The UK is about to learn the hard way that “responsible AI” needs receipts
The ICO’s March 2026 update on its AI and biometrics strategy is a reminder that UK regulators are no longer talking about AI in the abstract. The direction of travel is clear: organisations will be expected to show, in plain operational terms, how automated decisions are governed, challenged, and corrected.
That matters because most organisations still treat compliance as paperwork. Strategy documents and principles are useful, but they do not answer the question that lands in real disputes: what did the system do to this person, in this case, on this date, and why?
This is not a niche edge case. It is the everyday reality of high-impact, high-volume decisioning: recruitment shortlists, benefit eligibility, fraud flags, credit limits, pricing, access control, and any biometric gate that decides who is verified, blocked, or put into manual review. When outcomes are hard to explain, the risk is not just bias. It is operational failure: appeals that cannot be answered, complaints that drag on, and managers who cannot tell whether a model is helping or quietly breaking policy.
The next phase of UK AI governance needs to look less like ethics theatre and more like engineering discipline: decision-level logs, clear human override paths, and “prove it” controls that stand up when challenged. Without that, “trustworthy AI” collapses the first time a regulator asks for evidence rather than intent.


