Quentin CasaresData and AI leadership for regulated growth
Insights

2026-09-03 / 5 min

The 2026 data and AI regulatory reset: a board agenda

Five regulatory changes landed between February and July 2026 that alter what a UK board should expect from its data and AI functions. This is what changed, what it means, and the questions to ask before year end.

In brief: between February and July 2026 the UK commenced its new data protection regime, made a complaints procedure mandatory for every controller, designated its first Critical Third Parties, published its third-party reporting rules, and watched the EU defer its high-risk AI obligations while leaving transparency duties and penalties in place. Each change has a board-level question attached.

Regulatory change usually arrives slowly enough to be absorbed by the functions it affects. The first seven months of 2026 were different. Five changes landed in quick succession, each in a different part of the estate, and together they alter what a board should expect its data and AI leadership to be able to evidence.

What changed, and when

DateChangeWho it touches
5 February 2026The Data (Use and Access) Act 2025 commenced its principal data protection reformsEvery UK controller and processor
18 March 2026PRA PS7/26 and FCA PS26/2 published: operational incident and material third-party reportingRegulated financial services firms
19 June 2026Mandatory data protection complaints procedure took effectEvery UK controller, without exception
13 July 2026First Critical Third Parties designated: AWS, Google Cloud, Microsoft and OracleRegulated firms and their cloud dependencies
27 July 2026EU Digital Omnibus on AI in force: high-risk obligations deferred, transparency and prohibitions retainedAny firm placing AI systems on the EU market

The Data (Use and Access) Act is now live

The Act received Royal Assent on 19 June 2025 and was commenced in stages. The Commencement No. 6 Regulations brought the substance into force on 5 February 2026 with little public attention, and the ICO confirmed on 19 June 2026 that every data protection provision had commenced.

Four points deserve board attention. Recognised legitimate interests give a presumption of legitimacy to defined processing such as direct marketing, intra-group administration and network security, removing the balancing test for those purposes. The maximum penalty under the Privacy and Electronic Communications Regulations has risen from £500,000 to the UK GDPR level of £17.5 million or four per cent of global turnover, which turns marketing compliance from a nuisance into a material risk. The ICO has gained the power to compel interviews, require reports from approved persons at the organisation's expense, and issue document production notices. And from 19 June 2026 every controller must run a formal complaints procedure, acknowledge complaints within thirty days, and tell complainants of their right to go to the ICO.

The board question is simple. Has the privacy programme been re-baselined against the Act as commenced, and can the organisation show its complaints log?

Third-party resilience has a reporting regime

The UK's operational resilience framework reached full implementation on 31 March 2025. The March 2026 policy statements add the reporting layer. Firms will notify material third-party arrangements and report operational incidents on templates aligned with the EU's DORA and the Financial Stability Board's incident reporting format. The FCA's rules take effect on 18 March 2027.

The July designation of the four hyperscalers as Critical Third Parties closes the loop. Supervisors now have direct oversight of the providers, and firms will be reporting which of their important business services depend on them. A board should expect to see a maintained map of important business services, the third parties and ICT assets beneath each, and the impact tolerance for each service. If that map lives in a programme's slide deck rather than in a system of record, it is not yet a control.

The EU deferred the hard part, not the whole

The Digital Omnibus on AI, Regulation (EU) 2026/1744, pushed the AI Act's high-risk obligations to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products. It did not touch the Article 50 transparency duties, which applied from 2 August 2026, the prohibitions, which gain new entries on 2 December 2026, or the penalty tiers of seven and three per cent of turnover.

Two consequences follow for a UK firm with EU exposure. First, any customer-facing generative system needs its disclosure and content-marking obligations in place now, with legacy systems having until 2 December 2026. Second, systems already on the EU market before the deferred deadlines are grandfathered unless substantially modified, which makes the change log on every deployed model a regulatory document from this point forward.

UK regulators are not writing AI rules, and that is the point

The Treasury Committee's January 2026 report criticised regulators for not doing enough on AI and asked the FCA to publish practical guidance by year end on consumer protection and on Senior Manager accountability for AI harm. The Bank of England and PRA replied in April that they would remain technology-agnostic. The FCA's March perimeter report flagged general-purpose AI tools offering financial advice as an emerging risk at the edge of its remit.

The board reading of all this is that AI will be supervised through SM&CR, Consumer Duty and the PRA's model risk expectations in SS1/23. There will be no AI rulebook to point to and no AI-specific defence. There will be a Senior Manager whose name is on the use case.

Five questions before year end

  1. Which Senior Manager owns each material AI use case, and where is the register that says so?
  2. Can the organisation produce its Critical Data Elements, their owners and their last quality breach within a day?
  3. Where is the maintained map of important business services, their third parties and their impact tolerances?
  4. Has the privacy programme been re-baselined against the Data (Use and Access) Act as commenced, including the complaints procedure and the higher PECR penalties?
  5. For any AI system placed on the EU market, is the change log good enough to defend a claim that it has not been substantially modified?

None of these questions needs a new platform to answer. Each needs an owner, a list and a habit of evidence. That is what the 2026 reset asks of a board, and it is a reasonable ask.

Sources

Executive Data Briefing

A low-volume note for data and AI decisions with consequence.

Consent-based and double opt-in. Governance patterns, board-level data trust, and decision infrastructure - not generic AI commentary.