Regulation
UK AI regulation in 2026: what you actually have to do
There is still no UK AI Act, but that does not mean no obligations. What actually binds UK organisations using AI in 2026, and what to put in place.
The single most common misconception we meet in UK boardrooms is that AI is unregulated here because there is no UK AI Act.
There is no UK AI Act. There are also a great many binding obligations on the way you use AI. Both statements are true, and the gap between them is where organisations get into trouble, because the absence of a single statute is frequently read as an absence of duty, right up until a regulator asks a question that assumes one.
Here is the actual position as of September 2026, and what to do about it.
The state of play
The UK has deliberately not passed a cross-economy AI law. The approach set out in the government’s pro-innovation white paper puts the obligation on existing regulators to apply existing law to AI within their remits, rather than creating a horizontal AI regime.
The Regulating for Growth Bill announced in the King’s Speech in May 2026 would introduce cross-economy AI sandboxing powers (a mechanism for testing innovative products under regulatory supervision) rather than a binding horizontal AI law of the EU type. The direction of travel remains regulator-led.
This is often described as lighter-touch than the EU. For a compliance team, it is frequently harder, for a specific reason: there is no checklist that discharges your duty. Under a prescriptive regime you can demonstrate compliance by satisfying enumerated requirements. Under a principles-based one you have to reason about your particular use, reach a defensible conclusion, and be able to show your working. That is more demanding, not less.
What actually binds you
Ignore “AI regulation” as a category for a moment and ask which existing regimes your use case touches. For most UK organisations the live ones are:
Data protection (UK GDPR and the Data Protection Act). The most consequential and most frequently overlooked. Training or prompting a model with personal data is processing, and needs a lawful basis, a purpose limitation position, and, for anything high risk, a DPIA completed before processing begins. Article 22 rights around solely automated decision-making with legal or similarly significant effects apply directly to a great deal of what people are building. The ICO has been clear that AI does not get an exemption.
Sector regulation. Financial services firms face model risk management expectations and Consumer Duty obligations that reach any model influencing customer outcomes. Healthcare providers face information governance requirements, and a model that informs clinical decisions may be a medical device requiring MHRA involvement. These predate AI and apply to it without amendment.
Equality law. A model that produces materially different outcomes across protected characteristics creates discrimination exposure whether or not anyone intended it, and whether or not the mechanism is explicable.
Consumer and contract law. If a customer-facing assistant states something incorrect about your product, terms or obligations, that is your statement. “The model said it” is not a defence anyone has successfully run.
Employment law. AI in recruitment, monitoring or performance management sits on top of a well-developed body of law with a low tolerance for opaque process.
None of that is new. All of it applies now, and none of it is waiting for an AI Act.
The EU AI Act still reaches you
UK organisations placing AI systems on the EU market, or whose AI outputs affect people in the EU, are in scope regardless of where they are established. Being outside the EU does not remove the obligation.
The timeline has shifted. Following the EU AI Act Omnibus (provisional political agreement reached 7 May 2026), the main high-risk deadlines were deferred:
| Obligation | Deadline |
|---|---|
| Prohibited practices (Article 5) | Already in force and enforceable |
| Annex III high-risk systems (recruitment, credit scoring, law enforcement, education, essential services) | 2 December 2027 |
| Annex I high-risk systems (AI embedded in regulated products) | 2 August 2028 |
The deferral applies to the high-risk regime. It does not apply to the prohibitions, which are enforceable now, and which carry the heaviest penalties in the Act: up to €35 million or 7% of global annual turnover.
Those prohibitions cover social scoring, manipulative or exploitative techniques, and biometric categorisation using sensitive attributes, among others. Most organisations are not doing these things. The ones who are usually do not realise it: the risk sits in vendor tooling adopted without review, particularly in HR, workforce analytics and customer profiling, rather than in anything the organisation built itself.
If you have not audited your third-party AI tooling against Article 5, that is the highest-value hour of compliance work available to you right now.
What to actually put in place
The good news is that the same small set of artefacts satisfies most of these regimes at once. You do not need a separate programme per regulator.
1. An AI inventory
You cannot govern what you have not counted, and almost every organisation we assess underestimates its own use by a wide margin, because AI arrives embedded in tools that were procured as something else.
For each system record: what it does, what data reaches it, who the supplier is, where processing happens, who owns it internally, and what the failure mode looks like. Include the tools people are using without approval; you will find them, and they are usually the ones with the worst terms.
2. An AI policy people can actually follow
Most AI policies fail because they are written as prohibitions and therefore ignored. A workable one tells staff which data classifications may go into which tier of tool, and gives a route to get something approved. If your policy’s practical effect is that the compliant path is impossible, you have not reduced risk; you have moved it somewhere you cannot see.
3. DPIAs done before, not after
For any AI processing personal data at meaningful scale or with meaningful consequence, the DPIA is a legal requirement and the single most useful document you will produce. Done properly at design time it also answers most of what a procurement panel, an auditor or an information governance board will later ask.
4. A risk register with AI-specific entries
Generic technology risk entries do not capture the AI-specific failure modes: unreliable outputs stated with confidence, drift as the world changes underneath a fixed model, prompt injection through untrusted content, and over-reliance by users who stop checking. Each needs an owner, a control and a review date.
5. Human accountability that is real
“There is a human in the loop” is the most over-claimed control in AI governance. A human who approves 200 outputs an hour is not a control; they are a rubber stamp with a job title. If you are relying on human review, the review has to be resourced, time-boxed realistically, and evidenced, or you should stop claiming it.
DSIT’s AI Management Essentials
DSIT has published AI Management Essentials (AIME), a self-assessment tool aimed primarily at SMEs but applicable to any organisation developing, providing or using AI. It is structured around three themes: internal processes, managing risks, and communication.
Completion is voluntary. The reason to care is that government has been exploring integrating it into public sector procurement processes, which would make it a de facto commercial requirement for anyone selling to government, well before it becomes any kind of legal one.
If you sell into the public sector, working through AIME now is cheap, and it maps closely onto the artefacts above. It sits alongside the Algorithmic Transparency Recording Standard (ATRS), which applies to public sector bodies’ own algorithmic tools.
ISO/IEC 42001
For organisations that need to demonstrate governance to customers rather than regulators, ISO/IEC 42001, the AI management system standard, is becoming the recognised answer, in much the same way ISO 27001 became the default response to security questionnaires.
It is worth pursuing if AI governance questions are appearing in your sales cycle or your tenders. It is not worth pursuing simply because it exists. The underlying artefacts matter more than the certificate, and they are the same ones listed above.
The honest summary
You are not waiting for a UK AI Act to tell you what to do. The obligations are already live, they arrive through regulators you already deal with, and the evidence they will ask for is broadly the same evidence in each case.
Organisations that build that evidence as they go find it costs very little. Organisations that reconstruct it eighteen months later, under time pressure, in response to a question they cannot defer, find it costs a great deal, and occasionally find that the answer is that the system should not have been built the way it was.
This is general information about the UK regulatory landscape as at September 2026, not legal advice, and the position is moving. For advice on your specific obligations, consult a qualified solicitor.
If you need the artefacts above built rather than described, that is our AI governance and compliance service.