
A cross-party committee of MPs and peers has called for the UK to regulate AI by risk and across its whole lifecycle. In September, the Joint Committee on Human Rights published a report calling for a wide-ranging AI Bill, arguing that existing UK law cannot adequately address the human rights risks posed by AI.Â
Its recommendations include a tiered, risk-based approach, obligations across the lifecycle and supply chain, a single statutory regulator, mandatory transparency, a right to redress and prohibitions on uses incompatible with human rights.Â
The King’s Speech in May contained no standalone AI bill, though it did include a Regulating for Growth Bill that creates regulatory sandboxes for testing AI products, as the Society for Computers & Law summarised.Â
The EU has already shown that the hardest part is operational, not legal. So UK organisations should be concerned about what any potential obligations mean in practice. Â
The UK is looking at a model already in motion Â
The JCHR’s proposals largely mirror the EU AI Act. Prohibitions, conformity assessment and pre-market approval for high-risk systems, and fundamental rights impact assessments for deployers. The EU’s Digital Omnibus on AI, in force since 27 July 2026, deferred high-risk obligations for standalone Annex III systems to 2 December 2027 and for AI embedded in regulated products to 2 August 2028. Deferred, however, is not cancelled. Â
The rest of the timeline held. General-purpose AI model obligations have applied since August 2025, prohibited practices since February 2025, and the duty to tell people they are interacting with an AI system still stands.Â
Preparing for the AI Act has already forced organisations to work out which of their systems are high-risk, what evidence they can produce about how those systems make decisions, and who in the supply chain is accountable when something goes wrong. Most found that harder than expected because they had never documented their AI properly in the first place.Â
You cannot classify what you cannot seeÂ
Under the AI Act, risk classification attaches to the intended use case, not the underlying technology (Article 6). A provider that decides an Annex III system is not high-risk must document that assessment. That sounds manageable until you try it. When appliedAI analysed more than 100 enterprise AI systems, 40% could not be clearly classified, and the share of high-risk systems ranged from 18% to 58% depending on interpretation. The unclear cases clustered in critical infrastructure, employment and product safety.Â
Visibility is the deeper problem. IBM’s Cost of a Data Breach Report 2025 found that 63% of organisations studied had no AI governance policies to manage AI or prevent shadow AI. Of those that suffered an AI-related security incident, 97% lacked proper AI access controls, and heavy shadow AI use added around $670,000 to the average breach cost.Â
AI no longer arrives as a single approved project. It comes through software the company already bought, tools a department switched on and people building it who were never hired to. That is why registers go out of date, and why a compliance system can end up describing a company that no longer exists.Â
Lifecycle means live behaviourÂ
The EU’s lifecycle obligations are about how AI behaves in use. High-risk systems must allow automatic logging of events across their lifetime (Article 12), and deployers must monitor operation, assign human oversight and keep those logs for at least six months (Article 26). Providers must also monitor how their systems perform throughout their life, not just at launch (Article 72).Â
People affected by certain high-risk AI decisions with legal or similarly significant effects also have a right to an explanation of the individual decision (Article 86). That maps directly onto the JCHR’s transparency and redress recommendations. Anecdotally, it is the obligation organisations find hardest to evidence. Â
Most organisations still govern AI through the manual. That is to say, a policy, a register, a risk assessment signed off at launch. A manual is accurate on the day it is approved and then quietly stops being true, with nothing to tell you when that happens. An agent approved on Monday can be doing something nobody approved by Thursday. More process does not mean more safety; usually it means a longer manual.Â
The Dutch tax authority’s childcare benefits system used algorithmic risk scoring in which nationality was one of the risk factors, as Amnesty International documented. The Dutch Data Protection Authority later fined the Tax Administration €2.75 million for discriminatory and unlawful data processing. A system can be formally approved and still produce outcomes nobody intended. What matters is whether anyone is watching what it does.Â
Accountability runs through the supply chain, and now through agentsÂ
The supply chain matters too. A deployer or other party that substantially modifies a high-risk system or changes its intended purpose so that it becomes high-risk takes on the provider’s obligations (Article 25).Â
Agents are currently the fastest-growing part of enterprise AI and have the widest governance gap. Most governance was built for models such as a model registry, prediction monitoring and a human reviewing outputs. That does not work for a system that sets its own steps, calls external APIs and writes to records. By the time an agent produces its final output, it has already acted, so reviewing that output is incident response rather than oversight.Â
Gartner predicts that over 40% of agentic AI projects will be cancelled by the end of 2027, citing escalating costs, unclear business value or inadequate risk controls.Â
The AI Act was written before agents were in real-world use. Risk categories apply to the use case, not the tool, and accountability should be arranged at the system or product level too, including evidence. In that sense, the Act’s principles still hold. The practical gap is complexity, such as tracing agents’ decisions end to end. I would rather see regulators issue guidance on how existing obligations apply to agents than reopen the Act in its entirety.Â
What UK organisations can do now, without waiting for a billÂ
Five things matter. First, know where every AI system and agent is. Second, classify each by use case and risk. Third, turn policies into controls that are technically enforced. Fourth, monitor systems in production for drift and behaviour. And fifth, be able to explain any single decision after the fact. Â
The biggest gap is in operational capability. Firms that treat governance as a compliance deadline instead of a discipline will be caught out by whatever regime the UK decides upon.Â
The evidence backs this up. A recent Grant Thornton survey of nearly 1,000 US business leaders found that 78% lacked full confidence they could pass an independent AI governance audit within 90 days. That points to a significant governance maturity gap that many organisations still need to close.Â
Foundations, not paperwork Â
None of this is an argument against documentation. Registers, risk ratings and audit trails must still exist. The difference is where they come from. A manual is written about the system, while good governance produces documentation from the system as it operates. One is a description, the other is a reading.Â
Documentation is the output of governance, and it has been mistaken for governance itself. None of this depends on regulation, either. Remove the AI Act and the argument still holds, because no organisation wants someone harmed by a decision nobody checked.Â
Author:
Maarten Stolk, Co-Founder & CEO, Deeploy



