A cross-party committee of MPs and peers has called for a comprehensive new Artificial Intelligence Bill and a single independent AI regulator, warning that the UK's existing legal framework is not equipped to deal with potentially serious risks from rapidly developing technology.
The Joint Committee on Human Rights said current regulation is fragmented, difficult to navigate and leaves gaps in protection because much of the law applies to the organisations using AI rather than the companies designing the underlying systems.
In a report published on 14 September, the committee said a new statutory regime should cover the entire AI supply chain and lifecycle, with tougher obligations applying to systems considered to present higher risks.
Committee chairman Alex Sobel said the UK was currently “unprepared” for the consequences of rapidly developing AI and argued that a single regulator needed sufficient powers to enforce the rules.
Committee demands comprehensive AI Bill
The committee recommends legislation establishing different categories of AI risk, with relatively light requirements for low-risk systems and progressively stronger obligations for higher-risk models and applications.
Responsibilities would apply across the AI lifecycle, including to those designing, developing, modifying and deploying systems.
The committee said businesses should not face unjustified regulatory burdens and stressed that its proposed framework should remain proportionate so that British companies can continue to innovate.
However, it concluded that the potential scale of AI-related harm means relying on the existing collection of sector-specific laws and regulators is no longer sufficient.
Single independent AI regulator proposed
One of the report's most significant recommendations is the creation of a single independent AI oversight body established in law.
The regulator would act as a central point for concerns about the use of AI and monitor emerging risks and harms.
The committee says it should have strong enforcement powers, including the ability to establish codes of practice and transparency requirements and impose sanctions where rules are breached.
That would represent a major departure from the UK's current approach, under which AI is largely regulated through existing bodies responsible for individual sectors.
Some uses of AI could be banned outright
The proposed legislation would also allow certain uses of artificial intelligence to be prohibited completely where they are considered incompatible with human rights.
The committee identified areas including subliminal techniques and inappropriate uses of profiling or biometric information as potential candidates, although it said the precise prohibitions should be determined following public consultation.
Other AI systems judged to carry a high risk of causing human rights harms could require approval before being deployed.
The report also recommends due-diligence duties across the AI supply chain, graded according to an organisation's role and the seriousness of the potential risk.
Mandatory transparency when AI makes decisions
The committee is particularly concerned about automated systems being used to make or influence decisions affecting individuals without people understanding how AI was involved.
It recommends mandatory transparency requirements across the AI lifecycle, including an obligation to disclose the use of AI where a system can have a significant impact on individuals, groups or communities.
The committee also wants stronger safeguards around automated decision-making under UK data protection law.
It warned that simply having a nominal human involved in a decision does not necessarily amount to meaningful human oversight.
Current regulators cannot stop dangerous systems being released
The report highlights what the committee regards as a significant weakness in the present system: regulators generally do not have powers to test AI models before release or prevent their deployment because they are considered to pose unacceptable risks.
Developers currently engage with the Government's AI Security Institute on a voluntary basis and the institute does not have statutory powers to compel companies to submit models for testing.
The committee argues that this leaves regulators attempting to respond to harms after deployment rather than having a comprehensive framework capable of preventing them.
Sobel says UK is 'unprepared'
Alex Sobel, the Labour MP who chairs the Joint Committee on Human Rights, said AI was developing at such speed and complexity that its eventual impact was difficult to predict.
He warned that the UK was currently “unprepared” to deal with consequences that could potentially be severe.
Sobel said no existing regulatory approach to artificial intelligence, including Britain's, was fit for purpose and called for comprehensive protections covering the full AI supply chain.
At the same time, the committee acknowledged that AI could deliver major social and economic benefits and said regulation should focus most heavily on areas presenting the greatest risks.
Government has not accepted committee's proposals
The recommendations do not represent Government policy and ministers have not announced that they will create the regulator proposed by the committee.
The Government's existing position has been that most AI systems are regulated at the point where they are used through established specialist regulators, supplemented by the work of the AI Security Institute.
In a parliamentary answer published on 10 September, ministers said they continued to keep the adequacy of those arrangements under review, particularly in relation to emerging risks involving cybersecurity and critical national infrastructure.
The committee's report therefore places fresh pressure on the Government to decide whether Britain should retain its largely sector-based regulatory model or move towards comprehensive AI legislation backed by a dedicated statutory regulator.