British Business Review logo

Regulation

UK Government's AI Regulation Roadmap: What It Means for Business

The UK still has no AI Act. Here's what the sector-by-sector approach actually requires of businesses using AI in 2026.

By Laura Bennett · Economist & Contributing Author · Published

Last updated

Five years after the government first floated a "pro-innovation" approach to AI, Britain still hasn't passed an AI law. That's not an oversight — it's the policy. And it leaves business leaders in an odd position: told repeatedly that AI regulation is coming, while the actual legal obligations they face today sit scattered across half a dozen regulators' existing rulebooks rather than in one statute.

The framework dates to March 2023, when the Department for Science, Innovation and Technology published its white paper, A Pro-Innovation Approach to AI Regulation. It set out five principles — safety, transparency, fairness, accountability, and contestability — and asked existing regulators, rather than a new AI authority, to apply them within their own remits. The government's February 2024 response confirmed it: no cross-sector AI law in the near term. As of this year, that's still the position.

What changed, and what didn't

One thing that has shifted is the government's own AI safety body. The AI Safety Institute, set up in November 2023 with an initial £100 million commitment, was renamed the AI Security Institute in February 2025. The rebrand wasn't cosmetic. Technology Secretary Peter Kyle narrowed its mandate at the time to national-security-grade risks — cyberattacks, biological and chemical weapons uplift, large-scale fraud — and explicitly away from the bias and free-expression questions that had featured in its earlier remit. Businesses worried about discriminatory AI outputs in hiring or lending shouldn't expect help from this body; that's the Information Commissioner's Office's and the Financial Conduct Authority's territory instead.

The FCA is, by most accounts, the most active of the sector regulators on AI. Its existing Consumer Duty and Senior Managers regime already create binding obligations for firms deploying AI in anything client-facing — a credit-scoring model or a robo-adviser answers to those rules whether or not the word "AI" appears in them. The ICO, for its part, updated its AI and data protection guidance in 2024 and remains the most detailed public document on what "good" AI governance looks like under UK data law specifically.

The catch for anyone selling into the EU

None of this insulates a UK company from the EU AI Act if it has EU customers. Brussels' law is horizontal and risk-tiered; London's is sectoral and principle-based. A UK AI vendor with European clients typically ends up building to the stricter EU standard across the board, simply because maintaining two separate compliance programmes for one product is rarely worth the saving.

There is a live legislative question hanging over all of this: a statutory AI Bill targeting frontier models — the handful of firms building foundation models, not the much larger population of companies merely using AI tools built by others — remains under discussion but had not passed Parliament as of mid-2026. The January 2026 AI Opportunities Action Plan reaffirmed the sectoral approach rather than announcing a change of course, alongside newer initiatives like the AI Growth Lab and AI Growth Zones aimed at attracting investment rather than imposing new obligations.

Free newsletter

The British Business Brief

One email a week on UK business, regulation and capital: what moved, who paid for it, and what it means. No hype.

What this actually requires day to day

Because the principles aren't directly enforceable as standalone law — only the sector regulations they inform are — the practical test for most businesses isn't "are we AI-compliant" but "can we show our house is in order." Advisers working with FCA- and ICO-regulated firms tend to point to the same handful of things: a written account of how a given model reaches a decision and what data trained it; a defined point where a human can intervene before a high-impact AI decision takes effect; and documented bias testing for anything touching credit, employment, or insurance outcomes. None of it is exotic. What makes it a live compliance risk is that the obligations sit in guidance from several different regulators rather than one place, so it's easy for a mid-sized firm to be compliant with the letter of financial services rules while having no equivalent documentation for a hiring tool the ICO would expect to see.

Firms exporting into the EU should treat the AI Act's compliance calendar as the more binding deadline of the two. Everyone else should keep an eye on whether the frontier-model AI Bill actually reaches Parliament this year — and, in the meantime, treat the FCA's and ICO's existing guidance as the closest thing Britain currently has to AI law with teeth.

Related reading