The situation: There is no single UK AI Act. But five overlapping regulatory regimes already govern how UK businesses can use AI — and each of the major regulators updated their AI guidance in 2025 or 2026. The government has confirmed a sector-led approach, meaning the ICO, CMA, Ofcom, FCA, and sector regulators each handle AI in their own domain. The minimum viable compliance position across all of them is the same: a basic AI register.
What each regulator has said in 2026
ICO (Information Commissioner's Office): Published an updated AI guidance document in 2026 building on its 2023 and 2024 releases. Covers data protection obligations when training, deploying, and using AI — particularly around lawful basis for processing, transparency with individuals whose data is used by AI, and accountability requirements. Key update: AI-generated outputs that affect individuals (customer decisions, profiling, scoring) require a lawful basis and must be explainable on request.
FCA (Financial Conduct Authority): Published a 2026 AI update setting expectations on AI risk governance, board-level ownership, AI risk appetite, model risk management, explainability, bias testing, and operational resilience. Directly relevant to any business operating in regulated financial services — insurance, credit, lending, investment. The FCA expects AI to be treated as a material operational risk, not a productivity tool.
CMA (Competition and Markets Authority): Ongoing foundation models market study. Key concern: AI platforms creating structural dependency that locks businesses into single-vendor relationships. No new guidance published in July 2026, but the study is active and findings are expected in late 2026.
Ofcom: AI-in-media guidance expected Q3 2026. Primarily relevant to media businesses, but the underlying principles — AI disclosure, human oversight of automated decisions, audience accountability — will influence cross-sector expectations.
UK Government (cross-sector principles): The government confirmed the sector-led approach in 2025 and reaffirmed it in 2026. Language shifted from "AI safety" to "AI security and growth" — a signal that the regulatory focus is on enabling adoption while managing risks, not creating a blanket AI Act.
The five overlapping regimes that already apply
For a typical UK service business using AI tools, the relevant regimes are:
- UK GDPR / Data Protection Act 2018: Applies to any AI tool that processes personal data (customer names, contact details, behaviour data). Requires lawful basis, data minimisation, transparency.
- FCA Consumer Duty: If you provide regulated financial products or refer customers to them, the Consumer Duty's outcome-based obligations extend to AI-assisted decisions.
- EU AI Act (extraterritorial): Applies if you sell to EU customers or use high-risk AI systems affecting people in the EU. See today's fourth story for the detailed checklist.
- UK cross-sector AI principles: Voluntary now, but likely to harden into enforceable guidance within 18 months of the Geneva outcomes.
- Sector-specific rules: Healthcare, financial services, education, and law enforcement each have additional AI requirements from their sector regulators.
The two-hour AI register
Every current UK regulatory update — ICO, FCA, CMA, and the emerging cross-sector principles — asks for the same core documentation: a record of what AI you use, what it does, and who is accountable. This is the AI register. It is not a legal requirement today, but it is the minimum position that satisfies the spirit of all five regimes.
Here is the template. One row per AI tool. Complete in a spreadsheet or document:
| AI Tool | What it does | Data it touches | Decisions it informs | Who reviews |
|---|---|---|---|---|
| Claude / ChatGPT | Drafts customer emails, quotes, reports | Customer names, job details | Communication content | Grant (manual review) |
| CRM / GHL AI | Scores leads, tags contacts, routes enquiries | Contact data, conversation history | Lead prioritisation | Grant (weekly) |
| Scheduling AI | Suggests appointment times, sends reminders | Customer availability, job history | Booking decisions | Grant (auto-approved) |
| Review AI | Drafts review request messages | Customer name, job completion date | Review request timing and text | Grant (spot check) |
Add as many rows as you need. The goal is completeness: every AI tool that touches customer data or informs a business decision should be on the register. Review it quarterly. Update when you add new tools.
The two-hour action
Hour 1: List every AI tool you pay for or use regularly. Open a spreadsheet. Write the name of each tool in column A.
30 minutes: For each tool, fill in what it does, what data it uses, and what decisions it informs. Use the template columns above.
30 minutes: Assign a named reviewer for each tool — the person in your business responsible for checking that AI outputs are accurate and appropriate. For sole traders, this is you.
Done. Save as "AI Register — [your business name] — [date]". Review every quarter when you review your other business compliance documents.
Next step: Confirm that every AI vendor on your register has a Data Processing Agreement covering how you use their tool. Most major vendors (Anthropic, Google, OpenAI, Microsoft) offer these as standard — look in their trust/legal pages.
