UK AI Data Regulation Call for Evidence
Data regulation in the age of AI and other data-intensive technologies
United Kingdom
RAI-GB-NA-EVIDENC-2026The UK Department for Science, Innovation and Technology launched a call for evidence to adapt data regulation for AI, closing September 9, 2026.
Overview
The document, officially titled "Data regulation in the age of AI and other data-intensive technologies," represents a crucial initiative by the UK Department for Science, Innovation and Technology (DSIT) to proactively assess and adapt the nation's data regulatory landscape in response to the rapid advancements in Artificial Intelligence (AI) and other data-intensive technologies. Published on 15 July 2026, this call for evidence is designed to gather comprehensive insights and practical examples from a wide array of stakeholders, including businesses, innovators, researchers, civil society organizations, academics, and individuals. Its primary objective is to understand the intricate interactions between existing personal and non-personal data regulation and the evolving use cases of AI and data-intensive technologies. The UK government is committed to positioning the country as the fastest-adopting AI economy within the G7, recognizing that effective data access, sharing, governance, and reuse are foundational to achieving this ambition. This call for evidence is a direct response to the potential for current regulatory frameworks to create unintended consequences, either by limiting the positive benefits of new technologies or by failing to adequately protect individuals and maintain public trust. By seeking detailed feedback on what is working well, where uncertainties persist, and where friction or challenges are anticipated, DSIT aims to determine whether further guidance, targeted legislative amendments, or more fundamental regulatory reform is necessary to ensure the UK’s data framework remains fit for purpose in this technologically dynamic era. The consultation period is set to close on 9 September 2026, underscoring the urgency and importance the government places on this strategic review.
The initiative stems from a broader governmental recognition that while data is an invaluable asset and a significant driver of economic growth, contributing substantially to the UK economy and employment, its full potential is often constrained. The rapid evolution in the scale and complexity of AI and data-intensive technologies presents both immense opportunities and novel risks. Existing UK legal frameworks, such as the UK General Data Protection Regulation (UK GDPR), the Data Protection Act (DPA), and the Privacy and Electronic Communications Regulations (PECR), alongside sector-specific rules, govern data use. However, the emergence of advanced AI capabilities, new data supply chains, and innovative data uses may challenge the practical interpretation and application of these established rules. Previous evidence, including from DSIT’s AI Growth Lab call for evidence, has already highlighted specific issues such as lawful bases for large-scale data use, data minimisation, purpose limitation, data subject rights, and the allocation of roles and responsibilities across complex data-intensive supply chains. This uncertainty about compliance and legal risk has the potential to deter AI adoption and limit the societal benefits of responsible AI deployment. Therefore, this call for evidence is a proactive step to ensure that data regulation not only provides effective protections but also fosters confidence and clarity for organisations and individuals, thereby underpinning innovative and responsible uses of data across the economy.
Definitions
Within the context of this UK government call for evidence, a clear understanding of key terminology is essential for effective participation and subsequent policy formulation. The document specifically defines "data-intensive technologies" as applications where the sheer volume, velocity, and complexity of data constitute the primary engineering challenge, rather than computational power alone. This encompasses a broad spectrum of modern technological applications, including but not limited to distributed databases and stream processing technologies. Practical examples provided in the source material include ride-sharing services, video streaming platforms, and e-commerce systems, all of which rely heavily on the continuous processing and analysis of vast and intricate datasets. These technologies are distinct from general software applications in their inherent reliance on and manipulation of large-scale data, making their interaction with data regulation a critical area of inquiry. The call for evidence deliberately focuses on these technologies because their operational characteristics and data demands often push the boundaries of existing regulatory interpretations and applications, necessitating a review of current frameworks to ensure continued relevance and efficacy.
Furthermore, the call for evidence broadly refers to "data regulation" to encompass both personal and non-personal data frameworks. For personal data, this primarily includes the UK GDPR, the Data Protection Act (DPA), and the Privacy and Electronic Communications Regulations (PECR). These instruments establish the legal requirements for processing personal data, including principles like lawful basis, data minimisation, purpose limitation, and data subject rights. The document highlights that the application of these principles in the context of AI, especially with large-scale or special category data, presents significant challenges and uncertainties for organisations. For non-personal data, the regulatory landscape is less consolidated but includes relevant provisions within the Digital Economy Act and various sector-specific regulations. The interaction between these distinct regulatory domains, particularly when AI systems process mixed datasets, is a central theme of the inquiry. The government's interest extends to understanding how legal, technical, and governance arrangements can both enable the use and re-use of all types of data while effectively managing potential harms, thereby balancing innovation with robust protections for individuals and the wider economy. The document explicitly states that it does not focus on AI issues related to copyright or intellectual property, as these have been addressed in separate public consultations.
Governance and Institutional Framework
The "Data regulation in the age of AI and other data-intensive technologies" call for evidence is spearheaded by the Department for Science, Innovation and Technology (DSIT), a key governmental body responsible for fostering the UK's leadership in science, innovation, and technology. DSIT's role in initiating this consultation underscores the government's strategic commitment to developing a robust and adaptable regulatory environment that supports technological advancement while safeguarding public interests. This initiative is a direct manifestation of the UK's broader national AI strategy, which aims to make the UK a global leader in AI adoption and innovation. The government views data as a critical national asset and a fundamental driver of economic growth, a principle articulated in its Industrial Strategy and various sector-specific plans. Therefore, DSIT, in collaboration with other relevant bodies, is tasked with ensuring that the governance mechanisms and institutional frameworks surrounding data use are not only effective but also agile enough to keep pace with the rapid evolution of AI and data-intensive technologies. This includes scrutinizing how existing regulatory bodies, such as the Information Commissioner's Office (ICO), interpret and apply current laws to emerging AI applications, and identifying areas where new governance approaches or inter-agency coordination might be required to address novel challenges.
The existing governance framework for data in the UK is multifaceted, primarily anchored by the UK GDPR and the Data Protection Act 2018, which are enforced by the ICO. These laws establish a comprehensive regime for the protection of personal data, including principles of accountability, transparency, and data subject rights. Additionally, the Privacy and Electronic Communications Regulations (PECR) govern electronic communications, and parts of the Digital Economy Act address wider data sharing and access for public good. Recent legislative efforts, such as the Data (Use and Access) Act, have already introduced targeted amendments to modernise aspects of this framework, and initiatives like smart data schemes aim to enable greater innovative uses of data. However, DSIT's call for evidence acknowledges that despite these existing structures and ongoing reforms, the unprecedented capabilities of AI, particularly agentic AI, and the complexities of data-intensive supply chains, are testing the limits of how these rules are interpreted and applied in practice. The consultation aims to understand how legal, technical, and governance arrangements can be optimised to enable responsible data use and re-use, manage potential harms, and ensure that accountability is maintained across complex organisational ecosystems. This holistic review of the governance landscape is crucial for building public trust in AI and for ensuring that the UK's regulatory approach remains proportionate, effective, and conducive to innovation.
Key Focus Areas
The call for evidence from the Department for Science, Innovation and Technology (DSIT) is structured around five critical themes, each designed to elicit specific insights into the practical challenges and opportunities at the intersection of data regulation and AI. The first key focus area is "Accessing and using data." This theme delves into how organisations practically acquire, prepare, and utilise both personal and non-personal data. It seeks to understand the processes for selecting and evidencing lawful bases for processing, particularly in the context of large-scale or complex datasets, and how principles like purpose limitation and data minimisation are applied. Furthermore, it explores how permissions and licensing terms influence data use and re-use, aiming to identify any barriers or best practices in data accessibility that impact AI development and deployment. This area is crucial for understanding the foundational data practices that underpin AI innovation and where regulatory clarity might be lacking.
The second theme, "Data quality, accuracy, and downstream impacts," addresses how organisations manage the integrity and reliability of data throughout different processing stages. It investigates methods for assessing and maintaining data quality and accuracy, and critically, how considerations of fairness and potential impacts on individuals are integrated from the initial design phase. This focus extends to monitoring and addressing adverse impacts that may arise from AI model outputs or subsequent downstream uses of AI systems, highlighting the importance of robust data governance in mitigating risks associated with biased or inaccurate data. The third area, "Governing data use across organisations," examines the complexities of legal roles and responsibilities within intricate and often global AI supply chains. It seeks evidence on how accountability is maintained through various governance and oversight mechanisms, and how organisations approach automated decision-making processes while ensuring meaningful human involvement. This theme is vital for understanding the distributed nature of AI development and deployment and the challenges in assigning liability and ensuring oversight. The fourth focus, "Transparency and rights in complex data environments," explores how organisations provide transparency when personal data is used at scale or collected indirectly, and how they enable individuals to effectively exercise their data subject rights, such as access and erasure. It also considers how data flows across different organisations impact the overall transparency of AI systems. Finally, the fifth theme, "Effectiveness of data frameworks in regulating AI," is a meta-analysis, questioning whether existing data protection principles and rights offer meaningful protection in practice. It probes the adaptability of current frameworks to future technological developments, such as agentic AI, and invites views on whether alternative regulatory approaches might be better suited to address specific risks inherent in AI and data-intensive technologies. Collectively, these themes aim to provide DSIT with a holistic understanding of the current landscape and inform future policy directions.
Implementation Framework
The "Data regulation in the age of AI and other data-intensive technologies" call for evidence serves as a critical preliminary step in the UK's implementation framework for adapting its regulatory approach to AI. Unlike a legislative act that immediately imposes new rules, this document is a consultative mechanism designed to inform future policy and legislative actions. The evidence gathered through this process will directly influence whether the government decides to issue further guidance, implement targeted legislative changes, or undertake more fundamental reforms to the existing data regulatory frameworks. This iterative approach reflects a commitment to evidence-based policymaking, ensuring that any future interventions are proportionate, effective, and responsive to the real-world challenges and opportunities presented by AI and data-intensive technologies. The intention is to strike a delicate balance between fostering innovation and ensuring robust protections for individuals, thereby building public trust in these rapidly evolving technologies. The insights collected will be rigorously analysed by DSIT to identify specific areas where current regulations create friction, where uncertainty deters responsible innovation, or where existing protections may be insufficient in the face of new technological capabilities.
The implementation framework following this call for evidence will likely involve several stages. Firstly, DSIT will synthesise and publish a summary of the responses received, highlighting key themes, common challenges, and innovative solutions proposed by stakeholders. This public summary will provide transparency on the consultation outcomes and lay the groundwork for subsequent policy development. Secondly, based on this analysis, the government may then proceed to develop specific policy proposals. These could range from non-legislative measures, such as updated guidance for organisations on applying existing data protection principles to AI, to more formal legislative changes, potentially amending the Data Protection Act or other relevant statutes. The framework also considers the role of non-regulatory activities, such as market-led data-sharing infrastructure initiatives, in complementing regulatory efforts to promote technology adoption. The ultimate goal is to ensure that the UK's data framework remains dynamic and adaptable, capable of supporting the nation's ambition to be a leader in AI while upholding high standards of data protection and public confidence. This phased approach allows for flexibility and responsiveness, enabling the UK to continuously refine its regulatory stance as AI technologies mature and their societal and economic impacts become clearer.
Monitoring and Evaluation
The "Data regulation in the age of AI and other data-intensive technologies" call for evidence itself constitutes a significant monitoring and evaluation mechanism for the UK's data regulatory framework. By proactively seeking practical examples and insights from a diverse range of stakeholders, the Department for Science, Innovation and Technology (DSIT) is undertaking a comprehensive assessment of how current regulations perform in the dynamic context of AI and data-intensive technologies. This consultative process is designed to identify what aspects of the existing framework are functioning effectively, where ambiguities or uncertainties create challenges for compliance and innovation, and where there might be gaps in protection or unintended consequences. The collection of detailed case studies, descriptions of governance processes, operational details, and existing research serves as a robust method for gathering empirical evidence on the real-world impact and effectiveness of data regulation. This direct feedback loop is crucial for the government to evaluate whether its current policy settings are achieving the desired balance between fostering technological growth and ensuring public trust and safety.
Following the closure of the call for evidence on 9 September 2026, DSIT will embark on a thorough evaluation phase. This involves analysing all submitted responses to identify recurring themes, divergent perspectives, and innovative proposals. The evaluation will focus on understanding how technological advancements, particularly in areas like agentic AI, might make compliance more difficult, create unnecessary regulatory barriers, or expose new vulnerabilities in existing protections. Conversely, it will also assess how emerging technologies such as synthetic data or Privacy Enhancing Techniques (PETs) could enhance privacy and facilitate regulatory compliance. The outcomes of this monitoring and evaluation exercise will directly inform future policy decisions, guiding DSIT in determining whether further guidance, targeted legislative amendments, or more fundamental reforms are necessary. This continuous cycle of monitoring through stakeholder engagement, evaluating the impact of existing frameworks, and adapting policy accordingly is fundamental to maintaining a regulatory environment that is both stable and responsive to the accelerating pace of technological change in the age of AI. The government's commitment to ensuring its data framework remains effective, proportionate, and adaptable underscores the importance of this ongoing evaluative process.
Penalties, Liability, and Appeals
It is important to clarify that the "Data regulation in the age of AI and other data-intensive technologies" document is a call for evidence, not a legislative instrument that introduces new penalties, establishes new liability regimes, or outlines specific appeal processes. As such, this document does not propose any new fines, sanctions, or criminal penalties. Instead, its purpose is to gather information and insights that will help the UK government assess the adequacy of existing regulatory frameworks in the context of AI and data-intensive technologies. Therefore, any penalties, liability provisions, and appeal mechanisms relevant to data use in AI currently fall under the scope of existing UK data protection law and other relevant sector-specific regulations.
Specifically, where AI systems process personal data, they are subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. These laws contain comprehensive provisions for enforcement, including significant fines for non-compliance (up to £17.5 million or 4% of annual global turnover, whichever is higher). They also establish principles of accountability, requiring organisations to demonstrate compliance, and include provisions for data subjects to seek compensation for damages suffered due to infringements. The Information Commissioner's Office (ICO) is the independent supervisory authority responsible for enforcing these laws and can issue warnings, reprimands, enforcement notices, and penalty notices. Individuals also have rights to lodge complaints with the ICO and to pursue judicial remedies. While this call for evidence does not alter these existing provisions, the insights gathered will be crucial in determining whether the current liability and enforcement frameworks are sufficiently robust and clear to address the unique challenges posed by AI, particularly concerning issues like algorithmic bias, autonomous decision-making, and complex data supply chains. Any future legislative or policy changes resulting from this consultation would then address whether adjustments to these penalty, liability, and appeal mechanisms are warranted to ensure effective oversight and redress in the AI era.
Relationship to Other Instruments
The "Data regulation in the age of AI and other data-intensive technologies" call for evidence is explicitly positioned within the broader landscape of existing UK legal and regulatory instruments governing data and technology. It acknowledges that several frameworks already dictate how personal and non-personal data can be used, and its primary aim is to understand how these established rules interact with the emerging realities of AI. Central to this existing framework are the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA), which together form the cornerstone of personal data protection in the UK. These instruments are directly relevant as AI systems frequently rely on personal data for training, testing, and deployment. The call for evidence specifically highlights challenges in applying elements of the UK data protection framework, such as lawful bases for large-scale personal data use (including special category data), data minimisation, purpose limitation, data subject rights, and the allocation of roles and responsibilities across data-intensive supply chains.
Beyond the core data protection legislation, the document also references the Privacy and Electronic Communications Regulations (PECR), which govern electronic marketing and the use of cookies and similar technologies, and parts of the Digital Economy Act, which facilitates data sharing for public service delivery. Furthermore, it notes the existence of sector-specific regulations, such as those in the Health and Social Care sector, where stringent requirements like de-identification, restricted access for approved purposes, and data minimisation are crucial for safeguarding patient data. The government has also taken recent steps to modernise parts of this framework through the Data (Use and Access) Act, which introduced targeted amendments to data protection law and established initiatives like smart data schemes to enable greater innovative data uses. The Information Commissioner’s Office (ICO), as the UK’s independent data protection authority, has also been actively examining how the existing data protection framework applies to AI, including through its generative AI consultation and published guidance. This call for evidence builds upon and seeks to complement these ongoing efforts, aiming to identify where further adjustments or clarifications are needed to ensure a coherent and effective regulatory ecosystem that can accommodate the rapid evolution of AI and other data-intensive technologies.
International Alignment
The UK's "Data regulation in the age of AI and other data-intensive technologies" call for evidence explicitly acknowledges and positions its efforts within a wider international trend of governments and regulators grappling with the challenges posed by rapid technological change. The document notes that other jurisdictions are also considering how to respond to the proliferation of AI and data-intensive technologies, citing aspects of the EU’s recent proposed digital omnibus package as an example. This recognition underscores the UK's awareness that AI and data governance are global issues, and that achieving effective regulation often requires a degree of international alignment or at least an understanding of diverse approaches to ensure cross-border interoperability and avoid regulatory fragmentation that could hinder innovation or international trade. While the call for evidence focuses on the domestic UK context, the insights gathered will inevitably contribute to the UK's stance in international discussions and collaborations on AI and data policy.
The government's commitment to making the UK the fastest-adopting AI economy in the G7 implies a strategic imperative to ensure its data regulatory approach remains competitive and conducive to attracting international investment and talent in the AI sector. This necessitates a careful balance between establishing robust domestic protections and fostering an environment that is not unduly burdensome or misaligned with global best practices. By seeking to understand where existing data regulation creates friction or uncertainty for organisations operating with AI, the UK aims to refine its framework in a way that promotes responsible innovation without stifling growth. This proactive engagement with stakeholders to assess the adaptability of its frameworks to future developments, such as agentic AI, reflects a forward-looking approach that considers the global trajectory of AI development. Ultimately, the insights from this call for evidence will help shape a UK data framework that not only meets domestic societal expectations regarding data use but also facilitates international cooperation and ensures the UK remains a key player in the global AI ecosystem.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Call for Evidence Published | 2026-07-15 | The Department for Science, Innovation and Technology (DSIT) launched the call for evidence. |
| Call for Evidence Closes | 2026-09-09 | Deadline for submitting responses to the call for evidence. |
| Analysis of Evidence | Post 2026-09-09 | DSIT will analyse the submitted practical examples and insights to inform future policy. |
| Potential Future Policy/Guidance | TBD | Based on the evidence, DSIT may issue further guidance, targeted changes, or fundamental reform. |
Compliance Checklist
| Check | Required Action |
|---|---|
| Provide practical examples or case studies | Submit short, worked examples explaining current practices, desired but unpursued actions, or areas of uncertainty in data regulation's interaction with AI and data-intensive technologies. |
| Describe governance or decision-making processes | Detail the practical steps and frameworks your organisation uses for data governance and decision-making in the context of AI. |
| Offer operational detail on technology implementation | Provide technical, organisational, or contractual specifics regarding the implementation of relevant AI or data-intensive technology products or tools. |
| Share existing analysis, data, research, or evaluations | Submit any relevant existing (published or unpublished) analysis, data, research, or evaluations that can inform the government's understanding. |
| Address relevant themes | Respond to as many or as few of the five key themes (Accessing and using data; Data quality, accuracy, and downstream impacts; Governing data use across organisations; Transparency and rights in complex data environments; Effectiveness of data frameworks in regulating AI) as are pertinent to your experience. |
Sources and References
| Source | Type |
|---|---|
| Data regulation in the age of AI and other data‑intensive technologies | government |
| Data regulation in the age of AI and other data‑intensive technologies (Full Document) | government |
Related Regulations
United Kingdom AI Regulation Overview
United Kingdom89% similar
Ofcom's 2026/27 AI Strategy
United Kingdom87% similar
AI for Science Strategy
United Kingdom87% similar
A Pro‑Innovation Approach to AI Regulation (White Paper)
United Kingdom87% similar
Artificial Intelligence (Regulation) Bill [HL]
United Kingdom87% similar
© Regulations.AI — created on 22-Jul-2026 using Gemini 2.5 Flash