Summary
- The Joint Committee on Human Rights wants a dedicated AI Bill built around risk levels, enforceable obligations, and human-rights protections.
- High-risk AI systems could require prior approval, while some uses involving profiling, biometrics, or emotional inference could be prohibited.
- The committee argues that responsibility currently falls too heavily on organisations deploying AI rather than upstream developers able to influence how systems are built.
The UK should adopt a dedicated AI law, establish a statutory regulator, and require approval before high-risk systems can be deployed, according to a parliamentary committee that says the country’s existing mixture of data protection, equality, consumer, and sectoral regulation leaves material gaps around artificial intelligence.
The Joint Committee on Human Rights has recommended an AI Bill that would divide systems according to risk, impose obligations throughout the development and supply chain, create mandatory transparency requirements, and allow regulators to stop products reaching the market where unacceptable human-rights risks are identified.
Its report is considerably broader than previous UK proposals focused principally on the most powerful frontier models. The committee wants rules applying not only to organisations deploying AI but also to model developers, system providers, and other actors further upstream, arguing that existing law makes it too easy for responsibility to be transferred contractually towards customers that may have limited visibility into how the technology was built.
The committee described the existing legal environment as “patchy and confused”, while acknowledging that AI can support economic growth and improve areas including healthcare, accessibility, public services, and resource allocation. Its case is not for a general restriction on AI use but for a statutory framework differentiating obligations according to the potential harm of a particular system.
Responsibility would move up the supply chain
The supply-chain proposal could have significant consequences for technology procurement because much enterprise AI now involves several organisations. A foundation-model company may provide the underlying model, another supplier may tune or package it for a particular use, an integrator may connect it to business data, and the final organisation may deploy it to workers or customers.
Under existing UK law, the committee argues that legal responsibilities tend to become clearest at the point of deployment. Data protection duties, employment law, equality obligations, medical-device rules, and sectoral regulation can all constrain particular uses, but organisations further upstream may face fewer systematic requirements to identify and disclose the risks built into the systems they sell.
The report therefore recommends proportionate obligations across all stages of the AI lifecycle, with due-diligence duties differentiated according to each organisation’s role and the seriousness of the risk. It points to the EU AI Act as a possible starting point while arguing that any British system should be tailored to the UK’s own legal framework.
That approach would make supplier due diligence more consequential for companies buying AI. Procurement teams would have a stronger basis for demanding information about training data, testing, foreseeable risks, limitations, and the allocation of responsibility between provider and customer, while developers could face statutory requirements rather than relying principally on voluntary commitments and contractual terms.
High-risk systems could need permission first
Another substantial recommendation is prior approval for AI systems posing a high risk of human-rights harm. At present, pre-market assessment exists only in particular regulated areas, such as higher-risk AI-enabled medical devices, while most software can be released without a regulator first evaluating whether its use creates unacceptable rights risks.
The committee wants a wider testing, auditing, and evaluation regime, alongside powers to prevent systems being launched or to order their withdrawal. It also recommends placing the existing AI Security Institute on a statutory basis and giving it powers to review new and revised powerful models, including publishing findings before release.
Some AI uses would face prohibition rather than additional oversight. The report highlights subliminal techniques, emotional inference, and inappropriate uses of profiling or biometric data as examples of activities that may be incompatible with human rights, while calling for public consultation before detailed bans are written into law.
Transparency would also become mandatory for AI systems capable of significantly affecting individuals, groups, or communities. The committee wants organisations to disclose when AI is being used, explain its purpose in comprehensible terms, and provide information about the source of data used by the system.
A different UK model would emerge
The recommendations are not government policy and will now require a formal response, so organisations should not treat them as impending statutory obligations. They nevertheless add pressure to a long-running debate over whether the UK’s regulator-led approach can remain coherent as AI becomes embedded across employment, finance, public services, healthcare, policing, and consumer markets.
A dedicated AI Bill would also narrow the regulatory distance between Britain and the European Union, even if the resulting systems remained structurally different. UK governments have previously emphasised sector regulators and flexible principles rather than creating an EU-style horizontal AI regime, but the committee argues that cross-economy gaps cannot be closed solely by asking existing regulators to stretch their current powers.
There is disagreement over that conclusion. Evidence cited by the committee includes warnings from the Equality and Human Rights Commission, the Information Commissioner’s Office, Ofcom, and technology-industry representatives that another regulator could duplicate existing responsibilities or introduce overlap unless its remit is tightly drawn.
The committee nevertheless recommends a new body with enough authority to coordinate enforcement and intervene where no existing regulator has clear responsibility. It also wants the government to set a timetable for ratifying the Council of Europe’s Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law.
The policy choice becomes harder to postpone as companies integrate general-purpose models into systems that make or support consequential decisions. A regime centred mainly on the final user leaves developers comparatively insulated from harms introduced earlier in the chain; a broader framework shifts some of that responsibility back towards the companies designing models and products.












