No. The United Kingdom has no AI Act. AI is governed by existing law applied by existing regulators: chiefly UK GDPR and the Data Protection Act 2018, alongside sector rules such as the Financial Conduct Authority's. Government has consistently preferred this route to a single dedicated AI statute.
Is there a single UK statute governing AI?
There is no UK AI Act. The House of Commons Library's briefing on AI regulation in the UK (CBP-10003, published 10 June 2026) sets the position out plainly: the UK has no AI-specific legislation covering AI as a technology, and there is no single AI regulator. The King's Speech of 13 May 2026 set out a substantial legislative programme and none of it is an AI Act. Private members' bills proposing a central AI authority have been introduced in the House of Lords in recent sessions, and none has become law.
That absence gets misread in both directions. It does not mean AI is unregulated. Parliament declined to write a separate rulebook for the technology and left the existing ones to apply to whatever you do with it. Automate a lending decision and you are in financial services law. Automate a sift of job applicants and you are in employment and equality law. The AI part changes the evidence you must produce, not the duty you owe.
Which existing laws already apply to AI in the UK?
Data protection law does most of the work. UK GDPR and the Data Protection Act 2018 engage the moment your system touches personal data, and the ICO's guidance on AI and data protection works through what that means for accountability, fairness, transparency and data protection impact assessments. Two changes since 2025 matter most.
First, section 80 of the Data (Use and Access) Act 2025 rewrote the rules on automated decision-making and came into force on 5 February 2026. Where a significant decision about a person is taken solely by automated processing, meaning there is no meaningful human involvement, the controller must put safeguards in place. Those safeguards must let the person be told about the decision, make representations about it, obtain human intervention, and contest it.
Read that as an engineering specification, because it is one. To let somebody contest a decision you must be able to reconstruct it: which inputs, which model version, which rule fired, who signed it off, when. If your system cannot produce that record on demand, the obligation is unmet however good the model is.
Second, the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 came into force on 12 May 2026. They require the Information Commissioner to prepare a statutory code of practice on developing and using AI and automated decision-making, and set no deadline for delivering it. So a code is coming, its text is not published, and the duties it will interpret are already live. Build to the underlying obligation rather than wait for the interpretation.
Beyond data protection: the Equality Act 2010 where outcomes discriminate, consumer protection law where practices mislead, the Online Safety Act 2023 where Ofcom's duties reach AI-driven services, and your own sector rules on top.
Which regulators police AI in their own sectors?
Yours does, whichever yours is. There is no AI regulator to register with, only the regulator you already answer to, now asking AI questions.
The ICO covers personal data and automated decisions. The FCA covers financial services, and its AI Lab runs AI Live Testing, a supervised environment for testing AI systems in real-world conditions. Ofcom holds the online safety duties, the CMA covers competition and consumer harm, and the HSE, Environment Agency and professional bodies apply their own rules.
The practical consequence: you are not building one AI file. You are answering several regulators who share one underlying question: what did the system do, on what data, and which named person was accountable.
What is the Regulating for Growth Bill, and what does it do for AI?
It is the closest thing to AI legislation in the current programme, and it is not an AI Act. The King's Speech 2026 background briefing notes describe a Bill doing two things: strengthening the statutory growth duty on regulators, and creating cross-economy sandboxing powers announced by the Chancellor in her 2026 Mais Lecture.
The briefing notes describe those powers as legal powers to allow existing rules to be temporarily relaxed, under strict controls, to test new products and technologies in real-world settings. Cross-cutting AI sandboxes are listed among the uses being explored, alongside autonomous shipping and defence technology. The notes also state that the legislation is not about deregulation, and that trials would run under safeguards for consumers, workers and human rights.
Alongside it sits the AI Growth Lab, a Department for Science, Innovation and Technology proposal for exactly that kind of sandbox. Its call for evidence closed on 7 January 2026, and legal services was chosen as the first sector for an advisory version, which I have covered in who should actually use it.
Two things follow. The Bill was announced, not passed, so nothing in it is a duty you owe today. And its direction is permission to test under supervision, not exemption from proof: a sandbox that relaxes a rule still expects you to show a regulator what happened inside it.
How does the UK approach differ from the EU AI Act?
The EU classifies the system; the UK examines the use. Under the EU AI Act you work out a risk classification and inherit the obligations attached to it. In the UK you work out which regulator holds your sector and which existing duty your particular use engages.
That reads like two compliance programmes. In practice the evidence converges. Both regimes want a durable record of what the system did, what data it acted on, and which human was accountable. Build it once and it answers both. Build it for neither and you will reconstruct it under time pressure, from logs never designed to be evidence.
Does the EU AI Act still reach UK companies?
Yes, and being outside the EU is not a defence. The Act reaches providers placing AI systems on the EU market, deployers established in the EU, and providers or deployers elsewhere where the system's output is used in the EU. A UK company selling into the EU, or serving EU users from Britain, is in scope. More detail on whether the EU AI Act applies to UK companies selling into the EU.
The timetable moved. The high-risk obligations once due on 2 August 2026 were deferred by the Digital Omnibus on AI: stand-alone Annex III high-risk obligations to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. The Article 50 transparency obligations stay largely on their original schedule.
Do not read the deferral as a reprieve. The proof requirements survived the move intact; only the date changed. It is a build window, not a pause.
What should a UK organisation do while the position is unsettled?
Stop waiting for a statute and start producing evidence. Every regime in play is converging on the same demand.
Four steps, in order. Inventory the decisions rather than the tools: list every consequential decision AI touches and name the person accountable for each outcome. Section 80 turns that name into a legal requirement. Isolate the solely automated ones, because where there is no meaningful human involvement in a significant decision you owe the safeguards now, not when the ICO's code lands. Keep a record you would hand a regulator: inputs, model version, output, approver, timestamp. Then secure the lifecycle. The NCSC's Guidelines for secure AI system development cover secure design, development, deployment, and operation and maintenance, and its framing is right: "Security must be a core requirement, not just in the development phase, but throughout the life cycle of the system."
This is the problem Mickai® was built around. The Mickai Sovereign Intelligence Operating System runs on hardware the customer owns, is capable of running offline, and moves no data off the estate, because a regulated organisation should not have to rent its intelligence to use it. Every consequential action waits for a named person to approve it. The Open Audit Record then seals that action under ML-DSA-65, the post-quantum signature scheme NIST published as FIPS 204 in 2024.
That record is tamper-evident, not tamper-proof, and the distinction is the point. Tamper-proof would be a claim that nobody can alter the record, and I will not make it. Tamper-evident means that if the record is altered, verification fails, and an auditor can establish that offline with a public key, using tools that are not ours. You do not have to trust us to check us.
I am not arguing against the companies building the compute and cloud layer. Cloud remains the right answer for plenty of work outside the regulated perimeter. What I am arguing against is the assumption that a regulated organisation must ship its data offsite and then take a vendor's word for what happened to it. That is a choice, and there is now another option, set out on our sovereign AI page. Our closed beta is open, with one regulated company onboarding as a design partner.
Frequently asked questions
Has the UK passed an AI Act, and will it introduce one later?
No. The UK has not passed an AI Act and none appears in the 2026 legislative programme announced in the King's Speech. Government policy has consistently favoured applying existing law through existing regulators. A future statute is possible, but nothing currently before Parliament would create one, and no commitment to a date has been made.
Which regulator enforces AI rules in the UK?
There is no single AI regulator. Enforcement sits with whichever regulator already covers your activity. The ICO handles personal data and automated decisions, the FCA covers financial services, Ofcom covers online safety, and the CMA covers competition and consumer harm. Sector bodies such as the HSE and the Environment Agency apply their own rules to AI within their remits.
Does the EU AI Act apply to a UK business?
It can. The EU AI Act reaches providers placing AI systems on the EU market, deployers established in the EU, and providers or deployers outside the EU whose system output is used in the EU. A UK company selling into the EU or serving EU users is therefore in scope, regardless of where its infrastructure sits.
What is the Regulating for Growth Bill?
A Bill announced in the King's Speech on 13 May 2026. It would strengthen the statutory growth duty on regulators and create cross-economy sandboxing powers letting existing rules be temporarily relaxed, under strict controls, to test new technologies in real-world settings. Cross-cutting AI sandboxes are among the uses being explored. It is not an AI Act and is not yet law.
Do we still need a data protection impact assessment if there is no UK AI Act?
Yes. DPIA duties come from UK GDPR and the Data Protection Act 2018, not from any AI statute, so the absence of a UK AI Act changes nothing. The ICO's guidance on AI and data protection treats AI systems processing personal data as squarely within those duties, and a high-risk processing operation requires an assessment before you start.
Related briefings
UK AI regulation
- AI Cyber Security Code of Practice: Who It Applies To
- Does Cyber Essentials Cover the AI Tools Your Staff Use?
- ICO Code of Practice on AI and Automated Decision-Making
- ISO 42001 vs ISO 27001: Do You Need Both Standards?
- AI for Essential Services: What UK Regulation Requires
Data protection and UK GDPR
- UK GDPR and AI: Does Your Data Have to Stay in the UK?
- UK Data Storage vs AI Processing: What Is the Difference
Part of a series of 60 briefings on deploying and governing AI in UK regulated organisations, archived with a DOI at 10.5281/zenodo.22975756.
Evaluating AI for a regulated organisation? Mickai runs on hardware you own, offline. Consequential actions wait for a named person to approve them, and what the AI did is sealed into a signed record an auditor can check without us. Applications for the invitation-only closed beta are open. Apply for the closed beta.
Written by Micky Irons, founder and chief executive of Mickai LTD.
Top comments (0)