UKUnited KingdomIn forceUK principles

How the UK regulates AI

UK pro-innovation principles and Data (Use and Access) Act 2025

Status
In force
Binding
No
Object analysed
AI system
Requirements
6
Next milestone
2027

In short

No horizontal AI law: 5 principles applied by sector regulators (ICO, FCA, CMA…). The DUAA 2025 relaxes the rules on automated decisions while keeping safeguards.

Steps to compliance

  1. Inventory your AI systemsThis framework does not classify systems: its principles apply to the whole organisation.
  2. Determine your roleDuties vary by role: Organisation.
  3. Apply the 6 requirementsThey focus on: Explanation & redress, Accuracy & robustness, Cybersecurity and Transparency & notice.
  4. Prove it with checks9 checks to document, 9 of which also serve PL 2338, AI Act and NIST AI RMF.
  5. Track the deadlinesNext milestone: 2027, Frontier AI bill (potential).

Scope and penalties

Kind
Principles
Scope
Any organisation, through sector regulators.
Territorial reach
United Kingdom.
Penalties
Depends on the sector regulator; UK GDPR up to £17.5M or 4%.
Jurisdiction
United Kingdom

Timeline

Mar 29, 2023Pro-innovation white paper
Feb 6, 2024Government response
Jan 13, 2025AI Opportunities Action Plan
Jun 19, 2025Data (Use and Access) Act 2025
Release
2027Frontier AI billPotential
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

No classification: a principles framework applied to the whole organisation.

Requirements

6 requirements

CodeArticleRequirementApplies toChecks
UK-01Principle 1Safety, security and robustness
All
UK-02Principle 2Appropriate transparency and explainability
All
UK-03Principle 3Fairness
All
UK-04Principle 4Accountability and governance
All
UK-05Principle 5Contestability and redress
All
UK-06UK GDPR Art. 22A-22DSafeguards on significant automated decisions
All

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
VER-009-02Accuracy and robustness verified and documentedSystem
VER-009-03Cybersecurity of the AI system verifiedSystem
VER-033-D-02System explanation capability verifiedSystem
CHK-TRANSPARENCYTransparency and accountability risks are examined and documentedSystem
CHK-BIASFairness and bias are evaluated and results documentedSystem
CHK-ROLES-CLARIFIEDRoles, responsibilities and delegated authorities are documented and clear to relevant stakeholdersOrganisation
CHK-BR-CONTESTProcedure to contest a decision and obtain human review publishedOrganisation
VER-008-02System designed to allow human oversight (stop button, override)System
VER-033-D-01Decision explanation procedure documentedOrganisation

Themes covered

Frequently asked questions

Who is in scope of UK principles?

Any organisation, through sector regulators. United Kingdom.

What penalties does UK principles carry?

Depends on the sector regulator; UK GDPR up to £17.5M or 4%.

When do the UK principles obligations apply?

Jan 13, 2025: AI Opportunities Action Plan; Jun 19, 2025: Data (Use and Access) Act 2025; 2027: Frontier AI bill.

Is UK principles binding?

No. Kind: principles. Status: in force.

How does UK principles relate to other regulations?

The same checks serve several texts. Shared checks: PL 2338 (6), AI Act (5) and NIST AI RMF (5).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo