Platform AI governance Coverage Pricing Partners Sign in
Free readiness checkTalk to us
HomeAI laws › UK GDPR + DPA 2018 (no AI statute)
AI governance law · United Kingdom

๐Ÿ‡ฌ๐Ÿ‡ง UK GDPR + DPA 2018 (no AI statute)

The UK has chosen a pro-innovation, principles-based route rather than a single AI Act. Existing regulators apply five cross-sector principles - safety, transparency, fairness, accountability and contestability - to AI in their patch. For most organisations the binding hooks are the UK GDPR and the Data Protection Act 2018, with the DUAA automated-decision rules in Articles 22A to 22D live from 5 February 2026 and ICO guidance treated as quasi-binding.

Cited to primary sources
UK GDPR + DPA 2018
Governing framework
Information Commissioner's Office (ICO) + sector regulators
Supervisory authority
5
Controls this market requires
10
Required or strongly expected
Good to know: there is no UK AI-labelling, general-purpose-AI or conformity-assessment regime yet, so those items sit lower than under the EU AI Act. The strongest duties come through data-protection law, where automated decisions and impact assessments are firmly required.
Status: provisional overview (v0.1), reviewed against primary sources dated 24 Aug 2026; not legal advice.

What United Kingdom expects of you

All 12 AI-governance controls we track apply here, graded by how firmly the law requires each one.

Required mandated by binding law Expected near-mandatory / guidance-backed Prudent advisable Optional emerging n/a not applicable
AI RiskRequired

AI risk classification & impact assessment

Classifying each AI system by risk and running an impact assessment (AIA/FRIA; DPIA where personal data is used). UK GDPR Article 35 DPIA is required for high-risk AI processing.

Closes with: AI risk classification + impact assessment (AIA/FRIA)
AI DataRequired

Data governance for AI

Governing training/input data: quality, provenance, lawful basis for personal data, minimisation and bias. UK GDPR data-protection principles govern training and input data.

Closes with: AI data-governance standard
AI OversightRequired

Human oversight & automated decisions

Meaningful human oversight, and governance of solely-automated decisions with legal or significant effect on individuals. UK GDPR Articles 22A-22D automated decisions - DUAA, live 5 February 2026.

Closes with: Human-oversight + automated-decision safeguards note
AI SecurityRequired

Security of AI systems

AI-specific security: access to models and training data, protection against prompt injection/model abuse, secrets. UK GDPR Article 32 security of processing.

Closes with: AI security controls statement
AI IncidentRequired

AI incident response & serious-incident reporting

Detecting, handling and (where required) reporting AI failures and serious incidents to regulators. UK GDPR Articles 33-34 breach notification to the ICO within 72 hours.

Closes with: AI incident-response plan + reporting templates
AI GovernanceExpected

AI governance ownership & policy

A named owner (or committee) accountable for AI, and a written AI policy setting principles, scope and roles.

Closes with: AI policy + governance charter
AI InventoryExpected

AI system inventory / register

A maintained register of every AI system and use-case: purpose, owner, data used, risk tier and vendor.

Closes with: AI system register
AI AssuranceExpected

Accuracy, robustness & drift monitoring

Ongoing checks that AI performs as intended and does not degrade, with metrics and a review cadence.

Closes with: Model monitoring + drift-review plan
AI Supply ChainExpected

Third-party / vendor AI & foundation models

Due diligence on AI vendors and general-purpose/foundation models, recorded in model cards and supplier assessments.

Closes with: Vendor AI due-diligence + model cards
AI AssuranceExpected

Record-keeping, logging & conformity

Keeping the logs, technical documentation and conformity evidence regulators expect. Article 30 records and ICO expectations back documentation and logging.

Closes with: AI logging + technical-documentation pack
AI TransparencyPrudent

Transparency & disclosure

Telling people when they deal with AI or AI-generated content; labelling output; chatbot/deepfake disclosure. No statutory AI-labelling duty; ICO transparency guidance makes disclosure advisable.

Closes with: AI transparency + disclosure notices
AI UsePrudent

Acceptable use of AI by staff

An internal policy governing employees' use of generative AI: approved tools, data rules, output review. No binding rule; a staff generative-AI policy is prudent under ICO guidance.

Closes with: Acceptable-use policy for generative AI

Get UK-ready without a rulebook to read

PrivMatrix maps the five UK principles and the UK GDPR duties onto your AI systems, then generates the DPIAs, disclosures and policies that show a regulator you have done the work.

Other markets

See all AI laws →
๐Ÿ‡ช๐Ÿ‡บ EU๐Ÿ‡ฆ๐Ÿ‡ช UAE๐Ÿ‡ธ๐Ÿ‡ฆ Saudi Arabia๐Ÿ‡ฎ๐Ÿ‡ณ India๐Ÿ‡ถ๐Ÿ‡ฆ Qatar