The UK has chosen a pro-innovation, principles-based route rather than a single AI Act. Existing regulators apply five cross-sector principles - safety, transparency, fairness, accountability and contestability - to AI in their patch. For most organisations the binding hooks are the UK GDPR and the Data Protection Act 2018, with the DUAA automated-decision rules in Articles 22A to 22D live from 5 February 2026 and ICO guidance treated as quasi-binding.
All 12 AI-governance controls we track apply here, graded by how firmly the law requires each one.
Classifying each AI system by risk and running an impact assessment (AIA/FRIA; DPIA where personal data is used). UK GDPR Article 35 DPIA is required for high-risk AI processing.
Governing training/input data: quality, provenance, lawful basis for personal data, minimisation and bias. UK GDPR data-protection principles govern training and input data.
Meaningful human oversight, and governance of solely-automated decisions with legal or significant effect on individuals. UK GDPR Articles 22A-22D automated decisions - DUAA, live 5 February 2026.
AI-specific security: access to models and training data, protection against prompt injection/model abuse, secrets. UK GDPR Article 32 security of processing.
Detecting, handling and (where required) reporting AI failures and serious incidents to regulators. UK GDPR Articles 33-34 breach notification to the ICO within 72 hours.
A named owner (or committee) accountable for AI, and a written AI policy setting principles, scope and roles.
A maintained register of every AI system and use-case: purpose, owner, data used, risk tier and vendor.
Ongoing checks that AI performs as intended and does not degrade, with metrics and a review cadence.
Due diligence on AI vendors and general-purpose/foundation models, recorded in model cards and supplier assessments.
Keeping the logs, technical documentation and conformity evidence regulators expect. Article 30 records and ICO expectations back documentation and logging.
Telling people when they deal with AI or AI-generated content; labelling output; chatbot/deepfake disclosure. No statutory AI-labelling duty; ICO transparency guidance makes disclosure advisable.
An internal policy governing employees' use of generative AI: approved tools, data rules, output review. No binding rule; a staff generative-AI policy is prudent under ICO guidance.
PrivMatrix maps the five UK principles and the UK GDPR duties onto your AI systems, then generates the DPIAs, disclosures and policies that show a regulator you have done the work.