Every few months another headline asks where Britain’s AI Act has got to. The honest answer is that it isn’t coming, not in the shape people expect. There is no single AI statute before Parliament and no date to circle for one. Ministers have said repeatedly they don’t want to legislate AI as a technology the way the EU has. That gets reported as “the UK has no AI rules,” and we hear that line from clients often enough that it’s worth correcting properly, because it’s the kind of misreading that gets a small business into real trouble.
There’s still no single AI law, and that’s easy to misread
We’ve built enough client automations by now to know the gap between “there’s no AI Act” and “there’s no law” is where most of the risk sits. The House of Commons Library’s own briefing is blunt about it: the UK has deliberately chosen not to pass AI-specific legislation, and instead expects existing regulators to apply existing law to AI as one more technology within their remit. No new AI statute does not mean no exposure. If anything, relying on general law rather than a single tailored Act makes it easier to miss which rules bite, because there is no one place that lists them.
The five principles doing the job of a statute
What the UK has instead is five non-statutory principles that sector regulators are expected to apply within their own patches: safety and robustness, appropriate transparency, fairness, accountability, and contestability. The Information Commissioner’s Office applies them to data protection, the Financial Conduct Authority applies them to lending and advice, Ofcom applies them to online safety, and so on. Nobody signed these principles into law as an “AI Act,” but a regulator that already has enforcement powers over your sector now expects you to be able to explain how your AI made a decision, and to give someone a way to challenge it. The principles are soft. The regulators applying them are not.
The law already covering you
For most small businesses the sharpest edge is data protection. If an AI tool processes any personal data, customer records, job applicants, website visitors, it sits inside UK GDPR and the Data (Use and Access) Act 2025, which reworked the automated decision-making rules that used to sit in Article 22 and brought them into force from 5 February 2026. Add consumer protection law if you use AI in pricing or marketing, and employment law if you use it anywhere near recruitment or performance management. None of it was written with AI in mind, and all of it applies to AI use today. The ICO’s own fining guidance still caps the most serious UK GDPR breaches at the higher of £17.5 million or 4% of global turnover. In practice the ICO scales fines to the size of the business rather than reaching for the ceiling against a five-person firm, but the exposure is real, and “we didn’t know AI counted” is not a defence that has ever worked with a data regulator.
The governance gap: 83% of businesses have no AI policy at all
Here’s the number that should worry you more than any headline about a missing Act. The Government’s own UK Business Data Survey 2026 found that among businesses already using AI, only 17% have any policy or guidance covering how staff use it, just 5% with anything formal in writing and 12% running on informal guidance. That leaves 83% of AI-using businesses with no policy whatsoever. We see this constantly: a team is already feeding customer data into a chatbot or using AI to screen CVs, with nobody having decided what data is off-limits, who checks the output, or what happens when the AI gets it wrong. That gap is not a paperwork problem. It is the exact gap a regulator, or a customer complaint, walks straight into. A one-page policy costs an afternoon. A GDPR complaint with no policy to point to costs a great deal more.
The AI Growth Lab is help, not a loophole
The one genuinely new mechanism this year is the AI Growth Lab, a cross-economy regulatory sandbox that launched in June 2026 with legal services and conveyancing as the first sector through the door, with healthcare, professional services, transport and manufacturing flagged to follow through 2026 and 2027. Inside the sandbox, specific rules can be temporarily and conditionally relaxed for licensed firms testing an AI deployment under supervision. It’s open to SMEs and unregulated providers as well as regulated ones. Worth being clear about what it is not: it is not a way to sidestep data protection or consumer law while you experiment. It is a “help you comply” route for businesses who want regulatory clarity before they scale something, not an exemption from the rules covered above.
What to do this week
You don’t need a compliance department to close most of this gap. Write down, in one page, which AI tools your business actually uses and what data goes into them. Decide who reviews AI-generated decisions before they reach a customer, especially anything touching pricing, credit, or hiring. Check whether any tool you use makes an automated decision with a legal or similarly significant effect on someone, because that is exactly what the reworked Article 22A-22D rules under the Data Act now govern. And if you are about to deploy AI somewhere genuinely regulated, look at whether the AI Growth Lab’s sector sandboxes cover you before you build around uncertainty instead of asking the regulator directly.
There’s still no UK AI Act, and there probably won’t be one soon. That was never really the question that mattered. The question is whether your business can show it knows which existing rules already apply to the AI it’s using today, and 83% of UK businesses currently can’t answer that. Closing that gap costs an afternoon. Not closing it costs considerably more.