The U.K. government has presented itself as a potential global leader in AI safety, including through plans for an international summit and a £100 million foundational model task force. But a report from the Ada Lovelace Institute argues that international ambitions will carry little weight unless the country strengthens its rules and protections at home.
Broad principles leave key questions unanswered
The government’s preferred approach relies on existing regulators applying a set of principles to AI in their sectors. Those principles cover safety, security and robustness; transparency and explainability; fairness; accountability and governance; and contestability and redress.
The Institute says principles alone may not be enough. The plan does not give regulators new legal powers or additional funding, even as they take on responsibility for AI. That leaves open practical questions about who will oversee systems, how consistent oversight will be, and whether regulators can act when problems arise.
The report also points to gaps in the current regulatory landscape. It identifies areas such as recruitment and employment, education and policing, central government activities including benefits administration, and parts of the private sector such as retail. In these settings, responsibility for applying AI principles may be unclear or spread across an uneven network of regulators.
As AI use expands across sectors, the Institute warns, existing gaps could lead to inconsistent safeguards. Developers may also face uncertainty about which rules apply and which bodies oversee their systems. The report argues that clearer rights and new institutions are needed so protections reach people across the economy.
Data protection changes could weaken safeguards
The report raises a second concern: the government’s proposed Data Protection and Digital Information Bill (No. 2). The Institute says the bill would significantly amend protections in the UK GDPR, which it describes as important for protecting individuals and communities from potential AI harms.
One change discussed in the report concerns automated decisions. The bill would remove a prohibition on many types of such decisions and instead require data controllers to put safeguards in place, including measures that let an individual contest a decision. The Institute argues that this could mean a lower level of protection in practice.
That matters because the government’s AI framework depends heavily on existing laws and regulators. If the underlying data protection rules are weakened, the Institute says, the broader framework may be less able to guard against harm. It cites potential effects on people dealing with everyday services, such as applying for a loan.
The Institute recommends rethinking elements of the data protection bill that could undermine the safe development, deployment and use of AI, including changes to the accountability framework. It also calls for a wider review of existing rights and protections, with new safeguards considered where AI-informed decisions affect people.
What the Institute wants regulators to be able to do
Among its recommendations, the report proposes a statutory duty for regulators to consider the government’s AI principles. It also calls for strict transparency and accountability obligations, alongside more resources for regulators working on AI-related harms.
The Institute suggests exploring common powers for regulators, including a capability to oversee developers before AI systems are deployed. It also recommends considering whether an AI ombudsperson could help people adversely affected by AI. The report further calls for greater clarity on the law around AI and liability.
Together, these proposals are meant to address the limits of relying on broad principles and a fragmented set of existing rules. The Institute’s case is that credible AI safety regulation needs clear responsibilities, workable powers and routes for people to challenge decisions that affect them.
More visibility into foundational models
The report also focuses on foundational models, which have drawn government attention amid interest in generative AI tools such as OpenAI’s ChatGPT. The Institute recommends mandatory reporting requirements for U.K.-based developers of these models so regulators can better track rapid technical developments.
It proposes requiring leading developers, including OpenAI, Google DeepMind and Anthropic, to notify the government when they or their subprocessors begin large-scale training runs of new models. The Institute says early notice could give policymakers and regulators time to prepare for changes in AI capabilities.
Suggested reporting would also cover information such as access to training data, results from in-house audits and supply chain data. The report adds that the government could invest in small pilot projects to improve its understanding of trends in AI research and development.
The report’s central argument is that global leadership depends on domestic credibility. In the Institute’s view, a summit and international coordination can support that ambition, but they cannot replace stronger rules and protections within the U.K.