Skip to content
Lex Machina Review logoLex Machina Review
Menu

Regulation

What UK AI Regulation Applies After the Tech Department Breakup?

Authority
UK Government and regulators
Rule type
regulation
Jurisdiction scope
UK
Effective date
Feb 5, 2026
Source text
Read primary rule text ↗

Map automated decisions and ensure safeguards for significant decisions about individuals.

The breakup of the UK technology department changed who in Whitehall owns AI policy. It did not suspend the rules that already apply to law firms using AI. After the 20–21 July 2026 restructuring, AI policy and the AI Security Institute moved toward the Cabinet Office, science and innovation moved to the new Department for Business, Innovation, Skills and Technology, and online safety moved to DCMS; AI Minister Kanishka Narayan now attends Cabinet.[1][2][3]

For a COLP, DPO, or risk partner, the practical answer is narrower: the UK still has no AI Act before Parliament, and no single central AI regulator has appeared in its place.[4] But UK law firms are not operating in a regulatory gap. Five regimes already matter, with different authorities, dates, and compliance consequences.

UK government facade changing above stable regulatory foundations

The Current Compliance Map

RegimeAuthority or sourceStatus in July 2026Why it matters to law firmsImmediate compliance action
UK GDPR automated decision-making rules, as amended by the Data (Use and Access) Act 2025UK GDPR / ICO enforcement contextArticles 22A–22D in force from 5 February 2026.[5]Applies where AI or other automated processing produces significant decisions about people, including intake, HR, matter routing, profiling, due diligence triage, or risk scoring.Map automated decisions, identify whether special category data is involved, document transparency notices, contest routes, and meaningful human involvement.
ICO statutory AI codeInformation Commissioner’s Office, under SI 2026/425Duty to prepare the code in force from 12 May 2026; the code is not yet drafted, and final ADM guidance is expected in summer 2026.[5]Will shape privacy governance, DPIAs, vendor assurance, and evidence expectations for AI systems using personal data.Prepare records now, but avoid presenting assumptions about the final code as settled law.
Professional and sector regulator expectationsSRA, and where relevant FCA or OfcomExisting professional duties already apply; thematic SRA AI guidance is expected in 2026.[5][6]AI use does not displace duties of confidentiality, competence, supervision, client care, and regulated-sector obligations.Treat AI tools as supervised legal-service infrastructure, not as exempt technology experiments.
Online Safety Act 2023Ofcom / DCMS policy ownership after the reshuffleRelevant to user-facing services and platforms rather than every law-firm AI deployment.[1][3]Matters where the firm operates, procures, or advises on regulated online services.Check whether any client portal, community product, or platform work creates online-safety exposure.
EU AI ActEU institutions and national market-surveillance authoritiesTransparency obligations still begin from 2 August 2026; high-risk obligations were pushed to 2 December 2027 for standalone systems and 2 August 2028 for embedded systems under the May 2026 Digital Omnibus.[7][8]UK firms with EU clients, users, deployments, or AI outputs used in the EU may face extraterritorial obligations.Scope EU-facing systems separately; do not assume UK location removes EU exposure.

That table is the useful starting point because it separates political ownership from enforceable obligation. A ministerial move may affect future policy, procurement priorities, or the route by which industry lobbies government. It does not tell a firm whether its AI-assisted client intake workflow needs a human review path.

The UK Has No AI Act, but Live AI Rules Apply

The House of Commons Library briefing dated 10 June 2026 confirms that no AI bill is before Parliament.[4] That point matters because much of the commentary after the department breakup has treated “where has AI policy gone?” as if it were the same question as “what law applies?” It is not.

The dormant private member’s bill introduced by Lord Holmes, the Artificial Intelligence (Regulation) Bill [HL], should not be confused with government legislation. The research record shows it was last updated on Parliament’s site on 30 April 2026 and has not progressed past introduction. It may be politically interesting; it is not the source of today’s compliance work.

The government’s more concrete policy signal is the AI Growth Lab, launched on 8 June 2026 as a regulatory sandbox for conditional rule relaxation, with legal services and conveyancing named as the first priority sector.[5] After the DSIT breakup, exactly how that lab will sit with the Cabinet Office, DBIST, and existing regulators is still emerging. A law firm should read it as a direction of travel, not as permission to lower controls.

Five regulatory pillars standing on a unified compliance base

The Most Immediate Change: Automated Decision-Making Under UK GDPR

The live legal change that deserves the most attention is not the Whitehall restructuring. It is the Data (Use and Access) Act 2025 amendment to UK GDPR automated decision-making rules. Articles 22A–22D came into force on 5 February 2026 and shifted the model from a broadly restrictive rule to a “permitted provided” model, subject to safeguards including transparency, contestability, and meaningful human involvement.[5]

Comparison of old restrictive automated decision-making model and new permitted-provided model with safeguards

That is a material shift for legal practice because many law-firm AI deployments sit close to decisions about people, even when they are sold internally as productivity tools. Intake triage can affect whether a prospective client is taken on. Matter routing can influence which team reviews a case. HR screening can affect recruitment or performance management. Client profiling and due diligence scoring can affect the level of scrutiny applied to an individual. Risk scoring can affect whether a person is escalated, delayed, or rejected.

The important distinction is not whether the tool is labelled “AI.” It is whether automated processing makes, or materially contributes to, a decision that has legal or similarly significant effects for a person. A hypothetical example is a firm using an automated intake tool to rank employment claims for urgency. If the ranking merely helps a supervised solicitor sort a queue, the risk profile is different from a system that automatically rejects low-scoring enquiries without a meaningful opportunity for review.

The new model does not mean “automated decisions are now fine.” It means the compliance question has moved to whether the required safeguards are real. A firm should be able to show what the individual was told, how the decision was reached at a usable level of explanation, how the individual can challenge it, who conducts the review, and whether that reviewer has both authority and information to change the outcome.

What Meaningful Human Involvement Should Look Like

A partner signing off a dashboard after the system has already determined the result is weak evidence of meaningful human involvement. A reviewer who can see the relevant inputs, understand the basis for the recommendation, ask for further information, and override the result is in a better position. The point is not to create theatre around human review; it is to ensure that the human review can actually affect the decision.

  • Identify each workflow where automated processing makes or substantially influences a decision about an individual.
  • Separate administrative automation from decisions with legal or similarly significant effects.
  • Record whether special category data is used, inferred, or likely to be exposed during processing.
  • Define the human reviewer’s authority before the system goes live, not after a complaint arrives.
  • Keep evidence of challenges, overrides, false positives, and process changes.

For procurement teams, this changes the vendor conversation. The right question is not only whether the supplier has a privacy policy or a security certificate. The firm needs to know whether the product supports explanations, audit logs, review queues, override records, and configuration choices that allow the firm to meet its own UK GDPR obligations.

The ICO Code Is Coming, but the Duty Already Exists

The second live issue is awkward in the way compliance officers know well: the statutory duty exists, but the final instrument that will shape expectations is not yet available. Under SI 2026/425, the duty for the ICO to prepare a statutory AI code came into force on 12 May 2026. The code itself has not been drafted, and final automated decision-making guidance is expected in summer 2026.[5]

That means firms should prepare the evidence base now without pretending to know the final text. A board paper that says “we will wait for the ICO code” is too thin if the firm is already using AI systems that process personal data. A board paper that asserts detailed obligations from a code not yet drafted is also too confident.

The sensible middle ground is documentation uplift. For each AI use case involving personal data, the firm should be able to retrieve the data protection impact assessment or explain why one was not required, identify the lawful basis, describe the data categories, record the vendor’s role, and show how outputs are reviewed. If a tool is being used for client profiling, matter triage, recruitment, AML support, or knowledge search over client material, the firm should not be discovering the data flows for the first time during an ICO query.

DocumentWhat it should answerWhy it matters before the code is final
AI use-case registerWhere the tool is used, who owns it, what data it processes, and who is affected.Creates a single source of truth when departmental or regulator guidance changes.
DPIA or DPIA screening recordWhether the processing is high risk and what mitigations are in place.Shows that privacy risk was assessed before deployment.
Automated decision recordWhether the system makes or materially influences decisions about individuals.Connects the tool to Articles 22A–22D analysis.
Vendor assurance fileWhat the supplier says about training data, logging, explainability, retention, subprocessors, and security.Prevents supplier marketing material from becoming the firm’s only evidence.
Human review evidenceWho reviews outputs, when review occurs, and whether decisions are actually changed.Tests whether safeguards operate in practice.

This is also where knowledge-management teams often become accidental risk owners. If a generative AI tool is connected to document banks, precedent collections, or matter files, the governance question is not confined to data protection. It also touches confidentiality, privilege, information barriers, retention, and the accuracy of advice built on retrieved material.

The SRA does not need a bespoke AI rule before existing professional obligations bite. Current Principles and Code of Conduct duties apply directly to AI-assisted work, with confidentiality identified as a central concern; thematic SRA guidance on AI is expected in 2026.[5][6]

For a law firm, this is where a generic corporate AI policy usually fails. A rule that says “do not upload confidential information into public tools” is necessary, but it does not answer who may approve a legal AI product, whether client consent is required for a particular deployment, how hallucinated authorities are checked, or whether privileged material can be used in a vendor-hosted environment.

AI use in legal work should be supervised as legal work. If a junior lawyer uses a drafting assistant, the supervising solicitor remains responsible for the output. If a due diligence tool flags clauses, someone must understand the limits of the extraction. If a litigation team uses AI to summarise disclosure material, the team still needs a defensible process for checking accuracy and preserving privilege.

  • Confidentiality: decide which tools may receive client or matter data and on what contractual terms.
  • Competence: train users on tool limits, verification, and prohibited use cases.
  • Supervision: define who reviews AI-assisted outputs before they reach clients, courts, counterparties, or regulators.
  • Client communication: decide when AI use is material enough to disclose or seek instructions.
  • Records: keep approvals, risk assessments, and exception decisions in a form the COLP can actually inspect.

The expected SRA thematic guidance may sharpen those expectations, but it is unlikely to make confidentiality, supervision, or competence newly relevant. They are already there.

FCA, Ofcom, and Online Safety: Relevant, Not Universal

FCA and Ofcom expectations matter most where the firm is itself conducting regulated activity, providing services to regulated clients, or building products that sit inside a regulated sector. They should not be treated as universal AI law for every solicitor’s firm. They should be treated as sector overlays that may become highly important in the right matter.

A firm advising a financial-services client on AI-driven customer segmentation will need to think differently from a firm using a closed drafting tool for internal precedent work. A firm operating a user-facing online community, legal marketplace, client collaboration platform, or consumer product may need to consider Online Safety Act exposure. A traditional B2B firm using AI for internal research may not.

The departmental reshuffle is still relevant here because online safety moved to DCMS while AI policy moved toward the Cabinet Office.[1][3] That split may matter for future guidance and policy coordination. It does not change the threshold question for a firm: does the service it operates or advises on fall within the regime?

EU AI Act Exposure Is Real, but It Should Be Scoped Carefully

UK firms should not dismiss the EU AI Act simply because the UK has not copied it. The Act has extraterritorial reach, and UK firms with EU clients, users, deployments, or AI outputs used in the EU may fall within scope. Maximum fines can reach €35 million or 7% of worldwide turnover.[7]

The timing needs care. Under the May 2026 Digital Omnibus, high-risk obligations were backstopped to 2 December 2027 for standalone high-risk systems and 2 August 2028 for embedded high-risk systems, while transparency obligations still apply from 2 August 2026.[7][8] That makes the EU point urgent for some use cases and premature for others.

A UK law firm with no EU users, no EU deployment, and no AI outputs used in the EU has a different profile from a firm providing an AI-enabled employment screening service to EU clients, or a firm supporting an EU-facing legaltech product. The research record does not show an EU AI Act enforcement action against a UK firm as of July 2026, so this remains a legal exposure analysis rather than a tested enforcement story.

The absence of a UK-EU mutual recognition or adequacy arrangement for the AI framework adds another reason to scope carefully. A UK-only compliance memo will not necessarily answer EU-facing questions, and an EU AI Act memo may overstate obligations for purely domestic UK legal work.

What the Department Breakup Changes

The industry reaction to the breakup was strong. Matt Clifford called the move “a big mistake,” while Startup Coalition and TechUK warned publicly that dismantling the department would scatter attention across government.[9] Those concerns are not trivial. AI policy can suffer when sponsorship, budget, and accountability are dispersed.

But the backlash should not be allowed to become a compliance conclusion. The dissolution of DSIT did not repeal UK GDPR amendments, delay the ICO’s statutory duty, remove professional duties, or switch off EU AI Act exposure. Nor did it create a UK AI Act by administrative rearrangement.

The unresolved parts are operational. Reporting lines between Cabinet Office AI functions and DBIST may settle over time. The AI Growth Lab may become more important for legal services and conveyancing, or it may remain a controlled experiment. Future guidance may arrive through more than one department. Those are reasons to track authority and effective dates with discipline, not reasons to pause internal controls.

A Working Position for Law Firms in Q3 2026

A law firm updating its AI governance note in Q3 2026 can take a firm but bounded position: there is no UK AI Act currently before Parliament; the DSIT breakup changed policy ownership rather than substantive law; and enforceable obligations already arise from data protection law, the ICO’s statutory-code process, professional and sector duties, online safety where relevant, and EU law where the firm has EU-facing activity.

The work to prioritize is equally concrete. Start with automated decision-making and personal data. Then test confidentiality and supervision in legal workflows. Then scope sector and EU exposure by use case, not by anxiety. Finally, keep a live tracker for the ICO code, SRA guidance, and the AI Growth Lab, because those are likely to change the evidence firms need to produce before they change the basic fact that AI governance is already required.

Do not wait for a UK AI Act. Do not treat the loss of DSIT as deregulation. And do not overstate what is still unsettled when the more immediate problem is usually much closer: an AI tool is already in use, a person is already affected by its output, and the firm has not yet written down who is responsible for the decision.

References

  1. UK government scraps technology department in reshuffle, BBC.
  2. UK shifts AI policy in departmental reorganization, scraps tech ministry, MLex.
  3. UK DSIT Dissolved, Silicon.
  4. Artificial intelligence regulation and governance, House of Commons Library, 10 June 2026.
  5. UK AI Regulation in 2026: What's in Force, What's Coming, and What Your Business Should Do, Scaffold Digital, 18 June 2026.
  6. Regulatory Outlook January 2026: Artificial intelligence, Osborne Clarke, January 2026.
  7. AI Watch: Global regulatory tracker - United Kingdom, White & Case.
  8. AI Regulatory Horizon Tracker: UK, Bird & Bird.
  9. Andy Burnham's reported plan to dismantle UK tech department triggers AI industry backlash, Firstpost.

Operationalizing workflow

No workflow has been explicitly linked to this obligation yet. See Workflows generally.

Illustrative cases

No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.

← Back to Regulation

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →
Blogarama - Blog Directory