Britain's AI Data Review: A Consultation That Admits the Framework Is Broken
On 15 July 2026, DSIT opened a call for evidence on whether UK data law is fit for an AI economy. The fact that government is asking the question at all tells you the answer.

At 09:00 UTC on 15 July 2026, the Department for Science, Innovation and Technology quietly opened what may be the most consequential regulatory admission of this government's tenure. The call for evidence, titled "Data Regulation in the Age of AI and Other Data-Intensive Technologies," runs until 9 September 2026. Its existence is itself an indictment.
Britain has spent three years insisting that its principles-based, sector-led approach to AI governance is a competitive advantage. Light-touch. Pro-innovation. Adaptive. That was the story. And now DSIT is formally asking industry to document where the existing framework "creates friction," where uncertainty persists, and whether the answer is guidance, targeted legal change, or something more fundamental. When a government department solicits evidence of its own framework's failures, you are not reading a self-confidence exercise. You are reading a distress signal.
What DSIT Is Actually Asking
The call for evidence seeks practical examples of how personal and non-personal data regulation interacts with AI and other data-intensive technologies, and where legal or governance arrangements could better enable data use while managing harms. DSIT acknowledges that "emerging capability, like agentic AI, create new opportunities for the UK and highlight tensions with our existing data regulation."
That sentence should be read slowly. Not managed. Not addressed. Tensions. Agentic AI systems, those that take chains of autonomous actions across organisational boundaries, accessing multiple datasets, making inferences, triggering consequences, are already deployed at scale. Salesforce's 2026 Connectivity Benchmark Report found that 89% of UK organisations deploy AI agents, but only 54% have a centralised governance framework with formal oversight. The agents are running. The accountability architecture is not.
The companion review is equally telling. DSIT has simultaneously launched a call for evidence on whether public bodies should have more flexibility to charge above marginal cost for reusable public-sector data. This puts two levers on the same policy timetable that pull in opposite directions: clearer legal rules may reduce the cost of AI development, while broader charging flexibility for public datasets could raise the cost of obtaining the inputs that AI depends on. Britain is examining both the legal price and the access price of data-intensive innovation, without yet saying where either should settle.
That is not a strategy. That is a whiteboard.
The Accountability Vacuum
Hannah Arendt, writing about the machinery of bureaucratic diffusion, identified the particular danger of systems designed so that no single actor is responsible. She called it the rule of nobody. It is the precise structure Britain has constructed for AI governance.
There is no UK AI Act, and there will not be one for the foreseeable future. The government has confirmed as much, repeatedly. Instead, as Scaffold Digital's June 2026 analysis notes, "AI in the UK is governed through five existing regulatory regimes," distributed across the ICO, FCA, MHRA, Ofcom, and DSIT, with DSIT coordinating policy but holding no enforcement power whatsoever. DSIT issues guidance. It does not enforce. When something goes catastrophically wrong, the question of which regulator owns the failure will itself require litigation to resolve.
The House of Commons Treasury Committee sounded a specific alarm in January 2026: a "wait-and-see" approach to AI in financial services risks serious harm to consumers and the broader financial system. The FCA, for its part, reiterated that it does not currently plan to introduce AI-specific rules. The FCA's Mills Review, launched the same month, identifies AI as a systemic driver of change to 2030 and sets out seven priority recommendations, including securing the regulatory perimeter. Recommendations. Not rules. Not enforcement. Recommendations.
The ICO, to its credit, has at least named the problem clearly. Its January 2026 Tech Futures report on agentic AI highlighted risks including "reduced transparency due to agentic system complexity, and purpose creep and data minimisation concerns." The ICO's own data shows the architecture of accountability collapsing: the DRCF's 2026 warnings document seven categories of compliance risk, including fragmented accountability across model providers and deployers, prompt injection vulnerabilities, and action bundling without informed consent. One 2026 compliance forecast found that 63% of organisations cannot enforce purpose limitations on AI agents, 60% cannot terminate a misbehaving agent, and, most damningly, government respondents fared worse, with 90% lacking purpose binding on their AI deployments.
Government. Ninety percent.
The EU Is Not Waiting
While DSIT solicits evidence, Brussels has moved. The EU AI Act's Article 50 transparency obligations commence in August 2026. Prohibition on non-consensual intimate imagery generated by AI arrives in December 2026. Maximum fines sit at €35 million or 7% of worldwide turnover. The EU Commission and AI Board assessed the voluntary marking-and-labelling code of practice as adequate in July 2026, this month.
Britain departed the EU before the AI Act came into force. The government chose, deliberately, not to mirror Brussels. The UK's pitch is now, in the language of ministerial briefings, about being "the country that sets standards for how AI is deployed." But the EU Act has extraterritorial reach. Any UK organisation placing an AI system on the EU market, whose AI output is used in the EU, or whose AI affects EU residents in employment or public service contexts, falls within the Act regardless of UK domicile. Most organisations with European customers, which is most significant UK organisations, are therefore simultaneously subject to a regime with hard deadlines, hard enforcement, and hard fines, and a UK framework that is running a call for evidence about whether its rules work.
The divergence is not a competitive advantage. It is a compliance burden distributed asymmetrically onto businesses that cannot afford specialist legal teams for five jurisdictions.
Oppenheimer, after Trinity, said "now I am become Death." The men in the room did not stop the test to ask whether the theoretical framework for radioactive dispersal needed further evidence-gathering. The machine was already running.
The Public Data Charging Question Nobody Is Asking Loudly Enough
The companion review on public-sector data charging deserves more scrutiny than it has received. DSIT is asking whether public bodies should have more flexibility to charge above marginal cost for reusable data. Digital data can often be copied at negligible cost, so a strict marginal-cost approach frequently yields a zero or near-zero charge. Opening that up is framed as giving public bodies sustainable revenue to maintain data quality.
The risk calculation runs differently. The largest AI developers, OpenAI, Google DeepMind, Anthropic, have capital reserves that dwarf any UK SME or academic research institution. If public-sector data becomes a priced commodity with flexible charging, the entities most capable of paying premium rates for NHS records, HMRC datasets, or Met Office atmospheric data are the same American hyperscalers this government has been negotiating exclusive deployment deals with. This is not hypothetical. This is the structure of every extractive privatisation this country has undertaken since 1979.
DSIT insists the review covers only data already lawfully available for reuse and creates no new disclosure powers. That framing is accurate and insufficient. The question is not whether disclosure is lawful. The question is who can afford to access it, what they will build with it, and whether the public whose data generated the asset will ever see the benefit.
The call for evidence closes 9 September 2026. DSIT will then decide whether the evidence supports guidance, targeted amendment, or fundamental reform. It has not selected an outcome.
So let me ask the question DSIT will not:
If 90% of government AI deployments currently lack purpose binding, if agentic systems are already operating across organisational boundaries without adequate accountability structures, and if the primary legislative response is a call for evidence, at what point does a framework become, in law and in conscience, negligent?