UK regulators map AI sandbox plans and EU Act enforcement
The Information Commissioner’s Office is assessing a data protection Statutory Regulatory Sandbox that would let innovators test emerging technologies, including AI and automated decision-making, under time-limited derogations from parts of data protection law. The ICO recommends primary legislation to establish the regime, with safeguards covering civil claims, oversight of personal information, protections for children and transparency requirements.
The ICO also audited five police forces in England and Wales on facial recognition technology, issuing 107 recommendations across live and retrospective uses. Priorities include stronger governance, updated documentation, clearer processing records, appropriate image sourcing, retention controls, and regular checks on accuracy and bias.
The National Cyber Security Centre issued initial advice for deploying agentic AI systems securely, focusing on clear instructions, human oversight, sandbox boundaries and telemetry access. The government also opened a call for evidence closing on 6 November 2026 on how AI could transform the energy system and inform the UK’s “AI for Clean Energy Strategy”.
In the EU, the AI Office and national authorities gained powers from 2 August 2026 to enforce selected EU AI Act provisions, including prohibited practices, general-purpose AI obligations and transparency rules. CEN and CENELEC approved the first European standard supporting AI Act implementation, focused on quality management systems for providers of AI systems.