Category: UK AI Regulation

The United Kingdom has no single AI act; instead, AI is regulated through a principles-based framework applied by existing regulators — the ICO, FCA, CMA, Ofcom and others — alongside data protection law (UK GDPR and the Data Protection Act 2018), equality law, and sector rules. This section covers what that means in practice for UK organisations: which existing legal duties already bite on AI systems, what the ICO expects on automated decision-making and AI-driven processing, how UK common law is developing on liability for AI-caused harm, and — critically for many UK businesses — when the EU AI Act applies to them anyway despite Brexit, through its extraterritorial reach. The articles here are written primarily for UK SMEs and their advisers, who face the distinctive problem of navigating two regimes at once: a flexible domestic framework with few bright lines, and a prescriptive EU regime that catches them the moment their systems or outputs touch the EU market.