Detailed comparison
| Aspect | UK | EU AI Act |
|---|---|---|
| Regulatory structure | Principles-based and sectoral. Existing regulators (FCA, MHRA, ICO, Ofcom, CMA) apply existing law within their domains. The AI Growth Lab offers coordinated regulatory advice within current rules; broader waivers or new powers would require legislation. | Horizontal regulation. Single legal framework applies across all sectors with uniform requirements. |
| Central authority | None. AI Security Institute evaluates frontier AI but does not regulate. DRCF coordinates regulators. | European AI Office at EU level. Each member state designates national competent authorities. |
| Risk classification | No formal tiers. Risk assessment left to individual regulators and organizations. | Four tiers: unacceptable (banned), high-risk (strict requirements), limited risk (transparency), minimal (no requirements). |
| Prohibited practices | No AI-specific prohibitions in law. Existing laws (Equality Act, UK GDPR) apply. | Explicit bans: social scoring, real-time remote biometric ID (exceptions), manipulation, emotion recognition in workplaces and schools. |
| High-risk requirements | Depends on sector. FCA: Consumer Duty and SM&CR. MHRA: current medical-device rules. No unified AI-specific requirements or single horizontal commencement date. | Conformity assessment, risk management, data governance, logging, human oversight, transparency, accuracy / robustness testing, registration. |
| Documentation | Existing sectoral requirements apply. No AI-specific documentation mandates. | Extensive: technical documentation, quality management system, instructions for use, conformity declaration, EU registration. |
| Penalties | Vary by regulator. FCA can impose unlimited fines. ICO up to £17.5M / 4% turnover. | Up to €35M or 7% global turnover (prohibited practices), €15M or 3% (listed operator and Article 50 transparency obligations), and €7.5M or 1% (incorrect, incomplete, or misleading information supplied on request). |
| Timeline | Ongoing. No comprehensive horizontal AI Act. Existing law and sector regulators remain central; the AI Growth Lab operates as an advisory route within current rules, while any broader statutory powers require legislation. | Prohibitions in force Feb 2025; GPAI model duties from Aug 2025. Under the AI Omnibus now in force, relevant Annex III high-risk duties apply from 2 Dec 2027 and relevant Annex I product-embedded duties from 2 Aug 2028. |
| Legal basis | Non-statutory principles. Relies on existing legislation (UK GDPR, DUAA 2025, sectoral statute). | Directly applicable EU regulation with legal force in all member states. |
Extraterritorial impact: when EU rules apply to UK companies
The EU AI Act can apply to UK companies when they place AI systems on the EU market or when a system’s outputs are used in the EU, subject to Article 2’s conditions and exceptions. The AI Omnibus now sets the relevant high-risk dates; it does not change the need for a system-specific territorial-scope analysis.
The EU AI Act has broad extraterritorial reach. Article 2 specifies it applies to:
- Providers placing AI systems on the EU market — regardless of where they are established
- Deployers of AI systems located within the EU
- Providers and deployers in third countries where AI output is used in the EU
- Importers and distributors of AI systems in the EU
Practical implications
- Selling AI software into the EU can bring a provider within scope when the Act’s territorial and material conditions are met
- EU subsidiaries using UK-developed AI should assess their role and obligations system by system
- For third-country providers or deployers, output used in the Union can trigger scope under Article 2(1)(c), subject to the Act’s conditions and exceptions
- Products containing AI sold in the EU may face AI Act duties alongside applicable product-safety law
- The AI Omnibus is in force: relevant Annex III high-risk duties apply from 2 December 2027; technical standards and system-specific conformity planning still require advance work
Dual compliance strategy
Organizations operating in both markets can use a shared controls-and-evidence baseline, then map distinct EU legal duties and UK sector expectations. The AI Omnibus changes specified EU high-risk dates; it does not make the two regimes interchangeable.
Recommended approach
Classify AI systems under EU AI Act
Determine the applicable EU risk category and the UK sector rules for each system. For EU high-risk systems, map the enacted 2 December 2027 or 2 August 2028 date to the correct pathway.
Map the EU duties precisely
Identify the documentation, risk-management, data, oversight and monitoring duties that apply to each EU role and system. Do not assume that meeting them resolves UK sector requirements or future UK policy.
Layer UK sectoral requirements
Add UK-specific obligations from relevant regulators (FCA Consumer Duty, PRA SS1/23, MHRA medical device rules, ICO ADM requirements, and DUAA section 103, which commenced 19 June 2026) on top of EU compliance.
Maintain dual documentation
Keep separate obligation maps and submission artefacts while reusing defensible source records where appropriate. Reuse reduces duplication; it does not make the regimes or review processes equivalent.
Key differences in practice
Risk assessment
No prescribed methodology. Organisations determine approach. Regulators expect “proportionate” risk consideration aligned with the five principles.
Article 9 mandates risk management systems for high-risk AI: identification, analysis, evaluation and mitigation throughout the lifecycle.
Human oversight
For relevant solely automated significant decisions, the DUAA safeguards include telling the person, allowing representations, and enabling them to obtain human intervention. The ICO consultation on draft ADM and profiling guidance closed on 29 May 2026; final guidance had not been published on the consultation page as of 26 August. Sectoral requirements may apply on top.
Article 14 mandates human oversight for high-risk AI with specific capabilities: understanding, monitoring, interpreting, deciding to override, and stopping the system.
Transparency
“Appropriate transparency” principle. ICO guidance on explaining AI decisions. No mandatory disclosures for AI interaction (unlike EU chatbot rules).
Article 50 imposes defined transparency duties for certain direct AI interactions, synthetic or manipulated content, emotion recognition and biometric categorization, subject to the provision’s obviousness, law-enforcement, editorial, artistic and other context-specific conditions and exceptions.
Timeline comparison
| Date | UK development | EU AI Act milestone |
|---|---|---|
| Feb 2025 | AI Safety → AI Security Institute rename | Prohibited AI practices banned |
| Jun 2025 | DUAA Royal Assent | — |
| Aug 2025 | DUAA stage 1 effective | GPAI model obligations apply |
| Sep 2025 | PRA SS1/23 model-risk principles (current version 23 Apr 2026) | — |
| Oct 2025 | DSIT Blueprint for AI regulation; AI Growth Lab call for evidence opens | — |
| Nov 2025 | — | EU Commission tables Digital Omnibus on AI (19 Nov 2025) |
| Dec 2025 | AISI Frontier AI Trends Report | — |
| 27 Jan 2026 | FCA Mills Review launched | — |
| 5 Feb 2026 | DUAA bulk data-protection provisions in force | — |
| Mar 2026 | ICO AI & biometrics strategy update | — |
| Apr–May 2026 | FCA AI Live Testing cohort 2; AI Airlock phase 2 completes in May | — |
| 6–7 May 2026 | — | Omnibus provisional agreement (historical milestone) |
| 19 Jun 2026 | DUAA section 80 ADM safeguards and separate section 103 complaints duty in force | — |
| 27 Jul 2026 | — | AI Omnibus enters into force as Regulation (EU) 2026/1744 |
| 6 Jul 2026 | FCA publishes Mills Review and seven recommendations for its Board and Executive to consider | — |
| Next | MHRA AI Airlock phase 3 design in progress; follow official MHRA updates for timing and eligibility | — |
| No later than 2 Dec 2027 | — | Relevant Annex III high-risk duties apply |
| No later than 2 Aug 2028 | — | Relevant Annex I product-embedded high-risk duties apply |
Sector-specific considerations
Financial services
- · Consumer Duty applies to relevant AI-enabled retail outcomes; Mills Review published 6 July 2026
- · SM&CR accountability for AI decisions
- · SS1/23 Model Risk Management — automated monitoring expected
- · Principles-based, outcomes-focused approach remains the FCA baseline
- · AI Live Testing cohort 2 running through end-2026
- · BoE FPC priority: agentic AI in payments and markets
- · Creditworthiness evaluation or credit scoring for natural persons is listed, except fraud detection
- · Life-and-health risk assessment or pricing for natural persons is listed; insurance generally is not
- · Apply Article 6 classification and the applicable conformity pathway
- · Registration duties and Article 6(3) documentation depend on the classification result
- · Relevant Annex III high-risk duties apply from 2 Dec 2027
Healthcare
- · AI Airlock phase 2 completed May 2026
- · Phase 2 reports are not formal MHRA guidance
- · AI Airlock phase 3 design is in progress
- · Conformity and transition rules depend on device and certificate
- · Post-market surveillance in force since June 2025
- · NHS AI & Digital Regulations Service consolidates guidance
- · Article 6(1) requires both Annex I product-law coverage and a required third-party conformity assessment
- · Where that trigger is met, AI Act and MDR / IVDR duties can apply together
- · The product’s actual classification determines whether a notified body is required
- · Relevant Annex I product-embedded duties apply from 2 Aug 2028
How GLACIS can support dual-market evidence preparation
Operating in both markets means mapping the EU’s legal requirements and the UK’s sector-based expectations separately. The AI Omnibus sets the EU high-risk dates now in force; UK sector timelines continue independently. A shared evidence infrastructure can support both mappings without implying that one regime’s requirements satisfy the other.
Reuse evidence without equating regimes
For an instrumented workflow, GLACIS can preserve selected control-execution records that teams may reuse when preparing UK and EU materials. Each regime still requires its own legal, technical and sector-specific assessment.
EU AI Act technical documentation
Covered high-risk AI systems need technical documentation under the EU AI Act. GLACIS can capture operational evidence relevant to risk management, data governance, human oversight, and performance; legal sufficiency remains system- and pathway-specific.
UK principles evidence
Signed records of selected runtime events and control decisions may help a team prepare evidence for internal review or a regulator-facing process. GLACIS is not integrated with the FCA, PRA, MHRA, ICO or Bank of England, and no regulator acceptance or legal sufficiency is implied.
Potential evidence contributions across both regimes
| Requirement | EU AI Act | UK approach | Potential GLACIS contribution |
|---|---|---|---|
| Risk management | Article 9 RMS | Sectoral guidance | Timestamped records of selected configured controls and review events; not a complete risk-management system |
| Human oversight | Article 14 | DUAA meaningful intervention (5 Feb 2026) | Captured override and escalation events with available operator context |
| Transparency | Article 13 / Article 50 | Principle 2 | Export of the events and fields actually captured; completeness must be assessed separately |
| Accuracy and robustness | Article 15 | Principle 1 | Binding of supplied performance metrics and configured guardrail events to versioned context |
| Post-market monitoring | Article 72 | Sectoral post-market surveillance under current MHRA requirements | Configured production records may support incident correlation; reporting sufficiency remains pathway-specific |
| Individual rights / contestation | Article 86 right to explanation | DUAA section 80 / new UK GDPR Articles 22A–22D | Retrieval of captured decision and review events may support investigation and response preparation |