Sector rules

Sector regulators and AI

How existing UK regulators apply their current powers to AI: financial conduct, competition, medical devices and online safety.

Who it applies to

Any organisation in a regulated sector. In the UK model, your sector regulator is usually the one that will ask about your AI first.

Latest check 27 Sep 2026 7 rules · See changes in the Ledger


The rules

The CMA's foundation model principles

Proposed in the CMA's AI Foundation Models initial report of 18 September 2023: accountability, access, diversity, choice, flexibility, fair dealing and transparency.

Verified 27 Sep 2026 · Read the source

Incentivised reviews under the DMCC Act (CMA guidance)

Not banned outright. Lawful only if the consumer is told the review was incentivised and the review still reflects their genuine experience. A concealed incentivised review is a banned practice.

Verified 27 Sep 2026 · Read the source

The CMA's April 2024 update

Published 11 April 2024. It described an "interconnected web" of partnerships and investments among the leading firms and set out the CMA's concerns about competition in foundation model markets.

Verified 27 Sep 2026 · Read the source

The FCA's position on AI-specific rules

On 8 June 2026 the FCA restated: "We have been clear that we are not going to introduce new regulations for AI." It relies on existing frameworks, including the Consumer Duty and the Senior Managers and Certification Regime, and runs AI Live Testing to let firms test AI in real-world conditions with regulatory support.

Verified 27 Sep 2026 · Read the source

The MHRA AI Airlock

Launched 9 May 2024: a regulatory sandbox for AI as a Medical Device (AIaMD), testing regulatory challenges for AI medical devices with the aim of informing future guidance.

Verified 27 Sep 2026 · Read the source

Chatbots outside the Online Safety Act

Ofcom's guidance of 18 December 2025: chatbots that only let people interact with the chatbot itself, do not search multiple websites or databases, and cannot generate pornographic content are not covered. Ofcom says any change to its powers is a matter for government and Parliament.

Verified 27 Sep 2026 · Read the source

When generative AI is in scope of the Online Safety Act

Ofcom's open letter of 8 November 2024: a service is in scope where users can share chatbot-generated content with other users, or create chatbots available to others (user-to-user); where a generative AI tool searches more than one website or database (search service); or where it can generate pornographic material.

Verified 27 Sep 2026 · Read the source


What people get wrong

The three misreadings we see most often, and what follows from them.

Waiting for your sector regulator to publish AI rules before acting.

The FCA has said it will not write new AI regulations; it expects the Consumer Duty and SM&CR to cover AI outcomes now. A named senior manager is already accountable for the AI in their area.

Assuming a customer-facing chatbot is automatically outside the Online Safety Act.

If users can share its outputs with each other, if it searches across multiple sites, or if it can generate pornographic material, it is in scope, with risk assessment and safety duties.

Treating a clinical AI tool as ordinary software.

Software with a medical purpose can be a medical device, regulated by the MHRA, and in the EU it can also be high-risk AI under Annex I, with obligations from 2 August 2028.


The other four

The EU AI ActThe UK's approach to AI regulationThe Information Commission and UK GDPRAI management standards
Next step

Knowing the rule is not the same as having a process

Module 31, AI regulation: the EU AI Act and the UK approach, turns these into what you actually need: which rules apply to you, what they require and by when, and the steps to put in place.

This is education, not legal advice. Every rule links to its primary source so you can read the original for yourself.