A parliamentary committee is calling for mandatory AI disclosure, stronger accountability and new protections for creative workers. Here are the most important implications for agencies.
AI has rapidly become part of everyday agency life, from research and concept development to content production, recruitment, personalisation and customer communications.
But a major new parliamentary report suggests that the largely voluntary approach governing many of those applications may not last.
The Joint Committee on Human Rights has called for a dedicated AI Bill, mandatory transparency requirements and an independent regulator capable of investigating businesses, imposing sanctions and withdrawing systems from the market.
Its report, Human Rights and the Regulation of AI, contains recommendations to government rather than new legal requirements. The government has two months to respond.
It arrives as some of the technology industry’s most influential figures publicly question the speed of advanced AI development. As reported by The Guardian, OpenAI chief Sam Altman and Elon Musk have backed the broad direction of a call from Anthropic founder Dario Amodei to “slow the pace”.
For agencies attempting to balance innovation, client expectations and emerging risks, these are five of the report’s key points.
1. Agencies may have to disclose when and how they use AI
The committee wants mandatory transparency requirements to apply across the AI lifecycle.
Where an AI system could have a significant effect on an individual, group or community, organisations would have to say that it was being used and provide a “full and comprehensible explanation” of its purpose.
They could also be required to provide information about the source of the data used by the system.
For agencies, that could be relevant to automated customer communications, audience profiling, campaign personalisation, recruitment, casting and other applications which influence decisions about identifiable people.
It could also increase the information clients expect agencies to provide about AI-assisted creative work.
The report does not say that every routine use of generative AI would necessarily require public disclosure. Its recommended model would grade obligations according to risk, with fewer requirements for low-risk systems.
2. Responsibility could follow agencies through the supply chain
Modern AI projects often involve several organisations. A foundation model may be developed by one company, incorporated into a specialist product by another, customised by an agency and ultimately deployed by its client.
The committee says this makes it difficult to identify where a problem originated and who should be responsible.
Existing UK laws tend to place responsibility on the organisation deploying a system. The report argues that powerful technology companies can also use contractual terms to transfer risk to smaller organisations, even when those businesses cannot inspect or alter the underlying model.
It wants duties placed on actors throughout the supply chain, with responsibility allocated to those best positioned to identify and prevent harm.
That distinction matters for agencies. Depending on the project, an agency could be:
- A user of a third-party AI tool.
- A deployer operating a system for a client.
- A developer building an AI-enabled product.
- A supplier providing AI-generated content or automated services.
- An adviser influencing how a client applies the technology.
The proposed regime would differentiate between those roles and the seriousness of the associated risk. Agencies could not necessarily assume that responsibility rested entirely with either the platform provider or the client.
3. A human sign-off may not be enough
Many organisations currently rely on human approval as their principal safeguard against inaccurate, discriminatory or damaging AI output.
The committee warns that simply putting a person at the end of an automated process does not constitute meaningful oversight.
Its report recommends that UK GDPR regulations should make clear that “the mere presence of a ‘human in the loop’ is not enough to constitute meaningful human involvement or intervention”.
The reviewer would need to be sufficiently informed and independent to reach an objective view which had not been improperly influenced by the automated decision.
For an agency, that means human review should be substantive rather than a box-ticking exercise. The person approving an AI-assisted decision or piece of work may need to understand the system’s limitations, examine the relevant evidence and possess the authority to reject its output.
That could be particularly important when AI is used to shortlist candidates, select performers, profile audiences, moderate content or recommend actions affecting an individual.
4. Copyright, casting and cloned performances remain significant risks
The inquiry received evidence about copyrighted and professional creative work being incorporated into AI training datasets, as well as concerns about the rights of creators and performers.
The committee did not make detailed copyright recommendations because intellectual property was not a central focus of the inquiry. It did, however, conclude that the issues “clearly merit further investigation” and could require additional measures.
The report says it is important for the UK to protect its creative industries and safeguard performers’ human rights and livelihoods.
It cites evidence from Equity about a performer who agreed to provide a voiceover for non-commercial educational material intended to help visually impaired readers.
According to the union, a cloned version of her voice was subsequently “made available to others via a text-to-speech tool […] without [her] consent, control or pay”.
Potentially biased AI systems used for casting are also identified as a discrimination risk.
For agencies and production companies, the issues extend beyond conventional copyright clearance. Consent covering a recording or image for one project may not amount to permission to build a synthetic version of that person or reuse their likeness indefinitely.
The report does not settle those legal questions, but it makes clear that creator rights, data provenance, informed consent and protection against discriminatory selection are likely to remain central to the regulatory debate.
5. High-risk systems could require approval before launch
The committee proposes an independent AI oversight body with powers extending considerably beyond those available under the current fragmented regulatory system.
It wants the regulator to be able to:
- Test and evaluate high-risk AI systems.
- Require auditing before deployment.
- Investigate allegations of human-rights harm.
- Publish mandatory codes of practice.
- Sanction organisations that fail to comply.
- Order remedies for affected individuals.
- Block systems from being launched.
- Withdraw systems already on the market.
High-risk systems could require prior regulatory approval before being provided or deployed.
The committee also recommends prohibiting certain applications that are incompatible with human rights. Potential examples include subliminal techniques, emotional inference and inappropriate profiling or use of biometric data.
For the creative and marketing industries, that could be relevant to advertising technology claiming to detect emotions, biometric audience analysis, behavioural manipulation, automated recruitment and sophisticated profiling systems.
The precise prohibitions would be determined following a public consultation, meaning the report does not establish that every use of these technologies would automatically be banned.
What agency leaders can do now
The proposed AI Bill may change during the political and legislative process—or may not be adopted at all. But the report gives agencies a useful indication of the standards policymakers are considering.
Although the committee does not provide a specific compliance checklist for agencies, businesses can begin preparing by:
- Mapping the AI systems being used across the agency.
- Recording which tools and models contribute to client work.
- Checking the origin and permitted use of source material.
- Reviewing contracts with AI suppliers and clients.
- Establishing when AI use should be disclosed.
- Strengthening consent for synthetic voices, images and performances.
- Testing recruitment, casting and profiling tools for bias.
- Giving human reviewers the knowledge and authority to challenge outputs.
- Creating a process for complaints, corrections and withdrawal.
The committee insists that regulation should remain proportionate and avoid imposing unjustified burdens on smaller companies.