Source · Select Committees · Science, Innovation and Technology Committee
Recommendation 28
28
Deferred
Require generative AI providers to share internal data with independent online safety researchers.
Recommendation
Principle 5 is crucial for addressing potential harms from generative AI, as there is currently a serious shortfall in transparency and oversight of the platforms and systems that allow users to create AI-generated content. The government should require providers of generative AI services to provide information to those carrying out independent research into online safety. This should include data such as platforms’ internal decision-making processes, training datasets, optimisation objectives, safety mechanisms and guardrails on outputs. (Recommendation, Paragraph 77)
Government response summary AI-generated
The government states that provisions in the Data (Use and Access) Act empower the DSIT Secretary of State to create a future framework for independent researchers to access online safety data, which will provide a legislative footing for their research once implemented. This defers the specific requirement for generative AI providers to share data now.
Summary of the government's response below — read the verbatim text to verify.
Government Response
Deferred
HM Government · verbatim extract
Deferred
The government recognises the challenges that researchers face when seeking to obtain online safety data for research. As previously mentioned, the government has powers to create a new framework for researchers to access online safety data. The framework will be informed by a robust evidence base, including a report by Ofcom exploring existing access, barriers, and how greater access might be achieved which was published in July 2025. Improved access to online safety data will enable more comprehensive research into online safety risks, as well as the effectiveness of providers’ processes to mitigate risks to users as part of meeting their online safety duties. As set out in the previous recommendation, generative AI services that allow users to share content with one another or that search live websites to provide search results, are regulated under the online safety regime. The online safety regulatory framework confers a range of powers on Ofcom which will help ensure it can access the information it needs to understand how companies are fulfilling their duties. This includes a power to require a report from a skilled person about a regulated service. A “skilled person” is an individual, organisation, body of persons or association of persons that appear to Ofcom to have the skills necessary to prepare a specific report. This may include technical experts as well as independent researchers. This power will enable Ofcom to utilise the expertise of external experts (skilled persons) to help understand how companies are meeting their regulatory obligations. It may be used to assist Ofcom in identifying and assessing non-compliance or to help develop Ofcom’s understanding of the risk of non-compliance or ways to mitigate such risk where a provider appears to be at risk of failing to comply with a relevant requirement. Ofcom will also have the power to conduct audits which it can use to assess potential non- compliance with regulatory requirements and to build an understanding of the risk associated with a service. Ofcom will also be able to require a provider to allow an authorised person to remotely view certain types of information, where it is proportionate to do so. This includes remotely observing the carrying out of empirical tests. This is a standard method for understanding algorithms and which involve taking a test dataset, running it through an algorithmic system, and observing the output. Additionally, and as set out in the above recommendation, The AI Security Institute take’s a leading role in testing frontier AI models for potential risks both pre and post deployment, allowing the government to stay ahead of risks and capabilities as they emerge.
Read the full response on Parliament ↗