30 Jul 2025

EP21: Reviewing the AI Opportunities Action Plan: Getting the Foundations Right

In this special live episode of the UKAI Podcast filmed at UKAI’s 6 Month Review of the AI Opportunities Action Plan, former AI Minister and UKAI Advisor Matt Warman chairs a heavyweight panel of legal, regulatory and industry leaders to tackle the question: are the UK’s AI foundations fit for purpose? Joined by Fiona Ghosh (Ashurst LLP), Gaia Marcus (Ada Lovelace Institute), Sophia Ignatidou (ICO), and Amir Malik (Alvarez & Marsal), this session dives into the legal, ethical and commercial frameworks we need to unlock safe and sustainable AI adoption.

Trust, Regulation and the Future of AI: Building Confidence in the UK’s AI Economy

As the UK moves from AI ambition towards implementation, questions around regulation, trust, infrastructure and accountability are becoming increasingly important. A panel bringing together perspectives from the Ada Lovelace Institute, Ashurst LLP, the Information Commissioner’s Office (ICO) and Alvarez & Marsal explored what is holding back adoption — and what the UK needs to do to build an AI ecosystem that is both competitive and trustworthy.

Focusing the UK’s AI Ambitions

The UK’s AI Opportunities Action Plan contains 50 recommendations, but implementing all of them at once is neither realistic nor necessarily desirable. For Gaia Marcus of the Ada Lovelace Institute, the first step should be identifying where the UK has genuine comparative advantage and concentrating resources accordingly.

For most UK businesses, the challenge will not be developing frontier AI models. Instead, it will be deploying and adopting existing technologies effectively. This creates particular gaps around governance, liability and legal clarity.

There is also a more fundamental question: whether businesses are seeing enough value from AI to justify widespread adoption. Without a clear “bang for buck”, organisations may remain hesitant to invest at the pace policymakers expect.

The Search for Global AI Standards

For Fiona Ghosh of Ashurst, one question repeatedly comes up in conversations with clients: what is the global standard?

AI operates across borders, while businesses increasingly have global procurement strategies and technology systems. Although there is no single global legal framework for AI, organisations are already navigating a growing collection of standards and regulatory regimes, including the EU AI Act. This creates an opportunity for the UK to establish itself as a benchmark rather than attempting to create an entirely separate regulatory model.

The principles underpinning trustworthy AI — including accuracy, transparency, sustainability and trustworthiness — are increasingly international. Rather than defining itself through regulatory divergence, the UK could differentiate itself through openness and collaboration, using this as a foundation for inward investment.

Connecting AI Policy Across Government

AI policy cannot be considered in isolation. Financial-market reforms, the national payments vision, industrial strategy and the AI Opportunities Action Plan all intersect with the development and deployment of AI.

For businesses and their advisers, this creates a complex policy landscape. A more coherent vision across government would help organisations understand not only individual regulations, but how the different strands of economic and technology policy fit together.

The challenge is therefore not simply creating more AI policy, but creating a single direction of travel for the UK's digital and economic future.

Transparency Is Still a Major Barrier to Adoption

From the ICO's perspective, transparency remains one of the most significant barriers to AI adoption.

Businesses may want to adopt AI systems but lack sufficient information about what they are actually procuring. This can include uncertainty around training data, how systems have been developed and how their performance and risks can be monitored over time.

At the same time, organisations do not always have access to governance frameworks and tools that are sufficiently mature to manage those risks. This creates a cycle of uncertainty: businesses are unsure what they are buying, while also being unsure whether they have the capacity to monitor and govern it effectively.

Regulation Needs to Keep Pace with Innovation

The ICO has been working on AI-related issues for more than a decade and now works alongside other regulators through the Digital Regulation Cooperation Forum.

Its work reflects the breadth of AI's impact. Current priority areas include automated decision-making in government and recruitment, biometric and facial-recognition technologies used by law enforcement, and the lawfulness and transparency of developing foundation models.

The latter is particularly significant as foundation models become embedded across the wider technology ecosystem. This shift in perspective matters for regulation. Risks originating upstream in the development of foundational systems can ultimately affect businesses and consumers further down the deployment chain.

From National Sovereignty to User Sovereignty

The discussion around AI sovereignty extends beyond national infrastructure. Amir Malik of Alvarez & Marsal argued that there is an emerging question of user sovereignty: how much control individuals should have over the information, images, messages and other data they generate online.

The rapid development of generative AI has made this increasingly urgent. Deepfakes can use the likeness of individuals without meaningful control or consent, while personal communications and other digital content can become part of increasingly sophisticated AI systems.

For users, the question is becoming not simply whether their data can be used, but whether they have meaningful control over how their digital identity exists and is reproduced online.

Copyright, Consent and the AI Data Debate

This question also overlaps with copyright and data protection.

Fiona highlighted the tension between existing rights — such as the right to be forgotten — and copyright protections over images, artwork and other creative outputs. As AI systems generate new content from existing material, the boundaries between personal data, copyright and consent become increasingly complicated.

The central question is whether consenting to a particular use of a platform or social network should also mean consenting to AI systems using that information to generate something new. As AI becomes more capable, these questions will require increasingly sophisticated approaches to both regulation and individual rights.

Cybersecurity Cannot Be an Afterthought

Alongside regulation and infrastructure, cybersecurity emerged as a major concern.

AI adoption depends on secure digital infrastructure, yet the growth of AI systems also creates new opportunities for data leakage, manipulation and cyberattacks. Amir argued that greater attention needs to be given to organised cyber threats across organisations of all sizes.

For the ICO, cybersecurity also intersects directly with data protection. Models trained using personal data can create risks if that information is exposed, particularly when models are developed in one jurisdiction and subsequently deployed elsewhere.

The ICO is supporting government work on a code of practice for cybersecurity and AI, recognising that security needs to be considered alongside — rather than after — AI deployment.

Trust Is Not the Same as Trustworthiness

The panel also questioned what it actually means for the public to trust AI.

For Gus, the more useful concept is trustworthiness rather than trust. Public confidence should come from systems being transparent, accountable and capable of addressing problems, rather than from people simply accepting that AI is safe.

Research discussed during the panel suggests that public demand for regulation is increasing. An Ada Lovelace Institute and Turing Institute survey referenced by Gus found that 72% of the UK population wanted AI to be regulated, an increase on the previous survey two years earlier.

At the same time, public awareness of AI-related risks — from scams to deepfakes — appears to be increasing rapidly. The challenge is ensuring that understanding of AI's potential benefits develops alongside awareness of its risks.

Public Expectations Will Shape AI Adoption

The panel stressed the importance of remembering that policymakers, technology professionals and business leaders are not representative of the wider population.

The public's expectations around transparency, accountability and redress will increasingly shape how AI is adopted. People may be particularly sceptical where AI is used in contexts involving private companies, large technology platforms or decisions that directly affect their lives.

This makes understanding public attitudes an important part of AI strategy — not simply a communications exercise.

The Public Sector as a Test Case

Public-sector adoption could provide a useful benchmark for wider AI deployment. Because governments are held to a particularly high standard by the public, their use of AI can demonstrate what responsible deployment should look like. Transparency and mechanisms for redress are particularly important where automated systems affect citizens directly.

The panel also highlighted a potential problem for businesses: much of the risk created by AI can ultimately be pushed down to the organisation interacting directly with the consumer.

Businesses therefore have a reason to pay attention to how upstream foundation models are regulated, even if they are not themselves developing the underlying technology.

AI Is Transforming Workflows — and Creating New Risks

There was broad agreement that AI will fundamentally change everyday workflows and the nature of work. For businesses, however, the challenge is increasingly about implementation: finding the right talent, identifying valuable use cases and understanding how AI can actually transform an organisation rather than simply adding another layer of technology.

Amir described the market as roughly an 80/20 split. A smaller group of businesses remains uncertain about how AI will materially transform their operations, while a larger group is already asking practical questions about talent, implementation and strategy.

The competition for AI expertise is already intense, adding another challenge for the UK if it wants to remain a global leader.

Infrastructure and Sovereign AI

Infrastructure is another important part of the UK's AI opportunity. The panel highlighted growing interest in sovereign AI infrastructure, including compute capacity and the wider systems needed to develop and deploy AI. Governments increasingly have to think not only as regulators, but as providers and enablers of critical technological infrastructure.

This is attracting interest from investors and global funds, creating an opportunity for the UK to accelerate conversations around investment in AI infrastructure.

A UK Advantage in AI Innovation

Despite the challenges, the panel identified significant reasons for optimism. The UK already has a strong AI ecosystem, spanning established research institutions, frontier technology companies and emerging startups. AI and robotics, as well as applications in healthcare, could create significant opportunities for innovation and economic growth.

The question is how to combine that existing strength with the infrastructure, talent, regulation and security needed to scale it.

For Fiona, there are already signs of this potential through the quality of investment and deal flow entering the market. The opportunity is significant, but it needs to be matched by ambition and a clear direction.

From Ambition to a Clearer Vision

The panel's perspectives on the UK's current position ranged from cautious optimism to significant concern. What united them was the recognition that AI is moving faster than traditional approaches to governance can comfortably accommodate.

The UK therefore faces a balancing act: moving quickly enough to capture economic and technological opportunities while building safeguards that protect people and maintain public confidence.

For the UK to turn its AI ambitions into sustained advantage, the next phase will require prioritisation, global interoperability, practical regulation, cybersecutity, investment in infrastructure and greater user control.

Ultimately, the challenge is not simply to build an AI economy, but to establish a clear vision for the role that data and AI should play in British society — and to make sure innovation develops at a pace that people can trust.