The ICO Doesn't Need an AI Act to Fine You

By Meena Birk

Last week, on 2 August 2026, the European Commission's enforcement powers over general purpose AI models came into force. Fines of up to €35 million or 7% of global turnover for the largest infringements. Direct model evaluations. The power to pull a model from the EU market. It is a genuinely significant date, and most UK compliance conversations this month are about it.

That is the wrong fine to be worried about if you are a UK SME.

The EU story everyone is watching

The headline is real. From 2 August 2026, the Commission's AI Office can request documentation from providers of general purpose AI models, run technical evaluations, order corrective measures, and issue fines. The obligations themselves are not new; they have applied since August 2025. What changed is enforcement. The Commission finally has teeth.

Separately, the EU's Digital Omnibus package has pushed back several high-risk system deadlines. Standalone high-risk systems under Annex III now have until December 2027. That relief is real too, but it only applies to high-risk classification under the EU AI Act. It says nothing about your obligations under UK data protection law, and it says nothing about the ICO.

The story that should worry you is closer to home

The UK has no AI Act. What it has is an active regulator using existing powers, and a recent track record that most SMEs have not clocked.

  • In February 2026, the ICO fined Reddit £14.47 million over failures in how it processed children's personal data.

  • Capita received the ICO's largest ever settlement, at £14 million, notable because it was the ICO's first major enforcement action against a data processor rather than a controller.

  • Genetic testing company 23andMe was fined £2.31 million after a credential stuffing attack compromised UK user accounts, the fine reduced from an original £4.59 million after the company made representations.

  • Password manager LastPass was fined £1.23 million on similar grounds.

None of these were "AI fines." None of them needed a bespoke AI law to happen. Every one was a failure of basic technical and organisational measures under UK GDPR: inadequate authentication, unpatched known vulnerabilities, unclear processor accountability, insufficient safeguards around a vulnerable group's data. These are exactly the control gaps that show up when a company deploys an AI system without documented governance around it.

The ICO's powers just got bigger, not smaller

Two things happened this year that raise the stakes further.

The Data (Use and Access) Act came into force on 5 February 2026. It gives the ICO new compulsion powers and raises the maximum PECR fine to £17.5 million or 4% of global turnover, the same ceiling that already applies to UK GDPR breaches. Cookie consent, marketing communications and electronic communications failures can now produce multi-million-pound notices for the first time.

Then, in May 2026, a statutory instrument placed the Information Commissioner under a duty to prepare a Code of Practice on AI and automated decision-making. The Code itself is still being drafted, with final guidance expected later this year. Once published, it sits alongside UK GDPR as binding guidance. Failing to follow it will be treated as evidence of non-compliance in enforcement proceedings, whether or not a company has ever heard of "the AI Code."

The pattern SMEs keep missing

The mistake we see most often is treating "AI regulation" as a future problem tied to a law that has not fully landed yet. It leads companies to wait. Wait for the EU AI Act's high-risk deadlines. Wait for the ICO's AI Code to be finalised. Wait for clarity before doing anything.

That is backwards. The enforcement record above shows the ICO does not need a finished AI Code to fine a company for exactly the kind of gap an AI system introduces: unclear data flows, no human oversight record, no documented risk assessment, no evidence trail showing anyone checked the system before or after deployment. Enforcement under existing UK GDPR powers is already live, already well funded, and already targeting the same control failures that AI governance frameworks exist to close.

The regulators are not waiting for a dedicated AI law. Companies should not be waiting either.

What this actually means for your business

If you are an SME using AI in any customer-facing or data-processing capacity, whether that is a chatbot, a scoring model, a recommendation engine, or a vendor's embedded AI feature, the questions the ICO's own enforcement pattern points to are direct:

  • Do you have a documented data governance record for every system that touches personal data, including AI tools bought from vendors?

  • Can you show a named person reviewed and signed off on that system's risk profile?

  • If a regulator asked tomorrow, could you produce evidence, not just a policy document, that oversight actually happened?

Most SMEs cannot answer yes to all three. That is not a reason to panic. It is a reason to get a governance record in place before an incident forces the question, rather than after.

That is the gap our framework is built to close: a structured way to document data governance and operational oversight so the evidence exists before a regulator ever asks for it.

Where AI Assured fits: our framework's data governance and operational domains map directly onto the control failures behind every fine above, not because we chase EU AI Act deadlines, but because UK GDPR enforcement already rewards companies that can show their working.

Sources

  • European Commission, AI Office enforcement powers for general purpose AI models, effective 2 August 2026

  • Gibson Dunn, analysis of the EU Digital Omnibus package and revised AI Act high-risk deadlines

  • ICO enforcement notices: Reddit (February 2026), Capita, 23andMe, LastPass

  • UK Data (Use and Access) Act 2025, in force from 5 February 2026

  • SI 2026/425, statutory duty on the Information Commissioner to prepare a Code of Practice on AI and automated decision-making, in force 12 May 2026

Keep Reading