A narrow, dated note on UK instruments relevant to AI-agent oversight. The UK regulates AI through existing sectoral regimes rather than a comprehensive AI statute; for financial services, operational-resilience and accountability rules carry most of the weight. Each entry names the instrument's exact status.
These pages describe the product and cite public instruments. They are not legal advice, not a certification, and not a statement that any instrument applies to your organisation. The official source is authoritative; applicability questions belong to your advisers.
Instruments, by status
| Instrument | Status | What it addresses |
|---|---|---|
| PS21/3 · FCA and SS1/21 · PRA: operational resilience | Binding rules introduced by PS21/3 sit in the FCA Handbook; SS1/21 is a PRA supervisory statement setting expectations. In force from 31 March 2022; the mapping-and-testing transition completed 31 March 2025. | Important business services, impact tolerances, mapping of dependencies (including technology and third parties an AI agent relies on) and scenario testing. An agent action path that supports an important business service sits inside this mapping. |
| Critical Third Parties regime · FCA / PRA / Bank of England | In force 1 January 2025. | HM Treasury may designate a third party as critical to the financial sector, bringing it under direct regulator oversight; a vendor's services being systemic does not by itself trigger designation. |
| FCA PS26/2 · PRA PS7/26 · Bank of England FMI policy statement | Final policy published 18 March 2026; rules apply from 18 March 2027. Finalised guidance FG26/3 and FG26/4 (FCA) and SS1/26 with an SS2/21 update (PRA) accompany the policy statements. | Standardised incident reporting and registers of material third-party arrangements: the reporting surface an agent-related incident would travel through. |
| Senior Managers & Certification Regime (SM&CR) and Consumer Duty · FCA | Binding accountability regime. | Relevant senior managers remain accountable within their allocated areas of responsibility, and applicable prescribed responsibilities may also bear on AI governance; the Consumer Duty applies principally to retail-market business. Using AAES does not transfer that accountability, and an AAES accountable-manager registration is not an SM&CR appointment. |
| UK GDPR, as amended by the Data (Use and Access) Act 2025 | Binding law. Section 80 of the 2025 Act replaced Article 22 with new Articles 22A–22D, in force 5 February 2026 (SI 2026/82): a permission-with-safeguards model for solely automated significant decisions, with tighter rules for special-category data. The ICO has recorded all of the Act's data-protection provisions in force since 19 June 2026. | Solely automated decisions with legal or similarly significant effect: transparency, representations, human intervention and contestation safeguards under Article 22C. |
What AAES records may contribute
| Expectation | AAES contribution | Capability status |
|---|---|---|
| Named senior accountability (SM&CR) | Every registered agent has a named accountable manager, a configured association rather than a statutory appointment; approvals are attributable to a named person; agent identities cannot act as approvers through the supported AAES approval path. | Implemented. |
| Human intervention in consequential actions (UK GDPR automated-decision safeguards; Consumer Duty outcomes) | Actions the operator registers as irreversible (a registration classification, not an independent assessment of effects) require approval by an authorized person, bound to one intent and the exact payload, with expiry. An approval record does not by itself show the approver had adequate information, time or practical power to intervene. | Implemented. |
| Evidence for resilience mapping, self-assessment and incident review (PS21/3 / SS1/21; reporting policy) | Sealed, hash-chained decision records with offline integrity verification by the client's own reviewer. | Implemented. An independently controlled witness can be configured separately; that is not an external assessment, and the default deployment has none. |
AAES decision records may support review of access and approval controls. They do not establish lawful processing, model fairness, suitability, or compliance with any instrument as a whole.
Within the configured trust model, integrity verification checks the exported records; it does not establish that every action was recorded, that an external action succeeded, or that recorded assertions are true. Approval records do not by themselves establish meaningful human oversight. Enforcement depends on control of the credential path, and actions bypassing AAES are not recorded.
Residual responsibility and explicit gaps
- The client remains the regulated entity. Which regime bites (FCA, PRA, ICO or none) is your adviser's question, not this page's.
- Work outside AAES is invisible to AAES. Records cover actions routed through AAES; they say nothing about actions on bypass paths.
- No independent certification or assessment of AAES exists. No SOC 2 report, no penetration test.
- Status changes. The reporting rules implement in 2027. Re-check the primary source before relying on the status shown here.
Bring the instruments your risk team cites to a scoped evaluation.
Related pages:
This note: https://aaes.ai/library/jurisdictions/united-kingdom.html
Hong Kong note: https://aaes.ai/library/jurisdictions/hong-kong.html
Singapore note: https://aaes.ai/library/jurisdictions/singapore.html
Trust model: https://aaes.ai/library/trust-model.html
Scope an evaluation: https://aaes.ai/contact.html?ref=library-evaluation
