UK AI law basics relevant to small businesses

A woman in her forties sitting at a kitchen table reading printed notes next to an open laptop, mug of tea beside her
TL;DR

The UK does not yet have a single AI Act. For small service firms the binding rules are UK GDPR, the Equality Act, sector regulators like the FCA, and the five government AI principles, all enforced by existing bodies. The practical job is a short tool register, a clear lawful basis, a named owner, and honesty with staff and clients.

Key takeaways

- There is no standalone UK AI Act in 2026, but UK GDPR, the Equality Act 2010, and sector regulators already apply to AI you use. - The ICO can fine up to £17.5m or 4% of global turnover for serious UK GDPR breaches involving AI processing. - Article 22 of UK GDPR restricts decisions made solely by automation that have legal or similarly significant effects on a person. - A tool register, a written lawful basis, a named AI owner, and a privacy notice update covers most of what regulators expect from a small firm. - If you sell into the EU, the EU AI Act can apply to you even if your firm is UK-based, so check scope before assuming you are out.

A founder I spoke with last month had spent an afternoon Googling “UK AI law” before our call. She came in convinced she needed a six-figure legal review before her team could keep using ChatGPT and a transcription tool. She runs a fifteen-person consultancy. By the end of the call she had a one-page register, a named owner, and a privacy notice tweak. That was the work. The panic was the expensive part.

The reason that confusion is so common is that the answer is not where founders expect to find it. There is no single UK AI Act sitting on a shelf. What you actually have to comply with is already familiar, just applied to a new kind of tool. This piece walks through what UK AI law really is in 2026, when it bites for a small service firm, and what to do about it before the next round of regulator activity.

What does UK AI law actually look like in 2026?

The UK does not have a single AI Act yet. The government’s March 2023 white paper set five cross-sector principles that existing regulators are expected to apply within their own rulebooks: safety, transparency, fairness, accountability, and contestability. Bodies like the ICO, FCA, CMA, and Ofcom are now embedding those principles into rules they already enforce. The result is a patchwork, not a single statute.

That means there is no AI-specific licence to apply for, no AI register to file with a central body, and no separate AI inspector who turns up at your door. The relevant law for a small service firm is the law you already have. UK GDPR. The Equality Act 2010. Sector conduct rules if you are in financial services, healthcare, or another regulated field. The five AI principles are the lens regulators now use when they apply those existing powers to AI tools you bring into your business.

The government has reserved the option to introduce binding AI legislation if this approach proves insufficient. That moment may come, particularly if a major AI-driven discrimination case or safety failure forces it. For now, treating UK AI law as “existing law applied carefully to AI” is the accurate reading.

When do these rules actually bite for a small firm?

The trigger small firms hit first is UK GDPR. The ICO defines personal data broadly, so anything that can identify a person counts: names, emails, IP addresses, client records, call transcripts, CVs. The moment a tool processes that kind of data, UK GDPR applies, regardless of the size of your business. ChatGPT used on client emails, an AI screening service running CVs, or a transcription tool handling call recordings all qualify.

A higher-risk trigger is Article 22, which restricts decisions made solely by automation when those decisions have legal or similarly significant effects on a person. Automated credit scoring, fully automated rejection of job applicants, and purely automated disciplinary outcomes all fall under it. The default position is that individuals have a right not to be subject to such decisions unless specific conditions apply, and even then they must get human review and a route to contest. For a typical small consultancy this is rarely an issue, because humans are still in the loop. For anyone running automated screening or scoring, it is the rule to study first.

Equality law applies too. Biased AI outputs that result in less favourable treatment of someone with a protected characteristic can breach the Equality Act 2010, regardless of whether an AI-specific rule was breached. Employment lawyers have flagged AI-assisted recruitment tools as a particular risk for indirect discrimination if they are not tested and monitored.

What can it actually cost to get this wrong?

The ICO can fine up to £17.5 million or 4% of global annual turnover, whichever is higher, for serious UK GDPR breaches. That ceiling catches founders by surprise because it scales with turnover, not firm size. The British Airways breach in 2020 produced a £20 million fine after about 400,000 customer records were exposed. Marriott was fined £18.4 million the same month after a breach affecting 339 million guest records globally.

Neither was an AI case, but the same standards apply to AI tools that process personal data. The cost question is also wider than fines. Large clients, insurers, and lenders are starting to ask for documented AI governance, data protection impact assessments, and security certifications as a condition of doing business. Even where the law itself is light for a firm of your size, your clients may demand more. An employment tribunal claim under the Equality Act over an AI-assisted hiring decision can also land before any regulator gets involved.

There is also the EU angle, which catches a meaningful share of UK firms by surprise. The EU AI Act applies to AI systems placed on the EU market or whose outputs are used in the EU, regardless of where the provider is based. Fines for serious breaches can reach €35 million or 7% of global turnover. If your firm sells SaaS, services, or data-driven products into the EU, you may already be in scope.

What should a small firm actually do this month?

Four moves cover what UK regulators expect from a firm under fifty staff. First, write a one-page register of every AI tool in use, what data it touches, and what decisions it influences. Copilot, ChatGPT, the transcription tool, the chatbot on your website, the booking assistant. This single document is the artefact most-often-asked-for in any governance conversation, and it is the cheapest to produce.

Second, confirm and write down your lawful basis for using personal data in each tool. For a typical small service firm this will be legitimate interests or contract performance, occasionally consent. Avoid pasting confidential client material into third-party AI tools without checking the data processing terms, particularly around whether your inputs are used to train the provider’s models. OpenAI, Anthropic, Google, and Microsoft all publish current terms that say what happens to API and enterprise inputs.

Third, name one senior person as the AI owner. This is the accountability principle made concrete. It does not need to be a dedicated role, and for a small firm it usually sits with the operations director, the founder, or a partner. The point is that one person knows what tools are in use, what data they touch, and what to do if something goes wrong. Fourth, update your privacy notice to explain AI-related processing where AI meaningfully influences a decision about a person. Pricing, eligibility, screening, prioritisation: anywhere AI shapes the outcome that a customer or staff member experiences.

Where could this tighten quickly, and what should you watch?

The UK government has explicitly reserved the right to introduce binding AI legislation if the regulator-led model proves insufficient. The trigger is likely to be a high-profile incident, a major AI-driven discrimination case, or a sustained public backlash. If that happens, the gap between today’s light-touch posture and a stricter regime will close quickly, and firms that already have the four basics in place will adjust easily.

The other change to watch is the EU AI Act phasing in through 2025 and 2026. Its risk-based obligations apply to providers and deployers of high-risk systems, and its reach extends to UK firms serving EU customers. Even outside formal law, customers and insurers will increasingly ask for evidence of AI governance as part of procurement, particularly in regulated sectors. The direction of travel is towards more documentation and more named accountability, not less.

The honest read on UK AI law in 2026 is that it is largely existing law applied with new attention. The work for a small service firm comes down to making sure the basics of UK GDPR, equality, and sector conduct are actually being applied to the tools you have brought into the business in the last eighteen months. If you have not done a tool register yet, that is where to start. If you would like a second pair of eyes on what your firm should actually do, Book a conversation.

Sources

- UK Government (2023). AI regulation: a pro-innovation approach (white paper and 2024 response). The five UK AI principles and the regulator-led model that frames everything below. https://www.gov.uk/government/publications/ai-regulation-a-pro-innovation-approach - Information Commissioner's Office. Artificial Intelligence: UK GDPR guidance for AI. The ICO's primary guidance for organisations using AI with personal data, including lawful basis, fairness, and Article 22. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/ - Information Commissioner's Office and The Alan Turing Institute (2020). Explaining decisions made with AI. The reference document for how UK organisations are expected to explain AI-assisted decisions. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/explaining-decisions-made-with-artificial-intelligence/ - Information Commissioner's Office (2020). British Airways fined £20m for data breach affecting more than 400,000 customers. Reference case for the ICO's posture on security and accountability around personal data. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2020/10/british-airways-fined-20m-for-data-breach/ - Information Commissioner's Office (2020). Marriott International Inc fined £18.4m. Companion reference case on due diligence in complex IT environments. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2020/10/marriott-international-inc-fined-184m/ - Competition and Markets Authority (2023). AI Foundation Models: initial report and 2024 update. The CMA's view on competition risk in the AI supply chain that small firms depend on. https://www.gov.uk/government/publications/ai-foundation-models-initial-review - National Cyber Security Centre. The cyber security of AI. NCSC guidance on the cyber hygiene small firms need around AI tools, used in the security section. https://www.ncsc.gov.uk/collection/the-cyber-security-of-ai - Acuity Law (2025). Global AI regulation: a practical guide for UK businesses. UK legal commentary on the EU AI Act's extraterritorial reach for UK firms serving the EU market. https://acuitylaw.com/global-ai-regulation-uk-businesses-2025/ - GDPRLocal. UK Artificial Intelligence Regulation: complete guide for businesses. Practical SME-focused compliance framing used for the four-step action set. https://gdprlocal.com/uk-artificial-intelligence-regulation/ - European Parliament (2023). EU AI Act: first regulation on artificial intelligence. Reference for the risk-based EU regime and the fine ceiling that can apply to UK firms in scope. https://www.europarl.europa.eu/news/en/headlines/eu-affairs/20231201STO12410/eu-ai-act-first-regulation-on-artificial-intelligence

Frequently asked questions

Does the UK have an AI law for small businesses in 2026?

No single AI Act exists yet. The government's pro-innovation white paper from March 2023 set five principles that existing regulators apply within their own rulebooks. For a small service firm, the binding law you actually have to comply with is UK GDPR, the Equality Act 2010, and any sector rules you already follow, such as FCA conduct rules if you are in financial services.

When does UK GDPR apply to AI tools we use?

Whenever the tool touches personal data, which the ICO defines broadly as anything that can identify a person. That includes client emails fed into ChatGPT, CVs into a screening tool, call recordings into a transcription service, or customer records into a chatbot. The size of your firm does not change this. You need a lawful basis, data minimisation, security, and a way to respect data subject rights.

What should a small firm actually do this month?

Four things. Write a one-page register of every AI tool in use and what data it touches. Confirm a lawful basis for each. Name one person at senior level as the AI owner. Update your privacy notice if AI meaningfully influences any decision about a person. That covers what UK regulators are looking for from a firm your size in 2026.

This post is general information and education only, not legal, regulatory, financial, or other professional advice. Regulations evolve, fee benchmarks shift, and every situation is different, so please take qualified professional advice before acting on anything you read here. See the Terms of Use for the full position.

Ready to talk it through?

Book a free 30 minute conversation. No pitch, no pressure, just a useful chat about where AI fits in your business.

Book a conversation

Related reading

If any of this sounds familiar, let's talk.

The next step is a conversation. No pitch, no pressure. Just an honest discussion about where you are and whether I can help.

Book a conversation