The situation: There is no single UK AI Act. But five overlapping regulatory regimes already govern how UK businesses can use AI — and each of the major regulators updated their AI guidance in 2025 or 2026. The government has confirmed a sector-led approach, meaning the ICO, CMA, Ofcom, FCA, and sector regulators each handle AI in their own domain. The minimum viable compliance position across all of them is the same: a basic AI register.

What each regulator has said in 2026

ICO (Information Commissioner's Office): Published an updated AI guidance document in 2026 building on its 2023 and 2024 releases. Covers data protection obligations when training, deploying, and using AI — particularly around lawful basis for processing, transparency with individuals whose data is used by AI, and accountability requirements. Key update: AI-generated outputs that affect individuals (customer decisions, profiling, scoring) require a lawful basis and must be explainable on request.

FCA (Financial Conduct Authority): Published a 2026 AI update setting expectations on AI risk governance, board-level ownership, AI risk appetite, model risk management, explainability, bias testing, and operational resilience. Directly relevant to any business operating in regulated financial services — insurance, credit, lending, investment. The FCA expects AI to be treated as a material operational risk, not a productivity tool.

CMA (Competition and Markets Authority): Ongoing foundation models market study. Key concern: AI platforms creating structural dependency that locks businesses into single-vendor relationships. No new guidance published in July 2026, but the study is active and findings are expected in late 2026.

Ofcom: AI-in-media guidance expected Q3 2026. Primarily relevant to media businesses, but the underlying principles — AI disclosure, human oversight of automated decisions, audience accountability — will influence cross-sector expectations.

UK Government (cross-sector principles): The government confirmed the sector-led approach in 2025 and reaffirmed it in 2026. Language shifted from "AI safety" to "AI security and growth" — a signal that the regulatory focus is on enabling adoption while managing risks, not creating a blanket AI Act.

The five overlapping regimes that already apply

For a typical UK service business using AI tools, the relevant regimes are:

  • UK GDPR / Data Protection Act 2018: Applies to any AI tool that processes personal data (customer names, contact details, behaviour data). Requires lawful basis, data minimisation, transparency.
  • FCA Consumer Duty: If you provide regulated financial products or refer customers to them, the Consumer Duty's outcome-based obligations extend to AI-assisted decisions.
  • EU AI Act (extraterritorial): Applies if you sell to EU customers or use high-risk AI systems affecting people in the EU. See today's fourth story for the detailed checklist.
  • UK cross-sector AI principles: Voluntary now, but likely to harden into enforceable guidance within 18 months of the Geneva outcomes.
  • Sector-specific rules: Healthcare, financial services, education, and law enforcement each have additional AI requirements from their sector regulators.

The two-hour AI register

Every current UK regulatory update — ICO, FCA, CMA, and the emerging cross-sector principles — asks for the same core documentation: a record of what AI you use, what it does, and who is accountable. This is the AI register. It is not a legal requirement today, but it is the minimum position that satisfies the spirit of all five regimes.

Here is the template. One row per AI tool. Complete in a spreadsheet or document:

AI ToolWhat it doesData it touchesDecisions it informsWho reviews
Claude / ChatGPTDrafts customer emails, quotes, reportsCustomer names, job detailsCommunication contentGrant (manual review)
CRM / GHL AIScores leads, tags contacts, routes enquiriesContact data, conversation historyLead prioritisationGrant (weekly)
Scheduling AISuggests appointment times, sends remindersCustomer availability, job historyBooking decisionsGrant (auto-approved)
Review AIDrafts review request messagesCustomer name, job completion dateReview request timing and textGrant (spot check)

Add as many rows as you need. The goal is completeness: every AI tool that touches customer data or informs a business decision should be on the register. Review it quarterly. Update when you add new tools.

The two-hour action

Hour 1: List every AI tool you pay for or use regularly. Open a spreadsheet. Write the name of each tool in column A.
30 minutes: For each tool, fill in what it does, what data it uses, and what decisions it informs. Use the template columns above.
30 minutes: Assign a named reviewer for each tool — the person in your business responsible for checking that AI outputs are accurate and appropriate. For sole traders, this is you.
Done. Save as "AI Register — [your business name] — [date]". Review every quarter when you review your other business compliance documents.
Next step: Confirm that every AI vendor on your register has a Data Processing Agreement covering how you use their tool. Most major vendors (Anthropic, Google, OpenAI, Microsoft) offer these as standard — look in their trust/legal pages.