This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If a UK business cannot find one definitive set of AI rules, that is not because it has missed a central regulator. The UK routes different AI questions through existing laws and authorities. This reference maps common questions to the relevant regulator and primary document, then identifies where the UK data protection position no longer matches the EU GDPR text.
In short: There is no single UK AI regulator and no generally applicable UK equivalent of the EU AI Act in force. The subject and context determine the route: personal data goes to the ICO, consumer and competition questions to the CMA, regulated finance to the FCA, advertising to the ASA, cyber security to the NCSC, equality to the EHRC, and qualifying online services to Ofcom.
Regulatory status and sources checked: 4 September 2026.
The regulator depends on what the AI system is doing
The quickest way to navigate UK AI governance is to start with the affected activity, not the technology label. The government's framework assigns AI-related questions to existing regulators within their established remits, supported by five cross-sector principles: safety, transparency, fairness, accountability and contestability. The government describes those principles as non-statutory and says their application is initially left to regulators within their own remits. Read the UK AI regulation white paper.
| Question raised by the AI use | Primary authority to read | Starting document | What the source covers |
|---|---|---|---|
| Is personal information used to train, operate or evaluate the system? | Information Commissioner's Office, ICO | ICO guidance on AI and data protection | Lawfulness, fairness, transparency, minimisation, accuracy, security, accountability and individual rights |
| Does an AI agent set prices, issue refunds, present reviews or interact with consumers? | Competition and Markets Authority, CMA | CMA guidance on using AI agents | Consumer protection, business responsibility for agent behaviour and competition concerns |
| Is the use inside an FCA-regulated financial service? | Financial Conduct Authority, FCA | The FCA's approach to AI | How the FCA applies existing principles, the Consumer Duty and accountability frameworks |
| Is the output an advertisement or marketing claim? | Advertising Standards Authority and Committee of Advertising Practice, ASA and CAP | ASA and CAP guidance on generative AI advertising | Application of the advertising codes regardless of how an advertisement was created |
| Is the question about securing an AI system or agent? | National Cyber Security Centre, NCSC, with DSIT | NCSC secure AI system development guidance | Secure design, development, deployment, operation, access control and incident planning |
| Could a hiring, workforce or service outcome discriminate? | Equality and Human Rights Commission, EHRC | Equality Act 2010 and EHRC AI objective | Equality law and the EHRC's stated interest in biased AI employment decisions |
| Does a chatbot or AI service provide search or user-to-user functionality? | Ofcom | Ofcom guidance on AI chatbots | When a chatbot can fall within the Online Safety Act framework |
| Does the question concern training data and copyright? | UK government and Intellectual Property Office policy sources | Government report on copyright and AI | Current policy status, evidence gaps and options under consideration |
Several rows can apply to one system. An AI recruitment service, for example, can raise ICO questions about candidate information, EHRC questions about discrimination and NCSC questions about system security. The UK framework does not appoint one of those regulators as the universal lead for every overlapping issue.
The ICO covers personal data, automated decisions and biometrics
The ICO is the main source when an AI system processes information about identifiable people. Its AI guidance organises the issue around the UK GDPR principles, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability. The ICO also says this guidance is being reviewed following the Data (Use and Access) Act 2025, so older Article 22 explanations require particular care. See the ICO AI guidance structure and status notice.
For governance, the ICO identifies responsibility for data protection compliance, controller and processor roles, risk appetite and data protection impact assessments as central issues. Its guidance describes a data protection impact assessment as a way to document risks and safeguards where an AI system uses personal information. Read the ICO's accountability and governance guidance.
For recruitment, the ICO's audit work found concerns involving excessive collection, indefinite retention, unclear privacy information and tools that inferred characteristics such as gender or ethnicity from names. The regulator's published outcomes direct developers and recruiters to questions about purpose, lawful basis, minimisation, transparency, accuracy, bias testing and controller-processor instructions. Read the ICO recruitment audit outcomes.
For biometric recognition, the ICO says systems used to identify or verify a person process personal information and biometric data. Where biometric data is processed to uniquely identify someone, the ICO classifies it as special category biometric data. Its guidance then points to Article 9 of the UK GDPR and, where relevant, section 10 and Schedule 1 of the Data Protection Act 2018. Read the ICO biometric recognition guidance and the Data Protection Act 2018.
For automated decisions, the current statutory starting point is no longer the retained version of Article 22 that closely tracked the EU text. Section 80 of the Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A to 22D. The explanatory notes say the amended framework removes the former conditions for significant solely automated decisions involving non-special-category data, retains restrictions for special category data and requires safeguards for significant decisions. Read the section 80 explanatory notes.
Those main data protection changes came into force on 5 February 2026. The ICO's updated automated decision-making guidance was still in development when this page was checked, and its guidance pipeline listed a final version for winter 2026. See the government's commencement record and the ICO guidance pipeline.
The ICO's statutory AI and automated decision-making code is also not a finished code that can presently be treated as operative guidance. Regulations effective from 12 May 2026 require the Information Commissioner to prepare the code, while the ICO stated in June 2026 that it was starting that work. Read the 2026 regulations and the ICO's June 2026 status update.
The CMA covers AI conduct affecting consumers and competition
The CMA's material is the primary route when an AI system presents prices, reviews, sales information, refunds or other consumer-facing choices. Its March 2026 guidance states that a business remains responsible if an AI agent it uses acts illegally. The same guidance covers agents that communicate with customers or process refunds, rather than creating a separate liability category for the software itself. Read the CMA AI agent guidance.
Pricing agents can also create competition questions. The CMA's research says algorithmic pricing can increase the risk of coordinated market outcomes and that autonomous agents may intensify this concern when systems react to one another. This is a statement of the risk the CMA is monitoring, not a finding that automated pricing is inherently unlawful. Read the CMA's agentic AI analysis.
The position on fake reviews is now more specific than the retired page this reference replaces. The CMA says the unfair commercial practices provisions apply from 6 April 2025 and identify fake reviews, concealed incentivised reviews and misleading presentation of review information as banned practices. On penalties, the CMA says the amount “can be up to 10% of your business' global turnover or £300,000 (whichever is greater)”, and directs readers to chapters 6 and 7 of its direct consumer enforcement guidance (CMA200) for how it is set. That is a statutory maximum, not an automatic penalty for every breach. Read the CMA unfair commercial practices guidance, the CMA fake reviews guidance and the CMA's own statement of its direct consumer enforcement powers.
The ASA applies advertising rules regardless of how the content was made
The ASA and CAP say the advertising codes are media-neutral. If an advertisement falls within their remit, the applicable rules do not disappear because an AI system generated the text, image or distribution decision. Their guidance identifies misleading efficacy claims, endorsements, harmful stereotypes and socially irresponsible imagery as examples of issues that can arise in AI-generated advertising. Read the ASA and CAP guidance.
This remit concerns the advertisement, not every feature or output of the advertised AI product. ASA material is therefore the relevant source for a marketing claim, while an underlying personal-data issue still routes to the ICO and a consumer sales practice may also route to the CMA.
The FCA, NCSC and Ofcom answer sector and system questions
The FCA says it does not plan additional AI-specific regulation for financial services and instead relies on existing frameworks. Its published examples include the Consumer Duty, senior-management accountability and governance controls. This makes the FCA source relevant to regulated financial firms, but it does not turn FCA material into a general rulebook for businesses outside its remit. Read the FCA's current AI approach.
The NCSC addresses cyber security rather than privacy, consumer law or equality. Its secure AI development guidance covers secure design, development, deployment, operation, access controls, model and data protection, incident management and responsible release. For agentic AI, the NCSC has also published interim advice while stating that formal guidance is still being developed. Read the NCSC secure deployment guidance and its agentic AI status statement.
DSIT's separate AI Cyber Security Code of Practice is voluntary. It applies baseline principles to developers, system operators and other participants in the AI supply chain, and the government says it is intended to inform an ETSI standard. It is not an AI Act or a general statutory code governing every use of AI. Read the code and its legal status.
Ofcom is the route for Online Safety Act questions only when the service falls within the Act's definitions. Ofcom says a chatbot can be covered where it is, or forms part of, a qualifying search service or user-to-user service. A chatbot that only generates answers from its underlying model and lacks live search or content-sharing functionality was not automatically within those existing categories, although the Crime and Policing Act 2026 created a power for regulations to extend coverage to additional generative AI services. Read Ofcom's chatbot guidance and the 2026 Act explanatory notes.
Ofcom's illegal-content guidance was published on 18 February 2026, but that date did not place every chatbot under the Act. The source says the duties concern services that are in scope, and Ofcom provides a regulation checker for that threshold question. Read Ofcom's illegal-content duties page.
Equality and copyright do not fit neatly under the seven-regulator map
The EHRC and the Equality Act become relevant where an AI-supported decision may discriminate in employment or services. The Equality Act covers direct and indirect discrimination, so an equality question can arise from a criterion or outcome even when a system does not explicitly take a protected characteristic as an input. That is an inference from the structure of the Act, not a conclusion that a particular model or decision is discriminatory. Read the Equality Act 2010.
The EHRC has identified AI bias in recruitment and employment practices as an enforcement concern, but its site does not currently provide one consolidated AI governance manual for small businesses. The ICO itself directs readers towards EHRC material when a question moves from data-protection fairness into equality law. See the EHRC business-plan objective and the ICO fairness guidance.
Copyright policy is another boundary case. The government's 2026 report says its previously preferred broad text-and-data-mining exception with an opt-out is no longer its preferred way forward. The report also says there is no consensus, evidence remains limited and reforms will not be introduced until the government is confident they meet its objectives. The source therefore supports describing the proposal as abandoned as the preferred option, but not describing a replacement policy as settled. Read the government report on copyright and AI.
The allied-health use case from the retired set does not belong in this jurisdiction reference. Questions about using a named chatbot in a clinical or administrative workflow require separate implementation guidance and may also engage professional, health-sector and medical-device rules beyond the seven-authority map.
UK GDPR now differs from EU GDPR in decisions and transfer paperwork
The phrase “UK GDPR” should not be treated as interchangeable with the EU GDPR. The two regimes retain common concepts, but UK legislation has changed the domestic text and the applicable regulator, supporting legislation and transfer instruments are different.
| Issue | UK position | EU comparison | Why the distinction changes the source to read |
|---|---|---|---|
| Significant solely automated decisions using non-special-category data | Section 80 of the Data (Use and Access) Act replaced Article 22 with Articles 22A to 22D and removed the former limited conditions, while retaining safeguards. | EU GDPR Article 22 retains a general right not to be subject to such a decision, subject to contract, law and explicit-consent exceptions. | A UK assessment based only on the unchanged EU Article 22 text can state the wrong threshold. Read section 80 and EU GDPR Article 22. |
| Special-category information in automated decisions | The amended UK framework retains restrictions for significant solely automated decisions using special-category data. Section 10 and Schedule 1 of the DPA 2018 also supply UK conditions for certain special-category processing. | EU GDPR Article 22(4) and Article 9 provide the EU-level starting point, supplemented by applicable member-state law. | Recruitment, health inference and biometric identification cannot be assessed from the relaxed UK rule for ordinary personal data alone. Read the DPA 2018 Schedule 1 text. |
| Transfers to providers outside the UK | The ICO provides the UK International Data Transfer Agreement and a UK Addendum to the EU clauses. | The European Commission's standard contractual clauses operate under the EU GDPR. | The ICO says EU clauses are not valid on their own for a restricted transfer under UK GDPR. Read the ICO transfer-clause guidance. |
| A UK organisation also targets people in the EEA | The UK GDPR may govern UK processing while EU GDPR can separately apply to EEA-facing activity. | EU supervisory authorities and the EDPB, rather than the ICO, govern the EU side. | A single privacy analysis may need to distinguish data, people and transfers by regime. Read the ICO guidance on UK and EEA processing. |
Published principles do not settle every AI governance question
The UK regulator-led model contains deliberate boundaries. Government AI principles do not by themselves create one enforceable rulebook, voluntary cyber codes are not statutes, and regulator guidance cannot decide how a law applies to every set of facts.
Several sources are also moving. The ICO has marked parts of its AI, biometric and explanation guidance as under review after the Data (Use and Access) Act. Its statutory AI code is being prepared, while the NCSC describes its agentic AI advice as interim and copyright policy remains unsettled.
Regulatory overlap is another limit. The ICO can explain personal-data fairness, but says equality-law questions belong with the EHRC. Ofcom can explain the Online Safety Act's service categories, but a particular product's functionality and UK links determine whether those categories are engaged. A regulator, court or qualified adviser may therefore be needed where classification or application remains disputed.
Questions that identify the right authority
A business, vendor or adviser can use the following questions to locate the relevant primary material without treating them as a compliance checklist:
- Does the system receive, infer, retain or disclose information about identifiable people?
- Does it make or materially support a decision with a legal or similarly significant effect?
- Does it identify a person using facial, voice, fingerprint or behavioural characteristics?
- Does it present prices, reviews, endorsements, refunds or sales information to consumers?
- Is the organisation or activity regulated by the FCA or another sector regulator?
- Is an AI-generated output being used as an advertisement or substantiated product claim?
- Can users share content through the service, or does the service search across live websites or databases?
- Could a hiring, employment or service criterion disadvantage a protected group?
- Which entity controls the model, data, prompts, access permissions and incident response?
- Does personal information leave the UK, and which contractual transfer instrument is being relied upon?
These questions route an issue. They do not determine whether a particular use is lawful, fair, secure or compliant.
How this was researched
This guide is researched against primary regulatory sources and official regulator guidance, checked against those documents as of the date shown, and written for a business with no dedicated compliance function. We report what a named authority has published and link the document so you can read it yourself. We do not tell you what your legal obligations are.
Read our full methodology and independence and disclosure policy.
Related reading: our AI governance by region.
Related reading: Claude AI Review: Pricing, Features, and Business Verdict and Is Claude Pro Worth It? An Honest Assessment for Business Users.
Free tools: AI Privacy Risk Scorer to score your current AI tool setup against data-privacy best practice | AI Policy Generator to generate a customised AI policy for your business.
Does the United Kingdom have an AI Act?
No generally applicable UK equivalent of the EU AI Act was in force when this page was checked. The government's pro-innovation approach white paper continues to place most AI oversight within existing laws and regulators, although sector legislation and AI-related statutory changes can still apply.
Is the ICO the UK's AI regulator?
No. The ICO regulates data protection and information-rights issues involving AI. Consumer, advertising, financial-services, equality, cyber-security and online-safety questions fall within other authorities' remits.
Does every AI-assisted decision create a right to human review?
No. The statutory safeguards concern significant decisions based solely on automated processing, and the precise UK framework changed in February 2026. Human involvement can also be relevant to transparency, fairness or sector guidance even where the statutory automated-decision threshold is not met.
Are all AI chatbots regulated by Ofcom?
No. Ofcom's guidance on AI chatbots and online regulation says a chatbot is covered under the existing Online Safety Act categories when it meets the relevant definition, such as a qualifying search or user-to-user service. The 2026 legislation also created a power to extend the framework through regulations, so current scope requires checking.
Can a business use the EU standard contractual clauses for UK data?
Not on their own for a restricted transfer governed by UK GDPR. The ICO's guidance on standard data protection clauses, the UK IDTA and the Addendum says the UK IDTA or the UK Addendum to the EU clauses can provide the relevant UK contractual safeguard, subject to the rest of the transfer framework.
Has the UK settled whether copyrighted works can be used to train AI?
No new comprehensive settlement was identified. The government's 2026 report withdrew its earlier preferred opt-out exception as the preferred way forward and proposed further evidence gathering and consideration of alternatives.
Methodology and source boundary
This reference was checked on 4 September 2026 against legislation.gov.uk, GOV.UK and material published by the ICO, CMA, FCA, ASA, NCSC, EHRC and Ofcom. Consequential statements are linked to those primary sources. No product testing was undertaken, and the page does not assess how any rule applies to an individual organisation.
Next step
For operational guidance, use the related Need to Know AI implementation resources on AI registers, vendor due diligence, staff policy and automated-decision review. Those resources turn regulator questions into records and workflows without claiming to determine a business's legal position.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Use the free AI register template to record the AI systems each UK regulator's published questions would reach.
Use the free AI register template