15032022 011 1

Legislation and regulation

A rundown of the key legislative and regulatory standards and frameworks around AI use.

Introduction

As of early 2026, the United Kingdom does not have a single, standalone "AI Act" nor a dedicated, general-purpose AI regulator. Instead, it operates under a pro-innovation, sector-led regulatory framework. This approach tasks existing regulators such as the Information Commissioner’s Office (ICO), the Competition and Markets Authority (CMA), and the Financial Conduct Authority (FCA) with applying AI governance within their specific domains, guided by five cross-sectoral principles: safety, transparency, fairness, accountability, and contestability. These principles currently remain non-statutory, relying on regulators to interpret and apply them using existing powers.

Significant legislative changes have recently come into force via the Data Use and Access Act 2025 (DUAA) which amends, but does not replace, the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA) and the Privacy and Electronic Communications Regulations 2003 (PECR).  These reforms expand the circumstances under which automated decision making is permitted, clarify that "scientific research" includes commercial technological development, and introduce new criminal offences for the non-consensual creation of deepfake intimate images.

Alongside these data-specific reforms, two legal statutes continue to provide critical safeguards for AI deployment. The

Register for an account

Create an SGA account and gain access to all our resources and courses.

Register

Already have an account? Log in.