On April 28, 2026, UK Technology Secretary Liz Kendall delivered a major speech setting out the
government’s approach to AI regulation, confirming that Britain will not pursue a single, centralized
AI law in the near term. Instead, the UK is consolidating a “pro-innovation” model built on sector-
specific regulators, supervised regulatory sandboxes, and a new statutory footing for
experimentation with AI-enabled products and services.
The announcement builds on groundwork laid in late 2025, when the government published its
Blueprint for AI regulation (October 21, 2025) alongside a call for views on an AI Growth Lab — a
cross-economy regulatory sandbox designed to let AI products be trialled in real-world conditions
across healthcare, professional services, transport, and advanced manufacturing, even where
existing rules would otherwise impede deployment.
The model formalizes this approach further: under time-limited, closely supervised modifications to
specific regulatory requirements, companies can test AI systems under a licensing scheme with
built-in safeguards, including the ability for regulators to halt testing or impose fines if license terms
are breached.
This regulatory direction was confirmed in the King’s Speech of May 13, 2026, which introduced
37 bills but notably no fresh primary AI legislation. Two bills are most relevant to the AI
ecosystem: the Regulating for Growth Bill, which puts regulatory sandboxes onto a statutory
footing, and the Police Reform Bill, which creates a new legal framework — including an
independent regulator — for facial recognition and similar technologies.
Key Facts:
Core approach: Sector-specific regulators rather than one central AI regulator
AI Growth Lab: Cross-economy sandbox for healthcare, professional services, transport, advanced
manufacturing
Legal mechanism: Regulating for Growth Bill — statutory footing for regulatory sandboxes
(introduced in King’s Speech, 13 May 2026)
Facial recognition: Police Reform Bill creates new independent regulator for facial recognition
technologies
Existing legal coverage: AI is currently regulated through existing frameworks — data protection,
competition law, equality legislation, online safety
Criminal law dimension: Crime and Policing Act 2026 (Royal Assent 29 April 2026) creates new
offences for AI tools optimized to generate CSAM, deepfakes, and “purported intimate image
generators,” extending liability to both individuals and companies
Quantum technology: Quantum Regulators’ Forum established April 2025, comprising 9 regulators
(including DRCF, IPO, MHRA, Civil Aviation Authority, Ofgem)
Unresolved: No decision yet on AI-and-copyright reform; government says it “no longer has a
preferred option” on the underlying question
EU contrast: EU AI Act high-risk provisions take effect 2 August 2026, with the EU now actively
enforcing penalties for non-compliance — a notably stricter posture than the UK’s sandbox model
Expert Insight (SWRR Centre):
The UK’s choice to regulate AI through sandboxes and existing sectoral law rather than a single AI
Act is a deliberate bet that speed of deployment matters more than regulatory certainty — at least
for now. This has direct relevance for any country thinking about how to sequence AI governance
during a period of economic stress or reconstruction.
For a research centre focused on post-conflict recovery, the UK model offers a cautionary as well as
an instructive lesson. The instructive part: time-limited, supervised sandboxes allow technology to
be tested in high-need sectors (healthcare, infrastructure, advanced manufacturing) without waiting
years for comprehensive legislation — a potentially useful template for Ukraine, where
reconstruction needs are immediate and full regulatory frameworks take years to build consensus
around. The cautionary part: the UK government’s own admission that it has “no preferred option”
on AI-and-copyright reform, and the absence of any centralized AI law nearly four years into the
technology’s mainstream adoption, shows how easily core governance questions can be deferred
indefinitely under a sandbox-first approach.
The criminal-law provisions targeting AI-generated CSAM and deepfakes — folded into a general
Crime and Policing Act rather than AI-specific legislation — also illustrate a broader pattern worth
tracking: governments are increasingly choosing to regulate AI harms through amendments to
existing criminal, data protection, and equality law rather than purpose-built AI statutes. This is
faster to legislate but risks gaps where AI-specific harms don’t map cleanly onto existing legal
categories.
The UK-EU divergence here also matters strategically. As the EU moves toward active enforcement
of high-risk AI provisions from August 2026, the UK is positioning itself as the more permissive
jurisdiction for AI deployment — a dynamic that could shape where AI-driven reconstruction and
humanitarian-tech tools are piloted first in any future Ukraine-UK technology cooperation.
Sources:
Bird & Bird — “UK AI Regulation: UK government announces plans to set standards for how AI is
deployed,” April 28, 2026
House of Commons Library — “AI regulation in the UK,” Research Briefing, March 31, 2026
ResultSense — “UK AI regulation: May 2026 roundup of new laws and ICO guidance,” May 28,
2026
Osborne Clarke — “Artificial intelligence, UK Regulatory Outlook,” January 2026
