https://www.noxia.co.uk/field-notes/what-a-regulator-does-first · printed from noxia.co.uk · sources checked 24 September 2026
Field note · What we found
What a regulator does in its first year with a new power.
Three UK regulators are about to start using powers they have never used: the SIA on premises, whoever enforces the cyber regime, and the Information Commissioner under a code not yet written. There is one recent worked example of what year one looks like, and it is not what firms brace for.
- What we found
- Regulation
- Enforcement
- Compliance
The short answer
In its first year of direct consumer enforcement to 17 April 2026, the CMA opened investigations into 14 businesses and sent 157 advisory and warning letters — a ratio of more than eleven letters to each investigation. On fake reviews it wrote to 54 review publishers and reports 90% took action, opening investigations into the five that did not. Fines totalled £4.7 million, almost all in one case.
On this page · 5 sections
The instinct when a regulator gains a new power is to expect enforcement. What the one available worked example shows is correspondence.
Two features of that shape are worth naming because they repeat.
The letter is the instrument. A new regulator establishing a norm writes to far more firms than it investigates, and the letters work: 90% of the review publishers contacted acted without an investigation. A letter is not an opening position in a negotiation. It is the cheap path being offered once.
The fines concentrate. £4.2 million of the £4.7 million total was a single settlement. Year-one enforcement makes examples rather than sweeping — which means the probability of being fined is low and the consequence of being the example is not.
Three regulators about to do this
The Security Industry Authority becomes the regulator for premises under Martyn's Law, which it expects to come into force in spring 2027. It has never regulated premises capacity before.
The cyber regime brings managed service providers and data centres into scope with a 24-hour notification clock. Most of the firms affected have never had a regulator for this.
The Information Commissioner must produce a code of practice on AI and automated decision-making under regulations in force since 12 May 2026 — and the underlying duties have applied since 5 February 2026, so the guidance arrives after the obligation.
What the pattern suggests doing
- Make sure a letter would reach somebody. A regulator writing to a generic address that nobody reads converts a cheap warning into an expensive investigation, and that is an administrative failure rather than a compliance one.
- Do the assessment that each regime asks for, and keep it. In every one of these the first question is whether you looked. An assessment that concludes you are out of scope is a complete answer and costs an afternoon.
- Do not buy against year one. The expensive response is to procure a compliance product before anybody knows what the regulator expects. The arithmetic on that rarely clears, and the guidance that would tell you what to buy has not been written.
What this does not tell you
One regulator, one year, one set of powers. The CMA's consumer enforcement is not the SIA's premises regime and a pattern drawn from a single case is a hypothesis rather than a finding. We are presenting it as the only worked example available, not as a law.
It also describes priorities rather than boundaries. Areas that received letters in year one can receive investigations in year two, and a firm reading "letters first" as "nothing happens first" has misread it.
The three regimes above have their own notes with their own sources: premises capacity, the 24-hour clock, and the AI code. The grid showing which of them reaches you is mostly empty for most firms.
Questions people actually ask
What happens in a regulator’s first year with new powers?
On the one recent worked example — the CMA’s first year of direct consumer enforcement to 17 April 2026 — mostly correspondence. It sent 157 advisory and warning letters and 46 information notices against 14 investigations, and 90% of the review publishers it wrote to acted without further action.
How likely is a fine in year one?
Low, and concentrated. The CMA imposed £4.7 million in total, of which £4.2 million was a single settlement. Year-one enforcement tends to make examples rather than sweep, which means a low probability of being fined and a high consequence of being the example.
Which UK regulators are about to use new powers?
The Security Industry Authority as regulator for premises under Martyn’s Law; the regime created by the Cyber Security and Resilience Bill, with its 24-hour notification clock; and the Information Commissioner, required to produce a code of practice on AI and automated decision-making under regulations in force since 12 May 2026.
What should a firm do to prepare?
Make sure a letter would actually reach somebody, since an unread warning converts into an expensive investigation for administrative rather than compliance reasons. Do the assessment each regime asks for and keep it, even where it concludes you are out of scope. And avoid buying a compliance product before the guidance that would tell you what to buy exists.
Sources
- Competition and Markets Authority, “Direct consumer enforcement: one year on”, 17 April 2026: April 2025 to April 2026 — investigations into 14 businesses, 2 settlements, £760,000 in consumer refunds, £4.7 million in fines, 157 advisory and warning letters, 46 information notices; on fake reviews, advisory letters to 54 review publishers with “90% of the businesses we contacted then took action” and investigations opened into 5; the AA fined £4.2 million in a drip pricing settlement. competitionandmarkets.blog.gov.uk ↗ — primary; the regulator’s own account of its own first year, which is a statement of priorities rather than a neutral survey re-checked every 6 months
- One regulator, one year, one set of powers. The pattern drawn from it is a hypothesis about how new powers get used, not a finding, and we present it as the only worked example available rather than as a law. — a stated limit on the argument above, and the main weakness of this note
- The three regimes named are sourced in their own notes: ProtectUK and the Security Industry Authority on the Terrorism (Protection of Premises) Act 2025; GOV.UK factsheets on the Cyber Security and Resilience Bill; SI 2026/425 on the ICO’s code of practice duty. — primary, by way of the individual notes re-checked every 6 months
Checked 24 September 2026. Next scheduled check 23 March 2027. Numbers that move — leaderboards, live indices — are re-checked every 30 days; annual datasets and rules in force every six months; dated research once a year. If something here has gone stale before we got to it, tell us and we will correct it and say what changed.
Cite this note
Noxia, “What a regulator does in its first year with a new power”, Field notes, 23 September 2026; sources checked 24 September 2026. https://www.noxia.co.uk/field-notes/what-a-regulator-does-first
Would a letter from a regulator reach anybody at your firm?
It is an administrative question with an expensive answer, and it is the cheapest thing on this list to fix. We set up the routing and the record, so that a warning gets read, gets logged, and gets a named owner before it becomes an investigation.
Talk to us about thisRead next
Security
Two hundred people is where a new duty starts.
Standard tier at 200 to 799 expected people, enhanced at 800 and above. The regulator is the Security Industry Authority, which expects the Act to come into force in spring 2027.
Advice & compliance
The UK’s AI rulebook has an author now, and it is the ICO.
The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 came into force on 12 May 2026. The ICO must now write it.
What we found
Eleven new duties in fifteen months. Which reach you?
Automated decisions, targeted support, sick pay, verification, dashboards, tax filing, accessibility, cyber, possession grounds, premises capacity and energy standards — on one grid, by who each one reaches.