WRITTEN EVIDENCE SUBMITTED BY PROFESSOR SUBHAJIT BASU

(RAI0032)

 

I am a socio-legal scholar specialising in the regulation of emerging technologies, with particular expertise in artificial intelligence, big data, health data, and autonomous systems. My research focuses on the protection of fundamental rights in the digital age, critically examining how law and policy can address risks to privacy, accountability, and equality posed by technological decision-making.

The UK faces a decisive choice. It can embed its human rights tradition at the core of AI governance, or it can adopt a narrow pro-innovation stance that prioritises market entry over rights protection. In my view, rights should not be treated as barriers to innovation, but as the very conditions that make innovation legitimate, sustainable, and worthy of public trust.

Executive Summary

The UK’s current approach to AI regulation offers only partial protection. Rights are asserted in principle, but too often remain unenforceable in practice. If the UK is to align innovation with its longstanding commitments to dignity, equality, and accountability, Parliament must legislate for a stronger statutory framework.

Privacy and Data Usage

AI systems depend on large-scale data extraction that exceeds the boundaries of meaningful consent and transparency. The expansion of live facial recognition (LFR) across UK police forces illustrates the growing normalisation of disproportionate surveillance in the absence of statutory limits. It raises significant concerns under Article 8 ECHR, particularly when they retain data on innocent people or reproduce existing inequalities. Beyond the domestic context, the extraction of training data from the Global South raises what has been termed "technocolonialism," whereby privacy ceases to be a matter of individual autonomy and becomes an equity issue, reinforcing global asymmetries of power.

Discrimination and Bias

Algorithmic bias in AI is systemic rather than accidental. The persistent misidentification of women and minority ethnic groups in biometric deployments has been well documented; however, government claims of "no bias" obscure deeper structural harms. Bias is not confined to technical error but extends to how watchlists are compiled and which communities are disproportionately subjected to surveillance. Parliament should legislate for mandatory equality and human rights impact assessments, registries of public-sector AI deployments, and systematic bias audits.

Remedies and Accountability

The absence of effective remedies remains one of the most serious deficits in the current governance of AI. Accountability is dispersed across developers, deployers, and data controllers, while individuals are left to bear evidential burdens that are impossible to discharge in practice. Rights are therefore acknowledged in principle but hollow in effect. Parliament must impose statutory duties of transparency and accountability throughout the AI lifecycle, establish clear legal chains of responsibility, and ensure that regulators are adequately resourced and equipped with the necessary technical expertise to act at scale.

Current Framework

The UK GDPR, Equality Act 2010, and administrative law provide partial safeguards, but these are reactive and fragmented. The government’s 2024 AI framework sets out constructive principles—safety, transparency, fairness, accountability, and redress—but it remains non-binding. The UK’s signature of the Council of Europe AI Convention is symbolically significant, its impact will remain limited until it is implemented into domestic law.

AI Opportunities Action Plan

The AI Opportunities Action Plan reflects a clear ambition for growth but provides vague and instrumentalised commitments on rights. Regulators are tasked with a “growth duty,” which raises the risk that their core functions—protecting privacy, equality, and consumer rights—will be subordinated to economic priorities. Proposals for sovereign datasets, including NHS data, risk undermining privacy and autonomy in the absence of robust safeguards. Rights protections are framed as enablers of adoption rather than as fundamental entitlements.

Future Legislation

Any future legislation must embed enforceable duties rather than voluntary principles. It should require statutory human rights impact assessments, create enforceable rights of redress, and impose positive obligations on the state to prevent foreseeable harm, drawing on Articles 2, 3, and 8 ECHR. Critically, the same human rights standards must apply to private as well as public actors, given that private firms now dominate the development and deployment of AI systems central to public life.

Risk-Tiered but Rights-Centred Regulation

Different AI systems pose qualitatively different risks, requiring regulatory responses that are proportionate to context and potential harm. Biometric surveillance, predictive policing, and systems that directly impact liberty or equality require stricter safeguards than narrow, efficiency-focused applications. Oversight must reflect not only the nature of the technology but also its proximity to rights.

Liability Across the Lifecycle

Accountability should be based on both control and benefit, and liability must attach at each stage of the AI lifecycle—design, deployment, and use. Developers should be responsible for foreseeable harms linked to data or design flaws; deployers for governance and oversight; and users for ensuring ongoing monitoring and human intervention. Liability must be capable of being shared across actors to avoid gaps.


Redress Mechanisms

Redress must be made meaningful through a package of reforms: extending Human Rights Act remedies explicitly to AI harms; permitting collective redress and class actions; imposing statutory audit and transparency duties; introducing a rebuttable presumption of causality to ease evidential burdens; and creating a dedicated AI Ombudsman for systemic grievances in sensitive areas such as healthcare, policing, and employment.

International Dimension

AI is an international technology, and the UK’s regulatory approach must reflect this. Alignment with the Council of Europe AI Convention, OECD AI Principles, and the EU AI Act is critical to avoiding fragmentation and promoting common enforcement standards. Domestic law should embed mandatory human rights due diligence for UK firms across global supply chains and provide explicit powers to restrict, sanction, or prohibit the use of AI that contributes to human rights abuses abroad.

Council of Europe AI Convention

The Convention embeds into binding international law the principles of dignity, equality, transparency, accountability, and safe innovation. For the UK, its effect will depend on implementation—unless the UK declares that the Convention applies fully to private actors, its impact will be limited and largely symbolic.

Lessons from the EU AI Act

The EU AI Act demonstrates that human-centric, risk-based regulation can both safeguard rights and promote innovation. Its prohibitions on unacceptable practices such as social scoring, safeguards for high-risk systems, and accountability mechanisms offer a transferable model. The key lesson for the UK is that rights must be central, not secondary, to effective regulation.


1. How can Artificial Intelligence (AI) affect individual human rights for good or ill, in particular in the areas of:

Privacy and data usage

The UK's current approach to AI regulation prioritises innovation but, in my assessment, neglects the severity of privacy risks. AI systems are predominantly built on large-scale data extraction that outpaces meaningful consent or transparency, and privacy-preserving tools remain the exception rather than the rule. The most immediate danger is the normalisation of disproportionate surveillance. The August 2025 decision to expand live facial recognition (LFR) vans across seven police forces is a case in point. This rollout proceeds despite ongoing legal challenges and in the absence of a statutory framework, extending a technology that has already produced false match rates and retained images of innocent people without lawful authority.[1]

The government’s reliance on algorithmic testing that claims "no bias" in ethnicity or age exemplifies a familiar rhetorical move: reframing a structural rights problem as a question of technical accuracy. Under Article 8 ECHR, the relevant question is not efficiency but legality, necessity, and proportionality. By authorising expansion outside bespoke legislation, the government has chosen to privilege operational convenience over individual autonomy.

Are we sliding towards a surveillance society? (I know it is an old question, but it never loses relevance.) The deeper question may be whether we already inhabit one—albeit normalised, unevenly distributed, and often justified under the language of convenience, safety, or efficiency. AI is likely to intensify these dynamics, enabling more pervasive monitoring through tools such as live facial recognition, predictive policing, and algorithmic profiling. The issue is not just technological capability but what the government is doing to set clear legal limits, enforce safeguards, and ensure democratic oversight. Moreover, when training data is drawn globally, often from the Global South, the UK participates in what may be described as “technocolonialism”: consolidating informational power in the hands of actors in the Global North and transforming privacy from a matter of individual autonomy into one of global equity.[2]

Discrimination and bias

Algorithmic discrimination is not an aberration but a foreseeable outcome of training systems on biased datasets. The persistent misidentification of women and minority ethnic groups in biometric deployments is well documented;[3] however, the government now argues that “no bias” exists in the settings used. Even if such claims are accurate in narrow statistical terms, they obscure the wider equality harms: who appears on watchlists, how those watchlists are compiled, and which communities are disproportionately subject to surveillance. This reflects what I term the politics of surveillance neutrality—the presumption that technical validation can substitute for questions of justice and equality.

The EU AI Act recognises biometric surveillance as "high risk” and subjects it to strict safeguards.[4] The UK, in contrast, has left equality considerations to the discretion of regulators and police practice. In my judgment, this gap is unacceptable. Parliament must legislate for mandatory equality and human rights impact assessments, registries of public-sector AI deployments, and systematic bias audits. Anything less will entrench structural inequality beneath the veneer of technical objectivity, leaving discrimination to be managed piecemeal rather than prevented at source.

Effective remedies

In my view, the lack of effective remedies is the most serious deficit in the current governance of AI. Individuals affected by AI-driven decisions, such as those misidentified by facial recognition technology, often have no clear or accessible path to challenge outcomes. People may be flagged as suspects in public spaces and then required to prove their innocence, reversing the burden of proof. This dynamic reveals a structural flaw: accountability is dispersed across developers, deployers, and data controllers, with no single actor clearly responsible.

The result is that rights are asserted in principle but cannot be enforced in practice. Remedies that depend on individuals initiating complex legal challenges after harm has occurred are not real protections; they are formalities that place an impossible burden on those least able to contest powerful technologies. For remedies to be meaningful, Parliament must legislate to impose duties of transparency and accountability on all actors across the AI lifecycle. Transparent chains of responsibility must be established so that it is always possible to know who is accountable for decisions that impact rights. Regulators must also be adequately resourced and equipped with technical expertise to act at scale. Without these reforms, remedies will remain inaccessible, and fundamental rights will continue to erode under the weight of unaccountable systems.

2. To what extent does the UK’s existing legal framework provide sufficient protections for human rights in relation to AI? 

The UK’s existing legal framework provides fragments of protection but falls short of offering comprehensive or enforceable safeguards. Individuals must rely on general laws—data protection legislation, equality law, and administrative law—supplemented by a non-statutory, principles-based AI framework. These regimes collectively establish important principles, but they remain uneven, incomplete, and too often place the burden on individuals to contest opaque and powerful systems.

Data protection law is the most developed source of protection. The UK GDPR and Data Protection Act 2018 regulate data processing across the AI lifecycle, requiring Data Protection Impact Assessments for high-risk processing and prohibiting solely automated decision-making with significant effects, subject to exceptions. Individuals have rights to information, access, and contestation. However, the law is technology-neutral and does not directly reference AI, leaving many deployments outside its scope. Even where applicable, its effectiveness depends on the individual’s capacity to understand and challenge automated systems.

The Data Use and Access Act 2025 modifies this, while it strengthens complaints procedures and imposes clearer duties to protect children, it simultaneously broadens organisations’ ability to rely on “legitimate interests” to justify automated decision-making and relaxes requirements for notice in research and archiving. In my view, this tilts the balance towards organisational flexibility at the expense of individual autonomy.

The Equality Act 2010 prohibits discriminatory outcomes in AI-assisted decision-making; however, it was not designed with AI in mind and places the onus on individuals to prove discriminatory effects across systems they cannot meaningfully interrogate. Without statutory duties of transparency and equality impact assessments, these protections remain more theoretical than practical. Administrative law, meanwhile, offers procedural safeguards, but these are reactive and resource-intensive, leaving structural opacity intact.

The Government’s AI framework (February 2024) identifies five cross-sector principles—safety, transparency, fairness, accountability, and redress. Regulators must interpret and apply them in their sectors, publishing plans and guidance. These measures are constructive, but they are non-binding. There is no statutory duty to apply the principles consistently or cooperate across sectors.

Internationally, the UK’s signature of the Council of Europe Framework Convention on AI and Human Rights is a milestone. It obliges states to safeguard equality, privacy, transparency, and effective remedies throughout the AI lifecycle, and to consider moratoria or bans on uses incompatible with human rights. However, until it is implemented domestically, these obligations remain aspirational.

The UK framework provides principles, rights, and oversight in fragments, but not as a coherent or enforceable whole. The result is that individuals are promised fairness, transparency, and accountability in principle but too often left without accessible remedies in practice.

3. To what extent is the government’s policy approach to deploying AI, expressed in its “AI Opportunities Action Plan”, sufficiently robust in respect of safeguarding human rights?

The AI Opportunities Action Plan is ambitious for growth but muted on rights. It repositions regulators as promoters of innovation, requiring them to report annually on how they have “enabled growth”, with the possibility of override by a central body with a higher tolerance of risk.[5] This reframing risks subordinating regulators’ core functions—privacy, equality, and consumer protection—to the government’s economic narrative.

Unlike the EU AI Act, which expressly prioritises rights and imposes binding obligations on high-risk AI, the UK relies on sectoral discretion, leaving protections fragmented and contingent.[6] Where rights are mentioned, they are largely instrumentalised: safety is framed as a means to secure public trust and adoption, rather than as a fundamental entitlement.

The plan’s proposals for opening “high-value datasets”, including NHS and cultural archives, illustrate the danger. There is little engagement with past resistance to health data sharing or with the rights claims that flow from personal and collective data. Without meaningful opt-out mechanisms, transparency, or enforceable safeguards, the pursuit of sovereign datasets risks eroding privacy and autonomy while undermining public confidence.[7]

In my view, the plan is insufficiently robust. Its economic objectives are concrete; its rights protections are vague. Unless the government brings forward legislation to embed enforceable safeguards aligned with its obligations under the Council of Europe AI Convention, rights will remain vulnerable to being overridden by growth imperatives.[8]

4. What would be needed in any future UK legislation to protect human rights?

Future legislation must begin with the principle that human rights protections cannot be subordinated to economic ambitions. The AI Opportunities Action Plan frames risk in narrow terms of safety and security, but AI risk extends to systemic discrimination, chilling effects on expression, economic dislocation, and existential threats from frontier systems. A credible legislative framework must embed binding rights-based duties, not just voluntary principles.

Three elements are essential. First, statutory human rights impact assessments should be required for all significant AI deployments, particularly in the public sector, where procurement decisions affect millions. Second, individuals must have clear rights of redress, including explanations, the ability to challenge outcomes, and enforceable remedies. Third, the state must be placed under positive duties to prevent foreseeable rights violations by AI, drawing on the jurisprudence of Articles 2, 3, and 8 ECHR. Without such provisions, rights protections risk being marginalised in favour of growth imperatives.

To what extent should the same human rights standards apply to private actors as public bodies when they use AI?

In practice, the most powerful AI actors are private corporations. Big Tech dominates compute, data, and model development. The government’s plan for “sovereign AI” is, in reality, contingent on private investment, with proposals even to guarantee energy access for frontier developers. This creates acute risks of capture: private incentives shaping public policy. Accordingly, the same human rights standards must apply to both private and public actors. If corporations control infrastructure and datasets underpinning public services, their decisions directly affect citizens’ rights. It would be incoherent to hold government departments to Convention standards while exempting contractors performing equivalent functions.

Legislation must therefore:

Anything less risks collapsing the “growth duty” into a duty to insulate private firms from scrutiny.

To what extent might different kinds of AI technology require different regulatory approaches?

Different AI technologies pose qualitatively distinct risks. General-purpose models trained on massive datasets raise systemic concerns about the concentration of power, disinformation, and safety challenges. Narrow AI tools in recruitment or healthcare diagnostics engage more immediate risks of bias, error, and data misuse.

A risk-tiered regulatory model is justified, but distinctions must reflect the impact on rights, not just economic significance. The appropriate criteria are:

The government’s proposal to empower a central body to override regulators in the name of “risk tolerance” illustrates the danger of capture. Legislation must therefore differentiate without fragmenting, avoiding both over-generalisation and selective deregulation.

5. Who should be held accountable for breaches of human rights resulting from uses of AI, and on what basis?

Accountability cannot rest solely with the most proximate operator. Responsibility must be allocated across the AI lifecycle, reflecting the distributed control exercised by developers, deployers, and users[9].

The basis is twofold: control and benefit. Actors who design or deploy systems retain control over data, architecture, and safeguards, while those who profit from adoption should bear responsibility for preventing foreseeable harms. This echoes the principle of shared responsibility: AI development is co-creation, and liability must extend to all actors whose decisions materially contribute to rights-infringing outcomes.[10]

Where in the process of developing, deploying and using AI technologies should liability arise?

Liability should attach at each significant stage:

Legislation should allow for shared and overlapping liability, recognising that responsibilities are distributed but indivisible.

What additional measures, if any, are needed to ensure that individuals have sufficient redress where they have suffered harm because of the use of AI?

In my view, redress is undermined by asymmetries of power and information. Individuals face insurmountable evidential burdens in establishing causation in opaque AI systems. To correct this, five reforms are required:

Without these measures, remedies risk being formal rather than substantive — leaving human rights breached in practice but vindicated only in principle.

6. How might regulation match the pace of AI technology development, such as the emergence of agentic AI, to ensure that human rights are preserved as technology continues to develop?

Regulation must not lag behind technology. With agentic AI, after-the-fact remedies are inadequate: enforceable duties must be embedded at design, development, and deployment stages. This requires statutory obligations throughout the AI lifecycle, with documented intervention points, escalation routes, and enforceable containment measures in place when systems act unpredictably.

A risk-proportionate, adaptive model is essential. The EU AI Act ties obligations to risk categories rather than technologies. The UK should go further by mandating post-market surveillance, incident reporting, and recall powers, supported by a standing foresight unit to provide horizon scanning, red-team testing, and living guidance.

Deployment “gates” are crucial, as they restrict system-set objectives, require logs of plans and actions, and mandate re-evaluation at major updates. Containment and rollback mechanisms—such as kill switches, rate limits, and fallback to human control—must be treated as essential safeguards, not optional features. Accountability must be clear and non-delegable: developers for model safety and transparency, deployers for context-specific safeguards, and operators for monitoring and response.

7. How could regulation take account of the international nature of AI? How could it address the potential consequences for human rights in the UK of the malign use of AI by regimes in other countries?

Three approaches are required. First, align with supranational frameworks such as the Council of Europe AI Convention and OECD AI Principles, while ensuring interoperability with the EU AI Act. Second, embed mandatory human rights due diligence into UK law for companies operating across global supply chains. Third, strengthen cross-border cooperation so regulators can exchange information, coordinate investigations, and act jointly.

UK regulation should restrict the import, deployment, or export of AI systems linked to rights violations. This requires targeted sanctions, enhanced export controls on dual-use AI, and duties on UK firms to demonstrate that overseas partnerships do not contribute to abuses. Regulators should also be empowered to provide redress for individuals in the UK who have been harmed by the misuse of AI abroad, recognising transnational harms within the framework of the Human Rights Act.

8. How much difference will the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law make to the protection of human rights in the UK?

The Framework Convention is a significant development, as it embeds into binding international law the principles of dignity, equality, non-discrimination, accountability, transparency, and safe innovation. For the UK, already bound by the Human Rights Act 1998 and the European Convention on Human Rights, the Convention does not create wholly new obligations but strengthens existing commitments by providing an AI-specific framework and a monitoring mechanism. It also situates the UK within an emerging international consensus, aligning it with partners such as the EU and the US, which enhances the UK’s credibility in advocating for rights-respecting AI governance abroad.

However, the actual impact it will have in practice depends on its implementation. The Convention’s scope is weakened by exemptions for national security, defence, and research and development, as well as the discretion given to States over how far to apply its provisions to private actors. Given that most AI systems are developed and deployed by private firms, this flexibility risks leaving substantial gaps. Unless the UK, like Norway, declares that the Convention applies fully to private as well as public actors, its effect will be limited. Moreover, the broad national security carve-out risks undermining rights protections precisely where intrusive AI tools are most often deployed.

The Convention matters, then, less as a transformative instrument than as a baseline. It provides an international standard against which domestic law and policy can be measured, but the UK will need to go further if it wishes to ensure comprehensive protection. Ratification should be accompanied by a declaration extending its application to private actors, and by a domestic framework that narrows reliance on security exemptions and reinforces remedies for individuals.

9. What lessons can be drawn from regulation of the impact of AI on human rights in other jurisdictions, such as the European Union?

The EU’s AI Act demonstrates that a human-centric, risk-based framework can align technological progress with the protection of fundamental rights. Its stratified approach—prohibiting unacceptable practices such as social scoring, subjecting high-risk systems to rigorous safeguards, and imposing transparency requirements for lower-risk uses—offers a model of how law can be tailored to the severity of potential harms. The UK should draw from this structure when considering its own regulatory path, particularly by ensuring that human rights considerations are embedded at the heart of any future framework.

Two lessons are particularly salient. First, the EU has recognised that regulatory clarity fosters innovation and trust simultaneously. It is clear that by providing defined obligations and banning practices incompatible with democratic values, the EU has created a stable environment for investment while protecting dignity, privacy, and equality. Second, the Act underscores the importance of accountability mechanisms—including conformity assessments, audit requirements, and post-market monitoring—that allow regulators and individuals to challenge harmful outcomes.

The UK has thus far prioritised a pro-innovation agenda, with human rights framed only indirectly within broader economic objectives. The EU's approach shows that placing rights protection at the centre of regulation is not an obstacle to growth but a precondition for sustainable and trusted AI adoption. For the Joint Committee, the key lesson is that effective regulation must combine foresight, enforceable obligations, and a willingness to prohibit uses of AI that are fundamentally at odds with human rights. In my view, without such safeguards, commitments to responsible AI risk becoming merely rhetorical rather than substantive.

 

 

(Sept 2025)

11

 


[1] Big Brother Watch, Biometric Britain: The Expansion of Facial Recognition Surveillance (23 May 2023); Big Brother Watch, Face Off: The Lawless Growth of Facial Recognition in UK Policing (May 2018) 12–18; Kate Whannel, ‘Government Expands Police Use of Facial Recognition Vans’ BBC News (London, 13 August 2025).

[2] Adekemi O and Basu S, ‘Decoding and Reimagining AI Governance Beyond Colonial Shadows’ in Regine Paul, Emma Carmel and Jennifer Cobbe (eds), Handbook on Public Policy and Artificial Intelligence (Edward Elgar 2024) 220–234

[3] Big Brother Watch, Biometric Britain: The Expansion of Facial Recognition Surveillance (23 May 2023); Urquhart, Lachlan, and Diana Miranda. "Policing faces: the present and future of intelligent facial surveillance." Information & communications technology law 31, no. 2 (2022): 194-219

[4] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence [2024] OJ L 2024/1689 (EU AI Act), recital 11, art 2(1)(c)

[5] UK Government, AI Opportunities Action Plan (13 January 2025) https://www.gov.uk/government/publications/ai-opportunities-action-plan/ai-opportunities-action-plan

[6] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence [2024] OJ L 2024/1689, arts 5–7

[7] Information Commissioner’s Office, AI in Recruitment Outcomes Report (November 2024) https://ico.org.uk/media2/migrated/4031620/ai-in-recruitment-outcomes-report.pdf

[8] Council of Europe, Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (5 September 2024)

[9] A useful illustration comes from the emerging scholarship on autonomous delivery robots (ADRs), which highlights that when such systems operate in public spaces, liability cannot be localised to a single actor. See Subhajit Basu, Adekemi Omotubora & Charles Fox, ‘Autonomous delivery robots: a legal framework for infliction of game-theoretic small penalties on pedestrians’ (2024) 16 Law, Innovation and Technology 631

[10] Bart Custers, Henning Lahmann and Benjamyn I Scott, ‘From Liability Gaps to Liability Overlaps: Shared Responsibilities and Fiduciary Duties in AI and Other Complex Technologies’ (2025) 40(5) AI & Society 4035.