Five cross-sectoral principles, existing regulators, the Regulating for Growth Bill, and why the UK still has no horizontal AI Act.

Educational content, not legal advice. AI regulation is fast-moving and jurisdiction-specific. Verify every obligation and deadline against the primary legal text and consult qualified counsel before making compliance decisions. Accurate as of the research date shown in the metadata below.

Still no UK AI Act, and that is the point

As of mid-2026 the United Kingdom has no single, horizontal AI statute and no AI bill before Parliament. This is a deliberate choice, not a gap. The UK's strategy, set out in the March 2023 White Paper 'A pro-innovation approach to AI regulation', is to apply existing law to AI through existing sector regulators, guided by common principles, rather than create one new AI law and one new AI regulator. It is, by design, the opposite of the EU's centralised, risk-based AI Act.

The five cross-sectoral principles

The framework rests on five principles that regulators are expected to interpret and apply within their own domains:

  1. Safety, security and robustness: AI systems should function reliably and securely across their lifecycle, with risks managed.
  2. Appropriate transparency and explainability: those affected should be able to obtain meaningful information about how and when AI is used.
  3. Fairness: AI should not undermine legal rights, discriminate unfairly, or produce unfair market outcomes.
  4. Accountability and governance: clear organisational accountability and effective oversight across the AI lifecycle.
  5. Contestability and redress: affected parties should be able to challenge AI-driven outcomes and seek redress.

Importantly, these principles are currently non-statutory. Regulators are asked to have 'due regard' to them and to implement them using their existing powers and existing law, supplemented by guidance, rather than through new binding AI-specific duties.

Who actually regulates AI in the UK

Because there is no central AI regulator, AI is governed by the sector regulator whose remit it touches. The most active are:

Regulator Domain How AI is caught
ICO Data protection and privacy UK GDPR and the Data (Use and Access) Act 2025 govern personal-data processing, profiling and automated decisions.
Ofcom Online safety and communications The Online Safety Act covers AI-generated illegal and harmful content on in-scope services.
FCA Financial services Technology-agnostic, outcomes-focused supervision; existing rules (e.g. senior-manager accountability, consumer duty) apply to AI use.
CMA Competition and markets Competition and consumer law, including scrutiny of foundation-model markets.
MHRA Medical devices AI as a medical device regulated under existing device rules.

Coordination runs through the Digital Regulation Cooperation Forum (bringing together the ICO, Ofcom, FCA and CMA) rather than a single AI authority. The AI Security Institute (formerly the AI Safety Institute) conducts frontier-model evaluations but is a research and testing body, not a regulator with enforcement powers.

The 2026 developments: growth over horizontal rules

The direction of travel in 2026 reinforced the light-touch stance rather than reversing it:

  • Regulating for Growth Bill: announced in the King's Speech background notes in May 2026, its centrepiece is the 'AI Growth Lab', a programme of issue-specific regulatory sandboxes in which specific rules can be temporarily relaxed for licensed pilots. It is a pro-innovation enabling measure, not a binding horizontal AI law.
  • FCA reaffirmation: in September 2025 the FCA restated that it is a technology-agnostic, principles-based, outcomes-focused regulator and that firms will not face bespoke new AI rules.
  • Automated decision-making reform: section 80 of the Data (Use and Access) Act 2025 came into force on 5 February 2026, replacing Article 22 of the UK GDPR. It broadens when automated decisions can be made (including on a legitimate-interests basis for non-special-category data) while requiring safeguards, information to individuals, the ability to make representations, human intervention, and a route to contest the outcome.

Parliamentary and civil-society pressure for a binding AI framework continues, and private members' bills have been floated, but none had become law or entered the government's legislative programme as a horizontal AI Act by mid-2026.

UK versus EU at a glance

Dimension United Kingdom European Union
Legal form No horizontal AI law; principles applied via existing sector law Single binding regulation (the AI Act) with direct effect
Architecture Existing sector regulators; no central AI authority AI Office plus national competent authorities and the AI Board
Basis of obligations Largely non-statutory principles plus existing law Statutory, risk-tiered obligations (prohibited, high-risk, limited, minimal)
Enforcement teeth Each regulator's existing powers and penalties Fines up to 35M EUR or 7% of worldwide turnover (Article 99)
Posture Pro-innovation, sandbox-led, outcomes-focused Rights-protective, prescriptive, ex-ante conformity
Do not read 'lighter touch' as 'no obligations'. UK organisations still face binding duties under the UK GDPR / DUAA, the Online Safety Act, equality law, consumer and financial-services rules. And any UK product placed on the EU market, or whose output is used in the EU, can fall squarely within the EU AI Act regardless of the UK's own approach.

Practical takeaways for cross-border teams

  • Map by regulator, not by 'AI law'. In the UK, your obligations flow from whichever sector regulator your use case touches, most often the ICO.
  • Treat the EU AI Act as the higher bar. If you serve both markets, building to EU high-risk standards generally satisfies UK principles as well, rarely the reverse.
  • Watch the sandboxes. The AI Growth Lab may offer genuine regulatory flexibility for UK pilots; it is worth tracking if you are launching novel AI in a regulated sector.
  • Revisit automated decisions. The DUAA changes the ADM rules materially; if you rely on Article 22-style safeguards, re-check them against the new UK regime.