AI regulation in United Kingdom
The UK has deliberately not passed a standalone AI Act, relying instead on existing sector regulators applying shared cross-sectoral principles. This is a live policy area and could change.
Pro-innovation, principles-based approach
Administered by Sector regulators (ICO, FCA, CMA, etc.), coordinated centrally.
- No dedicated AI statute and no AI-specific obligations. Existing law applies unchanged: data protection, equality, consumer, financial services and sectoral safety rules all reach AI systems already.
- Five non-statutory principles guide regulators — safety and robustness, transparency and explainability, fairness, accountability and governance, and contestability and redress.
- Obligations arrive through your sector regulator rather than through an AI law, so the compliance question is which regulator you already answer to.
No single AI regulator. The ICO, FCA, PRA, CMA, Ofcom, MHRA, HSE and NCSC each apply their existing powers and penalties within their own remit.
This page is a general orientation guide built from public sources, not legal advice, and it does not establish that any organisation complies with United Kingdom's requirements. AIC certifies governance against its own published standard; that is a different question from legal compliance, and neither substitutes for the other. Back to the map.