United Kingdom: Why It Chose Not to Have an AI Law — the Sectoral Approach Explained

By Carlos Montiel | Enterprise AI Specialist
Leer en español →
Published: 2026-07-28 | By: Carlos Montiel | Reading time: ~4 minutes

While the EU was building the world's most ambitious AI law, the UK made the opposite decision on purpose: not to legislate horizontally, and to trust the regulators that already exist.

Five principles, no new law

The UK did not pass a comprehensive AI law like the EU AI Act. Instead, it adopted a "pro-innovation" framework built on five principles that existing sector regulators must apply within their own domain, using their existing legal authority: safety/robustness, appropriate transparency and explainability, fairness, accountability and governance, and contestability and redress.

The sectoral model in practice

Instead of a single AI regulator, the UK spreads oversight across the regulators that already covered each sector — the FCA for financial services, the ICO for data protection, and so on — each applying the five principles within its own legal jurisdiction. It's a deliberate bet on avoiding a new regulator and a horizontal law that, according to the government's argument, would slow AI investment in the country.

The AI Security Institute: it evaluates, but doesn't enforce sanctions

The AI Security Institute (renamed from AI Safety Institute in February 2025) evaluates frontier models for capabilities relevant to national security and publishes technical reports for policymakers — but it's explicitly a government evaluation body, not a market supervisor, and it doesn't impose sanctions against individual deployers. It published its first Frontier AI Trends Report on December 18, 2025, based on two years of evaluations across more than thirty frontier models.

The pressure toward harder obligations

The government's AI Opportunities Action Plan already explicitly mentions the possibility of considering mandatory requirements for frontier AI developers — including incident reporting and pre-deployment safety evaluations. The purely voluntary approach may not be permanent; it's more of a transitional stage than a fixed philosophy.

What it means for companies operating in both the UK and the EU

For a company operating in both markets, the contrast is direct: in the EU there's a single horizontal law with explicit risk classification; in the UK you have to track which sector regulator applies to each specific use case and what guidance that particular regulator has published on AI — it's a more fragmented map, but with much less mandatory formal documentation burden as long as the approach stays voluntary.

Carlos Montiel
Enterprise AI Solutions Architect
Specialist in LLMs, Agents, and Orchestration
guatemalia.com/en/#contact · info@guatemalia.com

Need to implement AI at your company?

Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.

Contact Carlos Montiel

info@guatemalia.com