Library
UK AI Regulation: Who Enforces What
As of 13 August 2026 there is no UK AI Act and no government AI bill before Parliament. Enforcement sits with existing regulators: ICO, CMA, FCA, MHRA, Ofcom, under existing law. A statutory ICO code on AI and ADM is required; the code itself is not yet in force.
Last reviewed
MikeFounder & developer
- UK AI
- AI governance
- Compliance
On this page
Who this is for
- UK operators who were told they can ignore AI rules because “the UK has no AI Act”
- Teams selling into the UK who need to know which regulator will actually write to them
- Readers mapping UK dates onto the global calendar
Current status of a UK AI bill
No dedicated UK AI Act is in force. No government AI bill is before Parliament as of 13 August 2026.
On 16 July 2026, answering a Lords question on AI legislation, the government restated a context-specific, sector-by-sector approach, pointed to existing statutes (including the Online Safety Act), and referred to a forthcoming cross-economy Regulating for Growth Bill rather than a horizontal AI statute. No timetable for a dedicated AI bill was given.
Lord Holmes's private member's AI Regulation Bill fell with the session on 30 April 2026. It is not pending law.
The 2023 white paper's five principles (safety, transparency, fairness, accountability, contestability) remain policy direction, not a statute you can be fined under by themselves.
This page will change if a bill is introduced. Until then, do not plan as if a UK AI Act were six months away, and do not plan as if nothing applies.
The regulator map
| Regulator | Remit that actually touches AI | What they use |
|---|---|---|
| ICO | Personal data, automated decisions, biometrics, PECR | UK GDPR (as amended by the Data (Use and Access) Act 2025), DPA 2018. ADM Articles 22A–22D live from 5 February 2026. Statutory AI and ADM code required by SI 2026/425 (in force 12 May 2026). Code not yet published. See the code tracker and the ADM regime. |
| CMA | Competition and consumer protection in digital markets | Existing competition and consumer law; Digital Markets, Competition and Consumers Act powers; work on foundation models and search. |
| FCA | Financial services | Consumer Duty (PRIN 2A), outsourcing (SYSC 8), operational resilience (SYSC 15A), model risk for PRA-regulated firms. No standalone FCA “AI rulebook”. |
| MHRA | Medical devices, including software and AI as a medical device | UK medical-devices framework; sandbox activity for AI as a medical device. If your tool diagnoses, triages or treats, start here, not with the ICO. |
| Ofcom | Online safety, telecoms, broadcast | Online Safety Act 2023; Telecoms Security Act 2021. Recommender systems, generative content on regulated services, network security. |
They coordinate through the Digital Regulation Cooperation Forum (DRCF) (ICO, CMA, FCA, Ofcom). MHRA sits closer to the health stack. DSIT sets policy. DSIT does not issue your enforcement letter.
Equality law, product safety, and sector licences do not pause because a model is involved.
What a UK operator should do first
- Inventory the systems, including vendor copilots. Building an AI system inventory.
- For each row, name the UK regulator that already has you, before asking about a future AI bill.
- If personal data and a decision about a person are in play, read DUAA ADM now, not in 2027.
- If you also place systems on the EU market, or the output is used there, add the EU timeline. The absence of a UK AI Act does not cancel Regulation (EU) 2024/1689.
Questions
Is there a UK AI Act?
No. As of 13 August 2026 there is no horizontal UK AI statute and no government AI bill in Parliament.
So nothing applies?
False. UK GDPR, DPA 2018, equality law, Consumer Duty, the Online Safety Act, medical-device rules and the rest apply to AI the same way they apply to any other system. The ICO's ADM rules are already rewritten.
Will the Regulating for Growth Bill be the AI bill?
Unknown. The government has pointed at it as the vehicle for regulatory sandboxes and related growth measures. It is not a published AI Act. Status unclear as of 13 August 2026. Verify before treating it as the source of AI duties.
We only have EU customers. Do we ignore this page?
If you have no UK establishment and no UK people, the ICO is not your first letter. The EU AI Act and GDPR still may be. If you have UK staff using the same tools, you are back on this map.
What changed
- 13 August 2026: First publication. Cadence: high-risk / fast-moving (30–90 days). Next review due 13 October 2026. Off-cycle if a government AI bill is introduced or SI 2026/425 produces a draft code.
Note: This is compliance consulting and training, not legal advice. We work alongside your legal counsel, translating regulation into operational reality rather than replacing them. For a structured pass, see AI compliance.
Was this helpful?
Also in the library
- The AI Vendor Risk ChecklistA procurement list you can actually use. Data handling, training-on-your-data, sub-processors, audit rights, and model-change notifications: the clauses that decide whether a vendor is safe to put on a live path.
- What Counts as High-Risk Under Annex IIIAnnex III is a use-case list, not a model list. Most Lathestone clients who over-classify do it because the tool is 'AI'; most who under-classify miss internal HR and customer-decision systems. Article 6(3) exemptions exist. They are narrow, and profiling is not one of them.
- Building an AI System InventoryStart with a list. Most governance programmes stall because nobody has an honest register of what is already in use, including the vendor copilots people forget to mention. The sheet below is the one we use in an audit. Copy it.