Who this is for: UK compliance officers, data protection officers (DPOs), AI deployers subject to UK GDPR, Notified Bodies evaluating dual UK/EU compliance, and legal teams advising on the UK's emerging AI regulatory framework.
CRITICAL ASSESSOR NOTICE: This guide is published by the platform vendor (Tenable Nova LLC). Assessors must independently verify all claims against primary regulatory texts and their own professional judgment. SWT3 creates evidence records; it does not make compliance determinations.
Legislative status update (August 25, 2026): The UK has not enacted a standalone AI safety bill. The AI Regulation and Safety Bill, originally a Private Member's Bill (PMB) introduced by Lord Holmes, did not advance to Royal Assent. Instead, the UK is pursuing AI regulation through sector-specific amendments to existing legislation. The Crime and Policing Act 2026 (Royal Assent April 29, 2026) amended the Online Safety Act to cover AI-generated illegal content. The King's Speech 2026 referenced a Cyber Security Bill, AI regulatory sandboxes, and digital identity measures, but no dedicated AI safety bill. The UK currently regulates AI through UK GDPR, the Data (Use and Access) Act 2025, and sector-specific regulators (FCA, MHRA, OFCOM). UK businesses with EU customers also face EU AI Act requirements from August 2, 2026 (Article 2 extraterritorial reach). This guide maps the bill's provisions to SWT3 witness infrastructure for organizations preparing for eventual UK AI legislation.
Contents
1. The UK AI Regulatory Landscape 2. What the Bill Proposes 3. Obligation-to-Procedure Mapping 4. SWT3 Procedure Cards 5. Dual UK/EU Compliance 6. Quick Reference 7. Quick Start 8. References1. The UK AI Regulatory Landscape
The UK is on the verge of its first dedicated AI statute. The AI Regulation and Safety Bill cleared the House of Commons in August 2026, with Royal Assent expected by October 2026. Until enactment, AI systems are governed through existing laws and sector-specific regulators, each applying established frameworks to new technology.
UK GDPR Article 22 provides rights around automated decision-making: the right to human review, meaningful information about the logic involved, and the right to contest decisions made solely by automated processing that produce legal or similarly significant effects.
Data (Use and Access) Act 2025 establishes the framework for digital verification and smart data schemes. It modernizes the UK's data governance infrastructure and creates the legal basis for trusted digital identity services.
Sector-specific regulators apply existing mandates to AI within their domains:
- FCA (Financial Conduct Authority) -- AI in financial services, algorithmic trading, credit decisioning
- MHRA (Medicines and Healthcare products Regulatory Agency) -- medical device AI, Software as a Medical Device (SaMD)
- OFCOM -- online safety obligations, recommender system transparency, age assurance AI
UK AI Safety Institute (AISI) currently operates in an advisory capacity, testing frontier models and publishing safety evaluations. Once the bill receives Royal Assent, AISI will gain statutory audit authority over high-capability AI systems. The Australia-UK Memorandum of Understanding on AI safety cooperation was signed on May 24, 2026, establishing bilateral evaluation sharing.
EU AI Act extraterritorial reach: UK businesses serving EU customers need EU AI Act compliance from August 2, 2026. Article 2 of the EU AI Act applies to providers and deployers outside the EU when AI system output is used within the Union. This creates a dual compliance reality for any UK organization with EU-facing operations.
2. What the Bill Proposes
| Provision | Requirement | Status |
|---|---|---|
| AI Safety Institute | Statutory audit authority over high-capability AI | Commons passed |
| Mandatory reporting | Developers must report critical safety incidents | Commons passed |
| High-risk notification | Registration requirement for high-risk AI systems | Commons passed |
| Transparency | Users must be informed when interacting with AI | Commons passed |
| Human oversight | Meaningful human control over high-risk decisions | Commons passed |
| Regulatory coordination | AISI coordinates with sector regulators (FCA, MHRA, OFCOM) | Commons passed |
| International cooperation | AISI cooperates with international safety institutes | Active (MOU with Australia) |
3. Obligation-to-Procedure Mapping
| Bill Provision | Evidence Required | SWT3 Procedure |
|---|---|---|
| Safety evaluation | Risk assessment records | AI-RISK.1 |
| Guardrail enforcement | Guardrail status per inference | AI-GRD.1 |
| Transparency disclosure | User notification records | AI-TRANS.1 |
| Explainability | Decision rationale artifacts | AI-EXPL.1 |
| Human oversight | Human-in-the-loop records | AI-HITL.1 |
| Fairness/non-discrimination | Bias evaluation evidence | AI-FAIR.1 |
| Audit trail | Immutable operation logs | AI-AUDIT.1 |
| Logging pipeline | Structured event capture | AI-LOG.1 |
4. SWT3 Procedure Cards
Eight SWT3 procedures produce the evidence chain most relevant to the UK AI Regulation and Safety Bill.
Risk Assessment
Bill context: The bill would require AI developers to conduct and document risk assessments for high-capability models. AISI would have authority to review these assessments and request additional evaluation.
How SWT3 witnesses it: Records risk assessment events with timestamped anchors. Each assessment produces a Witness Anchor documenting the model evaluated, risk factors identified, and mitigations applied. Creates an auditable history of risk management decisions.
AI-RISK.1 anchors prove risk assessments were conducted and when. Cross-reference with AI-GRD.1 to verify that identified risks led to corresponding guardrail configurations. A risk assessment without follow-up guardrails is a gap.
Guardrail Enforcement
Bill context: Safety evaluations must demonstrate that appropriate guardrails are in place. AISI audit authority means organizations must prove guardrails are not only configured but actively enforced during operation.
How SWT3 witnesses it: Records guardrail status per inference -- whether guardrails were active, whether they triggered, and what type of intervention occurred. Creates continuous evidence of safety enforcement, not just configuration.
AI-GRD.1 anchors show guardrails were active during operation, not just documented in policy. For AISI audit readiness, verify continuous guardrail coverage with no gaps during active deployment periods.
Transparency Record
Bill context: Users must be informed when interacting with AI systems. The bill aligns with EU AI Act Article 50 transparency obligations, creating a dual compliance opportunity for UK/EU deployers.
How SWT3 witnesses it: Records what transparency measures were active during each interaction -- what disclosures were shown, whether the system identified itself as AI, and what limitations were communicated. Timestamped per interaction.
AI-TRANS.1 anchors are primary evidence for transparency compliance. Verify disclosure was conspicuous and per-interaction, not a one-time buried disclaimer. Cross-reference with EU AI Act Art. 50 requirements if the organization serves EU customers.
Explainability Evidence
Bill context: AISI would have authority to request explanations of AI system behavior. Organizations must demonstrate they can explain why their systems produce specific outputs, particularly for high-risk decisions.
How SWT3 witnesses it: Records explainability artifacts -- feature importance, attention patterns, reasoning traces. Creates evidence that the organization can substantiate its AI system's decision-making process on demand.
AI-EXPL.1 anchors demonstrate good-faith explainability effort. For high-risk systems, verify that explainability_method is substantive (not placeholder) and key_factors reflect meaningful decision inputs.
Human Oversight
Bill context: The bill emphasizes meaningful human control over high-risk AI decisions. This aligns with UK GDPR Article 22 (right to human review of automated decisions with legal effects) and extends it to a broader range of AI systems.
How SWT3 witnesses it: Records human-in-the-loop events -- when a human reviewed, approved, or overrode an AI decision. Creates evidence of meaningful human oversight, not rubber-stamp approval.
AI-HITL.1 anchors prove human oversight occurred. Check that review timestamps show reasonable review duration (instant approvals suggest rubber-stamping). Cross-reference with AI-RISK.1 to verify high-risk decisions received proportionate human review.
Fairness Evaluation
Bill context: The bill's non-discrimination provisions require organizations to evaluate AI systems for bias across protected characteristics. This intersects with the Equality Act 2010 and UK GDPR data protection impact assessments.
How SWT3 witnesses it: Records fairness evaluation events -- bias metrics, demographic parity scores, and evaluation methodology. Creates evidence of proactive bias monitoring, not reactive remediation.
AI-FAIR.1 anchors show bias evaluation was conducted systematically. Verify evaluation covered relevant protected characteristics under the Equality Act 2010. Sporadic evaluation is a gap -- look for regular cadence.
Audit Trail
Bill context: AISI statutory audit authority means organizations must maintain comprehensive, tamper-evident audit trails. The ability to reconstruct AI system behavior over time is foundational to regulatory cooperation.
How SWT3 witnesses it: Every witness anchor is an audit trail entry by design. The append-only ledger with cryptographic fingerprints ensures records cannot be altered after the fact. Forensic timeline reconstruction via swt3 reconstruct enables full operational replay.
AI-AUDIT.1 is the foundational procedure. Verify anchor continuity -- gaps in the audit trail during active deployment are the most significant finding. Use swt3 reconstruct --cycle to trace multi-step operations.
Logging Pipeline
Bill context: Structured logging underpins every other obligation. Incident reporting requires logs. Transparency requires interaction records. AISI audit authority requires retrievable operational data.
How SWT3 witnesses it: Records logging pipeline health -- log completeness, delivery confirmation, and structured event capture. Ensures the infrastructure supporting all other procedures is itself monitored and witnessed.
AI-LOG.1 anchors prove the logging pipeline was operational. A gap in AI-LOG.1 during a period with active AI-INF.1 anchors indicates selective logging -- a serious finding.
5. Dual UK/EU Compliance
| UK Bill Provision | EU AI Act Article | Shared SWT3 Procedure |
|---|---|---|
| Transparency disclosure | Art. 50 (transparency) | AI-TRANS.1 |
| Human oversight | Art. 14 (human oversight) | AI-HITL.1 |
| Risk assessment | Art. 9 (risk management) | AI-RISK.1 |
| Safety evaluation | Art. 9 + Annex IV | AI-GRD.1 |
| Bias monitoring | Art. 10 (data governance) | AI-FAIR.1 |
| Incident reporting | Art. 62 (serious incidents) | AI-LOG.1 |
| Audit readiness | Art. 12 (record-keeping) | AI-AUDIT.1 |
| Explainability | Art. 13 (transparency) | AI-EXPL.1 |
Organizations running SWT3 for EU AI Act compliance already have the evidence infrastructure for the UK bill. The same witness anchors satisfy both jurisdictions. Rather than maintaining separate compliance programs, SWT3's framework-agnostic witness architecture generates evidence once and maps it to both regulatory contexts. This is particularly relevant for organizations with operations in both the UK and EU -- a common pattern since Brexit created dual regulatory exposure.
6. Quick Reference
| AISI Auditor Question | Where to Look |
|---|---|
| Has the organization assessed risks for this AI system? | AI-RISK.1 anchors with risk_factors and mitigations fields. Cross-reference with AI-GRD.1 for implementation evidence. |
| Were users told they were interacting with AI? | AI-TRANS.1 anchors with disclosure_type. Verify per-interaction, not one-time. |
| Can the organization explain this output? | AI-EXPL.1 anchors linked to the inference via inference_id. Check explainability_method and key_factors. |
| Was there human oversight for this high-risk decision? | AI-HITL.1 anchors with review_duration and reviewer_id. Check timing relative to AI output. |
| Are guardrails actively enforced? | AI-GRD.1 anchors showing continuous coverage during deployment. Gaps indicate periods without guardrail enforcement. |
| Is the audit trail tamper-evident? | Witness Anchor fingerprints are SHA-256 hashes. Verify via swt3 verify --enclave or the public verifier at sovereign.tenova.io/verify. |
7. Quick Start
pip install swt3-ai
from swt3_ai import WitnessClient
client = WitnessClient(
tenant_id="your-tenant-id",
api_key="axm_live_..."
)
# Record a risk assessment for AISI readiness
client.witness_risk_assessment(
model_id="your-model",
risk_factors=["bias", "hallucination", "privacy"],
mitigations=["guardrails", "human_review", "data_filtering"]
)
# Record transparency disclosure
client.witness_transparency(
disclosure_type="ai_interaction",
disclosure_text="You are interacting with an AI assistant.",
conspicuous=True
)
# Run the demo to see it in action
python -m swt3_ai.demo
Full SDK documentation: sovereign.tenova.io/docs
Create a free account: sovereign.tenova.io/signup
8. References
- UK Parliament: AI Regulation and Safety Bill [HL] (bills.parliament.uk)
- UK AI Safety Institute (gov.uk)
- Data (Use and Access) Act 2025 (legislation.gov.uk)
- UK GDPR and Data Protection Act 2018 (legislation.gov.uk)
- EU AI Act crosswalk guide (SWT3 Protocol)
- EU AI Act August 2026 Checklist (SWT3 Protocol)
- Cryptographic AI Evidence Quickstart (SWT3 Protocol)
- SWT3 SDK Documentation (sovereign.tenova.io/docs)
- Create a free account (sovereign.tenova.io/signup)