{"id":147018,"date":"2026-08-12T09:19:05","date_gmt":"2026-08-12T09:19:05","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=147018"},"modified":"2026-08-12T09:32:53","modified_gmt":"2026-08-12T09:32:53","slug":"united-kingdom-artificial-intelligence","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/united-kingdom-artificial-intelligence\/","title":{"rendered":"United Kingdom: Artificial Intelligence"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-147018","comparative_guide","type-comparative_guide","status-publish","hentry","guides-artificial-intelligence","jurisdictions-united-kingdom"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Shoosmiths LLP<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2020\/01\/logo.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Shoosmiths LLP<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2020\/01\/logo.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of Artificial Intelligence laws and regulations applicable in United Kingdom<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What is the legal definition of \u201cartificial intelligence\u201d in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The White Paper issued by the UK government in March 2023 (last updated in August 2023 \u2013 &#8220;A pro-innovation approach to AI regulation&#8221;) noted &#8220;there is no general definition of AI that enjoys widespread consensus&#8221;. A Research Briefing issued more recently in June 2026 (\u201cAI regulation in the UK\u201d) echoes this sentiment, and states \u201cArtificial intelligence can take many different forms and there is no single, universally agreed definition\u201d. The UK government\u2019s approach instead focuses on the following core characteristics of AI: &#8220;adaptivity&#8221;, whereby AI systems can infer patterns and connections in data which are not easily discernible to humans; and &#8220;autonomy&#8221;, whereby AI systems possess the capability to make decisions independently of human input.<\/p>\n<p>The draft UK Artificial Intelligence (Regulation) Private Members&#8217; Bill (the \u201cBill\u201d), defines AI as &#8220;Technology enabling the programming or training of a device or software to perceive environments and use data to make decisions or take actions&#8221;. The Bill was initially introduced in 2023, and re-introduced into the House of Lords in 2025, but has made no progress (see further in Question 3 below).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In January 2025, the UK government published a policy paper (&#8220;AI Opportunities Action Plan: Government Response&#8221;), endorsing all recommendations set out within the related AI Opportunities Action Plan (commissioned in July 2024 and authored by Matt Clifford CBE). The 50 advisory recommendations within the Action Plan focus on investment and cross-sector collaboration, intended to position the UK as an &#8220;AI maker&#8221;. The UK government has shown firm commitment in implementing the Action Plan, having since published the Industrial Strategy Digital and Technologies Sector Plan (the \u201cModern Industrial Strategy\u201d), outlining the actions taken by the government to-date and building on proposals to be implemented over the coming decade. In January 2026, the Starmer Labour government published a further policy paper (\u201cAI Opportunities Action Plan: One Year On\u201d), outlining how it has delivered against the recommendations in the Action Plan. At the time of publication, the Starmer Labour government had reported delivering against 38 of the 50 actions.<\/p>\n<p>In July 2026, Andy Burnham became the UK Prime Minister, succeeding Sir Keir Starmer. The Burnham Labour government has already announced broad changes to the machinery of government, including the abolition of the Department for Science, Innovation and Technology (\u201cDSIT\u201d), which was formerly responsible for overseeing certain AI-related elements of the Modern Industrial Strategy. The functions previously within DSIT have been redistributed across government. A new Minister for Artificial Intelligence role has been created within Cabinet, alongside an AI Taskforce, both designed to \u201cdrive the Government\u2019s overall strategy on AI and unlock the opportunities it holds for growth, prosperity and public sector transformation\u201d.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be\/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The UK has not yet implemented clear rules or guidelines on AI. The government\u2019s White Paper (see Question 1) does, however, set out a regulatory framework that aims to be &#8220;pro-innovation, proportionate, trustworthy, adaptable, clear and collaborative&#8221;. It identifies five &#8220;values-focused cross-sectoral principles&#8221; for AI regulation. These are: (1) safety and security; (2) transparency and explainability; (3) fairness; (4) accountability and governance; and (5) contestability and redress. These principles are intended to guide businesses in designing, developing, and using AI in a responsible manner, and are referred to as a principles-based approach.<\/p>\n<p>Under the principles-based approach, Regulators are required to publish their own sectoral guidance. Indeed, the main UK regulators, including the Financial Conduct Authority (\u201cFCA\u201d), Competition and Markets Authority (&#8220;CMA&#8221;) and the Information Commissioner\u2019s Office (&#8220;ICO&#8221;) have published documents outlining their strategic approaches to regulating AI generally, as well as guidance relating to discrete elements of the technology. By way of example, in March 2026 the CMA published guidance for organisations on complying with consumer law when deploying AI agents.<\/p>\n<p>To the limited extent that AI is currently specifically regulated in the UK, this is implemented through existing legal frameworks such as the data protection regime and intellectual property laws (see as further discussed within). Some chatbots and AI-generated material are regulated by Ofcom under the Online Safety Act, and the government has put in place a legal framework for specific controls on non-consensual deepfakes and a greater range of chatbots which pose a risk of harm.<\/p>\n<p>As noted above in Question 1, the Bill introduced in 2023 seeking to regulate artificial intelligence has not progressed. As a private members bill, it would require significant parliamentary support to progress.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers\/clients?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>As noted above, to the limited extent that AI is specifically regulated within the UK, this is implemented through existing general legal frameworks, with oversight from sector-specific regulators. For example, the CMA states that organisations must not mislead, and must therefore disclose the use of AI agents to consumers.<\/p>\n<p>The position on transparency and explainability in relation to automated decision making under UK data protection legislation is explained further in Question 13 below. The ICO has published the following guidance, \u2018Explaining decisions made with AI\u2019 (here). Transparency and explainability also feature as one of the five &#8220;values-focused cross-sectoral principles&#8221; for AI regulation which are contained within the UK government White Paper (see further at Question 1).<\/p>\n<p>Professional services firms will be required to disclose the use of AI in their work in accordance with professional standards. For example, the Solicitors Regulation Authority makes it clear that law firms are responsible for informing clients of the use of AI in relation to their matter (Risk Outlook report: The use of artificial intelligence in the legal market \u2013 November 2023).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes, individuals have a qualified right not to be subject to solely automated decision-making if the processing involves special categories of data under the UK data protection regime. Organisations are therefore required to build meaningful human review into any such decision-making processes (see further below at Question 13). Human input is also particularly important where AI is used within employment contexts given the increased uptake of AI systems within the workplace (see further discussion below at Question 12).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Discriminatory outcomes from the use of AI systems may contravene the protections in the Equality Act 2010. UK data protection legislation also states that controllers must only process personal data in ways that people would expect and not use it in ways that may cause unjustified adverse effects (see further below at Question 13). Organisations that utilise AI in ways that fall outside the reasonable expectations of data subjects may be at risk of breaching the data protection principle of fairness.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>As the UK does not have an overarching AI legislative framework, defective AI systems will be dealt with by existing common law and\/or statutory causes of action available under UK law, on a fact-specific basis in the context of the deployment and use of those systems and the nature of harm caused in each case. The potential routes for liability (discussed further below) include contractual liability, the tort of negligence (if a duty of care is owed between parties), and product safety legislation (where the AI is integrated into a product) under the Consumer Protection Act 1987.\u00a0 The Consumer Rights Act 2015 may also protect consumers where they have entered into a contract for AI-based products and services.<\/p>\n<p>Criminal liability may be established in respect of harm caused by an AI system if it can be attributed to a legal person. For example, in the most extreme cases, a corporate entity can be liable for corporate manslaughter under the Corporate Manslaughter and Corporate Homicide Act 2007.\u00a0 Recent legislation (namely s.250 of the Crime and Policing Act 2026) has also significantly expanded the corporate criminal liability regime in the UK, with the result that organisations may now be held criminally liable where a senior manager commits any criminal offence when acting within the actual or apparent scope of their authority.<\/p>\n<p>AI systems present a potentially complex nexus of liability between the different parties within the AI supply chain, ranging from developers through to corporate customers and any ultimate end-users. Currently there is no AI-specific statutory basis on which responsibility or liability for claims related to harm caused by AI is allocated between parties in the UK (in common with many other jurisdictions). As such, claims will be managed in accordance with the existing statutory and common law rights and causes of action outlined above.<\/p>\n<p>In July 2026 the UK Jurisdiction Taskforce published its final legal statement on Liability for AI Harms under the private law of England and Wales.\u00a0 The statement does not have binding legal effect but aims, through authoritative commentary on generic scenarios of wide application, to reduce perceived uncertainty as to whether and, if so, how English law is likely to impose liability on a person where (non-deliberate) harm results from the use of AI. The UKJT\u2019s overarching conclusion is that English law, as a well-developed and flexible common law system adept at accommodating technological developments, is generally capable of addressing questions of liability for AI-related harm through existing legal principles. Where there is a contractual relationship between the relevant parties, those contractual arrangements will be the primary basis on which liability is allocated.\u00a0 The UKJT does not foresee any special difficulty in applying the usual principles of contract law in an AI context.<\/p>\n<p>In the absence of a contractual relationship, liability for AI harm may in principle be established in the tort of negligence where it can be shown that one party owed a duty of care to another, that it breached that duty of care, and that the breach has caused loss\/damage.\u00a0 Again, the UKJT does not anticipate any major difficulties in applying the normal principles of the law of negligence in an AI context.\u00a0 As in any other negligence claim, the defendant may reduce its liability by establishing that the claimant\u2019s own negligence also caused and\/or the acts or omissions of a joint tortfeasor (i.e. a third-party wrongdoer) also contributed to the harm caused.\u00a0 Any contribution claim against a third party must be brought either as a \u2018Part 20\u2019 claim within any existing proceedings, or as a standalone claim within two years of judgment\/settlement establishing the liability in respect of which contribution is sought.<\/p>\n<p>Liability for AI-generated statements may arise in negligent or fraudulent misstatement, defamation or deceit to the extent the statement is attributable to a legal person.\u00a0 For example, where a human editor has reviewed but not adjusted a defamatory statement in a draft article produced using an AI tool which is then published online, or where the developer of an AI chatbot has been reckless as to the accuracy of the output the chatbot will produce. One point of difference is that since an AI system has no legal personality itself, a separate legal person (i.e. an individual or corporate entity) cannot be held vicariously liable for the acts\/omissions of such a system.\u00a0 However, this does not affect the legal analysis in other scenarios where a person may be held liable for the acts\/omissions of another where the use of AI is involved.\u00a0 For example, an employer may be vicariously liable for an employee\u2019s negligent use of an AI tool, and an NHS Trust (owing non-delegable duties to its patients) may be primarily liable to a patient for harm caused by a defective AI diagnostic tool.<\/p>\n<p>If the AI system is embedded in a product, a claim can be pursued against any of the following: (i) the producer (i.e., the manufacturer), (ii) a person who holds themselves out as a producer, or (iii) the importer of the product into the UK under the Consumer Protection Act 1987. As to any product liability claim, (and in common with negligence claims), the defendant may seek a contribution where the third party is liable to the claimant for the same damage\/loss.<\/p>\n<p>As there is no current AI-specific statutory basis for determining claims in the UK, the burden of proof in AI-related cases will depend on the cause of action (as with general civil claims). The most common burden of proof in civil claims in England and Wales is for the claimant to prove their case on the balance of probabilities. In criminal cases, the prosecution must prove the offence was committed beyond all reasonable doubt. However, various statutory causes of action may differ. For example, the Consumer Protection Act 1987 imposes strict liability on manufacturers of defective products.\u00a0 This means the claimant must simply prove that the product is defective and that the defect most likely caused the damage which is the subject of the claim, but they do not need to show that the manufacturer was negligent. Claimants should therefore seek advice as to the specific merits of an individual case, and any necessary burden of proof that needs to be met for that claim to be brought, in respect of any prospective claim involving AI.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What cybersecurity obligations apply to AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under UK data protection legislation, data controllers and processors must put in place measures to ensure appropriate security of personal data. Various aspects of AI system design, including the increased attack interface, the variety of data sources, and complexity of data sharing especially through agentic AI, make cybersecurity an important consideration in system design and operation. The ICO has recently issued more fines for cybersecurity breaches including a \u00a314 million fine of outsourcer Capita, announced in October 2025.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Is the use of artificial intelligence insured and\/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The use of AI is insurable in the UK, and insurers are increasingly offering tailored products to address AI-related risks. The market has seen the development of specific policies covering AI performance risk, including third-party liability arising from the operation or failure of AI systems. These policies are particularly relevant in high-risk sectors such as healthcare, finance and autonomous technologies. In addition to bespoke AI policies, general liability policies, such as professional indemnity, directors\u2019 and officers\u2019 liability, cyber, and technology errors and omissions, may also respond to AI-related losses, even if not explicitly referenced. Insurers are, however, increasingly reviewing policy wordings and introducing exclusions to limit unintended exposure to so-called &#8220;silent AI&#8221; risks. Insurers will consider carefully the nature of the technology, its intended use and the insured\u2019s risk mitigation strategies during the underwriting process, and will price accordingly. Particular attention is paid to the transparency, explainability, and governance of AI systems, especially where decision making is automated or semi-automated.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In the UK, patent applications must name a human as the inventor or inventors. Although patent applications have been submitted in UK cases which have named AI as an inventor, the courts have consistently refused to recognise inventorship. The Supreme Court finally determined this position, ruling unanimously that a patent application naming an AI machine, rather than a natural person, as the inventor is invalid under the UK Patents Act 1977.<\/p>\n<p>The Intellectual Property Office has recognised that technology developments mean that AI is making significant contributions to innovation, and held a consultation to consider whether the current rule for inventorship could potentially be improved to better support innovation and incentivise the generation of new AI-devised inventions. The outcome was that for the time being there will be no change to the rule that patent applications must name a human as the inventor.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Do images or works generated by and\/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In the UK, images or artistic works may benefit from copyright protection to the extent they are original, i.e., the author\u2019s own intellectual creation. The threshold for originality in the UK is low and does not require particular creativity, although the author will have given the work their &#8220;personal touch&#8221;. It is certainly the case that images may be created by a human who has assistance from AI, and, provided the work meets the usual threshold for originality, it will benefit from copyright protection like a work created using any other tool.<\/p>\n<p>Issues of copyright ownership may arise, however, because the technology underpinning AI must be trained and improved through exposure to large datasets, including the vast number of images available on the Internet. These images are protected by copyright as artistic works. Although UK copyright law generally permits text and data mining of copyright works for non-commercial purposes, many AI platforms&#8217; commercial aspect means this fair-use exception cannot necessarily be relied upon. For example, if AI is directed to create &#8220;an image in the style of David Hockney,&#8221; it may return an image similar or identical to an existing David Hockney work, calling into question the originality and ownership of the AI-generated image and risking copyright infringement for the human creator.<\/p>\n<p>Images generated by a computer where there is no human creator are capable of copyright protection. The &#8220;author&#8221; of a &#8220;computer-generated work&#8221; is defined as &#8220;the person by whom the arrangements necessary for the creation of the work are undertaken&#8221;. There is a degree of ambiguity, however. In the case of images generated through an AI platform, this could mean that the person directing the AI through keywords or instructions is deemed the author. Alternatively, the creator of the AI platform itself could assert ownership, although many AI platforms clarify through their terms and conditions that ownership of any AI generated work vests in the user, thereby passing over to the user any risks of third-party claims of infringement.<\/p>\n<p>The UK government&#8217;s March 2026 Report on Copyright and Artificial Intelligence expressly notes that the law relating to computer-generated works remains under review, but no legislation has yet been passed in the UK to give certainty around ownership of copyright in AI generated images.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Five main issues for businesses to consider when using AI in the workplace are:<\/p>\n<ol>\n<li><strong>Discriminatory outcomes and algorithmic bias:<\/strong> The risk of AI producing discriminatory and\/or biased outcomes that may expose businesses to potentially expensive discrimination claims, regulatory scrutiny and PR damage. This risk is particularly relevant where AI is used in recruitment, promotion, performance assessments, disciplinary processes or redundancy exercises. Employers remain responsible for decisions influenced by AI and cannot avoid liability by relying on automated systems.<\/li>\n<li><strong>Data protection, privacy and employee monitoring:<\/strong> AI systems often rely on large volumes of personal data and may be used to monitor employee activity, productivity or workplace behaviour. Businesses must ensure compliance with applicable data protection laws, particularly in relation to transparency, fairness and automated decision making. Employers should also consider employee expectations of privacy and whether monitoring is proportionate and justified.<\/li>\n<li><strong>Changes in established working practices and roles:<\/strong> Increased use of AI is expected to result in increased efficiency and cost savings for businesses. This is likely to lead to: employees working more with AI systems as opposed to people; opportunities for some employees to carry out higher-value or more interesting work; and, potentially, redundancies where AI performs all or part of certain existing work functions within a business.<\/li>\n<li><strong>Managing communication with employees:<\/strong> Businesses will need to carry out required impact assessments and communicate clearly with employees to address legal constraints and allay concerns regarding privacy and monitoring when implementing AI systems in the workplace. Employees may be concerned that their role may be replaced in certain scenarios, and may choose to leave before that happens, when in fact the business may have had no plan to replace such roles.<\/li>\n<li><strong>Governance and human oversight:<\/strong> Businesses may become increasingly dependent on AI systems, so will need to develop and maintain adequate operational plans to address situations where these systems fail or are temporarily unavailable. Businesses will also need to be satisfied that there is sufficient human involvement and oversight of the AI systems, both at the time they are being designed and implemented, and on an ongoing basis. Meaningful human input reduces the risk of inadvertent discrimination caused by bias in the AI algorithm. To reduce both discrimination and data protection risks, an employer should ensure a human has final responsibility for any significant decisions made or impacted by AI, particularly where there is the potential for dismissal.<\/li>\n<\/ol>\n<p>A further development is the increasing use of generative AI by employees themselves. Employees are increasingly using AI tools to draft grievances, whistleblowing complaints and tribunal claims. While this may improve accessibility and efficiency, it can also lead to more sophisticated workplace complaints and increase the risk of inaccuracies or unsupported allegations. Employers and HR teams should ensure that workplace processes are sufficiently robust to deal with AI generated content and remain focused on the underlying facts.<\/p>\n<p>Existing UK employment laws apply in the normal way in relation to the employment and treatment of personnel within a business, irrespective of whether their role interacts with or involves the use of AI. However, regulators have increased their focus on AI-assisted employment practices, particularly in recruitment, performance management and employee monitoring. Recent regulatory guidance has highlighted concerns around transparency, bias and the use of solely automated decision-making without meaningful human involvement. As a result, meaningful human oversight is increasingly viewed as a key safeguard and has featured prominently in proposed AI legislation and policy recommendations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What are the main privacy\/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p><strong>a. Automated decision making.<\/strong> AI can be used to make automated decisions about individuals. The UK General Data Protection Regulation (&#8220;UK GDPR&#8221;) requires compliance measures where individuals are subject to a solely automated decision, including profiling, which produces a legal or similarly significant effect. Organisations must implement suitable measures to safeguard individuals\u2019 rights, freedoms and legitimate interests, including by providing human intervention so individuals can contest a decision. Individuals have a qualified right not to be subject to solely automated decision-making if the processing involves special categories of data under Article 9 UK GDPR.<\/p>\n<p><strong>b. Transparency.<\/strong> The UK GDPR requires organisations to provide individuals with meaningful information about the logic involved, as well as the significance and the envisaged consequences of automated decision-making. This can present challenges given the complexities of AI algorithms. If the information provided is too technical, individuals may struggle to interpret it. Organisations must therefore deliver information in a clear fashion. Further challenges arise when AI is trained using personal data scraped from the internet. Providing the information required under Article 14 UK GDPR to data subjects in this context can be operationally challenging. Controllers often seek to rely on one of the exemptions under the UK GDPR and UK Data Protection Act 2018 (&#8220;DPA 2018&#8221;) to the right to be informed, such as impossibility or disproportionate effort. The Data (Use and Access) Act 2025 clarified (at least in the UK) that controllers may rely on the exemption even when not processing for scientific research and statistical purposes. However, determining whether such an exemption applies is not always clear cut. Furthermore, controllers who seek to rely on an exemption must consider the effect of such reliance on the overall lawfulness, fairness and transparency of the processing and whether additional safeguards are required.<\/p>\n<p>The ICO cautions that processing of this nature, i.e., &#8220;invisible processing&#8221;, results in additional risks to a data subject as they cannot exercise control over the use of their data. In such circumstances, privacy information should still be published on the controller\u2019s website and the controller should carry out a data protection impact assessment.<\/p>\n<p><strong>c. Data Protection Impact Assessments (&#8220;DPIAs&#8221;).<\/strong> Under the UK GDPR, a DPIA is mandatory if the processing of personal data is likely to result in a high risk to the rights and freedoms of individuals. A DPIA\u2019s purpose is to identify and minimise the data protection risks associated with a project. It is likely that the use of AI will trigger the need for a DPIA where this involves the processing of personal data. Additionally, a prior consultation with the ICO may be required if the DPIA indicates that the processing would result in a high risk to individuals which cannot be suitably mitigated. The ICO has shown a tendency to closely examine DPIAs in the context of AI systems, and has published guidance on DPIAs in the context of AI (here) which makes it clear that the &#8220;vast majority&#8221; of AI use cases will require a DPIA.<\/p>\n<p><strong>d. Data minimisation.<\/strong> Processing large amounts of data is central to AI. Organisations will need to balance this need with the data minimisation requirement under the UK GDPR, which requires that organisations only process personal data to the extent it is adequate, relevant, and necessary.<\/p>\n<p><strong>e. Vendor due diligence.<\/strong> Most AI systems are provided by third parties, which means vendor due diligence plays a crucial role in ensuring organisations can comply with their data protection obligations. The ICO cautions that assurances from the AI vendors should be sought about any bias testing they conducted, or the controller should test the model themselves. Organisations must also ascertain the data protection roles of vendors and, where relevant, implement compliant data processing terms with third parties that process personal data on their behalf as processors.<\/p>\n<p><strong>f. Controller\/processor\/joint controller roles.<\/strong> Identifying controller, joint controller, and processor roles in the context of AI can be complex, not least because many parties are involved in the development and deployment of AI systems. The ICO has published initial guidance and scenarios to assist with the assessment (here), which includes indicators of when an organisation may act as a controller in the context of an AI system.<\/p>\n<p><strong>g. Lawful basis for training data.<\/strong> Most AI systems rely on publicly accessible sources for their training data. Where training data contains personal data, processing is subject to the UK GDPR. It can, however, be difficult to identify an applicable lawful basis to such web scraping activities. &#8220;Legitimate interests&#8221; may not be an available basis if data is processed in ways the data subject does not reasonably expect or privacy information is not provided. Obtaining training data via web scraping, in most cases, will be invisible processing. The ICO\u2019s latest position on determining whether there is a valid lawful basis for web scraping (in the context of training generative AI) is available here. Legitimate interests is the only available basis and the balancing test must be carried out. The Open Rights Group lodged a complaint with the ICO against Meta in 2024 over UK GDPR violations related to Meta\u2019s plans to use personal data for AI model training, alleging &#8220;clear intentional breach of the law&#8221; including lack of legitimate interest and a lack of transparency. Following engagement with Meta, the ICO issued a statement in October 2024 but is considered unlikely to take further legal action. ICO guidance on various unresolved aspects of AI development and use is scheduled for later in 2026 including Agentic AI, anonymisation for research, and ADM and profiling.<\/p>\n<p><strong>h. Fairness and accuracy.<\/strong> Under the UK GDPR&#8217;s fairness principle, controllers must only process personal data in ways that people would expect and not use it in ways that may cause unjustified adverse effects. Ensuring the statistical accuracy of AI outputs is part of this fairness principle. The UK GDPR (at Recital 71) highlights the need for statistical accuracy in automated decision-making, and states organisations should put in place &#8220;appropriate mathematical and statistical procedures&#8221; for the profiling of individuals. The ICO provides guidelines for technical specialists and compliance professionals on fairness here.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Data scraping by UK entities may be prohibited as follows:<\/p>\n<p>Database right: Depending on the geographical location where the database holding any source data was made, extraction and reutilisation of all or a substantial portion of data from that database may be a violation of the EU sui generis database right and\/or its UK equivalent.<\/p>\n<p>The EU sui generis database right protects data held in databases which were either (i) made in an EU member state where there has been a &#8220;substantial investment&#8221; in obtaining, verifying, or presenting the contents of the database; or (ii) made in the UK prior to 1 January 2021. Following Brexit, a similar right exists in the UK in respect of databases made in the UK.<\/p>\n<p>A person resident in the UK who conducts widespread data scraping may violate the rights of an EU organisation or a UK organisation which has invested in its database.<\/p>\n<p>Privacy: As a processing activity, data scraping is regulated by the ICO and subject to UK data protection laws, ICO guidance and applicable case law.<\/p>\n<p>In August 2023 the ICO and 11 other Data Protection Authorities published a joint statement calling for the protection of personal data from unlawful data scraping on social media sites. The statement sets out expectations for how social media companies should protect personal data from unlawful data scraping, which may lead to increased vigilance in this context from social media companies.<\/p>\n<p>Following consultation, the ICO finalised its position (here) on the issue of whether there is an applicable lawful basis for data scraping. It confirms that &#8220;legitimate interests&#8221; is the only available lawful basis and will require developers to pass the necessity test and the balancing exercise with data subject rights. The ICO has stated that to carry out data scraping in compliance with the UK GDPR, and for any lawful basis to be available, the relevant controller must do so in compliance with the law (and particularly the lawfulness principle under Article 5 UK GDPR), including any applicable website terms and conditions. New guidance on the applicability of new Article 84A on processing for scientific research, is under consultation, and ICO guidance on Agentic AI, anonymisation for research, and ADM and profiling, is expected in 2026.<\/p>\n<p>Copyright: Copyright may protect the contents of a database, or individual items of source data, where the data in question are considered copyright works under the Copyright, Designs and Patents Act 1988. Where a person resident in the UK undertakes data scraping in respect of the collection of images, photographs, articles or similar without the permission of the owner of those data items, this may infringe copyright and leave the scraper facing legal action.<\/p>\n<p>Developments in IP law may influence the legality of data scraping in the UK for AI training. The landmark case of Getty vs Stability AI, commenced in the High Court in June 2025, had the potential to shape the how UK copyright laws are applied in an AI context, particularly in the collection and use of copyright materials for training purposes, but the primary copyright infringement complaint was dropped for jurisdictional reasons. That said, the case has heightened awareness and increased pressure on the government to consider reforming copyright laws around AI training. An ongoing consultation is expected to lead to a legal framework for use of copyright materials in an AI context, and is expected to influence best practice. Proposals aim to balance developer access to data for AI training by way of a text and data mining exemption, with protection of rights for copyright owners through transparency and compensation mechanisms. Despite the UK Government publishing its report on Copyright and Artificial Intelligence in 2026, and rules relating to transparency and reporting coming in force under recent legislation, the position around the permitted use of text and data in training of AI remains unclear.<\/p>\n<p>Breach of terms and conditions: Many database owners specifically reserve all rights in their source data, and apply terms and conditions which specifically prohibit the collection or use of any data gathered in this way. Any UK person who scrapes data from any source \u2013 whether UK or overseas, may face a claim under one or more of the aforementioned grounds.<\/p>\n<p>Competition: In a report published in 2024, the CMA observed that limitations on the ability to use web-scraped data could benefit those holding the data or with resources to purchase access to data. The CMA also noted that imbalances could emerge between early movers and later entrants in the ability to train models on web-scraped data, and that developments in firms\u2019 abilities to use web-scraped data could impact the range of models available to deployers and users.<\/p>\n<p>These concerns remain particularly relevant in light of the 2025 CMA investigation into Google\u2019s general search and search advertising services, and whether the search engine should be designated as having strategic market status (SMS) under the Digital Markets, Competition and Consumers Act 2024. In June 2026 the CMA issued its decision confirming that Google would be designated as having SMS in respect of general search services, and accordingly, would be made subject to certain conduct requirements (stipulations which seek to address any adverse impact on competition). One such requirement is designed to provide publishers with more control over how their data is used within Google\u2019s AI Overviews. Google must make available controls which allow publishers to opt out of their content being used within Google\u2019s AI Overviews. Google must also ensure that any such publisher content which is used within its AI Overviews is properly attributed to the respective publisher.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">To what extent is the prohibition of data scraping in the terms of use of a website enforceable?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are no reported cases in England and Wales on the enforceability of terms prohibiting data scraping. However, a European Court of Justice case prior to Brexit (Ryanair Ltd v PR Aviation BV) supports the proposition that such terms would be enforceable. In the absence of directly applicable reported judgments, enforceability would depend on the principles of English contract law.<\/p>\n<p>Separately from any potential actions for breach of contract, the ICO\u2019s position at the time of writing is that data scraping carried out in breach of website terms and conditions cannot comply with the lawfulness requirements under Article 5 UK GDPR, and therefore will be in breach (see Question 13). In terms of enforceability:<\/p>\n<ul>\n<li>a data subject may complain (either to the ICO or bring a court claim), as a result of damage they have suffered due to the breach of the UK GDPR;<\/li>\n<li>the ICO could bring enforcement action, issue fines, or issue an order to cease the processing activity, against the relevant controller;<\/li>\n<li>criminal liability may arise under section 170 of the DPA 2018, which sets out an offence of obtaining or disclosing personal data without the consent of the controller.<\/li>\n<\/ul>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The UK does not have a central AI regulator or authority. That said, the Digital Regulation Cooperation Forum (\u201cDRCF\u201d) is a collaborative forum comprising the following UK regulators who are responsible for digital regulation: the ICO; Ofcom; the CMA; and the FCA.\u00a0 The DRCF is designed to assist organisations who operate across multiple sectors.<\/p>\n<p>In July 2026, the UK\u2019s new Prime Minister, Andy Burnham announced broad changes to the UK government\u2019s machinery designed to empower local leaders and drive economic growth.\u00a0 The changes include the abolition of the Department for Science, Innovation &amp; Technology (\u201cDSIT\u201d) a stand-alone ministerial department created in 2023 to deliver on the then-government\u2019s ambition to be a global science, innovation and technology leader.<\/p>\n<p>DSIT\u2019s functions will be redistributed across the newly expanded Department for Business, Innovation, Science and Trade (\u201cDBIST\u201d) and the Department for Digital, Culture, Media and Sport (\u201cDCMS\u201d). Responsibility for AI strategy, public sector AI adoption and the AI Security Institute will move to the Cabinet Office under this reshuffle.\u00a0 Kanishka Narayan has been appointed Minister for Artificial Intelligence and will lead the new AI Taskforce, which has been established to \u201cdrive the Government\u2019s overall strategy on AI and unlock the opportunities it holds for growth, prosperity and public sector transformation\u201d. Lord Vallance has been appointed Chair of the AI Taskforce and will report directly to the Prime Minister.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>According to recently published Tech Nation Report (\u201cThe Tech Nation Report 2026: The Next Wave of UK AI\u201d), AI companies have contributed around $255 billion to the UK economy. After the US and China, the UK is the third largest AI market in the world.\u00a0 The UK government has also delivered against multiple actions set out in AI Opportunities Action Plan (January 2025), and has launched an AI Playbook for the public sector (\u201cArtificial Intelligence for the UK Government\u201d &#8211; February 2025) which provides public sector organisations with technical guidance on the use of AI and how to mitigate risks.\u00a0 Use of AI within the legal sector appears to be increasing, see further below.\u00a0 The recently published Mills Review (\u201cAI and the future of retail financial services (The Mills Review)\u201d \u2013 July 2026) sets out how AI might transform the retail financial services sector by 2030 and beyond.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">How is artificial intelligence used in the legal sector, by lawyers and\/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>AI use in the UK legal sector appears to be rising. LexisNexis\u2019 August 2025 report (\u201cThe AI Culture Clash\u201d) found that 61% of UK lawyers now use AI, representing an increase from the 46% reported in January 2025.\u00a0 Only 9% of respondents to the survey stated that there was a \u2018resistance or fear around use of AI.\u2019\u00a0 Over 51% of respondents said they prefer AI tools built specifically for legal work, as opposed to general purpose AI tools which are also available on the market.\u00a0 The Law Society also recently issued guidance on the risks and opportunities presented by use of agentic AI in law firms (\u201cThe Law Society Foresight Report: Shaping the Future of Agentic AI in Legal Practice\u201d \u2013 February 2026).<\/p>\n<p>Recent concerns around use of AI in the legal profession have centered on use of publicly available AI tools in legal practice, and the potential loss of confidentiality and legal professional privilege (LPP) which may result from such use.\u00a0 The recent judgement in R (Munir) v Secretary of State for the Home Department [2026] UKUT 81 (IAC) provides clear guidance to legal professionals on their obligations in using AI tools and the potential consequences for confidentiality and LPP.\u00a0 Case law has been developing around the use of AI by lawyers and parties to litigation, in particular the consequences of \u2018hallucinated\u2019 material being put before the Court (e.g. R (Ayinde) v The London Borough of Haringey [2025] EWHC 1383 (Admin) and Cork v Smith [2026] EWHC 1199 (Ch)).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Five key challenges include:<\/p>\n<ol>\n<li>The rapid pace of AI development, which can outstrip the creation of traditional regulation. This &#8220;pacing problem&#8221; means that legal standards do not typically reflect AI\u2019s latest technological capabilities, presenting challenges for lawyers advising clients on the law in this area. Law firms may also lack guidelines for internal AI use cases.<\/li>\n<li>Trust in adopting AI technology. If lawyers do not trust AI and its output, they are less likely to use it. As AI deployment progresses, the issue of trust is likely to grow and will need to be managed carefully, particularly following well-publicised instances where fictitious case law and fake citations have been included in AI-drafted legal documents. Different use cases have different risk profiles and firms (and their clients) will work within their own risk appetites. Equally, uncertainty around the impact on confidentiality and privilege may impede adoption to some extent, however again the risks in this respect will vary between tools and use cases.<\/li>\n<li>Uncertainty if a &#8220;patchwork&#8221; of laws is created in the UK, and a possible risk of duplication or gaps in the law, particularly as the government\u2019s proposals do not anticipate a significant consolidated oversight body to ensure regulatory consistency.<\/li>\n<li>Disruption within the legal job market. The rapid advancement of agentic AI solutions may reshape the legal workforce, reducing demand for certain roles while creating new opportunities and areas of specialisation (see further below).<\/li>\n<li>Recent changes to machinery of government (including the abolition of DSIT as described above in Question 2) could result in short- to medium-term uncertainty around policy, investment, prospective regulatory approaches and AI adoption. However, such changes may also be viewed as an opportunity to reassess priorities and develop new approaches to AI governance and innovation.<\/li>\n<\/ol>\n<p>Five key opportunities include:<\/p>\n<ol>\n<li>New areas of legal advice. Lawyers should be well-placed to advise on new laws and regulations that seem likely to come into being over the coming years. UK lawyers should have the opportunity to help develop these rules in a way which can help build trust in AI within the UK and beyond.<\/li>\n<li>New business models. Businesses may be able to use AI to develop new business models, which could change how legal services are delivered, a prime example being the SRA\u2019s 2025 approval of an AI-driven law firm. There should be opportunities for development and implementation of new AI-powered products and solutions.<\/li>\n<li>The opportunity to &#8220;go global&#8221;. UK legal businesses may be able to leverage the UK\u2019s global reputation and use AI to create products and solutions which can be rolled out internationally, particularly in countries with common law legal systems.<\/li>\n<li>The opportunity to &#8220;add value&#8221;. Lawyers may increasingly struggle to compete against AI for certain tasks. This should lead to a greater focus on specific client needs and more complex tasks where lawyers can provide personalised and bespoke support, supplemented by AI.<\/li>\n<li>Disruption within the legal job market. The growing demand for specialist AI tools designed for legal professionals has the potential to reshape the legal workforce, with roles such as legal innovation specialists and legal engineers becoming increasingly prominent.<\/li>\n<\/ol>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The recent creation of a Cabinet-level ministerial position, dedicated to AI, suggests that the technology remains a significant policy priority for the UK government over the next 12 months. The decision to integrate DSIT\u2019s functions into existing departments reinforces this view, reflecting the Government\u2019s stated position that AI and related technologies are not distinct sectors of the economy, but increasingly underpin economic activity across a wide range of industries.<\/p>\n<p>Additionally, we see the rise of agentic AI leading to heightened focus on regulation, responsible governance and changes to the \u2018state-of-the-art\u2019 in privacy and cybersecurity. As AI capabilities continue to evolve and business adoption accelerates, we expect to see a corresponding increase in emerging risks relating to cybersecurity, data privacy and liability. With no horizontal regulatory framework in the UK, the EU AI Act will continue to influence businesses, particularly insurers and cross-border operators, and without domestic legislation to refer to, may cement itself as the de facto standard.<\/p>\n<p>As the risks posed by agentic AI are more complex than traditional generative AI, we are likely to see increased scrutiny of AI governance, new liability frameworks for AI-related harm, and more pressure on AI vendors to provide greater transparency and insights into their internal AI governance and risk management practices.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">7585<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/147018","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=147018"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}