Parliament’s Joint Committee on Human Rights (“JCHR”), made up of members of both the House of Commons and the House of Lords, has concluded that the legal framework for AI regulation is “patchy and confused”.
The conclusion features in the Committee’s latest report, “Human Rights and the Regulation of AI”, following an inquiry launched last year, to investigate whether existing law and regulation sufficiently protects human rights in the face of growing use of AI (paragraph references in what follows are to the Report).
The conclusion is perhaps unsurprising.
Alan Turing asked “can machines think?” as long ago as 1950 but today’s concerns about AI have mostly arisen after the 2022 launch of ChatGPT. And that is merely one form of AI technology.
It would be remarkable to find a ready-made legal and regulatory framework for technologies which didn’t exist five years ago. But, that does not mean there's no role for existing laws, chief amongst them human rights.
The Emergence of A Framework
The JCHR does recognise that a framework for AI regulation is beginning to emerge. We are probably still in the ‘primordial soup’ stage of its evolution.
The Committee identifies the 2024 Council of Europe Framework Convention on Artificial Intelligence and Human Right, Democracy and the Rule of Law (“Framework Convention”) as the first legally binding international instrument on this subject (§22). (The JCHR also considers the EU Artificial Intelligence Act, which has similarities with the Framework Convention, but more briefly).
However, the Framework Convention’s bindingness is more ambition than reality. Despite having 21 signatories, it has not been ratified by a single state. It remains more of an agreement to act than an action in itself, and even at that it’s not in force.
The UK Government, for its part, has expressed an intention to ratify the Framework Convention, but has set out no timetable for doing so (§24). The Prime Minister, nevertheless, this week told the UN that the UK
“… will work towards agreeing a single set of global principles and standards to ensure the transparency and access we need to increase our preparedness – and to ensure that AI development is safe…”
An initial step could be to ratify the Convention and, indeed, the JCHR “urge[d] the government to seize the opportunity to be an early adopter of the Framework Convention” and to set out a timeline for ratification (§§26-27).
The Key Risks to Rights
The Committee takes the Framework Convention, despite its nascency, as something of a framework for its own report. It examines “key risks to human rights”, and follows the Framework Convention’s choice of three principles to consider: equality and non-discrimination; privacy and personal data protection; and the right to an effective remedy (§29).
In relation to the first, equality and non-discrimination, the Committee reviews a range of problematic examples, before concluding that “AI systems are prone to producing unfairly discriminatory outcomes” (§38). Of course, human rights law deprecates discrimination, which is prohibited by Article 14 of the European Convention on Human Rights. And, of all the human rights law in force in the UK, anti-discrimination law is perhaps the most complex.
Second, in respect of privacy and personal data, the JCHR rehearses several controversial applications, and concludes that AI systems “pose particular risks” because of web scraping, and the potential for “highly intrusive use” (§45). The examples are well-known, and likely engage several legal regimes, including Article 8 ECHR, and the UK GDPR.
Third, the Committee sets out that, in the absence of transparency, individuals may be unable to obtain an effective remedy in respect of AI systems (§49). Then, finally, the JCHR refers to the impact on intellectual property rights (§53), the right to a fair trial (§55), and “wider risks to human rights” (§§56-59).
It is inevitable that the Committee’s survey of risks to rights can only scratch the surface. A novel technology, of general and potentially pervasive use, will more likely than not impact any given human right. The Committee concludes that it will “continue to monitor developments in this area closely and may return to the topic in the future” (§59). It is difficult to see how it could do anything else.
Legal Framework – What Role for Human Rights?
The analysis then turns to the legal framework which exists to address these risks to rights. The JCHR identifies some long-standing common law causes of action, such as the law of negligence, and also several statutory frameworks, including:
All of the above are likely to feature in AI-related litigation in the years to come. However, the JCHR spends relatively little time on perhaps the most potent means by which human rights can be safeguarded, at least against violations by the state.
The JCHR does not linger on the prospect of the Human Rights Act 1998, or the European Convention on Human Rights, as a mechanism by which to seek redress for AI-caused human rights infringements. It touches on it, briefly, under the heading “obligations of public bodies” (§72).
It is right that, because the Act only applies to public authorities, and much AI technology development is done by private actors, there are limits on what the Act can do to safeguard rights (§101). Nevertheless, the potential impact on Convention rights, and therefore the scope for HRA litigation, is immense:
- Article 8 ECHR (right to privacy) will be engaged by any AI processing of personal data (for example in facial recognition technology);
- Article 8, with Article 14 ECHR, provides a means to challenge any discriminatory interferences with privacy (for example where there are racial or gender biases in AI systems);
- Article 6 ECHR may be engaged by the use of AI in the criminal justice process if it affects a fair trial;
- Article 10 ECHR may be engaged by systems which impact upon freedom of expression and the right to receive information.
These are just off-the-cuff examples. While a search of the database of the European Court of Human Rights today yields only five mentions of “artificial intelligence” in the Court’s case-law, none of which are significant, it is unlikely that the number will remain that low for long. And there will be plenty of cases in national courts that engage these issues at the same time as they arise in Strasbourg – and likely before.
This litigation may only arise in respect of acts and omissions of States and public authorities within States. But it represents a fertile ground for the development of broader principles of protection which can be applied to both public and private entities.
The Role of Human Rights Litigation
Indeed, at the end of last year, Judge Arnfinn Bårdsen, Vice-President of the European Court of Human Rights, wrote that in this area the Court has “just started”. He went on to say that:
“As we proceed, the Court will have to develop and clarify the Convention principles faced with, and adapted to, AI on a case-by-case basis. That implies that there will be no grand Master Plan, according to which the Court will design its jurisprudence. Law is, on the contrary, created cautiously, step by step, within the boundaries of the Court’s competences and jurisdiction under the Convention and in accordance with recognised principles of adjudication and legal method.”
Moreover, Vice President Bårdsen drew attention to the Court’s approach to the Convention as a “living instrument”, which is interpreted and applied in a way “adapted to the present-day conditions”. Indeed, without such an approach, he said “the Convention would already have been completely outdated and without any real bearing for such drastic leaps in societal development as AI”.
On this point, the Judge’s remarks chime with the observations of the lawyer and technologist, Richard Susskind, who warns that much of the debate on AI regulation suffers from the rear view mirror fallacy: looking to legislate for technologies that are already out of date. Any lasting framework, whether national, European, or international, may need to be based more on principles than on technology-specific rules. On this, the thinking has already begun, for example in the work of Professor Yuval Shany at Oxford.
In the meantime, litigation based in the current legal framework, drawing on broad principles of human rights and data protection, developed over decades, will shed light on both the risks to human freedom, and the strengths and weaknesses of existing legal protections. The law may be “patchy” in the short term, but it need not be “confused” in the long term.

/Passle/5b3f2cb9780ebf0410d034b3/MediaLibrary/Images/62cbdb4cf636e90f90cbb708/2023-12-01-17-45-47-680-656a1bcbc939f53538e0fca7.jpg)
/Passle/5b3f2cb9780ebf0410d034b3/MediaLibrary/Images/62cbdb4cf636e90f90cbb708/2023-11-16-15-35-05-870-655636a93d4d3db2aa2b7272.jpg)
/Passle/5b3f2cb9780ebf0410d034b3/SearchServiceImages/2026-07-29-10-50-14-501-6a69dae6d6577ad78941cbac.jpg)