Sofpact field note

One Control Set, Not Two: AI Governance for UK Firms Serving Europe

Editorial diagram of UK and EU obligations converging into a single control set with a mapping document

A UK organisation looking for the law it must comply with when it deploys AI will not find a single statute. There is no UK AI Act. What exists instead is a set of obligations already in force — data protection, equality, consumer, employment, financial services conduct, product safety, professional duties — applied by the regulators that already supervise the organisation, to activity that now happens to involve AI.

This is frequently described as a lighter regime. In operational terms it is not lighter; it is less signposted. Nobody sends a checklist, and the absence of one is easy to mistake for an absence of obligation.

Two questions, not one

Most UK firms of any size face two separate questions, and confusing them produces either wasted effort or a gap.

The first is what already applies in the UK. If an AI system processes personal data, data protection law applies in full — including the accountability duties. The Information Commissioner’s Office guidance on the accountability and governance implications of AI is explicit that senior management accountability is not delegable to a technical team, and treats a data protection impact assessment as a live instrument for identifying and controlling risk rather than a form completed once. If the system affects decisions about people, equality and employment law apply regardless of how the decision was reached.

The second is whether the EU AI Act reaches the organisation. That is a question about where systems are placed on the market and where their output is used, and it is a question for legal advice rather than assumption. It is worth asking early, because the answer determines the scope of everything that follows. A UK firm with European customers, a European entity or a European user base should establish the answer deliberately rather than inferring it from the absence of a UK statute.

Why one control set beats two

Where both regimes are in play, the instinct is to run two programmes. That is almost always the wrong shape. The underlying controls overlap heavily — knowing what systems exist, what decisions they touch, what data they use, what evidence supports them, who owns them, and what happens when they fail. Those are the same artefacts whether the driver is an ICO expectation, a client’s due diligence questionnaire, an insurer’s proposal form or a European obligation.

Build the control set once, to the strictest standard that applies to the system in question, and keep a separate, short mapping document that records which obligation each control answers. The mapping is what changes when the law does. The controls mostly do not.

This also fixes the most common failure, which is having controls that nobody can locate when asked. A firm that can produce an inventory, an owner, an evaluation record and a review date for each material system is in good shape under any of these regimes. A firm that cannot is exposed under all of them simultaneously.

What the sector evidence shows

The Bank of England and FCA survey of AI in UK financial services is the most useful published picture of where UK firms actually are. It found 75% of firms already using AI, with a further 10% planning to within three years, and foundation models accounting for 17% of use cases. On governance, 84% reported a named person accountable for their AI framework.

The number worth sitting with is a different one: only 34% of firms reported a complete understanding of the AI they use, with 46% reporting partial understanding. Accountability has been assigned faster than comprehension has been built. The survey also recorded that firms expect third-party dependencies, model complexity and embedded or “hidden” models to be the risks that grow most over the following three years — all three of which are recognisable as consequences of adopting AI faster than you can enumerate it.

Where to borrow structure

The absence of a UK statute does not mean the absence of a usable framework. Three are worth borrowing from, none of which requires certification or a licence.

  • Evaluation practice. The NIST AI Risk Management Framework organises the work as Govern, Map, Measure and Manage. Map first is the instruction most often skipped: enumerate and contextualise before attempting to measure.
  • Management structure. ISO/IEC 42001 supplies defined responsibilities, documented objectives, controlled change and periodic review. A firm can adopt the discipline without pursuing the certificate.
  • Delivery practice. The Artificial Intelligence Playbook for the UK Government is written for public bodies but is the most practical UK-published guidance on deciding whether AI is the right tool, what to avoid, and how to buy and implement it. Its instruction that AI generally warrants more substantial evaluation than other interventions applies with equal force in the private sector.

A proportionate first pass

For a firm that has adopted AI without a governance programme — which is the normal position, not a failing — the sequence that produces the most defensibility per week of effort is short.

  • Enumerate. List the AI systems actually in use, including features added to software you already owned. The list is almost always longer than expected.
  • Sort by consequence. What happens to a customer, an employee or an obligation when this system is wrong? Most entries need an owner and a review date and nothing more.
  • Do real work on the few. For systems affecting decisions about people, produce the evaluation evidence, the human-review arrangement, the record-keeping and the escalation route.
  • Write the mapping. One page recording which control answers which obligation, and which questions are still open pending advice.
  • Set a review date and hold it.

None of this requires waiting for legislation, and none of it is wasted if the UK position changes. It is the same work in either direction.

If you would like the two questions separated cleanly and the control set designed once, that is governance and assurance work, usually scoped as an assessment.

Informational, not legal advice. Sofpact builds the operational controls — oversight, audit trail, evidence — and works alongside your counsel, who owns the legal interpretation.