The UK didn’t pass an AI Act. It didn’t need to.
Ask “is there a UK AI Act?” and the answer in 2026 is still no. Britain deliberately went the other way — a light-touch, regulator-led framework rather than a single statute. That doesn’t mean AI is unregulated in the UK; it means the rules live in data-protection law and sector regulators, and you have to know where to look.
The framework
The UK’s 2023 AI White Paper set out five cross-sectoral principles — safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress — to be applied by existing regulators (the ICO, FCA, CMA, and Ofcom) within their own remits. These are principles, not penalties — the enforcement teeth come from whatever statute the relevant regulator already administers.
What actually binds
For most companies, the binding layer is data-protection law. UK GDPR Article 22 gives individuals rights around decisions based solely on automated processing that have legal or similarly significant effects. The ICO’s guidance on AI and data protection sets out expectations for fairness, transparency, and lawful basis. And the Data (Use and Access) Act 2025 reformed the automated-decision rules — relaxing the Article 22 default for non-special-category data, provided appropriate safeguards are in place. If your AI processes UK personal data or makes automated decisions about UK people, the ICO is your regulator, and its fines reach £17.5M or 4% of global turnover.
What’s coming
A private-member AI (Regulation) Bill keeps reappearing, and the government has signaled targeted legislation for the most powerful frontier models “when parliamentary time allows.” But nothing comprehensive is enacted, and the near-term posture remains the principles-plus-existing-regulators model. Track the frontier-model bill; don’t hold your program waiting for it.
For a U.S. company
If you have UK users or a UK entity, treat this as a data-protection problem, not an “AI Act” problem. ICO-aligned governance and correct handling of Article 22 automated decisions covers the large majority of your exposure — and it maps cleanly onto the explainability duties you’ll meet in the EU and Quebec, so the work isn’t UK-specific overhead.
Do these three things now
1. Map AI that touches UK personal data or makes automated decisions about UK people. 2. Align to ICO AI guidance and UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025. 3. Watch for targeted frontier-model legislation — but build to the data-protection layer now.
The UK’s bet is that its existing regulators can handle AI without a new statute. For you, that means the compliance work is real but familiar — it lives in data protection, where you probably already have a program to build on.
This briefing is general information from Sentinel Assurance Group, not legal advice. Regulatory dates and requirements change — we maintain these briefings, but verify against primary sources and counsel before acting. Last reviewed July 22, 2026.
See how a Gap Assessment maps your exposure →Not sure which of these reach you?
Find out in 30 minutes.
The free AI Risk Exposure call maps your AI footprint to the obligations that actually apply — and the ones that don’t.
Book the call →