UK’s New Prime Minister & The Possible Compliance Agenda

UK’s New Prime Minister & The Possible Compliance Agenda

9 Min Read

Andy Burnham became the UK’s 59th Prime Minister on 20 July 2026.  He comes into office at a difficult time with an increasingly complex international agenda and a wide range of domestic issues including the cost-of-living crisis.  It’s likely that initially at least there won’t be much time for legislative change but how might Burnham shape the international compliance agenda?

Our analysis of an AI Agenda under the new Prime Minister

Burnham has already made changes in the way his government deals with AI with the closure of the Department for Science, Innovation and Technology (DSIT) and the removal of Liz Kendall the Secretary of State for Science, Innovation and Technology from Government.  The AI Minister, Kanishka Narayan, will now sit within the Cabinet Office and will attend Cabinet meetings. He will also be part of the Department for Business, Innovation, Science and Trade (DBSIT) which will replace the former Department for Business & Trade.  There are some suggestions that Burnham may favour more AI regulation, possibly adopting some of the approaches the EU has introduced in the EU AI Act (see The EU Artificial Intelligence (AI) Act | FAQs).  Narayan has already spoken of the risks of AI saying that AI poses real risks to the public and that “it is right that the British public shares those worries, for jobs, for the pace of change“.

The new Office for the Prime Minister and the Cabinet (OPMC) will also have some AI related responsibilities.

Potential changes in Data Protection Regulation

The removal of Kendall will also affect data protection regulation at a difficult time for the UK data protection regulator, the Information Commissioner’s Office (ICO).  The Information Commissioner, John Edwards, announced his retirement on 19 June 2026 after an internal investigation into his conduct.  Edwards has since spoken critically of Kendall – in a recent blog he said “I bear Liz Kendall no ill will but am confident that neither she nor DSIT will be missed in the field of digital regulation.  Prime Minister Andy Burnham has sacked the Secretary of State for Science Innovation and Technology, and announced that the Department she presided over is destined for the knackers yard.  Kendall was renowned among my colleagues for becoming hyper-fixated on whatever was the issue of the day in the media, but having no coherent plan for the department.”  The ICO recently announced 7 new non-executive directors, but it seems that there will be no significant data protection regulatory expertise on that board.  The vacancy for the Information Commission Chair has now been published but whether a salary of £120,000 per annum (admittedly for a planned 3-day week) will attract the best candidates remains to be seen.

The ICO faces real challenges not only with its new structure but also with the rise of complaints which are complicated by more complainants using GenAI to add volume, complexity and aggression to their communications.  This is becoming a real burden to regulators and also to businesses.  But the ICO has new powers in the Data (Use and Access) Act 2025 (see here Alert: UK’s Data (Use and Access) Bill receives Royal Assent) and they have some capable staff. 

ESG, supply chain, and procurement under a new administration

Burnham has some track record as Mayor of Greater Manchester in looking at procurement to drive change in the supply chain.  He used Manchester’s spend of around £20-25 billion to try and lead “progressive procurement” also called “social value procurement” to try and change public sector procurement.  He also spoken out on ESG-related issues in the supply chain including Uyghur forced labour, framing it as a critical human rights and corporate accountability issue.  The new Foreign Secretary Ed Milliband has also spoken on these issues and whilst Energy Secretary introduced a legislative amendment to ban the new state-owned company, Great British Energy, from using solar panels, wind turbines, and batteries linked to Chinese slave labour.  The changes in the new administration could mean:

  1. An increased focus on ESG issues in government procurement
  2. Encouraging Government suppliers to help address other societal issues for example by providing more apprenticeships for the young unemployed
  3. Looking at supply chain transparency
  4. A renewed focus on anti-corruption – this was certainly focus of Starmer’s time too and the recent report into COVID-era procurement has shown the scale of the problem

UK Government public spending is predicted to be around £1.36 trillion this year.  There have been calls, for example in the UK Parliament’s Business, Energy and Industrial Strategy Committeeenquiry into forced labour, for the UK to use its buying power to try and influence change.  That could be something which interests the new Burnham administration following the Manchester experience.  However, Burham also seems to favour more local accountability which may mean that decentralisation weakens some possible procurement gains.

Modern Slavery Act changes

We’ve discussed previously possible changes to the Modern Slavery Act 2015 (see The Modern Slavery Act 2015).  It seems likely that the new administration would favour updating the UK’s modern slavery law but this would require parliamentary time which might be hard to find.  In the short term we’d expect more focus on the power the Government has as a buyer of products and services rather than legislative change.

Whistleblowing

Burnham is generally seen as more pro-employee than the previous administration.  This could lead in the longer term to a strengthening of whistleblower protections possibly building on some of the changes to whistleblowing laws across the EU.  Burnham has previously spoken in favour of more whistleblower protections for example in the NHS and in exposing wrongdoing in public bodies.

Corporate responsibility

Some of the drive to greater corporate responsibility could be possible without legislative changes.  s.172 Companies Act 2006 already imposes various duties on boards including the need to consider “the likely consequences of any decision in the long term”, “the impact of the company’s operations on the community and the environment” and “the desirability of the company maintaining a reputation for high standards of business conduct”.  Reminding boards of these responsibilities could become more common, for example for water company directors involved in pollution scandals.  The new Crime and Policing Act 2026 also has additional powers to hold directors to account (see here Alert: The UK’s Crime and Policing Act 2026).

The abolishment of DSIT and the potential impact on cybersecurity laws

The demise of DSIT could also have an impact on the UK Government’s plans to change UK cybersecurity laws (see here FAQs: The UK Cyber Security and Resilience Bill).  These plans would have brought closer alignment in some respects to the EU NIS2 regime (see here: The EU’s NIS2 Directive | Compliance Lawyers | London).  With DSIT gone the responsibility for change here is likely to pass to the newly enlarged and renamed Department for Digital, Culture, Media and Sport (DCMS) under Secretary of State Lisa Nandy.  Nandy recently announced her departure from X and may focus her energies more on social media and harm to children rather than speeding up the progress of the Cyber Security and Resilience Bill.  However, the Bill seems to be making some progress and had its Second Reading in the House of Lords on 14 July 2026.  It will enter the Committee stage in the House of Lords on 1 September 2026, and it may be that the new administration will review the effort required to get the Bill over the line after that process is complete.

Devolved Powers

We’ve mentioned devolved powers already.  There’s a potential issue for compliance professionals here too if issues like planning, housing enforcement, transport regulation and skills funding are devolved to local administrations.  There is a risk that compliance professionals may have to deal with different regulators for different locations in the UK which could add complexity and cost.  The increased political instability in the UK and the rise of new parties as a feature of local government could exacerbate these risks.

Practical steps

It’s too early in the administration to make concrete predictions of likely change.  However, businesses may want to think about the following:

  1. Making sure they have a plan in place to monitor changes with the new administration.  Whilst the same political party is in power the early indications are that this will be a considerable reset.
  2. Reviewing their ESG programs.  We know that some businesses have de-prioritised this given changes in the US regime but this may become more important in the UK.
  3. Consider the impact on any business with the UK public sector.  The indications are that any changes will be reinforced by contractual changes rather than asking businesses for informal changes.  You may need to assess the impact of those changes on your UK business.

For further information

Please contact Jonathan Armstrong or Vivien Yanni-Gan for more information on these topics.  In addition:

  1. The list of the ICO’s new board members: Seven non-executive members appointed to Information Commission Board as chair recruitment launches – GOV.UK
  2. The job description for the new Information Commission Chair: Appointment details – Information Commission Chair – Apply for a public appointment – GOV.UK
  3. Some announcements regarding structural changes: Machinery of Government changes: Fact Sheet – GOV.UK

Note:  there is some debate over the numbering of PMs in the UK but we’ve adopted what would appear to be the majority view.

Related Insights

Insights

Everything Compliance Podcast: How businesses should prepare for the Failure to Prevent Fraud offence

In this episode of the Everything Compliance podcast, Jonathan Armstrong covers a recent speech by the Director of the Serious Fraud Office, Graeme McNulty, who said the SFO intends to...

2 Min Read

Read More Everything Compliance Podcast: How businesses should prepare for the Failure to Prevent Fraud offence