Five AI Regulatory Regimes: What UK CIOs Must Map in 2026
UK GDPR, the EU AI Act’s extraterritorial provisions, FCA Consumer Duty guidance, the UK’s cross-sector AI principles, and sector rules from bodies such as the MHRA and SRA now apply simultaneously to most enterprise AI deployments. No single filing satisfies all five.
That overlap is not theoretical. Recent industry surveys found that 62% of UK CIOs say their organisation is not fully prepared to comply with the EU AI Act, and 57% are not fully prepared for the UK’s own AI governance framework. AI adoption has outpaced the internal controls needed to manage it, and the gap is now a board-level risk rather than an IT backlog item.
What are the five AI regulatory regimes CIOs must now navigate?
UK GDPR and the Data Protection Act 2018 remain the floor for any AI system touching personal data — customer records, employee files, support tickets, or sales notes. Layered on top: the EU AI Act, which applies extraterritorially to UK firms whose AI systems affect EU users or markets; FCA Consumer Duty guidance for AI used in financial services decisioning; the UK’s cross-sector AI principles applied by existing regulators including the ICO, Ofcom and CMA; and sector-specific rules from bodies such as the MHRA (health AI), the SRA (legal AI) and the EHRC (employment AI). A single AI deployment can trigger obligations under three or four of these at once.
Executive Action:
- Commission a regulatory-overlap map for every live AI system, listing which of the five regimes apply
- Flag any system touching EU users or data for EU AI Act extraterritorial review
- Assign single ownership for each regime to avoid gaps between compliance, data protection and risk teams
Why are so many CIOs still unprepared for the EU AI Act’s reach?
Most UK CIOs built their governance programmes around domestic expectations — the ICO’s AI guidance and the FCA’s Consumer Duty rules — on the assumption that Brexit removed EU exposure. It did not. The EU AI Act applies to any provider or deployer placing an AI system on the EU market or whose AI system’s output is used in the EU, regardless of where the organisation is headquartered. For UK groups with EU subsidiaries, EU customers, or EU staff, high-risk AI use cases now carry EU-level conformity assessment, technical documentation and human-oversight obligations that go further than anything in the UK’s current voluntary framework.
Executive Action:
- Identify every AI system with an EU touchpoint — users, data subjects, or market outputs
- Classify each by EU AI Act risk tier (unacceptable, high, limited, minimal)
- Brief the board on conformity assessment timelines for any high-risk system
How should CIOs structure governance to satisfy all five regimes at once?
Rather than running five parallel compliance programmes, leading CIOs are building a single governance architecture and mapping each regime’s requirements onto it. In practice that means standing up two permanent groups: an Enterprise AI Council that sets AI strategy and approves policy at the point of adoption, and a Model Risk & Assurance Committee that owns ongoing validation, performance monitoring, drift detection and explainability. Structuring the programme around ISO 42001 — the international AI management system standard — gives CIOs a defensible single framework: an organisation built to ISO 42001 and EU AI Act standards will already satisfy most FCA model risk expectations and ICO data protection impact assessment requirements, with only targeted UK-specific additions required.
Executive Action:
- Stand up an Enterprise AI Council with cross-functional sign-off authority
- Adopt ISO 42001 as the single governance backbone rather than five separate playbooks
- Require every new AI use case to pass through the Model Risk & Assurance Committee before go-live
What should CIOs bring to the board this quarter?
Boards are increasingly asking CIOs for a single answer to “are we compliant?” rather than five separate updates. The most effective response is a one-page regulatory heat map — every live AI system, its applicable regimes, its risk tier, and its remediation status — refreshed quarterly. This also gives audit and risk committees a defensible record ahead of any FCA, ICO or EU regulator enquiry.
Executive Action:
- Present a quarterly AI regulatory heat map to the risk or audit committee
- Benchmark current governance maturity against INFORMD’s AI governance test
- Set a remediation deadline for any system flagged high-risk under two or more regimes
CIOs who want a structured starting point can use INFORMD’s AI governance test to benchmark current maturity, and the technology strategy review template to brief the board. INFORMD’s executive briefings library tracks each of the five regimes as they evolve.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.
Only if the AI system’s output is used in the EU or affects EU users, regardless of where the company is based. UK-only operations with no EU touchpoint fall outside its scope, but many groups with EU subsidiaries or customers are caught.
A set of five principles — safety, transparency, fairness, accountability and contestability — applied by existing regulators like the ICO, FCA and CMA within their current mandates, rather than a single new AI law.
No. ISO 42001 provides a single governance framework that maps to most requirements across regimes, reducing duplication, but organisation-specific obligations under the EU AI Act, FCA rules and UK GDPR still apply separately.
The CIO or CTO typically owns the technical mapping, working with the data protection officer and compliance function, with outcomes reported to the risk or audit committee for board visibility.
