There is no UK AI Act. Your AI still answers to old laws, a new rule on automated decisions, and the EU AI Act where its output is used in the EU.
AI Regulation in the UK 2026: What Applies to Your Business
By James Cotton · Last updated · 9 min read
Part of our topic guides on AI Governance & Data Strategy and AI Skills for Business.
By James Cotton, Founder, iO-Sphere
Every entry below was checked against its source on 1 October 2026, and the register is re-checked each month.
The register
| Rule | In force since | Regulator |
|---|---|---|
| UK GDPR and Data Protection Act 2018 | 25 May 2018 | Information Commission (ICO) |
| Automated decision-making rules | 5 February 2026 | Information Commission (ICO) |
| Equality Act 2010 (tribunal compensation) | 1 October 2010 | Tribunals |
| Digital Markets, Competition and Consumers Act 2024 | 6 April 2025 (fining power) | CMA |
| EU AI Act | 2 August 2026 (general application) | National market surveillance authorities (AI literacy duty); the AI Office (general-purpose models) |
The data regulator in the first two rows has a new legal form. On 30 September 2026 the office of Information Commissioner was abolished and its functions passed to the Information Commission (SI 2026/1015). It still works under the name ICO, and guidance published before that date was issued by the ICO.
The maximum penalties are set in statute, and each figure here is a ceiling. Under data protection law, the automated decision rules included, a fine can reach £17.5 million or, for an undertaking, 4% of worldwide annual turnover in the preceding financial year, whichever is higher. The CMA can fine up to £300,000 or, if higher, 10% of turnover in and outside the UK. The Equality Act sets no upper limit on tribunal compensation.
Which rows are yours
Four questions sort most businesses.
Does your AI process personal data? Then data protection law applies to it. The code of practice the Information Commission must prepare is about this too: processing personal data in developing and using AI.
Does software take significant decisions about people with nobody meaningfully involved? Then the automated decision rules apply. An illustration of ours: an online loan application scored and declined by software, with no person reviewing the result before the applicant is told. Nobody was meaningfully involved, so the question left is whether the refusal has a legal or similarly significant effect on the applicant.
Do you sell to consumers or advertise to them? Then consumer law applies, AI agents included, and so do the advertising rules.
Is your AI's output used in the EU? Then the EU AI Act may reach you, from wherever you are based.
Equality law runs alongside all four. If a decision your AI shaped leads to a discrimination claim that succeeds in a tribunal, the tribunal can order compensation, and the Act sets no upper limit on it.
The rules on automated decisions
Articles 22A to 22D of the UK GDPR replaced the old Article 22 for decisions taken on or after 5 February 2026. A decision is solely automated "if there is no meaningful human involvement in the taking of the decision". It is significant if it has a legal effect on the person, or a "similarly significant effect".
If a decision like the loan example is solely automated and significant, the business must have safeguards that tell the person about the decision and let them make representations, obtain human intervention and contest it. For decisions about applicants and staff, data and AI skills for HR teams goes further.
Two limits are tighter. A solely automated significant decision cannot rest on the recognised legitimate interests basis at all. One that uses special category data needs explicit consent, or a contract or legal requirement together with a condition in Article 9(2)(g).
Advertising, chatbots and regulated sectors
The ASA said in May 2025 that "There is no blanket legal requirement in the UK to disclose the use of AI in ads". What does apply to campaigns and customer-facing output is worked through in AI governance in marketing operations.
Some chatbots fall under the Online Safety Act. Ofcom says one is outside it if users interact only with the chatbot, it does not search multiple websites or databases, and it cannot generate pornographic content. Where the Act applies, the ceiling is the greater of £18 million and 10% of qualifying worldwide revenue.
Financial services and healthcare have their own regulators. The FCA says it does "not plan to introduce extra regulations for AI". The PRA's model risk principles for banks, SS1/23, took effect on 17 May 2024.
In health, the National Commission into the Regulation of AI in Healthcare's recommendations for a future framework were published on 10 September 2026; they are recommendations, not law. At this check we found no AI-specific binding rules from the FCA, PRA, MHRA, Ofgem or Ofcom. AI governance in regulated sectors takes each sector in turn.
Is there a UK AI law?
There is no UK AI Act. The King's Speech of 13 May 2026 announced no AI bill; in its briefing notes, AI appeared only under the Regulating for Growth Bill's sandbox powers. Lord Holmes's AI regulation bill fell at the end of the last session, and at this check the only AI-titled bill before Parliament was the Artificial Superintelligence Bill, a ten minute rule bill.
How the UK approach was built
Every UK government document on this page dated before 20 July 2026 came from an earlier government: gov.uk records the Starmer government as ending on that date, and Andy Burnham is now Prime Minister.
The March 2023 white paper proposed five principles for existing regulators to interpret within their remits, and the Sunak government confirmed them on a non-statutory basis in its response of 6 February 2024:
- Safety, security and robustness
- Appropriate transparency and explainability
- Fairness
- Accountability and governance
- Contestability and redress
That response kept the approach "under review" and said the government "would consider introducing binding measures" if existing mitigations proved inadequate.
A joint letter published on 28 January 2026, from the then Technology and Business Secretaries (Liz Kendall and Peter Kyle) and other departmental Secretaries of State went to 19 regulators. It asked each to publish, by May 2026, a plan for how it would help enable safe AI-powered innovation, with steps such as publishing guidance on how existing rules apply to AI, and to report every year after.
The ICO, CMA, FCA and PRA were among the 19; Ofcom and the Equality and Human Rights Commission were not. The ICO's reply of 27 May 2026 committed it to "develop an AI & ADM statutory code of practice". A business building its own controls can start from an AI governance framework for a UK business.
When the EU AI Act reaches a UK business
Being based in the UK does not settle it. Article 2(1) applies the Act to providers putting AI systems on the EU market wherever they are established, and also to:
"(c) providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union"
The Digital Omnibus on AI (Regulation (EU) 2026/1744) came into force on 27 July 2026, left that paragraph unchanged, and set new dates. The calendar now runs:
- 2 February 2025: prohibited practices and the AI literacy duty
- 2 August 2025: obligations on providers of general-purpose AI models
- 27 July 2026: the Omnibus in force; Articles 102 to 110 apply
- 2 August 2026: general application, including the Article 50 transparency duties; the AI Office gains enforcement powers over general-purpose AI models
- 2 December 2026: two new prohibitions (non-consensual intimate imagery and child sexual abuse material); providers of generative systems that were on the market before 2 August 2026 must meet Article 50(2) by this date
- 2 December 2027: high-risk systems under Annex III, the stand-alone high-risk uses
- 2 August 2028: high-risk systems under Annex I, AI built into regulated products
The European Commission sorts systems into four tiers: unacceptable risk, high risk, transparency risk, and minimal or no risk. Whether yours is high-risk depends on whether its use appears in Annex III or it sits inside a product covered by Annex I.
The fines under Article 99 are tiered. Prohibited practices alone carry up to EUR 35 million or 7% of total worldwide annual turnover for the preceding financial year. Other operator obligations, Article 50 transparency included, carry up to EUR 15 million or 3%, and incorrect information to authorities EUR 7.5 million or 1%. For an undertaking the ceiling is whichever is higher; for SMEs, whichever is lower.
The AI literacy duty after July 2026
The Omnibus rewrote Article 4. Providers and deployers must now "take measures to support the development of AI literacy of their staff" and of others operating AI on their behalf, without having to "guarantee any specific level of AI literacy of any individual". The original wording was to "take measures to ensure, to their best extent, a sufficient level of AI literacy".
The Commission's AI literacy Q&A leaves the measures to the organisation: it says "no strict requirements or mandatory trainings are imposed", and "There is no need for a certificate. Organisations can keep an internal record of trainings and/or other guiding initiatives."
National market surveillance authorities enforce the duty from August 2026, and "Any sanction must be proportionate". The Q&A adds that deployers of high-risk systems must still have staff "sufficiently trained" for human oversight (Article 26); the high-risk dates are in the calendar above.
Training is one of the measures an employer can take, and the record of it, such as data and AI fluency training for a team, is evidence of the measures rather than a compliance certificate.
For the people who will own these rules inside a business, our Data & AI Governance apprenticeship (Level 4) runs on the Level 4 Data Protection and Information Governance Practitioner standard.
Still to come from the Information Commission
Since 12 May 2026 the law has required a code of practice on processing personal data in developing and using AI and in automated decision-making, with guidance on children's data. The duty now sits with the Information Commission (section 124A). There is no deadline in the law, and at this check no code had been published and no date given.
The regulator's guidance plans list final automated decision-making and profiling guidance for winter 2026; the draft's consultation closed on 29 May 2026. The same page still listed an agentic AI consultation for September 2026, with final guidance in autumn, though no consultation had been announced by the time of this check.
How many firms have heard of AI regulatory guidance
In DSIT's UK Business Data Survey 2026 (4,450 businesses, October 2025 to January 2026), 46% of the 1,870 AI-using businesses were not aware of any AI regulatory guidance. Among the same AI users, 17% had a policy or guidelines on AI and 82% had none (section 3.4).
Frequently asked questions
Does the EU AI Act apply if we only use an AI tool someone else built?
It can. The duties on general-purpose AI models bind the providers of those models; a UK business using such a tool is caught by Article 2(1)(c) where "the output produced by the AI system is used in the Union". If so, the AI literacy duty applies to it, and the Article 50 transparency duties may too, depending on what the system does.
Do we need ISO/IEC 42001 or the NIST framework?
No: both are voluntary. ISO/IEC 42001 is an international standard published in December 2023. The NIST AI Risk Management Framework 1.0, released on 26 January 2023, "is intended for voluntary use" and is being revised, with no date given.
Is there a fine for using AI without a policy?
None of the ceilings on this page is a fine for lacking a policy; each attaches to breaching its own law, such as taking an automated decision without the safeguards. For the EU literacy duty the Commission's Q&A says "no specific governance structure is mandated". A written staff policy is one way to record the measures you took: see a generative AI use policy for staff.
Upskilling a whole team?
Tailored data and AI training for organisations, from data literacy to technical upskilling, built around your team's real work.