As noted in the second edition of this Law Over Borders Guide, at GBP 23.9 billion, the UK remains the largest AI economy in Europe and the third largest globally after the United States and China. It continues to attract significant investment from major AI companies such as Google and Anthropic and geographically seems to have benefited from an “offshore” position relative to the European Union and the United States. The UK is also a net beneficiary of a current wave of “Sovereign AI” investment which is designed to reduce structural dependency on US based hyper-scalers.
The UK has an uncodified or “unwritten” constitution which is not contained in a single document. It is instead contained in legislation, case law, treaties and other conventions. While no aspects of the UK constitution are specifically focused on AI, a key component is the Human Rights Act 1998 (HRA) which incorporated the rights and freedoms guaranteed under the European Convention on Human Rights (Council of Europe Convention for the Protection of Human Rights and Fundamental Freedoms, as amended, known as the ECHR) into the laws of the UK, enabling their enforcement in domestic courts. A number of the rights provided for under the ECHR are relevant to AI and are further explored below.
Key components of UK human rights law relevant in an AI context include:
- the ECHR;
- the HRA; and
- the Equality Act 2010.
Article 8 ECHR — Right to respect for private and family life
This provides for the right to respect for individuals’ private and family life, home and correspondence. AI systems frequently process personal data and such processing may involve profiling, biometric identification or surveillance.
The judgment of the Court of Appeal in R (Bridges) v. Chief Constable of South Wales Police [2020] EWCA Civ 1058 was an important ruling which considered the use of automated facial recognition (AFR) technology by police to check CCTV recordings of the general public using “watchlists” of selected individuals. The judgment found that the AFR was used in a context in which it was not made clear to individuals where the technology could be used and who could be placed on a relevant watchlist and was not in accordance with the law, though the court did reject arguments that the interference with the Article 8 ECHR right by the police had been disproportionate.
Article 14 ECHR — Prohibition on discrimination
This provides for other ECHR rights and freedoms to be secured without discrimination and may be relevant in contexts involving use of AI including recruitment, the consideration of credit applications, and sentencing and parole decisions.
In Bridges, the Court of Appeal found that reasonable steps had not been taken to ascertain whether the AFR technology had a racial or gender bias in accordance with the public sector equality duty (a requirement under section 149 of the Equality Act 2010). This duty requires a public authority to have due regard to the need to eliminate discrimination.
Article 6 ECHR — Right to a fair trial
This entitles individuals to a fair and public hearing within a reasonable time by an independent and impartial tribunal established by law. If AI is used in the administration of justice or in decisions affecting civil rights, then Article 6 ECHR may be engaged.
While there is limited case law to date, the judgment of the High Court in R (Ayinde) v. Haringey LBC [2025] EWHC 1383 (Admin) considered the actual or suspected use of generative AI tools to produce arguments or statements which are not checked and contain hallucinations and so result in false information (such as a fake citation or quotation) being put before the court. In its judgment, the High Court noted the risks of using AI for legal research and the professional duty on legal professionals to check the accuracy of such research before relying on it in the course of their work. Ensuring the accuracy of research presented before a court is important to ensure procedural fairness and therefore directly relevant to Article 6 ECHR.
Article 10 ECHR — Right to freedom of expression
This right to freedom of expression is increasingly relevant to the use of AI in the context of expression and assembly.
While case law is again limited to date, in the case of R (On the application of Thompson) v. Commissioner of Police of the Metropolis [2026] EWHC 915 (Admin) the High Court considered the deployment of live facial recognition (LFR) cameras and noted that deployment of LFR can have a “chilling effect” on the exercise of rights, such as Article 10 ECHR, though the guidance to police officers on proportionality in that case was found to act as an effective safeguard against arbitrary outcomes.
Other human rights
The use of AI could also potentially engage other rights and freedoms under the ECHR, including:
- Article 5 ECHR: the right to liberty and security;
- Article 9 ECHR: the right to freedom of thought, conscience and religion;
- Article 2 ECHR: the right to life; and
- Article 3 ECHR: the prohibition of torture and inhuman or degrading treatment.
Patent protection in the UK for AI technology can be obtained via the UK Intellectual Property Office (UK IPO) and via the European Patent Office (EPO). Generally speaking, the requirements to obtain a patent are similar in both cases (the invention should be new, inventive, explained in enough detail to enable the reader to implement the technology, and avoid the exclusions to patentability).
In order to obtain patent protection for AI technology the UK IPO or EPO is generally looking for a technical purpose or a technical implementation; one of these is needed to avoid exclusions to patentability set out in the UK Patents Act 1977 and the European Patent Convention. The exclusions to patentability relevant to AI technologies include mathematical methods, programs for computers and sometimes methods of doing business.
- In cases where the invention has a technical purpose it may be possible to avoid the exclusions by limiting claim scope of a patent application to a purpose considered by the patent office as being technical. Examples of technical purposes are controlling a self-driving vehicle, medical image analysis, speech recognition, detecting and mitigating a cyberattack, and many others. Note that general purpose AI technology, such as a training algorithm or an attention mechanism, is typically not considered to have a technical purpose because the purpose is considered mathematical.
- In cases where the invention has a technical implementation it may be possible to avoid the exclusions by limiting the claim scope of a patent application to algorithm details adapted to computer hardware. Examples of technical implementations are an algorithm that balances workload between a graphics processing unit and a central processing unit of a computer, and an algorithm that adjusts a word shift size to match that of a processor in a computer. Technical implementations can be useful to enable patent protection for general purpose AI technology such as a training algorithm or transformer architecture.
In the UK there has been a recent change in the law regarding assessment of patentability of AI technology due to the Emotional Perception UK Supreme Court case mentioned in Section 2.4, below. Because of the recent change the previous guidance from the UK IPO regarding examination of patent applications for AI has been withdrawn.
Copyright generally as applicable to AI works
Copyright in the UK is regulated by the Copyright, Designs and Patents Act 1988 (CDPA 1988) supplemented by relevant case law. Traditionally, UK copyright as a protectable right subsists in the expression of the relevant AI system (typically as a neural network or model represented in software), but not the underlying ideas and principles. This is challenging from a rights perspective for trained AI models which may not differ substantively from untrained models, as both will share the same physical expression, whereas the former will be considerably more valuable both from a monetary and utility perspective.
“Computer generated” works
Unusually for most jurisdictions, the CDPA 1988 makes provision in section 9(3) for the protection of works that are computer generated. At first this would seem to provide a solution to the paradox of human authorship which is required generally for copyright protection and a hurdle which purely AI generated works are unlikely to clear. However, the provision is problematic, not least because the measure was drafted well before the introduction of mainstream AI systems and also due to its vagueness. The recent case of THJ Systems Ltd v. Sheridan [2023] EWCA Civ 1354 reaffirmed that human originality was still a fundamental basic requirement of UK copyright law. The Report on Copyright and Artificial Intelligence, published by the government in March 2026, pursuant to the Data Use and Access Act, has concluded that section 9(3) be repealed.
Text and data mining exceptions
In common with the EU, the UK does not generally have a “fair use” copyright doctrine. Instead, UK law embodies the rather narrower concept of text and data mining exceptions (see section 29A, CDPA 1988). These apply in the context of research for non-commercial purposes. The UK government has vacillated on plans to broaden these exceptions to allow for a broader industry friendly rights holder “opt out” in the context of AI training (including web scraping of content). As of May 2026 it has withdrawn from this original approach in the face of intense rights holder lobbying and has now adopted a “wait and see” approach.
Database rights
Database rights in the UK protect investment in and curation (obtaining, verifying and presenting) of the data in a relevant database. They are distinct from copyright and prevent the unauthorised extraction or re-use of substantial parts of a database. These rights may be relevant to AI training datasets, but only to the extent that such datasets fall within the relevant definition of “database” (i.e. data which is arranged in a “systematic or methodical way”, see Regulation 6 of the Copyright and Rights in Databases Regulations 1997). Unlike copyright, there is no prevailing requirement of originality in such rights.
UK trade secret law is governed by a dual system of common law breach of confidence and the Trade Secrets (Enforcement, etc.) Regulations 2018. It protects commercial information, such as customer lists, technical know-how, and pricing structures. To qualify as a trade secret, information must:
- be secret;
- have commercial value because it is secret; and
- have been subject to reasonable steps to keep it confidential.
Given the difficulties articulated above in relation to other forms of IP protection, trade secrets and confidentiality have a role to play in protecting valuable AI related assets, provided they remain confidential.
The landmark High Court ruling of Getty Images v. Stability AI (2025 EWHC 38 Ch) provided some limited guidance on AI and copyright infringement and was a favourable judgement for AI providers vis-à-vis content rights holders. Getty Images, a well-known provider of stock images, alleged that Stability AI, providers of the image generating AI model Stable Diffusion, had used Getty Images-owned image data from its library of images without a valid licensing agreement, in order to train Stable Diffusion. Getty had claimed that the AI generated output of Stability’s model reproduced in substantial form its own copyrighted works. The primary copyright and database rights infringement claims were ultimately dropped at trial. In November 2025 Mrs Justice Joanna Smith held that contrary to Getty’s claim, Stable Diffusion did not store, contain or reproduce any of Getty’s copyright works. On secondary copyright infringement claims, the High Court found that the acts of importing the pre-trained Stable Diffusion model into the UK, or possessing or dealing with it in the UK, did not amount to secondary copyright infringement (sections 22 and 23, CDPA 1988). This was despite Stability AI accepting that that Getty’s copyright works were used to train the Stable Diffusion model outside the UK.
The UK Supreme Court gave their decision in Emotional Perception AI Limited (Appellant) v. Comptroller General of Patents, Designs and Trade Marks in February 2026. The case concerned patentability of AI technology used for recommending music tracks. The court re-aligned the UK test for patentability of computer-related inventions, including AI technologies, with the European Patent Office test. The case was remitted to the UK IPO to apply an intermediate step where claim features are filtered out if they do not contribute to the technical character of the claim. Only features that remain after the filtering contribute to an inventive step. The exact details of how the UK IPO will apply the intermediate step are expected to be known later in 2026 or early in 2027.
In the UK the following key laws regulate the handling of personal data, including in the context of AI technologies:
- UK GDPR. The UK’s version of the EU GDPR (Regulation (EU) 2016/679). After the UK left the EU, the EU GDPR no longer applied directly, so legislation was required to implement it into domestic law. The outcome is the UK GDPR, which has been in force since 1 January 2021. It preserves the key principles of EU GDPR and makes some adaptations to reflect the UK context.
- Data Protection Act 2018 (DPA). The DPA operates alongside the UK GDPR and adds UK-specific detail to it, including exemptions and conditions for using special categories of personal data.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR). PECR brings the EU “e‑Privacy Directive” (2002/58/EC) into UK law. It works alongside the UK GDPR and the DPA and sets out privacy rules for electronic communications services, direct marketing, and the use of cookies and similar storage and access technologies.
- Data (Use and Access) Act 2025 (DUAA). DUAA became law on 19 June 2025. It makes changes to (and adds to) the UK GDPR, the DPA and PECR. Most of its data protection and e‑privacy changes took effect on 5 February 2026, with a small number of provisions starting later in 2026.
Applicability and basic requirements
The UK GDPR applies (including in an AI context) to UK entities and in some cases, also to overseas entities. Specifically, the UK GDPR applies to:
- The processing of personal data in the context of the activities of a UK establishment of a controller or a processor.
- The processing of personal data of individuals who are in the UK, by an entity not established in the UK, where the processing is related to:
- the offering of goods or services to individuals in the UK; or
- the monitoring the behaviour of individuals within the UK.
Processors have more limited responsibilities although they are, for example, required to implement appropriate technical and organisational measures to ensure that personal data is kept secure.
Individuals have a range of rights under the UK GDPR which are broadly equivalent to those under the EU GDPR (for example, the right to access their personal data). However, from 19 June 2026, DUAA also requires that controllers have a process in place for handling complaints about breaches of the UK GDPR. This includes providing a way for individuals to complain directly to them. Controllers will be required to acknowledge complaints within 30 days and take appropriate steps to respond and provide an outcome, without undue delay.
Automated decision-making (ADM)
A key use case for AI tools is to support automated decision-making. The UK GDPR includes specific rules on decisions made solely by automated means (including profiling) using personal data, where the decision has a legal or similarly significant effect on an individual.
Before DUAA took effect, these rules were broadly aligned with the EU GDPR and were relatively strict. In practice, ADM was only permitted in limited situations, for example, where the individual had given explicit consent, or where the ADM was necessary to perform a contract between the individual and a controller.
Under DUAA, however, Article 22 of the UK GDPR has been replaced by a more flexible approach, set out in section 4A, of Chapter III, of the UK GDPR.
The practical effect is that in the UK, there are now a broader range of circumstances in which ADM can be undertaken (provided that it does not involve special category data, such as health data or biometric data used for identification). Specifically, ADM is permitted where one of the lawful bases in Article 6 of the UK GDPR applies. This includes the “legitimate interests” lawful basis under Article 6(1)(f), provided that the relevant legitimate interests are not overridden by the individual’s interests, rights or freedoms.
To protect individuals, the controller must also provide information about the ADM and allow the individual to make representations, request human intervention, and challenge the decision.
Children’s data
The Information Commissioner’s Office (ICO) has a current focus on safeguarding those most at risk from harm, including children. It has recently reviewed 34 social media and video sharing platforms focusing on issues such as the use of default privacy and geolocation settings, profiling for targeted advertising, and age assurance. This work has translated into enforcement action. Specifically, the ICO has fined two platforms (Reddit and Imgur) in February 2026 for shortcomings in their handling of children’s personal information and age assurance measures, and failure to carry out data protection impact assessments. The fines were for GBP 14.47 million (Reddit) and GBP 247,590 (Imgur).
DUAA has reinforced the UK GDPR in this respect by introducing an explicit requirement in Articles 25(1)(A) and (B) for providers of most online services (information society services) likely to be accessed by children, to take their needs into account when deciding how to use their personal data. Organisations within scope of this provision are also expected to comply with the ICO’s Age Appropriate Design Code (also referred to as the Children’s Code).
The ICO has confirmed that generative AI (GenAI) developers and deployers may fall within the scope of the Children’s Code where their system and its outputs are likely to be accessed by children under 18.
ICO Regulatory position on AI
AI is a current priority for the ICO. Its key areas of focus include generative AI, foundation models, ADM systems, AI and children, AI and online safety, police use of biometrics technologies, and recommender systems.
The current UK Government has set out its plans for facilitating access to public and private data sets to enable development of frontier AI and other AI applications in the AI Opportunities Action Plan (AI Action Plan). This includes:
- identifying at least five “high-impact” public datasets to make available for AI research and innovation;
- shaping what data is centrally collected and how, so that it is suitable for AI developers and researchers;
- developing guidelines and best practices for releasing open government datasets which can be used for AI; and
- exploring how to curate and unlock private datasets.
The government believes that these plans will be supported by a National Data Library, which the government has taken steps to establish since it was formed in July 2024.
A number of sector-specific open data initiatives are already underway, including, for example:
- National Underground Asset Register, which holds data about underground pipes and cables, was put on a statutory footing under the Data (Use and Access) Act 2025 (DUA Act);
- Health Data Research Service, launched in 2025, which is intended to be a single point of secure access to health and care data; and
- Genomics England Research Environment, which has one of the largest genomic datasets and can be accessed by academia and industry for research purposes.
In March 2026, the government published Smart Data 2035: The UK’s Smart Data Strategy (Smart Data Strategy), setting out its long-term version for smart data schemes in the UK. Smart data schemes will mandate sharing of customer data held by service providers (upon a customer’s request) with authorised third-party providers, who will then be able to use the data to provide services to customers.
In addition to UK human rights law, an important source of regulation of biometric data is UK data protection law.
Voice data
The UK GDPR imposes additional obligations on the processing of voice data to the extent that it constitutes biometric data for the purpose of uniquely identifying a person.
As noted above, the ICO has produced guidance on biometric recognition and has highlighted that voice recordings are considered highly intrusive. It has also indicated that surveillance systems should not normally be used to record conversations and that the capacity to record audio by default should be switched off with the use of such functionality requiring a much greater justification.
The ICO has previously issued an enforcement notice requiring His Majesty’s Revenue and Customs (HMRC) to delete voice pattern data of all user records collected unlawfully without valid consent to use as a means of “voice ID”. This resulted in the deletion of approximately five million records.
Facial recognition data
As in the case of voice recognition, automated facial recognition (AFR) is regulated by the UK GDPR. Such processing of biometric data for uniquely identifying a person is classified as the processing of special category data under the UK GDPR and so subject to additional obligations.
As noted in Section 1.2, above (human rights decisions and conventions), the use of AFR was considered in-depth by the Court of Appeal in R (Bridges) v. Chief Constable of South Wales Police [2020] EWCA Civ 1058. In addition to its findings in respect of human rights law summarised in Section 1.2 above, the Court of Appeal also found that the data protection impact assessment (DPIA) undertaken to assess and mitigate the risks associated with the use of AFR in that case was deficient in that it failed to adequately consider the issues with Article 8 ECHR arising and failed to address relevant deficiencies as required by data protection law. Following the judgment, the ICO issued further guidance on the use of AFR, including in respect of DPIAs, the lawfulness of processing, fairness and transparency and data minimisation.
In May 2022, the ICO imposed a fine of GBP 7.5 million on Clearview AI (a US-based company) for using images of individuals in the UK scraped from the web and social media to create a global online database that could be used for facial recognition by law enforcement and other organisations and an enforcement notice ordering the company to stop processing and to delete such data. Clearview contested the ICO’s enforcement action. In the latest ruling on the case, the Upper Tribunal determined that Clearview’s processing of personal data was related to the monitoring of the behaviour of individuals in the UK and did not fall outside the scope of UK data protection law (The Information Commissioner v Clear AI Incorporated [2025] UKUT 319 (AAC)). The case is ongoing as in December 2025 Clearview was granted permission to appeal the decision to the Court of Appeal.
Bias and discrimination
The deployment of artificial intelligence in decision-making processes raises significant concerns about the perpetuation and amplification of bias and discrimination. AI tools are often trained on datasets that may reflect historical inequalities or societal prejudices, and the design choices embedded in their architecture can further entrench unfair outcomes. Where systems are used to make or inform decisions affecting individuals (for example, in recruitment, service delivery, benefits administration, or performance management) there is a risk that certain groups will be treated less favourably on grounds related to protected characteristics. The distinction between bias and discrimination is an important one: bias is a systemic tendency within a decision-making process, whether human or automated, whereas discrimination refers to the adverse and unlawful effects that flow from it.
Domestic anti-discrimination and equality legislation treatment
The principal legislative framework governing discrimination in the UK is the Equality Act 2010 (the “Equality Act”), which provides comprehensive protections against direct and indirect discrimination, harassment, and victimisation across a range of protected characteristics including age, disability, gender reassignment, race, religion or belief, sex, and sexual orientation. These protections apply irrespective of whether a decision is made by a human being or by an automated system and extend beyond the employment context to the provision of goods, services, and public functions — meaning organisations using AI in customer-facing or general public facing decision-making are exposed to liability.
Direct discrimination
In the AI context, direct discrimination may arise where a system applies explicitly biased rules or relies on proxy variables that effectively serve as substitutes for a protected characteristic (for example, using postcode data that closely correlates with ethnicity to filter applicants or determine service eligibility).
Indirect discrimination
In practice, however, indirect discrimination is likely to present the more prevalent risk. Here we would be dealing with AI models built on ostensibly neutral criteria, but which nonetheless produce outcomes that disproportionately disadvantage particular protected groups. The risk is further compounded by intersectional effects, where multiple protected characteristics interact to produce patterns of disadvantage that may not be visible when each characteristic is considered in isolation. Employers, service providers, and public bodies bear responsibility for discriminatory outcomes generated by AI tools they choose to deploy — even where those tools are developed or supplied by third parties.
Duty to make reasonable adjustments
The Equalities Act also imposes an anticipatory and reactive duty to make reasonable adjustments to prevent disabled persons from being placed at a substantial disadvantage, a duty which extends to ensuring that AI-driven processes provide accessible alternatives and do not disadvantage individuals on account of their disability. Where an AI-driven process places a disabled person at a substantial disadvantage in comparison with persons who are not disabled, employers and service providers are under a duty to take such steps as are reasonable to avoid that advantage.
Relevant UK case law
Questions of legal liability in AI-related discrimination cases are inherently complex, spanning the roles of system developers, deployers, data controllers, and commissioning bodies. The case of Manjang v. Uber Eats UK Ltd illustrates the practical consequences of these issues. In that matter, the claimant alleged that AI-powered facial recognition checks were racially discriminatory and that software performed less effectively for individuals from ethnic minority backgrounds. The case highlighted not only the potential discriminatory impact of the technology itself, but also the absence of meaningful human oversight or accessible routes to challenge automated decisions — deficiencies criticised by the Equality and Human Rights Commission.
The UK does not have AI-specific cybersecurity legislation. Instead, a patchwork of existing and forthcoming cyber laws, regulations, and guidance applies to the security of AI systems. Key rules that have a broad application are referenced below. However, additional requirements also apply on a sector-specific basis, for example to telecommunications providers and in respect of financial services and trust services.
The UK GDPR and the DPA impose the broadest layer of cybersecurity obligation, requiring controllers and processors of personal data to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks to such data. Given that many AI systems involve the processing of personal data, this is a key obligation to consider when using such systems.
The Network and Information Systems (NIS) Regulations 2018, implementing the EU’s NIS Directive, impose cybersecurity requirements to improve the resilience of the UK’s critical national infrastructure, covering operators of essential services (in sectors such as energy, transport, health, and digital infrastructure) and relevant digital service providers. Regulated entities must take appropriate and proportionate technical and organisational measures to manage risks to the security of their network and information systems, including AI systems deployed within them.
The UK Government’s Cyber Security and Resilience Bill (CSRB), introduced in 2025, will significantly update the NIS Regulations. Key proposed changes include:
- expanding the scope of regulated entities, bringing managed service providers and data centres within the regime;
- strengthening incident reporting requirements; and
- granting regulators enhanced powers to set and enforce cybersecurity standards.
With the NIS Directive in Europe having been re-formulated in 2023 under the new NIS 2 Directive, there is now increasing divergence between the UK and EU’s cybersecurity regimes for critical national infrastructure, although generally common measures can be implemented which fulfil the requirements of both regimes.
AI also intersects cybersecurity legislation, which is applicable in more specific circumstances, as follows:
- The National Security and Investment Act 2021 gives the government powers to scrutinise and intervene in foreign investments that may pose risks to national security. AI (and specifically its application to cybersecurity) is one of the 17 sensitive sectors in which the acquisition of a qualifying entity or asset must be notified to the Investment Security Unit in the Cabinet Office before completion.
- The Product Security and Telecommunications Infrastructure Act 2022 imposes minimum security requirements (such as bans on default passwords) in respect of internet-connectable consumer products. AI-enabled consumer devices (such as smart home products and wearables) will generally fall within scope.
The UK’s Competition and Markets Authority (CMA) has been engaging extensively on AI, making it clear that it is prepared to use its full toolkit to address any anti-competitive scenarios in AI markets. It has been shaping its approach to the adoption of AI across different industries, sectors and business models understanding its impact on competition and markets. Given the cross-border nature of AI, the CMA has also collaborated heavily with other international competition authorities.
Significantly, the CMA has embraced new powers under the Digital Markets, Competition and Consumers Act 2024 (DMCCA). These include direct enforcement powers in relation to consumer protection law and the new UK digital markets regime to regulate large tech companies — similar to the EU’s Digital Markets Act (DMA).
Algorithmic collusion
AI can be used by algorithms to enable more price transparency and high-frequency trading. Deep learning techniques based on AI can also be used to monitor prices, implement common policies, send market signals or optimise joint profits. As well as being pro-competition, these tools can also risk facilitating collusion between competitors.
Following publication of guidance on “pricing algorithms and competition law”, the CMA has been actively reminding industry that competition law fully applies to AI-driven practices. This guidance illustrates how automated pricing tools can inadvertently or deliberately facilitate price-fixing or information sharing between competitors, citing a case where two online sellers used software to avoid undercutting each other’s prices (resulting in CMA fines and a director’s disqualification).
The CMA is increasingly using AI and data science in its own enforcement toolkit, deploying its own in-house AI capabilities to monitor markets. This includes using machine learning to detect cartel activity in bidding markets.
In March 2026, the CMA launched an investigation into the suspected sharing of competitively sensitive information among rival hotel chains Hilton, IHG Hotels and Marriott. The case centres on the alleged use of STR, a data analytics tool, to exchange information that could distort competition by reducing the uncertainty companies would ordinarily face regarding their competitors’ conduct.
Abuse of dominance
Companies in a dominant position have a special responsibility not to use AI in a manner that risks distorting competition. For instance, competition is likely to be harmed where a dominant platform’s algorithms favour its own products and services over those of rivals. This may have the effect of promoting the dominant company’s products or services such that it does not need to compete on its own merits. Google is currently engaged in several abuse of dominance proceedings raising such concerns.
Dominant players may also have an advantage if their size gives them access to larger data pools than those of their competitors. In digital markets, the user data that certain players have access to, often combined from multiple channels, power the AI systems which deliver targeted advertising. This data, to which competitors do not have access, is a key barrier to competition for challenger players trying to compete with the larger firms. It is expected that future UK legislation will seek to tackle this problem.
Consumer protection
The DMCCA gives the CMA enhanced powers to regulate digital markets and enforce consumer law in the same way that it enforces competition law. Current CMA enforcement priorities involving conduct based on AI include:
- Personalised pricing. Algorithmic systems enable companies to offer different prices to different customers depending on the information they hold about them, for example offering higher renewal prices to customers identified as being more likely to renew with the same company. This “personalised pricing”, if directed at consumers, may infringe the DMCCA if it misleads consumers or involves a breach of professional diligence.
- Dark patterns. “Dark patterns” are online choice architecture features that are designed to influence users into making commercial decisions (e.g. buying or signing up) to their detriment. For example, using AI systems to target users with messaging designed to create a false sense of urgency (e.g. stating that there is only limited availability). The CMA has already used its new DMCCA powers to investigate whether Appliances Direct and Wayfair ended time-limited sales when they said they would.
- Personalised search rankings. Personalised search rankings (where algorithmic systems facilitate preferences for particular services, products or suppliers) may potentially lead to negative outcomes for consumers by manipulating their decision-making. Personalised rankings based on protected characteristics (e.g. age, disability, sex or race) could amount to unlawful discrimination and breach equality legislation.
Merger control
The CMA has used its merger control powers to examine a number of deals between major tech companies and target companies active in AI. Such types of deals, which previously often fell outside the scope of the UK merger regime due to the target’s low UK turnover/market share, were the principal reason for the introduction of the new acquirer-focused merger control threshold that came into force in January 2025. This new threshold is satisfied where one party has a ≥33% share of supply and a UK turnover exceeding GBP 350 million, thereby capturing transactions where major tech companies invest in innovative AI companies.
The CMA has recently looked at three prominent acquisitions of small AI companies by large tech companies: Microsoft’s stake in Mistral AI, Amazon’s investment in Anthropic, and Microsoft’s partnership with Open AI. In all three cases, the CMA found the transactions did not qualify for investigation on the basis that they did not constitute “relevant merger situations” under the merger control rules. In another recent case, involving Microsoft’s hiring of key staff from Inflection AI, the CMA concluded that it did not appreciably reduce competition in foundation model or AI chatbot development, partly because Inflection AI was not yet a significant competitor and strong competition remains. While the CMA did not identify any immediate threats to competition, it is clear that the CMA will review even minority investments or partnerships in the AI sector if there’s potential to stifle competition.
Private enforcement
The UK courts are seeing increasing numbers of cases involving companies active in AI. For example, in Ad Tech Collective Action LLP v. Google, the upcoming trial will determine whether programmatic advertising algorithms favoured Google’s own ad exchange. Similarly, in Foundem (Infederation) v. Google & Others, the core allegation is that search engine ranking algorithms systematically down-ranked competitors.
There is no specific UK legislation that regulates AI from a competition/antitrust perspective. The use of AI is, however, subject to compliance with UK competition law rules (as explained above).
New digital markets regime (ex ante regulation)
The main development in domestic antitrust regulation relevant to AI is the implementation of the new digital markets regime introduced by the DMCCA. This establishes an ex ante regulatory regime under which the CMA can designate firms as having “Strategic Market Status” (SMS) and impose tailored conduct requirements and pro-competition interventions on them.
Agentic AI is artificial intelligence, often powered by discrete GenAI models such as GPTs (generative pre-trained transformers), that executes workflows and tasks. Unlike generative AI systems which are largely passive in nature, agentic AI is often characterised by interaction and data exchange with other third-party systems. Note that AI agents are not the same as agentic AI:
- Agents are generally the individual elements within an agentic platform and confusingly can be themselves generative AI systems (note, however, the tendency in the market to use terms such as agent and agentic interchangeably).
- Agentic AI typically deploys an orchestration layer to co-ordinate multiple AI agents (roughly analogous to a conductor of an orchestra). Orchestration layers (or orchestrators) may also themselves constitute GenAI models. The orchestrator determines how individual agents interact with each other to achieve the requested goal. Note that this process is not the same as automation — orchestration involves a high degree of non-linear concurrent activity.
The UK does not recognise AI agents as having any form of legal personality, capacity to enter contracts or ability to act on behalf of principals. In this regard, there is no difference in the legal treatment of AI agents vis-à-vis generative or discriminative AI systems. The Law Commission’s document, AI and Autonomous Systems 2023–2024, rejects granting AI legal personality. The House of Commons research briefing of 31 March 2026, AI Regulation in the UK, explains that the UK does not have any AI-specific regulations or legislation covering AI as a technology.
In the March 2023 UK Government white paper, A pro-innovation approach to AI regulation, it is explained that AI will be overseen by sector-specific regulators such as Ofcom, Ofgem, the Financial Conduct Authority (FCA) and others.
The March 2023 white paper sets out five cross-sector principles for the sector specific regulators to apply; see Section 9.2, below.
While agentic AI is not specifically mentioned in the 2023 white paper, sector specific regulators are expected to apply these five cross-sector principles to agentic AI used in their sectors.
The Law Commission is currently reviewing the law relating to liability for defective products, considering the operation of the existing product liability regime (including in relation to AI) and whether it is fit for purpose. That review is anticipated to include a public consultation on proposed reforms in the second half of 2026.
A consultation is also being conducted by the UK Jurisdiction Taskforce on its draft Legal Statement on Liability for AI Harms under the private law of England and Wales. That consultation has now closed and the results are being considered, following which it is anticipated that a final version of the Legal Statement will be published.
Section 2(1) of the Consumer Protection Act 1987 (the “CPA 1987”) provides strict liability in circumstances where damage is caused wholly or partly by a defect in a product. A product is defined at section 1(2) of the CPA 1987 as “any goods or electricity”. In the circumstances, the CPA 1987 only applies to goods that are physical assets such that freestanding computer programs (and by analogy AI systems) are not included under the strict liability regime. To the extent that an AI system is incorporated into a physical product and that product fails due to the AI system, liability may arise under the CPA 1987.
Where a user suffers harm as a result of a failure of an AI system, assuming a contract has been entered into between the user and the supplier of the AI system, that user may have a claim for breach of contract against the supplier. The availability of such a claim will depend on the contract itself which will likely deal with allocation of risk, contain warranties in respect of performance, include provisions on the limitation of liability, etc. If a breach of contract has occurred, the general rule is that damages for breach of contract compensates the injured party (i.e. they should be put in the same position as if the contract had been performed).
An alternative basis for any claim would be in the tort of negligence. To bring a claim in negligence a party needs to establish:
- the presence of a duty of care;
- the relevant standard of care;
- that there has been a failure to meet that standard of care;
- that the negligence caused the loss; and
- that the loss was sufficiently foreseeable that the law permits recovery.
Whether a duty of care arises in a specific scenario is a matter of fact. Note that pure economic loss is not recoverable unless the defendant owed a duty to the claimant not to cause the claimant to sustain purely economic loss.
The Online Safety Act 2023 imposes a duty of care on services that host user-generated content, services that facilitate online interaction between social media providers and search engines to prevent the proliferation of illegal content and activity online. Where such services incorporate the use of AI systems, the duty of care will include those systems. While the duties owed under the Online Safety Act are not directly enforceable by an individual, breach of the same (and any enforcement action taken by OFCOM) could be advanced as evidence of a breach of the duty of care in a claim for negligence against such a platform relating to their use of AI systems.
As set out above, section 2(1) of the CPA 1987 only applies to the extent that an AI system is incorporated into a physical product in circumstances where the relevant AI system causes that product to fail, liability may arise.
The General Product Safety Regulations 2005 (SI 2005/1803) (GPSR) implement into English law the EU General Product Safety Directive (2001/95/EC). Regulation 5 of the GPSR provides that a producer is not to offer, supply, offer or agree to supply, place on the market, or offer or agree to place on the market a product unless the product is a safe product.
“Product” is defined under Regulation 2 of GPSR as a product which is intended for consumers or likely, under reasonably foreseeable circumstances, to be used by consumers and which is supplied or made available in the course of a commercial activity, whether new, used or reconditioned and includes a product that is supplied or made available to consumers for their own use in the context of providing a service. This definition is broader than that under the CPA and not specifically limited to goods. In the circumstances, while yet to be tested in English case law, it is possible that this definition could capture both free-standing AI systems as well as AI systems incorporated into physical goods.
A “safe product” is defined in Regulation 2 of the GPSR to be a product which under normal or reasonably foreseeable conditions of use, including duration and, where applicable, putting into service, installation and maintenance requirements, does not present any risk or only the minimum risks compatible with the product’s use, considered to be acceptable and consistent with a high level of protection for the health and safety of persons.
To the extent a product is not a safe product, as set out above, Regulation 5 prohibits such product being offered, supplied or placed on the market. Regulations 7–9 of the GPSR provide for the steps that should be taken by producers and/or distributors in respect of such products including withdrawing or recalling such products, warning consumers and notifying the enforcement authority in writing.
To date, there have been no significant cases within the UK relating to AI product liability.
At the time of writing, there is no general purpose, cross-sectoral AI legislation in the UK (like the EU AI Act, for example). The UK’s existing legal framework applies to AI. To date, the government has continued with the approach set by the previous government, which is to require UK regulators to develop sector-specific guidance that applies their existing regulatory framework to the deployment of AI in their sector (for further details, see Section 9.2, below).
New, targeted AI legislation is, though, being considered or has been introduced in the following areas:
- Regulatory sandboxing. The May 2026 King’s Speech introduced a Regulating for Growth Bill, which will create an AI Growth Lab. This in turn will support a framework for AI “sandboxes”, controlled environments where AI innovation can be fostered and specific regulatory requirements relaxed on a temporary basis. This represents a pivot by the current UK Government away from original plans to implement AI-specific legislation (the previous policy was to implement legislation to regulate very powerful GenAI models).
- AI training and copyright. More recently, the government carried out a copyright and AI consultation on potential changes to copyright law, including to reform the area of copyright and AI training. The consultation sought views on the government’s policy options to address challenges to copyright laws from the widespread use of copyright material for training AI models, and the difficulty rights holders have found in exercising their rights in this context. Following the consultation, on 18 March 2026 the government published a full report and economic impact assessment. The report states that, for now, the government does not plan to introduce a new data mining exception, and it proposes to work with industry to develop best practice on input transparency to help rights holders assert their rights.
- AI and data. The DUA Act has recently introduced reforms to UK data protection law in the UK that are widely seen as being AI-friendly. This includes expanding the circumstances in which decisions can be made based solely on automated processing of personal data, clarifying that “scientific research” can include commercial research and processing for technological development, and allowing broad consent to processing for the purpose of scientific research.
- AI and deepfakes. The DUA Act amends the Sexual Offences Act 2003 (SOA) to introduce new offences for creating, or requesting the creation of, the purported intimate image of an adult without their consent. The recently enacted Crime and Policing Act 2026 (CPA) also amends the SOA and introduces a ban on making or supplying any tool for the purpose of creating intimate images (so-called “nudification” apps, which are typically AI-powered) and place new duties on online platforms to ensure such images are taken down within 48 hours of being reported.
- GenAI and AI chatbots. Following concerns that UK law does not adequately regulate all forms of AI chatbot, the CPA amends the Online Safety Act 2023 and provides the government with the power to address harms to individuals from illegal AI-generated content (online) and the use of online GenAI services.
- AI and medical devices. The government is considering new proposals for regulating medical devices that use AI. The government has established the National Commission into the Regulation of AI in Healthcare to support this goal. The National Commission is a cross-sector body of experts that look at how AI should be regulated and give recommendations to the Medicines and Healthcare products Regulatory Agency (the UK regulator for medicines, medical devices, and blood products), which are due to be published in 2026.
With respect to the introduction of new, general AI legislation, the government has continued with the strategy set by the previous government, which is to require regulators to develop sector-specific regulatory guidance that applies their existing regulatory framework to the deployment of AI in their sector. This approach was first set out by the previous government in its AI white paper, published in March 2023, A pro-innovation approach to AI regulation (AI White Paper). The AI White Paper introduces the following five, non-statutory AI principles, to be implemented by the UK’s sector regulators:
- safety, security and robustness;
- appropriate transparency and explainability;
- fairness;
- accountability and governance; and
- contestability and redress.
In November 2024, the current government endorsed this sector-led approach and committed itself to a “pro-innovation” strategy, with regulators addressing AI risks in their sectors.
In July 2024, the government published its AI Action Plan, which it says is a plan to make the UK “an AI superpower”. The AI Action Plan sets out how the UK Government intends to “ramp up” AI adoption to boost economic growth, provide jobs for the future and improve everyday lives. It hopes to accomplish this by achieving three goals:
- world-class AI infrastructure, talent and regulation;
- rapid AI adoption in the public and private sectors; and
- positioning the UK as being the best partner to those building frontier AI.
Building on the AI Action Plan, in June 2025 the government published its Modern Industrial Strategy (“Industrial Strategy”) which sets out a number of government “interventions” for delivering its AI ambitions. These include strengthening the UK’s position as a global hub for AI R&D, maximising the UK’s stake in frontier AI through the creation of a new Sovereign AI Unit (which was launched in April 2026, and is set-up to invest GBP 500 million in British AI startups), delivering an AI and copyright framework that supports AI development in the UK (for the latest on that, see Section 9.1, above), promoting AI adoption, and accelerating AI-enabled scientific breakthroughs.
Following the AI Action Plan and Industrial Strategy, the government has published a number of papers that further outline policy in priority areas:
- In July 2025, the government published the UK Compute Roadmap, which sets out a 10-point plan for delivering the infrastructure for supporting an AI-enabled economy.
- In November 2025, the government published Delivering AI Growth Zones, which sets out its strategy for creating “AI Growth Zones” (i.e. AI data centre capacity), and published its AI for Science Strategy, which aims to develop frontier capability in AI-driven science, and to maintain the UK’s “position of global scientific leadership” through the integration of AI into science.
- In April 2026, the government announced that it will develop a UK AI hardware plan to secure capability in chips and the semiconductor technologies that underpin the full AI hardware stack.
Does the UK have a dedicated AI law equivalent to the EU AI Act, and how is AI currently regulated?
No. As at the time of writing, the UK has no general-purpose, cross-sectoral AI legislation comparable to the EU AI Act. Instead, the UK applies its existing legal framework to AI and relies on a sector-led approach in which existing regulators develop guidance applying their regulatory remits to AI deployments in their respective sectors. This approach is underpinned by the five non-statutory cross-sector principles first articulated in the March 2023 AI White Paper, A pro-innovation approach to AI regulation. The current government has endorsed this pro-innovation, sector-led strategy and has pivoted away from earlier plans to introduce dedicated legislation for very powerful GenAI models. The May 2026 King’s Speech instead introduced a Regulating for Growth Bill, which will establish an AI Growth Lab to support regulatory “sandboxes”.
What changes has the Data (Use and Access) Act 2025 introduced for automated decision-making (ADM) using AI?
The DUA Act has materially liberalised the UK’s approach to automated decision-making, in what is widely regarded as an AI-friendly reform. Under the DUA Act, Article 22 has been replaced by a more flexible regime set out in section 4A of Chapter III of the UK GDPR. ADM is now permitted wherever any of the lawful bases in Article 6 of the UK GDPR applies — including the “legitimate interests” basis under Article 6(1)(f), provided those interests are not overridden by the individual’s interests, rights or freedoms. The principal exception is that this broader permissibility does not extend to ADM involving special category data (such as health data) or biometric data used for identification, where stricter conditions continue to apply.
Do AI agents have legal personality or authority to act on behalf of users in the UK?
No. The UK does not recognise AI agents as having legal personality, legal capacity to enter contracts, or authority to act on behalf of a principal in their own right. The chapter makes clear that, in legal terms, AI agents are not treated differently from other AI systems merely because they appear autonomous or are capable of interacting with third-party systems.
How does UK law regulate AI-generated deepfakes and harmful AI chatbot content?
While the UK does not yet have a general AI statute, targeted legislative reforms are being introduced to address specific AI-related harms. In particular, the Data (Use and Access) Act 2025 has amended the Sexual Offences Act 2003 to create new offences relating to the creation, or requesting the creation, of purported intimate images of adults without consent. The Crime and Policing Act 2026 goes further by banning the making or supply of tools intended to create intimate images, including so-called “nudification” apps, and by imposing new duties on online platforms to ensure that such images are taken down within 48 hours of being reported. In addition, the same Act amends the Online Safety Act 2023 to give the government powers to address harms arising from illegal AI-generated content online and the use of online generative AI services, including AI chatbots.
Can AI inventions be patented in the UK?
Yes, AI-related inventions can be patented in the UK, but patentability depends on how the invention is characterised. In general, the UK Intellectual Property Office and the European Patent Office look for either a technical purpose or a technical implementation in order to avoid exclusions from patentability, such as mathematical methods, computer programs as such, and certain business methods.
Inventions with a technical purpose may include applications, such as medical image analysis, speech recognition, cyberattack detection or control of autonomous systems. However, general-purpose AI advances, such as training algorithms or attention mechanisms, may face more difficulty unless the claims are framed around a technical implementation adapted to computer hardware.
Our deepest thanks go to the additional CMS experts and authors of the UK chapter whose contributions could not regrettably be separately identified due to space constraints: Sarah Wright, Laura Clarkson, Joanna Willems, Rob Grant, Ruth Derruau, Stephanie Woods and Jack Rigelsford.