The United Kingdom has no AI Act. That surprises engineers used to the EU's single regulation with risk tiers and conformity assessments. It also leads to a common mistake: assuming that no AI Act means no AI rules. The UK approach is to have existing regulators apply existing law to AI, guided by a short set of non-statutory principles. Data protection, equality, consumer, financial-services and online-safety law all already bind an AI system deployed in the UK.
This article explains how that model works, what changed through 2025 and 2026, and how to turn it into engineering controls: decision records for automated decisions, risk assessments for chatbots, and security controls from the government's AI cyber code. The facts were checked in October 2026. Several items are still moving: a promised AI bill, copyright policy and a cross-economy sandbox. Those are marked as pending, and you should confirm their status before relying on them.
Where things stand
The key milestones, in order:
- March 2023. The white paper "A pro-innovation approach to AI regulation" set out five cross-sector principles for regulators to apply within their existing remits, with no new regulator and no new statute.
- November 2023. The AI Safety Institute was set up around the Bletchley Park AI Safety Summit to evaluate frontier models.
- February 2024. The government's consultation response confirmed the approach, and key regulators were asked to publish how they would apply the principles.
- July 2024. The new government's King's Speech signalled legislation for the most powerful models. No AI bill had been introduced as of October 2026.
- January 2025. The AI Opportunities Action Plan set a growth-led agenda for compute, data and adoption.
- 31 January 2025. The voluntary Code of Practice for the Cyber Security of AI was published.
- 14 February 2025. The AI Safety Institute became the AI Security Institute, narrowing its focus to risks with security implications.
- 19 June 2025. The Data (Use and Access) Act 2025 received Royal Assent. Its automated decision-making reforms came into force on 5 February 2026.
- 18 March 2026. The government's report on copyright and AI said a broad text-and-data-mining exception with opt-out was no longer its preferred way forward. It set no legislative timetable.
- 14 September 2026. Parliament's Joint Committee on Human Rights published "Human Rights and the Regulation of AI", calling for a dedicated AI bill with risk tiers, prohibitions and an independent regulator able to withdraw systems. Government responses to select committees are normally due within two months.
How the regulator-led model works
The five principles are: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. They create no duties by themselves. Duties come from statutes that regulators already enforce, and the principles shape how regulators read those statutes when the subject is an AI system.
In practice, the regulator depends on what the system does and who it touches. The Information Commissioner's Office (ICO) covers personal data, which almost every AI system processes. Ofcom covers user-to-user and search services under the Online Safety Act 2023. The Financial Conduct Authority and the Prudential Regulation Authority cover conduct and model risk at regulated firms. The Competition and Markets Authority covers competition and consumer protection. The Equality and Human Rights Commission enforces the Equality Act 2010, which applies to a discriminatory model as to any other decision process. The Medicines and Healthcare products Regulatory Agency covers AI as a medical device. The Digital Regulation Cooperation Forum (CMA, FCA, ICO and Ofcom) coordinates where remits overlap.
The engineering consequence is that you can't answer "are we compliant with UK AI regulation?" in one place. You answer it per system, by listing which regimes the system touches and what evidence each expects. The table below maps each principle to the law that usually gives it force and a control you can build.
| Principle | Where the duty usually comes from | Control you can build |
|---|---|---|
| Safety, security, robustness | Sector safety law; UK GDPR security duty; AI cyber code (voluntary) | Threat model, red-team results, input/output scanners, incident runbook |
| Transparency, explainability | UK GDPR information duties; ADM safeguards; consumer law | Plain-language notice, per-decision reason codes, model documentation |
| Fairness | Equality Act 2010; UK GDPR fairness; FCA Consumer Duty for firms | Pre-release and ongoing outcome tests by protected characteristic, where lawful |
| Accountability, governance | UK GDPR accountability and DPIAs; senior-manager regimes | Named owner, DPIA, change log, model inventory |
| Contestability, redress | ADM safeguards (Article 22C); complaints duties; ombudsman schemes | Human review queue, appeal path, decision replay from logs |
Automated decisions after the Data (Use and Access) Act
For most product teams the most concrete change of the period is the Data (Use and Access) Act 2025. Section 80 replaced UK GDPR Article 22, which had in effect banned solely automated decisions with legal or similarly significant effects except in narrow cases, with new Articles 22A to 22D. From 5 February 2026, solely automated significant decisions using ordinary personal data are permitted, provided safeguards are in place. Decisions based on special category data, such as health or ethnicity, remain tightly restricted.
The safeguards in Article 22C require the controller to give the person information about decisions taken about them, to let them make representations, to obtain human intervention, and to contest the decision. These are engineering requirements as much as legal ones, because each needs a working system behind it. A minimal shape:
from dataclasses import dataclass, field
from datetime import datetime, timezone
import uuid
@dataclass
class DecisionRecord:
subject_id: str
decision: str # e.g. "decline_limit_increase"
significant: bool # legal or similarly significant effect?
solely_automated: bool # no meaningful human involvement?
special_category_used: bool # must be False on the automated path
model_version: str
inputs_ref: str # pointer to the exact features / prompt used
reasons: list[str] # plain-language reason codes shown to the person
decision_id: str = field(default_factory=lambda: str(uuid.uuid4()))
made_at: str = field(default_factory=lambda: datetime.now(timezone.utc).isoformat())
def finalise(rec: DecisionRecord, notify, review_queue):
if rec.special_category_used and rec.solely_automated and rec.significant:
review_queue.put(rec, reason="special-category data: route to human decision")
return "held"
if rec.significant and rec.solely_automated:
notify(rec.subject_id, rec.decision_id, rec.reasons,
actions=["make_representations", "request_human_review", "contest"])
return "issued"
def on_contest(decision_id, statement, store, review_queue):
rec = store.get(decision_id) # replay inputs + model version
review_queue.put(rec, reason="contest", statement=statement, sla_days=14)The 14-day review target in the sketch is a placeholder you set yourself, not a statutory figure. The parts that are hard to retrofit are replay and meaningfulness. You need to reproduce exactly what the model saw, so log a pointer to the features or prompt and pin the model version. And the human reviewer must be able to change the outcome. A reviewer who only confirms the model's output does not make a decision less automated. The ICO consulted on updated ADM guidance from 31 March to 29 May 2026. Check for the final version before you fix your design.
Generative AI under the Online Safety Act
If your product lets users share AI-generated content with other users, or your assistant searches across websites or databases, the Online Safety Act 2023 probably applies. Ofcom's open letter of 8 November 2024 said so explicitly. Chatbots inside user-to-user services are in scope, generative tools that search more than one site or database can be search services, and tools that can generate pornographic content carry their own duties.
In scope, the work is a set of written assessments plus controls that match them. You need an illegal content risk assessment, a children's access assessment and, if children are likely to use the service, a children's risk assessment. On the engineering side this maps to classifiers on generated output, reporting and complaint flows, age assurance where required, and records showing the controls run. The AI usage policy guide covers the internal side: what staff may put into these tools.
Security: the AI cyber code and the AI Security Institute
The Code of Practice for the Cyber Security of AI (31 January 2025) is voluntary. It sets 13 principles across the AI lifecycle, each with provisions marked as required, recommended or possible for compliance with the code. The government submitted it to ETSI as the basis for the technical specification ETSI TS 104 223. The first principles are to raise awareness of AI security threats, design for security as well as function and performance, evaluate threats and manage risk, enable human responsibility for AI systems, identify, track and protect assets, and secure infrastructure. Read the published text for the full list, because it continues through deployment, maintenance and end of life.
Treat the code as a checklist for your threat model even though it is voluntary. Customers and public-sector buyers increasingly ask for it, and it lines up with the UK GDPR security duty, which is not voluntary.
The AI Security Institute works on the frontier end: testing advanced models for chemical, biological and cyber capability and similar security risks. Its open-source evaluation framework, Inspect, is usable by any team building evals. For a deployer, the institute's output matters indirectly, through what model providers disclose and how they test. The AI labs ecosystem guide covers that relationship.
What is still pending
- An AI bill. Signalled in July 2024 and repeatedly expected, but not introduced as of October 2026. The Joint Committee on Human Rights wants risk tiers, prohibitions and a regulator with withdrawal powers. The content of any bill is unknown, so don't build to a rumoured draft.
- Copyright and training data. The March 2026 report dropped the opt-out exception as the preferred route and chose to gather evidence, watch litigation and EU implementation, and encourage transparency practices. Engineering response: keep provenance and licence records for training and fine-tuning data now, because every plausible outcome asks for them.
- AI Growth Lab. A proposed cross-economy sandbox for supervised testing under temporary regulatory changes. DSIT's call for evidence ran from 21 October 2025 to 7 January 2026, and some protections, such as fundamental rights and consumer safety, were proposed as excluded. Legislation would be needed for its stronger powers, so check its current status before planning around it.
Worked example: an LLM in a credit-limit flow
A UK consumer-credit firm wants an LLM-assisted flow that reads a customer's request for a higher credit limit, pulls account data, and approves or declines. Here is the regime map, built from the principles table.
- ICO and DUAA. A credit-limit decision is significant. If no human meaningfully intervenes, it is solely automated, so Article 22C safeguards apply. Build
DecisionRecord, reason codes, and a review and contest queue. Make sure the features exclude special category data and obvious proxies for it. Run a DPIA. - FCA. The firm is regulated, so Consumer Duty outcomes and its model risk framework apply. Validation evidence must cover the LLM step, which extracts intent and figures from free text, as well as the scoring model. Test extraction accuracy on real messages, including vulnerable-customer language.
- Equality Act. Test approval rates and error rates across groups where data allows, and check the LLM step for systematic misreading of particular writing styles or non-native English.
- Security. A customer message is untrusted input to an LLM with account access. Apply prompt-injection scanning, least-privilege tool access and output validation, and record them against the AI cyber code.
- Online Safety Act. Out of scope here: there is no user-to-user sharing and no multi-site search. Record the reasoning so a future feature change triggers a re-check.
The output is one evidence pack per system, containing the DPIA, validation results, fairness tests, decision-record samples and the security checklist. Any regulator that asks gets the relevant section.
Traps
- "No AI Act, so no rules." Every statute above applies today. Enforcement simply comes from several regulators instead of one.
- Forgetting the EU. A UK firm placing systems on the EU market, or whose system's output is used in the EU, may also fall under the EU AI Act. The EU AI Act guide covers its tiers. Design one control set that satisfies both and keep the evidence once.
- Rubber-stamp human review. A reviewer who can't change the outcome, or who approves hundreds of cases an hour, does not take a decision out of the automated category.
- Static compliance. Guidance is mid-revision: ICO ADM guidance, the copyright follow-up, and any AI bill. Put a quarterly review on the calendar with a named owner.
- Mixing up the institutes. The AI Security Institute evaluates frontier risks. It is not a regulator and does not certify your product.
What to do next
- Inventory your AI systems and, for each one, record which regimes apply: ICO, Ofcom, sector regulator, Equality Act, EU AI Act.
- For every significant automated decision, implement decision records, reason codes, and a representation, human-review and contest path. Rehearse a contest end to end.
- Confirm that special category data and close proxies stay off solely automated paths.
- If you run user-to-user or search features with generative AI, complete or refresh the Online Safety Act risk assessments.
- Map your threat model to the AI cyber code's 13 principles and record gaps.
- Start provenance and licence records for all training and fine-tuning data.
- Assign an owner to track the AI bill, ICO ADM guidance, copyright follow-up and the AI Growth Lab, and review quarterly.