AI rules for UK businesses in 2026: what applies when you build an AI system.
The UK has no AI Act, but it does have rules. Here’s what UK GDPR’s new automated-decision regime, the ICO, the FCA and the MHRA expect from an AI system, and what changes if you serve EU customers too.
The short answer for October 2026: the UK has no AI Act, and the May 2026 King’s Speech didn’t propose one. AI is regulated through existing law and the sector regulators. For a company building an AI system, four things matter most. The first is the new automated-decision rules in UK GDPR, which took effect on 5 February 2026. The second is the ICO, which is now writing a statutory code on AI. The third is your sector regulator: the FCA for financial services, the MHRA for health. And the EU AI Act applies to any part of your business that serves EU customers.
This guide covers what each one asks of the system you build. It’s a practical summary from a team that builds these systems, not legal advice.
No AI Act, but plenty of rules
The government’s approach is to let existing regulators apply their own rules to AI, rather than pass a single law. Its AI Opportunities Action Plan, launched in January 2025, focuses on adoption and infrastructure. A year on, the government reported 38 of its 50 actions met. For businesses, the practical effect is that the rules you already follow (data protection, equality, consumer protection and your sector’s regulations) apply to AI as they do to anything else. And the regulators are increasingly specific about how.
Adoption is moving quickly. The ONS’s business survey found that about 35% of UK businesses with ten or more employees used at least one AI technology in June 2026, up from about 12% in September 2023 (ONS).
Automated decisions: the rules changed in February 2026
The Data (Use and Access) Act 2025 replaced UK GDPR’s old Article 22 with new Articles 22A to 22D. They came into force on 5 February 2026 and apply to decisions made from that date. Two things changed:
- More room to automate. Organisations can now rely on legitimate interests for significant decisions made solely by automated means, as long as the decision doesn’t use special-category data such as health or ethnicity. Before, automated decisions of this kind were broadly restricted.
- Safeguards are required in return. People must be told about significant automated decisions about them. They must be able to make representations, to get a person to intervene, and to contest the decision.
Those safeguards are design requirements, not paperwork. A system that approves, declines, prices or prioritises people needs to record why it decided, show that reasoning to a reviewer, and offer a working route to a human. Building that in from the start is far cheaper than retrofitting it after a complaint.
The ICO: a statutory code on the way
The Information Commissioner’s Office is the main regulator for AI that uses personal data. Since May 2026 it has been required by law (SI 2026/425) to prepare a statutory code of practice on AI and automated decision-making, including children’s data. Its guidance pipeline for 2026:
- guidance on automated decision-making and profiling, consulted on until May 2026, with the final version due this winter;
- guidance on agentic AI, consulted on in September 2026, with the final version due this autumn.
Until those land, the ICO’s existing expectations hold. Do a data protection impact assessment for high-risk processing. Have a documented lawful basis. Be transparent with people, collect only the data you need, and be able to explain how the system reached an outcome.
Financial services: existing rules, applied to AI
The FCA says it does not plan to introduce extra regulations for AI. Instead, its existing regime applies. Under the Consumer Duty, an AI system has to deliver good outcomes for customers, including vulnerable ones. Under the Senior Managers and Certification Regime, a named senior person is accountable for it. For a lender, insurer or wealth firm, that means monitoring outcomes by customer group, keeping an audit trail of what the system did, and being able to show the regulator both.
Healthcare: where the MHRA draws the line
The MHRA confirmed in July 2026 that AI scribe and ambient voice tools used only to transcribe, summarise, draft letters or suggest codes for a clinician to review aren’t medical devices. Tools that support diagnosis or treatment decisions, or take automated action, are, and need the regulatory route that goes with that. The MHRA’s AI Airlock sandbox received £3.6m over three years in April 2026. A national commission on regulating AI in healthcare published its recommendations in September 2026, and the government’s response is still to come.
For a clinic or health-tech company, the boundary matters at the design stage. A system that drafts for a clinician to approve is a very different project, with a different timeline, from one that recommends treatment.
Serving EU customers too
If your system is used by people in the EU, the EU AI Act applies to that use, wherever your company is based. Its transparency rules for chatbots and generated content have applied since August 2026. Personal data can keep flowing between the UK and the EU: the European Commission renewed its UK adequacy decisions in December 2025, valid until December 2031. Many UK companies design to the stricter of the two regimes, so one system serves both markets.
What to build in from the start
| Build in | Why |
|---|---|
| A record of every decision and the data behind it | Explaining outcomes to people, the ICO or the FCA |
| A working route to a person | Article 22C safeguards; the Consumer Duty |
| Clear notices that AI is involved | UK GDPR transparency; EU Article 50 if you serve EU users |
| Data minimisation in prompts, retrieval and logs | UK GDPR; logs often hold more personal data than the system itself |
| Outcome monitoring by customer group | The Equality Act and the Consumer Duty |
| An evaluation set run before every release | Evidence that the system does what you claim (see evals before features) |
Questions UK businesses ask
Do we need to register our AI system with anyone?
Not in general. There’s no UK AI register for private companies. Sector rules still apply, such as medical device registration for health tools that qualify.
Can we use US model providers with UK personal data?
Yes, with the right transfer mechanism in place and a data protection impact assessment where the processing is high-risk. Check where each provider processes data and whether it offers UK or European hosting.
Does the Equality Act apply to AI decisions?
Yes. A decision doesn’t become exempt from discrimination law because software made it. Test outcomes across groups before launch and keep monitoring them after.
Modulus Labs AI builds AI agents, assistants and automation for UK and international companies, with decision records, human review and monitoring built in. Tell us what you’re building, and we’ll reply within one business day.