/ 6 min read / Entertainment & Media Guide to AI: Three years on

Regulation of AI in the UK

Introduction

Unlike the EU and some other parts of the world, the UK still does not have a single AI Act, with recent governments adhering to the pro-innovation, principles-based, and sector-led approach first set out in a 2023 white paper. AI continues to be regulated through existing laws: copyright, data protection, advertising, consumer protection, online safety, competition, and sector-specific rules. Those rules are applied by existing regulators rather than by one central AI regulator.

The position has not changed in principle since the last edition of this guide, but the surrounding picture has moved quickly. The government has emphasized growth and innovation, delayed plans for a narrow bill dealing with the most advanced AI models, announced a sandbox program to test AI products under controlled conditions, and consulted on the difficult question of AI and copyright.

The regulatory approach

The UK’s current approach is built around five broad principles: (1) safety, security, and robustness; (2) appropriate transparency and explainability; (3) fairness; (4) accountability and governance; and (5) contestability and redress. These principles are not set out in a standalone AI Act. Instead, regulators such as the Information Commissioner’s Office (ICO), Office for Communications (Ofcom), the Competition and Markets Authority (CMA), and the Advertising Standards Agency (ASA) apply them within the areas they already oversee. There is no central AI regulator and no UK equivalent of the EU AI Office, although the main digital regulators continue to coordinate through the Digital Regulation Cooperation Forum.

Rather than introducing a full AI statute, the government published a blueprint for AI regulation in October 2025. Its main proposal was an AI Growth Lab: a set of sector-specific sandboxes where businesses could test AI products in real conditions, with some rules temporarily relaxed under license and with safeguards in place. The King’s Speech of May 13, 2026 announced a Regulating for Growth Bill to create those sandboxing powers, but the Bill has not yet been introduced and its timing remains uncertain. 

Frontier models: Voluntary testing, not yet legislation

The closest the UK has come to AI-specific legislation is a proposed bill for the most advanced AI models, sometimes called frontier models. In broad terms, these are very powerful general-purpose models that may raise wider safety and security risks. The expected bill would put the existing voluntary testing arrangements on a legal footing by requiring developers to give the AI Security Institute access to their most capable models for safety testing before release. To date, that bill has not been introduced.

The role of the UK AI Security Institute is therefore limited. It evaluates the most advanced models and has access to many major models before deployment, but it is not a market regulator and it does not police everyday business use of AI. For the purposes of most media and entertainment businesses, AI use is still managed through existing legal and regulatory frameworks, rather than through a dedicated UK AI law.

Copyright and AI

Copyright is likely to remain one of the most important AI issues for the entertainment and media sector. Section 29A of the Copyright, Designs and Patents Act 1988 still permits text and data mining for non-commercial research only, so it does not give a general permission to use copyrighted works to train commercial AI models. That means the key question of when, if ever, commercial AI training on unlicensed copyrighted works is lawful in the UK remains unsettled. For a more detailed breakdown of the UK’s approach to legislating for copyright in AI and recent key case law updates, please see this overview. 

Advertising and AI-generated content

For advertising, the position is again that existing rules apply. There is no general UK duty to label AI-generated advertising. However, AI use may need to be disclosed where omitting it would mislead consumers. Committee of Advertising Practice advice from May 2025 states that advertisers should be clear where AI is material to the claim or impression created by the ad. AI also became a stated enforcement priority for 2026, alongside AI-assisted monitoring by the ASA. Guidance published in June 2026 added that deepfakes of real people must not suggest an endorsement that does not exist, and may raise passing off or image rights issues. Advertisers remain responsible for biased, offensive, or misleading material generated by AI tools they use. An industry best practice guide for generative AI in advertising followed in February 2026, developed with the ASA under the Online Advertising Taskforce.

Consumer law

Consumer law is another area indirectly regulating the use of AI. The unfair commercial practices provisions of the Digital Markets, Competition and Consumers Act 2024 (DMCC) came into force in April 2025, giving the CMA wider powers to enforce consumer law, including the ability to impose penalties of up to 10% of global turnover and to order redress. In March 2026, the CMA published guidance on AI agents in consumer-facing contexts, with the key message that consumer law applies in the same way whether a customer is dealing with a human or an AI agent. Businesses therefore remain responsible for what AI agents say and do, and should design, test, and monitor those systems so that they do not mislead, pressure, or unfairly steer consumers, or otherwise constitute an unfair commercial practice. The same principles apply to other uses of AI in a B2C context, including processing refunds, moderating reviews, marketing, or managing subscriptions – activities that are frequently subject to regulatory scrutiny and market practice investigations. In addition, the DMCC’s new online subscription rules are expected to come into force in early 2027. Again, while they are not AI-specific, they will be relevant where AI is used to manage sign-up journeys, renewal reminders, cancellation flows, retention, or refunds, as these systems will need to support clear pre-contract information, compliant reminder notices, and straightforward exit routes. For an overview of the new online subscription rules, please see this article.

Data protection and online safety

AI issues will also arise under data protection and online safety law. The ICO continues to regulate AI systems that use personal data, including profiling and automated decision-making. For a more detailed breakdown of the UK’s approach to data protection regulation of AI, please see this analysis.

Ofcom separately regulates some but not all AI-driven online services under the Online Safety Act, including recommender systems and age assurance. 

Ofcom’s starting point is that the Online Safety Act is technology-neutral and focused on the regulation of user-to-user services, search services that carry user-generated content, and services publishing pornographic content. Following its January 2026 intervention over sexualized deepfakes of real people, including children, Ofcom confirmed in February that not all chatbots are regulated. A chatbot is outside the Online Safety Act if it only allows users to interact with the bot itself and no other users (and therefore is not a user-to-user service), does not search multiple websites or databases (and therefore is not an online search engine), and cannot generate pornographic content. Content from chatbots or other AI tools may still constitute user-generated content when shared on other services or parts of the service.

Ofcom has been explicit that it can only act on harms covered by the Online Safety Act and that extending its powers to regulate AI chatbots more widely is a matter for government and parliament. That extension is now under way: the Crime and Policing Act 2026 amended the Online Safety Act to empower the Secretary of State to bring generative AI services further into scope by issuing secondary legislation. In June and July 2026, the government also announced additional safeguards for under-18s using chatbot services, including restrictions on sexualized content, sexually explicit content or role-playing features, and mandatory breaks, with exemptions for business and customer-service chatbots and scope to be defined in regulations. 

For now, providers of AI-driven media and entertainment features should carefully assess scope by reference to functionality. However, they should be prepared for that boundary to move.

Related Insights