AI Regulation in the UK: What Businesses Need to Know in 2026

Artificial Intelligence is now present in almost every industry. From customer service chatbots and recruitment software to cyber security, document automation and predictive analytics.  

Therefore the need to govern AI from a legal, regulatory or best practice perspective is also increasingly on the agenda. Some organisations are turning to ISO 42001 to provide a structured framework or Outsourcing AI Governance roles.  Either way, many organisations are asking the same question:

“What AI legislation applies in the UK?”

The answer is not that straightforward.

Unlike the European Union, the UK has not introduced a standalone AI Act. However, that does not mean AI is unregulated. In reality, organisations using AI are already subject to a growing framework of legislation, regulatory guidance and sector-specific requirements that together create significant compliance obligations. 

There is No UK AI Act

One of the biggest misconceptions surrounding AI governance is that because the UK has no dedicated AI law, businesses can largely use AI without regulatory oversight.

Rather than introducing a single piece of legislation like the EU AI Act, the UK Government has chosen a principles-based, regulator-led approach. Existing regulators remain responsible for overseeing AI within their own sectors using powers they already possess.

This means that organisations must comply with existing legislation that applies to how AI is developed and used rather than with AI-specific legislation itself.

The Data (Use and Access) Act 2025

The most significant legislative development affecting AI has been the Data (Use and Access) Act 2025 (DUAA).

Many of its data protection reforms came into force during 2026, including substantial changes to the UK’s rules on automated decision-making.

The Act replaces the previous Article 22 provisions of the UK GDPR with a new framework allowing organisations greater flexibility to use solely automated decision-making in many circumstances.

However, this flexibility comes with safeguards.

Where organisations make solely automated decisions that produce legal or similarly significant effects for individuals, they must ensure appropriate protections are in place. These include providing meaningful information about the decision, enabling meaningful human intervention where required, allowing individuals to make representations, and providing a mechanism for challenging decisions. Special category personal data continues to require stricter protections. 

It is important to understand that these requirements only apply to solely automated significant decisions. They do not automatically apply every time AI assists a human decision-maker.

Read our previous posts about the Data (Use and Access) Act 2025 (DUAA):

UK GDPR Still Applies to AI

For most organisations, the UK GDPR remains the primary legislation governing AI.

Whenever personal data is used to train, test or operate an AI system, organisations must comply with data protection principles including:

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Security
  • Accountability

Businesses should also consider whether they need to undertake a Data Protection Impact Assessment (DPIA), particularly where AI processing presents a high risk to individuals’ rights and freedoms.

AI Regulation Depends on Your Industry

Another complexity is that every organisation faces differing AI obligations. Much of UK AI regulation is sector specific.

Different regulators are publishing guidance explaining how existing legislation applies to AI within their own areas of responsibility.

For example:

  • The Information Commissioner’s Office (ICO) regulates AI where personal data is involved.
  • The Financial Conduct Authority (FCA) expects firms to use AI consistently with existing requirements such as Consumer Duty, operational resilience and governance.
  • Ofcom considers AI within communications regulation and the Online Safety Act.
  • The Medicines and Healthcare products Regulatory Agency (MHRA) regulates AI where it forms part of medical devices or healthcare technologies.

For organisations operating within regulated industries, these expectations are often just as important as legislation itself.

The ICO’s AI Code of Practice

One area generating considerable discussion is the ICO’s forthcoming AI and Automated Decision-Making Code of Practice.

The Government has introduced legislation requiring the ICO to prepare a statutory code, although at the time of writing the final version has not yet been published. The ICO has confirmed that developing this code is one of its priorities for 2026/27.

When published, the Code is expected to provide practical guidance on applying UK data protection law to AI systems.

While the Code will not create entirely new legal obligations, organisations should expect it to become an important benchmark when demonstrating compliance during ICO investigations.

Read more: ICO response to government on safe AI-powered innovation

Don’t Forget Other Existing Laws

AI governance also extends well beyond data protection.

Depending upon how AI is used, organisations may also need to consider:

  • Equality Act 2010
  • Human Rights Act 1998
  • Consumer protection legislation
  • Employment law
  • Product safety legislation
  • Intellectual property law
  • Sector-specific regulations

For example, using AI during recruitment could raise questions under equality legislation as well as data protection law, while deploying AI-powered products may lead to product safety requirements.

AI governance therefore needs to be considered across the organisation rather than as a purely IT or compliance issue.

What About the EU AI Act?

Although the UK has chosen not to introduce its own AI Act, many UK organisations will still be affected by the EU AI Act.

The legislation has extraterritorial reach. If a UK business develops AI systems for customers within the European Union or its AI outputs are used within the EU, the Act may apply even though the organisation is based in the UK.

Many UK technology companies, software providers and manufacturers therefore need to understand both UK requirements and European legislation.

Why ISO/IEC 42001 Matters

With AI regulation spread across multiple legal and regulatory frameworks, organisations increasingly need a structured approach to AI governance.

This is where ISO 42001, the world’s first Artificial Intelligence Management System standard, provides significant value.

Rather than focusing on individual laws, ISO 42001 establishes governance processes covering:

  • AI policies and objectives
  • Risk management
  • Human oversight
  • Accountability
  • Transparency
  • Supplier management
  • Performance monitoring
  • Continual improvement

Importantly, ISO 42001 is not a legal compliance standard and certification does not guarantee compliance with UK legislation. However, it provides an excellent governance framework that helps organisations demonstrate they are managing AI responsibly and systematically.

When combined with legal compliance activities such as GDPR assessments, AI impact assessments and sector-specific regulatory requirements, ISO 42001 can significantly reduce compliance risk while improving stakeholder confidence.

Preparing for the Future

The UK’s approach to AI regulation continues to evolve.

Rather than waiting for a single AI Act, businesses should recognise that AI governance is already here. Existing legislation is being updated, regulators are publishing increasingly detailed expectations, and customers are demanding greater assurance that AI is being used responsibly.

Organisations that establish effective AI governance now will be better positioned to adopt new technologies safely, demonstrate regulatory compliance and build trust with customers, employees and regulators alike.

How Assent Risk Management Can Help

At Assent Risk Management, we help organisations develop practical AI governance frameworks that support innovation while meeting regulatory expectations.

Our consultants can assist with:

  • AI governance reviews
  • ISO 42001 implementation
  • AI Risk Assessments & Impact Assessment
  • Data Protection Impact Assessments (DPIAs)
  • AI policy development
  • Internal audits

Whether your organisation is just beginning to use AI or is deploying advanced AI solutions across the business, we can help you build a governance framework that is proportionate, practical and ready for future regulation.  

Contact us for support navigating the AI compliance landscape.

Robert Clements
Robert Clements
Articles: 358