The UK’s stalled AI safety law and the gap it leaves

The UK still has no statutory regime requiring the most advanced AI models to be safety-tested before release. The Guardian reports that ministers had.

The UK still has no statutory regime requiring the most advanced AI models to be safety-tested before release. The Guardian reports that ministers had begun drafting one, and the worry now is that the work has stalled.

Key takeaways

  • The United Kingdom regulates advanced artificial intelligence mainly through existing sector regulators and voluntary agreements with developers, not through a dedicated AI statute.
  • The Guardian reports that an earlier group of senior ministers had started work on a new AI safety law, including a review of the powers government already holds and the option of compelling companies to submit products for pre-launch safety testing.
  • The UK’s AI Security Institute, set up in 2023 as the AI Safety Institute, can evaluate frontier models but depends on developers agreeing to give it access.
  • The European Union has taken the opposite route with a binding, phased AI statute, leaving the two jurisdictions increasingly divergent on how frontier systems are policed.

The AI safety bill that has not been introduced

Since 2023, successive UK governments have signalled that legislation aimed at the small number of companies building the most capable AI systems was coming, without one being placed before Parliament. The Guardian reports that senior ministers, alarmed by recent developments in the field, had begun drawing up plans for a new AI safety law, and that they were examining whether companies could be forced to submit products for safety testing before launch. The publication attributes this account to people briefed on the plans.

What is not known publicly is how far that drafting progressed, what scope the proposed law would have had, or whether it remains on the government’s forward programme. No text has been published and no introduction date has been announced. The Guardian’s report frames the current concern as one of attention: that a focus on immediate domestic problems has pushed AI risk down the political agenda. That is a characterisation of political priorities rather than a formal statement of policy, and the government has not said the work has been abandoned.

The review of existing legal powers

The Guardian also reports that ministers commissioned a review of legislation already on the statute book, to establish which powers they could use without passing anything new. This is a standard preliminary step, and it points to the structural problem the UK faces. Its approach to AI, set out in a 2023 white paper, deliberately avoided creating a new regulator or a new statute. Instead it asked existing bodies — those covering competition, communications, medicines, financial services, data protection and health and safety — to apply a set of cross-cutting principles within their own remits.

That design works reasonably well where an AI system is used inside an already regulated activity. It works less well for a general-purpose model that is released to the world and can be applied to almost anything. No single UK regulator has clear statutory authority over the act of releasing a frontier model itself. The findings of the review described by the Guardian have not been published, so it is not known which gaps it identified.

The AI Security Institute and voluntary model testing

The UK created the world’s first state-backed body dedicated to evaluating advanced AI models, announced around the Bletchley Park summit in November 2023 as the AI Safety Institute. It was renamed the AI Security Institute in February 2025, a change that reflected a sharper emphasis on national security-related risks such as the misuse of models for cyber attacks or the development of chemical and biological weapons.

The institute conducts technical evaluations of models, publishes methodology and works with counterpart bodies in other countries. Its central limitation is legal rather than technical: it has no statutory power to demand access to a model, to set a testing standard a developer must meet, or to delay a launch. Access to pre-release systems rests on developers choosing to cooperate. That arrangement has produced real evaluation work, but it leaves the state without recourse if a company declines, restricts what it shares, or ships a product before testing concludes.

The Frontier AI Safety Commitments

The voluntary framework the UK relies on was built through international summitry. The Bletchley Park summit produced a declaration signed by a large group of countries and the European Union acknowledging risks from frontier systems. At the follow-up summit in Seoul in May 2024, a group of leading AI developers signed the Frontier AI Safety Commitments, agreeing to publish safety frameworks, identify thresholds at which risks would be deemed intolerable, and set out what they would do if those thresholds were reached.

These commitments are undertakings, not obligations. There is no independent verification mechanism, no penalty for departing from a published framework, and no external body that decides whether a stated threshold has been crossed. Their value lies in creating public documents that can be compared over time and pointed to when a company’s behaviour diverges from them. Whether that is sufficient is precisely the question a safety statute would settle.

The EU AI Act as the nearest comparator

The European Union took the legislative route. Its AI Act entered into force in 2024, with obligations phasing in over subsequent years, and it includes a specific tier for general-purpose AI models, with additional duties for those judged to pose systemic risk. It establishes an EU-level AI Office, documentation and transparency requirements, and enforcement backed by penalties.

The comparison matters for the UK in two ways. First, large developers serving the European market will meet those requirements regardless of what the UK does, which changes the practical cost of a UK regime. Second, it means the UK’s position is a choice rather than an inevitability: a workable binding model exists next door, and continuing without one is a policy decision that will be judged on its results.

What the overall picture shows

Taken together, these strands describe a country with strong technical evaluation capacity and weak legal authority. The UK built an institute before most states had one, hosted the first international summit on frontier risk, and secured voluntary commitments from the leading developers. What it did not do was convert any of that into enforceable law. Every lever it holds over a frontier model release currently depends on a company’s willingness to cooperate.

That was a defensible position when the voluntary framework was new and capabilities were advancing along a visible path. It becomes harder to defend as the gap widens between what the institute can observe and what it can require. The account reported by the Guardian — a drafted law, a review of existing powers, an option to mandate pre-launch testing — suggests ministers themselves reached that conclusion. The unresolved question is not whether the analysis was done, but whether anything follows from it. Until legislation is published, the UK’s position remains what it has been since 2023: extensive expertise, and no statutory power to use it.

Sources and further reading

  • The Guardian, technology section — the report describing plans for a UK AI safety law, a review of existing powers, and concern that the issue has slipped down the agenda.
  • UK Government white paper on AI regulation (2023) — sets out the sector-regulator approach and the cross-cutting principles.
  • UK AI Security Institute — published evaluation methodology and reports on frontier model testing.
  • Official EU documentation on the AI Act — the phased obligations, including the general-purpose AI tier.

Surfaced from the rss:guardian_tech signal “delayed national AI legislation”. AI-assisted draft, editorially reviewed.

Visited 1 times, 1 visit(s) today
share this recipe:
Facebook
X
WhatsApp
Telegram
Email
Reddit