A useful starting point is to separate legislation, regulation and standards.
Legislation is binding law, such as the UK GDPR, the Data Protection Act 2018, the Equality Act 2010, the Online Safety Act 2023 and, for organisations operating in or supplying the EU, Regulation (EU) 2024/1689, the AI Act.
Regulation is the way public bodies interpret, supervise and enforce those duties. In the UK, this includes regulators such as the Information Commissioner’s Office (ICO), Equality and Human Rights Commission (EHRC), Competition and Markets Authority (CMA), Financial Conduct Authority (FCA), Ofcom and sector regulators.
Standards are usually voluntary unless written into contracts, procurement rules or legislation, but they are valuable because they define recognised good practice and evidence.
The UK does not currently have one general AI Act equivalent to the EU regime. Instead, the government has promoted a pro-innovation, context-specific approach built around five principles (DSIT, 2023). This means an AI tool used in recruitment, credit, health, education, finance, public services or customer operations may be governed by different regulators and sector rules. The Digital Regulation Cooperation Forum supports coordination between the ICO, CMA, FCA and Ofcom where digital issues overlap (DRCF, 2025). For practitioners, this means the first compliance question is not “is AI allowed?”, but “what is the use case, who is affected, what data is used, and which regulator or law is triggered?”
Data protection is often the most immediate legal layer. AI systems may collect, infer, classify, predict or generate information about identifiable people. The ICO’s AI guidance links AI use to UK GDPR principles such as lawfulness, fairness, transparency, accuracy, security, data minimisation and accountability (ICO, 2023). The Data (Use and Access) Act 2025 (DUAA) changes aspects of automated decision-making in UK data protection law, creating a more permissive framework in some circumstances but retaining safeguards, including information, representation and challenge rights (GOV.UK, 2025; ICO, 2025). A data protection impact assessment may be required where processing is likely to create high risk.
Equality and human rights duties also matter. AI can reproduce bias through historical data, proxy variables, inaccessible design, weak testing or unfair deployment. The EHRC warns that AI use can create risks under the Equality Act 2010 and the Human Rights Act 1998 (EHRC, 2024). This is especially relevant where AI influences recruitment, performance, learning access, service eligibility, prioritisation, fraud detection or customer treatment. Responsible practice therefore requires equality impact consideration, representative testing where possible, accessible communication and routes for people to challenge outcomes.
The EU AI Act adds another important layer for organisations with EU users, markets or suppliers. It uses a risk-based structure, including prohibited practices, high-risk systems, transparency duties and requirements for general-purpose AI models (European Commission, 2024). The timetable is phased and has been subject to 2026 simplification proposals, so implementation dates should be checked before deployment (European Commission, 2026). Even where the Act does not apply directly, its concepts are useful for governance because they focus attention on intended purpose, risk classification, human oversight, technical documentation, monitoring and user information.
Standards and assurance help organisations operationalise these duties. ISO/IEC 42001 sets requirements for an AI management system, supporting organisations to establish, implement, maintain and improve governance for AI systems (ISO, 2023). NIST’s AI Risk Management Framework organises risk work through Govern, Map, Measure and Manage functions (NIST, 2023). The OECD AI Principles promote trustworthy AI that respects human rights and democratic values (OECD, 2024). The UK AI Cyber Security Code of Practice adds baseline security principles across the AI lifecycle (DSIT, 2025). Together, these frameworks help teams evidence accountability rather than relying on good intentions.
In practice, the landscape should be converted into a live AI governance process. Each AI or automation use case should have an owner, intended purpose, risk rating, data map, supplier evidence, human oversight model, testing plan, user guidance, incident route and review date. Floridi (2023) argues that AI ethics only becomes meaningful when principles are connected to governance, incentives and accountability. For practitioners, that means documenting decisions, testing outputs, monitoring harms and pausing systems when risk outweighs benefit. Compliance is not a final sign-off; it is continual assurance that the system remains lawful, fair, secure and useful as technology, data and work change.
Action Point
Choose one AI or automation use case in your organisation. Create a one-page governance map showing: purpose, data used, people affected, relevant laws or regulators, applicable standards, risks, human oversight and evidence needed. Identify one missing control and agree who will complete it before the system is used or scaled.