---
title: "The UK and US approaches | Optimize All Academy"
description: "Two very different philosophies The EU chose a single horizontal law. The UK and US, as of September 2026, have no comprehensive AI statute . Instead, AI…"
url: https://optimizeall.com/learn/ai-governance-eu-ai-act/uk-and-us-approaches
updated: 2026-10-05
---

AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001 · Beyond the EU: UK, US, Gulf and Pakistan · lesson 10 of 17 · 15 min

# The UK and US approaches

## Two very different philosophies

The EU chose a single horizontal law. The UK and US, as of September 2026, have **no comprehensive AI statute**. Instead, AI is governed through existing law (data protection, consumer protection, equality, advertising, sector rules), regulator guidance, and in the US, a fast-growing patchwork of state laws. For a business, this means fewer AI-specific checklists but plenty of existing obligations that already apply to AI.

## United Kingdom

**Principles-based, regulator-led.** The 2023 AI Regulation White Paper set five cross-cutting principles for existing regulators to apply in their sectors:

1. Safety, security and robustness
2. Appropriate transparency and explainability
3. Fairness
4. Accountability and governance
5. Contestability and redress

Regulators such as the **ICO** (data protection), **CMA** (competition and consumer law), **FCA** (financial services), **Ofcom** (online safety and communications), **MHRA** (medical products) and the **EHRC** (equality) apply these within their remits. The government has repeatedly signalled legislation for the most powerful models, but no general AI bill had been enacted as of September 2026. Watch for developments rather than assuming a date.

**What already bites for UK businesses using AI:**

- **UK GDPR and the Data Protection Act 2018**, as amended by the **Data (Use and Access) Act 2025**, which reshaped the rules on automated decision-making: significant decisions based solely on automated processing are permitted in more circumstances, but with safeguards such as information, the ability to make representations, human intervention and contest. Special category data remains tightly restricted. Check ICO guidance on AI and data protection for current expectations.
- **Consumer protection**: the Digital Markets, Competition and Consumers Act 2024 strengthened the CMA's direct enforcement powers, including against fake reviews and misleading practices, which can involve AI-generated content.
- **Advertising**: the **CAP Code**, enforced by the **ASA**, applies to ads regardless of how they are made. AI-generated imagery that exaggerates product performance is misleading, just like a heavy photo filter.
- **Online Safety Act 2023** duties for platforms, and criminal offences around intimate image abuse, including sexually explicit deepfakes.
- **Equality Act 2010** for AI in hiring and services.

The **AI Security Institute** (renamed from the AI Safety Institute in 2025) evaluates frontier models but is not a regulator of businesses.

## United States

**Federal level.** No comprehensive federal AI statute. Key levers:

- **FTC**: Section 5 of the FTC Act (unfair or deceptive practices). The FTC has brought AI-related cases, including under its 2024 "Operation AI Comply" sweep against deceptive AI claims, and its rule banning fake reviews and testimonials (effective October 2024) explicitly covers AI-generated fake reviews. Claims about what your AI can do must be substantiated.
- **FCC**: in February 2024 it confirmed that AI-generated voices in robocalls count as "artificial" voices under the Telephone Consumer Protection Act, so prior express consent rules apply.
- **EEOC and CFPB** have stated that existing anti-discrimination and credit laws apply to algorithmic decisions.
- **Executive policy**: Executive Order 14365 of 11 December 2025, "Ensuring a National Policy Framework for Artificial Intelligence", pushes to challenge and preempt "onerous" state AI laws and asked for a federal preemption proposal. As of September 2026 that push is unresolved in Congress and the courts. Plan for state laws to keep applying unless and until they are preempted.
- **NIST AI RMF** remains the reference framework (Lesson 3.1).

**State level (selected, check current status):**

| Law | What it does | Status as of Sept 2026 |
|---|---|---|
| Colorado AI Act (SB 24-205) | Broad duties on high-risk AI and algorithmic discrimination | Enforcement blocked in federal court and replaced by SB 26-189, a narrower notice-and-transparency law effective 1 January 2027 |
| Texas Responsible AI Governance Act (TRAIGA) | Prohibits certain intentional harmful AI uses; AG enforcement; sandbox | Effective 1 January 2026 |
| California AI Transparency Act (SB 942, amended by AB 853) | Large GenAI providers must offer latent and manifest disclosures and a free detection tool | Operative 2 August 2026 |
| California SB 53 | Transparency and safety reporting for large frontier model developers | Enacted 2025 |
| Utah AI Policy Act | Disclosure when consumers interact with generative AI in certain contexts | In force (amended since 2024) |
| NYC Local Law 144 | Bias audits and notices for automated employment decision tools | In force since 2023 |
| Illinois HB 3773 | Amends the Human Rights Act on AI in employment decisions | Effective 1 January 2026 |
| Tennessee ELVIS Act | Protects voice and likeness against unauthorized AI replication | In force since July 2024 |

## Worked example: a UK agency running US lead-gen with AI voice calls

- **US (FCC/TCPA)**: AI voice calls to consumers need prior express consent (written consent for telemarketing to mobiles); state telemarketing rules add more.
- **Utah and similar state rules**: disclose AI interaction when required or asked.
- **UK (PECR/ICO)** if also calling UK numbers: rules on unsolicited marketing calls and automated calls apply.
- **FTC**: scripts must not make unsubstantiated claims; testimonials must be real.

The agency decides: consented numbers only, AI disclosure in the first sentence, a human transfer option, and call recordings retained per policy.

## Hands-on: a jurisdiction check prompt for your team

```text
You are a compliance research assistant. For the AI use case below, list the laws,
regulators and guidance likely relevant in [UK / US-federal / US-state: ___].
For each: (1) why it applies, (2) the specific duty, (3) the official source to verify,
(4) confidence (high/medium/low). Do not invent citations; if unsure, say "verify".
Use case: [describe purpose, users, data, outputs, where users are]
```

Use AI to draft the map; verify every item against the official source before relying on it.

## Pitfalls

- Believing "no AI law" means "no rules". Consumer, privacy, equality and advertising law apply today.
- Treating the US as one market. State laws differ and change quickly.
- Letting an LLM's legal summary go unverified.

## Video lecture: The UK and US approaches

Lecture coming soon · 13 chapters · about 9 minutes. Read the full transcript below.

1. UK and US
2. Why it matters beyond the UK/US
3. UK: five principles
4. Analogy: many existing referees
5. UK laws already in play
6. US federal levers
7. US states (selected)
8. Worked example: AI voice lead-gen
9. Use AI to draft, verify yourself
10. Example 2: UK e-commerce brand
11. Common mistakes
12. Watch me do it: jurisdiction register
13. Recap and next step

## Lecture transcript

### UK and US

The EU chose one big AI law. The UK and the United States went a different way, and that catches people out in two directions. Some assume there are no rules. Others assume an EU-style regime exists everywhere. Both are wrong. In this lesson, you'll learn how the UK's principles-based approach works, which existing laws already bite, the federal levers in the US, and the fast-moving map of US state laws, as of September twenty twenty-six.

### Why it matters beyond the UK/US

Why does this matter if you're not based in the UK or US? Because so many businesses in Pakistan and the Gulf serve UK and US clients, run ads to those audiences, or call their customers. The rules follow your customers, not your office. A Karachi agency running Facebook lead ads for a Texas client, or a Dubai firm placing AI voice calls to UK homeowners, is operating inside those rulebooks, whether it thinks about them or not.

### UK: five principles

Start with the UK. Its twenty twenty-three White Paper set five principles for existing regulators to apply: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. The ICO applies them to data protection, the CMA to competition and consumer law, the FCA to finance, Ofcom to online safety, and so on. The government has signalled legislation for the most powerful models, but as of September twenty twenty-six no general AI bill has been enacted.

### Analogy: many existing referees

An analogy for the UK and US approach: instead of one new rulebook for a new kind of vehicle, the existing traffic police, parking wardens and insurance regulators all issue guidance on how their existing rules apply to it. In the UK, the ICO, CMA, FCA and others each apply five principles in their own areas. In the US, the FTC, FCC and other agencies use their existing powers, while individual states add their own local rules. Same vehicle, many rulebooks, which is why a jurisdiction map matters.

### UK laws already in play

What already bites in the UK? Data protection, now amended by the Data Use and Access Act twenty twenty-five, which reshaped automated decision-making rules: more solely automated decisions are allowed, but with safeguards like information, the chance to make representations, and human review. Consumer law, with stronger CMA powers against fake reviews and misleading practices. The advertising code enforced by the ASA, which applies no matter how an ad was made. Online safety law and criminal offences for intimate image abuse, including sexually explicit deepfakes. And equality law for AI in hiring.

### US federal levers

Now the United States. There's no comprehensive federal AI law, but federal agencies use existing powers. The FTC polices deceptive and unfair practices, including exaggerated AI claims, and its twenty twenty-four rule on fake reviews explicitly covers AI-generated ones. The FCC confirmed in twenty twenty-four that AI-generated voices in robocalls count as artificial voices, so consent rules apply. Employment and credit regulators say existing anti-discrimination laws cover algorithms. And a December twenty twenty-five executive order pushes to preempt state AI laws, but that fight is unresolved, so plan for state laws to keep applying.

### US states (selected)

And the states. Colorado passed the first broad AI law, but its enforcement was blocked in federal court and it was replaced by a narrower notice-and-transparency law that takes effect in January twenty twenty-seven. Texas's Responsible AI Governance Act took effect in January twenty twenty-six. California's AI Transparency Act, requiring big generative AI providers to offer disclosures and a detection tool, became operative in August twenty twenty-six. New York City requires bias audits for automated hiring tools. Illinois regulates AI in employment decisions. And Tennessee's ELVIS Act protects voice and likeness from unauthorized AI replication.

### Worked example: AI voice lead-gen

Let's apply it. A UK agency runs AI voice calls for US lead generation. Under the FCC's reading of the Telephone Consumer Protection Act, AI voice calls to consumers need prior express consent, and written consent for telemarketing to mobiles. Some states require disclosure that the consumer is talking to AI. If they also call UK numbers, the UK's electronic marketing rules apply. And the FTC expects claims in the script to be substantiated. The agency's decision: consented numbers only, AI disclosure in the first sentence, a human transfer option, and recordings kept per policy.

### Use AI to draft, verify yourself

A practical tip. You can use AI to draft a jurisdiction map for a use case, using the research prompt in the lesson text, but treat it as a first draft. Ask it to name the official source for every item and to mark its confidence. Then verify each item yourself against the regulator or legislature's own website. Legal summaries from language models can be confidently wrong, and US state law changes fast.

### Example 2: UK e-commerce brand

A simpler example. A UK e-commerce brand uses AI to generate product images that make a vacuum cleaner look more powerful than it is, and AI-written reviews to fill a new product page. No AI law is needed to see the problem. The ASA would likely treat the images as misleading advertising, and the reviews would be fake reviews under UK consumer law, which the CMA can now enforce directly. In the US, the same reviews would fall under the FTC's rule on fake reviews. Existing law already covers the most common AI marketing mistakes.

### Common mistakes

Common mistakes. Believing there's no AI law, so there are no rules, when consumer, privacy, equality and advertising law apply today. Treating the US as one market, when state laws differ and change quickly, so check where your users actually are. And relying on a language model's legal summary without verifying it at the source. Use AI to draft your jurisdiction map, but check every entry against the regulator's or legislature's own website before you rely on it.

### Watch me do it: jurisdiction register

Watch me do it. I open a tab called Jurisdiction register and pick one use case: outbound AI voice calls to leads in the UK and the US. Columns: Jurisdiction, Instrument, Binding, Duty, Official source, Confidence, Verified on. First I run the research prompt from the lesson text in our chat assistant, pasting the use case description. It returns seven items. Now I verify each one. US federal, TCPA as interpreted by the FCC for AI voices: binding, duty is prior express written consent for telemarketing to mobiles. I open the FCC's own page, confirm, and date it. US federal, Do Not Call registry: binding, scrub before calling. A state bot-disclosure law: I check the legislature's site, confirm the scope, and note that it applies when the bot is used to sell. UK, PECR automated calls: binding, prior specific consent needed. UK, ICO guidance on recordings: guidance, notice and lawful basis. The model also listed a law I can't find on any official site, so I delete that row. That's why we verify. Five verified rows, one hallucination removed.

### Recap and next step

Recap. The UK is principles-based and regulator-led, with existing laws on data, consumers, advertising, online safety and equality already applying to AI. The US has federal agencies enforcing existing laws, an unresolved preemption push, and a changing patchwork of state laws. No AI law never means no rules. Your next step: for your top AI use case, list the UK or US laws that apply using the research prompt, then verify each one and add it to your inventory.

## Key takeaways

- As of September 2026, neither the UK nor the US has a comprehensive AI statute; existing laws apply to AI.
- The UK applies five principles through sector regulators; the Data (Use and Access) Act 2025 reshaped automated decision-making rules.
- US federal agencies (FTC, FCC, EEOC, CFPB) enforce existing law; state AI laws vary and change quickly; federal preemption is unresolved.
- AI voice calls in the US need TCPA consent; AI-generated fake reviews are covered by the FTC rule.

## Try it

Run the jurisdiction research prompt for your top AI use case, then verify each item on the official regulator or legislature website and add verified items to your inventory.

- [Previous: ISO/IEC 42001: running an AI management system](https://optimizeall.com/learn/ai-governance-eu-ai-act/iso-iec-42001-ai-management-system)
- [Next: The UAE, Saudi Arabia and Pakistan](https://optimizeall.com/learn/ai-governance-eu-ai-act/gulf-and-pakistan-approaches)
- [All lessons of AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001](https://optimizeall.com/learn/ai-governance-eu-ai-act)
