AI governance frameworks: Compare

A learning aid, not legal advice.

Depth, from 0 (least) to 3 (most)0123Under review
Frameworks to compare

Pick two or three frameworks.

Dimension
UK principles-based approach to AI regulation (white paper CP 815 and government response CP 1019)
voluntary guidance
Nature
Depth 1 of 3.

Non-statutory principles; the government keeps targeted binding requirements under review.

Government response (CP 1019)
Where and to whom it applies
Depth 2 of 3.

The United Kingdom, across all sectors, through each regulator's existing remit.

White paper (CP 815)
Roles addressed
Depth 1 of 3.

Addressed to regulators, who apply the principles to the organisations they supervise; no provider and deployer split.

Initial guidance for regulators; white paper
Risk approach
Depth 1 of 3.

Context-based: risk is judged by each regulator for its sector, not by a central list.

White paper (CP 815)
Inventory and documentation
Depth 1 of 3.

Central government departments must publish records under the Algorithmic Transparency Recording Standard; no inventory duty on companies.

ATRS mandatory scope and exemptions policy
Risk or impact assessment
Depth 1 of 3.

No general assessment duty; the planned AI Management Essentials self-assessment tool will not be published (government response, 2025-12).

AI Management Essentials, government response
Human oversight
Depth 2 of 3.

The Data (Use and Access) Act 2025 replaced UK GDPR Art. 22 with Arts. 22A to 22D: significant automated decisions need safeguards, including human intervention and a way to contest.

Data (Use and Access) Act 2025, s. 80
Transparency and notices
Depth 2 of 3.

Appropriate transparency and explainability is one of the five principles; public-sector algorithmic tools are recorded under ATRS.

White paper, five principles; ATRS policy
Data governance
Depth 2 of 3.

UK GDPR and the Data Protection Act 2018, as amended by the 2025 Act, govern personal data used in AI.

Data (Use and Access) Act 2025: data protection changes
Testing, robustness and security
Depth 1 of 3.

Safety, security and robustness is one of the five principles; the AI Security Institute (renamed 2025-02-14) tests advanced models.

White paper; government announcement of the renaming
Monitoring and incident reporting
Depth 0 of 3.
Under review
Assurance and enforcement
Depth 1 of 3.

Enforcement only through each regulator's existing powers; accountability and governance, and contestability and redress, are principles.

Government response (CP 1019)
Effort to implement
Depth 1 of 3.

Light to moderate, depending on the sector regulator and on data protection duties.

White paper (CP 815)
Key dates
Depth 3 of 3.

White paper 2023-03; response 2024-02-06; ATRS mandatory for departments from 2024-02-06; Data (Use and Access) Act assent 2025-06-19, s. 80 in force 2026-02-05.

Government response; Data (Use and Access) Act 2025 guidance

A learning aid, not legal advice. Where AI SENTINEL is mentioned, it supports or maps to the dimension; it does not certify anything. Dates are those the official texts state on the date shown.