Overview of the 2026 Framework
The UK Government's updated AI regulatory framework, published in early 2026 by the Department for Science, Innovation and Technology (DSIT), marks a significant shift from the principles-based approach of 2023. Building on lessons from the EU AI Act and recommendations from the AI Safety Institute, the new framework introduces binding obligations for organisations developing or deploying certain categories of AI in the UK.
Unlike the EU's prescriptive approach, the UK framework maintains a sector-led implementation model — meaning that existing regulators (FCA, ICO, CQC, Ofcom) take responsibility for enforcing AI-specific requirements within their domains. However, a new cross-sector duty now requires organisations to demonstrate "proportionate AI governance" regardless of sector.
What Counts as High-Risk AI?
The framework defines high-risk AI across eight domains, closely mirroring but not identical to the EU categories:
- Healthcare and medical devices — including diagnostic, triage and treatment recommendation systems
- Financial services — credit scoring, fraud detection, algorithmic trading systems affecting retail customers
- Employment and HR — AI-assisted recruitment, performance monitoring, termination decisions
- Education and skills assessment — automated marking, admissions tools, learner profiling
- Critical national infrastructure — energy, water, transport management systems
- Law enforcement and border control — biometric identification, risk profiling, predictive policing tools
- Access to essential services — benefits assessment, housing allocation, social care planning
- Democratic processes — voter profiling, political advertising targeting, election monitoring
Notably, the UK framework excludes general-purpose AI models (like large language models) from the high-risk category unless they are fine-tuned and deployed in a high-risk application.
New Obligations for Businesses
Organisations deploying or developing high-risk AI must now comply with the following obligations by the stated deadlines:
- AI Impact Assessment — A documented assessment of algorithmic risks, data quality and potential harms, updated annually or upon significant model changes.
- Human Oversight Requirement — High-risk AI systems must include a meaningful human review mechanism before final decisions affecting individuals.
- Transparency Notices — Individuals must be informed when an AI system has made or substantially influenced a decision affecting them.
- Technical Documentation — Model cards, data sheets and performance benchmarks must be maintained and available to regulators on request.
- Post-Market Monitoring — Ongoing performance monitoring with incident logging and mandatory reporting of serious AI-related harms.
Compliance Timeline
The framework introduces a phased compliance timetable to give businesses time to adapt:
- April 2026: Guidance published by sector regulators; voluntary registration opens
- October 2026: AI Impact Assessments required for new high-risk deployments
- April 2027: Full compliance required for existing high-risk AI systems
- 2028 onwards: Periodic re-assessment cycles and enhanced audit requirements
Penalties for Non-Compliance
Enforcement sits with existing sector regulators, each with their own penalty frameworks. However, the framework introduces a new "AI governance failure" designation that can be referred across regulators. The ICO has confirmed it will treat serious AI governance failures under its existing data protection enforcement powers, with fines of up to £17.5 million or 4% of global turnover.
Next Steps for UK Tech Leaders
For CIOs, CTOs and AI governance leads, the immediate priorities should be:
- Conduct an internal AI inventory — catalogue all AI systems in production and assess their risk category
- Identify your lead regulator for each high-risk deployment
- Start drafting AI Impact Assessment templates, drawing on the DSIT template published alongside the framework
- Review supplier contracts — if you're using third-party AI, ensure your vendors can provide required technical documentation
- Appoint or designate an AI Accountability Lead (not necessarily a new hire — this can be an extension of an existing role)
The full DSIT guidance document and sector-specific FAQs are available on GOV.UK. UK AI Hub will continue to track regulatory developments as the compliance deadlines approach.