How the UK regulates AI
UK pro-innovation principles and Data (Use and Access) Act 2025
- Status
- In force
- Binding
- No
- Object analysed
- AI system
- Requirements
- 6
- Next milestone
- 2027
In short
No horizontal AI law: 5 principles applied by sector regulators (ICO, FCA, CMA…). The DUAA 2025 relaxes the rules on automated decisions while keeping safeguards.
Steps to compliance
- Inventory your AI systemsThis framework does not classify systems: its principles apply to the whole organisation.
- Determine your roleDuties vary by role: Organisation.
- Apply the 6 requirementsThey focus on: Explanation & redress, Accuracy & robustness, Cybersecurity and Transparency & notice.
- Prove it with checks9 checks to document, 9 of which also serve PL 2338, AI Act and NIST AI RMF.
- Track the deadlinesNext milestone: 2027, Frontier AI bill (potential).
Scope and penalties
- Kind
- Principles
- Scope
- Any organisation, through sector regulators.
- Territorial reach
- United Kingdom.
- Penalties
- Depends on the sector regulator; UK GDPR up to £17.5M or 4%.
- Jurisdiction
- United Kingdom
Timeline
Qualifying a system
Classification axes and possible verdicts
No classification: a principles framework applied to the whole organisation.
Requirements
6 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| UK-01 | Principle 1 | Safety, security and robustness | ||
| UK-02 | Principle 2 | Appropriate transparency and explainability | ||
| UK-03 | Principle 3 | Fairness | ||
| UK-04 | Principle 4 | Accountability and governance | ||
| UK-05 | Principle 5 | Contestability and redress | ||
| UK-06 | UK GDPR Art. 22A-22D | Safeguards on significant automated decisions |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| VER-009-02 | Accuracy and robustness verified and documented | System | ||
| VER-009-03 | Cybersecurity of the AI system verified | System | ||
| VER-033-D-02 | System explanation capability verified | System | ||
| CHK-TRANSPARENCY | Transparency and accountability risks are examined and documented | System | ||
| CHK-BIAS | Fairness and bias are evaluated and results documented | System | ||
| CHK-ROLES-CLARIFIED | Roles, responsibilities and delegated authorities are documented and clear to relevant stakeholders | Organisation | ||
| CHK-BR-CONTEST | Procedure to contest a decision and obtain human review published | Organisation | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) | System | ||
| VER-033-D-01 | Decision explanation procedure documented | Organisation |
Themes covered
Frequently asked questions
Who is in scope of UK principles?
Any organisation, through sector regulators. United Kingdom.
What penalties does UK principles carry?
Depends on the sector regulator; UK GDPR up to £17.5M or 4%.
When do the UK principles obligations apply?
Jan 13, 2025: AI Opportunities Action Plan; Jun 19, 2025: Data (Use and Access) Act 2025; 2027: Frontier AI bill.
Is UK principles binding?
No. Kind: principles. Status: in force.
How does UK principles relate to other regulations?
The same checks serve several texts. Shared checks: PL 2338 (6), AI Act (5) and NIST AI RMF (5).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.