When the National Audit Office examined the machine learning model that scores Universal Credit advance requests for fraud risk, it found the Department for Work and Pensions had managed to test fairness against exactly one of the nine characteristics protected by the Equality Act 2010. Age. Not because the department declined to examine the remaining eight, but because it did not hold enough claimant data to examine them at all. That finding, published by the NAO in October 2025, compresses the UK’s AI governance gap into a single sentence: a live algorithm making consequential decisions about people’s money, a fairness assessment bounded by whatever data the state happens to hold, and no external body mandated to insist on better.
What Britain chose instead of a rulebook
The UK’s regulatory position was set by a 2023 White Paper and has not been seriously revisited since. No immediate legislation. No dedicated AI regulator. No enforceable rules spanning sectors. Existing regulators were instead asked to apply five principles inside their own patches: the Information Commissioner’s Office, Ofcom, the Financial Conduct Authority, the Competition and Markets Authority and others. Safety. Transparency. Fairness. Accountability. Contestability.
Read as a statement of values, that list is unobjectionable. Read as law, it is not law. The principles carry no statutory force, no regulator is funded to police them horizontally, and nothing obliges a public body to tell you an algorithm was involved in a decision about your claim, your housing application or your risk score. A dedicated AI Bill has been signalled repeatedly without appearing. A Private Member’s Bill tabled in the Lords in March 2025 would create a central coordinating authority, but it has no government backing and, on the usual arithmetic for such bills, will not reach the statute book.
Writing for LSE British Politics and Policy, Peter Chai, a Research Associate at Waseda University, argues this is not merely a regulatory omission but a constitutional one. An algorithm shaping decisions about benefits, policing or housing is exercising public power, and public power in this country is meant to arrive with a route to contest it.
Strategic Reality: The five AI principles are the UK’s entire cross-sector framework, and not one of them is enforceable. An organisation contracting with government on an AI system inherits that ambiguity rather than a compliance checklist.
| What exists | What does not |
|---|---|
| Five non-statutory AI principles for regulators | Any legal obligation to apply them |
| Sector regulators with existing powers | A body mandated to oversee public-sector AI as a whole |
| The Algorithmic Transparency Recording Standard, mandatory for Whitehall since February 2024 | Any equivalent obligation on councils |
| Judicial review, in principle | A low-cost route for an individual to contest an algorithmic decision |
| An AI Bill, signalled since 2023 | An AI Bill |
What the DWP case actually shows
The department has run its Universal Credit advances model since May 2022. Claims scored as high risk go to a caseworker before payment is released. The NAO puts estimated savings from the model at £4.4 million, and found it identified fraud risk roughly three times as often as a randomised control sample did. Over the three years ending March 2025, data and analytics work received £73 million of earmarked funding, against £447 million for Targeted Case Review and £364 million for counter-fraud resource. The algorithm is real, it beats chance by a wide margin, and it is a modest line inside a far larger counter-fraud programme.
The fairness assessment is the interesting part. The department runs this analysis only where it holds data covering at least 70 per cent of the relevant population, a sensible threshold that stops thin samples generating confident nonsense. Claimants supply their date of birth when they apply, so age clears it comfortably. The equality questionnaire that would capture everything else is optional, and the share of referred claimants answering it with anything other than “prefer not to say” fell below that bar. Eight characteristics therefore went untested. What the department examined alongside age were attributes carrying no protection in law, nationality among them.
The results, published in detail for the first time in July 2025, show the model underperforming for particular groups. Claimants in age bands from 45 to 54 upwards, and non-UK nationals, are referred for review at rates out of step with the fraud actually found among them. A referral is not a refusal. Legitimate requests get approved once a caseworker has looked. But the claimant supplies the additional evidence first, and someone already waiting on an advance payment is poorly placed to absorb that delay.
Critical Context: Nationality is not a protected characteristic in UK equality law, which is exactly why the disparity found here sits outside the usual equality framing. Some coverage has described it as protected. It is not, and that distinction changes which legal remedies an affected claimant can reach for.
Then there is the transparency standard, mandatory since February 2024 across departments and arm’s-length bodies that run front-line services or deal directly with the public. In its July 2025 cross-government review, the NAO found most analytics tools deployed against fraud and error had not complied with it. The department told auditors it expected to be compliant before 2026. A mandatory standard that most in-scope tools have not met is a voluntary one with better branding.
The gap runs in both directions
The usual framing pits citizen protection against state efficiency. The evidence does not support that trade-off as cleanly as it is normally drawn.
Officials told the NAO that publishing detail about fraud analytics can hand fraudsters a map, which is a real tension rather than an excuse. More striking, the Cabinet Office reported being unable to draw on records of earlier fraudulent conduct, or to run network analysis linking officials to suppliers, because of wording in the Local Audit and Accountability Act 2014 barring data matching that identifies patterns suggesting no more than someone’s future propensity to defraud. So the same vacuum leaving a claimant without a clear route to challenge a risk score also leaves counter-fraud teams unsure what they are permitted to build. Missing rules are not deregulation. They are uncertainty, and uncertainty costs money on both sides of the counter.
The contrast with Brussels deserves stating precisely, because it is frequently overstated. Under the EU AI Act, systems used in welfare, law enforcement and migration land in the high-risk category, which brings obligations covering transparency, meaningful human oversight, and rights to information for the people affected. Breaching those obligations attracts administrative fines reaching €15 million or 3 per cent of worldwide annual turnover. The larger headline figure, €35 million or 7 per cent, is reserved for the practices Article 5 prohibits outright, not for high-risk non-compliance. The substantive difference from Britain is not the size of the fine. It is that an affected individual holds enforceable rights at all.
| Stakeholder | Exposure under the current UK approach |
|---|---|
| Citizen subject to a decision | May never learn an algorithm was involved; no low-cost route to contest it |
| Public body deploying AI | Non-binding principles, unclear legal limits on legitimate data use |
| Supplier to government | Obligations vary by buyer; no common assurance standard to build against |
| Sector regulator | Expected to apply five principles with no legal duty and no extra funding |
| Local council | Outside the transparency standard entirely, while running housing and eligibility decisions |
What should fill the gap
Chai proposes three steps, and they are the right three. Put the five principles on a statutory footing so regulators hold a duty rather than an invitation. Extend the transparency standard to councils as a precondition for running AI in decisions touching individual rights. Give citizens an accessible administrative appeal, with an obligation on the public body to explain in plain language how the decision was reached.
Each carries a known weakness, and it is worth being honest about them. Statutory duties are worth only as much as the enforcement standing behind them, and regulators are not being handed new budgets. Registration confirms a tool exists without establishing whether it treats people fairly, which is the job of independent audit. An appeals route means little if the explanation a claimant receives is intelligible to a data scientist rather than to the claimant.
For organisations that are not government but sell to it, or that run AI inside any regulated decision, the practical implication is different and more immediate.
If you are early in deployment: Record which decisions involve a model and which are wholly human, before anyone asks. That register is the artefact every subsequent obligation gets built on.
If you are already in production: Run the fairness analysis you can run, and document why the rest is out of reach. A published data-coverage threshold is a defensible, auditable position. “We did not look” is not.
If you are contracting with the public sector: Ask which transparency obligations bind the buyer, and assume they tighten within the contract term. Retrofitting assurance later prices worse than recording it now.
Implementation Note: The DWP’s method is a reasonable default for private-sector deployments in regulated decisions. Set a data-coverage threshold, analyse only above it, publish what you found, and state plainly which attributes you could not assess and why.
Four problems nobody is solving yet
The fairness data paradox. Testing a model for bias across protected attributes requires holding data on those attributes. Collection is optional, minimisation is a legal virtue, and equality questionnaire response rates are low. The stronger your data-minimisation posture, the blinder your fairness testing gets. Mitigation: treat equality-monitoring data as a distinct, tightly scoped purpose with its own retention and access controls, rather than folding it into general processing.
Transparency as an attack surface. Publishing how a fraud model scores risk hands a determined fraudster precisely what they want. Mitigation: separate what you publish about a system’s purpose, oversight and measured outcomes from what you publish about its features and thresholds. The former is the accountability requirement; the latter rarely is.
Duties without capacity. Imposing obligations on regulators nobody has resourced converts a governance gap into compliance theatre. Mitigation: sequence the duty behind a funded audit function, or accept that the early years yield paperwork rather than scrutiny.
Councils are where the decisions land. Housing eligibility, social care triage and school placement are local functions, and local government sits outside the transparency standard. Mitigation: buyers and suppliers should adopt the standard voluntarily at council level now, because the alternative is a retrofit under deadline once it becomes mandatory.
Warning ⚠️: No UK statutory AI framework does not mean no legal risk. Equality law, data protection law and public law duties all bite on algorithmic decisions today. What is missing is a workable route for individuals to invoke them, and that route is the piece most likely to arrive first.
The takeaway
Britain made a defensible bet in 2023. Technology-specific law dates quickly, and asking established regulators to stretch existing doctrine avoids freezing a fast-moving field into statute. The bet’s flaw is not excessive permissiveness. It is that AI governance was treated as a regulatory and commercial problem when it is also a constitutional one, and the constitutional half has no owner.
Three things determine whether an organisation comes through the next phase well. Know which of your decisions are model-influenced, and be able to say so on demand. Be able to explain any one of them in language a non-specialist would accept. Hold measured, published evidence of how the system performs across groups, honest gaps included. Almost everything a future statutory regime is likely to demand reduces to those three, and none of them requires waiting for the Bill.
A companion piece to this one argues that the UK already has algorithmic accountability law, and departments are designing their way out of it. The two failures compound: the statutory protections that do exist get switched off by design, and the governance machinery that would catch that was never built. Also relevant: where the UK sits among national AI governance models, the accountability gap in AI procurement, and why UK government AI projects keep stalling.
Sources and attribution
Primary argument: Peter Chai, “The UK’s AI governance gap”, published 2 June 2026 by LSE British Politics and Policy. Chai is a Research Associate at the Faculty of Political Science and Economics, Waseda University.
Figures on the Universal Credit advances model, its fairness analysis, departmental funding and transparency-standard compliance come directly from two National Audit Office reports: Tackling benefit overpayments due to fraud and error (October 2025) and Using data analytics to tackle fraud and error (HC 988, July 2025). Where the NAO and secondary accounts diverge on the detail of the fairness assessment, the NAO figures are used here. Penalty tiers follow Article 99 of the EU AI Act.
Analysis by Resultsense. We make sense of AI in the UK for professionals and businesses working out what the technology actually changes.