The UK: regulating AI without an AI law
Lesson 1 of 5 in The UK, Canada, Brazil — and the Missing Map: Africa, the Middle East, Latin America.
The United Kingdom made a bet no other major economy made: govern AI with the regulators you already have, and pass no AI statute at all.
The March 2023 white paper — A pro-innovation approach to AI regulation — set out five cross-sectoral principles: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; contestability and redress. Sound familiar? They are the OECD principles wearing a Union Jack. The twist is in the delivery mechanism: no new law, no new AI regulator. Each existing regulator applies the five principles inside its own remit, using powers it already holds. Medicines regulator handles medical AI; financial regulator handles credit models; the data-protection authority handles everything touching personal data — which, in practice, is almost everything.
| Regulator | Remit | Legal hook | Example AI actions |
|---|---|---|---|
ICO | Data protection and privacy | UK GDPR applies to AI | Guidance on AI and data protection; enforcement against Clearview AI; consultations on generative-AI lawful basis |
CMA | Competition and markets | Foundation-model market power | Foundation-model market reviews; scrutiny of big-tech / AI-lab partnerships and cloud dependencies |
FCA | Financial services | AI in credit, insurance, trading | AI update reports; supervisory expectations for model risk under existing SM&CR accountability rules |
Ofcom | Communications and online safety | AI-generated content, recommender systems | Online Safety Act codes that reach algorithmic curation and synthetic content |
MHRA | Medicines and medical devices | AI as a medical device | AI Airlock regulatory sandbox for AI medical devices; software-as-medical-device guidance |
The regulators coordinate through the Digital Regulation Cooperation Forum (DRCF) — ICO, CMA, FCA and Ofcom pooling expertise so a firm facing four regulators hears one broadly consistent story. Alongside them sits the Algorithmic Transparency Recording Standard (ATRS), which requires central-government bodies to publish structured records of the algorithmic tools they use — one of the few mandatory AI-specific instruments in the UK stack, and only for the public sector.
The argument for this architecture: sector regulators know their domains, principles flex faster than statutes, and innovation is not frightened away. The argument against, made loudly by Parliament’s own committees: principles without new powers or duties are advice, not law. A regulator that lacks jurisdiction over an AI harm cannot conjure it from a white paper — and no regulator owns general-purpose model providers at all.
What the UK did build was frontier-model capacity. The Frontier AI Taskforce (April 2023) became the AI Safety Institute (announced at the Bletchley Park summit, November 2023) — the first state body dedicated to evaluating frontier models, with pre-release testing arrangements with Anthropic, Google DeepMind and OpenAI and an open-source evaluation platform, Inspect, that other governments now use. In February 2025 it was renamed the AI Security Institute: same evaluators, new framing — national security, cyber misuse and bio risks in, societal-impact language out. Hold onto that rename; the capstone module reads it as a data point about the whole 2025 mood shift.
Meanwhile the promised frontier AI bill — a manifesto commitment to make frontier labs’ safety commitments legally binding — kept slipping. The January 2025 AI Opportunities Action Plan completed the pivot from safety to growth: compute investment, AI growth zones, public-sector adoption. Adjacent instruments filled some gaps: the Data (Use and Access) Act 2025 reworked parts of UK data law, and a bruising consultation on copyright and text-and-data mining for AI training ran into fierce resistance from the creative industries. The UK signed the Council of Europe Framework Convention — accepting treaty-level AI duties while declining domestic ones — and then, with the US, refused to sign the Paris summit declaration in February 2025.
Key terms: soft law, AI safety institute, Council of Europe Framework Convention on AI, regulatory sandbox, algorithmic transparency recording standard
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.