Transparency and identity verification
Houses should be on top of the new UK regime for identity verification: we’re now in the transition period and your senior team members must complete the verification process (IDV).
The UK is sensitive to the accusation that its structures are used for fraud or money-laundering and this is a flagship measure to tackle that risk. Identity checks are already mandatory for individuals when they become a new LLP member, director or PSC (person with significant control), or a new UK corporate entity is set up. There still remains uncertainty about the timing for introduction of IDV measures for corporate members of LLPs, corporate directors of companies and officers of RLEs (relevant legal entities – i.e. entities that are themselves PSCs). We’re expecting to find out more in 2026 and GPs should stay alert to this.
A further difficulty for houses to navigate is the current transitional period (November ’25 to November ’26) during which every existing director, LLP member and PSC, who is an individual, must undergo an identity check and get a unique code before their relevant deadline. That code must then be registered at UK Companies House against every company or LLP where they have a relevant role.
Houses should care about whether their senior teams comply with new identity checks. Failure could mean their disqualification as directors.
This is important for all asset managers with a UK corporate entity or UK limited partnership in their structure. It is also relevant where individual representatives from GPs sit on UK boards (and it is obviously relevant to those portfolio companies in their own right).
Although this is a personal obligation, the house should care about compliance. Failure could result in fines, prosecution and referral to the Insolvency Service. Repeated or aggravated failures could result in criminal prosecution or disqualification from acting as a director.
The UK Government is introducing further transparency measures for UK limited partnerships too. We don’t yet know when these will start to take effect – but GPs should stay alert as they are coming down the track. The measures include the requirement to have a partnership email address, a UK registered office and an authorised corporate service provider via which most partnership filings at UK Companies House will have to be made.
Trickier, is the new requirement to file more information about LPs: GPs will need to ensure the information they hold on LPs is up to date, and, once in force, changes must be notified to UK Companies House within 14 days. However, older limited partnership documents might not oblige investors to provide GPs with the information they need within the required timeframe.
AI, data and cyber risk
The European Commission is looking to simplify and consolidate its AI and data rulebooks.
Some good news first: according to the proposals, businesses who develop or use new “high-risk” systems will have more time to get on top of the EU’s AI requirements. Compliance deadlines will be linked to the availability of Commission guidance and harmonised standards, but with backstops of December ’27 (for certain AI systems used in employment, credit-scoring or biometrics) and August ’28 (for systems subject to product safety legislation, such as critical infrastructure or medical devices). There are also plans to shift the AI literacy obligation away from businesses to the EU institutions and Member States.
There’s likely to be a delay to the EU’s AI rules for high-risk systems
On data, on top of December’s expected but welcome EU confirmation that the UK is still “adequate” to allow free flow of data from the bloc to the UK, there is further positive news in the form of the EU’s proposed single breach/incident reporting channel. The plan is “report once, share many” across GDPR and other data/cyber frameworks, as well as an extension to the timeframe for reports to 96 hours.
In the UK, the Government has dangled the possibility of a comprehensive UK AI Bill for summer 2026, but remains cautious about whether regulation will dampen innovation. It hopes that a regulatory sandbox for AI will help establish which rules are necessary (or not).
Your Checklist.
Our analysis.
Click below for our detailed briefings
Limited Partnership Transparency
Our guide on what you can do now to prepare for the additional administrative requirements
AI, Data and the EU’s ‘Digital Omnibus’
Our comprehensive dive into the EU’s AI and data plans in ’26
Details of a UK Government consultation on reporting ransomware demands
Managing cyber supply chain risk
Our take on the proposed regulation of how businesses manage their cyber-risk
Links to other relevant sites
















