WRITTEN EVIDENCE SUBMITTED BY THE EQUALITY AND HUMAN RIGHTS COMMISSION

(RAI0075)

Introduction

The Equality and Human Rights Commission is the National Human Rights Institution for England and Wales, and for reserved matters in Scotland. We are also the regulator of the Equality Act 2010.

Our role is to make the country a fairer place by enforcing and upholding the laws that safeguard everyone’s right to fairness, dignity and respect.

We get our powers from the Equality Act 2006. Our specific human rights duties include:

We welcome the opportunity to provide written evidence to the Joint Committee on Human Rights’ inquiry into human rights and the regulation of AI. AI was a distinct strategic focus for the EHRC in our strategic plan for 2022 – 2025 and we are continuing to take action on AI in our new, more agile strategic approach.

We have developed a good understanding of the risks to human rights from AI, and work closely with the wider regulatory community in the UK to understand appropriate responses and interventions. We have engaged the UK government as it develops its approach to regulating AI and continue to do so.

We would welcome the opportunity to expand on any of these points in oral evidence if it would help the Committee.

Human Rights Issues

1. How can Artificial Intelligence (AI) affect individual human rights for good or ill, in particular in the areas of:

               privacy and data usage

               discrimination and bias

               effective remedies for violations of human rights?

 

1.1           AI is a general term applied to a range of technologies. There is currently no legal definition of AI in the UK. In A pro-innovation approach to regulating AI (the AI White Paper), the former UK government defined AI as having two characteristics:

1.2           The Council of Europe Framework Convention on AI, Human Rights and the Rule of Law defines AI as machine-based systems that generate outputs such as predictions, content, recommendations or decisions that may influence physical or virtual environments. Different artificial intelligence systems vary in their levels of autonomy and adaptiveness after deployment.

1.3           Similarly, the European Union’s AI Act highlights autonomy and adaptiveness as core characteristics of an AI system, which generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.

1.4           These definitions are important: AI is not a single thing, and the risks and opportunities are unique to a specific tool or model’s purpose, use and utility. We will return to this point throughout this submission.

1.5           AI undoubtedly has many potential opportunities, some of which are already becoming apparent. The principal benefit from most AI use is around speed and scale, bringing significant efficiency savings.

1.6           It can also bring better, more consistent decisions, including potentially avoiding bias that can exist in human analysis and decision making. AI systems are being used to better understand and mitigate the impacts of climate change, helping to protect people’s property, a right guaranteed under article 8 of the ECHR. Significant promise has also been shown in improving healthcare, for example AI analysis of medical images to detect cancer.

1.7           However, with these benefits come many risks to human rights. These risks have been recognised by the UN,OECDUNESCO and the Council of Europe amongst many others.

1.8           Some of these risks include:

Article 10 - Right to respect for private and family life

1.9           One thing that AI tools have in common is that they rely on huge amounts of data, often personal data – data that refers to our personal characteristics and can be used to identify individuals. The privacy implications are therefore significant across many, if not most, AI types and uses.

1.10      This is prevalent across AI deployed in the public and private sectors in for example recruitment, employee monitoring, the social security system, health and social care and police surveillance technology.

1.11      The Information Commissioner’s Office (ICO) is the dedicated regulator for data privacy. The EHRC and ICO have a Memorandum of Understanding to support our respective regulatory activity in relation to AI and have collaborated on several projects.

1.12      The ICO has also highlighted privacy concerns in relation to web scraping to train AI and the use of intrusive workplace surveillance.

Article 10 – Freedom of Expression and Article 11 – Freedom of Assembly

1.13      Surveillance technologies can have significant impact on the rights to freedom of expression and assembly, set out in Articles 10 and 11 of the ECHR.

1.14      Live Facial Recognition (LFR) is the primary tool being used increasingly in public spaces by police in England and Wales. This is where cameras used to scan every person’s face that passes to match against a watch-list of wanted individuals, in real-time.

1.15      The European Court of Human Rights considers that use of such technology in public spaces, particularly if used around protest risks having a chilling effect on freedom of expression and assembly, causing people fear of exercising their lawful rights.

1.16      Other technologies, for example emotion recognition tools used in employment and recruitment settings, can also have a chilling effect on individuals’ freedom of expression.

Article 4 – Right to a Fair Trial

1.17      The Ministry of Justice recently published the AI action plan for justice, which sets out how the UK government intends to use AI in the justice system.

1.18      The use of AI could improve access to justice, in particular by simplifying and speeding up the court process. However, the use of AI in the justice system without appropriate safeguards risks the right to a fair trial. A Council of Europe study described these risks, from the use of predictive policing (using historic crime data to try and predict future crime or reoffending) through to the use of AI to support or inform judicial decision making, highlighting poor accuracy rates and racial discrimination.

1.19      The UK government recently announced investment in predictive policing AI tools. It is imperative that human rights considerations - including but not limited to the right to a fair trial - are incorporated in any use of such tools.

Article 14 - Prohibition of discrimination

1.20      The holding and processing of personal data through AI can lead to discriminatory outcomes because of incomplete or poorly representational data, or replication of historic bias in decision making.

1.21      For example, a recent academic study of the use of Large Language Models in care planning by Local Authorities found that some models were more negative about male health than for women. This could potentially result in women not receiving the care they need.

1.22      The use of AI systems could result in discrimination because of how they are used. This could be the specific task they are used for, or by choices around how, when or who an AI system is targeted.

1.23      For example, careful planning and safeguards are required to ensure LFR is not deployed in a way that could result in discrimination, and that any disproportionate use in relation to any group sharing a protected characteristic is monitored. For example, research has highlighted that over half of all LFR deployments in London in 2024 were in areas with a higher-than-average Black population. Data seen by EHRC has shown that Black men are disproportionately stopped by the Metropolitan Police Service when using LFR.

1.24      The scale at which AI tools operate can also mean that any potential for discrimination is magnified.

1.25      The combination of the risk of bias in data sets with the risks of discrimination from the use case and processes around the use call for socio-technical solutions. This means developing an understanding of risks from both the technology and in how it is used and putting in place mitigating activities to prevent discrimination.

1.26      For example, the EHRC worked with the ICO and DSIT on the Fairness Innovation Challenge, which brought together public authorities and service providers to examine how algorithmic systems can affect equality and rights outcomes. Through this project, we offered advice to innovators on the equality and rights implications of AI to support the development of socio-technical solutions. In one example the Open University was developing a system for early intervention with students at risk of dropping out from their studies.   We provided advice to ensure the training data is representative of ethnic minority groups to reduce the risk that particular ethnic minority students were not identified as at risk.

Effective remedies for violations of rights

1.27      Remedies exist for AI-based violations of rights as they do for non-AI breaches. This can include taking legal action, through existing regulation or through ombudsman schemes.

1.28      A significant challenge for effective remedy is ensuring individuals know that AI has been used and that it can be challenged. Transparency in AI use is essential to support challenge and remedy.

1.29      The AI White Paper included the principles of transparency and explainability and remedy and redress. We support the emphasis on these principles as it is essential that people know when AI is being used in decisions about them and provide the ability to challenge decisions.

1.30      The UK government has also introduced the Algorithmic Transparency Recording Standard, a standardised way for public sector organisations to publish information about how and why they are using algorithmic tools (including AI).

1.31      While this standard is a good starting point for transparency, people should be proactively informed about the use of AI in any significant decision about them, and about how such decisions can be challenged.

1.32      A further barrier to effective remedy is system capacity including through regulators, ombudsmen and the justice system. We expand on this point in response to question 3.

Existing legal and regulatory framework

2.    To what extent does the UK’s existing legal framework provide sufficient protections for human rights in relation to AI? 

 

2.1           The UK has a mature legal framework to protect human rights in many different settings.

2.2           The protections offered by the European Convention on Human Rights (ECHR) and the Human Rights Act 1998 (HRA) apply to the use of AI by public bodies as much as and in the same way as for traditional public service delivery. Individuals can uphold these rights through the courts.

2.3           Other laws and regulations have their origins in or adopt and build on ECHR rights in some way. For example, Data Protection law is based on and extends the right to privacy (article 8 ECHR) and elements of media regulation protects the right to freedom of expression (article 10 ECHR). The Equality Act builds upon the right to non-discrimination (article 14 ECHR).

2.4           There is currently little case law relating to the use of AI and breaches of rights. This is likely down to a number of factors, including the newness of the technology and the lack of individuals’ knowledge of the use of AI. Nonetheless, the courts have for example considered the human rights implications of LFR, and the EHRC supported legal action against Uber Eats after a driver argued its identity verification tool was racially discriminatory.

2.5           This mature network of law and regulation does provide some protection for human rights in relation to AI. Regulators are also public bodies and must consider human rights in the discharge of their public functions. Many regulators are developing their approaches to regulating AI within their own remits.

2.6           The AI White Paper set out the then UK government’s approach to regulating AI, primarily using the existing regulators and legal frameworks, while acknowledging the potential need for specific additional legislation in future. The current government have not changed the approach set out in the AI White Paper.

2.7           We agreed with this approach: regulators have appropriate and detailed knowledge of the risks and impact from AI within their own remits and sectors.

2.8           However, while the AI White Paper recognised risks to human rights from AI, it only contained minimal reference to human rights within the principle of Fairness. This does not reflect the full and broad range of human rights, nor the potential risks posed by AI. We have not seen any additional focus on protecting people from breaches of their rights because of the use of AI from the UK government since.

2.9           We further highlighted the need for government to recognise the resource pressures on regulators, including the financial imbalance between regulators and the tech industry and the complexity and cost of enforcement in relation to the use of AI. We called on government to invest in regulators to ensure an effective regulatory environment that supports responsible innovation. We return to this point in response to question 3.

3.    To what extent is the Government’s policy approach to deploying AI, expressed in its “AI Opportunities Action Plan”, sufficiently robust in respect of safeguarding human rights?

 

3.1.        The AI opportunities action plan (the Action Plan) sets out that AI is both an economic opportunity and an opportunity to transform public service delivery, and places significant emphasis on expanding the use of AI across public services.

3.2.        The Action Plan did not reference human rights. However it did emphasise the role of effective regulation in supporting innovation, building trust and protecting people from risk. It also recommended that the UK government commit to funding regulators to scale up their AI capabilities.

3.3.        In its response to the Action Plan, the UK government agreed with this recommendation, and said it would be addressed through regulators’ sponsor departments ahead of the Spending Review 2025. This did not happen for EHRC.

3.4.        The Committee will be aware that the EHRC budget has remained static for over 10 years at £17.1million, including the recent period of high inflation. This amounts to a real terms cut of over 30% and growing. There are no indications that we will receive any increase to our budget in the near future.

3.5.        The Committee itself has also asked the UK government to consider whether this settlement is sufficient to tackle emerging technology, amongst other pressing issues.

3.6.        As set out elsewhere in this evidence, EHRC has been undertaking and is continuing to undertake work on AI. However, our ability to do this at scale is limited by our resources.

Possible changes to legal and regulatory framework

4.    What would be needed in any future UK legislation to protect human rights?

        To what extent should the same human rights standards apply to private actors as public bodies when they use AI?

        To what extent might different kinds of AI technology require different regulatory approaches?

 

4.1.           The AI White Paper set out the UK government’s approach to regulating AI through existing regulators using their existing powers. We broadly agree with this approach, as regulators have detailed understanding and expertise of the uses and risks of AI within their own sectors and remits, subject to having sufficient resources. Many regulators are developing approaches to regulating AI within their remits

4.2.           While the existing legal and regulatory frameworks are extensive and flexible enough to respond to most known or anticipated risks,  some AI technologies or uses of technologies may require new specific legal and/or regulatory responses due to the risk to human rights that will become apparent overtime.

4.3.           For example, the EHRC has recommended that Government bring forward a dedicated legal and oversight framework to cover police use of LFR and other biometric identification and surveillance technologies. We recognise that these technologies can be a valid and effective policing tool, but use must be grounded in human rights considerations, specifically around privacy, freedom of expression and assembly and non-discrimination.

4.4.           The Human Rights Act 1998 only applies to public organisations or those undertaking public functions. However, under the ECHR, the UK government has positive obligations to protect individuals from breaches of rights by private actors, such as through legislation or other measures.

4.5.           Regulations that extend human rights principles and protections to private actors are examples of how states can comply with positive obligations. Examples include Data Protection and the Equality Act 2010. These regulations apply to the use of AI as much as for traditional methods of service delivery.

4.6.           The positive obligations on states to protect human rights mean that the UK government must be alert to risks to human rights presented by private sector use, and take appropriate action when necessary. The private use of facial recognition in, for example, retail environments may be such an example where legislation and oversight is needed, given risks to privacy and non-discrimination.

4.7.           Similarly, the development of highly capable and easy to access AI tools such as ChatGPT, Gemini or Grok bring considerable and novel risks, which may impact on human rights. This could include societal-level impacts, including replication and amplification of existing societal biases that exist in a model’s training data. One family in the USA is currently suing OpenAI for wrongful death after their son took his own life after using ChatGPT. Malicious use of such tools could also be used to interfere with democratic processes by, for example, creating and disseminating misinformation. Deepfake technology could present significant risks to freedom of expression as well as having a particular negative impact on women and girls by replicating gender bias and stereotypes and allowing the creating of fake intimate images.

4.8.           Only if Government is alert to such emerging risks will it be able to put in place appropriate and proportionate mitigations, including potential new legal and regulatory frameworks, as they become necessary. The government has indicated a focus on security and safety in proposed legislation – it must take a wide view of safety to include human rights as appropriate.

4.9.           There are also strong ethical drivers for the private sector to take a human rights-based approach. Although not legally binding, the UN Guiding Principles on Business and Human Rights are a clear set of guidelines for businesses to follow to respect and protect human rights. These can be applied by businesses that are developing AI models and tools, as well as those considering using AI.

5.    Who should be held accountable for breaches of human rights resulting from uses of AI, and on what basis?

         Where in the process of developing, deploying and using AI technologies should liability arise?

         What additional measures, if any, are needed to ensure that individuals have sufficient redress where they have suffered harm because of the use of AI?

 

5.1.           The Human Rights Act 1998 only applies to public authorities and those carrying out public functions. As such, accountability for breaches of human rights sits with the public organisation deploying the AI tool, whether it has been bought in or developed in house.

5.2.           Public organisations developing or buying in AI tools must consider their human rights obligations throughout this process. This includes the specific utility of the tool itself as well as the purpose and processes surrounding use of the tool.

5.3.           Similarly the Public Sector Equality Duty is non-delegable, meaning responsibility lies with the contracting public organisation to ensure all third-party contractors appropriately consider equality impacts.

5.4.           Other legislation and regulatory frameworks that are based on human rights may allow regulators to examine compliance throughout the supply chain. UK data protection law, for example, applies accountability with the data controller or joint controllers, meaning liability may lie with third party developers as well as the deployer.

5.5.           While liability must always rest with the deployer of an AI system, specific uses or technologies may require different approaches, ensuring liability lies throughout the supply chain from developer to deployer. For example, the ICO have set out that general purpose models like ChatGPT, Gemini or Copilot, which are available freely or come integrated within existing software contracts, may mean liability should lie across the supply chain.

5.6.           This ties into the need for government to be alert to risks to human rights posed by the private sector use of AI, and to ensure effective and proportionate protections – through legislation or other measures – are in place.

6.    How might regulation match the pace of AI technology development, such as the emergence of agentic AI, to ensure that human rights are preserved as technology continues to develop?

 

6.1.           Traditional regulatory approaches and law-making moves slowly and responds to known risks. However, the development and deployment of AI is happening at pace. This can result in problematic or harmful practices happening before government, the law and regulators have been able to understand and appreciate the risk.

6.2.           A real example, as referred to elsewhere in this submission, is the use of LFR by the police. This technology was first used by the Metropolitan Police in 2016 at the Notting Hill Carnival, with its use increasing rapidly over the last 18 months.

6.3.           The ICO issued an opinion on the use of LFR in 2019. It has been subject to judicial review at the Court of Appeal (Bridges v South Wales Police, 2020). In 2020, we raised concerns about the potential discriminatory impacts of LFR and called for its use to be suspended to allow its use to be informed by independent impact assessments and consultation, and for a rights respecting legal framework to be developed. Since 2022, EHRC has been working with policing bodies to understand current policies governing the use of LFR. Throughout 2023 and 2024, we again called for a comprehensive legal and oversight framework for its use. In August 2025, the Home Secretary confirmed the UK government’s intention to consult on a legal framework for the use of LFR.

6.4.           This timeline demonstrates how the technology adoption far outpaces the ability of lawmakers and regulators to act in an evidenced and proportionate way. There is a significant challenge for regulators and law makers to be able to keep pace with technological change, while also ensuring that regulation is designed and implemented with a good understanding of the risks.

6.5.           Given the pace of development, there is an opportunity to ensure human rights are ‘baked in’ to the development and deployment of AI though detailed guidance and tools to support those developing and deploying AI.

6.6.           Alongside the Framework Convention on AI, Human Rights, Democracy and the Rule of Law, the Council of Europe has developed the HUDERIA tool as guidance for taking a structured approach to risk and impact assessment for AI systems specifically tailored to the protection and promotion of human rights, democracy and the rule of law. It is also currently developing a Handbook on Human Rights and AI to offer guidance to policy-makers on upholding human rights in the era of AI.

6.7.           The EHRC has also produced guidance on AI and the Public Sector Equality Duty, and worked with partners including the Local Government Association and the ICO to produce guidance for local authorities in procuring AI. The Fairness Innovation (see 1.26 above) is a further example of working upstream with developers to build rights protections in at the start.

6.8.           This approach of developing guidance and practical tools is a valuable starting point. However, the ability to have significant impact with limited resources is challenging. We refer to our answer to question 3.

7.    How could regulation take account of the international nature of AI? How could it address the potential consequences for human rights in the UK of the malign use of AI by regimes in other countries?

 

7.1.           No response.

8.    How much difference will the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law make to the protection of human rights in the UK?

 

8.1.           The Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law is an important step in ensuring international agreement on tackling emerging risks posed by AI.

8.2.           The UK government has signed but not yet ratified the Framework Convention.

8.3.           The Framework Convention does not create any new human rights or legal obligations, but reiterates the importance of applying states’ existing human rights protections to AI.

8.4.           While it does not add to the legal framework, the UK’s ratification would signify a commitment to ensuring the use of AI in the UK respects human rights.

9.    What lessons can be drawn from regulation of the impact of AI on human rights in other jurisdictions, such as the European Union?

 

9.1.           All jurisdictions are still in the early days of regulating AI. While the EU has legislated through the AI Act, it is still in the early days of implementation.

9.2.           There will be, however, much to learn from other jurisdictions about both the risks to human rights from AI and effective and proportionate responses.

9.3.           The UK government should continue its strong international engagement on AI to learn from approaches elsewhere and continue to regularly and effectively engage domestic regulators to identify and respond to emerging risks.

9.4.           The EHRC is an active member of the European Network of NHRIs (ENNHRI) and participates in its AI working group. ENNRHI has played an active role in coordinating NHRI input to the AI Act and its subsequent implementation. We have taken and will continue to take any lessons learned from this and share with the UK government to inform its approach to regulating AI, for example sharing learning from the Dutch Child Benefit Scandal. While many ENNHRI members have not yet undertaken extensive work on AI, some now have a supervisory role under Article 77 of the EU AI Act, monitoring the impact of high-risk AI systems on fundamental rights. We anticipate being able to share more lessons in due course.

 

(Oct 2025)