The short answer
The significant legal changes for UK firms in 2026 are in data, online safety and AI rather than in general law. Key provisions of the Data (Use and Access) Act 2025 took effect on 5 February 2026, amending the UK GDPR and PECR and giving the ICO enhanced enforcement powers including PECR fines of up to £17.5 million or 4% of global turnover. Section 138 of the same Act took effect on 6 February 2026, criminalising the creation of non-consensual intimate images including AI deepfakes. Two new Online Safety Act priority offences came into force on 8 January 2026.
The deadline most firms have missed
From 19 June 2026, the requirement to implement data protection complaint-handling processes under the Data (Use and Access) Act takes effect. That is an operational obligation requiring a documented process, not a policy statement, and it applies to firms as data controllers in their own right.
The Data (Use and Access) Act 2025
The DUA Act received Royal Assent on 19 June 2025 and has been commenced in phases through secondary legislation rather than all at once, which is why its effects have arrived piecemeal.
The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, made on 29 January 2026, brought key provisions into effect on 5 February 2026. These amend both the UK GDPR and the Privacy and Electronic Communications Regulations.
Three changes matter operationally:
- Enhanced ICO enforcement. The ICO can now issue GDPR-style fines of up to £17.5 million or 4% of global turnover under PECR, a substantial increase on the previous ceiling.
- Stronger investigatory powers. The ICO can compel a witness such as a manager or employee to attend interview, with giving a false statement in response being an offence, and can require production of specific documents including data protection impact assessments and transfer risk assessments through an information notice.
- Revised timeframes and exemptions. The tranche includes changes to data subject rights response timeframes, privacy notice exemptions, and children’s higher protection matters, alongside a reformulated adequacy test for international transfers.
The deadline still ahead is 19 June 2026, when the requirement to implement data protection complaint-handling processes takes effect.
Why this lands on law firms directly
Firms are data controllers processing substantial volumes of personal data, much of it special category. The enhanced ICO powers apply to them as they apply to clients, and the ability to compel an employee to interview and to demand a specific DPIA changes what “we have a policy” is worth in an investigation.
The deepfake creation offence
This is the single most significant new criminal offence for practitioners to know about, and it is narrower and sharper than most summaries suggest.
Section 138 of the Data (Use and Access) Act 2025 was brought into force on 6 February 2026 by the Commencement No. 5 Regulations, made on 20 January 2026. It amends the Sexual Offences Act 2003 so that “intimate image” captures AI-generated and digitally manipulated content.
The offence is creating, or requesting the creation of, a purported intimate image of an adult without consent or reasonable belief in consent. Two features distinguish it from the existing framework:
- Creation, not just distribution. Previous offences targeted sharing. This targets production.
- The request alone suffices. An offence is committed even if the image is never produced or shared.
That second point is what practitioners most often get wrong. A person who commissions such an image has committed the offence at the point of asking, regardless of the outcome.
Online Safety Act enforcement
The Online Safety Act 2023 has moved from framework to enforcement, and the priority offence list has expanded.
On 8 January 2026 the Online Safety Act 2023 (Priority Offences) (Amendment) Regulations 2025 came into force, creating two new priority offences: making, encouraging or assisting serious self-harm, and cyber flashing. Both were already criminal offences; designating them as priority offences means regulated platforms must remove such content once aware of it and take steps to prevent it appearing.
Ofcom’s enforcement powers are substantial, with fines of up to 10% of global turnover available for failures in this area.
Further measures are in progress rather than in force. On 19 February 2026 the government announced an amendment to the Crime and Policing Bill requiring regulated service providers to take down non-consensual intimate images within 48 hours of notification. A separate amendment would bring AI chatbot providers not currently within the Online Safety Act’s scope into the regime, addressing the gap where a chatbot operating independently of a regulated social media service falls outside Ofcom’s powers entirely.
In force versus announced
The priority offences are in force. The 48-hour takedown requirement and the AI chatbot provisions are proposed amendments to a Bill still progressing through Parliament. Advising a client that either is currently binding would be wrong.
The Cyber Security and Resilience Bill
The Cyber Security and Resilience (Network and Information Systems) Bill was introduced to Parliament on 12 November 2025 and received its second reading on 6 January 2026. It is not yet law.
Its proposals include a strengthened enforcement regime with maximum penalties aligned to GDPR levels, and powers for the Secretary of State to instruct regulators and regulated organisations in emergencies.
For firms advising clients in regulated sectors, the practical question is scope: which organisations will fall within the regime and what incident reporting will be required. Those answers depend on the Bill’s final form and the secondary legislation that follows it.
Where AI regulation actually stands
This is the area where commentary most often outruns the law, so it is worth stating the position plainly.
The UK has not enacted a comprehensive AI statute equivalent to the EU AI Act. What exists is regulation of AI through existing regimes: data protection law governs AI systems processing personal data, the Online Safety Act governs AI-generated content on regulated platforms, and section 138 of the DUA Act criminalises a specific category of AI-generated imagery.
The unresolved questions remain unresolved. The use of copyright-protected material in AI training has been the subject of sustained consultation and dispute without a settled statutory answer. Obligations to label AI-generated content have been discussed rather than legislated.
For solicitors, the immediately binding constraints on AI use come from professional obligations rather than AI-specific statute. The duty not to mislead the court, the competence and supervision duties, and confidentiality all apply to AI-assisted work, as our guides to fake AI citations and AI in legal practice set out.
What this means for law firms
Three obligations land on firms directly rather than on their clients.
Data protection compliance needs revisiting. The February 2026 amendments changed response timeframes, privacy notice exemptions and international transfer assessment. A privacy notice last reviewed in 2024 is describing a different regime.
The June 2026 complaint-handling requirement is operational. It requires a process that works, not a policy that exists, and the ICO’s new power to demand specific documents means the evidence has to be producible.
Advising on the deepfake offence requires precision. Family, employment and criminal practitioners are most likely to encounter it, and the creation-and-request structure is materially different from the distribution offences that preceded it.
The wider justice-system reforms, including fixed recoverable costs, the ADR amendments and sentencing, are covered separately in our guide to Ministry of Justice reforms.
Compliance actions arising
- Review privacy notices against the February 2026 UK GDPR amendments
- Check data subject rights response timeframes reflect the revised position
- Build and document a data protection complaint-handling process before 19 June 2026
- Confirm DPIAs and transfer risk assessments exist and are producible on demand
- Review marketing consent practices against the increased PECR penalty exposure
- Brief relevant practice areas on the section 138 creation and request offence
- Track the Crime and Policing Bill amendments rather than treating them as current law
Frequently asked questions
What new laws came into force in the UK in 2026?
Key provisions of the Data (Use and Access) Act 2025 took effect on 5 February 2026, amending the UK GDPR and PECR. Section 138 of the same Act, criminalising creation of non-consensual intimate images including deepfakes, took effect on 6 February 2026. Two new Online Safety Act priority offences came into force on 8 January 2026.
Is it now illegal to create a deepfake in the UK?
Creating, or requesting the creation of, a purported intimate image of an adult without consent is a criminal offence from 6 February 2026 under section 138 of the Data (Use and Access) Act 2025, which amends the Sexual Offences Act 2003. The offence is committed even if the image is never produced or shared.
What are the new ICO enforcement powers?
The ICO can issue fines of up to £17.5 million or 4% of global turnover under PECR, compel witnesses such as managers or employees to attend interview, with false statements being an offence, and require production of specific documents including data protection impact assessments through information notices.
Does the UK have an AI Act?
No comprehensive AI statute equivalent to the EU AI Act. AI is regulated through existing regimes: data protection law where personal data is processed, the Online Safety Act for content on regulated platforms, and section 138 of the DUA Act for a specific category of AI-generated imagery. Copyright in AI training remains unsettled.
What is the 48-hour takedown rule?
A proposed requirement, announced on 19 February 2026 as an amendment to the Crime and Policing Bill, that regulated service providers remove non-consensual intimate images within 48 hours of notification. It is a proposed amendment to a Bill still before Parliament, not current law.
Is the Cyber Security and Resilience Bill law yet?
No. It was introduced on 12 November 2025 and had its second reading on 6 January 2026. Proposals include a strengthened enforcement regime with GDPR-level maximum penalties and emergency powers for the Secretary of State.
The key points
- 5 February 2026: core DUA Act amendments to UK GDPR and PECR in force
- 6 February 2026: section 138 deepfake creation offence, complete on request alone
- 19 June 2026: data protection complaint-handling processes required
- Still Bills, not Acts: the 48-hour takedown and the Cyber Security and Resilience regime
- No UK AI Act: AI is regulated through data protection, online safety and professional obligations
The practical takeaway
The distinction that matters most in this area is between what is in force and what has been announced. A great deal of commentary treats Bill amendments and consultation proposals as though they already bind, and advising a client on that basis is a real risk.
In force: the February 2026 data protection amendments, the enhanced ICO powers, the section 138 offence, and the expanded Online Safety Act priority offences. Coming: the June 2026 complaint-handling requirement. Proposed only: the 48-hour takedown, the AI chatbot provisions and the cyber security regime.