There is no UK AI Act. The UK has not passed a standalone AI law, and as of 1 October 2026 the government has not put one before Parliament.
That doesn’t mean you’re in the clear. Existing UK laws already cover how you use AI, and the EU AI Act can reach UK firms that work with EU customers. This guide explains which rules apply to a small business, what changed in 2026, and what to do in the next 30 days.
Is there a UK AI Act?
No. The UK has no standalone AI Act. AI is governed by existing laws, such as UK GDPR, consumer law and the Equality Act 2010, enforced by regulators including the ICO, CMA, FCA and Ofcom. The government sets non-binding AI policy through DSIT.
How the UK regulates AI instead
The UK follows a “pro-innovation” approach set out in a 2023 white paper. Existing regulators apply five principles inside their own areas: safety, transparency, fairness, accountability, and the right to challenge decisions.
These principles are guidance, not law. The upside is flexibility. The downside is that there’s no single rulebook, so you check a few sources instead of one.
Bills you may have seen in the news
Three items keep appearing in headlines. None changes what your business can do today.
- Artificial Intelligence (Regulation) Bill. A private member’s bill from Lord Holmes. Parliament’s records show it has sat at first reading in the Lords since March 2025, with no government backing.
- Artificial Superintelligence Bill. A backbench “Ten Minute Rule” bill introduced on 8 September 2026. It targets the most powerful AI systems, not a firm using ChatGPT for emails. Bills like this rarely become law without government support.
- Joint Committee on Human Rights. In September 2026 it called for a new risk-based AI Bill. That is a recommendation, not legislation.
Which UK rules already apply to your AI use?
Four areas of existing UK law matter most to small businesses: data protection, consumer and advertising law, employment and equality law, and intellectual property and confidentiality.
Data protection (UK GDPR)
If you put personal data into an AI tool, UK GDPR applies. You need a lawful basis, you must tell people what you do with their data, and you must keep it secure. High-risk uses may need a data protection impact assessment (DPIA). Maximum fines are £17.5 million or 4% of turnover, whichever is higher. Our UK GDPR compliance checklist covers the basics.
If you handle personal data, you probably also need to pay the ICO data protection fee.
What not to paste into a chatbot:
- Customer personal data
- Special category data (health, ethnicity, religion and similar)
- Confidential client documents
- Passwords and API keys
- Unreleased financial figures
Our ChatGPT for business guide explains which account types give you business-level data controls.
Consumer law and advertising
The CMA and the ASA care about what you tell customers, not which tool wrote it. Fake reviews, misleading claims and wrong answers from a chatbot are your responsibility. You can’t blame the software. If you’re adding an AI chatbot to your website, say clearly that it’s AI and offer a route to a human. Update your website terms and conditions to match.
Employment and equality law
The Equality Act 2010 applies even when software makes the call. If an AI CV screener ranks women or older candidates lower, you’re still the employer. Keep a person in the loop for hiring decisions. It also helps to add AI-use rules to staff contracts, and a free employment contract template is a reasonable starting point.
Intellectual property and confidentiality
Who owns AI-generated output is still unsettled in UK law, and the government has been reviewing copyright and AI. Treat anything important as needing human authorship and checking. Client contracts and NDAs may also ban third-party tools, so read them first. See our guides on protecting intellectual property and a free NDA template.
If you work in finance, online platforms or health, sector regulators (FCA, Ofcom, MHRA) add their own expectations.
Does the EU AI Act apply to a UK small business?
Sometimes. The EU AI Act (Regulation (EU) 2024/1689) applies to UK businesses that put AI on the EU market, or whose AI system’s output is used in the EU. If you only trade in the UK, it doesn’t apply to you.
The three tests
| Question | If yes |
|---|---|
| Do you sell an AI product or service to EU customers? | You may be a provider |
| Is the output of AI you use received or used in the EU? | You may be a deployer |
| Is your AI used for hiring, education, credit scoring or similar? | It may count as high-risk |
Selling physical goods to the EU doesn’t trigger the Act on its own. Using AI to market to or serve EU customers might. If you’re exporting goods, check your AI use alongside your customs paperwork.
Provider vs deployer in plain English
A provider builds an AI system, or has one built, and sells it under its own name. A deployer uses an AI system in a professional setting. Most small firms are deployers. Paying for ChatGPT makes you a deployer. Building a chatbot product on top of a model and selling it makes you a provider, and the duties are much heavier.
What small businesses must do
- Avoid prohibited practices. These have applied since 2 February 2025. Examples include social scoring, manipulative AI and emotion recognition at work or in schools.
- Build AI literacy. Article 4 expects staff to understand the tools they use. The Digital Omnibus talks revisited this duty, so check the final wording on EUR-Lex.
- Be transparent. Tell people when they’re talking to an AI, and label deepfakes.
- Follow high-risk rules if your use falls under Annex III, such as recruitment.
Updated EU timeline
Many guides still show 2 August 2026 for high-risk rules. That’s out of date. The Council approved the Digital Omnibus on AI on 29 June 2026.
| Date | What applies |
|---|---|
| 2 Feb 2025 | Prohibited practices; AI literacy |
| 2 Aug 2025 | Rules for general-purpose AI model providers |
| 2 Aug 2026 | Most remaining rules, including transparency duties |
| 2 Dec 2026 | Extended deadline for machine-readable marking of AI-generated content (certain systems) |
| 2 Dec 2027 | Standalone high-risk systems (Annex III, e.g. hiring) |
| 2 Aug 2028 | High-risk AI built into regulated products |
Confirm exact dates on EUR-Lex before you rely on them.
EU penalties
Fines go up to €35 million or 7% of turnover for prohibited practices, €15 million or 3% for most other breaches, and €7.5 million or 1% for giving regulators false information. For SMEs, the lower of the two figures applies. A UK-only business has no EU exposure.
Five real scenarios
Your obligations depend on what the AI does and who it affects. Here’s how that plays out.

| Scenario | UK rules | EU AI Act? | What to do |
|---|---|---|---|
| ChatGPT for marketing copy | UK GDPR if personal data; ASA rules; IP | Only if the campaign targets the EU | Policy, no personal data, human review |
| Website chatbot | Consumer law; UK GDPR | Yes, if EU visitors use it: disclose it’s AI | Label it as AI, offer a human |
| AI CV screening | UK GDPR automated decisions; Equality Act | High-risk if EU candidates (from Dec 2027) | DPIA, bias checks, human decision |
| AI bookkeeping | UK GDPR; supplier security | Unlikely | Check the supplier, review outputs |
| Selling an AI product to the EU | All of the above | Possibly as a provider | Take legal advice |
A 30-day AI compliance checklist
Most small businesses can cover the essentials in a month.
Week 1: Find out what you use
- List every AI tool, including free personal accounts and built-in features such as Microsoft 365 Copilot.
- Note what data goes into each one.
Week 2: Set the rules
3. Fix data handling. Use business accounts, switch off training on your inputs where possible, and update your privacy notice. Run a DPIA for risky uses.
4. Write a one-page acceptable use policy: approved tools, banned data, who checks output.
Week 3: Check people and suppliers
5. Name who reviews AI output before it reaches customers or affects someone’s job or credit.
6. Ask suppliers where data is stored, whether they train on it, and how it’s secured. Cyber Essentials is a useful baseline.
Week 4: Train and record
7. Run a 30-minute staff session and keep attendance records. That’s good evidence for AI literacy.
8. Ask your broker whether professional indemnity insurance covers AI-assisted work. Diarise a quarterly review.
Common mistakes
- Assuming no AI Act means no risk.
- Letting staff use personal AI accounts for client work.
- Trusting a vendor’s “compliant” label without asking questions.
- Running a chatbot that doesn’t say it’s a bot.
- Keeping no records of decisions or training.
What’s coming next in UK AI regulation
Expect gradual change through existing laws and regulators, not a big AI Act.
- UK: No government AI bill timetable exists. Watch the ICO’s code of practice on AI and automated decisions, the Law Commission’s review of the Consumer Protection Act 1987 for AI products, and regulator sandboxes under the government’s AI Growth Lab.
- EU: The Digital Omnibus has moved the high-risk dates and widened the list of banned practices. Watch for final guidance from the European Commission.
Habits that work under either regime are an AI inventory, human oversight and honest disclosure. If larger clients ask for proof, ISO/IEC 42001 is an optional AI management standard, and the NIST AI Risk Management Framework is a free reference.
FAQs
Is there a UK AI bill?
There is no government AI bill. Backbench bills exist but have no government backing. The government has said it will regulate mostly through existing regulators.
Do I need an AI policy?
No UK law requires one by name. In practice you need one, because UK GDPR makes you accountable for how personal data is used, and staff need clear rules.
Does the EU AI Act apply to UK businesses?
Yes, if you place AI on the EU market or the output of AI you use is used in the EU. UK-only businesses aren’t covered.
Do I have to tell customers I use AI?
There’s no general UK rule. But UK GDPR transparency applies if you process personal data or make automated decisions, and consumer law bans misleading practices. The EU AI Act requires chatbot disclosure for EU users.
What happens if I ignore this?
You risk ICO fines of up to £17.5 million or 4% of turnover, discrimination claims, customer complaints and contract breaches. For most small firms, the practical risk is a data or discrimination problem, not an “AI law” fine.
The short version
There’s no UK AI Act, but three sets of rules still reach you: UK data and consumer law, sector regulators, and the EU AI Act if you touch the EU market. Start with the checklist, write the one-page policy, and review it every quarter.
Once your foundations are in place, see how to use AI to grow a small business with confidence.

