Law and Policy

UK robot law and regulation: what rules apply to humanoid robots in Britain

There is no single UK Robot Law. The legal framework that applies to humanoid robots in Britain draws from several existing bodies of legislation, with genuine gaps where new regulation is still being developed. This guide maps what applies, what does not yet, and where to get advice.

Published 20 September 2026 by Humanoid Robot UK

One of the most common questions from UK organisations evaluating humanoid robot deployment is a simple one: what does the law actually require? The answer is less simple, because no single piece of UK legislation is written specifically for humanoid robots. What exists is a patchwork of health and safety law, product liability law, AI policy, data protection, and sector-specific regulation that collectively applies to robotic systems in various contexts. This guide maps that patchwork clearly and honestly, including the areas where the law is genuinely unsettled.

A note before proceeding: this guide is informational, not legal advice. Organisations making deployment decisions on the basis of regulatory requirements should obtain legal advice specific to their deployment context and jurisdiction.


Workplace and safety law

Health and safety legislation: the primary framework

For humanoid robots deployed in any UK workplace context, the Health and Safety at Work etc. Act 1974 is the primary legislative framework. It places a general duty on employers to ensure, so far as is reasonably practicable, the health, safety, and welfare of all employees, and to conduct their undertaking in a way that does not expose non-employees to risks to their health or safety.

Introducing a humanoid robot into a workplace is a change to the working environment that triggers the employer's obligation to conduct a suitable and sufficient risk assessment. That assessment needs to identify the hazards the robot presents, who might be harmed and how, what control measures are appropriate, and how those measures will be monitored and reviewed. The Provision and Use of Work Equipment Regulations 1998 (PUWER) apply to any equipment used at work; robots fall within scope and must be suitable for their intended use, properly maintained, and used by people with adequate information, instruction, and training.

The Health and Safety Executive is the principal enforcement body for workplace health and safety in Great Britain. HSE guidance on machinery and automation provides relevant context for robot deployments, though guidance specific to humanoid robots is not yet published as of mid-2026. Responsible deployment means applying existing machinery safety principles until specific guidance is available.

Machinery Directive provisions and UK equivalents

The UK has retained and updated elements of EU machinery safety legislation following EU exit. Machinery placed on the UK market must comply with the Supply of Machinery (Safety) Regulations 2008 (as amended), which set out essential health and safety requirements for machinery design and manufacture. The manufacturer of a humanoid robot sold or deployed in the UK market bears the primary obligation to comply with these requirements. The deploying organisation has obligations around maintenance, appropriate use, and not modifying safety features.

The EU has been developing an updated Machinery Regulation (replacing the Machinery Directive) that incorporates requirements specifically relevant to AI-enabled machinery. The UK has not directly transposed this regulation post-EU exit, and the extent to which UK law will evolve in parallel is not yet determined. Organisations evaluating robots certified under EU requirements should verify the current UK regulatory position for the specific product.


Product liability

What happens when a robot causes harm: product liability

The Consumer Protection Act 1987 establishes product liability in UK law: a producer is liable for damage caused by a defective product. If a humanoid robot injures a person or damages property due to a defect in the product, the manufacturer can be held liable without the injured party needing to prove negligence. This is a strict liability framework.

Applying the Consumer Protection Act to humanoid robots raises genuinely difficult questions. A robot that uses machine learning to adapt its behaviour is not a static product. If the robot's behaviour that caused harm resulted from learning that occurred after the product left the manufacturer's control, is that still the manufacturer's defect? What if the deployer fine-tuned the AI model for their specific application? What if a software update from the manufacturer changed the robot's behaviour in a way that contributed to an incident?

These questions are not settled in UK case law, which currently has no significant reported decisions involving humanoid robot liability. The UK Law Commission published a review of automated vehicles and product liability in the early 2020s that is relevant in principle; some of its analysis about AI systems and defect definition applies to robots. The government has indicated interest in updating product liability law to address AI and automated systems more clearly, but as of mid-2026 the Consumer Protection Act 1987 remains the primary statute, interpreted by courts without specific guidance on AI systems.


The UK AI regulatory approach

UK AI policy and what it means for humanoid robots

The UK government has taken a consciously different approach to AI regulation from the European Union. Where the EU has enacted the AI Act, a horizontal regulation applying tiered requirements based on risk level across all AI systems, the UK has opted for a sector-led, pro-innovation approach. Rather than a new horizontal AI law, the UK relies on existing sector regulators to apply their established frameworks to AI-enabled products and services, with government guidance and coordination from the AI Safety Institute.

For humanoid robots, this means the applicable regulatory framework depends on the deployment context. A humanoid robot deployed in a manufacturing facility falls primarily under HSE oversight through the health and safety framework. A humanoid robot deployed in a medical or care context may fall under MHRA oversight if it has a clinical function, and under CQC oversight if it operates in a regulated care setting. A robot operating in a public space may engage different regulatory considerations.

The practical consequence of the sector-led approach is that there is currently no single regulatory body with clear UK-wide oversight of humanoid robots in general. This creates uncertainty for innovators and deployers, which the government has acknowledged. The AI Safety Institute, established in 2023 and renamed the AI Security Institute in 2024, is primarily focused on frontier AI models and does not directly regulate physical robotic systems, though its evaluation frameworks and safety standards work may eventually become relevant to AI-enabled robots.


Data protection

UK GDPR and data law as applied to humanoid robots

Humanoid robots operating in any environment collect data: visual data from cameras, audio from microphones, sensor data about the environment and the people in it. Where that data includes information about identifiable individuals, UK GDPR applies. The Data Protection Act 2018 implements UK GDPR in domestic law and is enforced by the Information Commissioner's Office.

The key obligations for organisations deploying data-collecting robots include: identifying a lawful basis for each category of personal data processed; being transparent with data subjects about what data is collected and why; implementing data minimisation; applying appropriate security measures; and addressing data subject rights including access, rectification, and erasure. Where robots process biometric data such as facial recognition or gait analysis, stricter requirements apply as this is a special category of personal data under UK GDPR.

Data protection impact assessments (DPIAs) are mandatory where processing is likely to result in high risk to individuals. Deploying robots in care homes, hospitals, or other settings involving vulnerable people and processing data about them is almost certainly a high-risk processing activity requiring a DPIA before deployment begins.


Employment law

What employment law requires when introducing robots

Introducing humanoid robots to a workplace that employs people is a significant change that engages several areas of employment law.

Where automation will affect the number of employees or the nature of their roles, collective consultation obligations may be triggered. The Trade Union and Labour Relations (Consolidation) Act 1992 requires collective consultation for proposed redundancies of 20 or more employees within 90 days. Information and Consultation of Employees Regulations 2004 give employees in organisations of 50 or more the right to request information and consultation arrangements, including on decisions likely to lead to substantial changes in work organisation.

The legal principle of implied mutual trust and confidence in employment contracts is also relevant. Introducing automation in ways that are secretive, inadequately communicated, or perceived as arbitrary may give rise to constructive dismissal claims from affected employees.

Beyond the legal minimum, ACAS guidance on managing workplace change and the TUC's published positions on automation and work provide practical frameworks for engaging employees fairly in automation decisions. Employers who take genuine consultation seriously tend to experience fewer legal challenges and better operational outcomes from automation projects.


The honest gaps

Where the UK regulatory framework has genuine gaps

It would be misleading to suggest that the existing UK regulatory patchwork fully addresses humanoid robots. Several areas have genuine gaps that are likely to require regulatory development as deployment scales.

Liability allocation in multi-party deployments is unclear. When a robot deployed under a RaaS contract causes harm, and the harm results from a combination of the manufacturer's hardware and software decisions, the RaaS provider's operational choices, and the deploying customer's site management, the allocation of liability between those parties is not clearly determined by existing law. Contract terms between the parties will be the primary source of certainty, but they cannot resolve questions of liability to third parties.

The legal status of AI decision-making in regulated contexts is not settled. A robot making decisions in a care setting, for example choosing how to assist a person, occupies ambiguous ground between a medical device, a care tool, and an autonomous agent. The regulatory framework has not caught up with this ambiguity.

Insurance for humanoid robot deployments is an emerging market. Standard commercial and public liability policies may not clearly cover losses arising from robot operation. The Lloyd's of London market and specialist insurers are developing product lines, but coverage terms, exclusions, and pricing are not yet standardised. Any serious deployment plan should include a specific insurance review.


Staying current

How to keep up with UK robot regulation as it develops

The UK regulatory landscape for humanoid robots will evolve as deployments scale and policy attention grows. Organisations making procurement and deployment decisions should monitor the following:

  • HSE guidance and consultations on automated machinery and AI in the workplace.
  • DSIT (Department for Science, Innovation and Technology) AI regulation publications and updates to the pro-innovation AI framework.
  • ICO guidance on AI and data protection, including the ICO's AI and data protection guidance series.
  • MHRA guidance on software as a medical device and AI in healthcare, if deploying in health contexts.
  • The UK AI Safety Institute's safety evaluation frameworks.
  • Law Commission reports on automated systems, liability, and related topics.

Legal advice from a firm with expertise in technology, product liability, and employment law is strongly recommended for any organisation proceeding beyond exploratory evaluation of humanoid robot deployment.


Common questions

Questions readers often ask

Is there a specific UK law for humanoid robots?

No. There is no single UK law written specifically for humanoid robots. The legal framework is a patchwork of existing legislation: health and safety law (principally the Health and Safety at Work etc. Act 1974 and PUWER), product liability law (the Consumer Protection Act 1987), data protection law (UK GDPR and the Data Protection Act 2018), employment law, and sector-specific regulation. The UK has taken a sector-led approach to AI regulation rather than enacting a horizontal robot or AI law equivalent to the EU AI Act.

Who is responsible if a humanoid robot injures someone in the UK?

Under the Consumer Protection Act 1987, the manufacturer of a defective product is strictly liable for damage it causes. However, applying this to humanoid robots raises unsettled questions when harm results from AI learning that occurred after manufacture, or from software updates, or from deployer customisation. The employer deploying the robot also carries duties under health and safety law for the safety of workers and visitors. In multi-party RaaS deployments, liability allocation between manufacturer, RaaS provider, and deployer is typically determined by contract, though third-party liability to injured persons is not resolved by contract alone.

Does UK GDPR apply to humanoid robots?

Yes, where a humanoid robot collects or processes data about identifiable individuals, UK GDPR applies. This includes visual data from cameras, audio data, and any biometric processing such as facial recognition. Deployers must identify a lawful basis for processing, be transparent with data subjects, apply data minimisation, and conduct a Data Protection Impact Assessment (DPIA) where processing poses high risk, which is likely in care, healthcare, or public-facing contexts.


What to read next

Related guides