Article

UK: Joint Committee on Human Rights publishes report on the regulation of AI

Highlight of the week

UK: Joint Committee on Human Rights publishes report on the regulation of AI
On September 14, 2026, the Joint Committee on Human Rights (JCHR) published its report titled Human Rights and the Regulation of AI (the report), together with an accompanying press release. The JCHR is a cross-party joint select committee of Parliament, comprising up to 12 members appointed from both the House of Commons and the House of Lords. The JCHR’s remit is to examine matters relating to human rights in the UK and to scrutinize government bills for their compatibility with human rights. 

The report sets out the JCHR's findings following its inquiry into whether existing UK law and regulation adequately protect human rights in the context of artificial intelligence (AI) and calls on the government to introduce a comprehensive AI Bill and establish a new independent AI oversight body. In the course of its inquiry, the JCHR received evidence from key regulators, including the Information Commissioner’s Office (ICO), which told the JCHR that while the challenges posed by AI to privacy and data protection are complex, it did not consider them “insurmountable under the current legislation”. 

The report acknowledges that AI has the potential to drive economic growth and enhance certain human rights protections. However, the JCHR identifies novel and serious risks, noting in particular that (i) AI systems are often opaque; (ii) individuals are frequently unaware AI is being used in ways that affect them, and (iii) harms can occur at scale and speed. The report focuses on three key risk areas: 

  1. Equality and non-discrimination: highlighting concerns that AI systems are prone to producing unfairly discriminatory outcomes, which may arise from bias in the datasets on which the systems are trained, as well as from the manner in which they are developed and deployed.
  2. Privacy and personal data protection: noting the prevalence of web scraping to train large language models and the potential for AI systems to be used in intrusive ways, including by collecting personal data, such as biometric data, from individuals without their awareness or consent, and to use that data to identify them. The JCHR observes that the availability of AI systems increases the risk that individuals can be re-identified from apparently anonymised data, particularly where multiple datasets can be combined to reveal identifying factors.
  3. Right to an effective remedy: highlighting risks where there is insufficient transparency concerning the use of AI systems to support significant decisions about affected individuals, and where it is difficult for those individuals to access mechanisms to challenge such decisions.

The JCHR has concluded that existing UK law is not fit for purpose, noting that current laws apply to AI primarily at the point of deployment, placing the burden of responsibility on deployers rather than on the upstream developers that design and build AI systems. The JCHR stated that the current framework is fragmented, relies on harm-specific and sector-specific legislation, and leaves gaps in protection. Regulators also lack the power to test AI systems before release or to prevent their release if they pose unacceptable risks.

Call for a new AI Bill

The JCHR has recommended that the government introduce a new AI Bill to create an AI-specific legal framework applying across all sectors. The Bill should adopt a risk-based approach, classifying AI systems by level of risk and imposing proportionately more demanding obligations on higher-risk systems, while not placing unjustified burdens on businesses, particularly small and medium-sized enterprises (SMEs). Key recommendations include:

  • Prohibiting certain use cases of AI (with the detail of such prohibitions to be established following public consultation), including subliminal techniques, emotional inference and the inappropriate use of profiling or biometric data, as well as the development of very powerful AI systems (such as artificial general intelligence and artificial superintelligence, which may have the capacity to evade effective human control).
  • Requiring prior approval before AI systems posing a high risk of causing harm to human rights can be provided or deployed.
  • Imposing proportionate due diligence obligations on actors at all stages of the AI lifecycle and supply chain (from design and development through to deployment), differentiated according to each actor's role and the seriousness of the risk posed.
  • Introducing mandatory transparency requirements across the AI lifecycle, including an obligation to inform individuals when AI systems are being used in ways that significantly affect them, and to provide information about the source of data used (noting that transparency should also operate between actors in the supply chain, so that deployers receive sufficient information from upstream developers to carry out their own due diligence).
  • Using the regulation-making powers under the UK General Data Protection Regulation (UK GDPR) to strengthen safeguards for automated decision-making, including to make clear that the mere presence of a “human in the loop” is not sufficient to constitute meaningful human involvement. Instead, data subjects must be given enough information to mount an effective challenge against automated decisions.

JCHR recommendations

The JCHR has recommended the establishment of a single, independent AI oversight body on a statutory footing. The new body should, among other things, act as the central point of contact for raising concerns about AI; carry out testing and evaluation of AI systems (including a prior approval regime for high-risk uses); prohibit AI systems from being launched or deployed (and order their withdrawal from the market) if unacceptable risks are identified; publish mandatory codes of practice and sanction noncompliant actors; and order remedies in individual cases without requiring affected individuals to incur prohibitive costs.

The JCHR has also recommended that the AI Security Institute (AISI), which currently operates on a voluntary basis with no statutory powers, should be placed on a statutory footing, with developers of powerful AI models required to submit new models to AISI for review, evaluation, and testing.

Finally, the report notes that the UK has signed but not yet ratified, the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy, and the Rule of Law, the first legally binding international instrument targeting AI. The JCHR has urged the government to set out a timeline for ratification subject to public consultation.

The report is available here, and the press release is available here. 

Related capabilities

subscribe

Interested in this content?

Sign up to receive alerts from the A&O Shearman on data blog.