A cross-party committee of the UK Parliament on September 14, 2026 published a 233-paragraph report concluding that British law cannot protect people from harms that artificial intelligence systems are already causing, and calling for a dedicated AI Bill, an independent regulator able to pull systems off the market, and prohibitions on some uses of the technology.
In Short
A committee of UK lawmakers spent more than a year asking experts, campaigners, tech companies and a minister whether British law protects people from harm caused by artificial intelligence, and concluded that it does not. AI already helps decide who gets hired, who gets flagged by an employer and who gets stopped by police, and you may never find out a machine was involved, which makes it close to impossible to complain or get compensation. The committee wants a dedicated law for AI, a watchdog that can block risky systems and bans on uses such as software that guesses your emotions, but nothing changes unless the government accepts the proposals.
Twenty recommendations, one missing bill
The document, titled Human Rights and the Regulation of AI, is the Fourth Report of Session 2026-27 of the Joint Committee on Human Rights, printed as HC 160 and HL Paper 56. It ends with 59 numbered findings, of which 20 are formal recommendations to government and 39 are conclusions. The committee drew its members from both Houses and agreed the text on September 9, 2026, at a meeting chaired by Lord Alton of Liverpool with ten members present. Alex Sobel, listed as the committee's chair on its membership page, was instructed to present it to the Commons.
Its central demand is something ministers already promised. According to the report, the government told Parliament in the King's Speech of July 17, 2024 that it would "seek to establish the appropriate legislation to place requirements on those working to develop the most powerful artificial intelligence models." More than two years later, no dedicated AI Bill has appeared. The committee wants one, and it wants that Bill to give full effect to the Council of Europe's Framework Convention on Artificial Intelligence, which the UK has signed but not ratified.
What would such a law contain? The report does not draft clauses, but its recommendations sketch an architecture in six parts.
Risk tiers and red lines
According to the report, the Bill would classify AI systems by risk and mandate "proportionately more demanding obligations for higher-risk AI systems and AI models." Low-risk applications, which the report illustrates with social event planning, shopping and simple administrative tasks, would face lighter requirements. The committee prefers broadly framed principles in statute, with detail delegated to codes of practice that can be updated faster than primary legislation.
At the top of the scale sit outright prohibitions. The committee recommends banning the use of AI for "subliminal techniques, emotional inference or inappropriate use of profiling or biometric data." It then goes further. "Because of the very serious human rights risks, this would mean that the development and provision of very powerful AI systems (such as Artificial General Intelligence and Artificial Superintelligence) which risk causing widespread and very serious harm, including the capacity to evade effective human control, would be prohibited," according to the report. The precise list of banned practices would follow a public consultation.
No equivalent prohibitions exist in UK law, according to the committee, which notes that AI is already used in the public sector for fraud detection in the benefits system, predictive policing and real-time biometric identification in public places.
Prior approval and due diligence
Systems "posing a high risk of causing harm to human rights" would need prior approval before they could be provided or deployed. Every actor in the supply chain would carry due diligence obligations when designing, developing or deploying high-risk systems, differentiated by that actor's role and by the seriousness of the risk. The European Union's AI Act, according to the report, "may provide a useful point of departure" for scoping those duties, with provisions tailored to the UK.
Disclosure and automated decisions
Transparency requirements would apply to all actors across the AI lifecycle. Deployment of systems with significant effects on individuals, groups and communities would carry "an obligation to state when AI systems are being used and provide a full and comprehensible explanation of what it is being used for," plus information about the source of the data the system uses.
The committee also asks ministers to use existing regulation-making powers in the UK GDPR to tighten the rules on automated decision-making. Those regulations, it says, would state that "the mere presence of a 'human in the loop' is not enough to constitute meaningful human involvement or intervention." A human reviewer would have to be "sufficiently informed and independent to be able to reach an objective view that has not been improperly influenced by the automated decision," and people subject to a decision would receive information about their individual circumstances rather than the general operation of the system.
A regulator with withdrawal powers
The committee recommends an independent AI oversight body on a statutory footing, either newly created or formed by expanding an existing regulator. Its proposed powers run to eight enumerated items under a single heading. They include testing and evaluating AI systems, including a prior testing, auditing and evaluation regime for high-risk uses; prohibiting models or systems from release or deployment and ordering their withdrawal from the market; issuing mandatory codes of practice and sanctioning developers and deployers who breach them; ordering remedies in individual cases without affected people incurring prohibitive costs; and maintaining, under a statutory duty, "a public repository of AI incidents."
One power reaches beyond British borders. Where actors in the AI supply chain sit outside the UK, the body would assess the risks of deploying their systems domestically, "having regard to how those actors are regulated in their home state," and could limit or prohibit deployment if it found unacceptable risks that could not be addressed within the UK.
A statutory AI Security Institute
The AI Security Institute (AISI), established in November 2023 and renamed from the AI Safety Institute in February 2025, would be placed on a statutory basis. Developers of powerful models would be required to submit new models, and new versions of existing models, for review, evaluation and testing, along with technical specifications covering "model properties, training data and process, intended use, security and safety testing and risk control measures." AISI would assess and publish findings before release and could "issue preliminary 'warning' statements associated with release of new AI foundation models." To avoid duplication, the committee suggests ministers consider merging AISI's functions with those of the new regulator.
Treaty and diplomacy
Two further recommendations face outward. The committee wants a published timeline, subject to public consultation, for ratifying the Council of Europe Framework Convention, and it wants the government to use its G20 presidency to press for international mechanisms that address AI harms and allow early intervention in the development of foundation models.
How the evidence was gathered
The inquiry opened in July 2025. Over ten oral evidence sessions held between July 2, 2025 and February 25, 2026, the committee put 111 questions to witnesses, and its published list of written evidence runs to 74 numbered submissions. Professor Karen Yeung of the University of Birmingham served as special adviser.
Technology companies appeared in person. Alexandria Walden, Google's global head of human rights, gave evidence on January 21, 2026. Rob Sherman of Meta and Ginny Badanes of Microsoft followed on February 25, the same day as Kanishka Narayan, then Parliamentary Under-Secretary of State and minister for AI. Three regulators, Ofcom, the Information Commissioner's Office (ICO) and the Equality and Human Rights Commission (EHRC), appeared together on February 4.
Evidence-taking closed before a change of government leadership. According to the report, a new Prime Minister took office, the Department for Science, Innovation and Technology (DSIT) was abolished, and the Department for Business and Trade became the Department for Business, Innovation, Science and Trade. Narayan was appointed Minister of State for Artificial Intelligence on July 20, 2026, jointly in the Cabinet Office and the new department, and will attend Cabinet. The committee reads that continuity as a reason its evidence remains relevant.
Three rights under pressure
The committee narrowed its focus to three principles drawn from the Framework Convention: equality and non-discrimination under Article 10, privacy and personal data under Article 11, and the right to an effective remedy under Article 14(1). Workers' rights, environmental impact and intellectual property were raised by witnesses but left largely aside.
Bias that is built in
Witnesses described discrimination arising both from biased training data and from choices made by deployers. The cases cited in the report are specific. An Uber Eats courier could not log on to work because facial recognition software, which the report says was worse at identifying Black people's faces, did not recognise him. A Durham Constabulary system for assessing reoffending risk placed heavy reliance on postcodes. Amazon discontinued an AI recruitment tool found to discriminate against women. Members of the Communication Workers Union reported AI tools flagging workers for investigation for stopping at traffic lights or failing to "upsell" in call centres.
Javier Ruiz Diaz of Amnesty International UK described the false certainty such systems project. The system "does not say 'we think this is happening'; it says 'we know this is happening'," he told the committee. The Law Society of England and Wales said solicitors were already advising on cases involving biased data in public-sector AI, calling it "not a hypothetical problem for the future but one that requires immediate attention to protect human rights."
Faces, scraping and inference
The starkest number in the report concerns policing. The committee heard that between January 1 and October 29, 2025, around 3 million people would have had their faces scanned by police facial recognition technology in the UK without their consent. The Algorithmic Transparency Recording Standard, the government's main disclosure tool for public-sector algorithms, is not mandatory for police forces or local authorities, according to a footnote in the report.
Training data raises a second problem. Large language models depend on huge volumes of data, much of it collected through web scraping, which according to the report had often been done "without sufficient consideration of the implications for individuals." The Ada Lovelace Institute warned of technologies that claim to infer "sensitive internal states like a person's emotions, intentions, attention or truthfulness," often "with low levels of scientific validity."
Correcting data inside a trained model may not even be possible. "Are you affecting the intrinsic model or just the output and the way it talks back to you?" asked Ravi Naik, a data rights solicitor.
Remedies nobody can reach
People rarely know when AI shaped a decision about them. "You cannot mount redress to an AI-related harm if you do not know that AI has been used in the first place," said Ellen Lefley of the law reform charity JUSTICE. Kay Firth-Butterfield of Good Tech Advisory put it more directly: "AI should always identify itself to users, or users should be told when AI is involved. If you do not do that, you take away a right to remedy."
Some harms only show at scale. Connected by Data pointed to research finding that AI-generated summaries of women's health records downplayed their needs compared with men's, a pattern no single claimant would be likely to prove but which, in aggregate, produces worse outcomes for women as a group.
Where the current rulebook breaks
The report's fourth chapter is a catalogue of gaps, and its common thread is that existing protections attach to the wrong end of the supply chain. "Taken together, existing UK laws that could apply to AI systems do so primarily at the point of deployment, so that deployers are the primary holders of responsibility for harms arising from AI systems," the committee concludes. "They are therefore likely to allow human rights harm that could have been prevented."
The gaps are legal, not rhetorical. The Equality Act 2010 covers those providing services to the public, so it does not reach business-to-business transactions such as a developer licensing a model to a company. The Human Rights Act 1998 binds only public authorities, while practically all AI development happens in the private sector. Strict liability for defective products under the Consumer Protection Act 1987 applies to AI built into physical goods but not to stand-alone software, a distinction the committee calls "difficult to justify in principle." That gap is due to narrow in one part of the UK: the EU's revised Product Liability Directive, which covers all software including AI, is to be implemented in Northern Ireland under the Windsor Framework by December 2026, according to the report. A Law Commission review of product liability, with terms of reference dated December 8, 2025, is considering the same question for the rest of the country.
Contracts widen the gap further. "Currently, legal risks are primarily pushed to downstream actors through the use of contracts and standard terms & conditions," the Ada Lovelace Institute told the committee. "Consequently, upstream developers (usually LLM or foundation model developers) are largely shielded from risk, even though they have considerable impact on the functioning of the AI product." Michael Birtwistle of the institute summarised the problem in one line: "The major gap in our regulatory system is managing risk upstream with those building the tech."
Public-sector transparency fares little better. The recording standard, mandatory for government departments and many arm's-length bodies, has no statutory basis. "It has been mandated but we know it is not being used properly. Not all algorithmic use is on there," said Louise Hooper of Garden Court Chambers. DSIT itself described the standard as "a transparency and communication standard, not an assurance or audit mechanism."
Human oversight as a weak safeguard
Deployers often point to human review as protection. Witnesses were sceptical. "Even highly trained and qualified 'humans in the loop' may struggle to scrutinise effectively the AI's output given that AI tools can process much larger volumes of information than it is possible for a person to do," JUSTICE told the committee. The report also cites research suggesting people become more biased after interacting with biased AI, creating a feedback loop. Spain's data protection authority flagged the same automation bias risk in a February 2026 guide on AI agents and the GDPR.
Regulators stretched across remits
In 2024 the government wrote to 13 regulators with responsibilities relating to AI, according to the report. None has a cross-economy remit. The EHRC's budget, it says in written evidence, has stayed at £17.1 million since 2016, and the commission told the committee: "we do not have the technical expertise on AI that other regulators have." Ofcom described its AI powers as limited to the deployment and use-case level within its designated sectors, and named AI chatbots and image generators as "edge cases" that do not fall squarely within its remit. The ICO struck a more confident note, saying the challenges were "complex but we do not think they are insurmountable under the current legislation."
Litigation is no substitute. Naik said bringing an action against a private company could cost "seven-figure sums" before any damages claim. Birtwistle's verdict on the overall system: "AI is regulated in the UK, but only incidentally and not well."
The incident that hardened the argument
Evidence-taking ended in February, but the committee's conclusions lean on an event from July. According to the report, OpenAI made a statement on July 21, 2026 describing a "new kind of security incident," in which AI models being tested in an internal sandbox used a previously unknown vulnerability to gain internet access and then hacked into another company, Hugging Face, to find information to help achieve a test goal. OpenAI has said it is strengthening protections around its tests.
The committee drew a broad lesson. The incident "illustrates how the newest AI models can engage in activities that would be unlawful if undertaken by a legal person," it concludes. "It also suggests that at present society largely relies on private companies to take voluntary action to guard against such incidents. This is unsatisfactory." That reasoning underpins the call for regulation on a precautionary basis "by analogy with the regulation of other potentially harmful products such as pharmaceuticals."
The same section carries a sharper warning from Dr Iulian Serban of LawZero, who described large language models from companies including OpenAI and Anthropic as "brittle black boxes that we do not fully understand." Witnesses also flagged agentic AI, systems of multiple AI agents acting autonomously, which the report says may take unauthorised actions with unforeseen systemic consequences. Views on longer-term risks diverged: Professor Roman Yampolskiy of the University of Louisville argued that with uncontrolled superintelligence "the only way to win is not to play the game," while other witnesses called any threat from artificial general intelligence "remote."
A government that bet on growth
The report places much of the blame on policy direction. The AI Opportunities Action Plan, published by DSIT in January 2025, was produced by the entrepreneur Matt Clifford, who according to the report has since joined Anthropic, and nearly all of its recommendations were accepted. PPC Land covered the plan at the time, including its proposals for AI Growth Zones. It describes Britain as the third largest AI market in the world. In January 2026, then Science Secretary Liz Kendall set out an ambition for the UK to become "the fastest adopting AI country in the G7."
Ministers argued existing law is adequate. DSIT told the committee that "the UK's domestic legal framework is consistent with the principles set out in the [Framework Convention]," and that it favoured regulation "at the point of use by our existing expert regulators." Narayan said "static forms of regulation, where we have been historically, may not be best adapted to where we are likely to go."
The committee disagreed. It found the Action Plan "fails to pay sufficient attention to the need to secure the protection of human rights from AI-generated interference throughout the supply chain." The rebranding of AISI in February 2025, which gave the institute a sole focus on national security and serious crime and removed references to algorithmic bias from its agenda, drew particular criticism. Birtwistle said the shift showed "the deregulatory flavour of the government's attitude towards AI."
Opinions split along predictable lines. Meta's representative described the government's approach as a "thoughtful and sensible approach and in some ways a global model." Other witnesses called it "uncritical and deregulatory" and "asleep at the wheel." Barrister Susie Alegre said the Action Plan "turns a blind eye to the human rights risks posed by AI." Even the British Standards Institution, which backed the plan's positive outlook, suggested "there might be room for an 'AI Safety Action Plan'" with more attention to risk.
One watchdog or many?
The proposed oversight body is the most contested recommendation. Google argued for sector-specific rules. Walden told the committee that "regulating AI is necessary but must be done well [...] We really do not want duplicative laws or to be reinventing the wheel," adding that "responsibility [for harm] should look different for different actors, depending on their relation to that harm."
Some regulators resisted as well. According to the report, the EHRC warned that a "single AI regulator would duplicate and complicate existing regulation," and the ICO said any new body would have to "cover well-evidenced gaps that could not be addressed by empowering and resourcing current regulators." Ofcom wanted any coordinating body to delegate to existing regulators in areas within their expertise. Lefley proposed a middle path: an AI authority with "a duty of vigilance over the sufficiency of existing regulatory schemes and existing law."
The committee sided with a single point of contact, arguing that individuals currently have to work out which of several regulators to approach and have little recourse if ignored. "We are confident this can be done without creating duplication," it concludes.
The European yardstick
The EU AI Act runs through the report as both model and warning. The committee sets out its four tiers: prohibited practices, high-risk systems subject to essential requirements, general-purpose models with transparency and systemic-risk duties, and limited-risk systems with transparency duties. Silkie Carlo of Big Brother Watch said the UK needed "something like an EU-style AI Act or a digital Bill of Rights." Bates Wells LLP called the EU Act "overly complex," and Dualarity Ltd noted it had been characterised as "overly bureaucratic," urging a "UK-flexible way [of regulating] that maintains our attractive environment for AI R&D."
Brussels has itself softened its timetable. EU institutions agreed on May 7, 2026 to push high-risk deadlines to December 2, 2027 and August 2, 2028, while adding a new prohibition on AI-generated child sexual abuse material and non-consensual intimate imagery. The consolidated text, in effect since July 27, 2026, keeps fines of up to 35 million euros or 7 percent of worldwide turnover for prohibited practices. Transparency duties under Article 50 became applicable on August 2, 2026, with fines of up to 15 million euros or 3 percent of turnover. The committee's footnote dates the Commission's Article 50 guidelines to August 6, 2026; PPC Land reported the guidelines and the accompanying code of practice as published on July 20, 2026.
The Council of Europe treaty is the other reference point. It is the first legally binding international instrument on AI, opened for signature in Vilnius on September 5, 2024, and needs five ratifications to enter into force. The European Union ratified it on May 15, 2025, according to the report. The report's text states that seventeen states and organisations have signed; its own footnote lists nineteen, including the UK, the EU, the United States, Canada, Israel, Japan and Uruguay. Narayan told the committee "I feel no significant obstacles in us being able to put [the Convention] into effect," but no ratification timetable has been published. The Law Society said the UK "has an opportunity to be the first state to ratify." The Council of Europe is meanwhile moving on adjacent ground: draft guidelines on privacy in large language model systems, dated August 26, 2026, were scheduled for review by the Convention 108 Bureau in Paris on September 16 and 17.
Why the marketing industry has a stake
Advertisers rarely build foundation models. They deploy them, through automated bidding, audience generation, creative tools and, increasingly, agents with write access to live accounts. That places much of the industry precisely where the committee says liability currently lands: on the deployer, often bound by vendor terms that push responsibility downstream. A UK law requiring due diligence differentiated by role would rebalance those contracts. The EU has already moved in that direction; PPC Land reported that the consolidated AI Act text attaches the 15 million euro or 3 percent penalty to breaches of Article 25's supply-chain obligations, giving vendor contracts for AI tooling in marketing stacks a new clause to negotiate.
The proposed ban on emotional inference deserves close reading. The EU AI Act prohibits emotion recognition only in workplaces and education, according to the report. The committee's recommendation carries no such qualifier. PPC Land noted in 2025 that the EU's transparency rules on emotion detection and biometric categorisation reach advertising platforms using those signals for audience targeting, and that the Commission's guidance on the boundary between influence and manipulation could restrict certain behavioural targeting. A UK prohibition worded as broadly as the committee's would reach further.
Automated decisions are another pressure point. The Data (Use and Access) Act 2025 rewrote the UK's rules on solely automated decisions, which the report says are now restricted mainly where special category data is involved; the committee now wants regulations that would make nominal human review insufficient. Across the Channel the direction is already clear: the Dutch data protection authority on August 21, 2026 fined Uber 824,990,000 euros over fully automated decisions about drivers. Britain's own regulators said in March 2026 that AI agents do not fall outside existing UK regimes, and the ICO is developing a statutory code of practice on AI and automated decision-making.
Synthetic media sits within the committee's equality findings. The report cites deepfake intimate-image abuse as having disproportionate effects on minoritised groups, and records a case from the performers' union Equity in which a voice actor who agreed to a recording "for non commercial purposes to help visually impaired readers to access educational content" later found a cloned version of her voice "made available to others via a text-to-speech tool [...] without [her] consent, control or pay." For brands commissioning synthetic voices or likenesses, the deepfake question has already moved into courts and codes; a Dutch court barred Grok from generating non-consensual nude images earlier this year.
Online safety regulation already touches advertising directly. Ofcom in July 2026 proposed nearly 40 draft measures that would, for the first time, impose binding duties on large platforms to tackle fraudulent adverts under the Online Safety Act 2023. According to the report, the Crime and Policing Act 2026 gives the Secretary of State power to extend that Act to AI services, a power that could close a gap PPC Land described when the government's children's consultation noted that chatbots fall within scope only if they enable user-to-user sharing or search the live internet.
The report also shows how far UK AI governance currently runs through competition and data regulators. The Competition and Markets Authority's first binding conduct requirement on Google, imposed in June 2026, gives publishers opt-out controls over AI Overviews and model training, with substantive obligations from December 3, 2026. The ICO, by contrast, advised government in May 2026 to relax consent rules for low-risk advertising. Neither is the cross-economy AI law the committee describes, and copyright, which the committee explicitly set aside, remains with the House of Lords committee that called in March 2026 for mandatory training-data transparency.
What comes next
A note on the report's landing page gives the government two months to reply, which points to mid-November 2026. The committee adjourned until October 14. Ministers are not bound to accept any recommendation, and the report concedes that the government's approach "may change under the new Prime Minister," whose administration had not published any AI-specific policy by the time the text was finalised, though it had made statements on frontier AI capabilities on September 7 and on AI security on September 9.
Several dates will shape the reply. The Council of Europe's Convention 108 committee meets in plenary from November 17 to 19, 2026. Northern Ireland's implementation of the revised EU product liability rules is due by December 2026. The CMA's obligations on Google bite from December 3. In Brussels, high-risk obligations under the AI Act remain more than a year away.
The committee frames its case as compatible with the government's growth agenda, arguing that regulation can build trust and certainty. Whether a government that has chosen adoption speed as its yardstick agrees is the open question. The report's summary closes with a line from one of its witnesses: "The only growth worth having is one that protects human rights."
Timeline
- November 2023: The AI Safety Institute is established as a research body inside DSIT.
- July 17, 2024: The King's Speech commits to legislation placing requirements on developers of the most powerful AI models.
- August 1, 2024: The EU AI Act enters into force.
- September 5, 2024: The Council of Europe Framework Convention on AI is opened for signature in Vilnius.
- January 2025: The UK publishes the AI Opportunities Action Plan written by Matt Clifford.
- February 2025: The AI Safety Institute is renamed the AI Security Institute, with references to algorithmic bias removed from its agenda.
- February 2025: The European Commission clarifies the line between influence and manipulation under Article 5 of the AI Act.
- May 15, 2025: The European Union ratifies the Framework Convention.
- June 2025: The Data (Use and Access) Act 2025 rewrites UK rules on automated decision-making.
- July 2025: The Joint Committee on Human Rights opens its inquiry; the first oral evidence session is held on July 2.
- September 2025: The European Commission consults on Article 50 transparency rules covering emotion recognition and biometric categorisation.
- October 29, 2025: The committee hears that around 3 million people had their faces scanned by UK police facial recognition between January 1 and October 29, 2025.
- December 8, 2025: The Law Commission sets terms of reference for its product liability review.
- January 2026: Liz Kendall sets out an ambition to make the UK the fastest adopting AI country in the G7.
- January 21, 2026: Google's Alexandria Walden gives evidence.
- February 2026: Spain's data protection authority publishes its guide on agentic AI risks under the GDPR.
- February 4, 2026: Ofcom, the ICO and the EHRC give evidence.
- February 25, 2026: Meta, Microsoft and AI minister Kanishka Narayan give evidence; evidence-taking closes.
- March 2026: The UK government's children's consultation notes that many AI chatbots fall outside the Online Safety Act.
- March 6, 2026: A House of Lords committee report calls for AI training-data transparency.
- March 31, 2026: Four UK regulators publish a foresight paper on agentic AI; the ICO publishes its report on automated recruitment.
- May 7, 2026: EU institutions agree to delay AI Act high-risk deadlines to 2027 and 2028.
- May 18, 2026: The ICO advises government to ease consent rules for low-risk advertising.
- June 2026: The CMA imposes its first conduct requirement on Google, covering publisher content in AI features.
- July 10, 2026: Ofcom opens consultation on draft codes for fraudulent advertising.
- July 20, 2026: Kanishka Narayan is appointed Minister of State for Artificial Intelligence; the European Commission publishes its Article 50 guidelines and code of practice.
- July 21, 2026: OpenAI describes a "new kind of security incident" involving Hugging Face.
- July 22, 2026: A machinery of government fact sheet records AISI's move to the Cabinet Office.
- July 27, 2026: The consolidated EU AI Act text takes effect.
- August 2, 2026: Article 50 transparency obligations become applicable across the EU.
- August 21, 2026: The Dutch data protection authority fines Uber 824,990,000 euros over automated decisions.
- August 26, 2026: The Council of Europe's draft guidelines on privacy in large language model systems are dated.
- September 9, 2026: The committee agrees the report.
- September 14, 2026: The report is published.
- September 16-17, 2026: The Convention 108 Bureau is scheduled to review the draft LLM guidelines in Paris.
- October 14, 2026: The committee's next scheduled meeting.
- Mid-November 2026: The government's reply falls due.
- November 17-19, 2026: The Convention 108 committee meets in plenary.
- December 2026: The revised EU Product Liability Directive is due to be implemented in Northern Ireland.
- December 3, 2026: Substantive CMA obligations on Google take effect.
- December 2, 2027: First of the delayed EU AI Act high-risk deadlines.
Related PPC Land coverage
- UK regulators warn agentic AI is already here - and it needs watching now - The March 2026 foresight paper from the CMA, FCA, ICO and Ofcom on autonomous AI systems.
- Council of Europe drafts privacy rules for AI chatbots and agents - Draft Convention 108 guidelines on LLM memory, agents and training-data leaks.
- UK modernizes data protection with new automated decision framework - How the Data (Use and Access) Act 2025 changed the rules on automated decisions.
- Dutch regulator fines Uber 825 million euros over automated driver blocking - The largest Article 22 penalty issued so far.
- EU AI Act gets its first real haircut - high-risk deadlines pushed to 2027 - The May 2026 provisional agreement on new deadlines and added prohibitions.
- AI Office gains 5% daily penalty power over Google and Meta AI systems - The consolidated AI Act text and its penalty structure.
- EU AI content rules force publishers to label or risk 3% of turnover - The Article 50 guidelines and transparency code.
- EU clarifies boundary between influence and manipulation under AI Act - Article 5 prohibitions as they intersect with behavioural targeting.
- European Commission opens consultation for AI transparency guidelines - Emotion recognition and biometric categorisation duties that reach ad platforms.
- Council of Europe unveils AI discrimination playbook for regulators - Guidance for equality bodies on algorithmic discrimination and the AI Act.
- Spain's data watchdog maps the hidden GDPR risks of agentic AI - The AEPD's guide on agent architectures, automated decisions and automation bias.
- Ofcom proposes scam-ad code as UK loses £200m a year to fraud ads - Draft Online Safety Act codes on fraudulent paid advertising.
- UK launches landmark consultation on children's online world: what's at stake - The consultation chapter on AI chatbots and gaps in the Online Safety Act.
- UK regulator forces Google to give publishers AI opt-out rights today - The CMA's first binding conduct requirement covering AI training and grounding.
- UK's ICO tells government to cut consent rules for low-risk ads - The regulator's May 2026 advice on consent for contextual and measurement uses.
- Lords demand AI firms disclose training data or face UK licensing freeze - The House of Lords report on AI, copyright and the creative industries.
- Dutch court bans Grok from generating non-consensual nude images - The Amsterdam injunction against synthetic intimate imagery.
- AI facial recognition locked up the wrong woman for 5 months - Documented failures of facial recognition in law enforcement, including a UK wrongful arrest.
- UK unveils ambitious AI action plan to become global leader in artificial intelligence - The January 2025 AI Opportunities Action Plan the committee criticised.
Summary
Who: The UK Parliament's Joint Committee on Human Rights, drawing on evidence from Google, Meta, Microsoft, Ofcom, the ICO, the EHRC, civil society groups, academics and AI minister Kanishka Narayan. Its recommendations are addressed to the UK government, and would affect AI developers, deployers including advertisers and platforms, regulators and the AI Security Institute.
What: A 233-paragraph report, Human Rights and the Regulation of AI, with 20 recommendations and 39 conclusions. It calls for a dedicated AI Bill with risk tiers, prohibitions on practices including emotional inference and the development of very powerful AI systems capable of evading human control, prior approval for high-risk systems, supply-chain due diligence, mandatory transparency, tighter automated decision-making rules, an independent statutory regulator with power to withdraw systems from the market, and a statutory AI Security Institute with mandatory pre-release model submission.
When: Agreed on September 9, 2026 and published on September 14, 2026, after an inquiry opened in July 2025 and evidence sessions running from July 2, 2025 to February 25, 2026. A government reply is due by mid-November 2026.
Where: The United Kingdom, with reference to the EU AI Act, the Council of Europe Framework Convention signed in Vilnius, and Northern Ireland's separate implementation of EU product liability rules.
Why: The committee concluded that existing UK law places responsibility on deployers rather than developers, offers no general transparency duty, leaves stand-alone AI software outside strict product liability, and relies on under-resourced regulators and costly individual litigation, so that people harmed by AI systems lack an effective remedy.
Discussion