Sector regulators

Which UK regulator covers your AI use?

The UK deliberately chose not to create an AI regulator. Instead, whichever body already regulates your sector applies its existing rules to your AI. That means the answer to 'who governs our AI?' depends entirely on what your business does.

Last reviewed: August 2026

How the UK approach actually works

Government policy set out five cross-sector principles — safety, transparency, fairness, accountability, and contestability — and asked existing regulators to apply them within their own remit. There is no registration scheme, no single checklist, and no one body to ring.

The practical consequence for a small business is uncomfortable: you may be answerable to two or three regulators for the same AI tool, each with a different emphasis, and none of them will tell you that unprompted.

The one that always applies

If your AI touches personal data, the ICO is in scope regardless of sector. Everything below stacks on top of that, it doesn't replace it.

Regulator by sector

ICO

Every business that touches personal data

The default regulator for AI in the UK, because almost all business AI use involves personal data. Expects a named owner per tool, a lawful basis, transparency in your privacy notice, and a DPIA where the AI influences decisions about people.

FCA

Financial services, lending, insurance, payments, wealth

No standalone AI rulebook. Instead the Consumer Duty, SM&CR accountability and existing operational resilience and outsourcing rules apply to AI. In practice: a named senior manager must be accountable for an AI system, you must be able to explain outcomes to a customer, and you must show the AI doesn't produce foreseeable harm or poor value for a group of customers.

EHRC

Anyone using AI in recruitment, promotion or service access

Enforces the Equality Act 2010. An AI tool that screens CVs, ranks candidates or scores applicants can produce indirect discrimination even with no protected characteristic in the data — proxies like postcode, career gaps or school do the same work. The employer is liable, not the vendor.

MHRA

Health and care providers, medtech, anything diagnostic

AI that supports diagnosis, triage or treatment decisions may be a regulated medical device requiring UKCA marking. Administrative AI — scheduling, note-taking, correspondence — generally isn't, but clinical note-taking tools sit close to the line and need a careful read.

Ofcom

Platforms, publishers and anyone hosting user content

The Online Safety Act imposes duties on services that host user-generated content, including duties around AI-generated harmful material and recommendation systems. Relevant if your product has a feed, a forum, messaging, or user uploads.

SRA / ICAEW / RICS

Solicitors, accountants, surveyors and other regulated professions

Professional bodies expect competence and confidentiality to survive AI adoption. Client confidential information going into a public AI tool is the recurring issue, alongside unchecked AI output being relied on in advice.

Ofqual / DfE

Education, training and awarding organisations

Rules around assessment integrity, marking, and use of AI on learner data — including safeguarding expectations where the learners are children.

And then there's the EU AI Act

If you have customers or staff in the EU, the EU AI Act reaches you even though you're a UK business. It classifies AI systems by risk and puts substantial obligations on anything it treats as high risk — which explicitly includes AI used in recruitment, worker management, credit scoring, and access to essential services.

A UK recruitment firm placing candidates with an EU employer, or a UK company with one employee in Dublin, is inside that scope. This is the single most commonly missed exposure we see.

What to do with this

  • Identify your primary sector regulator from the list above.
  • Assume the ICO applies as well, unless no AI tool you use touches personal data.
  • Check whether any EU customer, supplier arrangement or staff member pulls you into the EU AI Act.
  • For each AI tool, note which regulators are relevant and who inside your business owns it.
  • Re-check when you adopt a new tool, not annually — adoption is what changes your exposure.

See where your own AI use actually stands

Register the AI tools your team uses and get a risk rating for each one, in plain English. Free, and it takes about ten minutes.

Not legal advice. This guide explains how the rules are generally understood and is here to help you get organised. It isn't a substitute for advice from a qualified solicitor or your own compliance team.