There is no UK AI Act, and any vendor selling you compliance with one is selling a fiction. The UK chose a principles-based, regulator-led approach — but the instruments underneath it are concrete. For PRA-regulated banks and insurers, SS1/23 sets model risk management expectations: a model inventory with risk tiering, named owners and a validation cadence. For central government and arm's-length bodies, the Algorithmic Transparency Recording Standard (ATRS) requires published records of algorithmic tools. The recurring failure is a stale inventory.
No AI Act — and why that matters
The UK has deliberately not enacted a horizontal AI law. Its 2023 white paper chose a principles-based, sector-regulator approach over a single statute — existing regulators (the FCA, the ICO, the CMA and others) apply a common set of principles within their domains. Selling a "UK AI Act" compliance product would therefore mean selling something that doesn't exist. The honest question isn't "how do I comply with the UK AI Act" — it's "which existing instruments actually bind my organisation?"
Model risk management (PRA SS1/23)
For PRA-regulated firms, the most concrete instrument is the supervisory statement on model risk management principles (SS1/23). It expects firms to hold a complete model inventory, assign each model a risk tier, and validate models on a cadence proportionate to that tier. AI and machine-learning models sit squarely within its scope. In practice that means: know every model you run, rank them by materiality and complexity, and be able to show that the high-tier ones are validated on time.
A model's tier follows from its characteristics — materiality, complexity, and how much autonomy it's given — not from a label. Deriving the tier from those inputs, and computing the next validation due date from the firm's cadence, keeps the inventory consistent and makes an overdue validation impossible to miss.
Algorithmic transparency (ATRS)
For the public sector, the UK has the Algorithmic Transparency Recording Standard (ATRS) — a standard format for government departments and public bodies to publish information about the algorithmic tools they use in decisions affecting the public. An ATRS record describes what a tool does, why it's used, the data behind it, and the human oversight around it. It's a transparency instrument rather than a risk-classification one, but for public bodies it's a real, published obligation.
UK and EU together
Organisations operating on both sides of the Channel face both regimes. A firm might owe an EU AI Act register for systems placed on the EU market and a UK model inventory under SS1/23 — different rulebooks, overlapping estate. The worst outcome is maintaining two disconnected spreadsheets that quietly disagree about which systems exist.
How Qgentic handles the UK
Qgentic AI Governance (UK) builds the SS1/23-shaped model inventory with tiers computed from materiality, complexity and autonomy, validation-due dates derived from your cadence, and the ATRS record where you publish one — on the same engine, approval gate and audit trail as the EU AI Act register. It is prepare-only, and it says plainly, in the product, that the UK has no AI Act. Honesty about the rulebook is the point.
Qgentic builds the UK model inventory with computed tiers and validation clocks, and the ATRS record — on the same engine as the EU AI Act.
See the UK AI platform Try the live demo