Written and maintained by CASRAI Editorial Board
Last updated
Last verified: September 20, 2026, against the white paper’s own page on GOV.UK. The UK’s AI White Paper — formally “A pro-innovation approach to AI regulation,” published 29 March 2023 and updated 3 August 2023 — sets out five cross-sector principles that existing UK regulators are expected to apply to AI within their own remits. The distinguishing fact, easy to miss if you only skim a summary: the white paper does not create a central AI regulator at all. It is a sector-led framework, and as of this page’s verification it remains non-statutory — regulators are only expected to gain a statutory duty to have regard to the principles once Parliament allocates time for that legislation, with no date set.
The Five Cross-Sector Principles
Rather than writing a single new AI statute, the white paper asks existing regulators to interpret and apply five principles within whatever domain they already oversee:
| Principle | What It Asks Regulators to Assess |
|---|---|
| Safety, security and robustness | Whether an AI system functions reliably and safely, and is resistant to failure or attack, within the regulator’s sector |
| Appropriate transparency and explainability | Whether the level of transparency about how a system works is appropriate to the risk it poses, and whether its decisions can be explained |
| Fairness | Whether an AI system produces discriminatory or otherwise unfair outcomes, judged against existing law the regulator already enforces |
| Accountability and governance | Whether clear lines of accountability exist for an AI system’s outcomes within the organisation deploying it |
| Contestability and redress | Whether people affected by an AI-driven decision have a route to contest it or seek redress |
Notice what is absent from that list: there is no sixth principle establishing who enforces the other five across sectors, because no single body does.
No Central Regulator: A Sector-Led Model
The white paper is explicit that it is not proposing a new AI-specific regulator. Instead, it directs existing sectoral regulators to apply the five principles within their current statutory remits. GOV.UK’s own page names several by way of example: the Information Commissioner’s Office (ICO) for data protection, the Medicines and Healthcare products Regulatory Agency (MHRA) for AI in medical devices, the Financial Conduct Authority (FCA) for AI in financial services, the Equality and Human Rights Commission (EHRC) for discrimination, and the National Cyber Security Centre (NCSC) for AI security. Each regulator is left to decide how the five principles translate into guidance for its own sector, using tools it already has — the white paper adds no new enforcement power to any of them.
That design choice is the whole story of this page: it means “the UK’s AI regulation” is not one thing you can point to, but a set of expectations distributed across regulators who were not created for this purpose and who move at different speeds using different tools.
Non-Statutory Now, Statutory “When Parliamentary Time Allows”
As published, the five principles are non-statutory — regulators are asked, not legally required, to apply them. The white paper does describe an intended next step: after an initial implementation period, the government anticipates introducing a statutory duty requiring regulators to have due regard to the principles. But that step is explicitly conditional on “when parliamentary time allows” — language that commits to no date and no guaranteed legislative slot. As of this page’s verification, that statutory duty has not been introduced, and the framework operates on guidance and existing regulatory powers alone.
Sector-Led vs. Centralized: the UK’s Framework Next to the EU’s AI Act
The contrast sharpens next to the approach CASRAI’s own jurisdiction map of AI regulation around the world covers for the EU, US, and China — that page does not include the UK’s white paper, which is part of why this page exists.
| Dimension | UK — AI White Paper | EU — AI Act |
|---|---|---|
| Central AI regulator | None — enforcement distributed across existing sectoral regulators | Yes — the EU AI Office plus national market-surveillance authorities |
| Legal status | Non-statutory principles; a statutory duty is anticipated but not scheduled | Binding regulation with tiered, legally enforceable obligations |
| Mechanism | Five cross-sector principles for regulators to interpret within their own remit | Risk-tiered categories (unacceptable, high, limited, minimal) with specific obligations per tier |
| Enforcement | Whatever powers each sectoral regulator already holds | Centralized penalty regime, including fines calculated as a percentage of global turnover |
Neither model is presented here as superior — CASRAI’s own view is that they trade off differently: the UK’s approach avoids the delay and rigidity of new primary legislation but leaves gaps wherever no existing regulator’s remit clearly covers a given AI use case, while the EU’s centralized model closes that gap at the cost of a single, slower-moving legislative instrument governing every sector at once.
How This Differs From CASRAI’s Other UK AI Pages
CASRAI already covers two adjacent but distinct pieces of UK AI policy, and it’s worth being precise about how this page differs from both, because the names are easy to conflate:
- UK AI Safety Institute vs AI Security Institute: The 2025 Rename Explained and CAISI and the UK AI Security Institute: How Pre-Deployment Testing Agreements Work both cover the UK’s frontier-model safety-testing institute — a single technical body that evaluates specific advanced models before deployment. This page covers something structurally different: the UK’s economy-wide regulatory framework, which has no equivalent single institute and instead delegates to whichever sectoral regulator already has jurisdiction.
- MHRA and AI in UK Clinical Research covers how one of those sectoral regulators — MHRA — applies device law and its own AI Airlock sandbox to a specific sector (clinical research and medical devices). That page is a worked example of the white paper’s sector-led model in practice for one regulator; this page is the framework those sector-specific applications sit underneath.
Until now, that top-level framework itself was undocumented on casrai.org — CASRAI’s frontier-AI-safety content covered the testing institute and one sector’s regulator, but not the cross-economy policy document that assigns both of them (and every other UK regulator) their role.
NIKOLAI Angle: A National-Policy Parallel to “Referenced-but-Undefined”
CASRAI’s own NIKOLAI — an independent, unendorsed dictionary of frontier-AI-safety elements, current release nikolai-v0.2, 64 elements across 10 tracks — documents a disclosure-status taxonomy on its Capability Threshold element (track N3, Thresholds and checkpoints): a lab or statute’s threshold disclosure is classified as quantified, qualitative, referenced-but-undefined, or classified. In NIKOLAI’s own crosswalk on that element, California SB 53 is marked referenced-but-undefined: the statute requires a frontier developer to describe the thresholds it uses to identify catastrophic-risk capability, but the statute itself does not define what that threshold has to be.
CASRAI is drawing an editorial parallel, not a factual claim about NIKOLAI’s contents: the UK white paper’s structure is the same pattern one level up, at national regulation rather than a single statute’s disclosure requirement. The white paper names five principles regulators must apply and even anticipates a future statutory duty to apply them — but it does not itself define enforcement mechanisms, penalties, or a compliance test for any of the five, leaving that undefined space to each sectoral regulator to fill independently, on its own timeline. That is structurally the referenced-but-undefined pattern: a requirement is named, but its operational content is left open.
As of this page’s verification, NIKOLAI’s Capability Threshold crosswalk does not carry a UK government or AI White Paper row — its existing rows cover individual labs (Anthropic, OpenAI, Google DeepMind, xAI, Amazon, Magic), evaluators (METR, the Frontier Model Forum), and statutes (the EU AI Act, California SB 53, the US government’s EO 14409). CASRAI is noting the UK white paper here as a candidate for a future crosswalk row, not asserting it already has one, and NIKOLAI does not represent that HM Government has reviewed, endorsed, or in any way adopted NIKOLAI’s terminology.
Frequently Asked Questions
Does the UK have an AI regulator?
Not a dedicated one. The AI White Paper deliberately avoids creating a new central AI regulator, instead directing existing regulators — among them the ICO, MHRA, FCA, EHRC, and NCSC — to apply five cross-sector principles within their own existing remits.
Is the UK’s AI White Paper legally binding?
No, not as published. The five principles are non-statutory. The government has said it anticipates introducing a statutory duty for regulators to have due regard to the principles after an initial implementation period, but only “when parliamentary time allows” — language that sets no date.
What are the five principles in the UK AI White Paper?
Safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress.
How is this different from the UK AI Safety Institute or AI Security Institute?
The Safety/Security Institute is a single technical body that evaluates specific frontier AI models before deployment. The AI White Paper is a separate, economy-wide policy document that assigns AI-regulation responsibility across every existing UK sectoral regulator — the institute is not one of the regulators the white paper delegates to, and the white paper does not govern the institute’s own testing work.
How does this compare to the EU’s approach?
The EU AI Act creates binding, centrally enforced, risk-tiered obligations administered in part by a dedicated EU AI Office. The UK’s white paper instead asks existing sectoral regulators to apply five non-statutory principles within their own remits, with no new central body and no EU Act-style tiered obligations.
Related Reading
- AI Regulations Around the World: A Jurisdiction Map
- UK AI Safety Institute vs AI Security Institute: The 2025 Rename Explained
- CAISI and the UK AI Security Institute: How Pre-Deployment Testing Agreements Work
- MHRA and AI in UK Clinical Research
- California SB 53 (Transparency in Frontier Artificial Intelligence Act): The Foundational Explainer
- The EU AI Act GPAI Code of Practice: What It Is and Who Signed It
- NIKOLAI: CASRAI’s Frontier-AI-Safety Dictionary







