United Kingdom

UK AI Regulation

No standalone AI statute — the UK has directed existing sector regulators to apply a shared set of cross-sectoral principles within their own existing powers.

Sector-regulator approach
UK sector regulators discussing cross-sectoral AI principles
Photo: Connor Gan via Unsplash
Governome Editorial Team2 min readHow we source and review this content.

The UK's approach to AI regulation is a genuine third model — distinct from the EU's single comprehensive statute and from the US's state-by-state statutory patchwork. Rather than a standalone AI law, the UK government's stated policy directs existing sector regulators to apply a shared set of cross-sectoral principles within their own existing powers, rather than creating new AI-specific enforcement authority.

The five cross-sectoral principles

The framework is built around five principles regulators are expected to apply within their existing remits: safety and security, appropriate transparency and explainability, fairness, accountability and governance, and contestability and redress. These aren't new legal obligations on their own — they're expectations for how existing regulators should interpret and apply their current powers to AI use cases.

Sector regulators actually doing the work

  • The Financial Conduct Authority (FCA) applies AI-relevant expectations to financial services firms largely through existing frameworks — model risk management, Consumer Duty — rather than AI-specific rules.
  • The Information Commissioner's Office (ICO) handles the data protection dimension of AI systems under UK GDPR, which continues to apply fully to AI systems that process personal data regardless of any AI-specific framework.
  • The Competition and Markets Authority (CMA) has taken a particular interest in foundation models and market concentration in AI infrastructure.

What this means practically

UK AI compliance work is genuinely sector-dependent in a way the EU AI Act isn't — there's no single classification test to run. A financial services firm's practical obligations run through FCA-adjacent expectations; a healthcare AI provider's obligations run through a different set of sector considerations entirely. Generic "UK AI compliance" checklists tend to miss this and default to describing the five principles without connecting them to a specific regulator's actual enforcement posture.

Is this likely to change?

This is genuinely an area of live policy debate — sector-regulator-only approaches face ongoing pressure, including from parts of Parliament, to move toward more comprehensive statutory footing. We update the status field on this page when the government's position moves, rather than trying to predict the outcome of an unresolved policy debate.

Sources & references

  1. Official source
  2. UK Government — AI regulation: a pro-innovation approach
European Union policy officials in discussion at a government building
Photo: Karson via Unsplash

regulations eu

The EU AI Act

The EU AI Act classifies AI systems into risk tiers and phases its obligations in on a multi-year schedule. Here's what's actually in force today, what's still phasing in, and how the risk tiers work.
Governome Editorial Team · 3 min read