Skip to content
Back to blog
AI Governance19 min read

AI Regulation for UK Companies: A Practical Compliance Guide

A practical guide for UK business leaders, legal teams, privacy professionals, product owners, and operations managers building responsible AI governance.

Artificial intelligence is moving quickly from a pilot project into ordinary UK business operations. A sales team uses a copilot to draft outreach, a service desk summarises calls, a manufacturer predicts maintenance, a bank screens applications, a retailer personalises offers, and an HR team ranks candidates. The important question is no longer whether your company uses AI. It is whether you know where it is used, what information it touches, who may be affected, which decisions it influences, and what evidence you can produce when a customer, employee, regulator, board member, or supplier asks.

This guide is for UK company directors, general counsel, privacy and security teams, product owners, procurement leaders, and operations managers. It describes the legal and policy position as of September 2026 and is practical operating guidance, not legal advice. The exact answer depends on your sector, business model, role in the AI supply chain, data, location, contract, and the effect of a system on people. Confirm significant uses with appropriately qualified UK counsel and the relevant regulator.

The UK approach in plain English

The UK has not adopted one comprehensive AI Act that classifies every model and gives every company the same checklist. Its stated approach is pro-innovation, context specific, and based mainly on existing regulators applying cross-sector principles within their existing remits. The government's response to the AI regulation white paper explains the policy direction. The five principles are safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress.

These principles are not, by themselves, a new private sector offence or a universal certification scheme. They are a way to coordinate the work of regulators such as the Information Commissioner's Office, Competition and Markets Authority, Financial Conduct Authority, Medicines and Healthcare products Regulatory Agency, Equality and Human Rights Commission, Health and Safety Executive, and Office for Product Safety and Standards. The government's initial guidance for regulators makes clear that regulators interpret and apply the principles within their own remits.

Keep your legal register precise. Label an Act, regulation, binding regulatory rule, enforcement order, contract, official guidance, voluntary standard, consultation, and policy announcement separately. A regulator's guidance can explain how to comply with an existing duty without creating a new duty. A proposed bill is not current law. A voluntary framework can be a sensible internal baseline, but it should not be marketed as proof that a system is legally compliant. This distinction is particularly important when leadership asks whether the UK has a single AI approval or whether a vendor's AI badge settles the issue. It does not.

The regulators that may matter

Start with the activity and the affected person, not the model name. The ICO is central where personal data is processed. The CMA may consider competition, consumer protection, unfair commercial practices, and the market power of digital services. The FCA and Prudential Regulation Authority matter to regulated financial firms and can expect sound governance, controlled outsourcing, suitable customer outcomes, and reliable models. The MHRA matters to medical devices and software with a medical purpose. The HSE and sector safety authorities matter when an AI system can affect workers, machinery, transport, or physical safety.

The Equality and Human Rights Commission is relevant to discrimination and equality duties. The Employment Agency Standards Inspectorate, ACAS guidance, employment tribunals, and ordinary employment law matter to hiring and workforce decisions. Ofcom matters to online safety and certain communications or media services. The Advertising Standards Authority can challenge misleading advertising claims even though it is not a statutory regulator. The Financial Ombudsman Service, Legal Ombudsman, and sector complaints routes can expose weak explanations and ineffective human escalation before a formal enforcement action.

UK GDPR and the Data Protection Act 2018

If an AI system processes personal data, the UK GDPR and Data Protection Act 2018 remain foundational. The core principles require lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Identify the controller, processors, joint controllers, purposes, lawful bases, special category conditions where relevant, retention, international transfers, security measures, and rights process before production. An AI label does not change the identity of the organisation responsible for the processing.

The ICO's guidance on AI and data protection is a practical source for design and review. It covers accountability, fairness, lawfulness, security, accuracy, individual rights, data minimisation, and governance. Treat it as regulator guidance that should be read alongside the statute, the UK GDPR, your facts, and any later ICO updates. Document why the processing is necessary and proportionate, what alternatives were considered, and how risks will be reduced.

A Data Protection Impact Assessment is expected where processing is likely to result in a high risk to people's rights and freedoms. Large scale profiling, systematic monitoring, special category data, biometric identification, and significant automated decisions can trigger this analysis. A useful AI DPIA maps the data flow, model, prompts, retrieval context, outputs, downstream action, affected groups, human involvement, vendor, hosting, retention, security, accuracy, fairness, explainability, and remedy. Revisit it when the model, data, user group, geography, purpose, or connected action changes.

Do not confuse anonymisation with removing a name. Free text can identify a person through a distinctive event, job title, date, location, account detail, or combination of facts. Review prompts, uploads, outputs, embeddings, evaluation data, logs, telemetry, and incident tickets. Use field filtering, redaction, tokenisation, pseudonymisation, access controls, environment separation, and short retention where they preserve the business purpose. Test deletion and correction processes against indexes and derived records as well as the original database.

Automated decisions after the Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. It did not replace the UK GDPR or the Data Protection Act 2018. Section 80 and Schedule 6 changed the automated decision framework, with the relevant provisions brought into force on 5 February 2026 under the 2026 commencement regulations. This status matters: the amended framework is current law as of September 2026, while future guidance or further amendments must be checked separately.

The amended framework is more permissive for significant decisions based solely on automated processing, but it is not permission to automate without safeguards. The Act replaces the former Article 22 structure with provisions concerning automated processing and significant decisions. Where the rules apply, organisations must provide information about the decision, enable the person to make representations, enable them to challenge the decision, and enable human intervention. Additional restrictions and safeguards apply where special category data is involved.

Read the ICO's rights guidance on automated decision making and profiling with the current legislation. The practical test is effect, not marketing language. A system that ranks, flags, recommends, or prioritises may still influence a significant decision. A human who merely clicks approve is not meaningful oversight. The reviewer needs relevant context, time, training, authority to change the result, and a route to record and correct errors.

Provide meaningful information about the logic involved without pretending that a technical explanation is automatically useful. Tell people what kind of information was considered, the purpose of the process, the likely significance, how to raise an issue, and how a human can reconsider the result. Define service levels for challenges. Preserve the input or relevant record, model and rules version, output, reviewer, decision, reason for override, and correction. A decision that cannot be reconstructed cannot be defended or improved.

Equality Act 2010 and discrimination risk

The Equality Act 2010 applies to the underlying treatment, not just to a human's intentions. AI can create direct discrimination, indirect discrimination, discrimination arising from disability, harassment, victimisation, or a failure to make reasonable adjustments. A model does not need to receive a protected characteristic to produce unequal outcomes. Names, postcode, school, language, employment gaps, working pattern, device type, health descriptions, and other variables can act as proxies.

High exposure uses include recruitment, candidate screening, promotion, scheduling, performance management, discipline, redundancy selection, pay decisions, customer eligibility, insurance, credit, housing, and access to essential services. Define the legitimate purpose and job or service relevance. Test selection rates, false positives, false negatives, quality, accessibility, and error patterns across relevant groups where lawful and statistically meaningful. Do not rely on a vendor's statement that the model is unbiased. Fairness depends on data, context, threshold, workflow, and the human decision that follows.

Reasonable adjustments need an owner and a practical route. Candidates and employees may need an alternative assessment, additional time, assistive technology, a human route, or the ability to correct an inaccurate record. Tell people what the tool does and how to request help. Train reviewers not to treat a model score as a fact. Record adjustments, challenges, decisions, and outcomes in a way that supports employment records and equality investigations while limiting unnecessary sensitive data.

Employment and workplace automation

Employment decisions deserve a dedicated review even where a particular AI law does not apply. Hiring and promotion tools can screen out qualified people. Productivity analytics can turn a proxy into a disciplinary record. Scheduling systems can penalise carers or disabled workers. Generative summaries can create an inaccurate impression of an employee. Automated monitoring can undermine trust and create data protection, consultation, contractual, and health and safety concerns.

Before deployment, document the business purpose, alternatives, data sources, validation, bias testing, notice, consultation, accommodation path, reviewer training, retention, vendor terms, and appeal process. Explain to workers what is being monitored or assessed, why, who sees the output, and how to challenge it. Restrict access to sensitive personnel data. Never let an unverified score be the sole reason for dismissal, discipline, refusal of an opportunity, or a material change to working conditions. A human decision maker must exercise independent judgment and be accountable for the final outcome.

Consumer protection, marketing, and competition

Consumer protection law applies to AI-enabled conduct even when the system is described as experimental. The Consumer Protection from Unfair Trading Regulations 2008, the Consumer Rights Act 2015, sector rules, and the general prohibition on misleading commercial practices can all matter. A chatbot can invent a warranty term, hide a cancellation route, give unsafe financial or health information, or make it difficult to reach a person. A pricing or recommendation system can use sensitive proxies, discriminate, or create a misleading impression of scarcity or personalisation.

The CMA's AI strategic update and its wider digital markets work are useful context for companies with powerful platforms, foundation model dependencies, or data access concerns. Consider competition risks in exclusive supply, tying, self-preferencing, access to data, interoperability, and switching. A smaller B2B company may not be a frontier model developer, but its distribution, procurement, or platform terms can still affect customers and competitors.

Make customer disclosures timely and specific. Say when a person is interacting with automation where that fact affects the interaction. Offer a visible human escalation route for complaints, account access, money, safety, eligibility, and contractual commitments. Review every claim such as accurate, autonomous, unbiased, secure, compliant, or guaranteed against evidence from the actual configuration and customer population. Keep test methods, limitations, dates, exclusions, and approval records. A benchmark is not proof of performance in every language, sector, or edge case.

Product safety and physical systems

If AI is part of a physical product, software, machine, vehicle, medical device, or safety-related system, product and workplace safety obligations may apply regardless of whether the model is sold separately. The Product Regulation and Metrology Act 2025 created powers relevant to modern products and emerging technology. The government's 2026 consultation on a new product safety framework is a consultation, not a complete new framework in force. Label proposals as proposals and verify future regulations before relying on them.

For an AI-enabled product, identify reasonably foreseeable misuse, adaptive behaviour, failure modes, safe states, update controls, cybersecurity, human instructions, and post-market monitoring. Allocate responsibilities across manufacturer, importer, distributor, software supplier, integrator, and operator. Preserve risk assessments, test results, technical files, version history, incident reports, corrective actions, and customer notices. An update that changes a model's behaviour can be a safety-relevant change and should pass change control before release.

Copyright and confidential information

UK copyright questions affect both inputs and outputs. Do not assume that a public webpage, customer document, image, code sample, or training corpus is free to copy into a model or retrieval system. Check licences, database rights, confidentiality, trade secrets, contractual restrictions, and the supplier's terms. Keep a record of data sources and permissions for internal datasets, fine tuning, evaluation, marketing assets, and generated deliverables.

The government published its Report and Impact Assessment on Copyright and Artificial Intelligence on 18 March 2026 under sections 135 and 136 of the Data (Use and Access) Act 2025. This report is an important current policy and evidence document, not a blanket new exception that permits every commercial use of copyrighted works. The government's assessment considered licensing, transparency, enforcement, and data mining options. Continue to check official legislation and IPO guidance because the policy debate remains active.

For generated work, human review should cover accuracy, originality, confidential material, third-party rights, attribution, and the terms of any downstream licence. Do not promise that an AI output is free of infringement. Prevent users from uploading privileged or restricted documents to consumer tools. Configure vendor training and retention settings, and negotiate ownership, licence, deletion, and indemnity terms where the use justifies them. A procurement approval should identify who bears the risk when the provider changes its model or terms.

Bills, enacted laws, and what to monitor

As of September 2026, the UK's central AI framework remains a regulator-led, pro-innovation approach rather than a single comprehensive AI Act. The Data (Use and Access) Act 2025 is enacted and its automated decision provisions are in force. The Product Regulation and Metrology Act 2025 is enacted, while the 2026 product safety consultation contains proposals that should not be treated as current law. The copyright report required by the Data (Use and Access) Act is published evidence and policy work, not a general copyright licence.

The Regulation for Growth Bill and related proposals should be tracked with its parliamentary status and final text. A proposal for statutory sandboxing or a strengthened growth duty is not an operative duty until enacted and commenced. The AI Growth Lab for legal services, published in 2026, is an advisory sandbox supported by the Legal Services Board, Solicitors Regulation Authority, Council for Licensed Conveyancers, and ICO. Participation is not regulatory approval or endorsement, and the ordinary legal requirements remain.

Create a horizon-scanning owner who checks legislation.gov.uk, GOV.UK, regulator updates, consultations, enforcement notices, and sector bodies on a defined cadence. For each item record status, scope, covered actor, geography, effective date, transitional rules, enforcement body, affected use cases, and the internal action. This prevents a policy announcement from becoming an accidental prohibition or a future obligation from being discovered after a product launch.

Procurement and vendor controls

Buying an AI feature does not transfer all responsibility to the supplier. The vendor controls parts of the model and infrastructure. Your company controls the purpose, users, prompts, connected data, configuration, business process, and downstream decision. Classify the service before accepting standard terms. A low-risk drafting assistant and an automated credit, recruitment, safety, or claims workflow should not receive the same approval.

  • Identify the supplier's role, model family, material versions, hosting locations, subprocessors, support access, training use, and change process.
  • Specify how inputs, outputs, feedback, telemetry, uploaded files, prompts, and logs are retained, accessed, deleted, and used for training or service improvement.
  • Require privacy, security, confidentiality, breach notification, international transfer, audit evidence, regulatory cooperation, and data subject assistance appropriate to the use.
  • Require advance notice and a review right for material model, data use, hosting, functionality, subprocessor, or policy changes.
  • Define service limits, human escalation, safety controls, rollback, export, continuity, incident response, and termination assistance.
  • Prohibit unapproved high-impact decisions, require disclosure of limitations and evaluation results, and allocate responsibility for customer communications and corrections.

Ask for evidence rather than a badge. Review the contract, data processing terms, technical documentation, security assurance, model card or equivalent, evaluation results, incident history, support process, and configuration. Confirm whether the supplier can isolate your data, honour deletion, identify a model version, export relevant records, and notify you before a material change. For critical use cases, test the exit plan and vendor outage procedure before you depend on the service.

Build an AI inventory

Start with discovery, not a policy. Ask every function to list purchased software, embedded features, APIs, experiments, browser tools, open source models, spreadsheet add-ons, agents, and uses created without procurement approval. Reconcile responses against software asset records, cloud bills, identity groups, expenses, product roadmaps, data registers, vendor questionnaires, and security logs. Shadow AI is a governance finding. Hiding it makes the risk harder to control.

  • System and feature, model or provider, version, owner, users, business purpose, lifecycle stage, and connected actions.
  • Input data, output recipients, personal or special category data, confidential information, copyright material, and retention.
  • Affected people, geography, sector, decision impact, autonomy, human review, override authority, and ability to stop.
  • Vendor, contract, hosting, subprocessors, training settings, security controls, incident contact, and exit plan.
  • Known limitations, evaluation results, fairness and accessibility concerns, legal classification, open questions, and next review date.

Risk classification that helps people decide

Use internal tiers while making clear that they are not a claim that UK law has created one universal classification. A low tier can cover drafting or summarisation with no sensitive input, no external action, and no decision effect. A medium tier can cover customer interaction, internal retrieval, coding, or workflow recommendations that require verification. A high tier can cover employment, credit, insurance, health, eligibility, safety, legal rights, special category data, biometric processing, essential services, or autonomous action. A prohibited tier should stop uses that violate law, create unacceptable harm, or cannot be governed with available evidence.

Define minimum controls and approval authority for every tier. Reclassify after a new model, data source, user group, geography, connected action, or change in purpose. A drafting assistant becomes a high-risk workflow when it receives personnel files or sends final notices. A customer chatbot becomes more consequential when it can change an account or make a contractual promise. Record the rationale, residual risk owner, approval conditions, and reassessment trigger.

Governance and human oversight

Assign accountability at the use case level. An executive sponsor owns risk appetite and funding. Privacy owns data protection interpretation and rights processes. Security owns threat modelling, access, monitoring, and response coordination. Product and engineering own design, testing, release, and change control. Operations owns the process and human review. Procurement owns supplier evidence and terms. Legal, HR, finance, quality, safety, and sector specialists join where the use requires them.

Avoid a committee that approves everything but owns nothing. Use a short decision record with purpose, tier, applicable law, owner, data flow, controls, open risks, approval conditions, human route, and review date. Give reviewers authority to pause launch. Meaningful human oversight means the reviewer understands the output, considers context, can obtain more information, can disagree, can change the result, and is not measured in a way that rewards automatic acceptance. Measure overrides and outcomes, not just attendance at a review step.

Testing, monitoring, and incident response

Test what can go wrong in the real workflow. Depending on the use, evaluate accuracy, calibration, robustness, security, privacy leakage, prompt injection, harmful content, accessibility, language, fairness, drift, latency, cost, and recovery. Include edge cases, vulnerable people, noisy data, missing fields, adversarial inputs, and cases where the correct answer is to escalate. Set thresholds that trigger a pause or rollback before production.

An AI incident can be a privacy breach, discriminatory outcome, fabricated advice, unsafe recommendation, prompt injection, poisoned data, unauthorised tool action, misleading synthetic content, outage, missing log, or failed human review. Connect AI response to the existing cyber, privacy, safety, and complaints programmes, but capture model version, input or retrieval reference, output, action, reviewer, affected people, reproducibility, vendor contact, containment, and correction. Preserve evidence carefully and avoid copying sensitive prompts into broad tickets.

The playbook should cover access suspension, affected-case review, evidence preservation, vendor escalation, legal and privacy assessment, regulator or customer communication where required, correction of records and decisions, root cause, remediation, and controlled restart. Test a support bot revealing another customer's information, a recruitment system with unequal outcomes, a model producing unsafe instructions, and an agent attempting an unauthorised payment or record change.

A practical 30, 60, and 90-day plan

In days 1 to 30, establish visibility and stop avoidable exposure. Appoint an executive sponsor, privacy lead, security contact, and use case owners. Issue an interim rule for special category data, confidential information, unapproved tools, and high-impact decisions. Inventory uses across business, IT, HR, product, security, procurement, and suppliers. Screen each use for data protection, equality, employment, consumer, product safety, sector, contractual, and autonomous-action risk. Give every unknown an owner and due date.

In days 31 to 60, convert findings into controls. Approve risk tiers and decision records. Publish an employee acceptable-use standard and role-based training. Create an approved tool catalogue. Update procurement questionnaires and priority vendor contracts. Complete DPIAs and AI impact reviews for the highest exposure uses. Configure access, redaction, retention, logging, notices, human escalation, testing, and incident intake. Build a legal register that distinguishes enacted law, commenced provisions, guidance, voluntary standards, consultations, bills, and future dates.

In days 61 to 90, test the operating model. Run performance, fairness, privacy, security, accessibility, and language tests appropriate to each use. Sample logs and human overrides. Run an incident tabletop. Test rollback, correction, rights requests, vendor outage, and exit procedures. Add a change gate for new models, prompts, data sources, integrations, and user groups. Report open high risks, overdue evidence, training coverage, material incidents, correction time, and upcoming legal reviews to leadership. Set a quarterly review and an annual framework review.

Evidence that stands up to scrutiny

  • AI inventory with owner, purpose, provider, version, data, users, affected people, geography, tier, and review date.
  • Legal register labelling each item as enacted law, commenced provision, regulation, guidance, contract, voluntary framework, consultation, bill, or policy.
  • DPIA and AI impact review with alternatives, affected groups, residual risk, approval conditions, human oversight, notices, and reassessment triggers.
  • Data flow, lawful basis, special category analysis, retention schedule, access review, international transfer assessment, and rights process.
  • Model and dataset documentation, evaluation methods, limitations, fairness checks, accessibility and language tests, and change history.
  • Vendor diligence, contract clauses, subprocessors, security evidence, data use settings, incident commitments, service limits, and exit plan.
  • Human review instructions, escalation routes, override samples, reviewer training, and evidence that review changed outcomes when appropriate.
  • Incident register, preserved evidence, impact assessment, communications, corrections, corrective actions, and restart approval.
  • Executive decisions, risk acceptances, exceptions, KPIs, audit samples, training records, and scheduled governance reviews.

KPIs that show control

Measure coverage and effectiveness together. Coverage measures include the percentage of known uses inventoried, the percentage with an owner and tier, completed high-risk DPIAs, approved-tool adoption, staff training by role, vendor evidence coverage, and material changes reviewed before release. Outcome measures include human review completion, override rate by use and group, error rate by relevant language or group, privacy and safety incidents, time to contain, time to correct an affected record, challenge resolution time, rollback success, and unresolved high risks by age.

Failure modes to avoid

  • Waiting for a single UK AI Act before controlling personal data, discrimination, safety, misleading claims, and significant decisions.
  • Calling the pro-innovation principles a universal certification or saying that voluntary guidance is binding law.
  • Treating the Data (Use and Access) Act 2025 as a general permission to automate without the safeguards for significant decisions.
  • Assuming a vendor's compliant or responsible AI statement is a DPIA, equality assessment, security review, or deployment approval.
  • Using consent or a disclaimer as a cure for an incompatible purpose, excessive data, weak security, unfair treatment, or inaccurate advice.
  • Calling a person human in the loop when they cannot understand, challenge, override, or stop the result.
  • Testing only average cases or English performance while ignoring disability, accessibility, language, edge cases, and affected groups.
  • Keeping unlimited prompts and outputs, copying sensitive data into tickets, or forgetting indexes, embeddings, telemetry, and backups.
  • Launching an AI-enabled physical product without testing updates, adaptive behaviour, foreseeable misuse, safe states, and post-market incidents.
  • Creating a policy and inventory that do not connect to identity, procurement, product release, security response, complaints, and operational ownership.

Build versus buy

Buy mature commodity capabilities such as identity and access management, software discovery, training delivery, ticketing, evidence storage, vendor questionnaires, monitoring, and controlled model access. Build or configure the judgment-heavy parts: your use case taxonomy, UK legal register, risk appetite, approval gate, DPIA workflow, human review design, evaluation thresholds, escalation rules, and executive reporting. A governance platform can organise evidence, but it cannot decide whether a recruitment workflow has an equality risk, whether a product is safe, or whether a reviewer can genuinely correct an outcome.

What can we do for you?

Magna Products helps UK B2B companies turn scattered AI experiments into controlled, useful operations. We can inventory your AI use cases, map UK data protection, equality, employment, consumer, product, and sector considerations, design practical DPIA and approval workflows, review customer and workforce processes, strengthen vendor controls, and connect human oversight, incident response, evidence, and KPIs to the systems your teams already use. Talk with Magna Products to schedule a focused discovery workshop and leave with a prioritised 30, 60, and 90-day implementation backlog.

Need this
in production?

Tell us which workflow should run in software. We will scope a first slice you can ship without a platform migration.

Contact us