The gap between deployment and readiness
A survey published in March 2026 found that only a small fraction of UK compliance professionals, around one in thirty, say their organisation is fully prepared for AI regulation. Close to a third are still working out which rules apply to them at all.
Regulators are not waiting for that gap to close.
What UK regulators have already confirmed
The FCA confirmed in 2024 that the Senior Managers and Certification Regime, Consumer Duty, and its Principles for Business already govern AI-influenced decisions. There is no separate AI regime being awaited: existing obligations apply now, to decisions an AI system makes or shapes today.
The ICO launched its AI enforcement strategy in June 2025, naming automated decision-making as a primary focus. In March 2026 it published findings from direct engagement with more than thirty employers. Its central finding was that most organisations do not recognise they are making solely automated decisions, and are doing so without the safeguards UK GDPR requires.
The pattern to watch: insurers are beginning to ask for documented AI governance at renewal, a trajectory that closely mirrors the early years of cyber insurance underwriting. Healthcare underwriters have already confirmed this shift publicly.
Why this is an economic problem, not just a compliance one
Organisations are deploying agentic systems that make consequential decisions with no named owner, no meaningful oversight, and no audit trail an external party can verify. The result is not only regulatory exposure. It shows up as AI waste, failure costs, broken workflows, and revenue leakage, all of which insurers are starting to price into renewals.
The question to be able to answer
If a regulator, an insurer, or a board member asked today who is accountable for a specific AI-influenced decision in your organisation, and asked to see the evidence, could you answer without a scramble?
Most organisations cannot. Not because the governance work is impossible, but because nobody has yet mapped their specific deployment against the specific obligations that already apply to it.
Where to start
CLEARANCE is a deterministic diagnostic built to answer that question directly. A ten-minute structured intake, evaluated against a fixed library of governance gaps mapped to named regulatory obligations, producing an evidence report delivered to your inbox within minutes of payment.
If you are deploying AI in a regulated sector and cannot yet answer the question a regulator or insurer will ask, this is where to start.