
Responding to this week’s Joint Committee on Human Rights report, the trade body agrees with the diagnosis of the challenges facing businesses using AI – particularly in data and marketing, where organisations are grappling with opaque supply chains, uncertainty over data provenance and a lack of clarity around how existing rules apply to AI-enabled activity.
However, the DMA believes the answer is not necessarily more legislation. Much of the protection the Committee calls for already exists under UK GDPR, with even the Information Commissioner’s Office has told the Committee that the challenges are “not insurmountable under the current legislation”.
The trade body argues that policymakers should first focus on applying and enforcing the rules already on the statute book, before adding new layers of regulation.
The DMA raised these issues directly with Government officials at its Data & AI Engagement Day earlier this month, bringing together around 30 industry, government and DMA representatives to discuss how the UK’s data and AI framework is working in practice.
DMA director of policy and public affairs Michael Sturrock said: “On the diagnosis, we agree with the Committee. Industry leaders at the roundtables convened by the DMA with Government officials this month raised the same three problems.
“Risk sits in supply chains organisations cannot see into, there is no settled way to evidence where a dataset came from, and regulators do not have the technical capability to supervise how these systems are used.
“On the data protection framework, the regulator agrees with industry. The ICO told the committee that the challenges in privacy and data protection ‘are complex but we do not think they are insurmountable under the current legislation’, and that proposals for a new oversight body ‘should cover well-evidenced gaps that could not be addressed by empowering and resourcing current regulators’.
“Where we differ is the remedy. The report calls for new legislation. Our view is that the rules we already have need applying before anything is added. Where personal data is involved, the obligations the report asks for largely exist, and our members want to meet them.
“Organisations already have compliance reporting, audit and sign-off built around the ICO, which is the fastest route to changing behaviour. The immediate work is to carry through what is already in train and to enforce it. Then we can see what gaps remain.
“Members are carrying the cost of that uncertainty now. One member described campaigns not run because nobody could say the law covered them, and clients instructing their agencies to use no AI tool at all. Firms that invest in getting this right ought to see enforcement against those that do not.”
Related stories
Untrained and unsupervised: The real source of AI slop
ISBA: 99% of brands are using GenAI, few see benefits
DMA urges Govt to work with industry to drive AI boom
Three priorities for CMOs in the new AI-driven world
PwC: Act now so that data and tech spend gets results
Gartner: Industry must grasp ‘AI nettle’ or wither on vine
Decision Marketing at 15: The march of the robot army


Be the first to comment on "DMA: ‘UK must enforce GDPR before drawing up AI Bill’"