← Insights · August 25, 2026

Waiting for the AI rulebook is now the expensive option

Article card on a dark navy background reading Waiting for the AI rulebook is now the expensive option, with expensive option highlighted in green.

There is a specific kind of paralysis where everybody agrees the project is a good idea and nobody will sign the form.

It has become the default state of AI in British business. Dataiku’s Global AI Confessions Report: CEO Edition 2026, a Harris Poll survey of 900 chief executives at companies with revenue above $500m, found 51% of UK CEOs had delayed AI initiatives because of regulatory uncertainty, up from 26% the year before. That was one of the sharpest rises of any region surveyed (Intelligent CXO, IT Brief UK, both 11 May 2026). It is a vendor-commissioned survey of large companies, so weight it accordingly, and Dataiku has not published the fieldwork window.

The same UK respondents were the most enthusiastic in the study. 81% ranked AI strategy a top or high priority, the highest of any region, against 73% globally. 89% called themselves extremely confident in their AI strategy, while 77% said they were more worried about over-investing than under-investing, against 65% globally.

Read that together and you get a fairly precise portrait. British boards are more convinced by AI than anyone else in the survey, and more frightened of committing to it. Doubling in one year is not a technology story. Something changed in what they think they’re allowed to do.

It isn’t strict regulation. It’s unfinished regulation

The instinct is to reach for the deregulation argument. It doesn’t survive contact with the actual position, because there isn’t much UK AI regulation to be strict.

There is no UK AI statute and no government AI bill before Parliament. The May 2026 King’s Speech contained none, and the only AI bill in the Lords is a private member’s bill without government backing. The approach set out in the 2023 DSIT white paper leaves five cross-sector principles for existing regulators to embed into their own regimes, which means AI is governed through the UK GDPR, the Data (Use and Access) Act 2025 and whatever your sector regulator says.

That is a defensible design. The problem is what it feels like from inside a company trying to get something signed off.

The ICO published draft updated guidance on automated decision-making and profiling on 31 March 2026 and consulted on it until 29 May. Final guidance was expected in summer 2026. Checked on 13 August and again on 25 August, the ICO’s own guidance-plans page gives the publication date as Winter 2026 (ICO). Its new agentic AI guidance is listed for Winter 2026 as well, still at drafting stage with no consultation planned.

So if your system makes or informs decisions about people, the definitive statement of what is expected of you is a document that does not yet exist, and the date it was due has already moved once.

In financial services it is starker. The Treasury Committee reported on 20 January 2026 that by taking a wait-and-see approach the regulators are not doing enough, and recommended that by the end of 2026 the FCA publish practical guidance on the accountability and level of assurance expected of senior managers under the Senior Managers Regime for harm caused through AI (Treasury Committee, Norton Rose Fulbright). Read that as a senior manager. A committee of MPs has said you are personally accountable for something, and separately noted that nobody has yet told you what good looks like.

Model risk has the same shape. The PRA’s SS1/23 has applied since 17 May 2024 and its five principles cover model identification, governance, development and use, independent validation and mitigants (Bank of England). It is deliberately technology-agnostic, and it predates widespread generative AI, so it does not address every risk these systems introduce.

Meanwhile the EU moved its high-risk deadlines to December 2027 while its transparency obligations went live on 2 August 2026, so anyone with EU exposure has watched those goalposts move too.

Nobody is being told no. They are being told to wait, by several people, on different timetables.

The honest counter-argument

I would be selling you something if I stopped there.

Regulation is not the biggest barrier globally. McKinsey’s 2026 AI Trust Maturity Survey, taken between December 2025 and January 2026 across roughly 500 organisations whose respondents own AI governance, risk or investment decisions, found nearly two-thirds naming security and risk concerns as the top barrier to fully scaling agentic AI, well ahead of regulatory uncertainty. Only about a third reached maturity level three or higher on strategy, governance and agentic AI controls (McKinsey, 25 March 2026).

So some of what gets written up as regulatory uncertainty in a board paper is an internal governance vacuum wearing a regulator’s coat. If nobody in your organisation can say which models are approved, who signs off a version change or who reads the audit trail, the ICO’s publication schedule is not your blocker.

The distinction matters because it decides what you do next. External uncertainty is something you position for. Internal uncertainty is something you fix on a Tuesday.

Waiting is not free either. Deloitte’s State of AI in the Enterprise 2026, published in January from 3,235 board, C-suite, vice-president and director-level leaders across 24 countries surveyed in August and September 2025, found only 25% of organisations had moved at least 40% of their AI experiments into production (Deloitte, European Commission Digital Skills and Jobs Platform). Every quarter a decision sits in the pending tray, the compounding advantage goes to whoever made it.

What actually helps

None of this is an argument for charging ahead. It is an argument for building so that the shape of the final rules costs you a rewrite rather than a rebuild. Five things do most of that work.

Run the production gates at the start. Security review, lawful basis and DPIA, audit trail, monitoring with a named owner and an honest three-year run cost. A pilot meets all five on the day it asks to go live. Meeting them at the design stage is cheap. Meeting them at the end is a rebuild.

Write the operating model on one page. Which models are approved and on what basis, who signs off a version change and on what evidence, who owns the evaluation set, who reads the audit trail and whose phone rings when behaviour drifts on a Wednesday afternoon. In the McKinsey survey, organisations with clear ownership for responsible AI averaged a maturity score of 2.6, against 1.8 for those with no clearly accountable function. One page is enough, and it is more than most pilots have.

Treat the model as a controlled component. Identified, pinned to a version, under change control, validated by somebody other than the person who built it. If you can’t say which version produced a decision, you can’t answer for the decision, and that is true regardless of what the FCA eventually publishes.

Keep autonomy minimum and deliberate. Give the system the least agency that delivers the outcome, and make every increase an evidenced decision. Autonomy that arrives by accident is how organisations end up doing automated decision-making without knowing they had started, which the ICO’s 2026 recruitment report found real employers doing (Inside Privacy).

Build the evidence as you go. Not because a regulator asked, but because every draft you have read, from the ICO, the NCSC’s secure AI development guidelines and its May 2026 agentic AI guidance, through to SS1/23, asks for versions of the same four things: know what you’re running, know why it decided, keep a human accountable, be able to show your work. That overlap is not a coincidence, and it is the most reliable forecast available of what the final rules will want.

We built our own recruitment platform, Idonara, to those rules before anyone required it. Explainable scoring where every result carries its evidence, an immutable audit trail from the first architecture session, a human making every decision that affects a person. It was slower for about six weeks and cheaper every week since.

What this does not do

I would rather say this plainly than have you discover it later.

None of the above makes you compliant with rules that have not been written. It will not protect you if final guidance lands somewhere nobody expected. It does not move personal accountability off the named senior manager, and after the Treasury Committee’s report it is moving in the other direction. It will not shorten your procurement cycle, and it will not turn a weak use case into a strong one.

What it does is narrow the gap between what you have built and whatever gets asked for, so that adapting is a change request rather than a programme. It mitigates. It does not de-risk. Anyone telling you they can de-risk adoption against unpublished regulation is selling something.

The rules are coming either way. The ICO’s final guidance has slipped from summer to winter, the FCA has been asked to publish by the end of the year, and the EU has already shown it will move a deadline when it suits. The organisations that come out of this well will not be the ones that guessed the rules correctly. They will be the ones who built something they could explain, whatever the rules turned out to say.

We write an occasional Insights note on what’s actually working in applied AI, what to ignore, and what new UK and EU regulation means in practice. No spam, and you can unsubscribe from any email. Subscribe on aiapplied.uk.

Insights

Occasional, useful notes on applied AI.

What's actually working, what to ignore, and what the new regulation means for UK businesses. No spam.

We’ll only use your email address to send you these Insights notes. We never share it, and you can unsubscribe from any email. See our Privacy Policy.

AI Services

Where we work

Company

Latest writing

AI Applied Ltd, Technology House, 9 Newton Place, Glasgow G3 7PR. Registered in Scotland SC806963. support@aiapplied.uk · +44 141 465 5233