The UK’s AI approach is widely described as principles-based and pro-innovation.
The 2023 UK AI Regulation White Paper set out an approach in which existing regulators apply their powers to AI within their sectors, rather than creating a single binding AI law in the near term.
For UK organisations, this can create a specific governance challenge.
Unlike the EU AI Act, there is no single compliance target for AI across all industries. Expectations can evolve through sector-specific regulation and guidance, including from bodies such as the ICO, FCA, and CQC.
In that environment, ISO 42001 can provide a structured, auditable approach to demonstrate governance and control over AI systems, regardless of how sector expectations evolve. Under UK GDPR, organisations that use AI to process personal data must demonstrate accountability, transparency, and appropriate human oversight. These are enforceable expectations of GDPR, not simply good practice.
The NCSC has also published guidance on secure AI deployment, including considerations such as understanding what AI systems can access, what actions they can take, and who is accountable for their behaviour. These considerations align closely with the types of governance and control considerations relevant to effective oversight.
For organisations already certified to ISO 27001, ISO 42001 may be a natural complementary next step, extending management system discipline from information security into AI governance.
Read more about the EU AI Act and what it means for UK businesses.