Artificial Intelligence in the United Kingdom

Enforcement / fines in the United Kingdom

In the UK, AI is primarily governed through the existing powers of regulators such as the Competition and Markets Authority (CMA) and ICO, alongside sector-specific regulators including the FCA and Ofcom.

In addition, the Digital Regulation Cooperation Forum (DRCF) was established to facilitate coordination between these regulators on cross-sector digital risks and has launched an AI and Digital Hub to support businesses developing and deploying innovative technologies.

The ICO, CMA, FCA and Ofcom have all become more active in addressing AI-related risks. The ICO has moved into active enforcement, including investigations into the use of personal data in AI systems and enforcement action relating to children’s data, while the CMA has focused on the consumer law implications of agentic AI and emphasised business accountability for AI agents (particularly consumer protection around misleading outputs, unfair commercial practices and accountability for automated customer journeys). The FCA has highlighted the transformative impact of AI on financial services and the growing risks of AI-enabled fraud (and has mentioned it will rely on existing frameworks such as Consumer Duty and Senior Managers and Certification Regime (SM&CR)), and Ofcom has used its powers under the Online Safety Act 2023 to investigate AI-generated harms and age-assurance failures. Across regulators, common priorities include transparency, accountability and governance in AI systems, protection of children and vulnerable users, and increased cross-regulator coordination through the DRCF.

Continue reading

  • no results

Previous topic
Back to top