The JCHR’s AI blueprint and the accountability gap
On 14 September 2026 the UK Parliament’s Joint Committee on Human Rights delivered a comprehensive blueprint for algorithmic governance in its landmark report, Human Rights and the Regulation of AI.
The recommendations vs the reality
The report resulted in a clear diagnosis from the Committee: existing laws protect rights only downstream at the point of use, leaving foundation model developers insulated from legal liability while local authorities, SMEs, and healthcare providers bear the compliance burden.
To fix this, the JCHR recommended:
- A comprehensive primary AI Bill with tiered risk thresholds.
- Upstream due diligence to prevent model builders from contracting out of liability.
- A single statutory AI regulator with pre-market audit powers and the ability to issue binding remedies.
The policy outcome?
Whitehall largely set the blueprint aside. Prioritising economic adoption and pro-innovation growth under the AI Opportunities Action Plan, ministers opted against an omnibus AI Bill. Instead, oversight remains distributed across sector-specific watchdogs (the ICO, EHRC, and Ofcom), leaving the AI Security Institute on a voluntary testing footing and relying on narrow secondary powers.
The core debate: centralised vs distributed oversight
The divergence between the JCHR’s vision and the government’s policy highlights two distinct approaches to AI governance.
1. The case for centralised oversight (the JCHR blueprint)
- Closing the supply-chain blind spot. Sectoral watchdogs cannot effectively police upstream general-purpose models. A single, empowered regulator creates end-to-end accountability, ensuring the companies designing foundational architectures are directly answerable for downstream systemic bias and privacy harms.
- Single point of redress. For citizens harmed by algorithmic decisions, navigating a fragmented maze of sectoral watchdogs is impractical. A dedicated oversight body offers consistent standards, subpoena powers over model weights, and streamlined access to remedy.
2. The case for distributed oversight (the government and incumbent regulators’ view)
- Context is everything. AI deployed in medical diagnostics carries vastly different risks, ethics, and legal frameworks than automated hiring tools or algorithmic trading. Existing regulators argue that domain-specific watchdogs are best equipped to evaluate harm within their particular operational contexts.
- Agility over bureaucratic inertia. Creating a massive centralised “super-regulator” risks institutional turf wars, jurisdictional friction with existing authorities, and heavy compliance layers that could stifle investment and innovation.
As machine learning systems become deeply integrated into public administration and critical infrastructure, can an informal network of sectoral regulators truly hold upstream tech giants accountable, or is an omnibus statutory regulator inevitable?
Regardless of where this eventually lands, having your own house in order will keep you in the clear regardless of where the scrutiny comes from.
