Mark Pestridge at Telehouse Europe describes what regulators and industry must prioritise to keep UK tech moving

The UK is betting on technology to modernise public services and strengthen national resilience; however, that ambition only delivers if trust keeps pace. Scaling data-driven services and AI without eroding confidence in how they’re used is difficult, but it’s exactly the kind of balancing act smart regulation should be built to manage.
Trust sits at the centre of the UK’s principles-led regulatory model. Designed to protect people and businesses without stifling innovation, it gives organisations flexibility in how they meet regulatory outcomes while steering clear of rigid rules that can quickly date. In theory, it offers a framework that evolves alongside technology, rather than constraining it.
Making principles work in practice
For this model to succeed, it must be workable in day-to-day delivery. Service providers need clarity on what ‘good’ looks like, and confidence that meeting the intent of the rules will be recognised consistently.
Encouragingly, many organisations broadly support the direction of travel. Recent Telehouse research suggests that two-thirds (67%) of IT decision-makers from UK-based service providers believe current data protection rules are accelerating their ability to launch new digital services. The debate is not about weaker governance, but about ensuring oversight delivers clear outcomes and is predictable in practice.
When compliance is aligned with delivery rather than bolted on as a parallel process, it becomes part of how services are built rather than a barrier to progress. A similar pattern shows up in attitudes to AI, with 64% of respondents viewing the current UK AI regulatory framework as an accelerator. Flexibility can support innovation when expectations are understood and consistently applied.
The issue isn’t the rules, it’s the mechanics
Where confidence starts to waver, however, is not in the principle but in the execution. Approval processes are often experienced as opaque and variable, especially when evidence requirements are interpreted differently across stakeholders. Over time, that uncertainty turns governance into a planning risk, with programmes slowing down, contingency built into timelines, and assurance work expanding simply to protect timelines.
The research found that 34% of respondents say regulatory approvals delay planned technology rollouts on most or almost every project. For organisations operating across borders, the challenge intensifies. 37% cited inconsistent international rules as one of their biggest operational concerns over the next two years.
Persistent uncertainty doesn’t just affect project plans but also operating models. If assurance work grows faster than delivery capacity, organisations start looking for ways to contain cost and complexity, including shifting roles to where regulatory interpretation and compliance operations are cheaper to scale.
Over half (51%) of respondents said they have already cut or offshored technology roles, or plan to do so within the next 12 months, because of the cost and complexity of managing AI regulation. While this may ease short-term budgets, it also risks stretching remaining teams and weakening UK capability over time.
Critically, none of this is an argument for weaker governance. Strong regulation and robust approvals are essential to building trust in AI and digital services, and there is clear support across the sector for maintaining high standards. The next step is to remove avoidable friction, through clearer evidence expectations and more predictable approvals.
Creating clarity without constraining innovation
Delivery teams need practical guidance on evidence for data governance, model governance, and ongoing monitoring, particularly where third-party components are involved. The aim is not to prescribe every control, but to reduce guesswork so that assurance is designed into services from the outset rather than assembled at the end. Predictability can matter as much as guidance. When organisations cannot anticipate key steps and likely timeframes, they slow down by default and build contingency into plans. Structured pre-engagement, clearer checkpoints, and a workable escalation route reduce late-stage rework and help avoid inconsistent interpretation between stakeholders.
Industry also has a role to play. There is no need to wait for a perfect framework to improve pace. Regulator readiness should be treated as a delivery requirement from day one, with assurance documentation built and maintained alongside development and clear ownership of key controls.
Standardisation is another powerful lever, as using consistent templates and shared control language reduces internal debate and makes it easier to work with customers and suppliers. Many organisations are aligning programmes with recognised standards such as ISO/IEC 27001 for information security and ISO/IEC 42001 for AI management. These frameworks provide a shared baseline for controls and evidence that speeds up assurance, especially when combined with pre-audited environments.
Certified infrastructure further reduces friction. Recognised as part of the UK’s Critical National Infrastructure, well-documented data centre facilities can reduce bespoke assurance work and shorten approval cycles. Organisations that invest in engineering and risk capability, including security, tend to move faster because compliance is part of normal delivery. If complexity pushes that capability overseas, the UK pays the price later in slower delivery and a thinner skills base.
The UK can keep standards high while delivering resilient and modern public services at pace. To achieve this, regulators must provide clear evidence, expectations and predictable approvals. It will also require industry to embed assurance into delivery and build on certified foundations. With practical clarity on both sides, governance can become a competitive advantage, accelerating delivery while strengthening trust in the digital services people rely on.
Mark Pestridge is Executive Vice President and General Manager at Telehouse Europe
Main image courtesy of iStockPhoto.com and saifulasmee chede


© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543