UK AI Regulation 2026: A CIO’s Four-Regulator Checklist
The UK has no single AI law. CIOs answer to the ICO, FCA, Ofcom and CMA under existing powers, plus the extraterritorial EU AI Act.
Why Doesn’t the UK Have a Single AI Law?
The UK government has deliberately avoided a US-style single AI statute. Instead, the Department for Science, Innovation and Technology directs existing sector regulators to apply their current powers to AI within their own remit — a “pro-innovation” approach set out in 2023 and reaffirmed since. In December 2025, the Financial Conduct Authority confirmed it will not introduce AI-specific rules, choosing instead to supervise AI risk through frameworks such as the Consumer Duty and SM&CR. That decision closed the door, for now, on a UK equivalent to the EU’s more prescriptive statute.
For a CIO, this creates a distinctive shape: no single AI rulebook, but several regulators each expecting AI governed within their existing rules. Ambiguity is the operating environment, not a phase before a bill arrives.
Executive Action
- Confirm with legal and compliance that no UK-wide AI statute is currently before Parliament, and track DSIT policy statements rather than waiting for a bill.
- Map which existing regulator or regulators already govern your sector’s core activities — that is where AI obligations will actually be enforced.
- Brief the CEO and board that “no AI Act” does not mean “no AI law” — obligations already apply through existing regimes.
Which Regulators Actually Govern Your AI Systems?
Four regulators carry the bulk of UK AI oversight today. The Information Commissioner’s Office (ICO) polices AI through UK GDPR and the Data (Use and Access) Act 2025, including a forthcoming statutory code on AI and automated decision-making. The Financial Conduct Authority (FCA), and the PRA where prudential risk is engaged, supervise AI used in credit decisions, trading and customer outcomes under existing conduct rules. Ofcom oversees AI used in content moderation under the Online Safety Act. The Competition and Markets Authority (CMA) watches AI foundation-model markets and algorithmic pricing for competition harms.
Sector regulators add further obligations on top: the MHRA for AI in medical devices, the Civil Aviation Authority for aviation systems, and Ofgem for energy network AI. A single deployment can sit inside two or three regulatory perimeters at once.
Executive Action
- Build a register mapping each AI system in production to the regulator or regulators whose rules it falls under — not just data protection, but sector conduct rules too.
- Assign a named compliance owner per regulator relationship, rather than a single generic “AI governance lead.”
- Cross-reference vendor and third-party AI tools against the same register — outsourced AI does not outsource regulatory exposure.
How Does the EU AI Act Reach UK Organisations Anyway?
The EU AI Act is extraterritorial. It binds UK organisations that place AI systems on the EU market, or whose AI output is used by people in the EU, regardless of where the company is headquartered. Obligations for general-purpose AI models began applying from August 2025, and the majority of the Act — including high-risk system requirements under Annex III, transparency duties and enforcement — applies from 2 August 2026. UK CIOs whose organisations sell into the EU, or whose software serves EU users, cannot treat the Act as someone else’s regulation.
Any UK enterprise with EU customers, an EU subsidiary, or an AI product used by EU-based staff needs a risk classification exercise now, not after the 2 August deadline passes.
Executive Action
- Determine whether any AI system your organisation builds or deploys reaches EU users, customers or markets — this triggers EU AI Act exposure regardless of UK headquarters.
- Classify EU-exposed AI systems against the Act’s risk tiers before the 2 August 2026 enforcement date.
- Assign EU AI Act ownership separately from UK regulatory compliance — the obligations, timelines and enforcement bodies differ.
What Should a CIO’s AI Compliance Register Actually Contain?
Oversight, not adoption, is where most organisations fall short. According to the Office for National Statistics (January 2026), 44% of large UK businesses with 250 or more staff now use AI. Yet according to McKinsey’s State of AI 2025 survey, only 17% of organisations say their board owns AI-governance oversight. A CIO cannot wait for that ownership question to resolve before building the register regulators will expect to see.
At minimum, record each system’s business purpose, the regulator(s) it falls under, its data sources, whether it influences decisions about individuals, and the named executive accountable for it. This is the evidence base the ICO, FCA, Ofcom and CMA will each ask for first in any inquiry.
Executive Action
- Build one AI system register spanning procurement, IT and business units — fragmented registers are the most common finding in regulatory reviews.
- Include third-party and embedded AI, such as AI features inside procured software, which are frequently missing from initial registers.
- Refresh the register quarterly, tying updates to procurement and change-management processes so it does not go stale.
How Should CIOs Prepare Before the Rules Tighten?
According to the EY Center for Board Matters, board-level AI-risk oversight among Fortune 100 companies tripled from 16% to 48% across 2025 — a sign that board attention is catching up even where formal ownership lags. UK CIOs should use that momentum rather than wait for a UK AI Act that, on current government policy, is not coming. The organisations best placed for 2026’s enforcement activity will be those that treated the absence of a single law as a reason to build a thorough compliance foundation, not a reason to wait.
The AI governance self-assessment and technology strategy review template give CIOs a structured starting point. Our related briefing on the ICO’s forthcoming AI code of practice covers automated-decision-making obligations in more depth.
Executive Action
- Commission a gap assessment against all four core regulators plus any sector-specific regulator, using the register built above as the input.
- Set a board reporting cadence for AI regulatory exposure — quarterly at minimum, given how fast the FCA, ICO and EU positions are moving.
- Treat 2 August 2026 (EU AI Act) and the ICO’s AI code consultation as the two hard deadlines to build toward this year.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk (/resources/).
Frequently Asked Questions
No. The UK has no single AI statute. The government directs existing regulators, including the ICO, FCA, Ofcom and CMA, to apply their current powers to AI within their sector, an approach the FCA reaffirmed in December 2025.
Yes, where a UK organisation places AI on the EU market or its AI output is used by people in the EU. Obligations for general-purpose AI began in August 2025; most remaining provisions, including high-risk system rules, apply from 2 August 2026.
The FCA, and the PRA for prudential matters, supervise AI in financial services using existing conduct and risk frameworks such as the Consumer Duty and SM&CR, rather than AI-specific rules.
Every production AI system’s purpose, data sources, applicable regulator or regulators, whether it affects decisions about individuals, and a named accountable executive — the baseline evidence regulators request first in any review.
