Artificial intelligence is advancing at a pace that regulators are struggling to match, leaving businesses that build, deploy and use AI to navigate an increasingly fragmented and uncertain rulebook.
A new whitepaper from LexisNexis Regulatory Compliance, titled ‘Navigating the challenges of AI regulation’, maps how jurisdictions across the world are responding, and warns that the gap between innovation and oversight is creating real exposure for firms.
According to the report, regulators face three persistent obstacles. There is still no agreed definition of what counts as AI for regulatory purposes, many systems operate as opaque “black boxes” that are difficult to audit or hold to account, and AI routinely crosses borders, complicating questions of jurisdiction. Policymakers must also strike a careful balance, as heavy-handed rules risk stifling innovation while light-touch regimes could allow harm to spread unchecked.
The result is a patchwork of approaches. The EU has opted for its prescriptive AI Act, the UK continues to favour a principles-based model led by existing regulators, and the US relies on a collection of state laws in the absence of a single federal statute. Meanwhile, several countries are retreating from previously planned mandatory frameworks.
In the UK, the government has avoided a standalone AI law, instead empowering regulators to apply five high-level principles: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. Existing legislation is already doing much of the heavy lifting. The Online Safety Act 2023, while not designed specifically for AI, directly affects recommender systems, content moderation tools, search algorithms and generative AI. Ofcom has made clear that algorithmic decision-making falls within the regulated service, meaning governance failures could quickly become enforcement risks, even where AI is supplied by third parties.
The Data (Use and Access) Act 2025 stops short of banning the use of copyrighted material in AI training, but commits the government to report on the issue within nine months of the Act taking effect. Broader legislation has been pushed back, with the first UK AI Bill now unlikely before the second half of 2026. Proposals in the pipeline include a Frontier AI Bill that would place the AI Security Institute on a statutory footing, alongside an AI Growth Lab designed to act as a cross-economy regulatory sandbox.
Beyond the UK, the EU AI Act sets out a risk-based structure, banning systems that pose unacceptable risks and imposing strict requirements on high-risk applications, supported by a new AI Office.
In the US, federal policy under “America’s AI Action Plan” prioritises global AI dominance, while regulation remains fragmented across states. China has introduced generative AI measures and, from 1 September 2025, mandatory labelling of AI-generated content, though vague references to “socialist values” have raised concerns about self-censorship.
The whitepaper covers various a range of areas on the evolving AI regulatory landscape. It explores how the UK’s five AI principles are being applied, the existing UK regimes that affect AI systems, how the EU AI Act’s risk-based approach compares to the fragmented US landscape, the key challenges facing regulators and practical steps businesses can take to build responsible AI practices.
For more insights, the whitepaper can be downloaded here.
Copyright © 2026 FinTech Global
Investors
The following investor(s) were tagged in this article.















Leave a Reply