Ask most UK business leaders which law governs their use of AI and you'll get a pause. It's an understandable one — because there isn't a single answer. There is no one "AI Act" in the UK that you can read, comply with, and tick off.
What exists instead is more awkward: several established regimes that each touch what your AI does, from different angles, at the same time. None of them is "the AI law." Together they form what you might call your compliance surface area — and most organisations have more of it exposed than they realise.
The five regimes already touching your AI
For a typical UK business in 2026, AI use sits across roughly five overlapping frameworks:
- UK GDPR — wherever AI processes personal data, including how decisions are explained.
- FCA Consumer Duty and AI guidance — for financial services, existing rules increasingly apply to AI-enabled models and outcomes.
- The EU AI Act — which has extraterritorial scope, so UK firms serving EU customers can be caught regardless of where they sit.
- The UK's cross-sector AI principles — the government's context-based approach, applied through existing regulators rather than one central body.
- Sector-specific rules — from bodies such as the ICO, MHRA, SRA and others, depending on what you do.
The UK has deliberately chosen this route. Rather than one statute, it regulates AI mostly "at the point of use," through the regulators that already oversee each sector. Flexible in principle — but it means the responsibility for joining the dots falls on you.
The scrutiny is rising, quietly
Even without new legislation, expectations are climbing. Through 2025 and into 2026 the FCA and the Bank of England have run roundtables with banks and insurers and signalled that existing rules — Consumer Duty, the Senior Managers regime, model risk management — already apply to AI, including more autonomous "agentic" systems. The direction is consistent: the window for innovation is open, but so is the door to greater scrutiny.
The minimum that actually protects you
Good news: you don't need a sprawling governance programme to be defensible. Most organisations land on a lightweight setup that a board can understand and a small team can run. Six elements do most of the work:
- An AI register — a living list of every AI system in use, internal and third-party. You can't govern what you can't see.
- A named risk owner — one accountable person, not a committee that meets when it remembers to.
- A quarterly review forum — a standing slot to catch new tools, new risks, and shadow AI creeping in.
- Vendor due diligence — basic checks before anything third-party goes live, especially where it touches customer data.
- Staff training — so the people using AI day to day know the boundaries and use it well.
- Incident response — a known route for when something goes wrong, before it has to.
Where to start in 30 days
If none of this exists yet, don't try to build it all at once. Start with the register and the named owner — between them they give you visibility and accountability, which is most of the value. The rest can follow over a quarter. The goal isn't to slow AI down; it's to make sure it can stand up when your board, your regulator, or your biggest customer asks the obvious question: are you OK?
Want a governance setup that protects you without smothering the work?
We help businesses build AI that's defensible across the regimes that apply to them — pragmatic, proportionate, and built alongside your compliance team.
Book a call Start a conversationSources: Bird & Bird, UK AI regulation (2026); Covington / Inside Global Tech, UK financial services regulators' approach to AI (2026); Osborne Clarke Regulatory Outlook (2026); House of Commons Library, AI regulation in the UK (2026). This article is general information, not legal advice; for regulated activity, take qualified counsel.