For an Australian company opening a UK office, hiring UK staff, or selling an AI-enabled product to UK customers, the good news is that the regulatory philosophy will feel familiar. The bad news is that "familiar" is not "identical," and the gaps that do exist, particularly around data protection, financial services conduct, and the long reach of European Union law, carry real compliance cost if they are discovered after the fact rather than before. This guide sets out what an Australian compliance team can safely assume stays the same when moving into the UK, what changes in ways that require new controls, and a genuinely AU-specific wrinkle, the extraterritorial pull of the EU AI Act, that has no equivalent at home.

What stays the same: two principles-based, regulator-led systems

Australia has no standalone AI statute. It relies on the voluntary Guidance for AI Adoption issued by the National AI Centre (referred to on this site as AI6) sitting above binding, sector-specific law: the Privacy Act 1988 (Cth) enforced by the Office of the Australian Information Commissioner, APRA's CPS 230 for regulated financial entities, ASIC for financial services conduct, and sector regulators such as the Therapeutic Goods Administration and the Fair Work Commission.

The UK's model is structurally the same shape. In its white paper A pro-innovation approach to AI regulation, published by the Department for Science, Innovation and Technology on 29 March 2023, the government deliberately declined to legislate a cross-sector AI Act. Instead it set five cross-cutting principles, safety and security, appropriate transparency and explainability, fairness, accountability and governance, and contestability and redress, for existing regulators to interpret within their own remits. In practice that means the Information Commissioner's Office (ICO) for data protection, the Financial Conduct Authority (FCA) for financial services, Ofcom for communications, the MHRA for medical devices, and the Competition and Markets Authority (CMA) for competition, each applying the five principles through their existing statutory powers rather than through a single new AI regulator.

For an AU compliance team, the practical implication is that the discipline you already have, mapping AI use cases to the regulator with jurisdiction over the sector and outcome, transfers directly. There is no UK equivalent of an AI-specific licensing regime, conformity assessment body, or AI regulator to register with. What changes is which binding statute sits underneath the principles, and that is where the real work begins.

What changes: UK GDPR is a heavier data protection backbone than the Privacy Act

Both countries route most AI accountability through their general data protection law rather than through AI-specific rules, but UK GDPR imposes obligations the Privacy Act does not, and an AU team used to the Australian Privacy Principles should not assume equivalence.

  • Automated decision-making rights. Until 5 February 2026, Article 22 of UK GDPR gave individuals a right not to be subject to a decision based solely on automated processing, including profiling, where it produced legal or similarly significant effects, together with a right to obtain human intervention and to contest the decision. Section 80 of the Data (Use and Access) Act 2025 came into force on that date, under the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, repealing that prohibition and replacing it with new Articles 22A to 22D. The default is now a safeguards-based permission: a controller may make a significant automated decision on ordinary personal data without relying on a specific exception, provided it gives the individual information about the decision and a working route to obtain human intervention and to contest the outcome, not just a documented one. A stricter, consent-based prohibition remains where the decision relies on special category data under Article 9. The Privacy Act has no direct equivalent of this regime at any stage, so credit scoring, hiring screening, and claims triage tools that were compliant in Australia will usually still need a working contestability and human-review mechanism for UK data subjects.
  • Formal risk assessment obligations. UK GDPR Article 35 requires a Data Protection Impact Assessment before deploying processing likely to result in high risk to individuals, a category the ICO treats most AI profiling and automated decision systems as falling into. Privacy impact assessments are recommended OAIC practice in Australia but are not a general statutory precondition for private-sector processing in the way a DPIA is under UK GDPR.
  • Recent legislative change. The Data (Use and Access) Act 2025 received royal assent on 19 June 2025 and amends the UK's automated decision-making regime, among other areas. Its automated decision-making provisions, described above, took effect on 5 February 2026, and the ICO's final updated guidance on the new Articles 22A to 22D regime is still being finalised. An AU team should treat alignment with the new regime, and the ICO's forthcoming guidance, as an active workstream rather than settled law to build against once and forget.
  • Registration and representation. Most data controllers processing UK personal data must pay the ICO's annual data protection fee, tiered by turnover and staff numbers from roughly £52 to £3,763, as set out in the ICO's guide to the data protection fee. And until an Australian parent has an actual UK establishment, Article 27 UK GDPR generally requires appointing a UK representative for any UK-facing processing carried out in the meantime.
  • Cross-border transfers back to Australia. Australia is not currently covered by a UK adequacy regulation, so personal data moved from a new UK entity back to the Australian parent for group reporting, model training, or shared services needs a transfer mechanism, typically the UK's International Data Transfer Addendum or an International Data Transfer Agreement, rather than relying on free-flow assumptions that apply to adequate jurisdictions.
  • Enforcement scale. The Privacy Act's serious or repeated interference penalty is the greater of $50 million, three times the benefit obtained, or 30 percent of adjusted turnover during the breach period, per contravention. UK GDPR's higher enforcement tier allows fines up to £17.5 million or 4 percent of annual global turnover, whichever is greater. Both are large numbers, but they are calculated on different bases and a group-wide turnover figure calculated for one regime will not translate cleanly to the other.

The FCA Consumer Duty: an overlay AU financial services teams do not have

If the UK expansion touches retail financial services, credit, insurance, or investment products, there is a second layer that has no direct Australian counterpart. The FCA's Consumer Duty, set out in Policy Statement PS22/9, came into force on 31 July 2023 for products open to sale or renewal and 31 July 2024 for closed products and legacy books. It layers three cross-cutting rules, acting in good faith, avoiding foreseeable harm, and enabling customers to pursue their financial objectives, on top of four outcomes covering product governance, price and value, consumer understanding, and consumer support.

Where AI is embedded in credit decisioning, insurance pricing and claims, or product recommendation and advice journeys, UK regulators are treating those as areas of close scrutiny under the Duty rather than waiting for AI-specific rules. On 27 January 2026 the FCA opened a long-term review, informally known as the Mills Review, into how AI could reshape retail financial services. The FCA published the review's findings on 6 July 2026, setting out seven priority recommendations covering the regulatory perimeter, system-wide coordination and oversight, the transition to more autonomous AI models, the FCA's AI Lab, and the foundations for agentic finance. Separately, the FCA and the ICO issued a joint statement on 27 March 2026 confirming that data protection law does not prevent firms from collecting, recording, and sharing customer vulnerability data in order to meet Consumer Duty expectations, a narrower point specific to vulnerable-customer data rather than a general reconciliation of data protection with Consumer Duty requirements. APRA's CPS 230 and ASIC's conduct obligations do not have a direct equivalent of the Consumer Duty's outcomes-based, evidence-of-good-outcomes test. An AU compliance function accustomed to demonstrating operational resilience and conduct risk controls under CPS 230 will need to build a parallel evidence trail showing that AI-influenced customer outcomes are fair, not just that the system is operationally sound and the model was validated.

The EU AI Act's extraterritorial reach: a wrinkle with no AU equivalent

This is the genuinely new problem for an Australian team, one that does not arise when expanding into most other jurisdictions this site has profiled. The EU AI Act (Regulation (EU) 2024/1689), as amended by the Digital Omnibus and in force from 27 July 2026, applies under Article 2(1)(c) to providers and deployers established outside the EU whenever the output of their AI system is used within the EU. Crucially, the trigger is use of the output in the EU, not active targeting of EU customers. A UK subsidiary of an Australian company that serves EU customers, even incidentally, through a UK-based platform can fall inside the EU AI Act's scope despite having no EU establishment at all.

This is a real trap for AU groups whose UK entity is intended purely as a UK and Commonwealth hub. If that UK entity's AI-enabled product or service produces outputs consumed by users in Germany, the Netherlands, France, or Spain, whether through direct sales, group subsidiaries, or simply an accessible web platform, EU AI Act obligations can attach regardless of Brexit. High-risk obligations under Annex III are deferred to 2 December 2027 and Annex I obligations to 2 August 2028, but Article 50 transparency obligations, covering disclosure requirements for chatbots, deepfakes, and AI-generated content, take effect from 2 August 2026 and are not postponed. Nothing in the Australian Privacy Act, AI6 guidance, or APRA framework has an extraterritorial trigger of this kind, so this is not a case of applying a familiar AU instinct to a new label. It is a genuinely new compliance surface that has to be mapped separately, typically by tracing where the UK entity's AI outputs actually land, not just where its contracts are signed.

Concrete steps for an AU compliance team

  • Map every AI use case against both the ICO's five UK regulatory principles and the sector regulator with jurisdiction (FCA, MHRA, Ofcom, CMA), the same discipline used against AI6 and Australian sector regulators, but against a different list of bodies.
  • Run a UK GDPR gap assessment against existing Privacy Act controls, prioritising the Articles 22A to 22D automated decision-making safeguards introduced by the Data (Use and Access) Act 2025, Article 35 DPIAs for high-risk profiling, and the ICO's data protection fee registration.
  • Confirm whether an Article 27 UK representative is needed for any interim period before the UK entity is fully established and processing UK personal data locally.
  • Put a lawful transfer mechanism, an International Data Transfer Addendum or International Data Transfer Agreement, in place for any personal data flowing from the new UK entity back to the Australian parent, since no UK-Australia adequacy regulation currently exists.
  • If the business touches retail financial services, build a Consumer Duty evidence trail for AI-influenced credit, insurance, or advice decisions, separate from and in addition to existing APRA CPS 230 and ASIC conduct documentation.
  • Trace where UK-hosted AI outputs actually land. If any reach EU-based users, however incidentally, assess exposure under EU AI Act Article 2(1)(c), and prioritise Article 50 transparency obligations given their 2 August 2026 commencement.
  • Confirm the business is applying the Articles 22A to 22D safeguards that took effect on 5 February 2026, not the repealed Article 22 prohibition, and build a review checkpoint for when the ICO finalises its updated guidance on the new regime.

Primary sources

Related articles