top of page
London city Town

COMPLIANCE UNITED KINGDOM

Enforced at runtime.

The UK regulates AI through a pro-innovation, sector-led approach: existing regulators apply cross-sector principles under existing law. That puts the burden of proof on your enterprise. EVEDY enforces the rules at runtime – and delivers the evidence.

FRAGMENTED AI REGULATION 

The regulatory landscape for AI in the UK

No single AI act – instead UK GDPR, five cross-sector principles applied by regulators such as the ICO and FCA, and growing expectations around frontier AI. This is an incomplete excerpt of the current compliance.

REGULATION

WHAT IT REQUIRES 

HOW EVEDY ENFORCES IT

UK GDPR & Data Protection Act 2018

Including ICO guidance on AI and automated decision-making

Lawful basis, data minimisation, security, transparency, and safeguards for solely automated decisions with significant effects.

Automatic PII redaction in prompts and responses, access control via your IAM, marked and logged automated decisions, complete audit trails.

Pro-innovation AI framework

Five cross-sector principles applied by existing regulators

Safety, transparency, fairness, accountability and contestability – enforced through existing regulatory powers (ICO, FCA, CMA, Ofcom).

Each principle is mapped to a runtime control: policy enforcement per use case, human-oversight escalation, tamper-evident records per regulator.

Algorithm Charter for Aotearoa

Public sector; relevant to suppliers to government

Transparency, partnership, and human oversight of algorithmic decision-making in and for public agencies.

Runtime controls and audit trails that let suppliers evidence Charter-aligned use of AI in government engagements.

FCA & PRA expectations

Financial services: governance of models and critical third parties

Senior-manager accountability, model risk management, operational resilience and consumer-duty outcomes when AI is used.

A central control plane across all models and agents, testing and evaluation of every version, continuous monitoring of non-deterministic behaviour.

AI Security Institute & upcoming legislation

Frontier-model scrutiny; targeted AI legislation under discussion

Growing expectations on evaluation, safety cases and incident reporting for advanced AI capabilities.

Evaluation and observability of every model and agent version, incident-grade event streaming to your SIEM, defensible evidence on demand.

ISO/IEC 42001 & internal policies

AI management standard and your own directives

A systematic AI management system: roles, processes, continuous improvement – plus your enterprise AI policies.

Enterprise policies are stored as machine-enforceable rules and applied automatically to every AI interaction – not just documented.

As of August 2026. This overview does not constitute legal advice.

THE DIFFERENCE

From written policy to runtime enforcement

Most enterprises have AI policies. Very few can prove they are followed. EVEDY closes exactly that gap.

1

Capture the rules

Legal requirements and internal policies are modelled as machine-readable policies – synchronised from your GRC platform if you wish.

2

Enforce at runtime

Every request to a model or agent passes through EVEDY. Violations are blocked, corrected or escalated – in real time, not after the fact.

3

Prove compliance

Audit trails per user, per agent and per regulation give internal audit, the board and regulators defensible evidence at any time.

bottom of page