Contributed By CMS Cameron McKenna Nabarro Olswang LLP
The UK does not currently regulate AI through a single comprehensive statute. Instead, AI systems are governed through existing frameworks including data protection, intellectual property, employment, product liability, consumer protection and sector-specific regulation.
For current purposes, AI is defined in the same way as it is in the UKJT Consultation Paper on AI and Civil Liability. In essence, that refers to technology that is autonomous.
The definition has two key components:
AI systems display:
This distinguishes AI from deterministic or merely automated software.
AI challenges traditional legal models and approaches primarily because AI has no legal personhood.
AI systems may:
Further practical difficulties associated with AI include:
These difficulties are not unique to AI but may be intensified by it.
English common law remains however sufficiently flexible to address many AI-related disputes. This is particularly important. After all, the law has developed in the way it has for good reasons and those reasons still exist in the AI context (sometimes a fortiori).The main challenge for the common law in the AI era is not the law itself having to change, but the means by which existing legal rules are applied to new sets of (technological) facts. Some of the more significant examples of this are outlined below.
AI Supply Chains and Actors
The following are the principal dramatis personae in AI ecosystems:
As above, since AI has no legal personality, it cannot itself cannot bear legal liability under English law. Only natural persons and legal persons may therefore be liable. Responsibility must therefore attach to developers, deployers, users, employers or suppliers.
Contract as the Primary Liability Mechanism
Contracts will often be the most common means of governing liability for AI-related harm.
Risk allocation commonly occurs through:
Negligence Liability and AI
The tort of negligence has a marked capacity for determining the locus of liability for harms caused by AI where there has been no ex ante contractual allocation of risk.
This of course means that claimants must establish:
As suggested above, existing negligence principles can generally adapt to AI-related harms. It is, however, the implementation of these principles to novel factual situations that requires a rethink.
Professional Negligence and AI
Professionals, for instance, might be liable for the negligent use of AI and for negligently not using AI.
Potentially negligent conduct includes:
Examples of such conduct include lawyers citing hallucinated cases, architects failing to review AI-generated designs and financial advisers relying blindly on AI outputs. An extant question is the extent to which professionals will be held liable for failing to employ relevant and available AI tools where it would have been reasonable to do so. In practice, this is a question whose answer will depend on the facts of any given case, and will be forensically resolved on the basis of the Bolam test (under which a court asks whether there exists a responsible body of professional opinion that would deem the use or non-use to have been reasonable in the circumstances). There is no reason why the Bolitho limitation on this (allowing a court to discount such an assessment where it finds it has no logical basis) would not apply in the same way as it does to any assessment of professional behaviour.
Liability for the Actions of Another
Whilst situations of this type are most often covered by the doctrine of vicarious liability, such an approach is not ideally suited to harms caused by AI because it is premised on harms being caused by another; and in legal terms, AI is not “another”. It would seem, therefore, that the concept of non-delegable duties is more appropriate in this context, ensuring that those who choose to implement AI in certain situations cannot thereby divest themselves of responsibility for the consequences of that.
Product Liability and the Consumer Protection Act 1987
Legal liability for defective products is an area in which AI creates particularly thorny problems. Not only does the ever-increasing production and use of AI and software-based products mean that there will inevitably be a corresponding increase in the damage caused by such products, but this is a legal field in which existing rules and principles are not so easily transposed onto the AI sphere. This is primarily due to the product liability regime that derives from the Consumer Protection Act 1987 (CPA). Developed to create (almost) strict liability for those supplying products that cause harm, the CPA aimed to spare consumers injured by defective goods from having to prove negligence on the part of the relevant suppliers. Claimants under the CPA instead need only prove that the product was indeed defective (with a very limited “development risks defence” available to producers where the scientific knowledge that would have allowed them to realise that the product was defective was not available to them at the relevant time). The idea behind the CPA — which was based on a European Directive — was to rebalance the risk of harm from defective products as between those who bought them and those who made a profit out of producing them.
The problem created by the rise of AI-based products is that, in many cases, the CPA is unlikely to apply to an AI system that is not incorporated into a tangible product. The issue is that the CPA 1987 applies to a “product”, which is statutorily defined to refer to “goods” and “electricity”. The CPA 1987 defines “defect” at s. 3(1): “if the safety of the product is not such as persons generally are entitled to expect; and for those purposes ‘safety’, in relation to a product, shall include safety with respect to products comprised in that product and safety in the context of risks of damage to property, as well as in the context of risks of death or personal injury”. CPR 1987 defines “goods” at s. 1(2): “means any goods or electricity and … includes a product which is comprised in another product, whether by virtue of being a component part or raw material or otherwise”.
In St Albans DC v International Computers Ltd [1996] 4 All E.R. 481, the Court of Appeal expressed the view that software was not “goods” for the purpose of the Sale of Goods Act 1979, but distinguished the situation where the software was supplied on disk. The same distinction was applied in the context of an electronic database in Your Response Ltd v Datateam Business Media Ltd [2014] EWCA Civ 281. More recently, the Court of Appeal in the Computer Associates UK Ltd v Software Incubator Ltd litigation held that software was not goods for the purposes of those regulations. The CJEU (in a post-Brexit decision) took a different view, but not one that informs the position under CPA 1987. It would seem therefore that, unless embedded within and forming part of a tangible thing, English law is unlikely to characterise software or AI as “goods” for the purposes of the stricter liability regime. This is particularly so given that most AI systems are supplied not as software but as services, which is one step further removed from the concept of “goods”. The Law Commission has recently announced that it will be looking a this issue, with a view to reforming the law in this area to make it more modern, fair and accessible, so this position might change in the near future (Law Commission projects tend to take around 18 months from inception to recommendation stage. Any consequent statutory changes are then likely to take around the same amount of time to pass through Parliament). It is worth noting that the EU has already made changes to its product liability law in order expressly to accommodate AI-based products in the form of its new Product Liability Directive (2024/2853)
In summary, therefore, the stricter liability regime might apply where AI is embedded within physical products such as autonomous vehicles and robotic systems, but not where it stands alone as a piece of software and is, for example, acquired by means of a download, as opposed to some means of physical delivery.
Causation Challenges
AI systems can create significant evidential difficulties because:
English law’s approach to dealing with difficult causation issue in the past has involved the use of:
Most notably, the causation element of the negligence inquiry has, in relatively recent times, seen the judicial development of a significant (and undoubtedly controversial) exception to the standard requirement that a claimant prove a but-for factual causal link between the defendant’s breach and her damage. In Fairchild v Glenhaven Funeral Services Ltd [2003] 1 AC 32, the House of Lords allowed claimants to establish a causal link by proving that a defendant’s breach materially increased the risk of their damage eventuating. Whilst this exception was set out as (and has remained) within very tightly constrained factual parameters, namely those involving a single causal agent, multiple potential sources of that agent and evidential impossibility in establishing a sine qua non relationship between any particular source of the agent and the ensuing damage, it stands as an example of the way in which the common law can adapt to apparently intractable evidential problems. There is no reason to suppose that it cannot rise to the challenges presented by the addition of AI to the causal nexus.
Harm Caused by Bad Actors
English criminal law has responded to the development and use of AI in a gradual and largely reactive way. Rather than creating a single “AI criminal code,” Parliament, the courts, prosecutors and regulators have adapted existing criminal offences while introducing targeted legislation for new AI-related harms, especially those involving deepfakes, fraud, online abuse and autonomous systems.
The response can be understood in five main areas.
1. Using existing criminal offences to cover AI conduct
English criminal law has generally treated AI as a tool used by humans, rather than as an independent legal actor with its own legal personhood. As with tortious liability, criminal liability therefore still attaches primarily to the person deploying or controlling the AI.
The focus remains on the human locus of mens rea and actus reus.
2. Creation of new AI-specific offences: deepfakes and intimate images
One of the most significant developments has been the criminalisation of sexually explicit AI-generated “deepfakes”. Historically, gaps existed because older revenge porn laws assumed that the images were real. AI-generated intimate images often fell outside those provisions.
In response, the UK government has introduced new offences targeting the creation of non-consensual intimate deepfakes, including the requests on which their creation is based, as well as the actions of sharing or threatening to share the images produced. (Changes made to the Sexual Offences Act 2003 by s 138 of the Data (Use and Access) Act 2025).
A major shift is that creation alone can now constitute an offence, even if the image is never distributed. The government justified this change by pointing to the rapid growth of AI-enabled abuse, particularly against women and girls.
3. Online platform regulation and the Online Safety Act
English law has also responded through platform regulation. The Online Safety Act 2023 imposes duties on online platforms to prevent illegal and harmful content, including AI-generated abuse.
Deepfake sexual imagery has increasingly been classified as priority illegal content, meaning platforms may have proactive duties to detect and remove it.
Ofcom has also begun to examine the role that AI systems and generative tools play in unlawful content dissemination.
4. Evidential and procedural challenges
AI has also, somewhat inevitably, affected criminal procedure and the integrity of evidence. Courts increasingly face concerns about fabricated audio or video evidence, AI-generated witness manipulation, the reliability of digital evidence, algorithmic bias and the explainability of AI systems.
Deepfakes create obvious risks for the integrity of criminal trials because realistic synthetic evidence may undermine confidence in video or audio proof.
At the same time, police forces are beginning to use AI for predictive policing, facial recognition, evidence review and risk assessment. This has, in turn, generated debate about fairness, transparency and compatibility with human rights protections under the Human Rights Act 1998, especially Article 6 (fair trial) and Article 8 (privacy).
Overall, English criminal law has responded to AI through a combination of adapting existing offences, creating targeted AI-specific crimes, regulating online platforms, expanding digital investigative powers and developing policy guidance.
In employment law, AI primarily raises issues in relation to recruitment and selection processes. The legal approach remains that determined by the application of the Equality Act 2010 and its proscription of employment practices that discriminate against candidates based on their protected characteristics, such as age, gender, race, disability or sexual orientation. This means that employers choosing to use AI-based recruitment tools must ensure that their function does not discriminate in any unlawful way. In practice, this will usually be a question of ensuring that the data used to “teach” the algorithm does not entrench historical biases.
Artificial intelligence has progressed through key architectural stages, shifting from traditional machine learning to foundation models, Retrieval-Augmented Generation (RAG) and agentic AI, each enabling more autonomous and context-aware capabilities across industries.
Traditional Machine Learning Applications
ML models trained on structured data are widely used for prediction and optimisation in sectors such as banking, healthcare, manufacturing and retail, delivering benefits including cost reduction and improved forecasting.
Foundation Models and LLMs
These large-scale models generalise across tasks and underpin AI chatbots, legal document analysis applications, coding assistants and media content generation, thereby increasing automation and enhancing user experience.
Retrieval-Augmented Generation Systems
By integrating LLMs with external data retrieval, RAG systems improve accuracy and are able to provide greater enterprise context. They also facilitate knowledge management in healthcare, finance and education.
Agentic AI Capabilities
The latest AI systems can autonomously reason, plan and execute activities across finance, cybersecurity, trade supply chains, healthcare and enterprise productivity functions.
The UK government actively supports artificial intelligence innovation and regards it as a key driver for economic growth and global competitiveness through a comprehensive national strategy.
National AI Strategy and Oversight
The UK’s National AI Strategy, launched in 2021, includes a ten-year framework for AI research, commercialisation, governance and education, providing support for institutions like the Office for Artificial Intelligence and the AI Safety Institute.
Investment and Incentives
The provision of funding through, inter alia, UKRI, Innovate UK and EPSRC supports universities and start-ups. These initiatives are complemented by R&D tax relief and grants designed to encourage innovation and monetisation.
Infrastructure, Skills and Partnerships
Investments have been made in, for instance, elite computing, STEM education and AI training. Funds have also been directed towards the formation of public-private partnerships and city-based initiatives to accelerate AI adoption and its use across key industries.
The UK adopts what is probably best described as a hybrid approach to AI regulation: innovation-focused and risk-based. It eschews precautionary regulation or uniform licensing and instead emphasises sector-specific oversight and cross-border alignment.
Pro-Innovation Regulatory Framework
There is no comprehensive, bespoke, overarching framework for AI. Instead, the following principles are regarded as paramount in its regulation: safety, transparency, fairness, accountability and redress. The Data (Use and Access) Act 2025 reforms the rules governing automated decision-making and international data transfers without imposing a general licensing system or homogenising risk profiles.
Two-Track AI Regulation
Standard and familiar AI is regulated by sector regulators such as the ICO and the FCA, while frontier or highly capable AI systems are subject to closer safety scrutiny through the AI Security Institute, in an effort to balance innovation and caution.
Human Oversight and International Approach
There is no universal or generic requirement for there to be a human in the loop. The UK seeks international interoperability and lies somewhere between the EU’s prescriptive model and the US’s laissez-faire approach, with lifecycle regulation spread across the design, deployment and post-deployment phases.
See 3.1 General Approach to AI-Specific Legislation.
See 3.1 General Approach to AI-Specific Legislation.
There is no applicable information in this jurisdiction.
There is no applicable information in this jurisdiction.
Text and Data Mining (TDM) Exceptions
The UK currently permits non-commercial research TDM under a narrow copyright exception (Section 29A of the Copyright, Designs and Patents Act 1988), without a broad commercial AI training exception. A proposed opt-out model for commercial TDM faced strong opposition and remains unresolved.
AI-Specific Data Processing Rules
AI is regulated under the UK GDPR and the Data Protection Act 2018, employing principles such as fairness, transparency and accountability. The 2025 Data (Use and Access) Act relaxed restrictions on automated decisions but emphasised the following safeguarding principles:
Web Scraping Legality
Web scraping for AI training involves a complex mixture of legal considerations including data protection, copyright, database rights, contract law rules and computer misuse. The ICO generally looks for a legitimate interests justification under the UK GDPR, based on purpose, necessity and balancing.
Synthetic Data Frameworks
The UK does not have bespoke legislation dealing with synthetic data, but its general approach is supportive of it as a privacy-enhancing technology when datasets are anonymised and the risk of re-identification is low. The ICO has expressed caution that generative models may unintentionally retain personal data, and so the regulatory focus remains on anonymisation standards under existing data protection laws. As of early 2026, the new Data (Use and Access) Act 2025 has updated the UK’s data protection framework, placing greater emphasis on robust governance for privacy-enhancing technologies (PETs) and revised definitions of anonymisation.
Deepfakes and Synthetic Media
The Online Safety Act 2023 addresses AI-generated harmful content including non-consensual intimate imagery and manipulated media, imposing active moderation duties on platform providers. See (1.1 General Legal Background for more detail).
Balancing Innovation and Protection
The UK’s approach is based on the premise of balancing innovation whilst also safeguarding creative industry rights and privacy.
Ongoing Political and Regulatory Activity
The UK government continues to consider various options for AI-related copyright exceptions and data governance. It is without question a controversial area of regulatory activity.
Whilst there have been a couple of private members’ bills concerned with general AI governance, none has succeeded and there are no plans for any overarching AI statute. In keeping with the general UK approach to law and regulation in this area, the legislative methodology has been sector and issue-specific (eg, online harms, copyright and product liability). See 1.1 General Legal Background for more information on online harms and product liability and 3.6 Data, Information or Content Laws for more on copyright.
There is a growing body of judicial and quasi-judicial decisions in the UK that is shaping how the law applies to AI systems and products. The most important cases fall into six clusters: intellectual property, data protection, liability for AI-related outputs, employment and algorithmic management, consumer protection and competition law.
Intellectual Property (IP)
AI as inventor: Thaler v Comptroller-General of Patents (DABUS)
The foundational UK AI patent case is Thaler v Comptroller-General of Patents, Designs and Trade Marks decided by the UK Supreme Court in 2023. The claimant argued that an AI system (“DABUS”) autonomously invented two products and should therefore be named as inventor.
The Supreme Court unanimously rejected the claim and held that:
The case established that an “inventor” under the Patents Act 1977 must be a natural person.
AI-generated works and copyright authorship
Although the UK Copyright, Designs and Patents Act 1988 expressly recognises “computer-generated works” where there is no human author, courts and policymakers increasingly interpret copyright as requiring meaningful human creativity. See SAS Institute v World Programming Ltd [2013] EWCA Civ 1482 for more information.
Human creative contribution remains a focal point for copyright protection, and purely autonomous AI output might in the future receive reduced protection in subsequent reforms.
Training data and copyright infringement: Getty Images v Stability AI [2025] EWHC 2863 (Ch)
Getty alleged that Stability AI copied millions of Getty images to train Stable Diffusion without permission. The litigation raised questions regarding:
The High Court rejected Getty’s secondary infringement theory but did not definitively resolve the legality of AI training on copyrighted works.
The case established that courts are reluctant to equate model weights with stored copyrighted copies, while leaving the broader legality of training on copyrighted material unresolved.
Patentability of AI systems: Emotional Perception AI Ltd v Comptroller [2026] UKSC 3
This shows that the UK courts continue to grapple with the distinction between patentable AI innovations and excluded software implementations.
Data Protection and Privacy
Facial recognition and AI surveillance: Bridges v South Wales Police [2020] EWCA Civ 1058
The Court of Appeal held that South Wales Police’s use of automated facial recognition technology was unlawful and in violation of Article 8 of the European Convention of Human Rights (ECHR).
Employment Law and Algorithmic Management
Uber BV v Aslam [2021] UKSC 5
The UK Supreme Court held that Uber drivers were “workers” entitled to labour protections. A major factor was Uber’s algorithmic control over fares, ride allocation, monitoring and penalties.
Algorithmic management can amount to a level of employer control that is sufficient to trigger employment protections.
Cross-Cutting Judicial Themes
Discussed above in 3.1 General Approach to AI-Specific Legislation (Two-Track AI Regulation – ICO, FCA and AI Security Institute), with enforcement by the ICO, CMA and FCA discussed in 5.3 Enforcement Actions.
Discussed above in 3.1 General Approach to AI-Specific Legislation under Pro-Innovation Regulatory Framework and Two-track AI Regulation.
Data Protection Enforcement Highlights
The ICO’s action against Clearview AI for unlawful facial recognition data scraping resulted in a £7.5 million fine and data deletion orders, setting key precedents on UK GDPR’s extraterritorial reach and biometric data legality. The ICO also scrutinises generative AI on data use, transparency, and automated decision risks.
Consumer Protection and Competition Focus
The CMA investigates foundation model markets for issues like market concentration and misleading AI claims, while regulators combat “AI washing” to ensure AI-enabled products comply with consumer protection and fairness rules.
Sector-Specific AI Oversight
The FCA targets financial services AI concerns including bias and operational resilience; employment AI systems and children’s privacy protections under the ICO’s Age Appropriate Design Code are also under growing regulatory scrutiny.
Enforcement Trends and Remedies
UK enforcement relies on fines, notices, audits, and coordinated actions through the Digital Regulation Cooperation Forum, with increasing attention on foundation models, human-centered accountability, and emerging agentic AI systems acting autonomously.
The UK has adopted a pro-innovation regulatory approach to AI governance, emphasising flexible regulation, international coordination, and industry-led technical standards rather than a single AI regulator. National standard-setting bodies adapt and operationalise international AI standards for domestic use, significantly impacting companies operating in the UK AI market.
UK AI Standard-setting Framework
The UK relies on existing regulators, technical standards bodies, assurance mechanisms, and voluntary governance frameworks to shape AI system design, deployment, and governance. Key bodies include the British Standards Institution, National Physical Laboratory, and the Alan Turing Institute, alongside sectoral regulators acting as quasi-standard setters.
Adoption of International AI Standards
The UK has incorporated important international standards such as ISO/IEC 42001 for AI management systems and ISO/IEC 23894 focused on AI risk management, covering governance, risk mitigation, human oversight, and lifecycle monitoring.
Expansion of AI Assurance Ecosystem
The UK government promotes AI assurance encompassing auditing, testing, certification, and governance validation, with growing expectations for companies to demonstrate explainability, fairness, robustness, cybersecurity, and compliance readiness.
Commercial and Regulatory Impacts on Companies
Compliance with AI standards affects governance burdens, procurement eligibility, litigation risks, and cross-border interoperability. Standards are especially critical for foundation models and autonomous AI, with scrutiny on data provenance, evaluation, hallucination management, and post-deployment monitoring
The UK’s engagement with international standard-setting bodies supports the pro-innovation, risk-based and sector-led approach discussed in 3.1 General Approach to AI-Specific Legislation. International standards help regulators and businesses apply principles such as safety, transparency and accountability consistently, while promoting cross-border interoperability.
The principal international body is ISO/IEC JTC 1/SC 42, whose standards include ISO/IEC 42001 on AI management systems and ISO/IEC 23894 on AI risk management. As discussed in 6.1 National Standard-Setting Bodies, these standards support AI assurance activities such as risk assessment, auditing, certification, human oversight and lifecycle monitoring. The UK participates through BSI’s ART/1 committee.
Other relevant bodies include the Institute of Electrical and Electronics Engineers (IEEE), the International Telecoms Union (ITU) and CEN-CENELEC JTC 21, which is developing harmonised standards for the EU AI Act. International policy is also influenced by the OECD AI Principles, the G7 Hiroshima Process and the Council of Europe AI Convention, which the UK has signed but not yet ratified.
Government’s AI Approach
The UK government adopts a pro-innovation stance on AI, guided by strategies and frameworks such as the National AI Strategy and the Generative AI Framework.
AI Types In Use
Agencies employ traditional machine learning for fraud detection and risk scoring, natural language processing for chatbots and document tasks, facial recognition by law enforcement, algorithmic decision-making for prioritisation and emerging autonomous systems in defence and cybersecurity.
Healthcare AI Applications
The NHS uses AI for medical imaging, cancer detection, diagnostics, patient risk stratification and administrative automation, making it one of the largest public AI adopters.
Taxation and Welfare AI
HM Revenue & Customs applies AI for tax fraud detection and compliance, while the Department for Work and Pensions uses algorithmic systems to detect benefits fraud and assess eligibility.
Law Enforcement and Immigration
Police deploy facial recognition and predictive analytics, with notable legal challenges regarding the legality of facial recognition technology; the Home Office uses AI for visa triaging and immigration risk assessments.
Defence and National Security
The Ministry of Defence explores AI for intelligence, cyber defence, autonomous systems, logistics and battlefield support.
Legal and Regulatory Framework
Public-sector AI is subject to the UK GDPR, data protection laws, human rights and equality obligations, administrative law and procurement rules, with an emphasis on the lawful, fair, transparent and safe use of AI.
Governance and Oversight
Frameworks stress accountability, explainability, human oversight, contestability and security in AI deployment across government bodies.
Concerns and Controversies
Issues include a lack of transparency, bias and discrimination, surveillance and the potential consequent infringement of civil liberties and the possibility of a growing overreliance on automation.
Ordinary public-law grounds such as illegality, irrationality, discrimination and procedural unfairness apply to AI decisions, with courts underscoring that algorithms do not remove legal accountability and that therefore human oversight is essential.
Strategic Importance of AI
The UK identifies AI as a core capability in multiple national strategies.
AI in intelligence and data processing
AI supports processing large intelligence datasets, pattern recognition, signals intelligence, satellite imagery analysis, language translation and intelligence fusion. Machine learning also accelerates analysis of communications metadata, imagery, cyber threats and behavioural patterns.
Cybersecurity applications
AI is used for intrusion and anomaly detection, malware analysis, threat intelligence, automated defence and vulnerability identification, offering faster cyberattack detection than traditional methods.
Autonomous and semi-autonomous systems
The UK is exploring autonomous aerial, maritime and robotic systems, mostly maintaining human supervision rather than full autonomy.
Decision support systems
AI assists operational planning, logistics optimisation, predictive maintenance, battlefield information management and strategic modelling, complementing human decision-makers.
Biometric and surveillance technologies
Facial recognition, biometric matching, behavioural analytics and predictive surveillance are increasingly used but raise privacy, bias and civil liberties concerns.
Generative AI and large language models (LLMs)
LLMs and generative AI are used for summarisation, intelligence drafting and synthetic training, while addressing risks like hallucinations, misinformation, data leakage, cybersecurity vulnerabilities and adversarial manipulation.
Legal and ethical frameworks
The Defence AI Strategy emphasises responsible, human-centric AI with transparency, accountability and legal compliance. Humans retain responsibility for lethal decisions, adhering to international humanitarian law, human rights, data protection and weapons review obligations.
The UK uses a sectoral, principles-based AI regulation relying on existing regulators, guidance, and standards, emphasising safety, transparency, fairness, accountability and redress. Focus areas include responsibility allocation, model governance, data provenance, cybersecurity, misinformation and market power concentration. This is discussed in more detail in 2.1 Industry Use (foundation models, LLMs and RAG), 3.1 General Approach to AI-Specific Legislation (regulatory approach), 3.6 Data, Information or Content Laws (TDM, data processing, deepfakes) and 4.1 Precedent-Setting Judicial Decisions (Getty Images v Stability AI on training data)
AI-assisted Legal Research Advances
AI tools use natural language processing and predictive analytics to speed up case law searches and generate legal analysis, but there are significant risks of hallucinated citations and inaccurate summaries.
Contract analysis efficiency
AI systems improve contract review and due diligence by reducing time and costs; however, concerns about data bias, confidentiality and accuracy persist, with law firms remain responsible for oversight.
Litigation prediction tools
AI can predict case outcomes and settlement values using historical data, but it may reinforce bias, oversimplify judicial reasoning and risk overreliance.
Generative AI drafting risks
AI assists in drafting legal documents but can hallucinate cases or misquote authorities, posing ethical risks and potentially leading to breaches of professional duties.
Confidentiality and data risks
Cloud-based AI raises concerns over the exposure of privileged information, data retention, cross-border transfers and cybersecurity vulnerabilities, requiring careful legal assessment.
Unauthorised legal practice concerns
AI chatbots offering legal guidance may risk the unauthorised practice of law and consumer harm, with current UK regulation emphasising professional obligations and consumer protection.
Ethical and professional duties
UK solicitors and barristers remain fully accountable for competence, confidentiality, supervision and integrity when using AI, and human oversight is essential to verify outputs.
Data protection and cybersecurity
Legal providers must comply with UK GDPR and implement robust cybersecurity measures to manage AI-related vulnerabilities and data risks.
Judicial adoption of AI
Courts cautiously explore AI for administrative tasks but emphasise human judicial responsibility, transparency and fairness, while avoiding automated adjudication.
Emerging governance and access issues
Law firms are developing AI policies to meet client expectations, while AI offers potential access-to-justice benefits amid concerns about inequality, bias and the erosion of professional judgement.
Discussed in 1.1 General Legal Background under “Contract as the Primary Liability Mechanism”, “Negligence Liability and AI”, “Professional Negligence and AI”, “Liability for the Actions of Another”, “Product Liability and the Consumer Protection Act 1987” and “Causation Challenges”.
Discussed in 3.1 General Approach to AI-Specific Legislation (principles-based, sector-led approach; DUAA 2025), with enforcement practice at 5.3 Enforcement Actions.
Discussed in 1.1 General Legal Background (definition of autonomous AI, absence of legal personhood and responsibility attaching to developers, deployers and users); 2.1 Industry Use (“Agentic AI Capabilities”); 3.1 General Approach to AI-Specific Legislation (“Pro-Innovation Regulatory Framework”, “Two-Track AI Regulation” and “Human Oversight and International Approach”); and 21.1 AI Governance Frameworks and Implementation.
Discussed in 1.1 General Legal Background, under “AI Supply Chains and Actors”, “Contract as the Primary Liability Mechanism”, “Negligence Liability and AI” and “Liability for the Actions of Another”.
Legal Frameworks for AI Fairness
The Equality Act 2010 is the main statute addressing discrimination based on protected characteristics. It is supplemented by the Public Sector Equality Duty, UK GDPR, the Data Protection Act 2018 and general human rights law, all of which apply to AI systems and seek to prevent unfair and discriminatory outcomes.
Fairness testing and bias mitigation
Organisations are increasingly required to conduct fairness assessments, bias testing, and algorithmic audits involving subgroup analysis and impact evaluations. Bias mitigation calls for representative datasets, balanced sampling, fairness constraints, human oversight and continuous monitoring.
Liability and enforcement
Organisations remain liable for discriminatory outcomes produced by AI systems, including those from third-party vendors. Relevant risks include discrimination claims, regulatory enforcement and judicial review. Public authorities are also subject to equality and human rights challenges, as exemplified by the unlawful facial recognition case of R (Bridges) v Chief Constable of South Wales Police, discussed previously.
Industry best practices and regulatory scrutiny
Responsible AI principles, including fairness, accountability, transparency and human oversight, are increasingly promoted in both hard and soft law, alongside governance frameworks and independent audits. UK regulators, including the ICO, FCA, CMA and EHRC emphasise compliance with fairness and explainability standards, with growing scrutiny on public-sector AI and generative AI systems.
Biometric AI Technologies and Applications
These systems include facial, fingerprint, iris and voice recognition; gait analysis; emotion recognition; behavioural biometrics; and biometric categorisation. They affect sectors such as policing, healthcare, retail and online identity verification.
Emotion recognition and biometric categorisation
Emotion recognition has generated regulatory concerns over its reliability and fairness. There is no blanket UK ban on its use, but it is regulated under data protection and equality laws. Biometric categorisation systems raise profiling and discrimination issues and are similarly regulated.
Remote biometric identification
Systems that identify individuals remotely through facial or gait recognition are not generally prohibited but are regulated as outlined above, with an emphasis on necessity, proportionality and appropriate safeguards.
Consent and transparency requirements
Biometric data is classified as special category data under Article 9 of the UK GDPR, requiring a lawful basis for processing and, often, explicit consent. This can present challenges in workplace contexts. Transparency requirements, including privacy notices and data protection impact assessments, are also mandatory.
Accuracy and bias concerns
Accuracy is critical in high-risk areas, with facial recognition systems demonstrating demographic biases that may create discrimination risks. Organisations are therefore expected to conduct ongoing accuracy and fairness assessments.
Data protection and security measures
Biometric data requires enhanced protection, including encryption, access controls, minimisation and limited retention periods. Cross-border data transfers and the processing of vulnerable individuals' data require additional safeguards.
Enforcement and regulatory scrutiny
The ICO has taken significant action in the past, such as that against Clearview AI for unlawful biometric data processing, as discussed above.
Discussed in 1.1 General Legal Background ("Harm Caused by Bad Actors" — the new deepfake offences and Online Safety Act) and 3.6 Data, Information or Content Laws ("Deepfakes and Synthetic Media").
Disclosure of AI Use
Organisations must inform individuals when AI systems materially affect them, with obligations arising under data protection, consumer law, financial regulation and professional standards. This includes automated decision-making, profiling, AI-generated content and customer interactions.
Chatbot interaction disclosure
Users should be informed when interacting with chatbots, especially in sensitive contexts involving vulnerable individuals or legally significant decisions.
Transparency of AI-generated content
Generative AI produces synthetic media such as deepfakes and cloned voices, raising risks of misinformation and fraud. UK approaches favour voluntary labelling and transparency standards, with online safety laws addressing harmful AI content and potential future rules on transparency in political advertising.
Explainability requirements
Explainability is key to trustworthy AI, with the UK GDPR granting individuals the right to meaningful information about automated decisions, particularly in employment, lending and healthcare. The Information Commissioner’s Office (ICO) stresses context-dependent explanations and human oversight, while public authorities are subject to legal obligations of fairness.
Safe harbours and exceptions
Transparency obligations are balanced against concerns relating to trade secrets, intellectual property, national security and law enforcement.
Regulation of manipulative AI
Concerns focus on AI systems that exploit behavioural vulnerabilities, manipulative advertising and emotional manipulation, particularly where children and other vulnerable users are affected. Consumer protection laws and the ICO’s Age Appropriate Design Code address these risks, alongside increasing scrutiny of dark patterns and AI-driven persuasion.
Foundation model transparency
Foundation models pose transparency challenges because of opaque training data and evolving capabilities. Regulatory focus includes data provenance, risk management, safety testing and governance, with developers using model cards and other forms of documentation. Market concentration and competitive concerns have also been highlighted.
Emerging trends and alignment
The UK aligns its AI governance framework with international standards and OECD principles, relying on voluntary industry standards while facing growing pressure for mandatory disclosure requirements and stronger oversight as AI technologies continue to advance.
Distinctive AI Procurement Challenges
AI systems evolve, produce probabilistic outputs and involve opaque models, creating risks such as hallucinations, bias and regulatory uncertainty that require unique contractual provisions.
Risk allocation and responsibility
Contracts address liability for data quality, output accuracy, governance and compliance, with suppliers seeking to limit responsibility for unpredictable AI behaviour and customers seeking operational accountability.
Service level agreements (SLAs) for AI
SLAs include traditional metrics like uptime but must also cover AI-specific measures, including accuracy thresholds, hallucination rates, bias metrics and model drift monitoring with human oversight.
Data rights and governance
Contracts define ownership and usage rights for input and output data, regulate the use of training data, address confidentiality and cross-border transfers, and ensure compliance with data protection laws like the UK GDPR.
Intellectual property issues
Procurement arrangements addresses ownership of AI-generated outputs, licensing, lawful use of training data, rights relating to custom models and fine-tuning and risks related to open-source software compliance.
Compliance warranties and indemnities
Suppliers provide warranties on regulatory compliance but often limit accuracy guarantees. Indemnities cover intellectual property infringement, data breaches and cybersecurity incidents with negotiated scope and liability limits.
Audit rights and governance
Customers seek audit rights for governance, compliance and technical reviews, balanced against suppliers' confidentiality and intellectual property protections, with enhanced requirements applying in regulated sectors.
Exit and portability provisions
Contracts mitigate vendor lock-in by including transition assistance, data and model portability, and termination rights for compliance or ethical concerns, while addressing challenges arising from proprietary APIs and cloud dependencies.
Liability and insurance considerations
Negotiations cover liability caps, exclusions and the allocation of regulatory risks, particularly in high-risk AI use cases. These arrangements are increasingly supported by emerging AI-specific insurance products that assess governance and cybersecurity controls.
AI Supply Chains and Accountability
AI supply chains involve multiple parties contributing to the development, deployment and operation of AI systems, creating complex accountability challenges. Organisations face growing regulatory and contractual obligations to ensure compliance, transparency and effective risk management across the AI lifecycle.
Due Diligence in AI Procurement
Organisations must conduct thorough due diligence regarding legal compliance, technical reliability, cybersecurity, data governance, fairness, explainability and operational resilience, given the evolving and probabilistic nature of AI systems. Sector-specific regulations further increase these expectations.
Assessing Upstream Provider Compliance
Evaluations focus on data protection, intellectual property, cybersecurity, sanctions compliance and sector-specific rules. Foundation models pose particular challenges due to their proprietary data and architectures, creating tensions between transparency and confidentiality.
Liability for Third-Party AI Components
Fragmented AI systems raise complex liability issues relating to harmful outputs, regulatory breaches and intellectual property violations. Downstream deployers remain responsible under various laws, regardless of third-party involvement.
Documentation and Transparency
Maintaining detailed records of model design, data sources, testing, bias, security measures and oversight processes is critical for governance, regulatory compliance, auditing and public-sector transparency. These requirements must be balanced against intellectual property and cybersecurity concerns.
AI System Provenance and Traceability
Tracking dataset origins, model lineage, training history and system modifications supports accountability, incident investigation, regulatory compliance and cybersecurity. Generative AI introduces has also increased the importance of watermarking and authenticity verification.
Contractual Cascading Obligations
Contracts increasingly include flow-down clauses requiring suppliers to impose equivalent compliance obligations on subcontractors. These obligations commonly cover data protection, cybersecurity, audit rights, indemnities and termination rights.
Emerging EU AI Act Value Chain Rules
The EU AI Act imposes extensive obligations on providers, deployers and other actors, including requirements relating to risk management, documentation, transparency, human oversight and cybersecurity. These obligations are influencing UK organisations that operate in Europe.
Emerging Trends in AI Governance
There is growing emphasis on AI assurance, independent auditing, operational resilience, cybersecurity, national security concerns and increased regulatory coordination across multiple domains.
These are discussed in 1.1 General Legal Background (the closing employment-law paragraph concerning the Equality Act 2010 and AI recruitment tools) and 12.1 Algorithmic Bias and Fairness (bias and vendor liability). The same discrimination protections apply to AI-assisted dismissal decisions. Where a significant dismissal decision is based solely on automated processing, the employee must be provided with information about the decision and be able to make representations, obtain human intervention and contest the decision.
In practice, most large organisations use some type of CV scanning software, either their own or embedded in vendor’s products. This use of AI must be carefully monitored and managed given the risk of decisions having an important effect on human life being taken or supported by autonomous systems.
Discussed in 4.1 Precedent-Setting Judicial Decisions (Employment Law and Algorithmic Management – Uber BV v Aslam); see also 12.2 Biometric Technologies and Emotion Recognition (workplace biometrics) and 12.4 Transparency and Disclosure (explainability in employment).
Discussed in 1.1 General Legal Background (Online Safety Act platform duties) and in 5.3 Enforcement Actions (CMA and consumer enforcement) and 18.1 Emerging Antitrust Issues in AI (platform-market competition and foundation-model concentration).
Artificial intelligence is increasingly integrated into UK financial services, affecting areas such as trading, lending, insurance, fraud detection, compliance, cybersecurity and operations. Once again, the regulatory approach is principles-based, relying on existing financial and data protection laws without standalone AI legislation.
AI Applications in Financial Services
AI technologies like machine learning, natural language processing and generative AI support functions including algorithmic trading, fraud detection, credit risk modelling, robo-advice, cybersecurity and compliance monitoring. Generative AI is increasingly used in coding, communications and workflow automation.
Algorithmic Trading Regulation
Algorithmic trading is governed by FCA rules, market abuse laws, MiFID controls and operational resilience requirements, mandating the development of robust systems, controls, kill switches, testing, monitoring and governance with clear algorithm ownership and documentation.
Market Abuse and Emerging Risks
AI-driven trading must comply with market abuse and insider dealing prohibitions; firms are accountable for manipulative conduct and algorithm failures. Regulators focus on autonomous trading, model opacity, systemic risks and third-party dependencies.
AI in Credit Decisioning
AI supports credit scoring, affordability checks, fraud detection, pricing, collections and underwriting, subject to FCA consumer protection, Consumer Duty, UK GDPR, equality laws and fairness, transparency and explainability requirements.
Bias and Explainability Concerns
AI credit models pose risks of discrimination and bias; regulators expect bias testing, fairness assessments, monitoring and governance. Firms must ensure AI decisions are explainable and transparent, avoiding opaque “black box” systems.
Model Risk Management
The PRA’s SS1/23 applies to AI and machine learning models and requires inventories, validation, governance, testing, documentation, change management and board oversight throughout the model lifecycle. Generative AI risks include hallucinations, data leakage, and cybersecurity vulnerabilities, necessitating safeguards and human oversight.
AI Governance Expectations
UK regulators expect firms to apply existing governance, resilience, conduct and risk frameworks to AI, with senior management accountability under SM&CR. AI governance committees, policies, risk assessments and audit frameworks have become increasingly common. Third-party risks from cloud and foundation-model vendors are closely scrutinised.
Data and Consumer Protection
Financial firms must comply with the UK GDPR, the Data Protection Act and confidentiality rules, ensuring lawful data processing, data minimisation, profiling transparency and rights regarding automated decisions. The FCA Consumer Duty mandates good outcomes, harm avoidance and clear communication, prohibiting exploitation or unfair AI outcomes.
Emerging Issues and International Coordination
Use of foundation models and generative AI raises concerns about hallucinations, misinformation, confidentiality and overreliance. Regulators focus on concentration risks from large tech providers and promote AI assurance, auditing and international regulatory cooperation.
Discussed in 7.1 Government Use of AI (Healthcare AI Applications) and in 2.1 Industry Use.
Autonomous vehicles are a clear example of AI embedded in a physical product, to which the product liability regime discussed in 1.1 General Legal Background may apply. They are also subject to bespoke motor-insurance and regulatory legislation. Under Section 2 of the Automated and Electric Vehicles Act 2018, an insurer has first-instance liability where an accident is caused by an insured automated vehicle driving itself on a road or other public place in Great Britain, subject to provisions concerning contributory negligence, unauthorised software alterations and failures to install safety-critical updates.
The Automated Vehicles Act 2024 establishes a wider framework under which vehicles may be authorised as self-driving; each authorised vehicle must have an authorised self-driving entity responsible for how it drives, and “no-user-in-charge” journeys must be overseen by a licensed operator. A human “user-in-charge” will generally be immune from offences arising from the manner in which the vehicle drives while an authorised self-driving feature is engaged, subject to statutory exceptions. Most of this framework is not yet fully in force: limited provisions commenced on 1 January 2026 and full implementation is expected in the second half of 2027. In the interim, the automated passenger services permitting scheme has opened for pilot deployments, with the government stating that passengers could begin booking taxi- and bus-style services during 2026.
The use of AI in retail and consumer spaces is discussed in 5.3 Enforcement Actions (consumer protection, “AI washing”, age-appropriate design code) and in 12.4 Transparency and Disclosure (manipulative AI, dark patterns).
Industrial robotics is another area in which AI may be embedded in physical machinery, so the product liability principles discussed in 1.1 General Legal Background may apply; industrial applications of machine learning are also noted in 2.1 Industry Use. The UK has no standalone robotics or industrial-AI statute. Workplace use is governed principally by the Health and Safety at Work etc. Act 1974 and the Provision and Use of Work Equipment Regulations 1998, under which work equipment must be suitable, maintained in a safe condition and used by appropriately informed and trained personnel.
Machinery placed on the Great Britain market must comply with the Supply of Machinery (Safety) Regulations 2008. Manufacturers supplying the EU market will additionally need to comply with Regulation (EU) 2023/1230 from 20 January 2027. That Regulation specifically addresses machinery control systems with fully or partially self-evolving behaviour. Under the EU AI Act, an AI system used as a safety component of machinery is classified as high-risk where the machinery falls within the relevant product legislation and is subject to third-party conformity assessment. Industrial robot safety is also shaped by ISO 10218-1:2025 and ISO 10218-2:2025, which incorporate material from ISO/TS 15066 on collaborative robots; ISO/TS 15066 nevertheless remains current and is under revision.
Patent Protection Criteria
AI inventions may be patented if they demonstrate novelty, inventive step, industrial applicability and technical contribution beyond abstract algorithms, but pure algorithms and mathematical methods are excluded. Patentable AI applications include diagnostics, automation and cybersecurity tools. Inventors, as discussed above, must be natural persons, excluding AI as inventors.
Copyright for Software and Data
AI software code is protected as literary works, including source code and documentation. Datasets may receive copyright, database rights or confidentiality protection based on originality and investment. Use of copyrighted materials in AI training raises legal disputes over unauthorised copying and licensing.
Trade Secrets for Models
Model weights, training methodologies and proprietary data are often protected as trade secrets under common law.
Database Rights
The UK grants sui generis database rights for substantial investment in data collection and verification, protecting against extraction and reuse of substantial parts of databases but not the underlying data itself.
Contractual IP Allocation
Contracts are crucial in AI development involving multiple parties, as they can define ownership, licensing and liability. Issues include rights in outputs, prompts, fine-tuned models and joint development risks requiring clear assignment from employees and contractors.
IP in Inputs and Outputs
Ownership of prompts and AI-generated outputs is legally complex. UK law recognises “computer-generated works” but generally requires human authorship for originality. Provider terms often govern user rights and reuse of outputs, influencing commercial risks.
Impact of Provider Terms
AI service agreements shape IP rights, permitted uses, liability and training permissions. Enterprise customers negotiate confidentiality provisions, opt-outs from training and ownership assurances amid dependencies on cloud providers and APIs.
Infringement Risks
Legal challenges include copyright and database rights infringement in training data, reproduction of copyrighted or confidential material in outputs, trade secret misappropriation and risks from synthetic media affecting personality rights and passing off. Cross-border issues complicate enforcement.
Emerging Trends
Licensing markets for AI assets are growing alongside regulatory scrutiny of foundation models, with a focus on transparency and copyright compliance. Organisations maintain provenance and audit trails, while international developments influence UK IP practices.
Discussed in 4.1 Precedent-Setting Judicial Decisions (Thaler v Comptroller-General (DABUS) (AI-generated works and copyright authorship) and in 16.1 IP Protection for AI Assets.
Discussed in 3.6 Data, Information or Content Laws (TDM exceptions, web scraping) and in 4.1 Precedent-Setting Judicial Decisions (Getty Images v Stability AI).
Discussed in 4.1 Precedent-Setting Judicial Decisions (AI-generated works and copyright authorship – Section 9(3) CDPA computer-generated works, SAS Institute) and in 16.1 IP Protection for AI Assets (IP in Inputs and Outputs).
Foundation models and open-source AI in the UK present unique intellectual property (IP) challenges that differ from those that arise in relation to traditional software. They involve complex issues of ownership, licensing, derivative works and compliance within existing IP laws.
Licensing Categories
AI models in the UK include proprietary foundation models with restricted API access and usage rights, open-weight models that share weights but impose commercial or modification restrictions, and open-source AI systems that allow modification and redistribution but faces legal uncertainties due to the nature of models and datasets.
API Versus Self-Hosting
API-based access limits user control and protects proprietary models through contractual governance, while self-hosted models offer greater customisation and control but at the same time increase compliance and security risks.
Derivative Works and Fine-Tuning
Fine-tuning raises unresolved legal questions about whether resulting models are derivative works or independent, with competing rights among developers, fine-tuners and data contributors often regulated by contractual terms.
Open-source Licensing Challenges
Traditional open-source licences focus on code and may not adequately cover model weights, datasets or outputs, which has led to the development of AI-specific licences with ethical and commercial use restrictions. Their enforceability remains uncertain.
Commercial Use Risks
Deploying AI commercially gives rise to risks of copyright and database rights infringement in training data and outputs, potential open-source licence contamination and heightened concerns in regulated sectors such as finance and healthcare.
Provider Terms Compliance
Foundation-model providers achieve enforcement through terms of service that restrict commercial deployment, fine-tuning, reverse engineering and may also terminate access for violations.
Model Merging and Distillation
Combining or distilling models raises legal issues in relation to derivative works, licensing conflicts, copyright infringement, trade secret violations and contractual breaches, with providers increasingly prohibiting competitive distillation and extraction.
Emerging Governance Trends
Regulatory focus is growing on transparency, data provenance and accountability for foundation models, alongside evolving AI licensing markets and international regulatory influences shaping UK practices.
Summary of IP Challenges
The landscape involves a complex interplay of licensing types, deployment restrictions, ownership of modified models, enforceability of AI-specific licences, infringement risks, provider compliance and legal questions around model modification techniques. It is clear, therefore, that there is ongoing uncertainty within IP frameworks.
Discussed in section 3.6, under “AI-specific Data Processing Rules”, “Web Scraping Legality” and “Synthetic Data Frameworks”, and in section 5.3 under “Data Protection Enforcement Highlights” in relation to the Clearview AI enforcement action.
Discussed in 3.6 Data, Information or Content Laws (the DUAA 2025 automated-decision safeguards: transparency, representations, human intervention, contestability) and in 12.4 Transparency and Disclosure (“Explainability requirements” – the UK GDPR right to meaningful information).
DPIA Requirements for AI
High-risk AI systems often require Data Protection Impact Assessments (DPIAs) due to large-scale personal data processing and automated decision-making, focusing on risks, bias, security and explainability. DPIAs should be reviewed and updated on an ongoing basis as AI systems evolve.
Privacy by design
UK GDPR mandates data protection by design and default throughout AI development, emphasising minimisation, transparency, security and fairness. Techniques like synthetic data and federated learning help balance AI optimisation and privacy.
Processor and controller roles
AI supply chains involve complex relationships among developers, cloud providers and others, raising challenges in defining data controllers and processors.
Cross-border data transfers
AI systems often involve multinational data and cloud infrastructure, requiring compliance with UK GDPR transfer restrictions including adequacy and contractual safeguards, especially when using US-based providers.
Generative AI risks
Generative AI raises concerns about memorisation of personal data, data leakage and hallucinated information, necessitating prompt filtering, access controls and output moderation.
Special protections
Additional safeguards apply when processing children’s data or data within sensitive sectors such as healthcare and finance, with an emphasis on profiling and behavioural manipulation risks under the ICO’s Age Appropriate Design Code.
Emerging governance challenges
Transparency about training data, explainability, synthetic data risks and AI assurance frameworks are increasingly important as foundation models and large-scale scraping grow.
Regulatory focus
The ICO stresses fairness, transparency, lawful basis and accountability in AI, with increased scrutiny of generative AI and alignment with international AI governance standards. Organisations must document processing and maintain vendor oversight.
Competition and antitrust issues related to AI markets in the UK have become a central focus for regulators, particularly the Competition and Markets Authority (CMA). Existing UK competition laws apply fully to AI markets, where concerns about market concentration, barriers to entry and vertical integration are prominent.
Merger Control Scrutiny
The CMA closely examines acquisitions, investments and partnerships involving AI startups, including “acqui-hires”, to prevent dominant firms from neutralising competition or consolidating scarce AI expertise. The Microsoft/OpenAI relationship was notably investigated for potential competition concerns.
Algorithmic Collusion Risks
AI systems may facilitate tacit collusion and price coordination through real-time monitoring and dynamic pricing, raising legal questions about liability and intent under the Competition Act 1998. The CMA continually stresses that companies remain responsible for algorithmic pricing decisions.
Abuse of Dominance Through Data and Infrastructure
Dominant firms may leverage proprietary data, cloud infrastructure and essential AI resources like GPUs to strengthen market power, potentially engaging in discriminatory access, exclusionary conduct or self-preferencing. The CMA highlights concentration in cloud services and vertical integration risks.
Vertical Integration Concerns
AI ecosystems often span foundation models, cloud infrastructure and software platforms, creating foreclosure risks and barriers to entry. Dependence on hyperscale cloud providers and exclusive infrastructure deals may lock startups into proprietary systems.
Exclusive Dealing and Tying
Exclusive cloud arrangements and tying of AI tools to dominant platforms may disadvantage competitors, reduce interoperability and increase ecosystem lock-in. The CMA champions openness, interoperability and user choice.
Foundation Model Market Dynamics
These markets involve high capital and compute requirements, scarce expertise and dataset access, all of which often lead to concentration and gatekeeper control. The CMA advocates accountability, access, diversity and transparency to address such risks.
Regulatory Investigations
The CMA has conducted extensive reviews of foundation models, cloud infrastructure and strategic partnerships (eg, Microsoft/OpenAI), demonstrating increased scrutiny of AI ecosystem power. International cooperation on AI competition issues is growing.
Emerging Regulatory Trends
Preventative regulation aims to address ecosystem power, infrastructure dependencies and network effects before market entrenchment. AI competition concerns increasingly intersect with digital platform and data governance regulations.
Artificial intelligence systems in the UK are subject to existing cybersecurity laws that address their integration and vulnerabilities across multiple sectors. These laws encompass data protection, operational resilience and sector-specific regulations, emphasising secure AI governance and risk management.
Cybersecurity Laws Apply Broadly
As set out above, UK legislation such as the UK GDPR, the Data Protection Act 2018 and the NIS Regulations govern AI systems in much the same way as other digital systems, imposing obligations related to information security, incident response and supply-chain security.
Data Protection Requirements
AI systems processing personal data must implement technical and organisational safeguards including encryption, access controls and monitoring to comply with the UK GDPR.
Enhanced Obligations for Critical Services
AI supporting essential services like healthcare, energy and transportation faces stricter cybersecurity rules under the NIS Regulations (which are likely to be updated by the Cyber Security and Resilience (Network and Information Systems) Bill) and operational resilience frameworks in financial sectors.
Threats From Adversarial Attacks
AI systems are vulnerable to attacks such as adversarial inputs, data poisoning, model extraction and prompt injection, which can cause misclassification, biased outputs or intellectual property infringement. Organisations are expected to test for and monitor these vulnerabilities.
Secure AI Development Lifecycle
Secure-by-design principles guide AI development, requiring authentication, encryption, audit logging, secure coding, validation and continuous monitoring to mitigate risks including those from generative AI and AI-assisted coding.
Incident Reporting Obligations
Organisations must report AI-related data breaches and operational incidents under UK GDPR, NIS Regulations and financial regulations, with frameworks addressing escalation, forensic investigation and regulatory communication.
Supply Chain Security Risks
AI supply chains involve foundation models, cloud providers and open-source components, creating risks of upstream compromise and malicious dependencies. Due diligence, contractual safeguards and national security considerations are increasingly emphasised by regulators.
AI for Cybersecurity Defence
AI is used for threat detection, anomaly monitoring and incident response, enhancing capabilities but simultaneously raising legal concerns about privacy, false positives, automated decisions and dual-use offensive AI. Robust oversight and governance controls are therefore necessary.
Regulatory Trends and International Alignment
UK regulators and the National Cyber Security Centre promote secure AI development, resilience testing and governance frameworks, aligning with international standards and focusing on foundation model security and systemic cyber risks.
AI raises critical environmental, social and governance (ESG) issues in the UK, affecting sectors like finance, healthcare and public administration. Despite lacking a bespoke and discrete AI ESG regime, UK regulations and international frameworks increasingly influence AI-related ESG obligations.
Environmental Impact of AI
AI systems consume substantial energy in training and operations, leading to concerns about greenhouse gas emissions, water use and e-waste. Companies disclose AI-related emissions under frameworks such as Streamlined Energy and Carbon Reporting (SECR) and Sustainability Disclosure Requirements, while pursuing efficiency and renewable energy solutions. Supply chains, including cloud and hardware providers, face environmental scrutiny.
Social Dimensions of AI
AI use also raises potential issues of fairness, bias and discrimination, especially in high-risk areas like recruitment and policing. There are also workforce impacts such as job displacement and surveillance concerns, which prompt initiatives for retraining and responsible automation. Human rights and misinformation risks also inevitably factor into social responsibility assessments.
Governance Challenges
AI governance is increasingly a board-level priority involving dedicated ethics boards and risk oversight. Areas of focus include fairness, accountability, transparency and security. Governance requirements extend to third-party vendors through due diligence expectations and contractual safeguards. Specifically, the UK Corporate Governance Code (paras, 142-150) guides expectations regarding internal controls and risk management.
ESG Due Diligence in AI Investments
Investors and procurement teams assess AI vendors on, inter alia, their environmental footprint, social practices and governance controls. Contracts often include compliance warranties and ESG commitments to manage risks such as litigation and cybersecurity vulnerabilities.
Regulatory Disclosure Requirements
The UK has no standalone AI ESG disclosure regime, but AI-related obligations arise through a mosaic of other duties, such as climate and sustainability reporting, corporate governance and data protection laws. In the contemporary environment, investor pressure drives transparency and responsible AI governance.
Emerging Trends
Policymakers focus on AI infrastructure sustainability and energy grid impacts. Responsible and trustworthy AI innovation is the aspiration, alongside a growing use of auditing, assurance and certification frameworks. AI governance is increasingly integrated into enterprise risk and sustainability strategies.
Key Environmental Concerns
These include AI’s energy consumption, carbon emissions, data-centre sustainability and infrastructure intensity, all of which are central to UK ESG considerations.
Key Social and Governance Concerns
Algorithmic bias, workforce effects, surveillance, misinformation, accountability, transparency, board oversight and supply chain governance form major challenges for responsible AI deployment in the UK.
AI governance in the UK comprises a multifaceted framework addressing legal, operational and ethical challenges.
Governance Structures Importance
UK organisations establish formal AI governance with board-level oversight, ethics committees and cross-functional risk management to ensure accountability and strategic coordination.
AI Risk Management Frameworks
Dedicated frameworks assess risks relating to privacy, cybersecurity, bias and operational resilience, often integrating AI risk into enterprise risk and compliance systems aligned with international standards.
Lifecycle Governance
AI governance covers design, development, testing, deployment, monitoring and retirement stages, emphasising lawful basis, fairness, explainability and security throughout the AI lifecycle.
Integration with Existing Governance
AI governance is embedded into existing risk, cybersecurity, procurement and compliance frameworks, intersecting with UK GDPR, financial services regulations and ESG governance.
AI Inventory and Classification
Maintaining inventories and classifying AI systems by risk, data sensitivity and operational impact supports accountability and enhanced governance for high-risk applications such as facial recognition and healthcare AI.
Impact Assessments and Documentation
Organisations conduct Data Protection Impact Assessments (DPIAs), fairness and ethical assessments while documenting governance records, model cards and audit trails to support explainability and regulatory compliance.
Third-party AI Governance
Due diligence and contractual governance address risks from AI supply chains involving cloud providers and vendors, focusing on cybersecurity, fairness and operational resilience.
Incident Response
AI-specific incidents, such as hallucinations and adversarial attacks, are managed through integrated internal incident response frameworks incorporating escalation, remediation and regulatory reporting procedures.
Proportionate Governance
Governance levels are tailored based on AI system risk, with lighter controls for low-risk systems and enhanced oversight for high-risk AI to balance innovation and compliance.
Practical Implementation Challenges
Rapid AI evolution, a lack of standardisation, explainability issues, resource constraints, third-party dependencies and cross-border compliance requirements complicate governance efforts, especially in relation to generative AI.
78 Cannon Street
London
EC4N 6AF
UK
020 7367 3000
www.cms.law/en/gbr/