Five rulebooks shape how a UK organisation uses AI.
The EU AI Act reaches UK firms whose AI is used in the EU. At home, existing regulators apply the government’s principles within their own remits. UK GDPR applies whenever AI touches personal data, and standards such as ISO/IEC 42001 are what auditors and customers ask for. Each page says what the rule is, when it applies, and where to read it for yourself.
Latest check 27 Sep 2026 45 rules tracked · See changes in the Ledger
The EU AI Act
A risk-based product-safety regime for AI systems and general-purpose AI models placed on the EU market or used in the EU: banned practices, high-risk obligations, transparency duties and GPAI rules.
15 rules tracked →
UK approachThe UK's approach to AI regulation
No single AI law. Five cross-sector principles applied by existing regulators within their own remits, plus government bodies for AI security research, sandboxing and skills.
7 rules tracked →
Information Commission / UK GDPRThe Information Commission and UK GDPR
Personal data in AI: lawful basis, transparency, fairness, accuracy, DPIAs, and the rules on solely automated decisions with significant effects.
10 rules tracked →
ISO 42001 / NISTAI management standards
Voluntary, auditable frameworks for running AI responsibly: ISO/IEC 42001 as a certifiable management system, and the NIST AI Risk Management Framework as a risk method.
6 rules tracked →
Sector rulesSector regulators and AI
How existing UK regulators apply their current powers to AI: financial conduct, competition, medical devices and online safety.
7 rules tracked →
AI rules change on a schedule, and we track them the same way as tool facts
The EU’s deadline for high-risk AI systems was 2 August 2026 until the Digital Omnibus on AI moved it to 2 December 2027 for the systems listed in Annex III. The same law rewrote the AI literacy duty. From 30 September 2026 the ICO is the Information Commission. A course recorded before those dates is teaching rules that have since moved.
Every rule on these pages is stored the same way as a fact in the Tool Atlas: a versioned fact with its primary source, the date it was last checked, and a public record in the Ledger when it moves. That is a promise about process, not a claim that nothing can be wrong.
AI regulation: the EU AI Act and the UK approach teaches it properly
These pages are the reference. The module is the training: working out which rules apply to your organisation, what they require and by when, and what to put in place. It sits at Level V, Director. Like every module, it cites these rules as live facts, so it updates when they do.
This is education, not legal advice. Every rule links to its primary source so you can read the original before you act, and take proper legal advice when the stakes justify it.
