United Kingdom - AI Risk Management
Central AI Risk Function (CAIRF)
United Kingdom
RAI-GB-NA-CARFCXX-2023The Central AI Risk Function monitors cross-sectoral AI risks to assist UK regulators and government departments, established as a policy mechanism by the Department for Science, Innovation and Technology in 2023. The policy came into force on 19 September 2023 and operates as a non-binding risk assessment body.
Summary
The Central AI Risk Function (CAIRF) is a central, cross-government function established by the United Kingdom’s Department for Science, Innovation and Technology (DSIT) in 2023 to provide continuous identification, measurement, monitoring and coordination of AI-related risks that may affect national security, public safety, economic resilience and societal wellbeing. CAIRF was announced publicly in a ministerial statement to Parliament on 19 September 2023 and is an operational element of the UK’s pro-innovation AI regulatory architecture set out in the March 2023 White Paper “A pro-innovation approach to AI regulation”. CAIRF’s principal responsibilities include maintaining and updating a UK AI Risk Register, conducting horizon scanning and system-level risk assessments (including for foundation and frontier models), surfacing cross-sectoral regulatory gaps, coordinating technical inputs into policy decisions, and supporting multi-regulator activity and advice to innovators through initiatives such as the DRCF AI and Digital Hub.
CAIRF is non-statutory in form (a government policy function rather than a new regulator) but operates as a central coordination mechanism that channels expertise from DSIT, the AI Safety Institute (formerly the Frontier AI Taskforce), line regulators (for example the Competition and Markets Authority (CMA), Medicines and Healthcare products Regulatory Agency (MHRA), Information Commissioner’s Office (ICO), and Office for Nuclear Regulation (ONR)), and academia. It plays a facilitative role: producing evidence and risk assessments that inform sectoral regulators’ decisions and national policy, supporting regulator preparedness, and enabling international cooperation consistent with the UK’s commitments under the AI Safety Summit and the Bletchley Declaration. CAIRF also supports development of testing and evaluation frameworks, best practices for safety and security, and cross-government situational awareness of emergent AI capabilities and misuse vectors.
Because CAIRF is an enabling/coordination function rather than primary legislation, its outputs typically translate into obligations, expectations or regulatory interventions applied by existing regulators within their statutory remits. The White Paper sets out a principles-based regulatory approach (safety, transparency, fairness, accountability and contestability) and envisages central functions such as CAIRF to monitor system performance and identify when binding or statutory measures may become necessary. CAIRF therefore sits at the interface between evidence, standards-setting (in partnership with the AI Safety Institute), and enforcement carried out by sectoral regulators when risks require formal action. The function also underpins the UK’s international engagement on frontier AI safety, providing the UK government with a consolidated view of national risks to inform diplomacy, partnerships and collaborative testing initiatives.
Key near-term products have included the cross-economy AI risk register work and contributions to regulator guidance and multi-agency pilot services for innovators. Over time CAIRF’s activity will help calibrate whether the UK’s context-based, principles-led approach remains proportionate or whether statutory duties should be introduced for regulators and developers of highly capable general-purpose models. CAIRF does not itself impose criminal or civil penalties; enforcement and penalties remain a matter for relevant regulators and existing statutes, but CAIRF’s assessments materially influence enforcement priorities and policy proposals.
Full article
Read full text ↗Overview
The Central AI Risk Function (CAIRF) is a cross-government coordination and monitoring function established inside the UK Department for Science, Innovation and Technology (DSIT). Announced in ministerial statements on 19 September 2023 and set out as a central function in the government’s AI Regulation White Paper, CAIRF's core mission is to identify, measure and monitor existing and emerging AI risks across government, industry and academia. CAIRF maintains the UK AI Risk Register and provides a single, holistic picture of systemic and sectoral AI risks that can inform regulator action, policy design and international engagement, including inputs into outcomes from the AI Safety Summit (Bletchley Declaration). While CAIRF is non-statutory in form, it is intended to strengthen regulatory coherence and enable faster, evidence-based government responses to novel AI hazards.
Definitions
CAIRF uses the terminology established in the White Paper and related government papers. Key terms include: 'AI risk' (probability and impact of harms from development or deployment of AI systems), 'foundation models'/'frontier AI' (highly capable, general-purpose models with broad applicability and potential for systemic effects), 'systemic risk' (risks that affect multiple sectors or national infrastructure), and 'AI Risk Register' (a living catalogue of identified AI-related risks and mitigations). CAIRF also distinguishes between (a) near-term misuse and safety risks that are sector-specific and (b) longer-term, systemic, or existential-style risks that could require whole-of-government responses.
Governance and Institutional Framework
CAIRF is hosted in DSIT’s AI Policy Directorate and operates in close coordination with the AI Safety Institute (AISI) which conducts technical testing and evaluations. CAIRF convenes representatives from lead AI Ministers, sectoral regulators and independent expert advisers. It feeds evidence to the Digital Regulation Cooperation Forum (DRCF) pilots for multi-regulator advisory services and supports the delivery of regulator AI plans. The function reports into senior DSIT officials and provides briefings to ministers, while its outputs are used by regulators with statutory powers (for example the Competition and Markets Authority, Information Commissioner's Office, MHRA and others) who remain responsible for enforcement within their remits.
Key Focus Areas
CAIRF concentrates on a set of priority functions: (1) horizon scanning and early warning for emergent capabilities and misuse vectors from foundation and frontier models; (2) maintenance and publication (subject to security considerations) of a cross-economy AI Risk Register; (3) system-level risk assessment and scenario analysis to understand cascading effects across critical infrastructure, healthcare, finance and national security; (4) coordination of evidence flows between the AI Safety Institute’s technical evaluations and policy/regulatory decision-makers; (5) identification of regulatory gaps and recommended mitigations, including guidance for developers and deployers; (6) convening and capacity-building for regulators to embed AI-specific expertise; and (7) engagement with international fora to align testing, standards and incident response practices. These activities support the government’s principled, context-based approach by ensuring policy is grounded in current technical understanding.
Implementation Framework
Operationally CAIRF runs cross-government working groups, maintains an AI Risk Register updated through engagement with regulators, industry and academia, and commissions/adopts specific technical evaluations from the AI Safety Institute. It supports regulator readiness through playbooks, practical guidance and joint sandbox pilots (e.g., DRCF AI and Digital Hub). CAIRF also establishes escalation pathways so that high-severity risks prompt rapid ministerial and regulator-level action. Internally, CAIRF coordinates with lead AI Ministers and an Inter-Ministerial Group (IMG) to ensure policy coherence and to allocate responsibilities for mitigation measures across departments.
Monitoring and Evaluation
CAIRF’s monitoring framework combines structured risk metrics, qualitative scenario analysis and technical evaluation outputs to assess both likelihood and impact. The function tracks indicators such as concentration in FM markets, speed of capability development, misuse incidents, and regulator preparedness. Periodic reviews and a rolling evaluation feed into the government’s AI regulatory response — including whether further statutory duties for regulators or sector-specific rules are warranted. CAIRF also measures the effectiveness of mitigations recommended to regulators and reports on progress in closing identified regulatory gaps.
Penalties, Liability, and Appeals
As a policy/coordination body CAIRF does not itself levy penalties or adjudicate liability. Where CAIRF identifies harms or regulatory breaches, it refers matters to the relevant statutory regulator or law enforcement for investigation and enforcement. Penalties therefore remain those available under sectoral or cross-cutting laws (for example consumer protection, data protection, health and safety, competition law). CAIRF can, however, recommend legal or policy changes to tighten liability allocation, redress mechanisms, or sanctioning powers where existing instruments are insufficient.
Relationship to Other Instruments
CAIRF operates alongside and in support of the Government’s White Paper AI Regulation White Paper, the AI Safety Summit outcomes (the Bletchley Declaration), the AI Safety Institute establishment materials and the UK Science and Technology Framework. It is intended to complement — not supplant — sectoral regulatory regimes and to inform future primary legislation if and when the government decides statutory measures are necessary.
International Alignment
International alignment is central to CAIRF’s remit: by aggregating national risk intelligence and aligning testing and evaluation standards with partners, CAIRF supports the UK’s international commitments made at the AI Safety Summit and under multilateral fora (G7, OECD). CAIRF liaises with counterpart functions internationally to support interoperable assurance practices and to coordinate state-led testing or information sharing about frontier model capabilities and risks.
Implementation Timeline
| Event | Date |
|---|---|
| Ministerial announcement establishing CAIRF (written statement to Parliament) | 2023-09-19 |
| AI Safety Summit (Bletchley Park) | 2023-11-01 to 2023-11-02 |
| Publication of White Paper (context for CAIRF) | 2023-03-29 |
| AI Safety Institute launch materials published | 2024-02-09 |
Sources and References
| Source | Type |
|---|---|
| A pro-innovation approach to AI regulation (White Paper, March 2023, amended PDF) | Primary Source |
| UK Artificial Intelligence Policy Update (Written Statement, 19 September 2023) | Primary Source |
| Introducing the AI Safety Institute (GOV.UK) | Primary Source |
| AI Safety Summit 2023: The Bletchley Declaration | Primary Source |
Requirements for a company
What an organisation has to do under United Kingdom - AI Risk Management, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
3- Engage with CAIRF submissions and risk register consultations.Regulators and large AI developers.
- Provide evidence and model capability information to CAIRF when requested.AI developers and research organisations.
- Adopt regulator guidance informed by CAIRF risk assessments.Sectoral regulators and public sector deployers.
Must not do
0Nothing in this category.
Should do
1- Participate in joint testing and sandbox programmes.AI developers, regulators, and the AI Safety Institute.
Should not do
0Nothing in this category.
Who must do what
The obligations under United Kingdom - AI Risk Management, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Regulators and large AI developers. | Engage with CAIRF submissions and risk register consultations. “Engage with CAIRF submissions / risk register consultations” | — | Compliance Checklist | Important |
| 2 | AI developers and research organisations. | Provide evidence and model capability information to CAIRF when requested. “Provide evidence and model capability information when requested (subject to lawful safeguards)” | — | Compliance Checklist | Important |
| 3 | Sectoral regulators and public sector deployers. | Adopt regulator guidance informed by CAIRF risk assessments. “Adopt regulator guidance informed by CAIRF risk assessments” | — | Compliance Checklist | Important |
| 4 | AI developers, regulators, and the AI Safety Institute. | Participate in joint testing and sandbox programmes. “Participate in joint testing and sandbox programmes” | — | Compliance Checklist | Recommended |
Related Regulations
AI Safety Institute (establishment following AI Safety Summit)
United Kingdom89% similar
A Pro‑Innovation Approach to AI Regulation (White Paper)
United Kingdom89% similar
Government response to the AI regulation white paper (AI regulation: government response)
United Kingdom89% similar
National AI Strategy - AI Action Plan
United Kingdom89% similar
National AI Strategy
United Kingdom88% similar
© Regulations.AI · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash