Who Gets to Decide What AI Is Allowed to Do?
Key Takeaways
- A cross-party UK parliamentary committee has called for a new AI bill, saying no country currently has a regulatory approach that is fit for purpose.
- The committee wants some uses banned outright, naming subliminal techniques and inappropriate use of profiling or biometric data.
- Days earlier, Anthropic published a report on blocking attempts to use its models for cyberattacks, surveillance, and influence operations.
- Right now the companies building these systems are also the ones deciding what counts as acceptable use, with no democratic process attached.
A cross-party group of MPs and peers has published a 100-page report arguing that existing law can't handle what AI is already doing to human rights. According to reporting by the BBC, published in September 2026, the Joint Committee on Human Rights wants a dedicated AI bill and a single independent oversight body established on a statutory basis.
Labour MP Alex Sobel, who chairs the committee, put it bluntly: nowhere in the world, including the UK, currently has a legislative approach to AI that works.
What the Committee Actually Wants
The recommendations are more specific than the usual call for "responsible AI," and two of them matter a great deal for anyone who cares about privacy.
The first is a risk-tiered regime, with heavier obligations on higher-risk systems, and duties applied across the whole lifecycle rather than landing on whoever happens to deploy the thing at the end.
The second is a list of uses that should be prohibited outright. The committee named subliminal techniques and inappropriate use of profiling or biometric data. It also pointed to AI being used to generate sexualised images of women and girls, and to scan faces without consent.
That second category is the one I'd underline. Facial scanning without consent isn't a hypothetical harm waiting to arrive. It's already embedded in age verification systems, retail security, and public space monitoring, and until now it's mostly been governed by whatever the company deploying it decided was reasonable.
The Companies Are Currently Grading Their Own Work
The timing here is useful, because the week produced a clear illustration of the problem.
According to reporting by Barbara Ortutay for the Associated Press, published September 11th, 2026, the AI company Anthropic released a report describing attempts to misuse its models. The company said it blocked efforts involving cyberattacks, surveillance tooling, and research that could have contributed to biological weapons.
One finding sits squarely in our territory. Anthropic said it identified groups creating hundreds of social media accounts designed to look like ordinary people, then using them to push a single political line. It outlined nine such operations, originating in Russia, Iran, Turkey, and across the Persian Gulf, South Asia, Africa, and Europe.
That's coordinated inauthentic behavior being assembled before it ever reaches a platform. It's genuinely useful that someone caught it.
But notice who caught it, and who decided what to do about it. John Thickstun, a computer science professor at Cornell, told the AP that this puts companies in an uncomfortable position, making value judgments at societal scale without any democratic or deliberative oversight.
He's right, and that's the argument for the committee's bill in one sentence.
Why This Should Matter to You
Self-regulation works until it doesn't, and you find out which one you're in afterward.
A company that publishes a report on the misuse it blocked is telling you about the cases it chose to disclose. There's no external auditor confirming the list is complete, no requirement to publish, and no consequence for deciding next quarter that transparency is bad for an upcoming public offering.
The same dynamic already governs most of what happens to your data online. Platforms set their own rules on tracking, retention, and profiling, then adjust them when it suits the business. The bodies that quietly shape internet governance operate largely outside public view, and by the time a rule reaches a parliament, the technical architecture it governs has usually been fixed for years.
Biometric profiling is the sharpest version of this. Your face isn't a password you can change after a breach. Once a system is built to scan it without asking, the question of whether that was permitted gets settled long after the cameras are installed.
I'd rather that question were answered by a statutory body that can be challenged in court than by a company's internal policy team, however well-intentioned. That's not cynicism about the people doing the work. It's just what accountability means.
The committee's report is a recommendation, not a law. Whether it becomes one depends on whether enough people notice it was written, which is a good reason to keep watching this particular fight.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
