Key Takeaways
- UK businesses should prepare around the AI they actually use, not wait for one catch-all UK AI Act.
- Existing laws and regulators already matter, including data protection, consumer protection and sector-specific requirements.
- A UK organisation may also fall within the EU AI Act depending on where a system is supplied, deployed or used and what role the business plays.
- Start with an AI register, risk-tier every use case and assign a named business owner.
- Keep evidence: supplier checks, impact assessments, evaluation results, training, approvals, incidents and review dates.
The practical way for a UK business to prepare for AI regulation is to find every AI use, identify who and what it can affect, map the applicable rules, and put proportionate controls around the higher-risk work. Do not wait for a single piece of legislation with “AI” in its title. Data protection, consumer, equality, employment, intellectual-property, product and sector rules can apply to an AI-assisted process now.
The UK government continues to use a principles-based, regulator-led approach. Its five cross-sector principles are safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. They are useful headings for a readiness programme, but they do not replace legal duties.
This guide is general business information, not legal advice. High-impact employment, credit, healthcare, education, insurance, safety, biometric or regulated-sector uses need advice from the relevant legal, data-protection and sector specialists.
The UK Position in 2026
The government's initial guidance on implementing the UK's AI regulatory principles describes a principles-based framework applied through regulators' existing remits. It expressly says the principles do not supersede existing legislation.
For a small business, this means the relevant question is not simply “is there an AI law?” It is:
- Are we processing personal data?
- Are we communicating prices, terms or product information to consumers?
- Is AI influencing recruitment, performance, access or another important decision?
- Is the product safety-critical or regulated?
- Are we creating or using protected content?
- Do we serve people or place products in the EU?
- What did we promise customers and staff in contracts and notices?
The Data (Use and Access) Act 2025 changed parts of the UK data framework, and the ICO confirmed in June 2026 that all its data-protection provisions were in force. The ICO also says parts of its AI guidance are under review. Use the current guidance and record when it was checked rather than relying on a static checklist copied a year ago.
Do Not Ignore the EU AI Act
The EU AI Act can affect an organisation outside the EU. Scope depends on the business's role, where a system or model is placed on the market or used, and where its output has an effect. A UK supplier with EU customers should not assume Brexit removes the issue.
The European Commission's current AI Act page sets out a risk-based framework and the implementation timeline:
- the Act entered into force on 1 August 2024;
- prohibited-practice and AI-literacy provisions applied from 2 February 2025;
- governance and general-purpose AI model obligations applied from 2 August 2025;
- transparency rules apply from 2 August 2026;
- following the 2026 political agreement on simplification, rules for certain high-risk areas are scheduled for 2 December 2027;
- rules for high-risk AI embedded in specified regulated products are scheduled for 2 August 2028.
The timetable and supporting guidance have changed, which is exactly why businesses need an owner and review date. Ask a qualified adviser to assess whether the organisation is a provider, deployer, importer, distributor or another actor, and whether a particular use falls into a prohibited, high-risk, transparency or lower-risk category.
The Readiness Checklist
1. Build an AI Register
Create one record for every AI-enabled tool and process, including features inside software already in use. Staff may be using writing assistants, meeting transcription, CRM scoring, design generation, support agents, recruitment screening and spreadsheet copilots without calling them an AI system.
For each entry record:
- tool and supplier;
- business purpose;
- named owner;
- users and affected people;
- input and output data;
- personal or sensitive data;
- decisions or actions influenced;
- connected systems and permissions;
- model or service version where known;
- country and sector reach;
- contract and renewal date;
- current risk tier and controls;
- last and next review.
Include unapproved use found during the exercise. The first response should be proportionate: contain risky sharing, understand why the tool was useful and provide a safer route. A ban nobody can follow tends to create more hidden use.
2. Assign the Business Role and Owner
Someone must be accountable for the outcome even when a supplier built the model. Name a senior business owner, operational owner and technical or supplier contact. In a small company one person may hold more than one role, but the responsibilities still need to be explicit.
Record whether the business is buying and deploying a tool, building a system, integrating a model into a service, or selling an AI product. Legal duties, evidence and customer information can differ by role.
The Competition and Markets Authority makes accountability clear in its 2026 guidance on using AI agents: if an agent used by a business does something illegal, the business is responsible. “The vendor's AI did it” is not a customer remedy.
3. Tier the Risk From the Use, Not the Brand
The same model can draft an internal agenda or influence whether someone gets a job. Assess the complete use context.
A simple internal tier can consider:
- impact on rights, money, work, safety or access to a service;
- personal, special-category, confidential or children's data;
- scale and frequency;
- whether a person knows AI is involved;
- ability to understand, challenge and correct the result;
- autonomy and permanence of the action;
- bias, inaccuracy and security consequences;
- vulnerable or dependent people;
- sector and geographic requirements.
Low-risk assistance may use lightweight approval and periodic sampling. High-impact decisions need specialist review, stronger evaluation, meaningful human oversight, documented explanation and a reliable contest route. Some uses may be inappropriate regardless of technical controls.
4. Map the Rules and Promises
Create a short obligations map for every medium- or high-risk use. It should cover applicable law, regulator guidance, contracts, professional duties, insurance conditions and internal policies.
The UK's five AI principles are a useful prompt:
| Principle | Evidence a business might keep |
|---|---|
| Safety, security and robustness | Threat assessment, failure tests, permissions, recovery plan, monitoring and incident records |
| Transparency and explainability | Customer or staff notice, source information, explanation method and known limitations |
| Fairness | Impact assessment, representative test cases, outcome review and correction process |
| Accountability and governance | Named owner, approval record, supplier contract, policy and review minutes |
| Contestability and redress | Human contact route, appeal process, correction time and remedy records |
Do not treat the table as a legal compliance certificate. It is an evidence structure to take into a proper review.
5. Complete the Data-Protection Work
Where personal data is involved, document purpose, lawful basis, fairness, necessity, minimisation, accuracy, retention, security and rights. Identify controller and processor roles and any international transfers.
The ICO's AI and data-protection guidance covers accountability, transparency, lawfulness, fairness, security, data minimisation and individual rights. Screen for a data-protection impact assessment before processing begins. A DPIA is required where processing is likely to result in high risk, and it should shape the design rather than justify a decision already made.
Ask whether the use genuinely needs personal data. Evaluation can often begin with synthetic, anonymised or carefully minimised information. Our guide to protecting business data in AI tools provides a practical supplier and staff checklist.
6. Check Suppliers and Contracts
A security page and a familiar logo are not enough. Request information proportionate to the risk:
- service and model providers;
- data locations and transfers;
- use of customer data for model training;
- retention and deletion;
- sub-processors;
- access controls and logs;
- security testing and incident notification;
- service changes and model updates;
- accuracy or performance evidence for the use case;
- audit or assurance reports;
- export and termination support;
- liability, intellectual property and support responsibilities.
The UK AI Cyber Security Code of Practice recommends supply-chain due diligence, limited permissions, documented models, data and prompts, testing, monitoring and secure end-of-life processes. Use those prompts in procurement even when the supplier is larger than your business.
Record gaps and the decision to accept, mitigate or reject them. A contract review should involve appropriate legal and security expertise for important systems.
7. Design Meaningful Human Oversight
A human clicking “approve” without time, information or authority is not meaningful oversight. Define:
- what the reviewer must check;
- which sources and context they can see;
- when the system must stop or escalate;
- what authority the reviewer has to change the result;
- how disagreements are recorded;
- workload and time available;
- competence and training required.
Avoid automation bias by showing uncertainty and known limitations. Sample approved results as well as rejected ones. If people almost always accept the output because reviewing it takes longer than doing the job, redesign the workflow.
8. Test the Real Failure Modes
Evaluate on real tasks with appropriately controlled data. Include rare and difficult cases, not only an average example prepared for the demonstration.
Test:
- accuracy and completeness;
- unsupported or fabricated answers;
- biased or inconsistent outcomes;
- prompt injection and malicious files;
- unauthorised data retrieval or actions;
- broken integrations and stale knowledge;
- ability to stop, roll back and recover;
- handoff to a person;
- accessibility and understandable notices;
- performance after a supplier or model update.
Define the acceptable threshold and owner before seeing the results. Preserve the evaluation set, configuration, date and decision. This is part of E-E-A-T in practice: the organisation can show experience, expertise and trustworthy evidence rather than simply claim responsible AI.
9. Train Staff by Role
General awareness is useful, but staff also need task-specific rules. A marketer, developer, recruiter and support agent face different risks.
Training should cover approved tools, prohibited information, checking output, copyright and confidentiality, bias, security attacks, escalation, record keeping and how to report a mistake. Managers need to know their accountability. Technical staff need secure design and testing. Customer-facing staff need transparent language and a human remedy.
The EU AI Act's AI-literacy obligation has applied since February 2025 for organisations within scope. Even where it does not apply, competent users are a sensible control. Record attendance, material, role and refresh date.
Our AI policy template guide can establish the rules, but training and workflow controls are what make them real.
10. Monitor, Record and Retire
AI performance can change when data, prompts, integrations, models or policies change. Set measures and review frequency according to risk.
Keep:
- sampled outputs and evaluation results;
- user complaints and corrections;
- incidents and near misses;
- supplier and model changes;
- access and action logs;
- measures of different affected groups where appropriate and lawful;
- approval and review minutes;
- training records;
- retirement, export and deletion evidence.
Create a clear stop condition. If a support agent begins issuing wrong refunds or a scoring system produces an unexplained pattern, the team should know who can disable it and how work continues manually.
A 30-Day Preparation Plan
Week 1: Find and Own
Issue a short staff survey, review software lists and expenses, and create the AI register. Assign owners and contain any obvious unapproved sharing of sensitive data.
Week 2: Risk and Scope
Tier every use. Mark personal data, consumer actions, employment, EU reach and sector regulation. Seek specialist advice for the high-impact group.
Week 3: Evidence and Controls
Collect contracts, supplier information, notices, DPIAs, evaluation results and policies. Identify missing controls. Prioritise actions that reduce material harm, not cosmetic documentation.
Week 4: Train and Review
Approve or pause each use, train staff by role, test incident and shutdown routes, and set review dates. Report the high-risk items, decisions and gaps to leadership.
For organisations needing a coherent adoption plan, AI strategy consulting can connect the register, risk work and implementation roadmap. Technical controls can then be built through AI integration services rather than added after launch.
Frequently Asked Questions
Does the UK have one AI Act that every business must follow?
The UK approach is not one general law equivalent to the EU AI Act. Existing data protection, consumer, equality, employment, intellectual-property, product-safety and sector rules can already apply, supported by a principles-based government framework and regulator guidance. The exact obligations depend on the use and sector.
Does the EU AI Act apply to a UK business?
It can. A UK organisation may be in scope when it provides or deploys an AI system in the EU, places a system or model on the EU market, or where an AI system's output is used in the EU. The role, use case and current implementation timetable need specialist assessment.
What should a small business do first about AI regulation?
Create an AI register. Record every approved and discovered tool, its purpose, owner, data, supplier, users, affected people, decisions, integrations and current controls. You cannot assess or govern AI use that the business has not identified.
Do we need a data-protection impact assessment for every AI tool?
Not automatically. A DPIA is required where personal-data processing is likely to result in high risk, and it is a useful risk tool for many significant AI uses. Screen each use, record the decision and complete the assessment before high-risk processing begins.
Is an AI policy enough to make the business compliant?
No. A policy sets expectations, but the business also needs named owners, risk assessment, supplier checks, training, technical controls, human review, evidence, incident handling and regular monitoring. The documented rule and the real workflow must agree.
Build Evidence, Not an “AI Compliance” Folder
Regulatory readiness is not a folder called “AI compliance”. It is the ability to show what the business uses, why it uses it, who is responsible, what could go wrong, which rules apply and how the risks are tested and controlled.
Start with the register. Prioritise uses that affect people, money, rights, safety or sensitive data. Keep evidence and review the position as law, guidance and the technology change.
If you need help turning a list of tools into a practical governance and delivery plan, contact MattDarm. We can map the systems, build proportionate technical controls and work alongside your legal or data-protection advisers.




