AI and automation 8 min read
Governing enterprise AI without a UK AI Act
Britain still has no AI statute, so a UK firm's obligations are the sum of existing regulators plus a European law that reaches across the Channel anyway.
Asked in December 2025 whether an AI bill was coming, the Secretary of State for Science, Innovation and Technology told the Commons committee that she was thinking about it more in terms of specific areas where we may need to act rather than a big all-encompassing Bill. The House of Commons Library records that exchange in its briefing of 10 June 2026, alongside the flat statement that the United Kingdom has no AI-specific regulation or legislation covering AI as a technology, and that AI is instead regulated in the context in which it is used.
That is the whole design, and it has been consistent across two governments. A binding AI bill was signalled in a manifesto and a King’s Speech, then deferred, then reframed. The Library notes that legislation has not been forthcoming and that no consultation on regulating AI has been launched.
For a compliance function this is worse than either alternative. A statute would give you a scope test and a deadline. No regime at all would give you a clean risk appetite conversation. What Britain has instead is a distributed obligation: every existing regulator’s expectations, applied to whatever you have built, discovered one at a time.
The five principles are the closest thing to a spine
The government’s February 2024 response to its own white paper consultation restates the framework, and it remains the reference document. Five cross-sectoral principles for existing regulators to interpret and apply within their remits: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; contestability and redress.
The same document sets out the government’s position on legislating, and it is worth quoting because it explains the delay rather than excusing it. Ministers wrote that some mandatory measures would ultimately be required across all jurisdictions, that acting before the risks and mitigations were properly understood would harm the ability to benefit from progress, and that the government would legislate when it was confident that it was the right thing to do.
Two years on, that sentence is still operative. Firms should plan on the basis that it will remain operative for a while yet.
The practical use of the five principles is not compliance, because they impose nothing directly. It is structure. They are the vocabulary your regulator will use when it eventually asks, and an internal framework organised around them will map onto whatever sectoral guidance arrives without being rebuilt. That is a cheap piece of foresight.
Where the obligations are actually accumulating
Because there is no statute, the useful question is not what the law says but which regulators have moved, and the answer is: more of them than most compliance functions are tracking.
The February 2024 response records that the government asked a number of regulators to publish an update setting out their strategic approach to AI, and those updates were collated in May 2024. The Commons Library notes that the Medicines and Healthcare products Regulatory Agency consulted between December 2025 and February 2026 on the regulation of AI in healthcare. Government itself published an AI Playbook for the UK Government in February 2025 to give departments technical guidance on using AI safely.
Read as a set, those are not five principles being interpreted consistently. They are separate bodies producing separate expectations at separate times, which is the criticism made of the model by people who are otherwise sympathetic to it. The Commons Science, Innovation and Technology Committee called reliance on existing regulators a sensible starting point while pressing for a more developed central coordinating function, and others have described the resulting picture as complex and fragmented, with a risk of uneven coverage.
For an enterprise operating across sectors, and most large ones do, fragmentation is the operative fact. A group with a bank, an insurer, a health division and a consumer business is not governed by one AI regime. It is governed by four supervisory relationships, each maturing at its own pace, and a group-level framework that cannot flex to all four will be quietly ignored by at least two of them.
There is also political weather to plan for. Polling cited by the Library from the UK AI Compass study, based on surveys in November and December 2025, found that 85% agreed that the country needs strong laws to force companies to make AI safe and secure, and that voluntary guidelines are not enough. Public opinion of that strength does not usually leave a legislative gap open indefinitely. An enterprise framework built on the assumption that nothing binding is coming is making a bet against both the polling and the government’s own stated intention to legislate eventually.
The European law that applies to you anyway
Any account of British AI governance that stops at the Channel is incomplete. The EU AI Act entered into force on 1 August 2024, with many provisions applying from 2 August 2026, and it is a horizontal instrument. The Commons Library summarises the reach precisely: the act applies to AI systems placed on the market or used in the EU regardless of where the provider or the system is based, and it also covers systems outside the EU, including those in the UK, where the output produced by the system is used in the EU.
Read that against a normal British enterprise. A model that scores applications in London and returns a decision acted on in Dublin. A shared services centre in Manchester generating output consumed by a group subsidiary in Amsterdam. A SaaS product built in Britain and sold to European customers. Each of those is a plausible route into scope, and none of them appears in the risk register as an AI matter, because they were filed under group structure.
The awkward consequence is that many UK organisations will end up running a European classification exercise as their primary AI governance activity, not because Parliament asked them to, but because it is the only jurisdiction that has issued a test they can apply.
What the regulated sector already reveals about accountability
Financial services is the one part of the British economy where somebody has counted. The Bank of England and the FCA’s 2024 survey found that 84% of firms reported having an accountable person for their AI framework, and that 72% said executive leadership were accountable for AI use cases. Encouraging, until the next clause: accountability is often split, with most firms reporting three or more accountable persons or bodies.
Three accountable parties is a governance arrangement that has not yet been tested. It works while nothing goes wrong.
The same survey found that 46% of firms reported only partial understanding of the AI technologies they use, against 34% claiming complete understanding, and attributed the gap largely to third-party models. It also identified the largest perceived regulatory constraint on AI use, and it is not an AI rule at all: data protection and privacy, followed by resilience, cybersecurity and third-party rules, and the Consumer Duty.
That is the UK approach working exactly as designed. The binding constraints on enterprise AI in Britain today are data protection law, operational resilience requirements, third-party risk rules and sector conduct duties. All four predate the current wave of technology. All four already have enforcement histories. A governance programme that starts with an AI ethics framework and gets to those in year two has the order backwards.
The public sector has the one instrument the private sector lacks
The Algorithmic Transparency Recording Standard requires central government to publish a record of the algorithmic tools it uses. Read the scope carefully, because it is narrower than the register’s contents suggest. The mandate covers ministerial and non-ministerial departments, plus arm’s length bodies that provide public or frontline services or routinely interact with the general public. Across the broader public sector the standard is recommended rather than required, so the councils, police forces and devolved bodies among the register’s 141 entries filed voluntarily. Which is the more interesting fact about them.
Its value is not the transparency, useful though that is. It is the discipline of the form. To complete a record an organisation has to name the tool, name the owner, describe what it does in its own words, state its phase, and set out how it is overseen. The published entries show the effect: single-purpose tools, explicit phases from pre-deployment through to retired, and an accountable organisation attached to each one.
There is no equivalent obligation on private firms, and no realistic prospect of one soon. Which makes the standard a free template. An internal register built to the same fields, maintained with the same rigour and reviewed at the same cadence gives a board a defensible answer to the only question that will actually be asked after an incident, which is what did you know you were running.
The unit of governance is the decision, not the model
The temptation is to govern models, because models are countable and vendors will happily supply an inventory. It is the wrong object.
The National Cyber Security Centre put the alternative crisply in its May 2026 guidance on agentic systems. Software may perform the act, but the accountability for choosing to deploy it, for the permissions it holds, for the controls around it and for whatever follows stays with named human beings. The same guidance asks organisations to consider whether AI is really needed, or whether a process could be simplified, removed or automated in a lower-risk way.
That last clause is the most valuable governance instruction published in Britain this decade, and it costs nothing. A great many proposals that fail an AI risk assessment would have passed a process redesign.
So govern the decision. For every automated or assisted decision, record what it decides, who is affected, what the appeal route is, who owns it by name, and what evidence exists that it performs as described. That register is regulator-agnostic. It answers the ICO, a sectoral supervisor, a European classification exercise and a select committee with the same document, and it survives the arrival of a statute that has not been drafted yet.
Related reporting is filed under AI and automation. The operating economics underneath all of it appear in the desk’s work on intelligent automation and on what enterprise agents have actually put into production.
The British position is often described as light touch. It is not light. It is unwritten, which is a different thing, and considerably more work.
Sources
- House of Commons Library, AI regulation in the UK, briefing 10003, 10 June 2026 researchbriefings.files.parliament.uk
- DSIT, A pro-innovation approach to AI regulation, government response to consultation, February 2024 gov.uk
- Bank of England and FCA, Artificial intelligence in UK financial services 2024, 21 November 2024 bankofengland.co.uk
- GOV.UK, Algorithmic Transparency Recording Standard, published records gov.uk
- DSIT, ATRS mandatory scope and exemptions policy gov.uk
- NCSC, Thinking carefully before adopting agentic AI, 15 May 2026 ncsc.gov.uk