Parliament says UK AI rules are not fit for purpose

· · AI

If your business uses AI tools and nobody has written down what that means for the business, you are not breaking any UK law. That is not reassurance. It is the actual problem a parliamentary committee just put a name to: there isn't a law to break, because the UK has never passed one.

The Joint Committee on Human Rights, a group of MPs and peers who scrutinise government policy for its effect on people's rights, published a report this month telling the government it needs to stop treating AI regulation as something it can improvise. The committee's chair, Alex Sobel MP, put it plainly: "we are unprepared to deal with its consequences however potentially dire they may be." His committee wants a proper AI law and a single regulator with the power to enforce it, The Register reported.

What the committee actually found

The UK currently relies on two things: existing laws that happen to cover some AI use (data protection, equality law, consumer protection) and voluntary commitments from the companies building AI models. The committee's verdict is that this leaves the field patchy and confused, with no single body responsible for AI as a whole. If an AI system produces an unfair or discriminatory outcome, working out who is accountable and how to get it fixed is currently a matter of chasing across several regulators, none of whom own the problem.

The report wants a risk-based law: lighter requirements for low-risk uses, tougher obligations the higher the stakes get, plus mandatory transparency about how AI systems are built and deployed. It also wants a single independent AI regulator, established in law, as the place a person or business could actually go with a concern. This mirrors the shape of the European Union's AI Act, which the UK has not adopted. The government has said since 2024 that it intends to legislate for the most powerful AI models, but no bill has been introduced.

What this means before any law exists

A select committee report is a recommendation to government, not a rule you need to comply with today. What it changes is the outlook: the current arrangement, use your judgement plus whatever the vendor promises, has just been described, by a parliamentary committee, as not fit for purpose. That assessment is reasonable to act on before it becomes legislation.

The practical point for a business already using AI tools, which by now is most businesses, is that the absence of formal rules is not a gap you can ignore. It is a gap you are filling yourself, whether you decided to or not. Every AI tool in use, every piece of data going into it, and every decision it is allowed to influence is currently governed by habit and whatever the supplier says in its marketing. A written AI-use policy, however short, turns that habit into a decision you made on purpose, and it is also the document you will reach for first if a formal law arrives and asks what controls you had in place.

How Steelwise can help

If you do not yet have a short, honest written policy covering which AI tools your business uses, what data goes into them, and who is accountable for the answers they give, that is a gap worth closing now, before a regulator makes it compulsory. Get in touch.

Further reading

← All filings