The UK has no single Artificial Intelligence Act. AI is regulated through the laws that already exist, applied by the regulators who already hold the relevant powers. That means data protection law, equality law, online safety law, consumer law, intellectual property law, criminal law and the ordinary law of negligence and contract all apply to AI, whether or not they mention it by name.
That position has held for three governments now, and it was confirmed again in the King's Speech on 13 May 2026, which contained no standalone AI Bill. What the UK does have instead is a growing layer of AI specific rules bolted onto existing statutes, a statutory code of practice on the way, and a set of regulators who have started to enforce.
Anyone who assumes the absence of an AI Act means the absence of legal risk has misread the situation entirely.
Key facts at a glance
| Question | Position as at August 2026 |
|---|---|
| Does the UK have an AI Act? | No. There is no comprehensive AI statute and no AI Bill currently before Parliament. |
| Which law bites hardest? | UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. |
| Who enforces? | Sector regulators: the ICO, Ofcom, the FCA, the CMA, the MHRA, the SRA and others. |
| Is training AI on copyright works lawful? | Unresolved. The Government dropped its proposed exception in March 2026 and the Getty appeal is pending. |
| Are sexual deepfakes illegal? | Yes. Creating or requesting them without consent has been a criminal offence since 6 February 2026. |
| Does the EU AI Act apply to UK firms? | Often yes, if you place AI on the EU market or your outputs affect people in the EU. |
Is there a UK AI Act?
No, and there is unlikely to be one soon.
The UK's approach rests on five cross sectoral principles first set out in the 2023 white paper and carried forward since: safety and robustness, appropriate transparency and explainability, fairness, accountability and governance, and contestability and redress. These are not legally binding in themselves. Regulators are expected to interpret and apply them inside their own domains.
The direction of travel since 2025 has been towards enabling adoption rather than restraining it. The AI Opportunities Action Plan of January 2025 shifted the emphasis for sector regulators away from detailed risk analysis and towards actively promoting AI innovation. In January 2026 the Technology Secretary wrote to 19 regulators asking each to publish a plan showing how it will enable safe AI innovation and to report annually on progress.
The main legislative vehicle is now the AI Growth Lab, announced in the DSIT Blueprint for AI regulation on 21 October 2025. This is a programme of licensed regulatory sandboxes in which specific rules can be temporarily relaxed or switched off for supervised pilots, with named target sectors including professional services, healthcare, transport and advanced manufacturing. The call for evidence closed on 2 January 2026. The Regulating for Growth Bill, announced in the May 2026 King's Speech, is intended to put cross economy sandbox powers on a statutory footing.
In early August 2026 the Growth Lab opened for applications, with legal services as the first sector and the Solicitors Regulation Authority, the Legal Services Board and the Council for Licensed Conveyancers attached as advisory regulators. Anyone considering applying should check the current position and deadlines on GOV.UK, because this programme is moving quickly.
The laws that already apply to AI in the UK
Data protection
This is where most AI compliance work actually happens.
The Data (Use and Access) Act 2025 made the single biggest change. Section 80 replaced Article 22 of the UK GDPR with new Articles 22A to 22D, which came into force on 5 February 2026. The old rule was a prohibition on solely automated decisions with legal or similarly significant effects, subject to narrow exceptions. The new framework is better understood as a right of challenge supported by safeguards. Solely automated decisions are lawful in a wider range of circumstances, provided the organisation gives the individual information about the decision, allows them to make representations, provides for human intervention and allows the decision to be contested. Special category data remains far more tightly restricted.
For many organisations this is a genuine liberalisation. It is also a trap, because the safeguards must be real, documented and capable of being evidenced.
A statutory code of practice on AI and automated decision making is on its way. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision Making) Regulations 2026, SI 2026/425, came into force on 12 May 2026 and place the Information Commissioner under a legal duty to prepare it. The code must include specific guidance on children's personal data. Once published, it is not optional background reading: courts and the ICO must take it into account in enforcement proceedings. In parallel, the ICO consulted on draft automated decision making guidance between 31 March and 29 May 2026, with final guidance expected during 2026 and the statutory code likely in 2027.
Equality law
The Equality Act 2010 applies to algorithmic outcomes exactly as it applies to human ones. If an AI shortlisting tool produces a disproportionate rejection rate for a protected group, the employer faces an indirect discrimination claim. "The model produced the shortlist" is not a defence, and neither is a vendor's marketing claim that a product is bias free. Liability sits with the organisation deploying the system.
Online safety
The Online Safety Act 2023 catches far more AI products than many providers expect. Generative AI services that allow users to share content with each other, that search multiple sites, or that can produce pornographic material can fall within scope, with duties to carry out illegal content risk assessments, to prevent users encountering priority illegal content and to apply age assurance where relevant.
The Crime and Policing Act 2026, which received Royal Assent on 29 April 2026, extends this further. It gives the Secretary of State powers to make regulations addressing illegal AI generated content and AI services, with a report on progress due by 31 December 2026 unless draft regulations are laid first.
Criminal law and deepfakes
Since 6 February 2026, section 138 of the Data (Use and Access) Act 2025 has amended the Sexual Offences Act 2003 to criminalise creating, or requesting the creation of, a purported intimate or sexual image of an adult without consent. The offence is committed even if the image is never produced and never shared. It captures digitally altered images as well as fully synthetic ones.
The Crime and Policing Act 2026 goes after the tools rather than just the users. Section 99 creates an offence of making, adapting, supplying or offering to supply a "purported intimate image generator", which covers so called nudification apps and services, and applies to corporate bodies as well as individuals. The Act also introduced deletion orders requiring removal of intimate images from online services.
Intellectual property
Copyright is the most contested area, and it is dealt with in full below.
Everything else
Contract, negligence, product liability, consumer protection, defamation, confidentiality and professional regulation all continue to apply. An AI system that gives negligent advice, a chatbot that makes a defamatory statement about a named individual, or a model that leaks confidential client material creates the same categories of liability that any other business failure would.
Who regulates AI in the UK?
There is no AI regulator. There are many regulators who regulate AI.
- Information Commissioner's Office: personal data, automated decision making, biometrics. Current priorities include automated decision making in recruitment and central government, foundation model development, and police live facial recognition.
- Ofcom: online safety, including generative AI services within scope of the Online Safety Act.
- Financial Conduct Authority: AI in financial services, including its AI live testing programme and a wider review of AI in retail financial services launched in 2026.
- Competition and Markets Authority: competition in foundation models and related markets.
- MHRA: AI as a medical device, including the AI Airlock sandbox.
- Solicitors Regulation Authority, Bar Standards Board and the judiciary: professional use of AI in legal services and the courts.
- Equality and Human Rights Commission: discriminatory outcomes and public sector equality duties.
If you operate in a regulated sector, your regulator's AI guidance is your rulebook, whatever Parliament does or does not pass.
AI and copyright: the fight that has not been settled
Getty Images v Stability AI
On 4 November 2025 the High Court handed down judgment in Getty Images (US) Inc and others v Stability AI Ltd [2025] EWHC 2863 (Ch), the first substantive UK ruling on copyright, trade marks and generative AI.
It answered less than everyone hoped. Getty accepted there was no evidence that training took place in the UK and abandoned its primary copyright and database right claims before closing submissions. What remained was a secondary infringement claim and a trade mark claim. Mrs Justice Joanna Smith held that an "article" under the Copyright, Designs and Patents Act 1988 can be intangible, and that making model weights available for download in the UK amounted to importation. But because the model weights did not themselves store or reproduce Getty's images, the model was not an "infringing copy", and the secondary infringement claim failed. Getty succeeded only narrowly on trade marks, in relation to watermark reproduction in historic versions of Stable Diffusion.
In December 2025 the judge granted Getty permission to appeal on the secondary infringement point, accepting that it raised a novel question of statutory construction with real prospects of success and far reaching implications, not only for AI models but for intangible articles such as software generally. That appeal is the single most important pending development in UK AI law.
The Government's March 2026 report
The Data (Use and Access) Act 2025 required the Government to publish a report and economic impact assessment on copyright and AI. Both were laid before Parliament on 18 March 2026.
The headline outcome was a retreat. The Government confirmed that a broad text and data mining exception with a rights holder opt out is no longer its preferred option. There will be no immediate reform of UK copyright law, no new regulator for AI transparency, and the courts will continue to apply existing law. The Government identified four areas for the next phase of work: digital replicas, labelling of AI generated content, creator control and transparency, and licensing.
The report also indicated that copyright protection for computer generated works under section 9(3) of the Copyright, Designs and Patents Act 1988 is likely to be removed, though that decision has been deferred. A consultation on deepfake harms, including the possible introduction of a personality right, was signalled for summer 2026.
The House of Lords Communications and Digital Committee had published a sharply critical report on 6 March 2026, concluding that the problem lies not with UK copyright law, which it described as an international gold standard, but with widespread unlicensed use and a lack of transparency by AI developers. The Government responded on 15 May 2026.
The practical position for now: if you are a rights holder, litigation and licensing are your routes, not legislation. If you are a developer, the absence of an exception means the absence of a safe harbour.
Where AI has already gone wrong: real examples of misuse
Fabricated case law in the courts
The most visible legal failure of generative AI in the UK has happened inside the justice system itself.
In R (Ayinde) v London Borough of Haringey and Al-Haroun v Qatar National Bank [2025] EWHC 1383 (Admin), the Divisional Court dealt with two cases in which fictitious authorities had been placed before the court. In one, a solicitor filed 18 non existent case authorities that had been produced using AI tools by the client and were never independently verified. The court described a lamentable failure to check material put before it. "My client provided it" was no answer.
The problem has not receded. In March 2026 a recorder sitting at Bournemouth Family Court ruled that an advocate who had presented a skeleton argument containing four cases or propositions that did not exist should be named publicly, because she offered paid legal services and the public interest required it. In April 2026 a judge referred two solicitors to the SRA over court documents containing inaccurate or non existent citations. Judges have also begun redacting fabricated citations from published judgments so that fake authorities are not scraped and propagated further by AI systems, a quietly remarkable development in itself.
The SRA updated its supervision guidance in June 2026 to cover AI assisted and AI generated work, requiring that outputs are subject to appropriate human review, scrutiny and professional judgement.
The lesson generalises well beyond law. A confident, fluent, entirely fictional output is the characteristic failure mode of these systems, and the professional obligation to verify does not transfer to the tool.
Non consensual sexual imagery at scale
In late December 2025 and early January 2026, the Grok chatbot integrated into X was reported to be generating sexualised images of real people. A study of 50,000 posts mentioning Grok between 25 December 2025 and 1 January 2026 found that more than half contained people in minimal attire, with around 2 per cent depicting individuals who appeared to be under 18. The Internet Watch Foundation flagged content meeting criminal thresholds.
Ofcom contacted X on 5 January 2026 and opened a formal investigation on 12 January 2026 into compliance with the illegal content risk assessment and safety duties in sections 9 to 11 of the Online Safety Act, alongside duties on children's access and privacy. On 15 January 2026 it opened a separate investigation into Novi Ltd over the Joi.com generative AI service and age assurance. A further investigation into Telegram followed on 21 April 2026. Ofcom can fine up to 10 per cent of global turnover.
This is the clearest signal yet that in the UK, the platform integrating an AI feature carries the regulatory risk, not just the model developer.
Deepfake enabled fraud
UK Finance reported that authorised push payment fraud losses rose 19 per cent in 2025 to £576.4 million, and warned that organised criminal groups are increasingly using AI tools including deepfakes, cloned voices and synthetic identities to impersonate trusted people and bypass identity checks. The Government's Fraud Strategy for 2026 to 2029 identified generative AI as an emerging challenge that lowers the barrier to credible scams at scale.
The best known corporate case remains the engineering firm Arup, which lost roughly 25 million US dollars in 2024 after an employee joined a video call populated by synthetic versions of the chief financial officer and colleagues.
Legally, the interesting point is that no new offence was needed. This is fraud by false representation, prosecuted under the Fraud Act 2006. What has changed is the cost of the deception, not its classification.
Automated hiring that was not really supervised
The ICO's "Recruitment Rewired" report, published in early 2026, found that many employers believed their AI tools were assisting human decision makers when in reality the tools were making the decisions. Hiring managers received AI generated fit scores and acted on them without the understanding or practical ability to override them, particularly at high application volumes. Employers frequently could not evidence how they were mitigating the risk of excessive reliance.
This matters enormously under the new Articles 22A to 22D. Nominal human involvement does not take a decision outside the automated decision making rules. Meaningful involvement requires competence, authority and genuine capacity to reach a different conclusion.
Facial recognition running ahead of the statute
Police use of live facial recognition has expanded rapidly. The Home Office policing white paper of 26 January 2026 committed more than £26 million to a national facial recognition system, £11.6 million to live facial recognition capability and £115 million over three years to a national centre for AI in policing, including a substantial increase in camera equipped vans. A Home Office consultation on a legal framework for police use of biometrics and facial recognition closed on 12 February 2026.
The technology is currently deployed without a bespoke statutory framework, governed instead by police policy, data protection law, the Human Rights Act and the public sector equality duty. Shaun Thompson, wrongly flagged by a system in 2024 and detained, brought a judicial review with Big Brother Watch challenging the adequacy of that framework. The High Court rejected the challenge in 2026, but the biometrics commissioners for England and Wales and for Scotland have publicly warned that deployment is outpacing the law that governs it.
AI in the workplace: what UK employers must do
There is no single statute on AI at work. There is a patchwork, and a live Business and Trade Committee inquiry into AI and the future of the workforce.
Practical obligations for any employer using AI in recruitment, monitoring or performance management:
- Complete a Data Protection Impact Assessment before procurement, not after deployment, and check whether the vendor uses your candidate or employee data to train its models.
- Identify a lawful basis. Legitimate interests is often the most appropriate in high volume recruitment. Consent is usually weak, because a candidate who feels unable to refuse has not given it freely.
- Make human oversight genuine. Document who reviews, what they see, what authority they have to depart from the output, and how often they actually do.
- Tell people. Explain when automated tools are used, what data they rely on and how to challenge an outcome.
- Monitor outcomes for bias across protected characteristics on an ongoing basis, and act on what you find. There is no statutory bias audit requirement, but there is Equality Act liability.
- Keep records. In tribunal proceedings, contemporaneous evidence that risk was assessed and monitored is materially different from reliance on supplier assurances.
The EU AI Act still reaches UK businesses
Brexit did not put UK companies outside the EU AI Act. The Act applies if you place an AI system on the EU market, or if the output of your system is used in the EU, or if it affects people in EU member states. Corporate domicile is not the test.
The timeline has shifted. The Digital Omnibus on AI, proposed by the European Commission on 19 November 2025, reached provisional political agreement on 7 May 2026, was endorsed by the European Parliament on 16 June 2026 and given final approval by the Council on 29 June 2026. Key effects:
- Obligations for standalone high risk systems under Annex III, which include hiring tools, credit scoring and biometric identification, move from 2 August 2026 to 2 December 2027.
- Obligations for AI embedded in regulated products under Annex I move to 2 August 2028.
- Watermarking and transparency obligations under Article 50(2) move to 2 December 2026 for systems already on the market.
- A new prohibition on AI systems for generating non consensual intimate imagery and child sexual abuse material applies from 2 December 2026.
The deadline moved. The obligations did not disappear, and other parts of the Act, including the prohibitions in force since February 2025 and general purpose AI model obligations since August 2025, continue to apply.
What happens next
Over the next 12 to 18 months, watch for:
- The Court of Appeal in Getty v Stability, which will decide whether a model can ever be an infringing copy.
- The ICO statutory code of practice on AI and automated decision making, expected in 2027, with final automated decision making guidance sooner.
- The Regulating for Growth Bill and the rollout of AI Growth Lab sandboxes sector by sector.
- The promised consultation on deepfake harms and a possible personality right.
- Regulations under the Crime and Policing Act 2026 on illegal AI generated content, with a progress report due by 31 December 2026.
- A statutory framework for police facial recognition, which commissioners suggest may still be years away.
- Whether pressure for a cross sector AI Bill returns, as several parliamentarians continue to argue that a bill by bill approach produces incoherence.
Frequently asked questions
Is AI legal in the UK? Yes. There is no general prohibition on developing or using AI. Specific uses can be unlawful, including creating sexual deepfakes without consent, supplying nudification tools, making discriminatory automated decisions, or processing personal data without a lawful basis.
Does the UK have an AI Act like the EU? No. The UK regulates AI in the context of its use, through existing law and existing regulators, and the Government has repeatedly declined to introduce a comprehensive AI statute.
Can I be sued if my AI system gets something wrong? Yes. Ordinary liability applies. Depending on the facts, that could mean breach of contract, negligence, discrimination, data protection infringement, defamation or regulatory enforcement. Responsibility does not transfer to the software vendor simply because a model produced the output.
Is it legal to train an AI model on copyright works in the UK? It is unresolved. There is no text and data mining exception for commercial training, the Government abandoned its proposed exception in March 2026, and the leading case did not decide the point because the training took place outside the UK. Licensing remains the safest route.
Who owns the output of an AI system? Also unresolved, and getting less certain rather than more. Section 9(3) of the Copyright, Designs and Patents Act 1988 currently provides for computer generated works, but the Government has indicated that provision is likely to be removed.
Are AI generated images of real people illegal? Sexual or intimate images of an identifiable adult created without consent are a criminal offence, as is requesting their creation. Other synthetic images of real people may engage data protection law, defamation, passing off or harassment depending on the circumstances.
Do I need to tell people when I use AI? In many situations, yes. Data protection transparency obligations apply where personal data is processed, and specific information rights attach to significant automated decisions. Sector rules and professional obligations may go further.
A closing point
The most common mistake in this area is treating "there is no AI Act" as though it meant "there are no rules". The opposite is closer to the truth. Because AI is regulated at the point of use, almost every existing legal duty an organisation already has applies to the AI it deploys, and the organisation, not the developer and not the model, is usually the one holding the liability.
The second most common mistake is assuming the position is stable. It is not. Between February and June 2026 alone, the UK gained a new automated decision making framework, a new criminal offence covering deepfake creation, a statutory duty to produce an AI code of practice, a new Act targeting synthetic image generators, and a reversal of Government policy on copyright. The law is being written now, in courtrooms, regulator investigations and select committee reports, and it will look different again in a year.
This article provides general information about AI and the law in the UK as at August 2026. It is not legal advice. Legal positions change quickly in this area and you should take specific advice on your circumstances.




