Human rights committee calls for AI Bill, single AI regulator and tougher UK GDPR rules on automated decisions
- Details
The UK Parliament's Joint Committee on Human Rights has called on the government to introduce a dedicated AI Bill, create a single statutory AI regulator and strengthen the UK GDPR's safeguards on automated decision-making, saying that the current legal framework is fragmented, applies mainly at the point of deployment and leaves people unable to find out when AI has been used in decisions that affect them.
Alex Sobel MP, chair of the committee, said no jurisdiction, including the UK, currently had a legislative and regulatory approach to AI that was fit for purpose, and that new legislation was needed to cover the whole AI supply chain and lifecycle. Sobel said the central aim was to ensure "that you, as an individual, know when AI is being used in the decisions that affect you", with avenues of redress available when something goes wrong.
Its report, Human Rights and the Regulation of AI (HC 160 / HL Paper 56), published today (14th September), follows an inquiry launched in July 2025 that took more than 70 written submissions and held ten oral evidence sessions. Its main recommendations are:
- A new AI Bill, as promised in the 2024 King's Speech, taking a risk-based approach that classifies systems by risk level and imposes proportionately heavier obligations on higher-risk systems and models
- Outright prohibition of AI uses incompatible with human rights, with subliminal techniques, emotional inference and inappropriate use of profiling or biometric data cited as candidates, subject to public consultation on the detail
- Prior approval from a public oversight body before high-risk AI systems can be provided or deployed
- Due diligence obligations on actors at every stage of the supply chain, graded by their role and the gravity of the risk
- Mandatory transparency requirements across the AI lifecycle, including a duty to state when and how AI is being used in decisions with significant effects on individuals
- Greater clarity in data protection law on automated decision-making, with UK GDPR rules strengthened so that the mere presence of a "human in the loop" does not count as meaningful human involvement
- A single, independent AI oversight body on a statutory footing, with powers to set codes of practice, impose transparency requirements and sanction wrongdoing
- The AI Security Institute placed on a statutory basis, replacing its current voluntary arrangements with developers
- A published timetable for ratifying the Council of Europe Framework Convention on AI, subject to consultation
The committee found that existing mechanisms on automated decision-making were not working as intended in practice. Articles 22A to 22D of the UK GDPR and sections 50A to 50D of the Data Protection Act 2018, as inserted by the Data (Use and Access) Act 2025 restrict decisions based solely on automated processing where there is no meaningful human involvement, require safeguards including notification, the right to make representations, human intervention and the right to contest a decision.
They also give the Secretary of State power under Article 22D to make regulations defining what does and does not amount to meaningful human involvement. Controllers deploying AI that is likely to result in high risk to individuals must also carry out a data protection impact assessment under Articles 35 and 36 and consult the ICO where residual risk remains high.
However, the committee heard that compliance with DPIA requirements is patchy, that the Equality Act 2010 does not reach developers supplying AI systems business-to-business, and that the Human Rights Act 1998 binds only public authorities while almost all AI development takes place in the private sector.
Witnesses told the committee that even highly trained human reviewers struggle to scrutinise AI outputs effectively and are prone to automation bias, and the report concludes that there are no specific legal obligations on human oversight outside the automated decision-making provisions.
On transparency, the committee concluded that existing law does not require individuals to be told that an AI system is in use, and that the Algorithmic Transparency Recording Standard, while a useful starting point, has no statutory basis and is limited in coverage.
The standard is mandatory for government departments and arm's-length bodies delivering frontline services but not for local authorities or police forces, and witnesses including Louise Hooper of Garden Court Chambers told the committee that not all algorithmic use by in-scope bodies is being recorded. The Law Society told the inquiry there remained a gap in the form of a wider right to challenge automated decision-making that does not depend on data protection law.
The Information Commissiner's Office (ICO) gave the committee a more sanguine account of the existing regime, saying the challenges AI raises for privacy and data protection were complex but not insurmountable under current legislation, and that it prioritised its resources towards areas of greatest impact in enforcement and upstream regulation.
William Malcolm of the ICO said the regulator believed in working with technology providers to build in privacy by design and default at the front end. Other witnesses, including Ravi Naik of AWO, described the ICO as stretched and said individuals could not expect the regulator to act on every complaint.
The report also recorded evidence that around three million people had their faces scanned by police live facial recognition between January and October 2025, that web scraping to train large language models has often taken place without adequate consideration of the individuals whose personal data is collected, and that re-identification from apparently anonymous data has become easier as multiple datasets can be combined. It noted that the government confirmed its intention to ratify the Framework Convention but has set no timetable.
The committee stressed that regulation should be proportionate, with lower-risk systems facing fewer requirements and no unjustified burdens on business, and that framework legislation setting out broad principles, supplemented by codes of practice, would keep pace with technological change better than detailed primary legislation.
It observed that the government, having promised legislation for the most powerful models in the 2024 King's Speech, has yet to bring forward a Bill, and that the AI Security Institute has no power to demand access to models or prevent their release.
“We also recognise that AI has the potential to provide great benefits to society, including improving how human rights are protected. That is why it will be important to ensure that regulation is proportionate and targets the areas of AI development and usage that pose the greatest risks," Sobel said.
The government has two months to respond.
Assistant Director of Legal and Governance
Senior Lawyer
Lawyer - Contract, Procurement and Information Law
21-09-2026
23-09-2026 9:30 am




