AI Governance Institute
Directory

AI Regulation in the United Kingdom

The United Kingdom has chosen a "pro-innovation" regulatory approach to AI, deliberately avoiding a standalone AI Act in favor of empowering existing sectoral regulators to apply principles-based guidance within their domains. The ICO governs AI data protection obligations under UK GDPR. The FCA and PRA issue AI-specific expectations for financial services firms. The CMA examines AI's impact on competition. Enforcement is distributed rather than centralized.

The UK AI Regulation White Paper (2023) established five cross-sector principles: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. These principles are not statutory — they guide regulatory interpretations and form the basis of sector-specific codes of conduct being developed by individual regulators. Organizations deploying AI in the UK should expect each regulator they already answer to (FCA, ICO, Ofcom, etc.) to issue AI-specific expectations within its existing framework.

The AI Safety Institute (rebranded as the AI Security Institute in 2024) focuses on frontier model evaluation and international AI safety standards rather than consumer-facing enforcement. Its work on evaluating pre-deployment frontier models has informed the UK's approach to AI safety agreements with major labs. A forthcoming AI Opportunities Action Plan and potential AI Bill signal that more structured legislation is coming, though the timeline remains uncertain.

Key themes

  • 1.Regulator-led, sector-specific guidance — no standalone AI Act
  • 2.ICO enforcement on AI and data protection under UK GDPR
  • 3.FCA AI expectations for financial services
  • 4.AI Security Institute frontier model safety evaluation

Regulatory frameworks and guidance(7)

Guideline

UK AI Growth Lab Regulatory Sandbox - Consultation on Two Models

DSIT opened consultation on the proposed UK AI Growth Lab in October 2025. The sandbox would allow AI testing under modified regulatory conditions. Options include central government administration across sectors or individual sandboxes managed by lead regulators. The aim is reduced compliance barriers with continued oversight.

Framework

UK AI Opportunities Action Plan

The UK published its AI Opportunities Action Plan in January 2025. It sets the Labour government’s adoption and infrastructure agenda for public bodies, developers, and AI enterprises. Commitments include AI Growth Zones, expanded computing infrastructure, and a National Data Library for development access.

PendingPending

UK AI Regulation Framework

The UK AI Regulation Framework assigns primary oversight to existing sector regulators using shared principles. Following January 2025’s AI Opportunities Action Plan, the approach is moving toward a more structured legislative basis.

Guideline

AI Risk Management Toolkit

The UK Government published this toolkit to help organizations understand, assess, and manage risk throughout the full lifecycle of AI projects. It applies to teams involved in designing, procuring, or delivering AI products and services, including public and private sector buyers. The toolkit provides structured guidance for embedding risk management into intake controls, procurement checklists, and delivery-stage governance.

Framework

UK-Canada AI Computing Power Collaboration Agreement

The UK and Canada signed an AI computing cooperation agreement on April 27, 2026. It provides for shared resources and joint investment supporting research and development. Government agencies and publicly supported researchers are its primary audience. Enterprises working within either national AI strategy may also be affected.

PendingPending

UK DSIT Call for Evidence on Data Regulation in the Age of AI and Other Data-Intensive Technologies

DSIT opened a call for evidence on adapting UK data law to AI and other data-intensive technologies. It addresses organizations collecting, processing, or sharing AI-related data, including agent deployments. Respondents are asked about transparency, provenance, and data-access control gaps.

PendingPending

Regulations Requiring the ICO to Produce a Statutory AI and Automated Decision-Making Code of Practice

UK statutory regulations direct the ICO to produce a code for AI and automated decisions involving personal data. It will cover organizations under UK data protection law using these systems to make or inform decisions about individuals. Once finalized, departures from the code may provide evidence of non-compliance in regulatory proceedings.