Read Public Law Project’s evidence to the Joint Committee on Human Rights here.

Parliament’s Joint Committee on Human Rights (the Committee) has concluded its inquiry into Artificial Intelligence (AI) regulation. Public Law Project (PLP) welcomes its report as perhaps the most thorough parliamentary treatment we have had of how AI is affecting (and may yet affect) people’s rights, including through its use in the public sector.

The Committee’s central conclusion is that the UK is not doing enough to regulate AI and protect people’s rights. Their report warns us that, in racing to realise the promises of AI, we risk taking power away from people by making decisions that affect them harder to understand and challenge. PLP’s evidence to the inquiry was focused on how this accountability problem arises in the public sector. This blog explains and comments on the relevant Committee findings.

Lack of transparency

The Committee has concluded that “the current legal framework does not provide for adequate transparency in relation to the development and deployment of AI systems” (at [130]). In the public sector, this transparency problem can be seen at two levels.1

At a systemic level (i.e. the general picture of how government is using AI), the Committee cited PLP’s Tracking Automated Government Register as evidence that government is insufficiently transparent about its use of AI in decision-making. It concluded that, although the Algorithmic Transparency Recording Standard (‘ATRS’) (a mandatory transparency requirement for certain central government algorithmic tools) “provides some transparency concerning the use of AI systems”, it is “limited in its coverage” (at [133]).

This systemic transparency problem should be addressed by any AI Bill aimed at safeguarding human rights (such as that recommended by the Committee). Placing the ATRS on a statutory footing would be a good way to start – it is already mandatory for central government, but compliance with it is low. Giving a suitable body a statutory responsibility for enforcing the ATRS could improve that.

At an individual level (i.e. the information given to individuals about how AI has been used in a decision affecting them), the Committee concluded that there is strong evidence to suggest that individuals have been unable to challenge human rights violations because they have not been told about AI use (at [131]).

The Committee agreed with PLP’s evidence that public bodies’ obligations to tell people when AI has influenced a decision affecting them need to be made clearer (at [215] and [217]). Although the UK GDPR requires that people be informed where a significant decision about them is taken solely through automated means,2 the requirement does not apply where a human decision maker is assisted by AI. Extending the requirement to AI-assisted decisions, and clarifying what information must be provided, could help people understand whether and how AI shaped decisions affecting them and assess whether a human was meaningfully involved in it (for example, by assessing whether the decision-maker had enough time and information to meaningfully review an automated output).

Fragmented regulation

The Committee concluded that “the present regulatory framework is fragmented and difficult to navigate” and that, as a result, a dedicated AI oversight body is needed to plug gaps in protection, including by auditing AI systems, issuing codes of practice and transparency requirements, investigating alleged breaches and sanctioning non-compliance (at [224]-[227]).

In the public sector, fragmentation can weaken accountability in three ways: first, by creating uncertainty about how existing legal standards apply when AI is used in decision-making; second, by making it harder to enforce those standards; and, third, by risking leaving gaps where types of harm are not properly addressed. Weak enforcement can make uncertainty worse, including by limiting opportunities for courts to clarify the law. So, the Committee is right to address both problems through its proposed AI Bill and new oversight body.

AI-assisted public decision-making may require targeted reform. PLP’s evidence details how public bodies using AI in decision-making have to navigate overlapping requirements across public law, human rights, equality law, and data protection – with considerable uncertainty about how each applies in this context (see our response to Question 2). As we have argued elsewhere, this has given a heightened significance to clear rules which are easier to apply. It is more straightforward, for example, to ensure that there is human involvement in significant decisions,3 than it is to assess, case by case, whether broader public law requirements such as fairness have been met. Targeted reform (including through the Law Commission’s review of public sector automated decision-making) could help clarify such requirements and prevent clearer, more easily applied rules from crowding them out.

Diffuse responsibility for AI

The Committee concluded that AI “deployers are the primary holders of responsibility for harms arising from AI systems” and “existing laws do not take due account of the complexity of the AI lifecycle and supply chain and are not directed to the actor that may be best placed to identify and avert the source of risks” (at [104]).

The concern is that responsibility for making sure systems are fair, lawful and non-discriminatory may not clearly attach to the actor(s) best able to identify and prevent connected risks. When a public body uses an AI system, it may be practically difficult for them to take meaningful responsibility for it if actors in the supply chain are not subject to complementary upstream obligations concerning, for example, the system’s design.

PLP has observed this play out as public bodies seek to comply with transparency requirements for automated decision-making. It is right that public bodies adopting AI systems to support their decision-making should be responsible for meeting relevant transparency requirements. However, as our upcoming research ‘Public Law Litigation in the Automated State’ will show, transparency mechanisms’ practical effectiveness can be undermined where upstream actors such as system developers are not required to provide public bodies with the information they need – particularly technical information, such as training data, which can be harder to obtain after deployment. Requiring developers to do so would make it easier for public bodies to meet both their transparency obligations and obligations to ensure decisions are fair, lawful and non-discriminatory decision.

Transparency is just one example of how diffuse responsibility can undermine accountability. So, the Committee is right to focus both on who should be liable for different AI risks, and on when in the AI lifecycle obligations must take effect. A failure to do so would be particularly problematic when public bodies use AI to assist with rights-critical decisions, with potentially harmful consequences for marginalised individuals and communities who are often most reliant on public services (a point which PLP included in its evidence and which the Committee agreed with at [134]). For example, bias in a system may originate in training data or a system’s design, shaped by upstream decisions made by its developer.4

Conclusion 

The Committee’s report rightly emphasises that any AI Bill must ensure that public decision-making does not become less accountable through AI use. This cannot be done by focusing exclusively on frontier systems. It will require us to make public-sector AI use more transparent; clarify and enforce the legal standards that govern AI-assisted decision-making; and ensure responsibility sits with the right actors at the right stages of the AI lifecycle. 

Read Public Law Project’s full evidence here.

References

1 Reflecting the distinction drawn in Leslie, M. (2024) ‘Securing meaningful transparency of public sector use of AI: comparative approaches across five jurisdictions‘, Public Law Project. 

2 Article 22C, UK GDPR (as amended by the Data (Use and Access) Act 2025). 

3 As was generally required under the UK GDPR (subject to specified exemptions) before the Data (Use and Access) Act 2025 weakened the requirement so that it only applies where special category data (as defined in Article 9) has been used. 

4 See, notably, R (Bridges) v Chief Constable of South Wales Police [2020] EWCA Civ 1058.