Journey

Responding to an AI regulatory investigation

What to do when a UK regulator investigates your AI system: ICO enforcement, FCA investigation, EHRC inquiry, CMA review. Covers immediate steps, your rights, evidence preservation, cooperation obligations, and potential penalties.

Running a Business Updated 15 September 2026
references 4 guides

A regulator has contacted you about your AI system

Receiving a letter, email, or formal notice from a UK regulator about your use of artificial intelligence means they have concerns about how your AI system operates, the decisions it makes, or its impact on individuals. This could stem from a complaint, a data breach notification, a thematic review, or proactive monitoring.

The UK does not have a single AI regulator. Instead, existing regulators enforce AI rules within their own remits. You need to identify which regulator has contacted you and what powers they hold.

Which regulator is investigating?

The regulator that has contacted you determines the legal framework, the powers they can exercise, and the potential consequences. Multiple regulators may investigate the same AI system simultaneously if it raises concerns across different domains.

Which AI regulator applies to your business

Map your AI systems to the relevant UK regulators and understand their specific enforcement powers and requirements.

Immediate steps

  • Note the deadline for response: Regulatory letters specify response deadlines. Request an extension in writing before the deadline if you need more time.
  • Preserve all records: Do not delete, alter, or destroy any documents, data, logs, model outputs, or correspondence related to the AI system in question. Destruction of evidence is a criminal offence.
  • Identify the AI system(s) in question: Establish exactly which AI system or automated decision-making process is being investigated.
  • Gather documentation: Collect DPIAs, model inventories, testing records, bias assessments, transparency notices, training data records, and human oversight procedures.
  • Seek specialist legal advice: AI regulatory investigations span multiple legal frameworks. Engage a solicitor with experience in regulatory enforcement and AI governance.
  • Notify your DPO: If you have a Data Protection Officer, involve them immediately. Also notify senior management and any AI governance lead.

Your documentation matters

Regulators will ask for evidence that you took a responsible approach to AI governance before the investigation began. Organisations that can demonstrate documented compliance processes typically receive more favourable outcomes.

Understanding potential penalties

Each regulator has its own enforcement powers and penalty framework. Penalties range from informal recommendations to significant financial sanctions. Cooperation and remedial action are mitigating factors across all regulators.

Assess and strengthen your compliance

Whether or not the regulator takes formal action, use the investigation as an opportunity to review and improve your AI governance. Regulators view proactive improvement favourably and it reduces the risk of future enforcement.

AI compliance assessment

Structured assessment to evaluate your AI governance maturity and identify priority compliance gaps.

AI governance framework

Build or strengthen your AI governance framework covering risk assessment, accountability, human oversight, and ongoing monitoring.

After the investigation

Once the investigation concludes, record lessons learned and implement any changes the regulator has recommended or required. Maintain evidence of improvements — regulators may follow up and will expect demonstrable progress.

AI compliance checklist

Comprehensive checklist covering data protection, transparency, fairness, oversight, and record keeping for AI systems.