The pro-innovation framework
The UK’s approach was formally established in the March 2023 White Paper “AI regulation: a pro-innovation approach” (Command Paper 815) and reaffirmed through the government’s February 2024 response. It explicitly prioritizes flexibility and outcomes over prescriptive compliance.
Core philosophy
Unlike the EU AI Act’s horizontal regulation with risk-based classifications, the UK framework:
- Empowers existing regulators to interpret and apply AI principles within their domains
- Avoids statutory requirements, leaving the five principles as non-binding guidance
- Prioritises outcomes over processes, so regulators look at results rather than mandating specific technical measures
- Maintains flexibility as AI technology evolves rapidly
Government response (February 2024)
- Reaffirmed the “agile and principles-based” approach
- Committed £10 million to boost regulators’ AI expertise
- Required the FCA, ICO, MHRA, Ofcom and CMA to publish AI strategic approaches by 30 April 2024
- Flagged potential future binding requirements on developers of the “most powerful” AI systems
AI Opportunities Action Plan and 2026 progress
The AI Opportunities Action Plan was launched on 13 January 2025, endorsing all 50 recommendations from the Matt Clifford review. The DSIT progress report of 29 January 2026, titled One Year On, reports 38 of 50 commitments met. Headline elements include:
- £14 billion in private investment commitments
- Creation of a National Data Library
- New AI Energy Council to address compute infrastructure
- Proposed UK Sovereign AI unit
- Continued emphasis on growth and opportunity over restrictive regulation
AI Growth Lab: current advisory phase
The government developed the AI Growth Lab as a cross-regulator program and launched an initial advisory offer in June 2026. At this stage it provides joined-up guidance within existing rules; it does not itself license participants to disregard or relax applicable regulation. Government said legislation to confer additional testing powers would be brought forward in autumn.
The call for evidence on the Lab’s design was extended and closed on 7 January 2026. Any future ability to test activity prohibited by current regulation depends on legislation not treated here as enacted. The government’s existing sectoral, principles-led approach remains the current baseline.
The five core principles
The UK’s AI governance framework centers on five cross-sectoral principles that regulators are expected to interpret and apply within their domains:
1. Safety, security and robustness
AI systems should function securely, safely, and robustly throughout their lifecycle. This includes protection against cyber-attacks, adversarial inputs, and unexpected failures.
2. Appropriate transparency and explainability
Organisations should provide appropriate information about AI systems. The level of transparency should be proportionate to the context and potential impact of decisions.
3. Fairness
AI systems should not produce discriminatory or unfair outcomes. This aligns with existing equality legislation including the Equality Act 2010.
4. Accountability and governance
Clear accountability structures should exist for AI systems. Organisations should have governance frameworks ensuring responsible development and deployment.
5. Contestability and redress
Individuals should be able to challenge AI decisions and seek appropriate remedies when harmed. This includes access to human review of automated decisions.
Important: These principles are currently non-statutory. While regulators are expected to incorporate them into their guidance, there is no legal requirement for organizations to demonstrate compliance with the principles themselves, only with the existing sectoral regulations as those regulators read them.
AI Security Institute (AISI)
Established as the AI Safety Institute in November 2023, AISI is now a research organization within the Department for Science, Innovation and Technology. Its current remit is to build scientific understanding of advanced-AI risks and solutions for governments.
Rename to AI Security Institute (February 2025)
On 14 February 2025 the government renamed it the AI Security Institute. The announcement said the name reflected a renewed focus on serious AI risks with security implications, including national-security and criminal misuse risks.
The February 2025 announcement identified cyber attacks, chemical and biological weapon development, fraud and child sexual abuse material as examples of the serious security risks in scope. AISI’s current research agenda also covers control, autonomy, human influence and societal resilience.
Frontier AI Trends Report and 2026 publications stream
AISI published its Frontier AI Trends Report on 18 December 2025. The government’s January 2026 progress report said AISI had more than 100 researchers and had tested 30 frontier models; those figures are a dated government snapshot, not a live model count.
AISI’s current research index lists publications through June 2026. Examples include:
- “Did you lie?”, on evaluating lie detectors across model scale (17 June 2026)
- Prefill awareness in large language models (10 June 2026)
- Loss of oversight, on how AI systems may become harder to audit, monitor and investigate (21 May 2026)
- Propensity inference, on environmental contributors to LLM behavior (24 April 2026)
- How are AI agents used?, drawing on evidence from 177,000 MCP tools (26 March 2026)
Activities and partnerships
- Model evaluations: AISI says it tests leading AI systems before and after public release.
- Open-source tooling: AISI publishes Inspect and other evaluation tools for wider research use.
- Current resourcing: AISI’s current organization page lists £66 million in funding per financial year and capacity to mobilise more than £15 million in grants.
- Collaboration: AISI describes work with UK and allied governments, research teams and leading AI companies; those relationships do not imply endorsement of a particular vendor or deployment.
Sectoral regulators
Unlike the EU’s centralised AI Office, the UK relies on existing regulators to govern AI within their domains. Each published a strategic AI approach in 2024 and has continued to refine guidance through 2025 and 2026.
| Regulator | Sector | Latest AI guidance |
|---|---|---|
| FCA | Financial services | AI Lab and AI Live Testing; Mills Review published 6 July 2026 with seven recommendations; AI good-and-poor-practice publication planned later in 2026 |
| PRA | Banks and insurers | SS1/23 Model Risk Management (effective May 2024; current published version dated 23 April 2026) |
| MHRA | Medical devices | AI Airlock phase 2 completed May 2026; program report updated 27 July 2026 and is not formal guidance; phase 3 design underway |
| ICO | Data protection | ADM and profiling consultation closed 29 May 2026; final guidance due winter 2026; separate AI code of practice in development during 2026/27 |
| Ofcom | Communications | Online Safety Act AI implications; synthetic media guidance |
| CMA | Competition | Foundation models review; AI partnership monitoring |
| Bank of England | Financial stability | AI roundtables summary (Feb 2026); FPC record (April 2026) flagged agentic AI in payments and markets as the next focus |
Digital Regulation Cooperation Forum (DRCF)
The FCA, CMA, ICO and Ofcom coordinate through the DRCF. The DRCF AI and Digital Hub continues to provide joint guidance for organizations working across multiple frameworks, and in 2026 has been a key channel for cross-regulator alignment around the AI Growth Lab.
UK GDPR and automated decision-making
The Data (Use and Access) Act 2025 changed the UK GDPR rules for solely automated significant decisions. For non-special-category data, those decisions may now rely on a wider range of lawful bases, but not the new recognized-legitimate-interests basis, and remain subject to safeguards.
Current safeguards for significant automated decisions
The reformed provisions apply where a decision is based solely on automated processing, with no meaningful human involvement, and produces a legal or similarly significant effect. The organization must provide safeguards that include:
- providing information about the decision;
- allowing the person to make representations and contest the decision; and
- allowing the person to obtain human intervention.
ICO AI and biometrics strategy update (March 2026)
The ICO’s March 2026 strategy update names three priority areas: foundation models, ADM in recruitment and public services, and police use of facial recognition. Recent ICO outputs include:
- Updated ADM and profiling guidance: consultation closed 29 May 2026; the ICO lists the final guidance as due in winter 2026
- AI code of practice: a separate workstream the ICO says it will develop during 2026/27
- Emerging-tech report on agentic AI (January 2026)
- Response to the Home Office consultation on biometrics, FRT and similar technologies (February 2026)
- Recruitment Rewired: updated guidance on automation in recruitment with the March 2026 blog “Automated decisions can streamline hiring with the right safeguards”
- Explaining decisions made with AI: joint ICO and Alan Turing Institute guidance remains available, while the DUAA-related ADM update is still being finalised
Data (Use and Access) Act 2025
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, introducing significant changes to UK data protection law and its interaction with AI. Most data-protection provisions came into force on 5 February 2026; the individual-rights provisions described below commenced on 19 June 2026.
Key changes for automated decision-making
- Wider permission for ADM: significant solely automated decisions involving non-special-category data may use a wider range of lawful bases, but not the new recognized-legitimate-interests basis
- Meaningful human involvement: a decision is solely automated when there is no meaningful human involvement in taking it
- Required safeguards: organizations must provide information, allow representations and contestability, and enable human intervention
- Special category data: the stricter regime continues to apply where sensitive data is involved
- Reformed adequacy test for international transfers, under which protection in third countries must be “not materially lower” than the UK standard
Implementation timeline
- Stage 1 (20 August 2025): initial provisions in effect
- Stage 2 (30 September 2025): additional changes effective
- 5 February 2026: bulk of data-protection provisions in force, including reformed ADM rules and children’s protections
- 19 June 2026: new individual right to complain and section 103 mandatory complaints procedure
Regulatory timeline
Already in effect
| Date | Development |
|---|---|
| April 2024 | FCA AI Update published |
| 17 May 2024 | PRA SS1/23 Model Risk Management effective |
| May 2024 | MHRA AI Airlock phase 1 launched |
| 14 February 2025 | AI Safety Institute renamed AI Security Institute |
| 19 June 2025 | Data (Use and Access) Act 2025 Royal Assent |
| 21 October 2025 | DSIT Blueprint for AI regulation; AI Growth Lab call for evidence opens |
| 18 December 2025 | AISI Frontier AI Trends Report published |
| 27 January 2026 | FCA Mills Review launched |
| 5 February 2026 | DUAA bulk data-protection provisions in force, including reformed ADM rules |
| February 2026 | Bank of England summary of AI roundtables published |
| March 2026 | ICO AI & biometrics strategy update |
| May 2026 | MHRA AI Airlock phase 2 completed after running from April 2025 to May 2026 |
| 6 July 2026 | FCA published the Mills Review with seven recommendations for its Board and Executive |
| 27 July 2026 | MHRA updated its AI Airlock phase 2 program report; the report is not formal regulatory guidance, and phase 3 design is underway |
Recent milestones and announced next steps
| Date | Development |
|---|---|
| 29 May 2026 | ICO ADM and profiling guidance consultation closed |
| 19 June 2026 | DUAA right to complain and section 103 in force |
| Later in 2026 | FCA says it plans to publish AI good-and-poor-practice material |
| Winter 2026 | ICO’s current plan lists final ADM and profiling guidance for publication |
| Q1 2027 | FCA AI Live Testing evaluation report |
| 2 December 2027 | Relevant EU AI Act high-risk obligations for Annex III systems |
| 2 August 2028 | Relevant EU AI Act product-embedded high-risk obligations for Annex I systems |
| 30 June 2028 / 2030 | Current GOV.UK transitional guidance uses category-specific CE-recognition endpoints: certain MDD/AIMDD devices reach the sooner of certificate expiry or 30 June 2028, while EU MDR/IVDR and certain IVDD routes run to 30 June 2030. A closed 2026 consultation proposed indefinite recognition for some routes, so 30 June 2030 is not a universal UKCA deadline. |
UK vs EU AI Act: key differences
A firm active in both markets is running two compliance models at once. The UK asks for judgment inside rules that already exist. The EU asks for a classification first, and a fixed set of obligations then follows from it.
| Aspect | UK approach | EU AI Act |
|---|---|---|
| Regulatory structure | Principles-based, sectoral | Horizontal legislation |
| Central authority | None. AISI evaluates only; DRCF coordinates | European AI Office + national authorities |
| Risk classification | No formal tiers | Four tiers: unacceptable, high, limited, minimal |
| Prohibited practices | None specified in AI law (existing laws apply) | Explicit bans on social scoring, certain biometrics, and manipulation |
| Compliance obligations | Flexible, outcome-focused | Prescriptive requirements per risk tier |
| Statutory basis | Non-statutory principles; sectoral statute (DUAA, MDR, etc.) | Directly applicable EU regulation |
| Current focus (2026) | Security and growth, through the DSIT Blueprint and the AI Growth Lab | Safety and fundamental rights, with the Omnibus delay reshaping the high-risk timeline |
UK companies can fall within the EU AI Act when they place systems on the EU market or when a system’s outputs are used in the EU, subject to Article 2’s conditions and exceptions. Under the AI Omnibus now in force, relevant high-risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product-embedded systems.
UK AI compliance checklist
Even without prescriptive AI-specific requirements, the following remains the working list:
Determine which regulators (FCA, MHRA, ICO, etc.) have jurisdiction over your AI use cases
Each regulator has published its strategic approach, so check your practices against the ones that reach you
Ensure automated decisions have appropriate safeguards and human review mechanisms
Designate accountable individuals for AI governance. In the 2024 joint FCA/Bank of England survey, 84% of respondent firms reported having an accountable person for their AI framework.
If operating in EU markets, ensure compliance with EU requirements regardless of UK rules
How GLACIS can support UK AI evidence work
The UK’s principles-based approach leaves organizations to connect applicable duties and supervisory expectations to their own controls and records. Glacis can contribute scoped operational evidence for configured AI workflows; it does not determine compliance, replace legal analysis, or establish that a control was effective.
Continuous attestation → accountability and governance
For in-scope events on a configured path, signed records can make covered fields and reported control outcomes independently checkable. The record does not establish complete coverage or regulatory acceptance.
Evidence pack → regulator inquiries
Evidence packages can organize signed records, declared scope and supporting context for review. They report covered actions and control outcomes; they do not explain a foundation model’s internal reasoning.
Evidence scope assessment → gap identification
Map an intended rule to a configured control, covered events, exclusions and the evidence available for review. Applicable legal conclusions remain with the organization and its advisers.
Mapping GLACIS to UK principles
| UK principle | GLACIS capability |
|---|---|
| Safety, security, robustness | Configured controls can record covered allow, block or escalation outcomes. Separate testing is still needed to assess robustness and effectiveness. |
| Transparency and explainability | Selected covered fields and reported outcomes can be exported for review. A receipt does not expose or explain internal model reasoning. |
| Fairness | Declared sampling and cohort fields can contribute to a fairness review; the record does not determine whether outcomes are fair. |
| Accountability and governance | Signed records can identify a configured control claim and reported outcome for a covered event. Responsibility mapping and effectiveness require separate evidence. |
| Contestability and redress | Retrieval of covered event records can contribute to complaint handling or access workflows, subject to the organization’s legal and data-governance process. |