Skip to main content
v2026.11,858 entries · CC-BY 4.0

The UK’s AI White Paper: A Regulatory Framework Without a Regulator

The UK’s AI White Paper sets five cross-sector principles for AI regulation but deliberately creates no central AI regulator, relying instead on existing regulators like the ICO, MHRA, FCA, EHRC and NCSC to apply them within their own remits.

Written and maintained by CASRAI Editorial Board

Last updated

Last verified: September 20, 2026, against the white paper’s own page on GOV.UK. The UK’s AI White Paper — formally “A pro-innovation approach to AI regulation,” published 29 March 2023 and updated 3 August 2023 — sets out five cross-sector principles that existing UK regulators are expected to apply to AI within their own remits. The distinguishing fact, easy to miss if you only skim a summary: the white paper does not create a central AI regulator at all. It is a sector-led framework, and as of this page’s verification it remains non-statutory — regulators are only expected to gain a statutory duty to have regard to the principles once Parliament allocates time for that legislation, with no date set.

The Five Cross-Sector Principles

Rather than writing a single new AI statute, the white paper asks existing regulators to interpret and apply five principles within whatever domain they already oversee:

Principle What It Asks Regulators to Assess
Safety, security and robustness Whether an AI system functions reliably and safely, and is resistant to failure or attack, within the regulator’s sector
Appropriate transparency and explainability Whether the level of transparency about how a system works is appropriate to the risk it poses, and whether its decisions can be explained
Fairness Whether an AI system produces discriminatory or otherwise unfair outcomes, judged against existing law the regulator already enforces
Accountability and governance Whether clear lines of accountability exist for an AI system’s outcomes within the organisation deploying it
Contestability and redress Whether people affected by an AI-driven decision have a route to contest it or seek redress

Notice what is absent from that list: there is no sixth principle establishing who enforces the other five across sectors, because no single body does.

No Central Regulator: A Sector-Led Model

The white paper is explicit that it is not proposing a new AI-specific regulator. Instead, it directs existing sectoral regulators to apply the five principles within their current statutory remits. GOV.UK’s own page names several by way of example: the Information Commissioner’s Office (ICO) for data protection, the Medicines and Healthcare products Regulatory Agency (MHRA) for AI in medical devices, the Financial Conduct Authority (FCA) for AI in financial services, the Equality and Human Rights Commission (EHRC) for discrimination, and the National Cyber Security Centre (NCSC) for AI security. Each regulator is left to decide how the five principles translate into guidance for its own sector, using tools it already has — the white paper adds no new enforcement power to any of them.

That design choice is the whole story of this page: it means “the UK’s AI regulation” is not one thing you can point to, but a set of expectations distributed across regulators who were not created for this purpose and who move at different speeds using different tools.

Non-Statutory Now, Statutory “When Parliamentary Time Allows”

As published, the five principles are non-statutory — regulators are asked, not legally required, to apply them. The white paper does describe an intended next step: after an initial implementation period, the government anticipates introducing a statutory duty requiring regulators to have due regard to the principles. But that step is explicitly conditional on “when parliamentary time allows” — language that commits to no date and no guaranteed legislative slot. As of this page’s verification, that statutory duty has not been introduced, and the framework operates on guidance and existing regulatory powers alone.

Sector-Led vs. Centralized: the UK’s Framework Next to the EU’s AI Act

The contrast sharpens next to the approach CASRAI’s own jurisdiction map of AI regulation around the world covers for the EU, US, and China — that page does not include the UK’s white paper, which is part of why this page exists.

Dimension UK — AI White Paper EU — AI Act
Central AI regulator None — enforcement distributed across existing sectoral regulators Yes — the EU AI Office plus national market-surveillance authorities
Legal status Non-statutory principles; a statutory duty is anticipated but not scheduled Binding regulation with tiered, legally enforceable obligations
Mechanism Five cross-sector principles for regulators to interpret within their own remit Risk-tiered categories (unacceptable, high, limited, minimal) with specific obligations per tier
Enforcement Whatever powers each sectoral regulator already holds Centralized penalty regime, including fines calculated as a percentage of global turnover

Neither model is presented here as superior — CASRAI’s own view is that they trade off differently: the UK’s approach avoids the delay and rigidity of new primary legislation but leaves gaps wherever no existing regulator’s remit clearly covers a given AI use case, while the EU’s centralized model closes that gap at the cost of a single, slower-moving legislative instrument governing every sector at once.

How This Differs From CASRAI’s Other UK AI Pages

CASRAI already covers two adjacent but distinct pieces of UK AI policy, and it’s worth being precise about how this page differs from both, because the names are easy to conflate:

Until now, that top-level framework itself was undocumented on casrai.org — CASRAI’s frontier-AI-safety content covered the testing institute and one sector’s regulator, but not the cross-economy policy document that assigns both of them (and every other UK regulator) their role.

NIKOLAI Angle: A National-Policy Parallel to “Referenced-but-Undefined”

CASRAI’s own NIKOLAI — an independent, unendorsed dictionary of frontier-AI-safety elements, current release nikolai-v0.2, 64 elements across 10 tracks — documents a disclosure-status taxonomy on its Capability Threshold element (track N3, Thresholds and checkpoints): a lab or statute’s threshold disclosure is classified as quantified, qualitative, referenced-but-undefined, or classified. In NIKOLAI’s own crosswalk on that element, California SB 53 is marked referenced-but-undefined: the statute requires a frontier developer to describe the thresholds it uses to identify catastrophic-risk capability, but the statute itself does not define what that threshold has to be.

CASRAI is drawing an editorial parallel, not a factual claim about NIKOLAI’s contents: the UK white paper’s structure is the same pattern one level up, at national regulation rather than a single statute’s disclosure requirement. The white paper names five principles regulators must apply and even anticipates a future statutory duty to apply them — but it does not itself define enforcement mechanisms, penalties, or a compliance test for any of the five, leaving that undefined space to each sectoral regulator to fill independently, on its own timeline. That is structurally the referenced-but-undefined pattern: a requirement is named, but its operational content is left open.

As of this page’s verification, NIKOLAI’s Capability Threshold crosswalk does not carry a UK government or AI White Paper row — its existing rows cover individual labs (Anthropic, OpenAI, Google DeepMind, xAI, Amazon, Magic), evaluators (METR, the Frontier Model Forum), and statutes (the EU AI Act, California SB 53, the US government’s EO 14409). CASRAI is noting the UK white paper here as a candidate for a future crosswalk row, not asserting it already has one, and NIKOLAI does not represent that HM Government has reviewed, endorsed, or in any way adopted NIKOLAI’s terminology.

Frequently Asked Questions

Does the UK have an AI regulator?

Not a dedicated one. The AI White Paper deliberately avoids creating a new central AI regulator, instead directing existing regulators — among them the ICO, MHRA, FCA, EHRC, and NCSC — to apply five cross-sector principles within their own existing remits.

Is the UK’s AI White Paper legally binding?

No, not as published. The five principles are non-statutory. The government has said it anticipates introducing a statutory duty for regulators to have due regard to the principles after an initial implementation period, but only “when parliamentary time allows” — language that sets no date.

What are the five principles in the UK AI White Paper?

Safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress.

How is this different from the UK AI Safety Institute or AI Security Institute?

The Safety/Security Institute is a single technical body that evaluates specific frontier AI models before deployment. The AI White Paper is a separate, economy-wide policy document that assigns AI-regulation responsibility across every existing UK sectoral regulator — the institute is not one of the regulators the white paper delegates to, and the white paper does not govern the institute’s own testing work.

How does this compare to the EU’s approach?

The EU AI Act creates binding, centrally enforced, risk-tiered obligations administered in part by a dedicated EU AI Office. The UK’s white paper instead asks existing sectoral regulators to apply five non-statutory principles within their own remits, with no new central body and no EU Act-style tiered obligations.

Related Reading

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about The UK’s AI White Paper: A Regulatory Framework Without a Regulator

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →