Guide
AI compliance checklist
Quick verification checklist covering all major AI compliance obligations. Use this checklist to confirm your business meets its data protection, equality, transparency, oversight, and record-keeping obligations when using AI systems.
Check your business follows the rules when using AI systems. You must protect data, treat people fairly, explain how your AI works, and keep records. If you break the rules, regulators can fine you.
- Check your AI follows data protection laws
- Ensure your AI decisions are fair and not biased
- Explain how your AI makes decisions when asked
- Assess and reduce risks from using AI
- Keep records of how you use AI
- Follow the UK's 5 AI principles for safety and fairness
- Fines can be up to £17.5 million for data breaches
- Other regulators can impose unlimited fines
- Use the linked guides for more detailed help
- Rules may become law by 2026
Use this checklist to verify that your business meets its AI compliance obligations. It covers the key requirements from data protection law, equality law, health and safety law, and the UK's AI regulatory principles.
Work through each section and resolve any gaps before moving on. If you identify areas where you are not compliant, refer to the detailed guidance linked at the end of this checklist.
Data protection
Equality and fairness
Transparency and explainability
Risk and safety
Governance and record-keeping
The UK's five AI regulatory principles
Your compliance arrangements should align with the five principles that guide all UK regulators in their approach to AI.
Enforcement and penalties
Multiple regulators can take enforcement action if your AI systems breach their requirements. The penalties vary by regulator and the severity of the breach.
Act on compliance gaps immediately
If you identified gaps in any section, address them as a priority. AI compliance failures can trigger enforcement action from multiple regulators simultaneously. The ICO, EHRC, FCA, HSE, and CMA all have powers to investigate and sanction businesses that fail to manage AI responsibly. Do not wait for a complaint or investigation to act — regulators expect proactive compliance.
Related guidance
- Assess your AI compliance obligations for a step-by-step assessment of which obligations apply to your business
- Set up an AI governance framework for detailed guidance on accountability, transparency, fairness, and record-keeping
- AI transparency and explainability obligations for practical approaches to explaining AI decisions