How can we help you?

The Joint Committee on Human Rights has issued a stark warning: nowhere in the world does a legislative framework exist that is genuinely fit to address the human rights risks posed by artificial intelligence. 

Read the committee's report here.

For those of us working at the intersection of law and technology, this is not a surprising conclusion, but it is a significant one. The question that follows is both urgent and genuinely difficult: what would meaningful regulation actually look like, and can any single jurisdiction realistically deliver it?

The problem is already here

The JCHR's report does not describe abstract future risk. It catalogues harms that are happening now: AI-generated sexualised imagery, non-consensual facial recognition, discriminatory bias perpetuated through systems trained on flawed datasets, and the weaponisation of AI to spread misinformation at scale. These are not theoretical concerns for policy papers. They are active violations of rights protected under the Human Rights Act 1998 and the European Convention on Human Rights, covering dignity, privacy, freedom from discrimination, and the right to a fair process.

The committee's call for a dedicated AI bill, a single independent statutory oversight body, and outright prohibition of certain AI uses reflects a growing recognition that piecemeal, sector-by-sector responses may be failing. The current framework is, as the JCHR puts it, "fragmented and difficult to navigate", leaving real gaps in protection for real people.

What meaningful regulation would need to look like

Effective AI regulation is not simply a matter of drafting new prohibitions. It requires genuine architecture, and several elements would be essential.
Risk-tiering with real teeth is the starting point. A proportionate framework, one that regulates a low-stakes recommendation algorithm differently from a system making decisions about welfare entitlements or criminal risk, is both legally defensible and practically workable. The EU AI Act attempted precisely this, though its implementation has exposed how difficult it is to classify risk in a field moving this quickly.

A statutory oversight body with genuine independence is equally critical. Voluntary industry commitments have, in the committee's view, not been sufficient. Any credible body must have the power to investigate, compel disclosure, and sanction, not merely to advise. It must also be properly resourced, because technology consistently moves faster than regulators.

Some applications of AI are simply incompatible with fundamental rights and should be prohibited outright. Subliminal behavioural manipulation, mass indiscriminate biometric surveillance, and systems that automate discriminatory profiling without meaningful human oversight should not be subject to a cost-benefit balancing exercise. 

Finally, obligations need to attach across the full AI lifecycle, not just at the point of deployment. Regulation that ignores design, training data, and testing will always arrive too late. Legal duties around data provenance and model transparency need to exist from the development stage onwards.

The isolation problem

This is where the analysis becomes uncomfortable for any purely domestic legislative agenda. The JCHR acknowledges that this is a global challenge requiring international cooperation, and that acknowledgement deserves to be taken seriously, because it cuts against the idea that a UK-only AI bill, however well drafted, can deliver meaningful protection on its own.

AI systems do not respect borders. A model developed in California, trained on data harvested globally, deployed via a platform registered in Ireland, and used by a person in London raises jurisdictional questions that no single Parliament can fully resolve. The regulatory arbitrage risk is real: if the UK imposes obligations that competitor jurisdictions do not, developers will find ways around them.

This does not mean domestic legislation is pointless. The UK can set standards, require transparency from systems operating within its borders, and use procurement and market access as levers. But meaningful protection will ultimately require the kind of international framework called for recently, encompassing global regulatory coordination, independent cross-border monitoring, and industry-wide standards with genuine enforcement behind them. 

The Prime Minister is today travelling to the UN General Assembly, where he is expected to announce the commencement of a new AI and Autonomy partnership with the United States, focused on protecting critical national infrastructure through AI technology. He is also expected to call for a global pause on the development of superintelligent AI and to propose the establishment of a new international AI safety agency, a development which, if realised, could go some way towards providing the cross-border oversight architecture that the JCHR's analysis demands.

Where does this leave us? 

As lawyers, we are trained to ask whether rights are matched by remedies. The JCHR's report raises that question in a context where the answer is, at present, no. 

The report does not resolve the tension between the need for domestic action and the reality that AI operates globally. But it does at least name it clearly. A UK-specific bill may be a necessary step, but it is unlikely on its own to be a sufficient one. How the Government navigates that tension, and whether it can build the international cooperation that meaningful oversight would require, remains to be seen.