2. The regulatory landscape
The UK's principles-based approach
At the time of writing, the UK has deliberately not passed a single, comprehensive AI act. Instead it has taken a principles-based, regulator-led approach: rather than creating one new AI law and one new AI regulator, the government set out cross-sectoral principles and asked existing regulators to apply them within their current remits, using the powers they already have.
The five principles
- Safety, security and robustness: AI systems should function reliably and securely throughout their use.
- Appropriate transparency and explainability: people should be able to understand when AI is being used and, to an appropriate degree, how it reaches its outputs.
- Fairness: AI should not undermine legal rights, discriminate unfairly, or create unfair outcomes.
- Accountability and governance: there should be clear human ownership and oversight of AI systems and their outcomes.
- Contestability and redress: people affected by an AI-driven decision should have a route to challenge it.
What this means in practice
For a UK firm, there's no single "AI compliance" checkbox to tick. Instead, your existing legal obligations already reach AI use: data protection law when personal data is involved, equality law when decisions about people are made, consumer protection law when customers are affected, and sector rules where a regulator oversees your industry.
The practical consequence is that the five principles map remarkably well onto the internal governance this course describes. If you can show clear accountability, human oversight, fair treatment, transparency with those affected, and secure reliable operation, you're aligned with the direction of UK policy whatever legislative form it eventually takes.
Note that this is an area of active policy development. Governments change position, and legislation may follow. Treat this lesson as a snapshot at the time of writing, and expect your policy review cycle, covered in Section 4, to pick up changes.
› Course contents
Why AI needs governing
The regulatory landscape
Building your AI policy and approving tools
Running AI day to day
Putting it into practice