The ICO isn't waiting for a new AI law.
It's enforcing the ones that already exist.
There is no UK AI Act, and the government's deliberately light-touch approach has convinced a great many businesses they have nothing to do. Most are non-compliant and do not know it.
UK GDPR already applies to every AI system that processes personal data. It made no exception for AI and needs no amendment to reach it.
The ICO has an AI Auditing Framework and is actively investigating AI deployments. It does not need a new statute to use the powers it already has.
The Equality Act 2010 covers AI in hiring. Where a tool screens or ranks candidates on your behalf, having bought it in is not a defence.
Not sure where you stand? Answer 7 questions and get your free UK AI compliance exposure report — instant, no sign-up.
Take the Free Check →"No UK AI Act" does not mean "no obligation."
The UK Government's AI regulation White Paper took a principles-based, pro-innovation approach — deliberately avoiding prescriptive legislation. Many businesses read this as a green light. It isn't. Existing law already reaches into AI systems in ways most businesses haven't mapped.
UK GDPR applies to every AI system that collects, processes, or makes decisions using personal data about UK individuals. Data minimisation, purpose limitation, fairness, and transparency requirements all apply — and automated decision-making has specific obligations.
The ICO published its AI Auditing Framework and has issued its first AI-specific enforcement actions. The ICO can and does investigate AI deployments — you don't need to wait for a formal complaint. Pro-active audits of high-risk AI uses are part of the ICO's published enforcement strategy.
The Equality Act 2010 applies to AI systems used in recruitment, promotion, disciplinary proceedings, or any employment decision. If your AI tool produces outputs that indirectly discriminate on protected characteristics — even unintentionally — you have liability.
The FCA has published AI guidance and expects firms to apply existing regulatory obligations — fairness, explainability, governance — to AI systems. FCA-regulated firms using AI in credit decisions, customer communications, or risk assessment have obligations beyond UK GDPR.
The ICO issued its first AI-specific enforcement action in 2024. Businesses can no longer claim ignorance of how existing law applies to their AI tools.
UK AI regulation: different from the EU, but not absent.
The UK's retained version of GDPR applies to all AI systems that process personal data. Automated decision-making provisions, transparency requirements, and data subject rights obligations all apply to AI deployments. This is the primary compliance obligation for most UK businesses using AI.
The ICO has published a detailed AI auditing framework covering accountability, transparency, data minimisation, security, and fairness in AI systems. The ICO uses this framework in investigations. Businesses without documented AI governance are exposed.
Any AI system used in employment decisions must not produce outputs that discriminate — directly or indirectly — on protected characteristics. This isn't a new obligation. It's the Equality Act applied to AI. Most HR AI tools have never been assessed against it.
The government's AI Regulation White Paper established five principles: safety, security, transparency, fairness, accountability, and contestability. These are currently non-statutory guidance applied by sector regulators. Future legislation may codify them. Building your framework around these principles now ensures resilience as the landscape firms up.
14 dates that decide whether you are compliant.
8 of them have already passed.
United Kingdom is one line of 6. The businesses we see are rarely on only one. Yours is marked. The others reach you through your customers, your staff and your suppliers, wherever you are registered.
Europe
- in force Obligations for general-purpose AI models.
- in force Article 50 transparency duties, deployer obligations, and enforcement powers for national regulators.
- coming New prohibitions, and Article 50(2) marking of synthetic content.
- coming Every Member State must have an AI regulatory sandbox running.
- coming High-risk obligations for Annex III systems — including AI used in recruitment, credit scoring, education and essential services.
- coming High-risk obligations for Annex I systems — AI embedded in products already covered by EU product safety law.
United Kingdom this page
- in force Most Part 5 data protection provisions of the Data (Use and Access) Act 2025, including the wider lawful bases for solely automated decisions and the safeguards that come with them.
- in force The duty on controllers to operate a complaints procedure and respond to data protection complaints within set time limits.
United States
- in force Texas HB 149, the Responsible Artificial Intelligence Governance Act — prohibited uses, government AI disclosure, and Attorney General enforcement.
- in force California SB 942, the AI Transparency Act — free AI detection tool and latent provenance disclosure for large generative AI providers. Delayed from 1 January 2026 by AB 853.
- coming Colorado SB 26-189 — developer and deployer duties for automated decision-making technology used in consequential decisions. It repealed and reenacted SB 24-205, which never took effect.
Canada
- in force Ontario ESA / O. Reg. 476/24 — a publicly advertised job posting must disclose the use of AI to screen, assess or select applicants. Employers of 25 or more, including where a third party screens on their behalf.
Australia
- coming Privacy Act 1988 (Cth), APP 1.7 — a privacy policy must say what kinds of personal information a computer program uses to make decisions that could reasonably be expected to significantly affect a person, and what kinds of decisions those are.
United Arab Emirates
- in force DIFC Data Protection Regulation 10 — a business deploying an autonomous or semi-autonomous system that processes personal data must tell users, on first use, what the system decides for itself, what it was built to do and what it does with the output.
If any of these apply to your business, you have compliance obligations today.
- Using any AI tool that processes personal data about UK individuals (UK GDPR applies)
- AI-assisted CV screening, candidate ranking, or any hiring or HR decisions
- Automated decisions about customers that have meaningful effects (pricing, credit, access)
- FCA-regulated firms using AI in customer communications, risk modelling, or credit decisions
- Healthcare, legal, or education organisations deploying AI in service delivery
- Any UK business that wants a documented, defensible AI governance position
Read it before you buy it.
This is not a mock-up or a contents page. It is a genuine UK AI Compliance pack — all 19 documents — produced by the same system that will produce yours, for a fictional recruitment firm we invented to test it. Their AI shortlists candidates, so the pack is written around that. Yours is written around whatever your business does.
Opens the PDF exactly as a client receives it. Yours is written around your business, your tools and your sector — not this one.
Build to what the ICO already audits, not to a statute that may never arrive.
Waiting for a UK AI Act assumes the duties start when it does. They do not, and the shape of them is already published. The government's five principles — safety, security, transparency, fairness, accountability and contestability — are non-statutory guidance that sector regulators apply today, and the ICO's audit framework asks its own questions of the same systems. Neither is a forecast. Both are what an investigation opens with.
So the durable move is to build to the principles, not to a bill. Do that and you hold a documented position now — and if Parliament codifies those principles, it tests a framework you already have rather than one you are writing under deadline. That is what the annual renewal is for: when the ICO, a sector regulator or Parliament moves, your framework moves with it, and you are not paying to start again.
Not sure which of these already bind you? Seven questions, no sign-up.
Take the free check →
Your customers decide which law
applies to you. Not your address.
Where your customers are, where your staff are and where your AI has effect — those decide, not where the business is registered. We write frameworks to four legal systems, and serve four more on request.
- United Kingdom UK GDPR, in force now. The Data (Use and Access) Act added automated-decision duties from 5 February 2026.
- European Union The EU AI Act. General-purpose AI obligations already apply; enforcement begins 2 August 2026.
- United States State by state, not federal. Texas from 1 January 2026, California from 2 August 2026, Colorado from 1 January 2027.
- Canada PIPEDA plus provincial law. Ontario's AI hiring disclosure rules applied from 1 January 2026.
UK AI Compliance Packages.
Every package builds a documented, defensible compliance position for your business. Prices in GBP. Stripe accepts all major cards.
- UK GDPR gap analysis for your AI tools
- AI Acceptable Use Policy (UK-specific)
- Employee AI guidelines
- ICO framework self-assessment
- Basic compliance roadmap
Best for: small businesses wanting to understand and document their UK GDPR obligations for the AI tools they're already using.
In your inbox by the end of the business day · Covers you for 12 months, renews yearly
Buy now — £797/yr →- Everything in UK AI Compliance Foundation
- Full ICO AI Auditing Framework assessment
- Employment AI procedures (Equality Act compliance)
- Automated decision-making notices and opt-out procedures
- Data subject rights procedures for AI-processed data
- Sector-specific obligations review (finance, health, legal)
Best for: businesses using AI in HR or employment decisions, FCA-regulated firms, or any business wanting a comprehensive, ICO-ready compliance position.
In your inbox by the end of the business day · Covers you for 12 months, renews yearly
Renews yearly — ICO guidance and legislation updates applied throughout your cover.
Book a scoping call → or buy directly — £1,297/yrEvery framework is annual — your fee covers 12 months of protection, with ICO guidance updates and UK AI regulation developments applied to your framework as they land, and renews yearly so your cover never lapses.
How we build your UK AI compliance framework.
Audit
We identify every AI tool your business uses, what personal data it processes, and what decisions it influences — hiring, customer, financial, or otherwise.
Assess
We map your AI use against UK GDPR obligations, the ICO AI Auditing Framework, employment law requirements, and any sector-specific obligations that apply to your business.
Document
We build your compliance framework — acceptable use policy, ICO self-assessment documentation, employment AI notices, automated decision-making procedures, and data subject rights processes.
Maintain
Throughout your 12-month cover, we monitor ICO enforcement decisions, guidance updates, and UK AI regulation developments — and update your framework so it stays current. Renews yearly.
Straight answers.
Is UK AI compliance different from EU AI Act compliance?
Yes, significantly. The EU AI Act is prescriptive legislation with specific requirements by risk category — it's a detailed rulebook. The UK government deliberately chose a different path: a principles-based approach applied through existing sector regulators rather than a single AI-specific law. In practice, UK compliance is less about ticking boxes on a new law and more about demonstrating that your existing obligations under UK GDPR, employment law, and sector regulations extend to your AI systems — and that you've documented your governance accordingly.
What does the ICO actually look for when investigating AI?
The ICO's AI Auditing Framework covers six areas: accountability and governance (who is responsible for AI decisions?), transparency (can individuals understand how AI affects them?), data minimisation (is the AI using only necessary personal data?), accuracy (are AI outputs accurate and regularly tested?), security (are AI systems and the data they process properly secured?), and fairness (are AI outputs fair and non-discriminatory?). Businesses with documented AI governance across these areas are in a substantially better position than those without.
Does the Equality Act apply to off-the-shelf AI tools I didn't build?
Yes. The Equality Act 2010 applies to the employer's actions, not the tool's source code. If you use an AI tool in a hiring or employment decision and the outputs are discriminatory — even if the tool was supplied by a third party — you carry the liability. Indirectly discriminatory outputs (for example, a CV screening tool that systematically deprioritises certain names or universities) can trigger Equality Act exposure.
We're a small business. Does this really apply to us?
UK GDPR applies to all businesses that process personal data, regardless of size — there are no small-business exemptions for AI systems. That said, proportionality matters: the ICO expects your compliance to be proportionate to your size and the risks involved. Our Starter package is specifically designed for small businesses that need a proportionate, practical compliance position without enterprise-level complexity.
Is this legal advice?
No. We produce compliance documentation frameworks and policy documents — we are not solicitors. For businesses in regulated sectors or facing specific ICO investigations, we recommend reviewing your documentation with UK-qualified legal counsel. For most businesses using standard AI tools, our frameworks provide a practical, well-documented compliance position that demonstrates good-faith effort to the ICO.
Get your UK AI compliance framework in place.
The ICO is already investigating AI deployments. UK GDPR already applies to your AI tools. The Equality Act already covers AI in employment decisions. Build your compliance position now.
See the Packages →Or book a free 20-minute call to discuss your situation — hello@opsintel.io