0%
HomeAboutSolutionsProjectsResearchIndustriesCareersInsightsContact
← Back to Blog

Community · Technical Insight

What Businesses Using AI, or About to, Must Know About UK AI Regulation

Type “UK AI Bill” into a search bar and you'll land on dozens of confident explainers, several of them wrong in the same specific way. Ask five small business owners what it requires and you'll get five different answers, and every one will be at least partly wrong, because there is no UK AI Bill in force, and none before Parliament with a realistic path to becoming one soon. The House of Commons Library's own briefing on AI regulation, last updated in July 2026, settles this plainly: government policy, stated as far back as February 2025, is that most AI systems get regulated at the point of use by existing expert regulators, not by a new law built around AI as its own category.

None of that means you're off the hook. It means the obligations that do apply to your AI tools are scattered across law you're probably already meant to be following, enforced by whichever regulator already has jurisdiction over your sector. Get this wrong in either direction, assume a law exists that doesn't, or assume nothing applies because no dedicated law exists, and you end up in the same place: an ICO investigation that will probe what you were doing with people's data.

What is the UK AI Bill, and does it apply to you?

Short answer: not yet, and not directly. There is a real bill in Parliament with “artificial intelligence” in its title, the Artificial Intelligence (Regulation) Bill, introduced in the House of Lords by Lord Holmes of Richmond. It's a private member's bill rather than a government bill, which matters, because private member's bills rarely become law without government backing. As of its most recent update it has only completed its first reading, with second reading and committee scrutiny still ahead of it. Treating it as a compliance deadline would be premature. Treating it as a signal of where regulation is probably heading is fair enough.

The practical position right now, confirmed by government's own policy statement and repeated in the House of Commons Library's briefing on AI regulation, is that AI gets regulated the way most things do in the UK: sector by sector, through whichever regulator already has jurisdiction over what your business does. The Information Commissioner's Office, the ICO, covers how AI tools handle personal data. The Financial Conduct Authority covers AI used in lending, insurance or financial advice. Ofcom covers AI embedded in telecoms and online platforms. The Department for Science, Innovation and Technology, DSIT, writes policy and coordinates across those regulators, but it doesn't itself enforce anything against a small business using an AI copilot to draft emails.

Enterprise AI risk versus everyday SaaS tool use

Most of what gets written about AI regulation is aimed at the handful of companies building frontier AI models, the ones with the resources to run their own risk assessments and legal teams. If your business builds its own AI model from scratch, or fine-tunes one on customer data for a paid product, you sit much closer to that end of the risk spectrum and the stakes are genuinely higher. But that isn't most small businesses. Most small businesses encounter AI as a feature already switched on inside tools they already pay for: an AI copilot in the CRM, an email drafting assistant, automated categorisation in the accounting software.

Even at that end of the spectrum, real obligations exist, because of what the AI touches: personal data. The Data (Use and Access) Act 2025 introduced a revised framework for automated decision-making, ADM, that took effect in February 2026. In plain terms, if a system makes a significant decision about a specific person largely on its own, whether to approve them for something, flag them as a risk, or reject an application, the business behind it has to tell that person, let them ask a human to review it, and be able to explain how the decision was reached. As legal analysis of the February and June 2026 changes points out, this is one of the areas where small businesses are most likely to be caught out without realising, because the AI feature making the decision usually came bundled into software they bought for something else entirely.

What the ICO expects once AI enters the picture

If you want the closest thing the UK has to a working AI rulebook for personal data, it isn't a bill, it's the ICO's own guidance on AI and data protection, and it's more substantial than most businesses assume. It sets out what accountability looks like for an AI system, including when a formal Data Protection Impact Assessment is expected before deployment, not after. It has a standalone chapter on transparency as it applies specifically to AI, on top of the general transparency principle. And it goes well beyond the old assumption that “accurate” just means the underlying data is correct, spelling out that statistical accuracy, meaning how reliably a model's outputs hold up in practice, matters just as much for fairness.

Fairness gets the most detailed treatment of all. The guidance draws a real distinction between fairness, algorithmic fairness, bias and discrimination, terms that get used interchangeably in most boardroom conversations but mean quite different things to a regulator, and it covers the practical trade-offs involved in mitigating bias in a live system rather than pretending the trade-offs don't exist. It also spells out the safeguards expected under UK GDPR's Article 22 wherever a system makes decisions about people largely on its own, the same automated decision-making protections that sit behind the Data (Use and Access) Act 2025 changes discussed above. None of this is optional reading for a business shipping its own AI feature. For a business simply using someone else's AI tool, it's still the clearest single answer to “what would the ICO actually check.”

Financial services already has its own AI playbook

If your business sits anywhere near lending, insurance, payments or financial advice, the FCA isn't waiting for a UK AI Bill either. Its position, set out plainly on its own AI in financial services pages, is to apply its existing rulebook to AI use cases rather than write a parallel set of AI-specific rules, and it's built real infrastructure around that approach faster than most regulators internationally. The AI Lab, running since 2024, lets firms test AI solutions in a supervised environment. AI Live Testing, launched in May 2025 alongside a Supercharged Sandbox and an AI Consortium, goes further, letting firms trial AI systems under real-world conditions with the regulator watching directly rather than reviewing after the fact.

The adoption numbers behind that infrastructure are worth knowing too: the FCA's own research found 75% of firms have already adopted some form of AI, and 84% have a named individual accountable for their AI approach specifically, which tells you where the regulatory bar is quietly settling even without new legislation. The FCA is also running the Mills Review, looking at how AI reshapes retail financial services over the longer term, which is the closest thing to a signal of where firm-facing AI rules might eventually tighten. If you're a fintech, a lender, or anyone touching regulated financial advice, that's the regulator to watch, not Parliament.

Five things worth doing this week, not after a regulator asks

1. Audit the AI features you're already using: list every tool with an AI feature switched on, your CRM, your helpdesk, your accounting software, your email client, not just tools you deliberately went looking for.
2. Work out which ones make decisions about people: for each one, ask whether it makes, or meaningfully influences, a decision about a specific customer or employee, credit, pricing, hiring, risk flags. That's the trigger for automated decision-making obligations under UK GDPR.
3. Write a short internal AI use policy: one page is enough for most small firms: which tools are approved, what data can and can't go into them, and who signs off before a new one is adopted.
4. Check your AI vendors' data processing terms: confirm where the vendor processes your data, whether it's used to train their models, and whether that's disclosed plainly rather than buried in a long terms-of-service update.
5. Check EU exposure separately: if you sell into the EU at all, the EU AI Act's high-risk compliance obligations are a distinct regime, already in force for high-risk categories like credit scoring, hiring and biometric identification, and worth checking against directly rather than assuming UK compliance covers it.

Low-cost compliance without an expensive legal team

None of the steps above require hiring outside counsel. A one-page AI use policy, a spreadsheet listing your tools and what they touch, and a documented process for the rare case where a human needs to review an automated decision cover the great majority of what a small business is expected to demonstrate if the ICO ever asks. The expensive version of this problem isn't the compliance work itself. It's not having done any of it when something goes wrong and having to reconstruct the whole picture under pressure.

Avoid the traps: common errors small firms make with customer data

The mistakes we see most often aren't exotic. Feeding customer data into a free public AI tool without checking what happens to it afterward. Using an AI tool's output to make a real decision about a real customer, a credit limit, a rejected application, without anyone ever reviewing it or being able to explain why. And assuming a tool's default privacy settings are the safe ones, when in a lot of cases the default is the setting that shares the most, not the least.

Frequently asked questions

Is there a UK AI Act?
Not yet. There's a private member's bill in the House of Lords that touches AI regulation, but it hasn't progressed past its first reading, and it isn't law. AI is currently regulated through existing regulators and existing law, principally UK GDPR.

What happens if an AI tool I use turns out not to comply with anything?
You're still responsible for how your business uses personal data, regardless of whether the tool itself was built compliantly. That's exactly why checking a vendor's data processing terms before adopting a tool matters more than waiting for a dedicated AI law to tell you what to check.

Do I need to worry about the EU AI Act if I only sell in the UK?
If you have no EU customers, users, or data subjects at all, the EU AI Act doesn't apply to you directly. It's worth confirming that's true rather than assumed, particularly if you sell through a marketplace or platform with EU reach you might not think about day to day.

The businesses that get caught out aren't the reckless ones

In our experience, it's rarely the business deliberately cutting corners that ends up explaining itself to the ICO. It's the one that adopted a helpful AI feature eighteen months ago, never revisited what it does, and simply forgot it was there by the time it made a decision worth questioning. Phexara treats AI governance as an engineering discipline built in from the first sprint, not a policy note written after a product's already shipped, precisely because that's the nature of the failure mode that shows up most often in practice.Talk to us about your AI governance approach, or see how we build oversight into AI features from day one on our AI governance and security solutions page.

Want to talk about how this applies to your organisation?

Contact Us