UK’s AI Regulatory Landscape
Current Regulatory Landscape
Unlike the EU AI Act, the UK has not yet enacted a single, comprehensive AI legislation. This is
largely due to fears of stifling innovation.
Instead, the UK has adopted a more flexible approach to regulating AI, established in the 2023 AI
White Paper. The White Paper empowers existing regulators, such as the Information
Commissioner’s Office (ICO) or the Equality and Human Rights Commission, to develop
tailored, context-specific regulations within their respective sectors.
For example, the ICO, which serves as the primary AI regulator for data protection matters under
UK GDPR and the Data Protection Act 2018, has introduced the “Preventing Harm, Promoting
Trust” strategy targeting AI and biometrics.
The AI White Paper also outlines five guiding principles to ensure the safe and innovative use of
AI in the industries monitored by regulators.
Data (Use and Access) Act 2025
The Data Use and Access Act 2025 (DUAA) primarily introduces reforms to the UK’s data
protection framework by amending the UK GDPR, the Data Protection Act 2018, and the
Privacy and Electronic Communications Regulations 2003. However, it also makes two
important contributions to AI regulation.
Firstly, the DUAA creates a more permissive framework under the UK GDPR for organisations
to implement automated decision-making that has legal or similarly significant effects on
individuals, provided they implement safeguards including transparency, meaningful human
intervention, and the right to contest.
Secondly, the DUAA sets a statutory deadline of 18 March 2026 for the Government to publish
an economic impact assessment and report on the use of copyright works in AI development. On
15 December 2025, the Government published the statutory progress statement required by
section 137 of DUAA. This summarised the results of the AI and Copyright consultation, where
88% of respondents supported strengthening copyright laws by requiring licensing for the use of
copyrighted material in AI training.
EU’s Competing Framework
In contrast to the regulatory guidance faced by UK businesses, EU businesses must comply with
mandatory, AI-specific rules. The EU AI Act establishes a risk-based approach to AI regulation
by classifying AI systems into 4 levels of risk: unacceptable risk (subject to prohibition), high risk
(subject to strict regulation), limited risk (subject to lighter obligations), and minimal risk (largely
unregulated). The higher the perceived risk, the stricter the rules.
The AI Act has also undergone simplification due to its complexity and overlap with other EU
digital laws.
Due to its extraterritorial reach, UK businesses trading in the EU must comply with the AI Act.
This creates particular challenges for UK organisations operating cross-border, who must
navigate both the UK’s principles-based approach and the EU’s risk-based approach.
The Prospect of a UK AI Act
The July 2024 King’s Speech included a bill that would impose requirements on those working
to develop the most powerful artificial intelligence models. That bill, however, did not
materialise.
Most recently, the Artificial Intelligence (Regulation) Bill (the AI Bill) was in the House of Lords.
Broadly, it aims to establish a central AI Authority to oversee the regulation of AI, codify the five
principles outlined in the White Paper, and require the AI Authority to engage with the public
when considering the development and implementation of AI regulations. Despite passing its
first reading, the AI Bill conflicts with the Government’s innovation-friendly strategy towards AI
and is therefore unlikely to receive support from the UK Government and become legislation.
Overall, the UK’s approach to AI regulation is deliberately flexible, relying on sector-specific
regulators and guidance rather than mandatory rules with a low prospect of a single
comprehensive AI legislation.
By Maria Chihai