDPR and replaced it with Articles 22A to 22D. Section 80 was partly in force at Royal Assent and came fully into force on 5 February 2026.
The change is substantive, not cosmetic. Under the old Article 22, a decision based solely on automated processing that produced legal or similarly significant effects was prohibited unless one of three narrow conditions applied. Under the new structure, Article 22B restricts such decisions where special category data is involved. Article 22C permits other significant automated decisions provided the controller puts safeguards in place: informing the data subject, allowing representations, providing human intervention, and allowing the decision to be contested. Article 22A introduces a test of whether there was "meaningful human involvement", and the Act shifts the statutory language from a decision based "solely on" automated processing to one based "on entirely" automated processing.
For a deployer, this cuts both ways. The default position on automated significant decisions is more permissive than it was, which is the point of the reform. But the safeguards in Article 22C are now the operative compliance obligation, and any programme built against the old Article 22 wording is describing a provision that no longer exists. The ICO's own AI guidance carries a notice that it is under review as a result of this Act, so it should be read with that in mind.
The Financial Conduct Authority
The FCA is the UK regulator most engaged with AI in practice, because financial services is where deployment is deepest and commercial stakes are highest. It is worth being precise about what that engagement is. The FCA's own AI approach page, first published 8 September 2025 and last updated 13 February 2026, states: "Our regulatory approach is principles-based and focused on outcomes. We do not plan to introduce extra regulations for AI. Instead, we'll rely on existing frameworks, which mitigate many of the risks associated with AI."
The Consumer Duty is the primary frame through which the FCA evaluates AI in retail financial services. Policy Statement PS22/9, "A new Consumer Duty", was published 27 July 2022; the Duty came into force on 31 July 2023 for new and existing open products and 31 July 2024 for closed products. It requires firms to deliver good outcomes for retail customers across four areas: products and services, price and value, consumer understanding, and consumer support. AI systems deployed in these areas are assessed against those outcome standards, not merely tested for technical accuracy.
In practice, this means a credit scoring model that produces accurate predictions but applies them in a way that creates poor outcomes for a class of customers can fail the Duty even where the model is technically sound. The outcome is what the Duty measures. Note that since 27 February 2025 the FCA no longer expects firms to maintain a Consumer Duty board champion, so any governance design still resting on that role is out of date.
The Senior Managers and Certification Regime is relevant but is often overstated. The FCA says the regime's rules emphasise accountability for senior managers and are relevant to the safe use of AI. There is no prescribed senior manager responsibility for AI governance in the regime, and an earlier version of this guide asserted one. What a firm should take from SM and CR is that AI decisions sit inside existing senior manager responsibilities rather than outside them, not that a new named AI accountability must be filed.
The FCA's actual AI publication is the "Artificial Intelligence (AI) Update", first published 22 April 2024 in response to the government's white paper response. There is no FCA discussion paper on AI in financial services; an earlier version of this guide cited "DP24/1" for that proposition, and DP24/1 is the FCA's discussion paper on the regulation of commercial and bespoke insurance business, published 29 July 2024.
The FCA AI Lab page was first published on 13 October 2024, not 2023. It is now the most useful practical route into the regulator. It hosts AI Live Testing, whose second cohort took applications from 19 January to 24 March 2026 with testing beginning in late April 2026, the Supercharged Sandbox run with NVIDIA, AI Spotlight and AI Sprint. For a firm that wants a supervisory conversation before deploying rather than after, this is the door.
The Prudential Regulation Authority and model risk
For banks, the closest thing in UK financial services to a binding AI-adjacent governance expectation is not an AI instrument at all. PRA supervisory statement SS1/23, "Model risk management principles for banks", was published on 17 May 2023 and took effect on 17 May 2024, with the current version published and effective 23 April 2026.
SS1/23 expressly reaches AI. Its sub-principles include identifying and managing the risks associated with the use of artificial intelligence in modelling techniques such as machine learning. Its scope is narrower than a general AI rule: it applies to UK-incorporated banks, building societies and PRA-designated investment firms that have internal model approval for credit risk, market risk or counterparty credit risk. A firm inside that perimeter deploying AI in a model covered by it should treat SS1/23, not any AI guidance, as the governing document.
The Information Commissioner's Office
The ICO's jurisdiction extends to any AI system that processes personal data. In the UK economy in 2026, that encompasses almost every AI system deployed in a commercial context, because almost every AI system processes some form of personal data in training, operation, or output.
The ICO's "Guidance on AI and data protection" was last updated on 15 March 2023, and the ICO's own page now carries a notice that it is under review and may change because of the Data (Use and Access) Act. It covers the UK GDPR obligation set as applied to AI. The requirements it maps for deployers come from the legislation, not from the guidance: data protection impact assessments for high-risk processing under Article 35 UK GDPR; a documented lawful basis for training data, operational data and output data at each stage; accuracy and fairness under the data protection principles; transparency under Articles 13 and 14; and, since 5 February 2026, the safeguards regime for significant automated decisions under Articles 22A to 22D rather than the former Article 22 prohibition. The ICO also publishes an AI and data protection risk toolkit, a downloadable workbook that is the most practical artefact it has produced, and it is flagged as under the same review.
On generative AI, what exists is a consultation response rather than guidance. The ICO ran a five-part consultation series through 2024 and published "Information Commissioner's Office response to the consultation series on generative AI" on 12 December 2024. It sets out policy positions on the lawful basis for training data, on outputs containing personal data, and on the allocation of controllership, and it says on its face that it does not cover the entirety of the ICO's regulatory expectations. An earlier version of this guide described it as 2024 guidance, which overstates its status.
The forward-looking document is the ICO's AI and biometrics strategy, "Preventing harm, promoting trust", published in June 2025, with a formal update in March 2026. The update confirms that draft guidance on automated decision-making and profiling is coming and will feed an AI and automated decision-making code of practice. For a deployer, that code is the thing to watch: a statutory code carries weight that guidance does not.
An earlier version of this guide described an ICO "ChatGPT investigation" and preliminary guidance flowing from it. No such investigation or guidance could be found anywhere on ico.org.uk, and the claim has been removed. The underlying practical point stands on its own: a UK deployer relying on a foundation model from a third-party provider is a controller in its own right for the processing it directs, and cannot rely on the provider's compliance to discharge its own.
The Competition and Markets Authority
The CMA published "AI Foundation Models: Initial report" on 18 September 2023 and has followed it with ongoing monitoring of AI market dynamics. Its focus is on competition and market structure rather than individual deployment obligations. For AI deployers, the CMA's practical significance is in the market infrastructure they rely on: the concentration of foundation model providers, the terms on which cloud hyperscalers provide AI compute, and the conditions attached to AI-enabled digital markets.
The Digital Markets, Competition and Consumers Act 2024 received Royal Assent on 24 May 2024. It gives the CMA powers to designate firms with strategic market status in digital activities and impose conduct requirements on them. AI companies that reach sufficient scale in the UK market may become subject to that regime. For the deployers who rely on them, conduct requirements on designated firms could translate into improved interoperability, portability and transparency from the AI providers they buy from.
The AI Security Institute
The AI Safety Institute was established in November 2023, evolving from the Frontier AI Taskforce. It was renamed the AI Security Institute on 14 February 2025, in a DSIT announcement that set the reason plainly: a focus on serious risks with security implications, including chemical and biological weapons capability, cyber attacks, fraud and child sexual abuse material. The then Secretary of State said it "will not focus on bias or freedom of speech". An earlier version of this guide attributed the rename to the AI Opportunities Action Plan, which is a different document from a different month.
The Institute is not a regulator. gov.uk states this in terms: "The Institute is not a regulator and will not determine government regulation." Its own site describes it as a research organisation within DSIT. Its three core functions are evaluations of advanced AI systems, foundational safety research, and information exchange.
For enterprise deployers, the Institute's significance is indirect. It does not supervise deployers, issue compliance guidance or take enforcement action. What it produces are evaluations of frontier models, which inform the government's own risk assessment and could bear on whether a given model class is acceptable in public sector procurement. Nothing it publishes creates an obligation on a private deployer.
Ofcom and the MHRA
Ofcom's Online Safety Act 2023 powers require user-to-user and search services to assess risk and put safety measures in place, including for AI-generated content. The regime was phased rather than switched on at once: Ofcom published the first illegal harms codes of practice and guidance on 16 December 2024, giving providers three months to complete their illegal content risk assessments, with more than forty safety measures to be introduced from March 2025. An earlier version of this guide said the powers were fully in force from 2024, which compresses a phased commencement into a single year.
The Medicines and Healthcare products Regulatory Agency regulates AI as a medical device where the system meets the definition under the Medical Devices Regulations 2002. AI that makes or substantially influences clinical diagnosis, treatment recommendation or patient triage is typically in scope. Its guidance, "Medical devices: software and artificial intelligence (AI)", was first published on 6 April 2023 and last updated on 3 February 2025. This is the one UK sector where AI deployment genuinely does trigger a pre-market authorisation regime.
UK versus EU: the divergence in practice
Cross-border operators deploying AI in both the UK and EU face genuinely different regulatory environments. The EU AI Act imposes a horizontal, mandatory, documented compliance regime for high-risk AI that applies uniformly across sectors. The UK regime is sector-specific, principles-based, and enforced through existing regulatory relationships.
The documentation a deployer needs for EU AI Act compliance, the risk management system under Article 9, the oversight register under Article 26(2), the FRIA under Article 27, does not have direct UK equivalents unless a sector regulator has specifically required equivalent documentation. An FCA-regulated firm may need to produce similar documentation to satisfy Consumer Duty outcome monitoring requirements, but the format, content, and regulator-facing presentation differ.
For the EU regulatory framework in full, see the EU AI Act operator provisions on the EU regulatory desk. For the cross-jurisdictional comparison covering US, EU, and UK in a single framework, see US, EU, UK: three approaches to the same question.
Practical implications for UK deployers in 2026
A UK enterprise deploying AI in 2026 without a formal governance programme is exposed, but not to an AI Act. It is exposed to the regulator responsible for its sector, acting under powers that predate AI entirely. The FCA can act on Consumer Duty failures through fines, business restrictions and senior manager sanctions. The ICO can issue enforcement notices and, under section 157 of the Data Protection Act 2018, fines up to a higher maximum of GBP 17.5 million or 4 per cent of total annual worldwide turnover, whichever is higher, with a standard maximum of GBP 8.7 million or 2 per cent. Ofcom's Online Safety Act powers carry substantial penalties of their own.
There is no published regulator baseline for AI governance, and any document that offers one is offering an opinion. What follows is ours, assembled from the obligations that actually bind: a documented inventory of AI systems and what each one decides; for every system touching personal data, a lawful basis and, where Article 35 is engaged, a data protection impact assessment; for any system making significant automated decisions, the Article 22C safeguards in operable form, meaning a real route to human intervention and contestation rather than a policy that says one exists; for FCA-regulated firms, evidence that outcomes under the Consumer Duty have been tested rather than assumed; for banks inside the SS1/23 perimeter, the model risk documentation that statement already requires; and an incident procedure that names who decides to switch a system off. This is a defensible position in a supervisory conversation. It is not a certification, and no UK regulator has said it is sufficient.
For the connection between this documentation baseline and insurance coverage eligibility, see the AI agent underwriting submission guide on the coverage platform. The documentation that UK regulators require and the documentation that insurers need to underwrite AI risk share significant structural overlap.
Frequently asked questions
Does the UK have a comprehensive AI Act equivalent in 2026?
No, and no government bill proposes one. Five cross-sectoral principles from the March 2023 white paper are applied by existing regulators in their domains, operationalised by the government response of 6 February 2024. The only live AI bill in Parliament is Lord Holmes of Richmond's Artificial Intelligence (Regulation) Bill, a private member's bill at first reading in the Lords since 4 March 2025.
What is the role of the UK AI Security Institute in 2026?
It evaluates advanced AI models for serious risks with security implications, including chemical and biological weapons capability, cyber attacks, fraud and child sexual abuse material. It was renamed from the AI Safety Institute on 14 February 2025. gov.uk states that the Institute is not a regulator and will not determine government regulation. It does not supervise deployers or issue compliance guidance.
What does the FCA expect from financial services firms using AI agents?
The FCA has stated that it does not plan to introduce extra regulations for AI and will rely on existing frameworks. In practice that means the Consumer Duty outcomes, the Principles for Businesses, and the accountability that Senior Managers already hold. There is no prescribed senior manager responsibility for AI governance. Firms should be able to show that customer outcomes from AI-assisted decisions have been tested rather than assumed.
How does the ICO regulate AI systems processing personal data in the UK?
Through UK GDPR and the Data Protection Act 2018. Key requirements are a documented lawful basis, data protection impact assessments under Article 35 where high-risk processing is engaged, transparency under Articles 13 and 14, and, since 5 February 2026, the safeguards regime for significant automated decisions under Articles 22A to 22D, which replaced Article 22. The ICO's AI guidance is currently under review because of the Data (Use and Access) Act 2025.
What changed for automated decisions in UK law in 2026?
Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 UK GDPR with Articles 22A to 22D, fully in force on 5 February 2026. The blanket restriction on solely automated significant decisions now applies where special category data is involved. Other significant automated decisions are permitted subject to safeguards: informing the data subject, allowing representations, providing human intervention and allowing the decision to be contested.
Is the UK AI regulatory framework diverging from the EU AI Act?
Yes, materially. The EU framework is horizontal, mandatory and uniform across sectors. The UK framework is sector-specific and rests on instruments that predate AI. Cross-border operators need to map and satisfy each regime independently. EU AI Act documentation does not automatically satisfy FCA or ICO expectations without adaptation.
References
- Department for Science, Innovation and Technology and Office for Artificial Intelligence. "AI regulation: a pro-innovation approach", 29 March 2023, with minor corrections to Annex C on 3 August 2023. gov.uk.
- UK Government. "A pro-innovation approach to AI regulation: government response", 6 February 2024, setting the 30 April 2024 deadline for regulators to publish their strategic approach to AI. gov.uk.
- UK Government. AI Opportunities Action Plan, 13 January 2025. gov.uk.
- Data (Use and Access) Act 2025, 2025 c. 18, Royal Assent 19 June 2025. Section 80 replaces Article 22 UK GDPR with Articles 22A to 22D, fully in force 5 February 2026 by S.I. 2026/82 reg. 2(j). legislation.gov.uk.
- Data Protection Act 2018, section 157 (maximum penalties). legislation.gov.uk.
- Financial Conduct Authority. "Our approach to AI", first published 8 September 2025, updated 13 February 2026. fca.org.uk.
- Financial Conduct Authority. PS22/9 "A new Consumer Duty", 27 July 2022; in force 31 July 2023 for open products and 31 July 2024 for closed products.
- Financial Conduct Authority. "Artificial Intelligence (AI) Update", 22 April 2024, and the FCA AI Lab, page first published 13 October 2024, including AI Live Testing and the Supercharged Sandbox.
- Prudential Regulation Authority. SS1/23 "Model risk management principles for banks", published 17 May 2023, effective 17 May 2024; current version published and effective 23 April 2026. bankofengland.co.uk.
- Information Commissioner's Office. "Guidance on AI and data protection", updated 15 March 2023, and the AI and data protection risk toolkit, both currently under review following the Data (Use and Access) Act. ico.org.uk.
- Information Commissioner's Office. "Response to the consultation series on generative AI", 12 December 2024. A consultation response, not guidance.
- Information Commissioner's Office. "Preventing harm, promoting trust: our AI and biometrics strategy", June 2025, and the AI and biometrics strategy update, March 2026.
- Competition and Markets Authority. "AI Foundation Models: Initial report", 18 September 2023. gov.uk.
- Digital Markets, Competition and Consumers Act 2024, Royal Assent 24 May 2024. legislation.gov.uk.
- Ofcom. Illegal harms codes of practice and guidance, published 16 December 2024, with safety measures introduced from March 2025, under the Online Safety Act 2023.
- Medicines and Healthcare products Regulatory Agency. "Medical devices: software and artificial intelligence (AI)", first published 6 April 2023, last updated 3 February 2025. gov.uk.
- UK Parliament. Artificial Intelligence (Regulation) Bill [HL], bill 3942, first reading 4 March 2025, not an Act. bills-api.parliament.uk.
- Regulation (EU) 2024/1689 (EU AI Act), Articles 9, 26, 27, for comparison only.