AI Trends
9 min read

UK AI in 2025: What Still Matters in 2026

A source-backed review of the UK's 2025 AI shift, updated for 2026 law, assurance and cyber risk, with practical portfolio decisions.

UK AI in 2025: What Still Matters in 2026
AI Trends / 9 min read
AIENGINE

9 min read

Share

The useful question at the end of an AI year is not whether every prediction came true. It is which assumptions now deserve investment, which need stricter controls and which should be retired. By July 2026, the UK picture is clearer: government has moved from ambition towards delivery, data law has changed, EU obligations have continued to phase in, agentic systems have created new consumer risks and cyber attackers have gained practical AI assistance.

This review was first published on 31 December 2025 and is current through 31 July 2026. It distinguishes confirmed events from scenarios. UK policy papers are not legislation. EU AI Act duties depend on an organisation's role, system and connection to the EU market, not simply its headquarters. Sector rules, contracts and other jurisdictions may also apply. Seek legal or regulatory advice for the actual deployment.

Replace the prediction list with an evidence ledger

A prediction becomes dangerous when its date and assumptions disappear. Maintain four separate records:

  • Observed fact: an event supported by a dated primary source.
  • Current obligation: a rule in force for the organisation and use case.
  • Scenario: a plausible development with an owner, probability range and review date.
  • Decision: the investment, control or pause triggered by the evidence.

Do not rewrite an old forecast so that it appears correct. Record whether it was supported, partly supported, contradicted or still unresolved. A statement such as “AI regulation will arrive in 2026” is too broad to test. “Article 50 transparency duties apply to this provider from a specified date” can be mapped to a role, product and control.

Use an evidence table for every strategic claim:

Claim typeMinimum evidenceOwnerReview trigger
Market demandComparable customer behaviour, not survey enthusiasmProductConversion or retention misses
ProductivityBaseline task time plus reviewed output qualityOperationsRework cancels time saved
Legal dutyCurrent primary law or regulator guidanceLegalCommencement or guidance change
Security riskThreat model, incident evidence and tested controlSecurityNew capability or attack path
Model capabilityReproducible evaluation on representative workAI leadModel, prompt or data change
Social impactOutcome by affected group and complaint evidenceRiskMaterial disparity or harm

Read the UK's 2025 action plan as delivery evidence

The UK's January 2025 AI Opportunities Action Plan was a policy programme, not permission to deploy any system. The government's one-year progress report, published in January 2026, said commitments had been met on 38 of 50 actions. It grouped progress around foundations, adoption and home-grown capability.

That is evidence of public programme activity, not proof that a particular organisation will receive cheaper compute, suitable data, skilled staff or commercial returns. For an investment case, connect each relevant action to an owned dependency:

  • the named infrastructure, dataset, programme or procurement route;
  • its actual availability and eligibility;
  • the organisation's integration and assurance work;
  • the benefit expected from that dependency; and
  • the contingency if delivery changes.

Treat uncompleted commitments, announcements and proposed zones as dependencies with dates, not assets already on the balance sheet. Review the linked government dashboard before a board paper repeats a 2025 status.

Treat assurance as a capability, not a certificate

In September 2025, the government published a trusted third-party AI assurance roadmap. It described ambitions for a multistakeholder consortium, a skills and competencies framework and an Assurance Innovation Fund. The roadmap is useful evidence that assurance capacity matters; it is not a universal accreditation scheme and does not transfer accountability to an auditor.

Before buying an assessment, define:

  • the exact model, version, workflow and user population in scope;
  • the claims the assessment is designed to test;
  • representative data and foreseeable misuse;
  • independence, competence and conflicts;
  • access to technical evidence and supplier limitations;
  • severity thresholds and unresolved findings;
  • report expiry and revalidation triggers; and
  • who remains accountable for deployment.

A penetration test cannot establish fairness. A bias evaluation cannot establish cyber resilience. A model benchmark cannot establish that staff will follow escalation rules. Assemble assurance around the real system and decision, then link each finding to remediation.

For a deeper operating model, use our UK AI governance boardroom controls guide.

Update data governance for the DUAA

The Data (Use and Access) Act 2025 changed parts of the UK's information-law framework. The ICO's current DUAA guidance states that all its data-protection provisions were in force by 19 June 2026. The Act amends rather than replaces the UK GDPR, Data Protection Act 2018 and PECR.

The ICO identifies changes involving research, recognised legitimate interests, cookies, complaints and automated decision-making. Those changes do not make every AI use lawful. For each workflow, document:

  • controller and processor roles;
  • purpose and lawful basis;
  • special-category or criminal-offence condition where needed;
  • compatibility of any reuse;
  • transparency and individual rights;
  • automated-decision safeguards;
  • retention and deletion;
  • international transfers; and
  • processor and subprocessor controls.

The DUAA expanded the lawful bases potentially available for significant automated decisions that do not involve special-category data, subject to safeguards. It did not remove the need to identify the decision, significance, data and human intervention honestly. Avoid relabelling a rubber-stamp as meaningful human review.

See our AI data privacy and UK GDPR guide for the operational record set.

Map the EU AI Act by role and date

The EU AI Act continued to phase in during 2025 and 2026. The European Commission's implementation timeline records that definitions, AI literacy and prohibitions applied from 2 February 2025, while general-purpose AI provider rules and governance applied from 2 August 2025. It now shows further milestones through 2028.

The timetable changed shortly before this update. The Commission reported that the AI Omnibus entered into force on 27 July 2026, extending some timelines and simplifying administration. Do not rely on a compliance slide created in early 2026. Recheck the official consolidated position and obtain advice on:

  • whether the organisation is provider, deployer, importer, distributor or another actor;
  • where the output or affected person is located;
  • whether the system is prohibited, high-risk, transparent-content-related or outside those categories;
  • whether a general-purpose model obligation applies;
  • the relevant placing-on-market and substantial-modification dates; and
  • transitional provisions introduced by the Omnibus.

“We are a UK company” is not a scope analysis. Equally, “the EU AI Act applies to all AI” is not a risk classification.

Reframe agentic AI around authority

The 2025 conversation often treated agents as assistants that could use tools. By 2026, the important variable is authority: what the system can read, decide, communicate, buy, delete or disclose without a fresh human act.

The Competition and Markets Authority's research on agentic AI and consumers explores potential benefits alongside risks involving transparency, liability, manipulation, competition and consumer control. It is research, not a finding that every agent causes those harms. It does show why a business cannot treat a shopping or service agent as a conventional chatbot.

Create an action register with:

  • permitted tools, data and counterparties;
  • value, rate and time limits;
  • prohibited decisions and content;
  • approval points for consequential actions;
  • authentication and secret handling;
  • evidence retained for each action;
  • cancellation and recovery paths;
  • supplier failure behaviour; and
  • a named business owner.

Start in read-only mode. Add one reversible capability at a time. A persuasive demo that books a test journey says little about refunds, hostile webpages, price changes, accessibility, duplicate actions or ambiguous customer intent.

Plan for AI-assisted cyber threats without inventing inevitability

The National Cyber Security Centre's assessment of AI and cyber threats to 2027 concludes that AI is likely to increase the frequency and intensity of cyber threats and lower barriers for less-skilled actors. It also emphasises uncertainty: capability, adoption and defensive response affect outcomes.

Translate that assessment into tested exposure rather than a headline. Prioritise:

  • identity, session and privilege controls;
  • phishing-resistant authentication;
  • patch and asset management;
  • secure model and tool integrations;
  • protection against prompt injection and untrusted content;
  • monitoring of agent actions and data movement;
  • recovery from destructive or fraudulent activity;
  • supplier and open-source dependency risk; and
  • exercises that include convincing synthetic messages.

The AI Security Institute publishes current evaluation research on advanced-model capabilities and safeguards. Use relevant methods as evidence inputs, but do not infer that a frontier-model result describes a smaller model, a guarded production workflow or a future release. Maintain local evaluations at the point of use.

For practical detection and response design, see our AI cybersecurity guide.

Measure portfolio value without AI theatre

Count deployed workflows only when they have an owner, users, controls and outcome data. Prototype totals and purchased licences measure activity, not value.

For each workflow, report:

  • volume completed and eligible population;
  • end-to-end time, including review and correction;
  • output acceptance and material error rate;
  • abstention and escalation;
  • user override and complaint;
  • outcome by relevant customer or worker group;
  • incident and near-miss severity;
  • full operating cost, including assurance; and
  • benefit compared with the pre-agreed baseline.

Segment the data. An average can hide a failure for rare cases, small customers, disabled users or another language. Avoid converting a vendor benchmark into a forecast unless task, model, data, controls and evaluation design are genuinely comparable.

Run a 90-day evidence reset

Days 1–30: inventory every production and shadow AI workflow. Record model, owner, purpose, authority, data, affected people, supplier, jurisdiction and current evidence. Freeze unsupported benefit claims and remove abandoned access.

Days 31–60: classify regulatory and security exposure. Refresh impact assessments, threat models, supplier evidence and representative evaluations. Reconcile the DUAA and EU AI Act timetable with counsel. Baseline outcomes before making changes.

Days 61–90: continue only bounded workflows with credible value and controls. Remediate evidence gaps, test rollback and publish an executive portfolio view that separates observed results from scenarios. The accountable board or risk committee approves expansion, limitation or retirement.

Set portfolio pause gates

Pause a workflow or expansion when:

  • its owner, purpose or permitted authority is unclear;
  • a material decision cannot be reconstructed;
  • law, guidance or supplier terms change without review;
  • personal data is reused without an evidenced basis;
  • an agent can take an irreversible action outside approved limits;
  • a model or integration changes without revalidation;
  • serious errors, disparities or complaints exceed tolerance;
  • security monitoring cannot distinguish human and agent activity;
  • claimed benefit disappears after review and rework; or
  • the organisation cannot disable, recover or exit the service.

The durable lesson from 2025 is not that AI accelerated. It is that credible adoption depends on evidence surviving change. A portfolio that can state what is known, uncertain, controlled and reversible is more valuable than one built around confident predictions.

TaggedUK AIAI RegulationAI AssuranceAI SecurityAI Governance
Work With Us

Interested in implementing this for your business?

We help UK businesses put these ideas into practice. Book a call to discuss your specific situation.