AI law for business: the UK rules on artificial intelligence (AI)
The UK has no single AI act. What it has is a set of existing laws and regulators that already reach every AI system you deploy. Below, pillar by pillar: what the law says, what you need to do, and where to verify it at the source.
Updated 4 July 2026
The legal pillars
AI regulation: the UK's pro-innovation approachPro-innovation white paper (2023); no UK AI act; EU AI Act for EU-facing business⌄
What the law says
The UK regulates AI through its March 2023 pro-innovation white paper, not through a statute. As of July 2026 there is no general UK AI act and no dedicated AI regulator. Instead, DSIT sets policy centrally and your existing regulators, the ICO, the FCA, the ASA and the CMA, apply five cross-sector principles within their own remits.
What it means for you
No AI act does not mean no rules. The regulators you already answer to police your use of AI under the laws they already enforce: the ICO on personal data, the FCA if you are authorised, the ASA on advertising, the CMA on consumer law. Compliance planning starts with your existing regulators, not with a hypothetical future AI statute.
Example: If your AI chatbot misquotes a price to a customer, that is a consumer law matter under existing rules, exactly as if a member of staff had said it. There is no separate AI regulator to answer to, and no AI exemption to hide behind.
Five non-statutory principles guide how regulators look at AI: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; contestability and redress. They are not law, but regulators apply them within their remits, so a deployment that ignores them invites scrutiny.
Example: Before you roll out an AI tool that affects customers, check it against the five principles: can you explain its outputs, is someone accountable for it, and how does a customer challenge a result?
The EU AI Act does not apply in the UK, but it reaches you the moment you sell into the EU. It applies to providers placing AI systems on the EU market and to providers and deployers whose AI outputs are used in the EU, regardless of where the business is established.
Example: A UK software firm offering an AI product to customers in Germany must comply with the EU AI Act for that product, even though no equivalent law exists at home.
No general AI bill sits before Parliament as of July 2026. The government has chosen a targeted route: existing law does the work, supported by innovation tools such as the proposed AI Growth Lab regulatory sandbox. Build your compliance on the current framework, not on a law that may never arrive.
Example: If you are budgeting for AI governance, put the money into UK GDPR, consumer and sector compliance now, rather than waiting for a UK AI act to define the requirements.
Data protection: UK GDPR and the DUAA 2025UK GDPR + Data Protection Act 2018, amended by the Data (Use and Access) Act 2025; regulator: ICO⌄
What the law says
The UK GDPR, the retained and since amended version of the EU regulation, governs every piece of personal data your AI touches. You need a lawful basis, you must inform people, respect their rights and keep the data secure. The Data (Use and Access) Act 2025 amended the rules, most notably on automated decision-making, with the main data protection changes in force since 5 February 2026.
What it means for you
Everything personal your AI processes, from chat transcripts and call recordings to email addresses and CRM records, sits under the UK GDPR. You need a lawful basis to process it and a privacy notice that tells people what you do with their data.
Example: If an AI agent answers customers on WhatsApp and saves the conversation history, those transcripts are personal data: you need a lawful basis and a clear entry in your privacy notice.
Since 5 February 2026, Article 22 has been replaced by Articles 22A to 22D. Solely automated significant decisions are now generally permitted, a relaxation of the old rule, provided you apply the safeguards: tell the individual, let them make representations, give them meaningful human intervention on request and a way to contest the decision. The stricter, prohibition-style regime is retained for special category data. This is a genuine divergence from the EU, which keeps the old default prohibition.
Example: You can now let a system decide a routine application outcome end to end, provided the person is told, can ask for a human review and can contest the result. The same decision built on health data still falls under the stricter regime.
The ICO's Guidance on AI and data protection is the operational rulebook: fairness across the AI lifecycle, transparency and explainability, accountability, and what an AI-specific DPIA must cover. High-risk processing needs that DPIA before you start, not after.
Example: Before you deploy AI that profiles customers at scale, run a DPIA using the ICO's AI guidance as the checklist. It documents the risks and mitigations, and it is the first thing the ICO asks to see.
The DUAA also created a list of recognised legitimate interests as a lawful basis and reformed subject access and complaints handling, with implementation phased over roughly twelve months from Royal Assent on 19 June 2025. Your lawful-basis map is worth revisiting.
Example: Map which lawful basis each AI workflow relies on and check it against the new recognised legitimate interests list, rather than defaulting everything to consent.
Fines and penalties
Up to £17.5 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious breaches, including the automated decision-making rules; the standard maximum is £8.7 million or 2% (UK GDPR Article 83).
Tax and invoicing: Making Tax Digital and e-invoicingMaking Tax Digital for VAT and for Income Tax (HMRC); e-invoicing mandate from April 2029⌄
What the law says
All VAT-registered businesses must already keep digital records and file VAT returns through compatible software under Making Tax Digital. From 6 April 2026, MTD extends to Income Tax for sole traders and landlords with qualifying income over £50,000. There is no general B2B e-invoicing mandate today, but one is coming: all VAT invoices must be issued as e-invoices from April 2029.
What it means for you
MTD for VAT requires digital records and digital links across the whole VAT return process. AI can prepare, check and reconcile, but the flow has to stay digital end to end, with no manual retyping in the middle.
Example: An AI workflow that drafts invoices and reconciles them straight into your accounting software keeps the digital link intact. Retyping figures from a PDF into the VAT return breaks it.
MTD for Income Tax starts on 6 April 2026 for sole traders and landlords with qualifying income over £50,000, then over £30,000 from April 2027 and over £20,000 from 6 April 2028. It means digital records and quarterly digital updates through MTD-compatible software.
Example: A sole trader above the £50,000 threshold needs quarterly digital updates from April 2026. Automating record capture now avoids a scramble at the first deadline.
E-invoicing is coming, not current. The government announced at Budget 2025 that all VAT invoices must be issued as e-invoices from April 2029, covering B2B and B2G but not B2C, on a decentralised exchange model. Real-time reporting to HMRC will not arrive in 2029, and the implementation roadmap is due at Budget 2026.
Example: If you are building an invoicing workflow in 2026, design it so structured e-invoices are an output format you can switch on, rather than a rebuild in 2028.
Consumer protection and advertisingCAP and BCAP Codes (ASA); Digital Markets, Competition and Consumers Act 2024 (CMA); Consumer Rights Act 2015⌄
What the law says
There are no AI-specific advertising rules, but the CAP and BCAP Codes apply in full to AI-generated ads: an ad must not mislead, whatever generated, edited or targeted it. Since 6 April 2025 the CMA can also decide consumer law breaches itself and fine businesses directly under the DMCC Act 2024, and the Consumer Rights Act 2015 gives consumers statutory rights over digital content.
What it means for you
There is no blanket legal requirement to disclose AI use in an ad. Disclosure is needed where the audience would otherwise be misled, and, crucially, disclosing AI use cannot cure a claim that is misleading in itself. The truth of the claim comes first; the label comes second.
Example: AI-generated imagery showing product results that are not real misleads even with an 'AI-generated' label attached. Fix the claim, not the caption.
The DMCC Act 2024 regime, in force since 6 April 2025, bans fake reviews outright, covering posting them, commissioning them and hosting duties for platforms, and bans drip pricing: every mandatory fee must appear in the headline price. AI-generated fake reviews and misleading AI-driven pricing sit squarely inside it, and the CMA no longer needs a court to act.
Example: Using AI to generate customer reviews, or letting a pricing engine reveal a compulsory admin fee only at checkout, are both breaches the CMA can now fine directly.
The Consumer Rights Act 2015 covers goods, services and digital content: what you sell must be of satisfactory quality, fit for purpose and as described, and pre-contract information becomes part of the contract. That applies to any AI-powered product or software you sell to UK consumers.
Example: If you sell a consumer app with an AI feature, the marketing description of what that feature does becomes a contractual term. Overselling it creates a statutory claim, not just a refund conversation.
Fines and penalties
Under the DMCC Act 2024, in force since 6 April 2025, the CMA can impose fines of up to 10% of annual worldwide turnover on businesses, plus up to £300,000 on individuals who are accessories (CMA207 guidance).
Work and recruitmentEquality Act 2010; UK GDPR Articles 22A to 22D; ICO guidance on recruitment AI and monitoring workers⌄
What the law says
AI used in hiring and people management is regulated through the Equality Act 2010, the UK GDPR and ICO guidance. You are liable for the discriminatory outcomes of the tools you deploy, automated hiring decisions must carry safeguards, and monitoring staff with AI needs a lawful basis and usually a DPIA.
What it means for you
The Equality Act 2010 makes the employer liable for the discriminatory outcomes of an AI screening tool it uses, even if a vendor built it. Bias can be direct discrimination under section 13 or indirect under section 19: a facially neutral algorithm that disadvantages a protected group engages section 19 unless you can justify it as a proportionate means of achieving a legitimate aim.
Example: If a CV screening tool consistently ranks candidates from one ethnic group lower, the tribunal claim lands on you, not on the software vendor.
The ICO's audit of AI recruitment tools, published in November 2024, found tools that let recruiters filter candidates by protected characteristics, tools inferring gender and ethnicity from names, excessive data collection and indefinite retention. It produced almost 300 recommendations. The practical asks: demand bias-testing evidence from vendors, minimise the data you collect, and tell candidates clearly how AI uses their information.
Example: Before you buy a screening tool, ask the vendor for its bias-testing evidence and its retention policy. The ICO expects you to have both on file.
Since 5 February 2026, a solely automated rejection of a job applicant is a significant decision under UK GDPR Articles 22A to 22D. It is generally permitted for non-special-category data if you provide the Article 22C safeguards: information about the decision, the ability to make representations, meaningful human intervention on request and a route to contest. The human involvement must be genuine, not a rubber stamp.
Example: You may auto-reject applicants who lack a required qualification, provided each rejected candidate is informed, can respond and can obtain a genuine human review on request.
Monitoring workers with AI falls under the ICO's monitoring guidance from October 2023: you need a lawful basis, transparency and proportionality, and a DPIA for monitoring likely to cause high risk. The guidance names biometric monitoring, keystroke monitoring and performance monitoring that can lead to financial loss as examples.
Example: An AI tool that scores staff productivity and feeds pay or dismissal decisions is high-risk monitoring. Run the DPIA before switching it on, not after.
Fines and penalties
Breaches of the UK GDPR rules these tools engage, including the automated decision-making provisions, carry ICO fines of up to £17.5 million or 4% of total worldwide annual turnover (UK GDPR Article 83).
Sector rules: the FCA and financial servicesFSMA 2000 and the FCA Handbook (CONC 3, Consumer Duty); FCA motor finance redress scheme (PS26/3)⌄
What the law says
There is no AI-specific FCA rulebook. AI in regulated financial services is governed through the existing FSMA framework: the Consumer Duty requires firms to put customers' needs first, and financial promotions must be clear, fair and not misleading. The sector's dominant compliance event in 2026 is the motor finance commission redress scheme. The Upper Tribunal is expected to hear the challenges in December 2026 or February 2027, so compensation payments are unlikely to start before 2027.
What it means for you
The FCA confirmed an industry-wide motor finance redress scheme in PS26/3 on 30 March 2026: agreements from 2007 to 2024, an estimated £9.1 billion total cost, 12.1 million eligible agreements and average compensation of about £829. Since 2 July 2026, however, the Upper Tribunal has suspended parts of the scheme pending legal challenges, with hearings considered unlikely before October 2026. The non-suspended rules continue to bind.
Example: A lender does not currently need to calculate or pay compensation under the suspended parts, but the record-keeping and complaints obligations in the non-suspended rules still apply while the challenges run.
Financial promotions are restricted by section 21 of FSMA 2000, and FCA rules in CONC 3 require consumer credit promotions, including AI-generated or AI-targeted ads, to be clear, fair and not misleading. The rule attaches to every promotion that goes out, however it was produced.
Example: An AI tool that drafts and targets car finance ads is producing financial promotions. Every variant it generates has to satisfy CONC 3, not just the master copy a human approved.
The Consumer Duty requires firms to put customers' needs first across how retail products are designed, sold and supported. That includes AI-driven sales, pricing and support journeys: the FCA judges the outcome the customer gets, not the technology that produced it.
Example: If an AI support agent handles customers of a regulated product, the quality of the outcome it delivers is Consumer Duty evidence, good or bad.
Solely automated creditworthiness or pricing decisions are significant decisions under UK GDPR Articles 22A to 22D, in force since 5 February 2026. The Article 22C safeguards apply on top of the FCA rules, not instead of them.
Example: An automated affordability decline must offer the customer information about the decision, a way to make representations, human intervention and a route to contest it, alongside your FCA obligations.
The full acts, annotated
By industry
Beyond the general rules above, some sectors carry their own legal particularities to account for when you deploy AI.
A dealership that introduces customers to lenders, recommends regulated agreements or helps with finance applications is carrying on credit broking and must be FCA-authorised. Any AI chatbot or sales agent that steers a customer toward finance operates inside that regulated perimeter.
Example: Your bot can confirm a car is available, book a test drive and outline finance and part-exchange options, but the regulated finance journey it hands over to must sit within your FCA permissions.
The motor finance commission redress scheme dominates the sector's 2026 compliance agenda: 12.1 million agreements from 2007 to 2024 and around £9.1 billion in estimated total cost, with parts of the scheme suspended by the Upper Tribunal since 2 July 2026 pending legal challenges. The non-suspended record-keeping, customer contact and complaints rules still apply to dealers as brokers and to lenders.
Example: Keep your finance commission records and complaints process running to the scheme's standards now. The suspension pauses parts of the compensation mechanics, not the rest of your obligations.
AI-generated car ads and online pricing must clear the CAP Code and the DMCC Act: disclosing AI use cannot cure a misleading claim, every mandatory fee such as an admin fee must appear in the headline vehicle price, and fake reviews are banned, with CMA fines of up to 10% of global turnover.
Example: If your listing engine quotes £14,995 and a compulsory £199 admin fee appears only at the desk, that is drip pricing under the new regime. Put the fee in the headline price.
AI screening tools carry a documented risk profile in the UK: the ICO's November 2024 audit found tools filtering by protected characteristics and inferring gender and ethnicity from names, and the Equality Act 2010 makes the employer liable for the discriminatory outcomes of tools it deploys.
Example: Put bias-testing evidence from the vendor, a DPIA and a candidate-facing explanation of how AI uses their information in place before the tool screens its first CV.
Since 5 February 2026, fully automated hiring decisions are lawful with the Article 22C safeguards: the candidate is informed, can make representations, can obtain meaningful human intervention and can contest the decision. This is a genuine UK divergence: the EU keeps the stricter default prohibition on solely automated decisions.
Example: A UK-only recruiter can automate more of the funnel than an EU competitor, provided every rejected candidate is informed, can respond and can get a genuine human review.
AI-powered employee monitoring needs a lawful basis, transparency and proportionality, and a DPIA where the risk is high. The ICO names biometric monitoring, keystroke logging and performance monitoring that can cause financial loss as high-risk examples.
Example: Keystroke-level productivity tracking is named by the ICO as high risk. If you cannot justify it as proportionate, do not deploy it.
There is no AI-specific FCA rulebook: the regulator works through outcomes. The Consumer Duty requires you to put customers' needs first across AI-driven sales, advice, pricing and support, and financial promotions, including AI-generated ones, must satisfy section 21 of FSMA and the clear, fair and not misleading standard in CONC 3.
Example: Treat every AI-generated promotion and every AI-led customer journey as in scope of your existing FCA obligations from day one.
Motor finance redress is the FCA's flagship consumer redress exercise and it is partially suspended as of July 2026: the Upper Tribunal paused parts of the PS26/3 scheme on 2 July 2026 pending legal challenges, with hearings unlikely before October 2026. Lenders and credit brokers must still comply with all non-suspended rules.
Example: Do not stand down your redress preparation. The suspension covers parts of the scheme, and the surviving rules continue to apply while the challenges proceed.
Data-driven credit and pricing decisions sit under UK GDPR Articles 22A to 22D plus the ICO's AI guidance: solely automated significant decisions need the Article 22C safeguards, and ICO fines for breaches reach £17.5 million or 4% of worldwide turnover.
Example: A solely automated pricing decision for a retail customer needs the Article 22C safeguards built into the journey, alongside your Consumer Duty evidence.
This page is informational, not legal advice. The law changes and every situation has its own facts, so confirm any concrete case with a qualified solicitor or accountant.
Want to use AI and stay on the right side of UK law?
Svennis builds AI solutions on Claude, designed from the start for the UK GDPR, the FCA's expectations and the rules on this page. You focus on the business, we build for compliance.