UK · GLACIS guides · Updated August 2026

UK AI regulation: the pro-innovation approach

A working guide to the UK’s principles-based, sectoral framework, refreshed for August 2026 with current FCA, PRA, ICO and MHRA developments and the Data (Use and Access) Act 2025 in force.

By Joe Braidwood 22 min read UK and EU timelines checked 26 August 2026
Oct 2025
DSIT Blueprint for AI regulation published
5 Feb 2026
DUAA data-protection provisions in force
May 2026
MHRA AI Airlock phase 2 completed
19 Jun 2026
DUAA right to complain and section 103 in force
What changed since January 2026
Executive summary

The UK has charted a distinctly different path from the EU. While the EU AI Act sets horizontal, prescriptive requirements across risk tiers, the UK relies on existing sectoral regulators to interpret and apply five core principles within their domains.

In February 2025 the AI Safety Institute was renamed the AI Security Institute to reflect a renewed focus on serious AI risks with security implications. The Data (Use and Access) Act 2025 received Royal Assent in June 2025 and its data-protection provisions were fully in force by 19 June 2026, expanding the circumstances for some automated decisions while retaining safeguards.

The practical result is a patchwork. UK organizations work from sectoral guidance issued by the FCA, PRA, MHRA, ICO and Ofcom. That is less prescriptive than the EU AI Act, but it is harder to hold in one head, and it gets harder still for firms operating across several regulated sectors or in both UK and EU markets while the Omnibus reshapes the high-risk timeline.

5
Core principles
6+
Sectoral regulators in play
75%
Respondents using AI in the 2024 joint FCA/Bank survey
No Bill
Primary AI legislation paused

The pro-innovation framework

The UK’s approach was formally established in the March 2023 White Paper “AI regulation: a pro-innovation approach” (Command Paper 815) and reaffirmed through the government’s February 2024 response. It explicitly prioritizes flexibility and outcomes over prescriptive compliance.

Core philosophy

Unlike the EU AI Act’s horizontal regulation with risk-based classifications, the UK framework:

  • Empowers existing regulators to interpret and apply AI principles within their domains
  • Avoids statutory requirements, leaving the five principles as non-binding guidance
  • Prioritises outcomes over processes, so regulators look at results rather than mandating specific technical measures
  • Maintains flexibility as AI technology evolves rapidly

Government response (February 2024)

  • Reaffirmed the “agile and principles-based” approach
  • Committed £10 million to boost regulators’ AI expertise
  • Required the FCA, ICO, MHRA, Ofcom and CMA to publish AI strategic approaches by 30 April 2024
  • Flagged potential future binding requirements on developers of the “most powerful” AI systems

AI Opportunities Action Plan and 2026 progress

The AI Opportunities Action Plan was launched on 13 January 2025, endorsing all 50 recommendations from the Matt Clifford review. The DSIT progress report of 29 January 2026, titled One Year On, reports 38 of 50 commitments met. Headline elements include:

  • £14 billion in private investment commitments
  • Creation of a National Data Library
  • New AI Energy Council to address compute infrastructure
  • Proposed UK Sovereign AI unit
  • Continued emphasis on growth and opportunity over restrictive regulation

AI Growth Lab: current advisory phase

The government developed the AI Growth Lab as a cross-regulator program and launched an initial advisory offer in June 2026. At this stage it provides joined-up guidance within existing rules; it does not itself license participants to disregard or relax applicable regulation. Government said legislation to confer additional testing powers would be brought forward in autumn.

The call for evidence on the Lab’s design was extended and closed on 7 January 2026. Any future ability to test activity prohibited by current regulation depends on legislation not treated here as enacted. The government’s existing sectoral, principles-led approach remains the current baseline.

The five core principles

The UK’s AI governance framework centers on five cross-sectoral principles that regulators are expected to interpret and apply within their domains:

1. Safety, security and robustness

AI systems should function securely, safely, and robustly throughout their lifecycle. This includes protection against cyber-attacks, adversarial inputs, and unexpected failures.

2. Appropriate transparency and explainability

Organisations should provide appropriate information about AI systems. The level of transparency should be proportionate to the context and potential impact of decisions.

3. Fairness

AI systems should not produce discriminatory or unfair outcomes. This aligns with existing equality legislation including the Equality Act 2010.

4. Accountability and governance

Clear accountability structures should exist for AI systems. Organisations should have governance frameworks ensuring responsible development and deployment.

5. Contestability and redress

Individuals should be able to challenge AI decisions and seek appropriate remedies when harmed. This includes access to human review of automated decisions.

Important: These principles are currently non-statutory. While regulators are expected to incorporate them into their guidance, there is no legal requirement for organizations to demonstrate compliance with the principles themselves, only with the existing sectoral regulations as those regulators read them.

AI Security Institute (AISI)

Established as the AI Safety Institute in November 2023, AISI is now a research organization within the Department for Science, Innovation and Technology. Its current remit is to build scientific understanding of advanced-AI risks and solutions for governments.

Rename to AI Security Institute (February 2025)

On 14 February 2025 the government renamed it the AI Security Institute. The announcement said the name reflected a renewed focus on serious AI risks with security implications, including national-security and criminal misuse risks.

Change in focus

The February 2025 announcement identified cyber attacks, chemical and biological weapon development, fraud and child sexual abuse material as examples of the serious security risks in scope. AISI’s current research agenda also covers control, autonomy, human influence and societal resilience.

Frontier AI Trends Report and 2026 publications stream

AISI published its Frontier AI Trends Report on 18 December 2025. The government’s January 2026 progress report said AISI had more than 100 researchers and had tested 30 frontier models; those figures are a dated government snapshot, not a live model count.

AISI’s current research index lists publications through June 2026. Examples include:

  • “Did you lie?”, on evaluating lie detectors across model scale (17 June 2026)
  • Prefill awareness in large language models (10 June 2026)
  • Loss of oversight, on how AI systems may become harder to audit, monitor and investigate (21 May 2026)
  • Propensity inference, on environmental contributors to LLM behavior (24 April 2026)
  • How are AI agents used?, drawing on evidence from 177,000 MCP tools (26 March 2026)

Activities and partnerships

  • Model evaluations: AISI says it tests leading AI systems before and after public release.
  • Open-source tooling: AISI publishes Inspect and other evaluation tools for wider research use.
  • Current resourcing: AISI’s current organization page lists £66 million in funding per financial year and capacity to mobilise more than £15 million in grants.
  • Collaboration: AISI describes work with UK and allied governments, research teams and leading AI companies; those relationships do not imply endorsement of a particular vendor or deployment.

Sectoral regulators

Unlike the EU’s centralised AI Office, the UK relies on existing regulators to govern AI within their domains. Each published a strategic AI approach in 2024 and has continued to refine guidance through 2025 and 2026.

Regulator Sector Latest AI guidance
FCA Financial services AI Lab and AI Live Testing; Mills Review published 6 July 2026 with seven recommendations; AI good-and-poor-practice publication planned later in 2026
PRA Banks and insurers SS1/23 Model Risk Management (effective May 2024; current published version dated 23 April 2026)
MHRA Medical devices AI Airlock phase 2 completed May 2026; program report updated 27 July 2026 and is not formal guidance; phase 3 design underway
ICO Data protection ADM and profiling consultation closed 29 May 2026; final guidance due winter 2026; separate AI code of practice in development during 2026/27
Ofcom Communications Online Safety Act AI implications; synthetic media guidance
CMA Competition Foundation models review; AI partnership monitoring
Bank of England Financial stability AI roundtables summary (Feb 2026); FPC record (April 2026) flagged agentic AI in payments and markets as the next focus

Digital Regulation Cooperation Forum (DRCF)

The FCA, CMA, ICO and Ofcom coordinate through the DRCF. The DRCF AI and Digital Hub continues to provide joint guidance for organizations working across multiple frameworks, and in 2026 has been a key channel for cross-regulator alignment around the AI Growth Lab.

UK GDPR and automated decision-making

The Data (Use and Access) Act 2025 changed the UK GDPR rules for solely automated significant decisions. For non-special-category data, those decisions may now rely on a wider range of lawful bases, but not the new recognized-legitimate-interests basis, and remain subject to safeguards.

Current safeguards for significant automated decisions

The reformed provisions apply where a decision is based solely on automated processing, with no meaningful human involvement, and produces a legal or similarly significant effect. The organization must provide safeguards that include:

  • providing information about the decision;
  • allowing the person to make representations and contest the decision; and
  • allowing the person to obtain human intervention.

ICO AI and biometrics strategy update (March 2026)

The ICO’s March 2026 strategy update names three priority areas: foundation models, ADM in recruitment and public services, and police use of facial recognition. Recent ICO outputs include:

  • Updated ADM and profiling guidance: consultation closed 29 May 2026; the ICO lists the final guidance as due in winter 2026
  • AI code of practice: a separate workstream the ICO says it will develop during 2026/27
  • Emerging-tech report on agentic AI (January 2026)
  • Response to the Home Office consultation on biometrics, FRT and similar technologies (February 2026)
  • Recruitment Rewired: updated guidance on automation in recruitment with the March 2026 blog “Automated decisions can streamline hiring with the right safeguards”
  • Explaining decisions made with AI: joint ICO and Alan Turing Institute guidance remains available, while the DUAA-related ADM update is still being finalised

Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, introducing significant changes to UK data protection law and its interaction with AI. Most data-protection provisions came into force on 5 February 2026; the individual-rights provisions described below commenced on 19 June 2026.

Key changes for automated decision-making

In force from 5 February 2026
  • Wider permission for ADM: significant solely automated decisions involving non-special-category data may use a wider range of lawful bases, but not the new recognized-legitimate-interests basis
  • Meaningful human involvement: a decision is solely automated when there is no meaningful human involvement in taking it
  • Required safeguards: organizations must provide information, allow representations and contestability, and enable human intervention
  • Special category data: the stricter regime continues to apply where sensitive data is involved
  • Reformed adequacy test for international transfers, under which protection in third countries must be “not materially lower” than the UK standard

Implementation timeline

  • Stage 1 (20 August 2025): initial provisions in effect
  • Stage 2 (30 September 2025): additional changes effective
  • 5 February 2026: bulk of data-protection provisions in force, including reformed ADM rules and children’s protections
  • 19 June 2026: new individual right to complain and section 103 mandatory complaints procedure

Regulatory timeline

Already in effect

Date Development
April 2024 FCA AI Update published
17 May 2024 PRA SS1/23 Model Risk Management effective
May 2024 MHRA AI Airlock phase 1 launched
14 February 2025 AI Safety Institute renamed AI Security Institute
19 June 2025 Data (Use and Access) Act 2025 Royal Assent
21 October 2025 DSIT Blueprint for AI regulation; AI Growth Lab call for evidence opens
18 December 2025 AISI Frontier AI Trends Report published
27 January 2026 FCA Mills Review launched
5 February 2026 DUAA bulk data-protection provisions in force, including reformed ADM rules
February 2026 Bank of England summary of AI roundtables published
March 2026 ICO AI & biometrics strategy update
May 2026 MHRA AI Airlock phase 2 completed after running from April 2025 to May 2026
6 July 2026 FCA published the Mills Review with seven recommendations for its Board and Executive
27 July 2026 MHRA updated its AI Airlock phase 2 program report; the report is not formal regulatory guidance, and phase 3 design is underway

Recent milestones and announced next steps

Date Development
29 May 2026 ICO ADM and profiling guidance consultation closed
19 June 2026 DUAA right to complain and section 103 in force
Later in 2026 FCA says it plans to publish AI good-and-poor-practice material
Winter 2026 ICO’s current plan lists final ADM and profiling guidance for publication
Q1 2027 FCA AI Live Testing evaluation report
2 December 2027 Relevant EU AI Act high-risk obligations for Annex III systems
2 August 2028 Relevant EU AI Act product-embedded high-risk obligations for Annex I systems
30 June 2028 / 2030 Current GOV.UK transitional guidance uses category-specific CE-recognition endpoints: certain MDD/AIMDD devices reach the sooner of certificate expiry or 30 June 2028, while EU MDR/IVDR and certain IVDD routes run to 30 June 2030. A closed 2026 consultation proposed indefinite recognition for some routes, so 30 June 2030 is not a universal UKCA deadline.

UK vs EU AI Act: key differences

A firm active in both markets is running two compliance models at once. The UK asks for judgment inside rules that already exist. The EU asks for a classification first, and a fixed set of obligations then follows from it.

Aspect UK approach EU AI Act
Regulatory structure Principles-based, sectoral Horizontal legislation
Central authority None. AISI evaluates only; DRCF coordinates European AI Office + national authorities
Risk classification No formal tiers Four tiers: unacceptable, high, limited, minimal
Prohibited practices None specified in AI law (existing laws apply) Explicit bans on social scoring, certain biometrics, and manipulation
Compliance obligations Flexible, outcome-focused Prescriptive requirements per risk tier
Statutory basis Non-statutory principles; sectoral statute (DUAA, MDR, etc.) Directly applicable EU regulation
Current focus (2026) Security and growth, through the DSIT Blueprint and the AI Growth Lab Safety and fundamental rights, with the Omnibus delay reshaping the high-risk timeline
Extraterritorial impact

UK companies can fall within the EU AI Act when they place systems on the EU market or when a system’s outputs are used in the EU, subject to Article 2’s conditions and exceptions. Under the AI Omnibus now in force, relevant high-risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product-embedded systems.

UK AI compliance checklist

Even without prescriptive AI-specific requirements, the following remains the working list:

Identify applicable sectoral regulators

Determine which regulators (FCA, MHRA, ICO, etc.) have jurisdiction over your AI use cases

Review regulator-specific AI guidance

Each regulator has published its strategic approach, so check your practices against the ones that reach you

Assess ADM under UK GDPR/DUAA

Ensure automated decisions have appropriate safeguards and human review mechanisms

Document accountability structures

Designate accountable individuals for AI governance. In the 2024 joint FCA/Bank of England survey, 84% of respondent firms reported having an accountable person for their AI framework.

Consider EU AI Act obligations

If operating in EU markets, ensure compliance with EU requirements regardless of UK rules

How GLACIS can support UK AI evidence work

The UK’s principles-based approach leaves organizations to connect applicable duties and supervisory expectations to their own controls and records. Glacis can contribute scoped operational evidence for configured AI workflows; it does not determine compliance, replace legal analysis, or establish that a control was effective.

Continuous attestation → accountability and governance

For in-scope events on a configured path, signed records can make covered fields and reported control outcomes independently checkable. The record does not establish complete coverage or regulatory acceptance.

Evidence pack → regulator inquiries

Evidence packages can organize signed records, declared scope and supporting context for review. They report covered actions and control outcomes; they do not explain a foundation model’s internal reasoning.

Evidence scope assessment → gap identification

Map an intended rule to a configured control, covered events, exclusions and the evidence available for review. Applicable legal conclusions remain with the organization and its advisers.

Mapping GLACIS to UK principles

UK principle GLACIS capability
Safety, security, robustness Configured controls can record covered allow, block or escalation outcomes. Separate testing is still needed to assess robustness and effectiveness.
Transparency and explainability Selected covered fields and reported outcomes can be exported for review. A receipt does not expose or explain internal model reasoning.
Fairness Declared sampling and cohort fields can contribute to a fairness review; the record does not determine whether outcomes are fair.
Accountability and governance Signed records can identify a configured control claim and reported outcome for a covered event. Responsibility mapping and effectiveness require separate evidence.
Contestability and redress Retrieval of covered event records can contribute to complaint handling or access workflows, subject to the organization’s legal and data-governance process.

Connect intended rules to reviewable operational evidence

Start where AI already acts in your organization: the configured controls, the evidence scope, the exclusions, and the claims a reviewer could independently check.

Talk to us

Related guides