Now
America.gov opens its doors, then revises its answers €30bn+EU call for up to seven AI gigafactories Europe’s AI Act: what applies now, and what waits until December 2027 554deepfakes logged in Brazil’s first round; only 371 labelled California signs 13 AI bills, including the “No Robo Bosses Act” 30+AI firms sent the first AI Act information requests Washington and Beijing open an AI incident channel 164AI-made ads in the US midterms, by one count Medicare’s AI pilot: thousands of denials, and an 83-day wait 42signatories to Canada’s voluntary data-centre principles The midterms’ machine-made ads 174MWCape Town data centre now under appeal Pew: global publics trust China more than the US or EU to regulate AI 83 dayswait reported under Medicare’s AI pilot, against a 72-hour standard Indonesia’s AI Rules Are Stuck on the President’s Desk 20home-grown foundation models backed by the IndiaAI Mission Pakistan Writes Rules for the Algorithmic State 2%of Turkish public investment budgets earmarked for AI Cape Town’s Data Centre Fight Puts a Price on AI’s Thirst Turkey Governs AI by Circular, Not Statute ChatGPT Now Answers to Brussels Twice Over Mexico Wants One AI Law. Its States Got There First Washington’s $1 AI Era Is Over. Now Agencies Get the Meter India’s Sovereign AI Bet Meets the Price of Silicon

Deployment Before Law: Britain’s AI Governance Gap

Parliament's human rights committee wants a dedicated AI Bill; the government's cyber legislation leaves frontier developers to volunteer; and the Met is fixing facial recognition cameras in the West End. The UK is deploying first and legislating later.

Policy & Regulation Desk
The Palace of Westminster, London
Photo: David Hunt, CC BY 2.0 · source

By the end of this year, the Metropolitan Police plans to have static, movable live facial recognition cameras operating across London’s West End and Soho. The force reports about 2,500 arrests linked to the technology since early 2024, including 173 from a pilot in Croydon. What it does not have is a statute specifically governing the practice. The Home Office consultation on a legal framework closed in February 2026, and legislation has no firm timetable.

That sequence, deployment first and law later, is the thread running through Britain’s approach to artificial intelligence this autumn. On 14 September Parliament’s Joint Committee on Human Rights (JCHR) published a report that challenges it directly. The government’s formal response is due around mid-November.

What the committee wants

The JCHR made 20 recommendations, and together they amount to the most detailed parliamentary blueprint for UK AI law so far. The centrepiece is a dedicated AI Bill implementing the Council of Europe’s AI Convention in domestic law.

Among its other proposals:

  • Bans on emotional inference, the use of AI to infer people’s emotional states.
  • Prior approval for high-risk systems before they are deployed.
  • An independent regulator with the power to withdraw systems from use.
  • A statutory AI Security Institute, with frontier models submitted before release.

Each of these goes beyond the government’s current position, which rests on existing regulators applying existing law, supplemented by voluntary codes. The King’s Speech in May 2026 contained no AI bill; IAPP described its digital agenda as diffuse.

Regulating users, not builders

The government’s handling of the Cyber Security and Resilience Bill shows how that position works in practice. On 2 September, The Register reported that ministers had rejected amendments that would have brought AI vendors and frontier developers within the bill’s scope. Instead the government is relying on the voluntary AI Cyber Security Code of Practice. Lords amendments proposing “red lines” and emergency shutdown powers were also rejected.

The effect is that organisations deploying AI carry statutory duties, while the companies building the most capable systems do not. There is a coherent case for this. Ministers can argue that the UK’s influence over frontier labs, most of them headquartered abroad, is greater through cooperation than compulsion; that premature statute risks freezing rules around today’s technology; and that sector regulators understand context better than a single AI authority would.

The counter-argument, which the JCHR and peers have pressed, is that voluntary commitments are only as durable as the commercial incentives behind them, and that the public bears the risk when they lapse.

A voluntary code is a promise made by those who will not bear the cost of breaking it.

Facial recognition as the test case

Live facial recognition is where the abstract debate becomes concrete. It is a high-impact use of AI by the state, conducted in public spaces, with direct consequences for privacy, freedom of assembly and the risk of misidentification. It is also, on the Met’s own figures, operationally productive.

The governance question is not whether the technology works but under what authority it is used. At present there is no statute written for the purpose, and the Home Office’s own consultation on a legal framework is an acknowledgement that the question is open. Supporters of current practice say existing law and guidance are sufficient; critics say a permanent fixed-camera network in central London is qualitatively different from time-limited deployments, and deserves explicit parliamentary approval.

The JCHR’s recommendations would change that calculus. Prior approval for high-risk systems and a regulator with withdrawal powers would, in principle, place a fixed LFR network under a licensing-style regime rather than leave it to operational judgement.

Where the UK sits internationally

Britain’s position is increasingly distinctive. The EU has a comprehensive AI Act, even if its high-risk obligations have been delayed to December 2027. South Korea’s AI Basic Act is in force, with enforcement due from early 2027. Japan has chosen a promotion-first model through its AI Basic Plan. The UK, by contrast, has so far declined to legislate for AI as such.

That is not necessarily untenable; Japan shows that a non-statutory model can be a deliberate choice. But the JCHR’s call to give domestic effect to the Council of Europe convention is designed to make the absence of a statute harder to defend.

What to watch

Date Event Why it matters
Around mid-November 2026 Government response to the JCHR report Will show whether ministers accept any of the 20 recommendations, especially an AI Bill or a statutory AI Security Institute
Ongoing Remaining stages of the Cyber Security and Resilience Bill Whether ministers revisit AI vendors or shutdown powers
By end of 2026 Met’s fixed LFR rollout in the West End and Soho Whether deployment proceeds before any statutory framework
No firm date Home Office legislation on facial recognition The consultation closed in February 2026; a bill would be the first AI-specific policing statute

The response in November will be the clearest signal yet of whether the government intends to keep regulating AI through its users or is prepared to legislate for the technology itself. For now, the cameras are arriving first.

Sources

  1. PPC Land — UK government faces two-month deadline to answer MPs and peers on AI law
  2. IAPP — King’s Speech signals diffuse UK digital policy agenda, but no AI bill
  3. The Register — UK cyber bill targets AI users, not the vendors building it
  4. IBTimes UK — Metropolitan Police expand facial recognition to London’s West End
  5. Gibson Dunn — EU AI Act omnibus agreement postpones high-risk deadlines
  6. US International Trade Administration — South Korea AI Basic Act
  7. Cabinet Office of Japan — AI Basic Plan

AI & GPP reports on how artificial intelligence and automation are changing the way governments decide, regulate and campaign. Corrections and tips: contact the editors.

Get the stories that matter to decision-makers, weekly.

Discussion

No comments yet. Start the conversation.

Discussion is open to members.

Join free Sign in

Read next

Pakistan Writes Rules for the Algorithmic State

Pakistan's draft National Data Governance Policy would give citizens a right to human review of automated decisions and force ministries to register high-risk AI. It arrives before the country has a data protection law.

Cape Town’s Data Centre Fight Puts a Price on AI’s Thirst

Housing activists have appealed Cape Town's approval of a 174MW Equinix data centre, arguing that planners waved it through without data on water, power or emissions. The case is becoming a test of how African cities govern AI infrastructure.