Three Years of the UK's Central AI Risk Function
Three years ago today, on 19 September 2023, the United Kingdom formally established the Central AI Risk Function (CAIRF) within the Department for Science, Innovation and Technology (DSIT). Operating continuously since its ministerial announcement, this central policy initiative serves as the nation's primary intelligence node for monitoring and evaluating systemic artificial intelligence risks.
What's changing — substance
CAIRF was established via a written statement to Parliament on 19 September 2023, building upon the coordination framework outlined earlier that year in the UK's initial AI policy strategy. Rather than operating as a statutory regulator equipped with direct enforcement or fining powers, CAIRF functions as an internal policy and intelligence hub. It works across government, industry, academia, and international partners to track and analyze hazards posed by advanced artificial intelligence.
At the heart of CAIRF's operational role is the UK AI Risk Register. This living registry tracks emerging threat vectors, catastrophic risks, misuse scenarios, and potential vulnerabilities facing critical national infrastructure or national security. To keep this registry up to date, the unit conducts continuous horizon-scanning and scenario planning regarding frontier AI capabilities.
Crucially, because CAIRF is a central policy function rather than a statutory regulator, it creates no independent legal penalties, statutory rules, or liability regimes. Instead, it serves as an analytical backbone for the UK government. The unit feeds technical evaluation evidence and policy guidance to government ministers, international safety bodies, and frontline statutory regulators.
For organizations developing or deploying complex software, CAIRF acts as an early-warning radar. While the unit cannot directly fine an organization, its findings actively shape regulatory enforcement. A heightened threat classification or risk listing in the central risk register alerts sector regulators, who then use their existing statutory powers to investigate systems or tighten sector-specific rules.
Who is affected — jurisdictions, sectors, sizes
CAIRF operates at the national level across the entire United Kingdom. Its core analytical scope focuses on developers and deployers of advanced foundation models and general-purpose frontier AI systems.
While large-scale frontier model developers face the most direct technical scrutiny from CAIRF's horizon-scanning work, the initiative's analytical reach impacts organizations of all sizes. Startups, enterprise deployers, academic research labs, and public sector bodies utilizing complex AI architectures fall within CAIRF's broad intelligence umbrella.
Direct enforcement based on CAIRF's intelligence remains entirely with established sector regulators operating under their pre-existing legal powers. Key bodies including the following actively monitor these developments:
- The Information Commissioner's Office (ICO), enforcing data protection, privacy, and automated decision-making rules.
- The Competition and Markets Authority (CMA), addressing competition and consumer protection issues in AI markets.
- The Medicines and Healthcare products Regulatory Agency (MHRA), overseeing software and AI deployed in medical settings.
Consequently, any organization deploying advanced AI systems in the UK—regardless of sector or size—is affected by the risk classifications and evaluation frameworks established by CAIRF.
Three things to do this week
Although CAIRF does not issue direct compliance fines, its analytical findings guide statutory enforcement. Organizations operating in the UK market should take three concrete actions to maintain alignment:
- Review internal threat models against the UK AI Risk Register. Evaluate your current model deployments against the living risk categories and mitigations published by DSIT to ensure your internal risk management aligns with central government findings.
- Audit sector-specific legal compliance. Map your AI deployments against the statutory authorities governing your sector—such as the ICO for data privacy, the CMA for consumer transparency, or the MHRA for medical devices—to ensure your documentation satisfies their current enforcement priorities.
- Establish ongoing horizon-scanning processes. Implement routine procedures to track risk briefings, safety evaluations, and technical updates released by DSIT and its partner organizations to ensure early awareness of shifting government risk priorities.
Related context
CAIRF exists within a broader portfolio of UK government initiatives designed to foster AI innovation while mitigating systemic hazards. The policy was initially envisioned in the foundational strategy document, A Pro‑Innovation Approach to AI Regulation (White Paper), published on 29 March 2023. The government subsequently expanded on CAIRF's role in the Government response to the AI regulation white paper.
Additionally, CAIRF works alongside technical evaluation bodies established in the wake of the November 2023 AI Safety Summit at Bletchley Park, including the AI Safety Institute, which published its operational overview on 9 February 2024 to support technical evaluations across government.
Note: this article was drafted by AI - Google Gemini