Back to Blog
Data & Governance

AI Regulation in the UK: What Exists, What Does Not, and What to Do Anyway

A
Arun Godwin Patel
August 10, 20267 min read

There is no UK AI Act. That does not mean AI is unregulated here. What UK GDPR, the ICO, the FCA and employment law already require of you, in plain English.

An umbrella standing in for the absence of a UK AI Act, sheltering the rules that do apply: UK GDPR, the ICO, employment law and sector regulators.

There is no UK AI Act. There is no UK AI regulator. There is no registration scheme, no conformity assessment, and no equivalent of the EU's risk tiers.

This leads a lot of British business owners to a conclusion that is half right. AI is not specifically regulated here. AI is comprehensively regulated here, by rules that were written before anyone was worried about it and that apply to you today.

This article is part of our guide to the EU AI Act for UK businesses, which covers the position for businesses with EU exposure.

Plain-English summary, not legal advice.

What the UK has chosen to do

The UK's approach is to regulate AI through existing regulators in their existing sectors, rather than through a single new statute. The government has issued cross-sector principles, and it is for each regulator to apply them within its own remit.

That means there is no single place to look. There are several, and which of them matters depends on what your business does.

UK GDPR and the ICO: the one that applies to everyone

If your AI touches personal data, and most does, this is the binding constraint. The Information Commissioner's Office is active, publishes detailed guidance on AI and data protection, and has enforcement powers that dwarf the practical risk most SMEs face from the EU AI Act.

What it actually requires:

A lawful basis. You need one to process personal data through an AI system, and "we wanted to try it" is not among them. Legitimate interests is the usual candidate and it requires a documented balancing test.

Transparency. People must be told how their data is used, in terms they can understand. A privacy notice that does not mention AI processing while AI processing is happening is a problem.

Rights around automated decisions. Where a decision produces legal or similarly significant effects and is made solely by automated means, individuals have specific rights, including to obtain human intervention and to contest the outcome. Recruitment, credit and insurance decisions are the obvious cases.

Data minimisation and purpose limitation. Data collected for one purpose cannot simply be repurposed to train a model. This one catches businesses constantly, and it is the subject of can you legally use your own customer data to train AI.

DPIAs. A Data Protection Impact Assessment is required for high-risk processing, which includes much automated decision-making and profiling.

The practical exposure for most UK SMEs is here, not in Brussels.

Employment law and the EHRC

If AI touches hiring, promotion, allocation of work or dismissal, discrimination law applies in full.

The Equality Act does not care that a model produced the outcome. If a process disadvantages people with a protected characteristic, you are answerable for it, and "the software did it" is not a defence. Indirect discrimination is the live risk: a model trained on your historical hires will reproduce your historical patterns, including the ones you would not defend.

This is the single most likely way a UK SME gets into genuine trouble with AI, and it is covered further in AI CV screening for small employers.

Sector regulators

Financial services. The FCA applies its existing framework, including the Consumer Duty and senior manager accountability, to AI-driven decisions. Firms are expected to understand and be able to explain the models influencing customer outcomes.

Healthcare. The MHRA regulates AI that meets the definition of a medical device, which is a lower bar than most people assume. Clinical decision support can qualify.

Legal and accountancy. Professional bodies have issued guidance on client confidentiality and the use of generative tools. The binding constraint is usually the confidentiality duty, not a technology rule.

Advertising. The ASA applies the usual rules on misleading advertising to AI-generated claims and imagery.

Consumer protection

Misleading a consumer is unlawful whether a person or a model did it. A chatbot that overstates what a product does creates the same liability as a salesperson who does. The business is responsible for the statement, and "the AI hallucinated" is a description of the cause rather than a defence.

What is likely to change

The direction of travel is towards more structure rather than less, though nothing imminent creates obligations you should be planning around today. Sector regulators continue to publish increasingly specific guidance, procurement requirements are tightening faster than legislation, and larger customers now ask AI governance questions in tenders.

That last point is worth noting. For most SMEs, the first entity to demand evidence of AI governance will be a customer, not a regulator.

What to do

Five things, none of them expensive.

Know what you have. An inventory of AI systems in use, what data goes in, and who is accountable for each. Most businesses find between five and fifteen, including several that nobody had thought of as AI.

Check your privacy notice matches reality. If you are processing personal data through AI tools and your notice does not say so, fix that this month. It is the cheapest compliance gap to close.

Put a human in the loop for consequential decisions. Anything affecting employment, credit, pricing for individuals or access to a service. Not review in principle. A named person who actually looks and has the authority to overrule.

Train the people using it. The most common real-world incident in a UK SME is not regulatory. It is a member of staff pasting confidential information into a public tool. Covered in AI training for UK businesses.

Write one page and review it twice a year. Format in how to build an AI risk register.

Key Takeaways

  • There is no UK AI Act. AI is regulated through existing law and existing regulators, and those apply to you now.
  • UK GDPR and the ICO are the binding constraint for most businesses: lawful basis, transparency, automated decision rights, purpose limitation, DPIAs.
  • Discrimination law is the most likely route to real trouble. A model trained on historical hiring reproduces historical bias, and the Equality Act does not accept software as a defence.
  • Consumer protection applies to what your chatbot says. The business owns the statement.
  • For most SMEs the first party to demand evidence of AI governance will be a customer in a tender, not a regulator.

Frequently Asked Questions

Is the UK going to introduce an AI Act?

Nothing on the near horizon creates obligations you should be building around today. The current approach is sector regulators applying cross-cutting principles, and it has been reaffirmed repeatedly. Plan for the rules that exist rather than the ones that might.

Does the ICO actually enforce this against small businesses?

The ICO's stated approach favours engagement and guidance over immediate penalties for smaller organisations, particularly where a business has made a genuine effort. That is not the same as no risk, and the effort has to be evidenced. A documented decision, however brief, puts you in a very different position from nothing at all.

We use AI to help with hiring. What is the single most important thing to get right?

A named human who reviews every rejection the system influences and has the authority to overturn it, plus a record of the criteria the tool is applying. If you can show that, you have addressed the bulk of both the data protection and the discrimination exposure.

Do we need a DPIA for using ChatGPT?

It depends on what you put into it. Using it to draft copy with no personal data involved does not trigger one. Using it to process customer records or make decisions about individuals very likely does. The trigger is the processing, not the tool.


Want to know which UK rules actually bite on how you are using AI? Talk to Halo Technology Lab. Our strategy and scoping service includes an AI inventory and a plain-English view of where your real exposure sits.

Share this article

Enjoyed this? Get the next one by email

Practical AI playbooks, build logs and tool teardowns. One email a week, free, unsubscribe in one click.

See what’s in it first

Have a project in mind?

Let's discuss how we can help bring your ideas to life.

Get in Touch