AI regulation gaps
Need for an AI regulatory framework that effectively addresses the identified challenges of AI governance.
Source spread
Where this theme appears
This theme appears across 7 independent accountability sources, so the source mix matters as much as the headline total.
1 PFD report
267 committee recs
2 HSSIB recs
1 HMICFRS rec
8 NAO recs
1 Scottish FAI
Browse by source
Source-grouped records are useful for tracing where a concern came from. Large sections show the 50 strongest matches for that source; counts still show the full theme total.
Select committee recommendations(267)— showing 50 strongest matches
#105 —
Recommendation: The continued development and integration of new technologies, such as digital assets and AI, into the financial services sector may alter how sections of this industry function . We are concerned by evidence to suggest that the UK regulators may …
Response attribution not verified
#103 —
Recommendation: Witnesses also commended the Government and the regulators’ approach to the use of AI by authorised firms. Sandra Boss told us: “By taking a principles-based approach it is enabling a rapidly changing area to develop and enabling companies to look …
Response attribution not verified
#19 —
Recommendation: The continued development and integration of new technologies, such as digital assets and AI, into the financial services sector may alter how sections of this industry function. We are concerned by evidence to suggest that the UK regulators may not …
Response attribution not verified
#17 —
Recommendation: Increasing use of digital communication can leave behind people in vulnerable circumstances, including older people and those with disabilities of mental and physical health, who need or prefer alternative communication channels.45 Citizens Advice told the committee that companies increasingly using …
#14 —
Recommendation: The Government must preserve the UK’s freedom to regulate AI, digital services taxes, and online safety in the national interest. The UK should not trade away these regulatory freedoms in pursuit of resuming the TPD. (Recommendation, Paragraph 69) Arrangement on …
Response status not verified
#21 —
Recommendation: Other key comparator markets such as the EU and USA have put in place import bans on goods linked to forced labour. The UK’s lack of equivalent legislation puts the UK at risk of becoming a dumping ground for goods …
Response attribution not verified
#35 —
Recommendation: The Government should establish an AI counter disinformation sandbox to test the boundaries of regulation and technology. The sandbox should facilitate experimentation of AI tools across Whitehall, the intelligence community and trusted international partners. (Recommendation, Paragraph 165)
Response attribution not verified
#54 — Publish cross-government guidance on liability for harmful AI uses, establishing it via statute where appropriate.
Recommendation: Nobody who uses AI to inflict harm should be exempted from the consequences, whether they are a developer, deployer, or intermediary. The next Government together with sectoral regulators publish guidance on where liability for harmful uses of AI falls under …
Response attribution not verified
#29 — US and EU AI governance approaches reveal downsides in scope and implementation.
Recommendation: Both the US and EU approaches to AI governance have their downsides. The scope of the former only imposes a requirement on Federal bodies and relies on voluntary commitments from leading developers. The latter has been criticised for its top- …
Response attribution not verified
#37 — Public Law Project warns of bias and transparency risks in DWP's machine learning for fraud.
Recommendation: However, written evidence we received from the Public Law Project raised a series of risks around DWP’s use of machine learning to tackle fraud. In particular, it noted the risk of machine learning taking on human biases when it was …
Response attribution not verified
#36 — DWP uses machine learning for fraud, but with limited transparency on fairness assessment.
Recommendation: DWP is implementing machine learning techniques to help it identify fraud in benefit expenditure. It has one machine learning model in operation, for new UC advance claims, alongside several others in development.69 The previous Public Accounts Committee raised concerns about …
Response attribution not verified
#7 — Share fairness impact assessment results for machine learning to reassure against unfair claimant treatment.
Recommendation: We remain concerned about the potential negative impact on protected groups and vulnerable customers of DWP’s use of machine learning to identify potential fraud. The previous Public Accounts Committee repeatedly raised concerns about the impact of data analytics and machine …
Response attribution not verified
#29 — Criminalise use of nudification apps as synthetic NCII and hold platforms accountable.
Recommendation: There is no legitimate reason whatsoever for the use or existence of nudification apps. The Government should ensure that the use of such an app is considered creation of synthetic NCII and therefore also a criminal offence and Ofcom should …
Response attribution not verified
#28 — Require tech companies to cleanse datasets of NCII and source data responsibly.
Recommendation: The private sector has innovated to create AI technology. It does not need to wait for legislation to catch up in order to safeguard individuals from harmful AI-generated content. As a starting point tech companies involved in AI content creation …
Response attribution not verified
#27 — Mandate consent-based offence for deepfake creation, including cultural intimate image abuse.
Recommendation: The Government’s plans to criminalise the creation of sexually explicit deepfakes/NCII, even if they are not shared, are very welcome and worthy of praise. However, the Government must ensure that the offence is consent- based and does not require the …
Response attribution not verified
#26 — Ofcom's proposals should require companies to accept non-consensual intimate image hash matching.
Recommendation: It is clear that some companies require further persuasion to accept NCII hashes. We welcome Ofcom’s plans to launch a consultation in spring 2025 on expansions to its Codes of Practice that would include proposals on the use of hash …
Response attribution not verified
#9 — Direct user-to-user and search engine services to utilise a registry of non-consensual intimate image content.
Recommendation: In its illegal content Codes of Practice, Ofcom should direct user-to-user and search engine services to make use of a registry of NCII content, compiled by an expert body, on a similar basis to the provisions that exist for child …
Response attribution not verified
#8 — Create guidance for internet providers and web browsers on tackling non-consensual intimate image abuse.
Recommendation: The Government should create guidance for internet infrastructure providers and web browser manufacturers on tackling online non-consensual intimate image abuse, similar to that which already exists for online child sexual exploitation and abuse. This guidance should direct both groups to …
Response attribution not verified
#7 — Amend the Crime and Policing Bill to make possession of non-consensual intimate images an offence.
Recommendation: The Government should bring forward an amendment to the Crime and Policing Bill to make possession of NCII an offence, in addition to its creation. This will put NCII on the same footing as CSAM in how it is treated …
Response attribution not verified
#6 — Justification to legally align NCII with CSAM to prompt provider action
Recommendation: For internet infrastructure providers to take the threat of NCII seriously and block access to websites that refuse to take it down, we believe that there is justification in bringing NCII in line with CSAM in law. (Conclusion, Paragraph 56)
Response attribution not verified
#5 — Ofcom's powers insufficient for timely removal of individual NCII abuse content
Recommendation: Ofcom’s current enforcement powers, while welcome, are far too slow and not designed to help individual victims get abusive images of themselves on non-compliant websites taken down or have access to them restricted. The duties under the regulatory regime created …
Response attribution not verified
#24 — AI governance fragmented across government, but recent departmental transfers consolidate responsibility.
Recommendation: At the time of the NAO report, responsibility for AI in government was split across the Cabinet Office—which was primarily responsible for AI adoption in the public sector, through CDDO, i.AI and the Government Digital Service (GDS)—and DSIT, which held …
Response attribution not verified
#13 — DSIT acknowledges more work needed for AI transparency and redress mechanisms.
Recommendation: We asked DSIT for reassurances that there would be sufficient transparency and mechanisms for citizens to challenge AI assisted decisions. It told us that there were provisions in the Data (Use and Access) Bill to allow for redress and challenge …
Response attribution not verified
#12 — The Algorithmic Transparency Recording Standard remains underused, hindering public sector AI transparency.
Recommendation: The Algorithmic Transparency Recording Standard (ATRS), is intended to support public sector bodies to improve transparency and provide information about the algorithmic tools they are using, but the NAO found it was not widely used.27 We challenged DSIT on this …
Response attribution not verified
#2 — Update committee on Algorithmic Transparency Standard compliance and high-risk AI spend controls.
Recommendation: Public trust is being jeopardised by slow progress on embedding transparency and establishing robust standards for AI adoption in the public sector. Public confidence that the AI technology used by government is fair, accurate, secure and safe is key to …
Response attribution not verified
#59 — Conduct a review of copyright and GDPR to prevent unlicensed data use for AI.
Recommendation: Within the next six months the Government should also conduct a review of the Copyright, Designs and Patents Act 1988 and the UK’s GDPR framework to consider whether further legislation is needed to prevent unlicensed use of data for AI …
Response attribution not verified
#58 — Legislate to prevent historical contract waivers from allowing AI use of recorded performances
Recommendation: The Government should legislate to prevent historical contract waivers from being interpreted to allow the use of recorded performances by AI tools. (Recommendation, Paragraph 207)
Response attribution not verified
#57 — Current legislation fails to protect performers from nefarious generative AI use across creative industries
Recommendation: Although the film and HETV industry may be motivated to protect performers’ interests, with the history of collective bargaining agreements equipping it do so, that situation is not common across all the creative industries. The UK’s patchwork of copyright, intellectual …
Response attribution not verified
#56 — Generative AI technologies threaten earnings and employment for film and HETV creatives
Recommendation: Our world-class creatives are the lifeblood of the UK’s film and HETV sectors. However, the rapid growth of generative AI technologies threatens their earnings and future employment opportunities. This is not just an issue for one part of the industry: …
Response attribution not verified
#55 — Require AI developers to license copyrighted works before training AI models
Recommendation: The Government should abandon its preference for a data mining exception for AI training with rights reservation model, and instead require AI developers to license any copyrighted works before using them to train their AI models. (Recommendation, Paragraph 194)
Response attribution not verified
#54 — Opt-out data mining regime risks UK’s creative industries and copyright reputation
Recommendation: Getting the balance between AI development and copyright wrong will undermine the growth of our film and HETV sectors, and wider creative industries. Proceeding with an ‘opt-out’ regime stands to damage the UK’s reputation among inward investors for our previously …
Response attribution not verified
#53 — Develop and mandate ethical AI certification for generative AI use in film and HETV
Recommendation: The Government’s AI Sector Champion for the creative industries, once appointed, should work with the industry to develop an AI certification scheme for the ethical use of generative AI in film and HETV. In setting out guidelines for the responsible …
Response attribution not verified
#52 — Fund BFI’s development of an AI observatory and tech demonstrator hub
Recommendation: At the Spending Review, the Government should fund the BFI’s development of an AI observatory and tech demonstrator hub to enable it to provide effective leadership around the industry’s use of AI. (Recommendation, Paragraph 186)
Response attribution not verified
#51 — Film and TV sectors need support to responsibly embrace generative AI growth potential
Recommendation: Industry guidelines based around protecting human creativity in the use of generative AI are welcome, but the film and TV sectors are calling out for help to embrace the growth potential of generative AI in a way that is fair, …
Response attribution not verified
#14 — Commission research on applying regulatory measures to SVoD platforms for IP ownership
Recommendation: We recommend the Government immediately commissions research on how regulatory measures, akin to the PSB terms of trade, could be applied to SVoD platforms to ensure that independent production companies developing IP in the UK maintain a minimum level of …
Response attribution not verified
#5 — Bring Section 14 of the Equality Act 2010 into force by next parliamentary session.
Recommendation: The Government should fulfil its commitment to bring section 14 of the Equality Act 2010 into force and do so by the end of the next parliamentary session at the latest. (Recommendation, Paragraph 24)
Response attribution not verified
#3 — Lead efforts to reach consensus on autonomous weapons and create an international instrument.
Recommendation: We recommend that the UK Government takes the lead in efforts to reach a consensus on the use of autonomous weapon systems and artificial intelligence on the battlefield and the creation of an international instrument on their use. (Recommendation, Paragraph …
Response attribution not verified
#37 — Empower Ofcom to issue penalty notices to platforms for monetising harmful content on their services.
Recommendation: There are insufficient disincentives for bad practice in the digital advertising market. Bad actors can exploit the ecosystem, monetising harmful content through major platforms. Following Principle 3, Ofcom should be empowered to give penalty notices to platforms when they allow …
Response attribution not verified
#35 — Mandate the Advertising Standards Authority to establish comprehensive digital advertising ecosystem guidelines for all actors.
Recommendation: To tackle the incentive behind amplified misinformation—namely, the monetisation of harmful content—there should be clear and enforceable standards for digital advertising market processes, as well as advertising content. Following our Principles 1, 3 and 5, government should ask the Advertising …
Response attribution not verified
#34 — Establish new arms-length body or extend Ofcom's powers to regulate digital advertising supply chain.
Recommendation: Tackling online harm means addressing the principles that incentivise and monetise its spread. In line with Principle 3, responsibility, the government should create a new arms-length body—not funded by industry—to regulate and scrutinise the process of digital advertising, covering the …
Response attribution not verified
#33 — Significant regulatory gap in digital advertising allows harmful content monetisation; self-regulation is insufficient.
Recommendation: There is a regulatory gap around digital advertising, as much of the regulation and interventions have been industry-led and focused on tackling harmful advertising content, as opposed to the monetisation of harmful content through advertising. We are not convinced that …
Response attribution not verified
#30 — Social media algorithms fail to differentiate harmful from harmless content, spreading misinformation.
Recommendation: Advertising is crucial to major social media companies, which depend on recommending engaging content to increase time spent on their platforms and draw attention to adverts. Their recommendation algorithms do not effectively differentiate between harmless and harmful engaging content, which …
Response attribution not verified
#29 — Mandate generative AI platforms to automatically label AI-generated media with metadata and watermarks.
Recommendation: To effectively tackle amplified misinformation as per Principle 1, the government should work with relevant experts and platforms to develop technology that automatically detects AI-generated media, meeting mis/ disinformation at its source. It should mandate all generative AI platforms, and …
Response attribution not verified
#28 — Require generative AI providers to share internal data with independent online safety researchers.
Recommendation: Principle 5 is crucial for addressing potential harms from generative AI, as there is currently a serious shortfall in transparency and oversight of the platforms and systems that allow users to create AI-generated content. The government should require providers of …
Response attribution not verified
#27 — Pass legislation requiring generative AI platforms to conduct risk assessments and implement user safeguards.
Recommendation: To protect citizens from the AI-exacerbated spread of misinformation and harm, the government should pass legislation that covers generative AI platforms, bringing them in line with other online services that pose a high risk of producing or spreading illegal or …
Response attribution not verified
#26 — Concerns regarding regulatory and government contradiction and Ofcom's complacency on online safety.
Recommendation: We are concerned at what appears to be contradiction and confusion between regulators and government over the capabilities, limitations and principles behind the Online Safety Act. We expect senior Ofcom officials and ministers to be fully aligned in their understanding …
Response attribution not verified
#25 — Online Safety Act fails to protect users from synthetic disinformation and harmful experimental features.
Recommendation: The Online Safety Act does not protect users from the commodification of synthetic mis/disinformation, or provide effective transparency for the systems that produce them. It fails to address the issue of tech companies rolling out experimental features that can feed …
Response attribution not verified
#22 — Collaborate with platforms to identify and track disinformation actors and their online spreading techniques.
Recommendation: Foreign interference and disinformation campaigns, with use of technology such as bots and AI, put UK citizens at risk. The possibility that some of the divisive messages and deceptive content spread by users—and amplified by algorithms—last summer were part of …
Response attribution not verified
#21 — Create an additional regulatory category for 'small but risky' platforms, based on their online harms.
Recommendation: The Online Safety Act does not do enough to address the risks posed by small platforms due to its exclusive focus on size. Ofcom should create an additional category to cover ‘small but risky’ platforms, based on analysis of the …
Response attribution not verified
#20 — Confirm that platform services are required to act on all risks identified in assessments.
Recommendation: To ensure true responsibility from platform companies, as per Principle 3, Ofcom and DSIT should confirm that services are required to act on all risks identified in risk assessments, regardless of whether they are included in Ofcom’s Codes of Practice. …
Response attribution not verified
HSSIB safety recommendations(2)
Missed detection of lung cancer on chest X-rays of patients being seen in primary care
HSIB recommends that NHSX, in collaboration with relevant stakeholders such as The Royal College of Radiologists and The Society and College of Radiographers, develops guidance to support independent benchmarking and validation of artificial intelligence algorithms for the identification of lung …
Safety Recommendation
12-lead electrocardiograms (ECGs) in ambulance services: diagnosis of suspected ST elevation myocardial infarction (STEMI) — …
Algorithm developers can improve patient safety by collecting data from different ethnic groups across different geographical locations to help increase the global representation and accuracy of auto-interpretation algorithms for STEMI.
Safety Observation
NAO audit recommendations(8)
Use of artificial intelligence in government
CDDO should work with the government functions to review existing guidance, government standards and assurance processes to ensure they adequately address the opportunities and risks of AI use and provide sufficient levers to promote safe and responsible use of AI …
Partially accepted
Use of artificial intelligence in government
CDDO should work with the government functions to review existing guidance, government standards and assurance processes to ensure they adequately address the opportunities and risks of AI use and provide sufficient levers to promote safe and responsible use of AI …
Partially accepted
Use of artificial intelligence in government
CDDO should work with the government functions to review existing guidance, government standards and assurance processes to ensure they adequately address the opportunities and risks of AI use and provide sufficient levers to promote safe and responsible use of AI …
Partially accepted
Use of artificial intelligence in government
CDDO should work with the government functions to review existing guidance, government standards and assurance processes to ensure they adequately address the opportunities and risks of AI use and provide sufficient levers to promote safe and responsible use of AI …
Accepted
Use of artificial intelligence in government
CDDO should work with the government functions to review existing guidance, government standards and assurance processes to ensure they adequately address the opportunities and risks of AI use and provide sufficient levers to promote safe and responsible use of AI …
Accepted
Use of artificial intelligence in government
To deliver on its strategy for public sector AI adoption, the Cabinet Office should: In collaboration with DSIT, assess the new strategy and governance arrangements to make sure they are fit for purpose and ensure effective coordination with DSIT-led AI …
Partially accepted
Use of artificial intelligence in government
CDDO should continue to prioritise the 2022-2025 roadmap for digital and data, to address the legacy IT infrastructure and data quality and access barriers to adoption of AI, and ensure future plans maintain continued focus on addressing the risks that …
Accepted
Use of artificial intelligence in government
The Cabinet Office should establish how government can bring together and share accessible insights from cross-government activity to identify, prioritise and test scalable AI opportunities in the public sector, including working with DSIT to leverage the wider research landscape such …
Partially accepted
Independent reviews(10)
National workload action group: reports on social worker workload — Rec 17
DfE should urgently produce national guidance on the use of AI in children’s social care, in partnership with Ofsted, Social Work England, BASW, Unison and the new AI Safety Institute, building on existing frameworks and standards to provide an ethical framework for decision-making to: • underpin the increased use of …
Health & Social Care
Fisher Review (Part 1) — Rec 2
To support the wider use of advanced technology in the criminal justice system, a cross-agency protocol should be created, covering the ethical and appropriate use of artificial intelligence in the analysis and disclosure of investigative material.
Justice & Legal
Accepted
Hall-Pesenti AI Review — Rec 14
The Information Commissioner's Office and the Alan Turing Institute should develop a framework for explaining processes, services and decisions delivered by AI, to improve transparency and accountability.
Other
Furman Review — Rec 20
Strategic recommendation D: The government, CMA and the Centre for Data Ethics and Innovation should continue to monitor how use of machine learning algorithms and artificial intelligence evolves to ensure it does not lead to anti-competitive activity or consumer detriment, in particular to vulnerable consumers.
Other
Sewell Commission — Rec 3
Improve the transparency and use of artificial intelligence The Commission supports the recommendations of the Centre for Data Ethics and Innovation (CDEI) and calls on the government to: • place a mandatory transparency obligation on all public sector organisations applying algorithms that have an impact on significant decisions affecting individuals …
Other
Goldacre Review — Rec TRE 57
Address TREs for Artificial Intelligence, but as a separate workstream, funded by existing AI resource TREs with the core features described above will readily support all analysis using traditional analytical or epidemiological research techniques. Analysis and research involving techniques that fall under the heading of Artificial Intelligence – particularly unsupervised …
Health & Social Care
Penrose Competition Review — Rec 13
NDMU should have a legal duty to extend and promote competition in the monopolies it regulates, by making pro-competition interventions to reinstate normal competitive conditions wherever it's possible and proportionate. As the Furman Review also recommended, this should include: designing and enforcing a pro-competitive code of conduct to give both …
Other
Penrose Competition Review — Rec 12
the new digital unit's extra-strong upfront powers must be ring-fenced tightly, to prevent regulatory creep, otherwise they will steadily spread to cover every digital sector of the economy. To reinforce this vital, central point, the new unit should be called the Network & Data Monopolies Unit (NDMU) and its extra-strong …
Other
Gloster Report (LCF/FCA) — Rec 13
the Treasury and other relevant Government bodies should work with the FCA to ensure that the legislative framework enables the FCA to intervene promptly and effectively in the marketing and sale through technology platforms, and unregulated intermediaries, of speculative illiquid securities and similar retail products.
Other
Goldacre Review — Rec IG 24
Negotiate co-ownership of claimed commercial innovations from NHS data When a company develops an “algorithm” such as a risk prediction tool they typically apply existing tools, techniques and code libraries to huge, richly detailed health datasets that were collected at great cost. The code libraries used for this work, such …
Health & Social Care