WRITTEN EVIDENCE SUBMITTED BY HANDLEY GILL LIMITED
(RAI0070)
Human rights issues
1. How can Artificial Intelligence (AI) affect individual human rights for good or ill, in particular in the areas of:
Human rights can be impacted throughout the artificial intelligence (AI) lifecycle:
In the course of their development, human rights can be infringed:
AI tools designed without regard for their human rights implications, or the enhanced human rights implications for specific groups, or which fail to incorporate safeguards, include:
Human rights can be adversely impacted when AI tools are misused, for example:
Conversely, AI tools can enhance human rights with examples including:
Where liability for AI tools is unclear and/or their ‘black box’ nature prevents the interrogation of outcomes, restricting transparency, accountability and explainability, the right to an effective remedy under Article 6 of the European Convention on Human Rights can be infringed.
The wider human rights impacts of AI may not be fully understood and are often not recognised; even in its recent proposals for the development of an AI Assurance profession[1], the government has failed to recognise the potential impact of AI on human rights other than in relation to privacy and discrimination.
Existing legal and regulatory framework
2. To what extent does the UK’s existing legal framework provide sufficient protections for human rights in relation to AI?
The practical ability or willingness to enforce the UK’s existing legal framework poses an immediate challenge to human rights protections, and these challenges are exacerbated by the development of adaptive and autonomous AI systems, such as agentic AI, and even AI systems that operate beyond their parameters without clear ownership, oversight or accountability, so-called ‘orphan’ AI systems. These medium-long term challenges have been recognised by the Law Commission in its recent discussion paper on ‘AI and the Law’[2].
The Government’s call on regulators to focus on growth and innovation, to the detriment of enforcement, means that in practice individuals cannot expect regulators to take action in relation to non-compliance and must instead seek to enforce their rights through the courts, if they have the knowledge, resources and commitment to do so. To take an ongoing example, proceedings for judicial review are currently being brought by a member of the public and the Director of Big Brother Watch have brought judicial review proceedings against the Commissioner of Police for the Metropolis in respect of the Metropolitan Police Service’s use of live facial recognition technology[3]. No regulator has taken public action against the MPS in respect of their use of this technology. Nevertheless, the Equalities and Human Rights Commission has been granted permission to intervene in the proceedings and is arguing that “the Met’s current policy governing the use of LFRT is incompatible with Articles 8 (right to privacy), 10 (freedom of expression), and 11 (freedom of assembly and association) of the European Convention on Human Rights”[4]. If that is the EHRC’s position, and if it is then it would be surprising if the Information Commissioner did not also have concerns about its data protection compliance, it should not take a member of the public having to bring proceedings for that to be expressed and regulatory action taken. While the Biometrics and Surveillance Camera Commissioner has also not taken any action, this post had been vacant for almost a year since the previous time-limited post holder who had been tasked with closing down the office stepped down after proposals to abolish the position were withdrawn (Francesca Whitelaw KC was appointed as the interim Biometrics Commissioner on 01 July 2025 for a period of up to 6 months; the post of Surveillance Camera Commissioner remains vacant).
The wider potential human rights impacts of AI, as identified above, are not necessarily reflected in the UK’s specific human rights legislation or in other statutes which protect human rights, and while these will therefore be subject to interpretation under the common law the practical impact is that human rights will not be adequately protected unless and until challenges are brought.
3. To what extent is the Government’s policy approach to deploying AI, expressed in its “AI Opportunities Action Plan”, sufficiently robust in respect of safeguarding human rights?
The AI Opportunities Action Plan was published subsequent to the government’s announcement in the 2024 King’s Speech[5] that it would introduce “appropriate legislation to place requirements on those working to develop the most powerful artificial intelligence models”; no such legislation has as yet been forthcoming.
The AI Opportunities Action Plan commissioned by the government and published in January 2025 called for it to shape the AI revolution, to create a thriving domestic AI ecosystem with British companies developing AI at every level of the tech stack and, achieve widespread use of AI products and services across the economy, and that one of the ways it should achieve this was by being “on the side of innovators”. Specific recommendations, included establishing ‘AI Growth Zones’ (AIGZs) to facilitate the accelerated build out of AI data centres, mitigate the sustainability and security risks of AI infrastructure, to unlock public and private sector data assets (including through the National Data Library, by rapidly identifying at least 5 high-impact public datasets it will seek to make available to AI researchers and innovators and establishing a copyright-cleared British media asset training data set), to reform the UK’s text and data mining regime so that it is at least as competitive as the EU’s, to work with regulators to accelerate AI in priority sectors and implement pro-innovation initiatives like regulatory sandboxes, to require all regulators to publish annually how they have enabled innovation and growth driven by AI in their sector, for the government to procure smartly from the AI ecosystem as both its largest customer and as a market shaper and, to publish best-practice guidance, results, case-studies and open-source solutions through a single “AI Knowledge Hub”.
The Government accepted the majority of these recommendations in full. In its response to the AI Opportunities Action Plan, the government recognised that “Ensuring we have the right regulatory regime that addresses risks and actively supports innovation will drive AI trust and adoption across the economy” and committed that it would “set out its approach on AI regulation and will act to ensure that we have a competitive copyright regime that supports both our AI sector and the creative industries”.
Human rights were not mentioned at all in either document, while only the need for privacy was recognised in the context of plans for the National Data Library.
The Government has certainly sought to forge ahead with the adoption of AI in the public sector, but its efforts to comply with human rights and wider public law obligations[6] have failed to keep up; it has not always complied with its own AI assurance standards when doing so, with belated or missing disclosures of the required Algorithmic Transparency Recording Standard. The government has also pressurised other public bodies, such as policing and law enforcement, to adopt AI without making available the additional funding and expertise to do so responsibly and expecting each organisation to proceed individually when the safest and most cost-effective approach would be to provide centralised support.
The Government’s approach is perhaps best illustrated by the then Secretary of State for Science, Innovation and Technology, Peter Kyle’s, speech at Manson House on 03 September 2025 in which he reiterated that “If AI can speed things up, even a little, then we will do everything we can to make that a reality”. Concepts of necessity and proportionality appear to have been surrendered to productivity and innovation, regardless of the financial or human cost.
Possible changes to legal and regulatory framework
4. What would be needed in any future UK legislation to protect human rights?
The enforcement of human rights is simply not achievable without transparency of: AI usage; the nature of the AI system; how the AI system was trained; the AI inputs; how AI outputs are used; and, assessments of risk. These should be mandated for all AI systems to understand how they can impact on human rights without the need to have recourse to threats of litigation and requests for pre-action disclosure.
The scope of human rights protection currently provided by UK legislation should be reviewed against international commitments.
Public law obligations inevitably mean that higher standards currently apply to public sector actors over private sector actors, but in the context of AI similar principles of transparency and explainability are necessary to deliver AI responsibly and therefore a baseline level of compliance is necessary for all actors even if higher standards are imposed on the public sector, with suppliers therefore at liberty to decide whether they wish to supply the public sector and comply with enhanced obligations or to develop public sector-specific products[7].
AI deployments which are high-risk or which have the potential for large scale impact should be subject to higher standards, whether deployed by private or public sector actors.
As the Law Commission has recognised in its discussion paper referenced above, the more autonomous and adaptive the AI system the greater the risk that existing legal and regulatory frameworks will fail to bite with human and other rights going unprotected and infringements unpunished.
General purpose AI systems, which have wide application and which form the underpinning to many deployments of AI, warrant greater regulatory oversight because of their potential for large scale adverse impacts.
AI systems that are designed for high-risk applications similarly warrant enhanced regulatory oversight.
5. Who should be held accountable for breaches of human rights resulting from uses of AI, and on what basis?
At present many contractual arrangements imposed by AI developers on end-users seek to shift all liability for the use of an AI system to the end-user, despite the end-user often not being in a position to determine the risk associated with the AI system, and while this may encourage innovation by AI developers it can stymie AI adoption by end-users.
As identified above, human rights infringements can occur throughout the AI supply chain, not merely as a consequence of their final deployment, and liability should therefore sit with the relevant actor in the chain but, in relation to human rights infringements arising from AI deployments, multiple actors could – and should - potentially be liable. For example, if an AI system was to be deployed in a medical context which performed poorly for a particular ethnic group causing harm and infringing human rights and equalities legislation, the end-user could be held liable but if they have merely adopted an AI system sold to them for that purpose then the developer of the AI system also ought to be liable.
The desirability of a legislative framework that protects innovation and productivity while securing an adequate level of protection for human rights by establishing minimum standards for responsible AI development and deployment subject to compliance with which liability can be avoided should be considered.
6. How might regulation match the pace of AI technology development, such as the emergence of agentic AI, to ensure that human rights are preserved as technology continues to develop?
We anticipate that principles-based, rather than rules-based, regulation will cope most effectively with the rapid pace of technological development and that while certain baseline standards should apply globally, the adoption of a risk-based approach to target the highest risk and/or largest scale AI systems should be adopted.
7. How could regulation take account of the international nature of AI? How could it address the potential consequences for human rights in the UK of the malign use of AI by regimes in other countries?
The UK already seeks to impose liability for the conduct of foreign entities impacting UK citizens in several contexts; the UK GDPR has extra-territorial effect in certain circumstances and entities operating outside the UK may be required to appoint a UK representative who can be held liable for non-compliance and the Online Safety Act 2023 grants Ofcom the power to apply to the courts to block certain sites and services from the UK if necessary.
On the international stage, the failure of major AI players including the USA and China to submit to the jurisdiction of the International Court of Justice presents challenges to the protection and enforcement of the human rights of individuals in the event of nation state action.
8. How much difference will the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law make to the protection of human rights in the UK?
While the UK is a signatory to the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, as is the USA, no country has ratified the Convention, which will only enter into force once it has been ratified by 5 signatories including at least 3 Council of Europe Member States.
The requirements of the Convention extend beyond existing UK law and would require legislation, for example:
If the Convention is implemented, however, it would provide the basis for individuals to be able to hold AI developers and deployers to hold AI to account in many cases.
9. What lessons can be drawn from regulation of the impact of AI on human rights in other jurisdictions, such as the European Union?
The EU’s AI Act has prohibited[8] some of the most potentially prejudicial AI systems including predictive policing, the creation or expansion of facial recognition databases created through untargeted web scraping, biometric categorisation to infer certain protected characteristics, live facial recognition for law enforcement, emotion recognition and social scoring. These are potentially permissible in the UK, albeit that in theory compliance with data protection and human rights law may present challenges but, regulatory investigation or enforcement actions do not appear to be being undertaken.
The EU AI Act requires that general purpose AI models with systemic risk[9], which includes those models that pose actual or reasonably foreseeable negative effects on fundamental rights are required to be reported to the European Commission and providers of high-risk AI systems will be required to conduct fundamental rights impact assessments as well as to adopt various other safeguards including in relation to human oversight and record-keeping.
Notwithstanding the withdrawal by US President Trump of President Biden’s Executive Order 14110 on the Safe, Secure and Trustworthy Development and Use of Artificial Intelligence which, among other things, provided for the reporting of test results on AI models to the government and establishes the US AI Safety Institute, and its replacement with his own Executive Order on Removing Barriers to American Leadership in Artificial Intelligence, which requires the creation of an action plan to “sustain and enhance America’s global AI dominance” but doesn’t reinstate any obligations pertaining to AI safety, reporting or testing, while dressed in the guise of consumer protection rather than human rights, the US’ Federal Trade Commission continues to take action against AI developers.
China, however, has adopted technical standards and industry-specific regulation.
While laudable, however, the comprehensive nature of the EU’s AI Act contrasted with approaches in the US and China risks inhibiting innovation and competitiveness and the US’ stance could render it effectively unenforceable.
Nicola Cain
CEO & Principal Consultant, Handley Gill Limited
(Sept 2025)
7
[1] https://www.gov.uk/government/publications/trusted-third-party-ai-assurance-roadmap
[2] https://lawcom.gov.uk/news/artificial-intelligence-and-the-law-a-discussion-paper/
[3] AC-2024-LON-001764 R (on the application of (1) Shaun Thompson and (2) Silkie Carlo) v Commissioner of Police for the Metropolis
[4] https://www.equalityhumanrights.com/met-polices-use-facial-recognition-tech-must-comply-human-rights-law-says-regulator
[5] https://www.handleygill.co.uk/handley-gill-blog/kings-speech-2024
[6] https://www.handleygill.co.uk/handley-gill-blog/public-authority-public-function-artificial-intelligence-ai-public-law-judicial-review
[7] https://www.handleygill.co.uk/handley-gill-blog/public-sector-algorithmic-transparency-recording-standard
[8] https://www.handleygill.co.uk/handley-gill-blog/eu-artificial-intelligence-ai-act-prohibited-practices-ai-literacy
[9] https://www.handleygill.co.uk/handley-gill-blog/eu-ai-act-implementation-general-purpose-ai-models