The UK's deliberate regulatory choice
When the EU was developing the AI Act, the UK government was making an explicit choice to go in a different direction. The 2023 AI White Paper articulated a "pro-innovation" approach: rather than enacting prescriptive horizontal AI legislation, the UK would rely on existing sector regulators to apply their domain expertise and existing powers to AI, guided by five cross-sector principles, safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress.
This approach reflects a genuine philosophical difference from the EU's risk-based classification framework. The UK's position is that sector regulators are better placed to assess AI risks in their domains than a central legislative framework. Whether this proves correct depends significantly on how effectively sector regulators adapt their frameworks to AI's distinctive characteristics.
ICO: UK GDPR and AI
The Information Commissioner's Office is the most active UK regulator in AI governance, both because UK GDPR applies broadly to AI systems processing personal data and because the ICO has invested significantly in developing AI-specific guidance. The ICO's Explaining Decisions Made with AI guidance, developed in partnership with the Alan Turing Institute, addresses automated decision-making in AI contexts and provides practical guidance on what meaningful explanation looks like. The ICO itself is also changing shape, under the Data (Use and Access) Act 2025, the single Information Commissioner role is being replaced by a board led body corporate, the Information Commission, with a Chair, a chief executive and non-executive directors. This governance transition is being phased in through 2026 and does not itself change the substantive guidance discussed below.
UK GDPR's Article 22 originally gave individuals a right not to be subject to solely automated decisions producing legal or similarly significant effects. Since 5 February 2026, the Data (Use and Access) Act 2025 has substituted Article 22 with new Articles 22A to 22D, turning what was a general prohibition into a safeguards regime, solely automated significant decisions are now permitted for most personal data, provided organisations give the individual information about the decision, a way to make representations, a route to human intervention, and a means of contesting the outcome. Special category data under Article 9 UK GDPR remains subject to a stricter rule, solely automated decisions using that data stay prohibited unless a specific Article 9 condition is met alongside the safeguards. The ICO consulted on updated automated decision-making guidance reflecting these changes between March and May 2026, with final guidance expected later in 2026. The ICO has been active in enforcing data protection requirements in AI contexts and has brought enforcement action against several organisations for algorithmic practices that breached UK GDPR. For any organisation using AI in significant decisions affecting UK individuals, credit, insurance, employment, healthcare, ICO's AI guidance should be treated as the baseline compliance expectation, now built around the Article 22A to 22D safeguards framework rather than the original Article 22 prohibition.
FCA: AI in financial services
The Financial Conduct Authority has engaged extensively with AI governance in financial services. The FCA's 2022 joint discussion paper DP5/22 with the Bank of England and the Prudential Regulation Authority on AI and machine learning identified the key governance challenges and signalled regulatory expectations. The FCA's Consumer Duty (effective 2023) creates obligations for good consumer outcomes that interact directly with AI governance, AI-driven systems that lead to poor consumer outcomes, through design or error, are a Consumer Duty concern regardless of whether they were AI-driven.
The FCA has been pragmatic about AI adoption in financial services, recognising its potential for beneficial outcomes alongside governance risks. Its approach has been to engage with industry through its AI Lab, launched in October 2024, whose Supercharged Sandbox gives firms GPU compute, enriched datasets and expert support to test AI use cases, run with NVIDIA and, for its second 2026 cohort, with Anthropic, alongside the FCA's existing digital and regulatory sandboxes, while making clear that existing regulatory obligations apply to AI as to other means of delivering financial services.
The EU AI Act problem for UK organisations
One consequence of Brexit that UK organisations sometimes underestimate is the EU AI Act's extraterritorial reach. The Act applies to providers who place AI systems on the EU market or put them into service in the EU, operators who use AI systems in the EU, providers and operators outside the EU where the output of their AI system is used in the EU. UK organisations are within scope on those tests regardless of the UK's own regulatory approach. This means that while UK-based organisations are not subject to UK AI legislation, they may simultaneously be subject to EU AI Act obligations for their EU-facing activities. Managing this dual environment, UK GDPR and ICO for domestic activities, EU AI Act for EU-facing activities, is the practical governance challenge for many UK organisations.
Related reading
- AI Governance by Industry in the UK: FCA, ICO, CQC, and Sector-Specific Requirements
- AI Governance for UK Small Businesses: What the ICO, ACAS, and UK GDPR Actually Require
- UK ICO AI Guidance 2026: Data Protection Obligations for AI Systems Under UK GDPR
- AI in UK Insurance: FCA Consumer Duty, PRA Expectations, and What Insurers Must Do Now
Further reading: ICO AI guidance