Joint Committee on Human Rights
Uncorrected oral evidence: Human rights and the regulation of AI, HC 1262
Wednesday 4 February 2026
2.20 pm
Watch the meeting
Members present: Lord Alton of Liverpool (Chair); Juliet Campbell; Baroness Chakrabarti; Tom Gordon; Lord Murray of Blidworth; Alex Sobel; Peter Swallow; Sir Desmond Swayne.
Questions 75 - 88
Witnesses
I: Andrew Breeze, Director for Online Safety Technology Policy, Ofcom; William Malcolm, Executive Director of Regulatory Risk & Innovation, ICO; Dr Mary-Ann Stephenson, Chair, EHRC.
USE OF THE TRANSCRIPT
21
Examination of witnesses
Andrew Breeze, William Malcolm and Dr Mary-Ann Stephenson.
Q75 Chair: It is my privilege to welcome you today to the 44th meeting of the Joint Committee on Human Rights. I have to begin today with the sad news that Lord Wallace of Tankerness KC, died suddenly last week during complications following surgery. He had just been appointed a member of the Joint Committee. Jim was personally a friend, and a colleague who worked in the Scottish Parliament, in the House of Commons, and here in the House of Lords. Yesterday, tributes were paid to him. If you want to know about a virtuous person who gave his whole life to the pursuit of justice, the upholding of democracy and the rule of law, then I would simply commend to you the Hansard from yesterday to read tributes that came from all sides of the House. The committee members and members of the team have recorded our own condolences and sympathy, and I have written to Jim’s widow, Rosie, and to the family. He will be greatly missed.
Our meeting today will fall into two parts. During the first session, we are going to continue with our inquiry into artificial intelligence and human rights. During the second session, we will be taking the impact of new legislation on the human rights of Chagossians. For anyone who is joining us online or here in our packed public gallery today and is unfamiliar with our work, it is worth just mentioning that we are made up of Members of both Houses of Parliament. As the name of the committee implies, we explore the impact of public policy and legislation that is before Parliament on human rights. Many previous reports, our evidence, recommendations and follow-up correspondence with Ministers—some of which have been approved already during the private part of our proceedings—are available on our website.
Today is the fifth public session in the AI inquiry since the call for written evidence closed in September. The purpose of today’s hearing is to enable members to question three of the United Kingdom’s national regulators about their approach to artificial intelligence, how they are balancing their safety objectives with the new growth duty, and what challenges they face when seeking to regulate AI. It comes the day after 50 Members of the House of Commons wrote to the Secretary of State asking about the way these technologies can impact people, not least children.
The committee is pleased to welcome representatives, therefore, from the Equality and Human Rights Commission, the Information Commissioner’s Office and Ofcom, which all have remits that include AI, but none of which focuses exclusively on AI. I should also note that the committee is grateful to the Northern Ireland Human Rights Commissioner, who was before us only a week ago talking about the new legislation for Northern Ireland and has submitted helpful written evidence in relation to the Windsor Framework and how that might have relevance to what we are doing on AI.
Without further ado, I am going to move, if I may, to a curtain-raising question before we turn to the more granular detail, which will be explored by members of the committee. I would like to ask you to outline which matters relating to artificial intelligence fall within your scope as a regulator. Are there matters relating to AI that can cause harm, including human rights harms, that you encounter and directly relate to your competences that fall outside your regulatory framework? Dr Mary-Ann Stephenson, let me go to you first.
Dr Mary-Ann Stephenson: As you know, the Equality and Human Rights Commission is the equality regulator for Great Britain, and the national human rights institution for England and Wales and for reserved matters in Scotland; the Scottish Human Rights Commission is responsible for devolved matters in Scotland. We have a very wide remit covering both the Human Rights Act and the Equality Act. In terms of human rights, the issues that would be engaged are obviously issues around right to privacy, right to a fair trial, non-discrimination and right to freedom of association and assembly. I can go into more details about that probably in answers to later questions, rather than saying too much at this stage.
Chair: Thank you, Dr Stephenson, that is a very good start. Let us go to Mr Malcolm.
William Malcolm: As members of the committee will be aware, the UK Information Commissioner’s Office is a whole-economy regulator. Therefore, our remit extends to anywhere that personal data are processed in the AI supply chain, from model training at one end right through to personalised apps and services that one might download on one’s smartphone to monitor health data. Because of that, we need to look at the right parts of the ecosystem to scale our impact. We do that through our AI and biometrics strategy, but of course, the general data protection regulation is a principles-based piece of legislation. It is technology neutral, so really our application is across the whole sector. On the harms point, to the extent that those harms relate to the processing of personal data, then clearly we have the powers that we need to tackle that.
Chair: Mr Breeze, as we go to you, can you also explore this point about whether there are things that none of you have any responsibility for and that can fall through the gaps?
Andrew Breeze: Certainly. Thank you. In contrast to my fellow panellists, Ofcom is a sectoral regulator rather than a whole-economy regulator. We are a converged communications regulator. I often think that most people have a particular sector that first springs to mind when they think of Ofcom: it might be post, it might be broadcasting, it might be online safety. You can almost look at Ofcom from different angles and see a different face of it. The commonality is that in all these sectors, we are tech neutral in the regulation that we do. Our powers to regulate AI are really at the deployment and use-case level, to the extent that they fall within the sectors that we have been given powers by Parliament to regulate.
Nothing immediately springs to mind in the sense of something that none of us regulates, particularly given the cross-economy nature of my fellow panellists. Something we have experienced as a sectoral regulator is that with the rapid development of AI deployment, you can end up with these edge cases, which are either in the fuzzy, grey edge of the perimeter of what we do or, on further investigation, outside. The Secretary of State and our chief executive have recently spoken about AI chatbots and AI image generators—some new activities that do not fall squarely within the online safety regulation remit that is a big part of my job.
Chair: Do you regularly talk to one another?
Andrew Breeze: We certainly very regularly talk to the Information Commission. We are lucky to share an office with it. We are also fellow members of the DRCF, and we have bilateral conversations. We also talk to the EHRC. Through the DRCF we did a one-off project on fairness in AI. I would say we have different intensities of relationship, but we certainly talk to each other a lot.
Chair: A very helpful introduction, thank you. Let us go to Sir Desmond Swayne and after that we will hear from Baroness Chakrabarti.
Q76 Sir Desmond Swayne: How difficult is it to regulate in this area of AI, and what might make it easier? For example, do you need more resources? Do you need greater technical expertise? Do you need more statutory powers, more guidance, more clarity? Let us move from left to right.
Andrew Breeze: I will take that first. The biggest challenge that we face is the pace of change. As we all know, legislation and regulation take time. The speed with which AI is developing—particularly the products, for us as a use-case level regulator—is extremely fast. Keeping pace with that is certainly a challenge. It is a challenge that we are resourced to meet. We have really focused on hiring technologists. We have around 100 tech experts and around 60 AI and machine learning experts in-house, but there is no denying that there are certainly challenges there.
Dr Mary-Ann Stephenson: I would very much agree on the pace of change and the speed of regulation. For example, live facial recognition technology was first used in 2016, and we are only now getting the Government to look into regulating it. That is a real issue. For us at the EHRC, one of the biggest issues is capacity and resources. In 2012, our budget was set at £17.1 million, which was then the minimum required for us to perform our statutory functions. Since then, our budget has remained frozen at £17.1 million, apart from the coming financial year, when we are expecting a small cost of living increase. That is a 35% cut over the last 10 years.
We have also taken on additional responsibilities around, for example, gender pay gap reporting. If we had more resources, there is a great deal more that we would like to do in this area. The lack of resources is a significant problem for us.
William Malcolm: I would echo the comments that have already been made on the pace of technological change. As a whole-economy regulator, I might layer on the fact that we are looking at different markets and the effect that technology has on different market verticals, as well as on consumers and users of technology. This is all coming at consumers and users of technology fast, so making sure that we are looking clearly at what that evidence base is telling us and investing in training and education is super important.
From an ICO perspective, we can always use more to do more, but we work within the envelope we have. Particularly on something like AI, which is across the whole economy, it is our job to prioritise our resources in areas where we can have the most impact, both in enforcement and upstream regulation. That is something we very much focus on.
On the powers point, we have new powers coming in under the Data (Use and Access) Act. We will be able to require technical reports, and similar to Ofcom, compel witnesses for the first time. There are new powers coming online, which we will not hesitate to use in cases where the public need to be protected.
Sir Desmond Swayne: How are the ICO and Ofcom going to balance the need to regulate to protect us from potential harms of AI with the requirement to prioritise growth?
William Malcolm: I can maybe start on that. The ICO has a lot of experience in running regulatory sandboxes. We have been running those for five years, and we are doubling down on those efforts. We run an innovation advice service where we can get quick answers to start-ups and entrepreneurs, and we are looking at how we can roll out better resources and data essentials to SMEs. All these things are vital. We believe in the importance of upstream intervention, working with providers of technology to catch technology as it is adapted and built, to get that privacy by design and default at the front end.
There is a whole new range of questions around that for AI, but we also do not hesitate to use our powers where we feel there is harm and where the public need to be protected. It is both encouraging the adoption at pace, including the roadblocks to adoption at pace, so that society and the public get the benefits of AI, but by the same token, signalling clearly where we think there are harms. The two things do not need to be in tension, and we can achieve both if we deploy our resources in the right way.
Chair: You can pick up some of these points later as well. If we run out of time, we are always open to written comments as well, which can be included. I want, if I may, to turn to Baroness Chakrabarti, and after that to Juliet Campbell, Member of Parliament.
Q77 Baroness Chakrabarti: This is a natural follow-up to Sir Desmond’s questions. The committee has received a high volume of evidence suggesting that an AI-specific regulator or oversight body would be beneficial. For my own part, for what it is worth, I see a direct analogy with pharmaceuticals: big business, lots of jobs, capable of doing enormous good for so many people, but equally capable of doing a lot of damage. We would not dream of not having a specific medicines regulator in this country—or in any developed country—given the problems that I have raised, would we? Even though there might be privacy issues and general human rights issues, we would not dream of not having a medicines regulator. I wonder what you think about that.
Andrew Breeze: I will take that first. It is a really interesting point and an important debate to be had, and we are having it. My starting point, in thinking about AI, is to remember the ChatGPT moment: there was this festival of people trying to come up with their analogies. Is it the new fire? Is it the new electricity? That is at the core of this question, really. Is it a general-purpose technology of the type that we do not typically regulate as directly, but that we delegate to sectors where we think its impacts are particularly acute? Or is it a this-time-is-different situation? Is the closer analogy something like pharmaceuticals, which means that you need something more specific?
From our point of view, we feel that we have a good grasp of the things that are happening in our sectors. If there were a co-ordinating body, we would be keen for it delegate to us where something was in our expertise, and then where there was convergence around, for example, whether it is a companion chatbot or a therapy chatbot. Those kinds of issues would need to be teased out, but it is a very live debate and one that we talk to Government about.
Dr Mary-Ann Stephenson: I similarly agree that this is a live debate. It is also important to recognise that AI is not one thing. You have everything from very specific tools like live facial recognition technology, up to general-purpose models—ChatGPT, Grok and things like that. All the existing regulators are actively working within their remit on these different issues. The first thing Government should do is to ensure that existing regulators are sufficiently funded and funded to be able to work together. There may be areas where there are gaps. There are certainly areas that are less well regulated than others. For example, healthcare is well regulated so, with our concern about equality and human rights, we can work with regulators in the healthcare system to ensure that they are thinking about these issues in relation to AI.
Other areas are less well regulated, such as the social security system, where we have seen HMRC use it to try to tackle false claims of child benefit from people who have left the country. In 63% of those cases, people had not actually permanently left the country. There were problems with the data because they might have come back over the land border from the Republic of Ireland to Northern Ireland, for example, or they had not actually flown. In those areas, you might need some additional regulation or support. The Government need to support the regulators to work together, to ensure we are all able to work together and to respond swiftly where we identify gaps, because this is a fast-moving area.
Baroness Chakrabarti: Am I right that, with your current remit and powers, none of you has the ability to give or refuse prior approval for a new AI product?
Dr Mary-Ann Stephenson: We do not.
William Malcolm: We do not have a prior approval regime. Where processing is higher risk, there is a requirement to consult with us on that high-risk processing and mechanisms to enable that. But we have no veto as such.
Chair: You have gathered, though, that the committee is interested in the idea of a single regulator. If, after the hearing is over, you have further thoughts on that and you want to share them with us, we would be grateful. Let us go to Juliet Campbell, who is going to drill deeper into this area of regulation, and after that to Mr Alex Sobel.
Q78 Juliet Campbell: Would you outline for us what powers you have with regard to private actors who may violate human rights with their use of AI? How do these powers differ from the Equality Act and Human Rights Act?
Dr Mary-Ann Stephenson: The Human Rights Act applies to public bodies; it does not apply to private actors. The Equality Act applies to providers of services and employers, so it has a much wider scope. We have additional powers within the Equality Act. We have stronger powers for enforcement of the Equality Act than we do for the Human Rights Act. There are also additional powers within the Equality Act, particularly around the public sector equality duty.
However, the Human Rights Act is not the only way in which human rights are enforced in this country. Governments have a positive duty to protect and promote human rights, and successive Governments have done that in different areas through different forms of legislation and regulation. In a way, the Equality Act gives effect to protection from discrimination in the Human Rights Act; laws covering data protection can give effect to right to privacy; the role of Ofcom covers some rights around freedom of expression, for example, under Article 10. While the Human Rights Act itself does not cover private actors, there are other bits of legislation and regulation that do, which give effect to human rights.
Juliet Campbell: Do you think these powers are sufficient to prevent harm to human rights and equalities caused by AI?
Dr Mary-Ann Stephenson: It depends on the area. I would defer to both my colleagues here on whether they have sufficient powers on information, right to privacy and freedom of expression.
William Malcolm: Yes, we do have sufficient powers to intervene where we believe that fundamental basics are going awry, whether that is accountability or transparency to members of the public. We have those powers.
I would maybe back up and say that, at the core of data protection legislation, this concept of data protection by design and default is actually really powerful in an AI context. We spend a lot of time working with technology developers and providers, trying to get in at the ground floor to make sure that best practice is baked in up stream. That in itself—that ability to engage and work with developers and engineers at the start of the cycle—is one of the things we do that is most effective. But where things go wrong, we have the legal powers we need to intervene and to make sure that we get the information required to move forward.
Andrew Breeze: I can speak about the Online Safety Act, which is probably the clearest example of where these rights are woven through a piece of sectoral legislation that we administer. Page 1 of the Act describes the objectives of the Act to make people’s lives safer online in the UK. It also says that it seeks to ensure that companies that do that do it in a way that protects people’s rights to freedom of expression and privacy.
Bringing this back to AI, where those companies are using AI systems—whatever they may be—or where we, as a public authority, are recommending that they should, we and they have to take into account the extent that they involve potential impacts on people’s privacy or freedom of expression. You may have seen that one of the grounds that we are investigating X for in our investigation into Grok on X is whether it took people’s privacy rights properly into account.
Chair: We may want to ask you more about that in a moment. Mr Sobel will do that. Just to reinforce the point that Ms Campbell was making about the deepening of regulatory powers, we are very interested in the Council of Europe’s framework convention. Can you remind the committee when that was first promulgated and whether we have ratified it? If we were to ratify it, would that enhance the powers that you have? Perhaps you could answer quite briefly, Dr Stephenson.
Dr Mary-Ann Stephenson: It is yet to be ratified. I understand that the UK Government intend to ratify it. It is not additional; it is about bringing together existing human rights standards rather than bringing in new regulatory powers, as I understand it.
Andrew Breeze: I vaguely think from my reading that it was promulgated in 2024. As far as I understand, no one who signed it has yet ratified it. Similarly, my understanding is that it brings together frameworks and then gives a Government a relatively broad degree of discretion about how they will implement it.
William Malcolm: Just to add to that, we obviously engaged in the consultation for that fully and our understanding is the same. It would not materially change the ICO’s existing powers, although we would like to see any oversight body retain independence.
Q79 Alex Sobel: Mr Malcolm, in your view, to what extent does the current data protection framework protect consumers against novel and emerging harms posed by the increased use of AI? Are there any gaps? For example, under current laws, can foundation model developers be held to account for data breaches when personal data has been scraped from the internet or from other sources?
William Malcolm: Thank you for the question. Data protection law is technology neutral. It has stood the test of time as new technologies have emerged. It has proven that the core principles of data protection law, which in many respects map to human rights principles of transparency and accountability, have stood the test of time and been flexible as new technologies have evolved. In the case of AI, there are really powerful accountability requirements in data protection law to complete data protection impact assessments and legitimate interest assessments, and for regulated entities to show their homework and how they have balanced the rights to individuals. These are really important tools.
Having said that, any new area of technology identifies gaps and tensions. That is undoubtedly the case. There are questions about how you would, say, practically apply the right to deletion in an AI model, when a model cannot delete the data. One has to take a viewpoint about what types of blocks, safeguards and filters might give effect to those rights. There are questions of interpretation about principles of data minimisation, for example, in a world where one might argue that the more information the model has, the greater the fairness aspect, the tendency against bias et cetera.
The general answer is yes; the principles in the framework endure. It provides a good foundation to drive accountability through organisations. But there are areas where, as regulators, we need to work with organisations to see how the principles practically apply. There are also undoubtedly areas for Government to look at, in where some new tensions arise.
Alex Sobel: On that point, yesterday I signed a letter to Liz Kendall, led by Dame Anneliese Dodds. It concluded by saying, “Only by having regulation in place that ensures safety by design at launch can we truly prevent online harms at industrial scale”. Do you generally agree that we need safety by design inherently in the model?
William Malcolm: Privacy by design as a default, as the GDPR provides for, is absolutely foundational to the development and deployment of new technology. The public are entitled to expect that organisations are doing the hard work of thinking through product innovation that will achieve that objective. To be frank, we are leaving an era of platform and smartphone technology—where a lot of these questions around design and default were widely debated and where there was clarity about what the outcomes meant—to a new product development cycle, where companies have work to do to ensure that they are coming up with best practices and technologies that meet the standards that are set out in the legislation. That is why we engage up stream early to try to encourage that conversation.
Alex Sobel: Following up on that, your remit is restricted to the category of personal data. In practice, does this have any negative implications for your function and operations? Does limiting to only personal data impose too narrow a focus now, particularly with AI? What are the limits of UK GDPR, for example, in relation to data that is sensitive but falls outside that definition of personal data?
William Malcolm: The questions about regulation of models generally are legitimate questions. As I have articulated, our remit is very much about the protection of data, accountability around that and data protection rights. The combination of accountability documents across regulators, from risk assessments that would be conducted by regulated firms under Ofcom’s remit to data protection impact assessments under data protection, will give a coherent picture. But I would accept there are open questions around foundation models and the like, which I know the Government and others are considering.
Chair: Yes, if you go to the last point, it would be helpful.
Alex Sobel: I have a couple of quick points. We have heard about evidence of biometric technology being used to infer people’s inner emotional states, which we understand is very concerning for people. Is it regulated in the UK? Who regulates it? In January we also saw that there was a report on agentic AI. How will this new form of AI be likely to impact human rights, and how should organisations respond? How should your organisation respond?
William Malcolm: We published a Tech Futures report on agentic, which set out our thinking in this area. There are novel and new issues of data protection that need to be unpacked, both by us as a regulator and by regulated entities; for example, automated decision-making in the supply chain. It is quite often hard to see where in the supply chain the decision is taken, even whether the decision is taken within the UK or not. In the interests of time, I am happy to refer you to our written conclusions on that in the report, but there are novel issues there that need to be looked at.
Chair: I would certainly be interested in what you have to say about supply chains. We did a big report as a committee on that very issue last year. If there is a beneficial advantage in doing this, we would want to know about it.
William Malcolm: Yes, we certainly can follow up in writing in the interests of time. It is a rather lengthy document, so I will not run through it all now, but we will follow up in writing.
Chair: Let me go to Dr Swallow because he has a question for Mr Breeze, in particular. After that, we are going to hear from Tom Gordon, Member of Parliament.
Q80 Peter Swallow: Mr Breeze, we know, of course, that Ofcom is conducting a process at the moment looking into online harms connected to AI with a particular social media company. To what extent do the powers that exist under the Online Safety Act allow you to address a broad range of harms caused by AI-generated content? For example, would it give you the ability to step in where content is misleading or discriminatory, or is it only in the case of the most significant and serious harms that you would feel empowered to step in?
Andrew Breeze: I am trying to work out whether to answer the specific question first or the general one. I will start with the general question. The Act is structured around a number of concepts, but I will talk about two main concepts. There are the service types, which are user-to-user platforms, search platforms, and regulated pornography providers. That is question one, if you like, when you are assessing a situation: is it one of those three regulated provider types? There are then a series of harms, which, again, are set out in the legislation. Those are broadly structured around illegal content—some of which is given greater priority by the legislation than others—and then legal content that is harmful to children. There is a list of those things. That is your starting point for any kind of regulatory question of scope in this area.
On the question of misleading and discriminatory content, I would say it is to the extent that it rises to the level of criminal activity. In the case of misleading activity, if you think about something like misinformation or disinformation, one of the priority offences is the foreign interference offence. I cannot remember it off by heart, but you would have to run through the limbs of that offence to ask, “Is it being done by a foreign actor in order to influence improperly the British democratic process?” General, legal disinformation would not fall within our remit.
Peter Swallow: Directly by a foreign actor or on behalf of a foreign actor?
Andrew Breeze: I believe it can be on behalf of, but you have to trace it back.
Peter Swallow: That is a really important distinction, of course, with some content that we are seeing at the moment.
Andrew Breeze: It also is a practical challenge because you have to be able to trace it back to that foreign actor or at least have reasonable grounds to think that it is them. Similarly on discriminatory content, again, if that rises to the level of a crime, then it would be illegal content and caught by the illegal content duties. If it is of the type specified in the harmful to children definition, which, again, I do not have memorised, that is something that children would have to be protected from, but it would not necessarily have to be taken down in the way that illegal content does. Adults would still be able to see it.
Peter Swallow: Let us focus on that mis- and disinformation. There has been plenty of evidence of real-world consequences where AI-generated content has created genuine real-world harms because of the spread of mis- and disinformation. That might not have been the intention when originally shared, or it might not be possible to prove that intent, but that has been shown. Are you confident that Ofcom has sufficient powers to regulate that? If not Ofcom, do any organisations have that? Are social media companies and other platforms currently under sufficiently strong regulatory frameworks, to ensure that they are appropriately tackling this harmful content—I say “harmful content” in terms of its normative meaning—on their platforms?
Andrew Breeze: I will try to answer all three parts of that. I would say we do not have powers to regulate that content. Parliament explicitly decided at the time the Act was passed not to cover content that was harmful but legal, except to the extent that it harms children, and it is part of that definition. I am not aware of any organisation in the UK that regulates that, but the European Union’s counterpart to the Online Safety Act, the Digital Services Act, has a mis- and disinformation provision in it. As a result, because of the cross-border nature of a lot of these entities, some are taking action on mis- and disinformation in response to that European-level legislation. But within the UK, we explicitly do not have powers to do that.
Peter Swallow: Finally—again, I am not suggesting that you want to get into the flesh of the specific case—just this week we have seen action taken in France against a social media company by law enforcement. It was a very robust response to challenges, and of course I am not suggesting any wrongdoing, but we can see the action being taken there. To what extent in the UK context do you feel that we have the correct powers in place to actually enforce the Online Safety Act and other laws against big tech companies, particularly where those tech companies are based outside the UK?
Andrew Breeze: Yes, it is a great question. The French example highlights the fact that this is a community effort, both internationally and nationally. We work with various government departments, including the Home Office and its partners, to ensure that the different levers we have to pull as a collective community are being pulled. We also work with international regulators on that.
In terms of our enforcement powers, I would highlight that under the Online Safety Act we regulate big tech, but we also regulate much smaller and, in many cases, quite risky service providers. Our complete regulatory population is estimated at around 150,000. In the case of big tech, very often they are quite significant stakeholders in the UK. You have only to walk around King’s Cross to see how many people they employ and the size of their investment. We have certainly been encouraged by the response of industry to regulation. We use a supervisory approach where we think that that will drive the right outcome. At the same time, we have strong enforcement powers under the Act, with the ability to levy significant fines, and we are confident that those will be effective.
The case that you are talking about of people being based out of the jurisdiction is actually more acute in the case of those smaller, riskier players that are not such stakeholders in the economy and do not have that same incentive to secure market access. In those cases, we have our business disruption powers, where we can go to the court and ask for orders in relation to ISPs, for example, to restrict access to those service providers. Those are yet to be tested, but they are part of our toolkit.
Chair: I am conscious of the clock beating us. We have only 15 minutes or so to go, and there are other questions from colleagues. That was a very helpful reply. I am going to turn to Tom Gordon, Member of Parliament, and then we are going to hear from Lord Murray. It would be good if you could make your answers a bit shorter, but also if you then want to write to us to answer them, we would love to hear from you.
Q81 Tom Gordon: The questions I have are principally around the engagement with government. If we start with you first, Mr Malcolm, you mentioned the regulatory sandboxes in response to Sir Desmond earlier. I was just wondering whether you might be able to elaborate on those, the involvement you had with government in them being set up, and the process and situation around them. It is not really clear whether or not AI applications are tested to identify potential harms to human rights in these testing environments. I just wondered whether there was any more detail on that, and whether you are confident that this is the right approach, or whether you have any concerns or suggestions for improvements of those sandboxes.
William Malcolm: I would start with the operation of the ICO’s own sandbox, which is a single-regulator, single-issue sandbox. We have been operating it for five years. We have had success at getting to the core of issues and giving tech companies and organisations the feedback they need to progress product development and incorporate standards clearly. We are doing work at the moment with DSIT, having got funding from the Regulatory Innovation Office, to look at whether there is a way to expand experimentation within the sandbox, or to look at where powers might be given to regulators to take more flexibility around that, with different accountability and governance mechanisms.
Additionally, of course, the Government are doing their own growth lab consultation. Some of the issues there are interesting when you start looking at cross-issue, cross-regulatory sandboxes. Those have the potential to scale even greater impact. One of the criticisms that industry sometimes makes of sandboxes is that it wants answers to all the questions from each part of the ecosystem, so we want to very much support the work to look at how that can happen. Cohort models—where we have multiple companies looking at an issue in one sandbox—also hold promise.
There is more we can say. I will take Lord Alton’s invitation to write to you, but, in short, yes, they are working. There is more we can do to streamline them and make them faster and more effective. We very much welcome initiatives, which we are involved in too, to see how we can look at other solutions, from cohort models to cross-regulatory sandboxes, which hold potential for the future.
Tom Gordon: I would like an answer to this just very briefly from anyone else on the panel. We have heard quite a lot about the ways that respective organisations are dealing with the current challenges faced in relation to AI and human rights. Part of the conversation around this in the public domain is that it is largely quite reactive because of the nature of things moving so quickly. In terms of thinking ahead and that future need from government, it would be handy to know what conversations you are having. I know we touched on this a little earlier, but in terms of the resource and support, how is that balance working between trying to deal with the situation as it is now versus future planning?
Dr Mary-Ann Stephenson: One of the things the Government said in their response to the AI Opportunities Action Plan was that they would liaise with regulators on their future capacity needs ahead of the spending review; that was in February last year. That did not happen for us so we have not had that conversation. People will have heard me and my predecessors say on frequent occasions that our budget has been frozen for 10 years. It creates significant capacity constraints in terms of what we can do; we are raising it with the Government.
There are particular areas where we think we could do more if we had more funding, particularly around working with other regulators—the ICO and others—where we already have good relationships on equality and human rights, to ensure that all regulators in this space understand equality and human rights issues. We could look at areas where there is less regulation, for example, around social security or the use of AI in the criminal justice system. We could work to identify some positive benefits of AI and how those could be better taken advantage of through, for example, assistive technology for disabled people. Those are all areas where—we have raised this with the Government—we are keen to continue.
The Chair: We would be very interested to hear what more you could do and what it would cost. If you could write to us—
Dr Mary-Ann Stephenson: We can certainly write you about that.
Q82 Lord Murray of Blidworth: I am going to raise a perennial AI concern—one that we have seen be raised by Big Brother Watch and other organisations. It is the question of bias in AI. We know that it is a significant issue for underrepresented groups, and it can obviously lead to great unfairness. To what extent do your three organisations feel able to address the potential for bias in the application of AI, particularly in AI training data? Which of your three regulators is best placed to address this issue?
Dr Mary-Ann Stephenson: We have strong evidence-gathering powers. If we identify potentially discriminatory outcomes in the use of a system, we can interrogate the data the system is based on. The issue for us is less about powers—particularly under the Equality Act, if there is discrimination—and more about capacity. It is really important to recognise that there is bias both in the training data—or potential bias in the outcomes of the data—and in the way technologies can be used.
If you look at something like facial recognition technology, I am sure you are familiar with the Home Office report that came out in November 2025 that looked at the algorithm used for facial recognition on the police national database. That showed false positive matches up to 9.9%—nearly 10%—for black women. There were higher false positives for black people and higher false positives for women—then put them both together.
That is to do with the data, but there are also issues to do with where live facial recognition is actually used, which is not an issue with the AI so much as with its use. For example, we know that, in London, live facial recognition has been used much more in areas with higher minority-ethnic populations. Although it is really important to recognise that there are issues to do with AI specifically, there are also issues to do with policy decisions that are made and are separate from AI.
The Chair: You will be glad to know that members of the committee met the Biometrics Commissioner yesterday to talk about these exact questions; we are on the case as well. Thank you for pointing out the discrepancy.
William Malcolm: I would make two supplementary points. We have already issued guidance on how to address bias in AI, as part of our guidance suite on how to address fairness principles; I can point the committee to that in our written evidence. Also, the new powers that are coming online under the Data (Use and Access) Act, which I referenced earlier—they will give us the power to require technical reports to be produced by third parties and costs to be borne by the provider—will give us even deeper power in appropriate cases to look under the hood at how these models are being constructed, and how these systems are being tested, to ensure that the elimination of bias is clear.
One of the counterintuitive points—it relates back to the minimisation point I made before—is that, sometimes, the more you minimise the data, the more bias you create. There is a real need for us as a regulator to understand that trade-off intention, to make sure that the right amount of data is going into the model to get the right outcomes for individuals.
The Chair: Ms Campbell has a question. There will be an opportunity for you, Mr Breeze, to add to anything you wanted to say on the last question.
Q83 Juliet Campbell: This is for Mr Malcolm. We are looking here at transparency and its importance when personal data is used in AI processes. To what extent do you think the transparency requirements under UK law achieve this? In your view, can the public authorities satisfy transparency requirements just by using entry on the algorithmic transparency reporting standards?
William Malcolm: On the first part of the question, we are in a position where UK law provides the right standard. There is more for tech providers and companies to do in this space. The range of warnings one gets when using chatbots or other tools is very variable, in terms of the nature of the outputs and how they are created. Transparency around model construction is variable. The standard is right, but there is more for organisations to do. On the second part of your question, we use that framework and endorse it inside the ICO.
Andrew Breeze: On the question of transparency and personal data, I would certainly echo everything that William has said. For us, the key overlap and inflexion point between our two regimes, in terms of online safety and the Information Commissioner, is age assurance and the algorithmic decision-making that can be used in certain forms of it.
To the extent that decisions are being made about people there, we would definitely support the idea that transparency is really important so that people can, first, understand why the decision has been made. This is less around the specific personal data point, which is very much within the ICO’s remit, but more in the sense of people understanding when a decision has been made about them by an automated system. Secondly, they can have the right of appeal and the right of redress, which is a core concept of human rights.
Dr Mary-Ann Stephenson: Knowing that there are processes to deal with it when there are problems is key. For example, we recently supported a case with an Uber Eats driver who was unable to log on at work because the facial recognition technology did not recognise him; it was worse at recognising black faces. The problem there was that it was very difficult for him to know what process of redress there was, other than taking a case to court. He would not have been able to afford to do that had it not been for support from the EHRC, because these cases are expensive and complicated and he was not a rich man. It is about not just transparency around use but transparency around this question: “If there is a system in place and it is not working, who do I go to to get it resolved?”
The Chair: We are going to go to Baroness Chakrabarti now, then we will come back to Ms Campbell, who is passionate about the human rights of children and the impact of such technology on children.
Q84 Baroness Chakrabarti: I am afraid that this is once more for Mr Malcolm. How will the new Data (Use and Access) Act, which changes the UK GDPR, impact your regulation of automated decision-making using personal data?
William Malcolm: The important thing to start with here is that the need for safeguards to be in place around the use of automated decision-making very much remains; it is central to the legislation. We are required by the Act to produce a code on AI automated decision-making. We are very much working to scope that out and looking forward to the statutory instrument being laid by DSIT.
There is an opportunity to look across the economy at the various safeguards that are used in different contexts when automated decisions are made, to take existing guidance on automated decision-making and to bring that all into one central code. We are very much looking forward to developing that. It will be useful to innovators and developers who want to comply with the law, by and large, and who want to get this right so that the UK can get the benefits of AI, but perhaps need guidance around what the practical safeguards might look like in any given context. There is a shift, but it very much protects the rights of individuals, with the focus very much on the safeguards that organisations need to put in place.
Q85 Juliet Campbell: Dr Stephenson, could placing age restrictions on the use of artificial intelligence applications have a negative impact on children’s human rights?
Dr Mary-Ann Stephenson: That is a very good question. With all these things, there is a balance to be struck, depending on the particular situation you are trying to achieve between the right of a child to access information and freedom of expression and the right of the child to be protected from harm. It is not a straightforward case of, “This would be a violation or that would be a violation”. You have a number of different rights that you have to consider when you are regulating in this space. You have to think about the best way to get that balance. That will depend on what form the regulation takes, the form of the system you are trying to regulate, the age of the child and so on. There is no straightforward answer. Children’s rights will be engaged, and they will be engaged whichever decision you make—whether to regulate or not to regulate.
Q86 Peter Swallow: Of course, we are asking these questions in the context of the Government considering a social media ban or otherwise restricting social media for under-16s. While it is not perhaps spoken about as much as it should be, questions could well be applied to AI applications and services as well. Mr Breeze, how practical is it to establish and enforce age limits on online products? Perhaps you could tell us a little about how it is currently working with online pornography and how it might be extended to other services. How would this fit with Ofcom’s approach to human rights more generally?
Andrew Breeze: Certainly. Age assurance is a cornerstone of the online safety regime, precisely because there is this requirement to seek a greater level of online safety for children than for adults. This implies that you need to know who the children on your platform are; that is clear.
Thus far—most visibly in relation to the pornography sector, but we have also seen this with social media services, where there is a high degree of risk to children from the content shared on those services—we have seen services introduce age assurance. That is a really great example of the power of regulation. A lot of people, prior to our age assurance D-Day in July last year, were probably quite sceptical about whether these services would introduce age assurance, on the basis that it had not been successful in other jurisdictions.
The next question is: how do you ensure that age assurance is highly effective so that you are correctly identifying who is a child and who is not, at the same time as preserving privacy as much as possible? That really illustrates the essential trade-off that we are constantly navigating in the human rights context—particularly in online safety—between the status quo, where you do not have age assurance, and the sharing of personal data. As I say, it is something we work on very closely with our colleagues in trying to get right.
The practicalities of it are that we have issued guidance. We have said, “Here are seven forms of age assurance that are capable of being highly effective”. We are open to industry coming up with better options. Now it is the work of moving those parts of our sectors that have not adopted it yet to the place that we want them to be.
Peter Swallow: The criticism sometimes comes that because of VPNs, for example, some bans are far from perfect, and not every young person is effectively prevented from accessing material that it has been decided they should not have access to. That slightly misses the point, does it not? When we put in these restrictions, of course it is always with a recognition that anyone with the right will and way will potentially be able to get around them. It is about making sure as many young people as possible are protected from products that have been deemed to be harmful to them.
Andrew Breeze: That is right. If you look at the evidence, it is compelling that the majority of children who report seeing harmful content usually were not looking for it. Very often it is either presented to them via something like a recommender algorithm, or it is shown to them by somebody else. That phrase of “stumbling across” is the one that people often use. If you take that as being the theory of change—that you want to stop people who are actively looking for it—then you can conceive of age assurance as being a fence that you build around that content.
Now, no one in history has built a completely impregnable fence. How high do you need that fence to be? That is where you engage the question of VPNs. We want to see what the evidence shows about what children are doing. We are doing that research, but we would not rush to restrict a legal technology that has privacy-preserving and security-preserving qualities, including for children, because our starting point is that children have human rights that will be engaged and need to be respected too.
It is definitely something that is very much on our radar, it is something we want to understand more about, but you are absolutely right: in the end, there is no impregnable defence that you can create on the internet against a determined person, whether they be an adult or a child.
Peter Swallow: The perfect must not be the enemy of the good.
Andrew Breeze: I certainly agree with that.
Q87 Alex Sobel: Mr Breeze and Mr Malcolm, both Ofcom and the ICO are members of the Digital Regulation Cooperation Forum. How has the DRCF responded to the challenge of AI regulation, and to what extent have its objectives been achieved?
Andrew Breeze: I will take that first. It will not surprise you to hear that AI has been a real focal point of the work that we do in the DRCF. The CMA and the FCA are not here today, but it clearly is a significant part of their remit. They have published and set up sandboxes, and they are very much thinking along the same lines as we are. It is a key area of that significant overlap in our remit, which is what the DRCF is created to do.
We updated the original six objectives to five strategic priorities, which are: protecting and empowering people online; unlocking digital innovation and economic growth, which comes back to Mr Swayne’s earlier question; supporting regulator effectiveness; leading domestic and international discussions; and anticipating future developments. I would highlight three key activities here, which underpin what we do in the DRCF.
First, is knowledge sharing. We each have our areas of expertise, and we can amplify that effect by pooling that knowledge and sharing it. Secondly, we have outreach through things like the DRCF AI and Digital Hub, and the successor models that we are looking at now around how we can encourage innovation and get out into the community of people who are regulated and help them understand their obligations better. Thirdly, we have our convening power. Last year the DRCF ran a responsible AI event in Westminster, which was very well attended by parliamentarians, industry stakeholders and civil society.
Those are the three key means by which we are trying to advance those five strategic priorities over the next three years.
William Malcolm: That was a comprehensive answer. I would just perhaps mention that the DRCF’s work on the Thematic Innovation Hub is particularly noteworthy, as was the call for evidence recently on agentic AI where they were able to gather integrated industry views across all the member regulators’ issues.
It is perhaps also worth pointing out that as well as all that co-ordination through the DRCF, which has been outlined, member regulators work bilaterally. We very much work bilaterally with Ofcom on the age assurance issues that just have been covered, and we are working bilaterally on the Grok matter. The DRCF is a great umbrella. It is really driving effective collaboration and knowledge sharing across the regulators. There is also strong bilateral working when occasion calls for it.
Alex Sobel: Just to follow up, what is DRCF’s relationship with the AISI? Are there any co-ordinated activities or engagement between the two bodies? Do the regulator members of the DRCF provide comprehensive coverage of the digital sector, or are there any gaps in membership or activity?
William Malcolm: I know that it has a strong relationship with the safety institute. I know that there are regular conversations around how the model training and impacts are there. I would not add more than that really. I do not know if there is anything supplementary that you would add.
Andrew Breeze: Similar to your earlier answer, in addition to the DRCF’s relationship with the AISI, we also have bilateral relationships with them. The strongest area of overlap for us is our online safety remit and the societal harms unit. There is a significant amount of work going on, and that is very helpful for us because we do not have powers into that upstream layer. That is a really useful engagement for us to have.
In terms of the question of whether we are well populated, our terms of reference set out that we would be the regulators with strong areas of digital overlap. We started as three, we are now four. We have added the FCA over time, and we do those one-off projects with other regulators where we see that it is necessary. To the extent that we spot a gap, we are definitely ready and willing to take on more people. But at the moment four is about right, partly because you add more people in, and it tends to get harder to co-ordinate
Q88 Chair: I will ask one last question, because I am interested in the issue of public trust in AI and the Equality and Human Rights Commission. Dr Stephenson will recall that as a result of using AI yourselves to analyse a public consultation, there was criticism in the public domain. I do not know whether that criticism was justified or not, but does it say something about how the public feel about AI and how regulators themselves need to be aware of that? I would like to ask your two colleagues as well, if there is one thing that you could have done differently—just one thing—during your time as regulator, what would that have been?
Dr Mary-Ann Stephenson: In terms of our use of AI, we had over 50,000 responses to the consultation on the code of practice, compared with about 500 when we consulted on the previous draft before the For Women Scotland ruling. We used supervised AI technologies. We did not use the technology to summarise responses, we used them to group them into themes that people then reviewed so that they could be organised. If we had not have done that, it would have taken us several years or several hundred thousand pounds to do that work.
What we did was in line with what other government departments and public bodies do when dealing with large amounts of data on that scale. To be honest, the concerns expressed about it were more to do with issues around the code of practice itself than our use of AI. We were not using AI to analyse or write a response; we were using it to group responses that we had received into something that different subject specialists could then review.
Chair: We are all on a learning curve when it comes to using AI. Let me ask your colleagues then. If there was one thing that you could learn from that you would do differently now, what would that be? Mr Breeze?
Andrew Breeze: There is probably something that I would like us to do more of, which is the international co-ordination work. It is really acute for us both in the classic online safety context and in the AI context. These are typically, at the frontier model end, very large, very well-funded companies with a huge cross-border element to them. We have had success with our work through the Global Online Safety Regulators Network.
Just this month we published a statement on age assurance, which tried to set out, in a fundamental rights way, the baseline things that we all agree about how it should be done—one of those factors being, for example, that it should be privacy preserving. That sense of the force amplification effect that you can have from that multilateral cross-border work is something we have definitely learned from and would be keen to do more of.
William Malcolm: In the theme of “more of”, we recently published our own internal AI use policy, having worked on it extensively. We received a lot of positive comments from SMEs and bodies that were looking at the same issue. As a regulator, the challenges around adoption of cloud-based solutions and AI are similar for us as they are for many public bodies. Doing more of showing what we are doing from a practice perspective, and continuing on that theme as a way of educating and getting best practice out there, is something we are very keen to double down on.
Chair: Thank you very much. On behalf of the whole committee, I would like to thank the three of you for coming here today and sharing your expertise and wisdom, and to again offer the opportunity to write to us further if there are other things that you would like us to consider. The committee will return to this issue of AI and human rights on 25 February, for those who are following online. We will have Kanishka Narayan, Member of Parliament, the Minister who serves in the Department for Science, Innovation and Technology, coming to speak to us then. With those words, I am going to suspend the hearing so that we can then have a brief pause before we return for our second session. Thank you again for being here.