Product1 publisher3 min readPublished
OpenAI's first ask for binding UK AI rules covers a much shorter list than MPs want
The Joint Committee on Human Rights wants stricter duties on higher-risk systems and an oversight body written into law. OpenAI says it would accept a narrow frontier-only law on security risks. The two asks name different companies.
The Product Desk · Product desk

What happened
- The Joint Committee on Human Rights published Human Rights and the Regulation of AI on 14 September, finding that UK law covers some AI systems while leaving serious gaps.
- On the same day OpenAI said it would back binding UK rules for the few companies building the most powerful AI. Politico reported that this is the first time the company has done so.
- The report says the AI Security Institute tests frontier models before release but holds no regulatory authority and cannot demand access to them.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint Under the frontier-only scope OpenAI endorsed, a company deploying a workplace monitoring tool keeps the obligations it already has, and its staff keep the routes to complain they already have.
- decision With pre-release testing still voluntary and Anthropic having already skipped it for Mythos 5.1, buyers who want independent testing have to write it into the contract themselves.
- contradiction The committee's chair says no country's approach is fit for purpose while the business secretary warns against being hyperbolic about AI risks, so the timing depends on which view the government acts on.
- precedent OpenAI has now asked two legislatures for capability-based mandates. A threshold test on model capability is the shape other labs will be pressed to accept or argue against.
A workplace system flagged drivers for discipline after they stopped at traffic lights. The Joint Committee on Human Rights lists that among the harms it says existing UK law does not cover [8]. The bill OpenAI said it would support would not reach it.
The committee's version would. It asks for stricter obligations on higher-risk systems, mandatory transparency across the AI lifecycle, a ban on uses it considers incompatible with human rights, and an independent oversight body set up in law [2]. It also wants more responsibility placed on the developers of foundation models, not only on the companies that deploy them [3].
OpenAI's version stops a long way short of that. Tom Duff Gordon, the company's head of policy for Europe, the Middle East and Africa [9], told Politico that any law should focus narrowly on national security and cybersecurity risks and should cover only the small number of labs and models at the frontier [11]. He asked for compulsory independent testing by third parties and rules for monitoring and reporting safety incidents [12]. "OpenAI is in a position to support legislation in the U.K. to establish durable, mandatory, capability-based requirements for frontier AI," he told Politico [10]. OpenAI said the rules should not cover startups working on less powerful systems [13].
"Nowhere in the world, including the UK, has a current legislative and regulatory approach to AI that is fit for purpose," said Alex Sobel, the Labour MP who chairs the committee [15]. Most of what his report catalogues is deployment. Police facial recognition scanned around 3 million faces in the UK without consent between January and October 2025, by the committee's estimate [6]. Across those ten months that averages roughly 300,000 faces a month [7].
The government has had a mandate since 2024. Labour's manifesto that year promised binding regulation for the handful of companies developing the most powerful models, the legislation has not been introduced, and ministers have relied on sector regulators and voluntary testing through AISI, Politico reported [18]. A government spokesperson told the Guardian: "We should not assume that the existing framework will always be sufficient as AI capabilities develop. Any future measures will be evidence-based and focused on the risks we need to address" [19].
For anyone with a rollout to defend, the useful split has two axes. The first is whether you train the model or deploy someone else's. The second is whether the system makes decisions about people. OpenAI has agreed to be regulated in one cell of that grid, the cell it occupies, and everything else waits on a bill nobody has written yet. In the meantime the question is which regulator takes the complaint when a system you shipped gets a person wrong. The committee found that no single body coordinates AI regulation in the UK and that people harmed by AI can struggle to find who is responsible [5].
What to watch
- Whether the government introduces the binding frontier bill its 2024 manifesto promised, and whether the text carries duties for deployers as well as labs.
- Whether AISI is given statutory power to demand model access. That would end the voluntary pre-release test regime.
- Whether ministers set a date for ratifying the Council of Europe AI convention the committee asked them to commit to.