by Claude Opus 5.5

With no general AI statute in the UK, which regulatory and governance expectations are most likely to shape hiring and job design (e.g., documentation, testing, human oversight, auditability, accountability)?

The UK still has no AI Act, and the May 2026 King’s Speech confirmed it won’t get one soon. What shapes AI-related hiring and job design is older law applied to new tools: data protection (reshaped by the Data (Use and Access) Act 2025), the Equality Act 2010, employment law and the existing rulebooks of sector regulators. All of them push employers towards the same four habits: write down what each system does, test it for bias and accuracy, give a named person real power to overrule it, and make one owner accountable. That work is creating jobs as well as changing them.

A regime of principles and regulators, by design

The government’s February 2024 response to its AI white paper set five cross-sector principles: “safety, security and robustness”, “appropriate transparency and explainability”, “fairness”, “accountability and governance” and “contestability and redress”. They are non-statutory and applied by existing regulators within their remits; thirteen, including the ICO, the Equality and Human Rights Commission (EHRC), the FCA and the Bank of England, published AI strategies in May 2024.

Nothing in 2026 has changed that architecture. The King’s Speech of 13 May 2026 contained no standalone AI bill. Its main AI measure is the Regulating for Growth Bill, which creates a regulatory sandbox for “responsible testing of AI products and services across multiple sectors”. Sandboxes ease how rules apply while a product is being tested. They place no new duties on employers that use AI.

The machinery of government has moved more than the law. Under Andy Burnham, DSIT was abolished on 21 July 2026. AI policy and the AI Security Institute moved to the Cabinet Office, and Kanishka Narayan became Minister of State for AI, attending Cabinet. This puts AI adoption closer to the centre of government, but nothing so far suggests new statutory duties for employers. Those duties come from the laws below.

Data protection: the hardest edge

Most of the Data (Use and Access) Act 2025 (DUAA) came into force on 5 February 2026 under SI 2026/82. That included new Articles 22A–22D of the UK GDPR on automated decision-making. Employers may now take “significant decisions”, such as rejecting a candidate, based solely on automated processing. In return they must have safeguards that let people get information, make representations, obtain human intervention and contest the decision. Decisions that use special-category data, such as health or ethnicity, remain tightly restricted.

The job-design consequence is that a “human in the loop” is now a legal question. The UK GDPR says a decision is solely automated “if there is no meaningful human involvement”. In its March 2026 “Recruitment rewired” report, the ICO found that many employers who believed they were using tools only for decision support were in fact making solely automated decisions. A reviewer only counts if they have the authority, competence and time to change the outcome. That turns review into a staffed and trained role with its own records.

A data protection impact assessment (DPIA) is required before high-risk processing, and since 19 June 2026 organisations must run a complaints process that acknowledges each complaint within 30 days. Since 30 September 2026 the ICO’s functions have sat with a new body, the Information Commission (SI 2026/1015). Its final ADM guidance is due in “winter 2026” and is still in draft. Question 2.12 covers this framework in detail.

Equality Act 2010: liability stays with the employer

The Equality Act is the most underrated constraint because it doesn’t care who built the tool. Section 39 makes the employer responsible for its “arrangements” for deciding whom to hire. That remains true when a vendor’s model makes the sift.

Three provisions matter most:

  • Indirect discrimination (s.19). A cut-off score, a ranking rule or a video-interview metric is a “provision, criterion or practice”. If it puts people with a protected characteristic at a particular disadvantage, the employer must show it is “a proportionate means of achieving a legitimate aim”. In practice that defence needs evidence: validation that the tool predicts job performance, adverse-impact testing by group, and a record of the alternatives considered.

  • Reasonable adjustments (s.20). If a practice puts a disabled person at a “substantial disadvantage”, the employer must take reasonable steps to avoid it, including providing information “in an accessible format”. Timed online games, automated speech analysis and asynchronous video interviews are the usual flashpoints. A non-automated route has to exist, and candidates have to know about it.

  • Burden of proof (s.136). Once a claimant shows facts from which a tribunal could infer discrimination, the burden moves to the employer to show it did not discriminate. An employer that cannot explain how its tool ranked people starts that contest at a disadvantage.

The EHRC enforces the Act. Its most visible AI intervention remains its backing for Pa Edrissa Manjang, an Uber Eats courier who said repeated facial-recognition checks led to his removal from the platform. The claim reportedly settled in 2024 without a ruling on the merits. No 2026 tribunal judgment on AI discrimination, and no new EHRC AI guidance in 2026, could be found. The legal principles are clear, but how a tribunal would apply them to AI hiring has not yet been tested.

Employment law: the ERA timetable raises the stakes

The Employment Rights Act 2025 contains no AI- or surveillance-specific provisions. What it changes is the cost of getting an AI-informed people decision wrong:

  • 6 Apr 2026. Change: Protective award for failing to consult on collective redundancies doubled from 90 to 180 days’ pay.

  • 7 Apr 2026. Change: Fair Work Agency established.

  • 1 Oct 2026. Change: Tribunal time limits extended from 3 to 6 months (9 Nov in Scotland).

  • 30 Oct 2026. Change: Strengthened harassment duties; new union access rights.

  • 1 Jan 2027. Change: Unfair-dismissal protection after 6 months’ service; compensation cap removed; fire-and-rehire largely banned.

  • 2027. Change: Guaranteed-hours rights; changes to the collective-consultation threshold.

The Burnham government has signalled continuity on this timetable. Once qualifying service drops to six months, many more employees will be able to challenge a dismissal informed by an algorithmic performance score. They will also have six months rather than three to bring a claim. In a collective redundancy, the employer must already give representatives “the reasons for his proposals” in writing under s.188 TULRCA. A redundancy publicly attributed to AI therefore has to be backed by evidence.

Financial services: the template for model governance

Finance shows where governance requirements end up as staffing. PRA Supervisory Statement SS1/23 on model risk management took effect on 17 May 2024. Formally it covers banks with internal-model approval, but it defines models as “all types of models... regardless of technology”, including vendor models and machine learning. It requires independent validation and gives a named Senior Management Function holder responsibility for the framework. The FCA does not plan AI-specific rules and relies instead on the Consumer Duty and the Senior Managers and Certification Regime. The Treasury Committee asked in January 2026 for guidance by the end of 2026 on how existing rules apply to AI, and industry questions whether SS1/23-style validation can scale to agentic systems.

The result is a “three lines of defence” structure for AI: builders, independent validators and auditors. Non-financial firms are adopting the same pattern. For listed companies applying the UK Corporate Governance Code, Provision 29 has applied since financial years beginning on 1 January 2026. Boards must now declare whether their material internal controls are effective. That includes any AI system that has become a material control.

The EU AI Act: an extraterritorial floor

The EU AI Act reaches UK firms that place AI systems on the EU market, and providers and deployers outside the EU “where the output produced by the AI system is used in the Union”. Annex III classes as high-risk any AI used to recruit, filter applications, evaluate candidates, allocate tasks, or “monitor and evaluate the performance and behaviour” of workers. The Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, delayed those obligations from 2 August 2026 to 2 December 2027. The ban on AI that infers workers’ emotions has applied since February 2025. UK groups with EU staff are likely to standardise HR tooling on the EU’s documentation and oversight requirements rather than run two regimes.

What this means for jobs

These expectations create a recognisable set of roles: model owners, DPIA and equality-impact specialists, independent validators, human reviewers with real authority, complaints handlers and assurance staff. They also change existing jobs: hiring managers must now explain decisions, not just make them. This is general information; specific situations need legal advice.

What to watch: the Information Commission’s final ADM guidance (due winter 2026), FCA guidance on AI under existing rules (requested by end-2026), the January 2027 unfair-dismissal changes, and the first UK tribunal judgment on discrimination by an AI tool.

Sources

From AI and Jobs: UK, October 2026