Artificial intelligence | UK Regulatory Outlook September 2026
Published on 28 September 2026
UK updates: ICO explores viability of a data protection regulatory sandbox for testing emerging technologies, including AI | Facial recognition in policing: ICO audit findings and recommendations | National Cyber Security Centre shares initial practical advice on managing agentic AI cyber risk | Government seeks views on how AI could transform the energy system | EU updates: AI Office and national authorities begin enforcing EU AI Act | Standardisation bodies publish first standard under the EU AI Act
UK updates
ICO explores viability of a data protection regulatory sandbox for testing emerging technologies, including AI
The Information Commissioner's Office (ICO) has published findings from its research into the viability of a data protection Statutory Regulatory Sandbox (SRS). The SRS would provide innovators with time-limited derogations from certain aspects of data protection law, under ICO oversight, enabling them to test emerging technologies and applications including AI, and automated decision-making use cases.
The ICO recommends that the power to create the SRS be established through primary legislation, which would define the ICO's role in its operation and governance, set out where derogations could be made, and criteria for participant selection. Detailed operational requirements would be set out in secondary legislation.
The regulator states that the government will need to consider protections for participants and the public, including shielding participants from possible civil claims arising from SRS testing and ensuring appropriate oversight and safeguards in respect of individuals' personal information. It also recommends legislative protections for children and clear transparency requirements.
The ICO hopes that these findings will inform policy development as the government progresses the forthcoming Regulating for Growth Bill and the AI Growth Lab.
Facial recognition in policing: ICO audit findings and recommendations
The ICO has audited five police forces in England and Wales examining their use of facial recognition technology (FRT) and making 107 recommendations in relation to compliance and best practice. It has published two outcomes reports, with core audit activity focused on live facial recognition (LFR) and retrospective facial recognition (RFR).
The ICO observed some good practice, with compliance rates generally higher for LFR than RFR, but also identified gaps, inconsistencies and areas for improvement. It states that forces audited engaged constructively and committed to addressing the issues identified.
Some of the areas for improvement identified by the ICO include:
- Governance and accountability. Ensuring clear senior leadership oversight of FRT and that staff understand their roles and responsibilities when deploying it, as well as delivering appropriate training.
- Document control. Keeping policy and guidance documents up to date and reviewing them regularly.
- Data mapping and records of processing activities. Maintaining clear and up-to-date records of processing activities relating to FRT and conducting data mapping exercises for all FRT procedures.
- Sources of images. Ensuring images used for RFR are obtained from appropriate sources and not kept for longer than necessary.
- Storage limitation. Assessing whether personal information is being held within retention guidelines and have a defined retention period or time limits for reviewing the need for continued storage of personal data for law enforcement purposes.
- Accuracy and bias. Verifying that facial recognition systems are accurate, carrying out regular compliance checks, and clearly outlining approaches to mitigating bias in policies and procedures.
The ICO intends to conduct its final audit of the Metropolitan Police later this year.
National Cyber Security Centre shares initial practical advice on managing agentic AI cyber risk
The National Cyber Security Centre (NCSC) has published a blog post setting out practical advice to help organisations deploy agentic AI systems securely within their environments, drawing on its research to date. The NCSC said it is working with partners to develop formal guidance that will build upon and supersede its initial blog advice.
The blog covers key considerations aimed at system designers and operators who are building environments in which AI agents are intended to operate with significant degrees of autonomy, or who are concerned about the implications of an AI agent performing unintended actions. These include providing agents with clearly defined instructions and context, ensuring appropriate levels of human oversight, defining the boundaries of a sandboxed environment within which the AI operates, and maintaining the ability to access and analyse telemetry data relating to AI activities. See also the cyber security section.
Government seeks views on how AI could transform the energy system
The government has launched a call for evidence, closing on 6 November 2026, seeking views on how AI can transform the energy system, including opportunities, risks and barriers to adoption. The vision for an AI-enabled clean energy system outlines the government's emerging thinking on the opportunities AI could create, while recognising the risks and wider system implications that will need to be managed.
The government states that its understanding of AI's role in the energy system is developing and that further evidence is needed. The vision sits alongside other work that will strengthen the evidence base, including the government's AI Champion for Clean Energy review of AI deployment in electricity networks, which makes recommendations on the reforms that may be needed to support safe, effective and timely deployment. According to the government, these will together inform the UK's "AI for Clean Energy Strategy". The strategy will consider the review's recommendations, setting out where further action is needed and identifying next steps on specific reforms, such as changes to funding, legislation or regulation.
MHRA Commission publishes recommendations on regulation of AI in healthcare
See products section.
Committee of Advertising Practice outlines current approach to advertising AI products
See advertising and marketing section.
EU updates
AI Office and national authorities begin enforcing EU AI Act
As of 2 August 2026, the European Commission's AI Office, together with national competent authorities, became empowered to enforce certain provisions of the EU AI Act. These include the prohibitions on certain AI practices, obligations for providers of general-purpose AI (GPAI) models, and transparency requirements.
The AI Office enforces the AI Act's rules for providers of GPAI models. It also has exclusive competence for the supervision and enforcement of obligations relating to: (i) AI systems based on GPAI models where the model and the system are developed by the same provider, or by providers forming part of the same undertaking (subject to certain exceptions set out in Article 75(1) of the Act, as amended by the Digital Omnibus on AI); and (ii) AI systems that constitute or are integrated into very large online platforms or very large online search engines designated under the Digital Services Act.
National competent authorities enforce the rules for other AI systems, and the European Data Protection Supervisor enforces the rules for AI systems used by EU institutions.
Enforcement powers for other provisions of the AI Act, namely, prohibitions related to the generation or manipulation of non-consensual intimate material and child sexual abuse material, and rules for high-risk AI systems, will apply only once those provisions become applicable.
Transparency rules under Article 50 of the AI Act also became applicable on 2 August.
Standardisation bodies publish first standard under the EU AI Act
The European standardisation bodies, CEN and CENELEC, have approved the first European standard developed to support the implementation of the EU AI Act. The standard addresses the requirements for, and provides guidance on, the definition, implementation and maintenance of a quality management system for providers of AI systems. It is designed primarily for providers of high-risk AI systems, which are required under the AI Act to have a quality management system in place.
The European Commission is expected to publish the reference to the standard in the Official Journal of the EU later in 2026.
The UK national standards body, the British Standards Institution (BSI), has published a corresponding standard.