UK Law, Regulation, Governance and Ethics of Artificial Intelligence (AI)
- Heather Connery

- Aug 4
- 9 min read
Updated: Aug 5

The AI Governance Challenge: Keeping Pace with Innovation
Technological innovation has consistently outpaced the development of legal and regulatory frameworks throughout history. Governments have often struggled to regulate emerging technologies at the same speed at which they are developed and deployed. This phenomenon is commonly referred to as the "pacing problem" and is particularly evident with AI.
Several factors contribute to this challenge. First, legislative processes are inherently lengthy and complex, often taking years to enact. Second, regulators and lawmakers may lack the technical expertise to fully understand rapidly evolving AI technologies. Finally, policymakers face the difficult task of balancing innovation and economic growth against important considerations such as consumer protection, public safety, privacy, and competition.
For me, AI can feel more like a technological "Wild West" than previous waves of innovation. Historically, technology adoption has often occurred within relatively well-defined boundaries. However, the emergence of publicly accessible generative AI systems such as ChatGPT, Claude and Grok has placed capability directly into the hands of individuals. This has created a greater reliance on technology companies themselves to establish appropriate safeguards, controls and responsible development practices. I think we can all agree that self-regulation alone is not sufficient.
While law and regulation continue to develop, governance frameworks and industry standards have increasingly filled the gap. Organisations are implementing internal controls and governance mechanisms even where formal legal requirements remain unclear. At the same time, many policymakers and practitioners openly acknowledge that AI is evolving so rapidly that traditional regulatory approaches may struggle to keep pace. Consequently, there has been growing interest in AI ethics frameworks as a means of guiding responsible development and deployment.
There are AI frameworks out there; two well-known ones are…
UNESCO Recommendation on the Ethics of AI (2021) (UK was involved in the development of this) and for those who would like more detail.
The Institute of Business Ethics has done some good work in this space.
AI Law
The most significant AI-specific legislation currently in force is the EU AI Act. The Act entered into force on 1 August 2024 and is being implemented through a phased approach until 2027. This staged implementation is common for major regulatory initiatives, allowing organisations time to prepare and adapt.
The implementation timeline is broadly as follows:
February 2025 - Prohibited AI practices become applicable, and AI literacy obligations commence
August 2025 - General Purpose AI (GPAI) obligations begin to apply
August 2026 - Most provisions become generally applicable
August 2027- Most obligations become applicable from August 2026, with certain regulated-product high-risk AI systems not becoming subject to the Act until August 2027
The EU AI Act adopts a risk-based framework, categorising AI systems according to the level of risk they present. The four categories are:
Unacceptable risk, e.g., certain forms of social scoring and manipulative AI.
High risk, e.g. financial services and creditworthiness assessments.
Limited risk, e.g. systems that require specific transparency obligations, such as informing users they are interacting with AI-generated content.
Minimal risk, e.g. most spam filters or AI-enabled productivity tools, which face minimal regulatory obligations.
The Act seeks to promote strong governance arrangements and risk assessments and management, promote transparency, explainability and the requirement for appropriate people to be AI literate.
In many respects, the AI Act builds upon existing digital regulatory initiatives such as the EU's Digital Operational Resilience Act (DORA), extending established governance and risk management principles into the AI domain. It also includes the OECDAI Principles (which the UK has also factored into their approach).
Whilst compliance with the EU AI Act is a legal requirement for organisations operating within its scope, many organisations are also turning to recognised standards such as:
ISO/IEC 42001 (Artificial Intelligence Management Systems)
ISO/IEC 27001 (Information Security Management Systems)
These provide a good baseline and hygiene when implementing the EU AI requirements. Unlike the European Union, the UK has not adopted a comprehensive AI law. Instead, it has pursued a principles-based and sector-specific approach. The UK Government's AI whitepaper, A Pro-Innovation Approach to AI Regulation, proposes that existing regulators apply five cross-sector principles within their respective domains rather than introducing a single AI regulator. The principles are:
Safety, security and robustness
Appropriate transparency and explainability
Fairness
Accountability and governance
contestability and redress
There have also been attempts to introduce dedicated AI legislation within the UK. One notable example is the Artificial Intelligence (Regulation) Bill, introduced by Lord Holmes of Richmond. The Bill is often viewed as a potential middle ground between the EU's highly structured approach and the UK's existing reliance on sectoral regulation.
However, it remains a Private Member's Bill and has undergone multiple discussions whilst still on its first reading, suggesting limited evidence of political appetite for comprehensive AI legislation in the near term.
AI Regulation
Regulators have largely focused on understanding the risks associated with current AI applications rather than creating entirely new regulatory frameworks. Within financial services, key AI use cases include:
Credit scoring
Fraud detection
Anti-money laundering (AML)
Algorithmic trading
Portfolio management
These applications have the potential to introduce substantial risks relating to bias, transparency, operational resilience and consumer outcomes. The UK's regulatory approach remains primarily sector led. However, the Digital Regulation Cooperation Forum (DRCF) established in 2020, brings together four of the UK regulators with responsibilities for digital regulation - CMA, FCA, ICO and Ofcom. There are other satellite and related governance groups, such as the UK’s AI Security Institute.
In the Finance sector, the Prudential Regulation Authority (PRA) and the Bank of England have focused on the systemic implications of AI adoption, including:
Concentration risk
Third-party dependency
AI model risk
Operational resilience
Whereas the Financial Conduct Authority (FCA) has concentrated on consumer outcomes and market integrity. It has actively sought to encourage responsible innovation through several initiatives, including the AI Lab and Digital Sandbox along with a strategic partnership with NVIDIA.
These initiatives are intended to help firms experiment safely while allowing regulators to better understand emerging risks and opportunities.
AI Governance
The benefits of AI are well documented, and we are all familiar with them. AI has the potential to drive economic growth, enhance productivity, improve decision-making and create new products and services. However, its rapid deployment and widespread adoption have also accelerated concerns regarding:
Algorithmic bias, e.g. hiring practices
Intellectual property rights, e.g., the Society of Authors campaign
Cybersecurity, e.g. Mythos risk
Accountability and liability, e.g. see a plethora of cases, seeing once a week in the press. One that stuck out for me was the landmark case of Mata v Avianca 2023, not the largest fine I have seen.
One of the most significant governance challenges is the opacity of many advanced AI systems, commonly referred to as the "black box problem”, particularly in large foundation models and deep neural networks In many cases, even developers may struggle to fully explain how particular outputs are generated. This creates significant governance concerns, particularly within heavily regulated industries or sectors requiring enhanced safeguarding.
Effective AI governance therefore seeks to ensure that organisations maintain sufficient oversight of systems throughout the AI lifecycle. Recognising these challenges, a growing body of guidance has emerged from organisations such as the Institute of Directors. Much of this guidance focuses on helping boards and senior leadership teams understand their responsibilities for AI oversight and ensuring that AI risks are incorporated into existing governance, risk management and control frameworks.
Increasingly, the role of boards is not simply to approve AI initiatives but to ensure that AI adoption aligns with organisational strategy, risk appetite, legal obligations and ethical principles.
As AI becomes embedded within critical business processes, effective governance will become a key differentiator between organisations that realise the benefits of AI responsibly and those that expose themselves to significant legal, regulatory and reputational risks.
AI and Data Protection
AI and data protection are closely linked. Many AI systems rely on large volumes of data to train, test and operate, making data quality, accuracy and governance critical. Poor-quality data can result in biased outcomes, inaccurate outputs and increased regulatory risk.
Although not designed specifically for AI, the General Data Protection Regulation (GDPR) and UK GDPR provide an important framework where AI involves personal data. Key principles such as lawfulness, fairness, transparency, accuracy and accountability remain highly relevant throughout the AI lifecycle.
Particular challenges arise where training data used to train AI models include personal or sensitive data, or where AI supports automated decision-making in areas such as recruitment, credit assessments or fraud detection. In these cases, organisations must consider privacy, fairness, transparency and the need for appropriate human oversight.
Strong data governance is therefore a fundamental component of responsible AI. Organisations that understand their data, maintain effective controls and monitor AI systems throughout their lifecycle will be better positioned to manage risk, demonstrate compliance and build trust in their use of AI.
AI Ethics
An area of particular interest of mine, and I have been fortunate to have sat on a panel with Jacob Turner almost 10 years ago, discussing cyber ethics. He is one of the UK's leading specialists in AI law, regulation and governance. He has advised the UK Government on AI policy and is frequently cited as an authority on AI regulation and ethics.
Legal scholars such as Jacob Turner have argued that AI creates unique governance and ethical challenges because it can make decisions independently and unpredictably. In his book, Robot Rules: Regulating Artificial Intelligence, Jacob identifies responsibility, rights and ethics as three of the fundamental challenges posed by AI. His work highlights that effective AI governance requires organisations to consider not only legal compliance but also accountability for decisions made by increasingly autonomous systems.
As covered in the intro, ethics is increasingly being used to fill the gap created by the pacing problem. While law and regulation remain under development, organisations are turning to ethical principles to guide responsible AI adoption. However, ethical frameworks are largely voluntary and therefore lack the enforceability of law or regulation.
The Future of AI Governance: Trust, Judgement and Accountability
Perhaps the biggest challenge facing law, regulation, governance and ethics in relation to AI is that nobody appears entirely certain what AI will ultimately become, how it will evolve, or what its long-term implications will be. Governments, regulators, academics and technology firms are all attempting to understand and respond to a technology that is developing at a pace rarely seen before. This creates a fundamental governance challenge: how do you effectively govern something that at present, is at a more detailed level ungovernable?
There are several cultural and societal concerns. One of the most widely discussed is trust. Despite the increasing capability of AI systems, many experts argue that trust may be the wrong objective. Professor Ben Laker has argued that organisations should not seek to trust AI in the same way they trust people; rather, AI should be viewed as a tool designed to perform specific tasks, with appropriate human oversight and challenge. The question, therefore, is not whether AI can be trusted, but whether organisations have appropriate controls in place to validate and monitor its outputs.
Professor Andrew Likierman, whose work has focused extensively on judgement and decision-making, highlights the distinction between information, analysis and judgement. AI may be capable of processing vast amounts of information and generating recommendations, but judgement remains a fundamentally human capability involving experience, context, values and accountability. As AI becomes more embedded in decision-making processes, understanding where human judgement ends and riskier machine assistance begins will become increasingly important.
Accountability presents another challenge. One of the more frustrating aspects of working with AI is that it can be confidently wrong. It may fail to complete a task correctly, require multiple rounds of correction, or produce outputs that ultimately take longer to review and amend than if the work had been completed manually in the first place. Yet when errors occur, there does not appear to be any meaningful accountability. The system simply acknowledges the mistake and moves on (I am doing an upcoming article on this). If organisations would not tolerate such behaviour from an employee without appropriate oversight, performance management or accountability, then why are AI systems increasingly being trusted with decisions that may have significant consequences for individuals and society?
Another challenge is that people are so busy experimenting with AI in their own areas, very few are thinking more broadly, e.g., a recent McKinsey article highlighted the potential for AI to streamline activities such as regulatory reporting, such as on a breach. At the same time, concerns have emerged regarding the use of AI in employment matters, misconduct investigations and other activities that may directly affect individuals: Whilst AI may offer efficiency gains, those benefits must be balanced against fairness, transparency, accuracy and due process.
If AI systems cannot always be relied upon to produce accurate information, lack human judgement and cannot themselves be held accountable, there are legitimate questions about the extent to which they should be involved in decisions where these qualities are essential.
At times, it can feel as though there is little joined-up thinking across the various discussions taking place. On the one hand, organisations are being encouraged to deploy AI to increase efficiency and automate increasingly complex tasks. On the other hand, concerns continue to emerge regarding reliability, bias, transparency and accountability. Reconciling these competing pressures will be one of the defining governance challenges of the coming years (sorry, I will get down off my soapbox).
Suffice it to say that there is a great deal happening in this space, and much of it is evolving in real time. Hopefully, through the various Camelot sessions and wider discussions, we can continue to explore these developments, share experiences and build a collective understanding of both the opportunities and the risks. The objective should not be to be either blindly optimistic or unnecessarily fearful, but instead to approach AI in a pragmatic, proportionate and informed manner.



