Living reference · Updated 24 July 2026

UK Technology Regulation Tracker

What is in force, what is proposed and what happens next. Every entry links to the responsible public authority, with proposals clearly separated from current duties.

Method

Read the status before the headline.

This is an editorial reference, not legal advice. We check official legislation, parliamentary records and regulator publications, record concrete dates and update an entry when its legal or procedural status materially changes.

“Open consultation” and “In Parliament” do not mean a proposal is law. “In force” may still involve staged guidance, enforcement or secondary rules.

01
Open consultation

Data regulation in the age of AI

The government opened a call for evidence on 15 July 2026 about whether UK data rules remain effective for AI and other data-intensive technologies.

Who it affects
AI developers, deployers, data holders, researchers and people whose information is used.
What happens next
Responses close on 9 September 2026. This is evidence-gathering, not a new AI Act or a settled legal change.
02
In Parliament

Cyber Security and Resilience Bill

The bill was carried over and reintroduced on 14 May 2026 after completing Commons second reading and committee scrutiny.

Who it affects
Proposed additions include data centres, managed service providers and other suppliers supporting essential or digital services.
What happens next
Commons report stage and third reading remain ahead. Duties can still change before Royal Assent and secondary legislation.
03
In force

Online Safety Act implementation

Ofcom’s implementation continues in stages. A new child sexual exploitation and abuse reporting duty entered force on 7 April 2026.

Who it affects
User-to-user and search services in scope of the Act, with duties varying by service, risk and reach.
What happens next
Providers should follow Ofcom’s current roadmap and industry bulletins rather than treat the Act as a single commencement date.
04
Phased commencement

Data (Use and Access) Act 2025

The Act received Royal Assent on 19 June 2025. Its data-protection, digital-verification and Smart Data measures are being commenced in phases.

Who it affects
Organisations processing personal data, digital verification providers and sectors covered by future Smart Data schemes.
What happens next
Check the government commencement plan and individual regulations before assuming that a particular provision is operational.
05
Active oversight

Critical Third Parties to UK finance

Direct joint oversight began on 13 July 2026 for designated entities of AWS, Google Cloud, Microsoft and Oracle.

Who it affects
The designated providers and the banks, insurers and market infrastructures that depend on their specified critical services.
What happens next
Providers enter assurance, testing and incident-reporting work. Financial firms retain responsibility for outsourcing and resilience.
06
In force

Consumer connectable product security

The UK’s product-security regime has applied since 29 April 2024, including rules on default passwords, vulnerability reporting and security-update information.

Who it affects
Manufacturers, importers and distributors of consumer connectable products placed on the UK market.
What happens next
Enforcement and product lifecycle practice matter now; this is no longer a future compliance programme.
07
Open consultation

Digital markets: mobile platforms

Apple and Google have strategic market status for their mobile platforms. The CMA is consulting on proposed requirements, including app-store steering.

Who it affects
Mobile-platform operators, app developers, payment providers and UK consumers.
What happens next
The current consultation closes on 28 July 2026. Proposed requirements are not final obligations until the CMA completes its process.

Corrections and updates

See something that changed?

Send the official source and the relevant entry to editor@uktechtrend.co.uk. Material factual corrections are recorded under UK Tech Trend’s editorial policy.