Britain’s AI policy is moving quickly but its legislation is not. The UK still relies on existing laws, specialist regulators and consultations to determine how AI should be used.
The government presents this approach as flexible, proportionate and innovation-friendly. In practice, however, the absence of a common statutory foundation is turning flexibility into fragmentation. Businesses must interpret overlapping rules, navigate several regulatory bodies and absorb the legal, compliance and administrative costs created by uncertainty. The result is a system designed to encourage innovation, but one in which businesses are increasingly carrying the cost of regulatory delay.
However, this may be starting to change. Andy Burnham has appointed Kanishka Narayan as Minister for Artificial Intelligence, with the right to attend Cabinet. Simultaneously, his government has established an AI Taskforce and proposed regulatory sandboxes through the AI Growth Lab, led by Lord Patrick Vallance; an already familiar face from Britain’s COVID-19 vaccine rollout.
One technology, multiple rulebooks
The UK does have rules governing artificial intelligence, but they are spread across several existing regulators rather than brought together under one dedicated AI law, meaning that the rules applying to an AI system depend largely on the sector in which it is used and the type of risk it creates.
There are clear advantages to this sectoral approach, because the risks change depending on how the technology is used. A recruitment tool might unfairly filter out strong candidates, a medical system could lead to a wrong diagnosis and a mortgage model might reject someone without a clear explanation. Specialist regulators understand these industries and can often respond faster than Parliament as the technology develops.
The difficulty is not that regulators lack expertise, it is that there is no single set of basic rules applying across the whole economy. Businesses operating in several sectors may therefore have to follow different guidance, definitions and enforcement standards at the same time.
Large companies can employ lawyers, compliance specialists and public-affairs teams to monitor these changes. However, smaller businesses are less likely to have those resources. They may only become aware of a new regulatory expectation once it is already being applied in practice, leaving them to absorb the cost of legal advice, system changes and additional compliance work.
Brussels is already setting standards
The absence of a UK AI Act does not free British companies from regulation. The EU AI Act can still apply when a UK business sells an AI system into Europe or when its technology affects people within the bloc.
From December 2027, standalone high-risk AI systems will face requirements covering risk management, data quality, record-keeping, human oversight and cybersecurity. The most serious breaches can result in fines of up to €35 million or 7 per cent of global annual turnover. For many British companies, meeting EU standards will therefore be commercially unavoidable, regardless of how flexible the UK’s domestic approach appears.
A British alternative
A principles-based approach was proposed in Lord Holmes of Richmond’s Artificial Intelligence (Regulation) Bill. That Bill would have placed principles including safety, transparency, fairness, accountability and redress on a statutory footing. It also proposed an AI Authority to coordinate existing regulators and identify gaps in the regulatory system. However, it made no further progress after the 2023-24 parliamentary session ended, and therefore never became law. The current system relies too heavily on separate regulators, overlapping guidance and voluntary interpretation, leaving businesses without a clear legal baseline.
By establishing standardised, binding duties on transparency, accountability, risk assessment and human oversight, specialist regulators could then apply those duties within their own sectors, whether finance, healthcare or employment.
This is not an argument for copying the EU’s complex rulebook. Rather, it is an argument for replacing regulatory fragmentation with legal certainty.
Fragmented and divergent legislative requirements remain one of the greatest barriers to innovation. For UK businesses to harness the opportunities presented by AI, they need a clear, coherent and proportionate regulatory framework that provides certainty without stifling growth.
The appointment of the UK’s first dedicated AI Minister to attend Cabinet signals that AI is moving beyond the margins of technology policy and becoming a central government priority. As the EU’s regulatory framework takes effect and increasingly shapes the standards followed by British firms, pressure is growing for the UK to set out a credible approach of its own.
UK businesses should engage early, sharing evidence with ministers, officials and parliamentarians, contributing to consultations and building coalitions, to ensure that future legislation reflects commercial realities. For organisations seeking to shape this debate, now is the time to establish a clear policy position and ensure their experience is heard here in Westminster.