Artificial Intelligence in the United Kingdom
Human oversight in the United Kingdom
Law / proposed law in the United Kingdom
A single specific law addressing AI has not been implemented in the UK yet. The UK Government continues to favour a pro-innovation, sector-led model, with existing regulators applying current legal frameworks and sector-specific powers to AI-related risks. That said:
- Two Private Members’ Bills relating to the regulation of the use of AI systems have been put before Parliament. The first relates to decision-making processes in the public sector, the Public Authority Algorithmic and Automated Decision-Making Systems Bill, introduced to the House of Lords by Lord Clement-Jones on 9 September 2024. The second is Lord Holmes’ Artificial Intelligence (Regulation) Bill, introduced on 4 March 2025, which would establish a central AI Authority, regulatory sandboxes and require an AI officer for organisations deploying AI. There has been little progress in the parliamentary programme.
- In October 2025, the Government announced its blueprint for AI regulation, which identified some of the tools it sees as necessary to deliver this growth and drive modernisation of key UK sectors. Part of these proposals include the use of regulatory sandboxes in key sectors (such as healthcare, professional services, transport, and the use of robotics in advanced manufacturing) to foster responsible development of AI. While the proposals are cross-sector in nature, the focus appears to be more on reducing barriers to growth. The Government launched a call for evidence, which closed on 7 January 2026, to seek views on the AI Growth Lab. In June 2026, the Ministry of Justice announced the first sector-specific advisory AI Growth Lab for legal services, bringing together legal-sector regulators to support responsible AI innovation in LawTech.
- Most recently, the King’s Speech of 13 May 2026 trailed a Regulating for Growth Bill, which aims to reduce the burden of unnecessary regulation through innovation, enable regulatory sandboxes, and help the UK safely seize opportunities from AI and other emerging technologies. More concrete proposals are expected as the legislative session progresses. In July 2026, following a change in Government leadership, incoming Prime Minister Andy Burnham’s team is reported to be seeking to revamp the UK’s AI strategy, addressing emerging challenges whilst fostering innovation and safeguarding public interests.
There are, however, many UK laws (relating to data protection, intellectual property, human rights, equalities, employment laws, etc.) that impact various aspects of AI development, deployment and use.
On data protection for example, the Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025. Although not an AI-specific statute, the DUAA is expected to play a significant role in the UK’s AI ecosystem by improving access to and use of data across regulated sectors, in turn, supporting AI development and innovation. The most relevant amendments impacting the use of AI in the UK are those related to automated decision-making, which took effect on 5 February 2026. The previous regime generally prohibited solely automated decisions (with no meaningful human involvement), including profiling, that had a significant legal effect, unless there was explicit consent or it was necessary for the entry into or performance of a contract. The DUAA moves the dial to a more permissive framework, aimed at reducing compliance burdens while in parallel mandating new safeguards (outlined in more detail in our guide to Data Protection Laws of the World). Automated decision-making is now permitted with those new safeguards implemented, unless special category data (e.g. health data) is involved, and organisations can now rely on legitimate interests as a lawful basis (i.e. instead of consent, which is hard to obtain, or contractual necessity, which was often difficult to establish for efficiency gains). Notably, the DUAA clarifies that human review must be ‘substantive and informed’, i.e. a human must be able to challenge or override an AI-driven decision or profile generation, but they do not necessarily need to be involved at all stages. This is important, as the Information Commissioner’s Office (ICO) has indicated that enforcement action may be prioritised where automated decision-making systems fail to offer meaningful human intervention, or where the lack of these safeguards could lead to significant discrimination or unfair treatment of individuals.
Regulatory guidance / voluntary codes in the United Kingdom
On 29 March 2023, the UK Government published a White Paper: A pro-innovation approach to AI regulation (White Paper) elaborating on the approach to AI set out in its 18 July 2022 AI Governance and Regulation Policy Statement. The White Paper set out proposals for implementing a proportionate, future-proof and pro-innovation legislative framework for regulating AI and identified five key principles (para 48, section 3.2.3):
- Safety, security and robustness.
- Appropriate transparency and explainability.
- Fairness.
- Accountability and governance.
- Contestability and redress.
On 31 January 2025, the UK Government published a Code of Practice for the Cyber Security of AI (Code) setting out cyber security requirements applying throughout the lifecycle of AI systems. The Code consists of 13 principles to be voluntarily applied by relevant groups within the AI Supply chain, namely system operators, developers, data custodians, end-users and other affected entities, with each principle linked to a particular stage of the AI system lifecycle.
On 31 July 2025, the British Standards Institution (BSI) launched the world’s first international standard for independent audits of AI systems aiming to ensure consistent evaluation of AI reliability, fairness and safety.
Additionally, in July 2025, the Government signed non-binding arrangements with several frontier AI model providers, to foster adoption in public services including deployment in ‘AI Growth Zones’.
The AI Security Institute continues to publish evaluations of frontier AI models and released an inaugural capabilities report assessing the most advanced AI systems in December 2025.
In April 2026, the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 were made, coming into force on 12 May 2026. These Regulations require the Information Commissioner to prepare a statutory code of practice on the processing of personal data in relation to developing and using AI and automated decision-making systems.
In June 2026, the Government established the AI Economics Institute (AIEI), a joint unit between HM Treasury and the Department for Science, Innovation and Technology, to analyse the economic impacts of advanced AI. The AIEI aims to strengthen the evidence base on how AI affects productivity, labour markets, firms and income distribution, supporting a proactive UK approach to shaping AI’s economic impact.
In March 2026, the Government published a report and impact assessment on Copyright and Artificial Intelligence, fulfilling its commitment under the Data (Use and Access) Act 2025. The report addresses how copyright law should apply to the training of AI models, including consideration of whether to introduce a text and data mining exception for commercial purposes. Following extensive consultation, the Government confirmed that it no longer has a preferred policy option, and is gathering further evidence while engaging stakeholders on potential approaches.
Appointed supervisory authority in the United Kingdom
A single supervisory body with authority for AI has not yet been appointed in the UK by way of statutory appointment – see the Enforcement / Fines section.
However, Lord Holmes’ proposed AI (Regulation) Bill seeks to create a central statutory AI Authority, which would coordinate oversight across sectors and set governance standards. In July 2026, the new Government under Prime Minister Andy Burnham appointed Kanishka Narayan MP as Minister for AI, with a portfolio including AI opportunities, the AI Security Institute, semiconductors and online safety.
Definitions in the United Kingdom
Beyond existing controller and processor definitions in UK data protection, a specific single law addressing AI and imposing AI definitions has not been introduced in the UK yet.
Prohibited activities in the United Kingdom
There is no single UK statute specifically prohibiting AI activities. However, DUAA introduced new criminal offences relevant to the use of AI, including the offences of creating, or requesting the creation of, a ‘purported intimate image of an adult’ (i.e. non-consensual sexual deepfakes). These offences, inserted into the Sexual Offences Act 2003 by section 138 of the DUAA, came into force on 6 February 2026. In addition, the Crime and Policing Act 2026 criminalises the making, adapting, supplying or offering to supply ‘nudification’ tools (software that generates or facilitates the generation of purported intimate images of a person). The Act broadly defines ‘thing’ to include a program, information in electronic form and a service. A defence applies where the defendant proves they took all reasonable steps to prevent the thing being used for creating purported intimate images without consent. These provisions complement existing offences under the Online Safety Act 2023 relating to the sharing or threatening to share intimate content without consent.
High-risk AI in the United Kingdom
Sector regulators are looking at high risks posed by AI in their sectors and the Financial Conduct Authority (FCA), the Office of Communications (Ofcom) and the Medicines and Healthcare products Regulatory Agency (MHRA) are increasingly embedding AI principles into their existing frameworks. Use of AI is likely to trigger the need for a data protection impact assessment where personal data is involved in the design, development and/or deployment.
Controls on generative AI in the United Kingdom
Organisations developing or using AI must comply with existing legislation, including the Equality Act 2010, Data Protection Act 2018, UK GDPR and, now, the Data (Use and Access) Act so those existing controls should be considered.
Additionally, the Crime and Policing Act 2026 amends section 216 of the Online Safety Act 2023 to empower the Secretary of State to make regulations aimed at minimising or mitigating risks of harm to individuals arising from illegal AI-generated content and from the use of AI services for the commission or facilitation of priority offences. Once such regulations are made, AI chatbots and other AI services currently falling outside the scope of the Online Safety Act (i.e. those that do not feature user-to-user sharing or live web searches) will be subject to duties to minimise or mitigate the risks of harm to UK users. These measures are intended to address concerns around children’s interactions with AI chatbots and other AI-related online harms. Given the Online Safety Act’s broad extraterritorial reach to providers whose services have a significant number of UK users or where UK users are among its target markets, the new provisions introduced by the Crime and Policing Act 2026 are likely to affect a wide range of AI service providers regardless of where they are established.
Enforcement / fines in the United Kingdom
In the UK, AI is primarily governed through the existing powers of regulators such as the Competition and Markets Authority (CMA) and ICO, alongside sector-specific regulators including the FCA and Ofcom.
In addition, the Digital Regulation Cooperation Forum (DRCF) was established to facilitate coordination between these regulators on cross-sector digital risks and has launched an AI and Digital Hub to support businesses developing and deploying innovative technologies.
The ICO, CMA, FCA and Ofcom have all become more active in addressing AI-related risks. The ICO has moved into active enforcement, including investigations into the use of personal data in AI systems and enforcement action relating to children’s data, while the CMA has focused on the consumer law implications of agentic AI and emphasised business accountability for AI agents (particularly consumer protection around misleading outputs, unfair commercial practices and accountability for automated customer journeys). The FCA has highlighted the transformative impact of AI on financial services and the growing risks of AI-enabled fraud (and has mentioned it will rely on existing frameworks such as Consumer Duty and Senior Managers and Certification Regime (SM&CR)), and Ofcom has used its powers under the Online Safety Act 2023 to investigate AI-generated harms and age-assurance failures. Across regulators, common priorities include transparency, accountability and governance in AI systems, protection of children and vulnerable users, and increased cross-regulator coordination through the DRCF.
User transparency in the United Kingdom
The principle of appropriate transparency and explainability identified in the White Paper specifies that AI systems should be appropriately transparent and explainable, on the basis that transparency can increase public trust, which can be a significant driver of AI adoption. Separately, existing principles under e.g. the Data Protection Act 2018 and UK GDPR should be considered.
Fairness / unlawful bias in the United Kingdom
The principle of fairness identified in the White Paper specifies that AI systems should not undermine the legal rights of individuals or organisations, discriminate unfairly against individuals or create unfair market outcomes. Since AI can have a significant impact on people’s lives, the principle states that AI-enabled decisions with high impact outcomes should not be arbitrary and should be justifiable. Deployment of AI systems with specific biases could breach existing laws, including the Equality Act 2010, the Data Protection Act 2018 and/or various employment laws, depending on context.
Human oversight in the United Kingdom
Existing principles under e.g. the Equality Act 2010, Data Protection Act 2018, UK GDPR and, now, the Data (Use and Access) Act must be considered. As noted in the Law / Proposed Law section, DUAA has resulted in a more permissive approach to automated decision-making, allowing decisions to be made provided safeguards are in place relying on legitimate interests (unless special category data is involved). Please see our guide to Data Protection Laws of the World for a summary of the new Articles 22A-22D of the UK GDPR.
In July 2026, the Department for Business and Trade opened a consultation on the use of workplace monitoring technologies, seeking views to shape potential regulatory interventions and responsible adoption frameworks. The consultation covers AI-enabled surveillance, algorithmic management and automated decision-making affecting workers, addressing concerns that excessive or non-transparent monitoring may undermine employee trust and wellbeing.
Existing principles under e.g. the Equality Act 2010, Data Protection Act 2018, UK GDPR and, now, the Data (Use and Access) Act must be considered. As noted in the Law / Proposed Law section, DUAA has resulted in a more permissive approach to automated decision-making, allowing decisions to be made provided safeguards are in place relying on legitimate interests (unless special category data is involved). Please see our guide to Data Protection Laws of the World for a summary of the new Articles 22A-22D of the UK GDPR.
In July 2026, the Department for Business and Trade opened a consultation on the use of workplace monitoring technologies, seeking views to shape potential regulatory interventions and responsible adoption frameworks. The consultation covers AI-enabled surveillance, algorithmic management and automated decision-making affecting workers, addressing concerns that excessive or non-transparent monitoring may undermine employee trust and wellbeing.