The United Kingdom governs artificial intelligence without an AI Act. Its approach is deliberately pro-innovation: five cross-sector principles, applied by the existing regulators within their remits, over the top of existing law such as UK data-protection law, rather than a single horizontal statute or a new AI regulator. This page sets out the principles, the regulators, the dates, and what is binding versus proposed, with links to the sources for each.
Last reviewed: 21 July 2026 · A statutory framework has been signalled but not introduced; confirm against the primary sources linked below
The UK has not enacted an AI Act, and as of 2026 no AI Bill is before Parliament. Its framework rests on five cross-sector principles from the 2023 white paper: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. These principles are non-statutory. They shape how the existing regulators use their existing powers, rather than creating a new AI law.
In practice that means AI is regulated sector by sector: the ICO for data-intensive AI, the FCA for financial services, Ofcom for online platforms, the MHRA for medical AI, and the CMA for competition and consumer matters, with DSIT coordinating overall policy. In October 2025 the government published a blueprint and an AI Growth Lab of regulatory sandboxes as the near-term vehicle in place of a Bill, while signalling that a statutory framework, likely focused on the most advanced frontier models, could follow in a later parliamentary session.
The government white paper A Pro-Innovation Approach to AI Regulation set out five cross-sector, non-statutory principles for AI, to be applied by existing regulators within their remits rather than by a new AI law or AI regulator.
The government confirmed the principles-based, context-specific approach and asked key regulators to set out how they would apply the principles, rather than legislating a horizontal AI Act.
The Information Commissioner’s Office published its AI and biometrics strategy, Preventing Harm, Promoting Trust, setting out how it will supervise data-intensive AI under UK data-protection law.
Reforms to the UK data-protection regime, enforced by the ICO, updated parts of the framework that most directly touch AI systems processing personal data.
The Department for Science, Innovation and Technology published a blueprint for AI regulation, with an AI Growth Lab of issue-specific regulatory sandboxes in which rules can be relaxed for licensed pilots, positioned as the near-term vehicle in place of an AI Bill.
The distinction that matters most for compliance is whether an instrument carries legal force, is guidance, or is a proposal not yet introduced. The table below sorts the main instruments accordingly.
| Instrument | Status | Applies to / owner |
|---|---|---|
| Five cross-sector AI principles (2023 white paper) | Non-statutory framework | Applied by existing sector regulators within their remits, not a standalone law |
| UK GDPR and the Data (Use and Access) Act 2025 | Binding | Any organisation processing personal data, including in AI; enforced by the ICO |
| Sector regulators applying AI (ICO, FCA, Ofcom, MHRA, CMA) | Binding | AI is regulated through each regulator’s existing powers in its sector |
| DSIT blueprint for AI regulation and the AI Growth Lab | Policy and sandbox programme | Government direction and licensed pilots, not a binding obligation on all firms |
| A statutory AI framework / frontier-AI rules | Proposed, not introduced | Signalled for a future parliamentary session; may cover incident reporting and pre-deployment safety for frontier models |
| EU AI Act (Regulation (EU) 2024/1689) | Binding on UK exporters | UK organisations that provide or deploy AI in the EU market |
For the roles the EU AI Act allocates between providers and deployers, which reach UK exporters, see our guide to EU AI Act roles and the EU AI Act timeline.
Two practical points follow. First, the enforceable obligations on a UK organisation today come from the laws and regulators that already apply to it, above all UK data-protection law enforced by the ICO, and the sector regulators, applied to its use of AI. The five principles shape how those regulators act, but they are not themselves a separate legal duty. Second, this is a moving position: a statutory framework has been signalled for the future, so a UK AI governance approach should be built to absorb one, particularly for organisations developing or deploying the most advanced models.
Because much of the national layer is principle and guidance rather than statute, the weight of day-to-day AI governance sits with each organisation’s own framework and controls. Our AI GRC guide covers how those pieces fit together, and a short governance assessment benchmarks where an organisation stands against a structured model, which maps cleanly onto the five principles.
No. As of 2026 the UK has not passed an AI Act, and no AI Bill is before Parliament. AI is governed by a deliberately pro-innovation approach: five cross-sector principles applied by the existing regulators within their remits, over the top of existing law such as UK data-protection law. The government has signalled that a statutory framework, focused on the most advanced models, may come in a future parliamentary session, but no draft has been published.
The 2023 white paper set out five cross-sector principles: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. They are non-statutory: they guide how existing regulators apply their powers to AI rather than creating new legal duties on their own.
There is no single AI regulator. Instead, existing regulators apply the principles in their sectors: the ICO for data-intensive AI, the FCA for financial services, Ofcom for online platforms and media, the MHRA for medical AI, and the CMA for competition and consumer matters. The Department for Science, Innovation and Technology (DSIT) coordinates overall AI policy.
Possibly, but not yet. The government delayed legislating through 2025 and, in October 2025, published a blueprint and an AI Growth Lab of regulatory sandboxes as the near-term approach instead of a Bill. Ministers have indicated a statutory framework, likely centred on frontier AI (for example incident reporting and pre-deployment safety evaluation), could follow in a later session. As of 2026 there is no published draft or commencement date.
Yes, where a UK organisation provides or deploys AI systems in the European Union market, the EU AI Act can apply to it regardless of the UK’s own approach. For many UK firms with EU customers, the EU AI Act is the most concrete AI statute they face.
A short, free assessment benchmarks where your organisation stands against a structured AI governance model, useful precisely because the UK layer is principle and guidance rather than a single statute.
This page is general information describing the state of United Kingdom AI policy as at 21 July 2026, not legal or compliance advice. A statutory framework has been signalled but not introduced, and positions change; always confirm the current position against the primary sources linked above and obtain advice from your own qualified counsel before relying on it.