America sneezes. Does the UK get a cold?
Sometimes. But the mechanism is usually not a six-month delay before an American rule becomes British law. US policy influences the UK through software vendors, cloud contracts, procurement requirements, technical standards, international companies and the behaviour those systems make normal.
That matters now because the newest American governance work is moving beyond simple chatbots. It is beginning to address AI agents: systems that can use tools, access information and take actions with less direct prompting.
Bottom line: UK businesses should not copy US legislation. They should copy the useful governance habits early: know what an AI system can access, what it can do, what evidence supports its claims and where a human must remain responsible.
What is coming out of America?
1. Faster adoption is being treated as a national priority
America's AI Action Plan, published in July 2025, puts innovation, infrastructure, adoption and international leadership at the centre of US AI policy. It calls for fewer barriers to private-sector development, wider use of AI in government and an evaluation ecosystem for powerful systems.
For UK organisations, the signal is commercial: American vendors are likely to keep shipping capabilities quickly, with governance controls expected to develop alongside deployment rather than before it. A small business needs an operating boundary that can keep pace with the tools it adopts.
2. The US is arguing for a national framework over a state-by-state patchwork
Executive Order 14365, issued in December 2025, directs the US administration to challenge some state AI laws, evaluate state requirements and pursue a federal reporting and disclosure standard. It also proposes a legislative framework that would pre-empt conflicting state rules, while preserving some areas such as child safety and state procurement.
This is not UK law. It is an important governance signal, however: large technology companies will keep seeking interoperable rules, and they will design products, contracts and assurance material around the markets that matter most to them.
3. Agents are moving the governance question from answers to actions
In February 2026, the US National Institute of Standards and Technology launched an AI Agent Standards Initiative. Its stated focus includes industry-led standards, open protocols, agent authentication and identity infrastructure, interoperability and security evaluations.
A June 2026 White House order also directs work on secure frontier-model deployment, cyber defence and the misuse of AI agents to access systems unlawfully. It explicitly says the order does not create a mandatory government licensing or pre-clearance requirement for releasing AI models.
The practical lesson is straightforward: an agent should not be treated as “just a chatbot” when it can retrieve records, send messages, change data, make bookings, approve payments or call another system.
4. Unsupported AI claims are already an enforcement problem
In August 2025, the US Federal Trade Commission approved a final order against Workado over claims about the accuracy of an AI content-detection product. The order requires competent and reliable evidence for effectiveness claims and requires supporting evidence to be retained.
That is a US enforcement action, not a UK rule. It is still a useful discipline for UK marketing: do not say an AI system is accurate, unbiased, secure, compliant or better than a human unless the claim is defined, tested and supported.
5. State laws are still part of the picture
The US federal push for a national framework does not mean state activity has stopped. Texas House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, took effect on 1 January 2026. Its provisions include requirements and restrictions around transparency, harmful manipulation, certain uses of biometric data and government AI interactions.
The detail and scope matter: one disclosure provision is aimed at government agencies interacting with consumers, rather than automatically applying to every private-sector chatbot. The wider point is that US AI governance is being shaped by overlapping federal, state and sector-specific measures.
What is happening in the UK?
The UK still does not have one general AI Act
The House of Commons Library briefing on AI regulation in the UK states that the UK does not have AI-specific legislation covering AI as a technology. Instead, AI is regulated in the context in which it is used, through existing frameworks and expert regulators. The government has signalled targeted rules for the most powerful model developers, but that legislation has not yet been forthcoming.
That does not mean UK businesses are unregulated. Data protection, consumer protection, employment, financial services, online safety, intellectual property and sector requirements may already apply depending on the use case.
The ICO is already pointing towards agent governance
The ICO's Tech Futures report on agentic AI says organisations remain responsible for the data protection compliance of agentic AI they develop, deploy or integrate.
It identifies risks that become more serious as systems act with greater autonomy: unclear controller and processor responsibilities, purposes that are too broad, processing beyond what is necessary, unintended inferences about sensitive data, reduced transparency, cyber security threats and concentration of personal information.
The ICO also makes an important design point: the data and tools an agent can access, together with the controls used to monitor, stop and limit it, affect how data protection law applies. Its May 2026 response to government says future work will include an AI code of practice and dedicated guidance on agentic AI.
Copyright is another area where US developments will influence the UK debate
The UK Government's March 2026 report on copyright and AI says there is no consensus yet on how copyright and AI training should be handled. It also notes that US litigation, transparency rules, technical standards and licensing developments will shape the impact of any UK reforms.
For organisations publishing AI-assisted content, this is a reason to keep a record of source material, human contribution, permissions and review. It is not a reason to claim that every AI-assisted draft is automatically unlawful.
A Private Member's Bill is not the same as UK law
The Artificial Intelligence (Regulation) Bill [HL] is a Private Member's Bill. Its existence shows continuing parliamentary interest, but it should not be described as a general UK AI Act or treated as a current obligation without checking its status and the final text.
What should a UK business do now?
- Keep an AI use register. Record which tools are used, for what purpose, by whom and with what information.
- Separate assistance from authority. Mark each workflow as drafting, recommending or acting. The more an AI system can change the world outside the chat, the stronger the approval and logging controls should be.
- Map the data and permissions. List the files, inboxes, customer records, calendars, payment systems and APIs an agent can reach. Remove access that is not needed.
- Define a stop condition. Decide what happens when the system is uncertain, receives a complaint, encounters sensitive data or wants to take an irreversible action.
- Keep evidence for important claims. If you say an AI tool improves accuracy, saves time, reduces risk or produces better results, define the comparison and retain the test.
- Make the human owner visible. A person should be accountable for the purpose, the approval point, the failure path and the decision to continue using the system.
- Review supplier terms. Understand retention, training use, subprocessors, security, model changes, export options and what happens when the provider changes the product.
- Prepare for customer questions. Be able to explain when AI is used, what it can and cannot do, what a person reviews and how someone can ask for help.
What this does not mean
You do not need to import American law, buy a large compliance platform or ban useful AI tools. You do need a proportionate way to understand the systems you are using and to stop them exceeding their purpose.
For a small organisation, that may be a two-page AI use register, a supplier checklist, a short staff policy and a human approval rule for consequential actions. Good governance is not measured by the size of the document. It is measured by whether the right person can see what the system is doing and intervene in time.
Our view
The US is setting the pace on AI infrastructure, adoption and agent interoperability. The UK is more likely to govern through existing regulators, sector rules, data protection obligations and targeted interventions. Those routes are different, but the sensible operational response is similar.
Start with the workflow, not the label. Define the purpose, data boundary, authority, evidence, human owner and stop condition before adding more autonomy.
This is general information, not legal advice. The position is dated 4 August 2026 and should be checked against the latest legislation, regulator guidance and supplier terms before a material deployment.
Sources checked
- America's AI Action Plan, White House, July 2025.
- Executive Order 14365: Ensuring a National Policy Framework for Artificial Intelligence, White House, 11 December 2025.
- Executive Order 14409: Promoting Advanced Artificial Intelligence Innovation and Security, White House, 2 June 2026.
- AI Agent Standards Initiative, NIST, updated 20 April 2026.
- FTC final order against Workado, 28 August 2025.
- Texas Responsible Artificial Intelligence Governance Act, HB 149, effective 1 January 2026.
- AI regulation in the UK, House of Commons Library.
- ICO Tech Futures: Agentic AI, Information Commissioner's Office.
- ICO response to government on safe AI-powered innovation, 29 May 2026.
- Report on Copyright and Artificial Intelligence, UK Government, March 2026.
- Artificial Intelligence (Regulation) Bill [HL], UK Parliament bill record.
