AI governance at a crossroads: Burnham, Trump and the battle for sovereign AI
23 September 2026
At the 81st United Nations General Assembly in September 2026, UK Prime Minister Andy Burnham and US President Donald Trump laid out two starkly different visions for artificial intelligence. Both see AI as a strategic priority. Beyond that, agreement is thin.
For UK businesses, the gap between the two positions is not academic. It has immediate, practical consequences.
Three jurisdictions, three philosophies
The three most significant jurisdictions for UK businesses — the EU, the UK and the US — are heading in fundamentally different directions.
The EU AI Act is already in force. This is the world’s first comprehensive, binding AI regulatory regime. It classifies AI systems by risk level, imposes strict obligations on developers and deployers of high-risk systems (covering governance, transparency, data quality, human oversight and post-market monitoring) and prohibits certain practices outright. Critically, it has extraterritorial reach. If your AI touches EU citizens, you are likely caught.
The UK has chosen a different path: principles-based, sector-led regulation. Existing regulators — the Financial Conduct Authority (FCA), Information Commissioner’s Office (ICO), Ofcom, the Competition and Markets Authority (CMA) and others — apply cross-cutting principles: safety, transparency, fairness, accountability and contestability.
The theory is sound: avoid premature legislation, let specialist regulators move quickly and encourage innovation. The practice is messier. AI is already caught by existing law — the Data Protection Act 2018 and UK GDPR govern automated decision-making, the Equality Act 2010 catches algorithmic discrimination and the Online Safety Act 2023 applies to AI-generated content. But obligations vary by sector, guidance is patchy and businesses face genuine uncertainty about where the regulatory floor sits.
The US is more fragmented still. There is no federal AI statute, and President Trump’s UNGA speech made Washington’s position plain: the US will resist what he called “any attempt to construct a globalist scheme of control” over AI. A patchwork of state laws, including Colorado’s AI Act, Illinois’ Biometric Information Privacy Act and California’s proposed frontier model legislation, sits alongside sector-specific enforcement from the Federal Trade Commission (FTC). For UK businesses with US operations, the compliance map is sprawling and fast-moving.
The result: a single AI system deployed across London, Paris and New York may face three distinct compliance regimes, three enforcement frameworks and three different definitions of acceptable risk.
Does sovereign AI matter?
Yes, but not in the way politicians typically frame it.
Burnham announced a planned UK-US AI defence partnership and positioned Britain as a bridge between Washington and Brussels. Politically pragmatic, but most frontier AI models are developed by US companies, cloud infrastructure is dominated by American hyperscalers (such as Amazon Web Services (AWS), Microsoft Azure and Google Cloud) and UK AI capability depends heavily on imported compute, foreign capital and US partnerships.
Sovereign AI requires meaningful control over data infrastructure, compute capacity, talent and strategic decision-making. The UK is currently an influential AI adopter, not an AI sovereign.
For businesses, that dependency matters in three ways:
- Regulatory autonomy: a government reliant on foreign infrastructure may find enforcement constrained by commercial realities
- Supply chain risk: if your AI stack depends on a single US hyperscaler, business continuity planning must account for geopolitical disruption, sanctions shifts and export controls
- Data sovereignty: UK GDPR imposes strict requirements on international transfers, and AI systems routing data through US infrastructure raise real questions about adequacy and contractual safeguards.
What should UK businesses actually do?
Waiting for the regulatory dust to settle is not a strategy. Businesses operating across jurisdictions need to act now.
- Map your AI exposure. Know what AI systems you are developing, deploying or procuring and where
- Build to the highest common denominator. If you operate in the EU, the AI Act is your baseline. Designing governance around its requirements will likely satisfy UK and US obligations too
- Stress-test existing contracts and build in AI-specific protections. Procurement agreements, SaaS terms and outsourcing arrangements were rarely drafted with AI obligations in mind. Review indemnities, liability caps, IP warranties, data processing terms, data localisation, audit rights and exit provisions
- Get board-level oversight in place. AI governance is a risk management function, not an IT project
- Diversify AI suppliers where possible. Interrogate where your data sits and who controls it
- Engage with the regulatory process. The UK’s sector-led model means businesses that participate in consultations will help shape the rules, not just follow them.
The bottom line
AI governance is no longer a compliance footnote. It’s a board-level, balance-sheet issue with geopolitical dimensions. The businesses that will navigate this best are those that treat governance not as a brake on innovation, but as the thing that makes responsible innovation possible.
For the UK, the harder question remains: can you set the rules for a technology you do not control? Until Britain has a credible answer, sovereign AI will remain more slogan than strategy.