Solutions — instrument
The UK delegates AI to the regulators you already answer to.
The pro-innovation approach delegates AI to existing regulators — the FCA, the ICO, the MHRA — rather than creating a cross-cutting statute. So the binding obligations come from the sector regulator you already answer to, and the evidence they will ask for is the same evidence in every case: who authorised this, what bounded it, and what happened.
What binds instead
- UK GDPR and the DPA 2018
- Binding today, and close enough to the EU clause map that the same evidence answers most of it — with the divergences worth reading rather than assumed away.
- FCA and PRA expectations
- The Senior Managers and Certification Regime already demands that a named individual is accountable for a function. An agent acting under authority nobody signed for is a problem under SM&CR before it is a problem under any AI rule.
- The five principles
- Safety, transparency, fairness, accountability and contestability. The last two are what a governance record is for — and contestability in particular needs the causal chain behind one decision, not a summary.
Two different facts sit close together here and are worth keeping apart. There being no AI statute is a fact about the UK. There being no UK market profile yet is a fact about the platform: a deployment picks from EU, US, Singapore and Australia, so a UK institution selects the EU profile and reads the divergences off itself. UK GDPR and the DPA 2018 are a distinct instrument, and enumerating those divergences is authoring work rather than anything the framework's shape prevents.
RotaGrant ships no clause map for the UK framework. The engine takes clause maps as data, so one can be authored — by you, by your counsel, or with us — and it will be scored like any other. What this page will not do is imply a mapping that does not exist, because a readiness percentage against an instrument nobody encoded is a number with no denominator.