UK AI Regulation by Sector: Practitioner Q&A
The UK has no AI Act. Which rules bind you depends on your regulator. FCA, SRA, MHRA and ICO expectations, plus where the EU AI Act reaches into UK firms.
The UK has no single AI Act. Existing regulators apply five cross-sector principles inside their own remits, so the rules binding you depend on who supervises you. This Q&A is for compliance and operations leads who need to know which obligations already apply and where the EU AI Act reaches in.
This page is general information rather than legal advice, and it reflects published regulator positions as we understand them at the time of writing. Positions in this area are moving quickly, so confirm your specific obligations with your own counsel or your regulator before acting.
What AI regulations apply to my sector in the UK?
The UK has no standalone AI statute. AI use is governed by whichever regulator already supervises your sector, applying existing law through the five cross-sector principles set out in the UK Government’s AI regulation white paper: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. The ICO applies UK GDPR wherever personal data is processed, whatever your sector. The EU AI Act can apply extraterritorially where you operate in or sell into the EU.
| Sector and regulator | Current stance | EU AI Act touchpoint |
|---|---|---|
| Financial services (FCA, PRA) | Existing conduct, resilience and accountability rules applied to AI; no separate AI rulebook published to date | Creditworthiness assessment and some insurance pricing sit in high-risk categories |
| Any sector processing personal data (ICO) | UK GDPR and DPA 2018 applied to training data, transparency and automated decisions | Overlaps on transparency and automated decision safeguards |
| Legal services (SRA) | Standards and Regulations applied through competence, confidentiality and supervision duties; guidance still evolving | Limited direct reach; relevant where tools are supplied into the EU |
| Healthcare and clinical (MHRA plus clinical governance) | Medical device rules may apply, depending on a tool’s intended purpose, where it informs diagnosis, triage or treatment | Safety components of regulated devices classed high-risk |
| Recruitment, education, insurance intermediation | No AI-specific regime; equality law and UK GDPR carry the weight | Employment and education uses classed high-risk |
Is AI actually regulated in the UK, or is it just guidance?
It is regulated, but indirectly. The absence of an instrument called an AI Act leads some teams to treat the space as voluntary. It is not: data protection, financial conduct, professional conduct, equality, consumer protection and product safety law all apply to AI systems as they apply to any other tool.
A discriminatory model output is an equality law problem; an opaque automated decision affecting an individual is a UK GDPR problem. The five principles are not directly enforceable, but the regimes carrying them hold the usual fines and licence consequences.
What does the FCA expect from firms using AI?
At the time of writing, the FCA’s published approach has been to supervise AI through its existing rulebook rather than through a dedicated AI chapter, so confirm the current position with the regulator before relying on it. Firms should therefore evidence AI governance through frameworks the regulator already examines: the Senior Managers and Certification Regime for accountability, the Consumer Duty for fair outcomes, operational resilience requirements for important business services and third-party rules where a model provider sits outside the firm.
PRA model risk management expectations apply to the firm types named in the supervisory statement currently in force, which is worth checking against your own permissions. The supervisory test is whether a named senior individual can explain what each system does, who signed it off and what the fallback is, which our AI Governance entry sets out.
What are the rules for AI in the legal sector?
As matters stand, the SRA has not published a bespoke AI rulebook and its guidance here continues to develop; solicitors remain bound by the SRA Standards and Regulations and their duties of competence, confidentiality, client care and integrity. Entering client material into a general-purpose model without contractual and technical assurance on retention and training risks a confidentiality breach, and relying on unverified output in advice or filings is a conduct risk rather than a quality problem.
Firms must also show how AI-assisted work is checked before it reaches a client or court. Unauthorised tool use by fee earners is the common failure route, so Shadow AI discovery comes first: you cannot supervise tools you have not identified. Our Shadow AI Discovery service runs that first pass.
How does the ICO fit in if my regulator has said nothing about AI?
The ICO’s jurisdiction runs across sectors regardless of what your primary regulator has published, because almost every commercially interesting AI use case touches personal data. Core requirements include a lawful basis, purpose limitation, data minimisation, a Data Protection Impact Assessment for high-risk processing, transparency about automated decision-making and safeguards where decisions are solely automated with legal or similarly significant effects.
Training data provenance and vendor data flows both fall in scope. Where a sector regulator has been quiet, treat the ICO as the binding constraint. Our answer on whether ChatGPT use can comply with UK GDPR works through the common staff-use case.
Does the EU AI Act apply to UK organisations?
Often, yes. The Act applies where an organisation places an AI system on the EU market, or where the output of a system is used within the EU, whatever the provider’s location. A UK firm serving EU clients, screening EU-based candidates or embedding a model into a product sold in the EU can fall in scope, with obligations scaling by risk classification and the heaviest documentation, testing and post-market monitoring duties falling on providers of high-risk systems.
Classify early, because remediation timelines are long. High-risk obligations were deferred by the Digital Omnibus on AI, Regulation (EU) 2026/1744, which entered into force on 27 July 2026: standalone Annex III systems now apply from 2 December 2027 and product-embedded Annex I systems from 2 August 2028. Our EU AI Act preparedness guide carries the full timeline and our answer on EU AI Act scope for UK businesses works through the scope tests.
Which sector has the strictest AI requirements?
Healthcare and clinical settings carry the highest bar, because tools informing diagnosis, triage or treatment may qualify as medical devices under current MHRA software guidance, depending on intended purpose, and attract regulation alongside clinical and information governance duties. Financial services follows, driven less by AI-specific rules than by the density of existing conduct, resilience and accountability requirements.
Legal and professional services face lighter formal regulation but sharp confidentiality and competence exposure. Semi-regulated sectors such as recruitment, education and insurance intermediation often underestimate their position, because equality law and UK GDPR bite hard on automated screening and pricing.
What should we do first if we do not know which rules apply?
Build an inventory before you build a policy, because obligations cannot be mapped onto systems you have not found. Where adoption has run ahead of policy, much of the estate will be unsanctioned. The sequence that works: discover what is in use including staff-adopted tools, classify each use case by data sensitivity and decision consequence, map each against your primary regulator, the ICO and any EU exposure, then assign a named owner per system.
An AI Security Gap Analysis produces that inventory and obligation map, and AI Behaviour Verification tests whether deployed systems behave as the documentation claims.
Do we need external help, or can we handle this in-house?
In-house is viable with three capabilities: someone who can translate regulatory text into control requirements, someone who can technically inspect model and data flows and enough authority to stop a business unit deploying something unsafe. Where the second or third is absent, the result is a well-written policy with no verification behind it.
External support earns its place in the initial discovery and classification pass, where independence matters, and in periodic verification. Ongoing governance belongs internally, embedded in change control and in a management system such as ISO 42001.
Map your obligations to your systems
AI Act Preparedness builds the inventory and obligation map that shows which regulator, which rule and which EU exposure applies to each AI system you run.