The ICO becomes the Information Commission this week, the UKJT says contracts (not new law) will settle who’s liable for AI harm, and a workplace monitoring consultation closes on Tuesday.
This week’s AI Governance news:
Three things landing in the same week, all worth five minutes of your time.
The ICO changes its name and its board structure on 30 September. A government consultation on workplace monitoring tech closes the same day. And the UK Jurisdiction Taskforce has published a legal statement that answers a question a lot of you have been asking: who’s liable when AI gets it wrong.
Here’s what each one means for you, and a prompt at the end to help you act on it.
1. The ICO becomes the Information Commission on 30 September
Source: Information Commissioner’s Office
Following the Data (Use and Access) Act 2025, the ICO formally becomes the Information Commission on 30 September 2026, with a new board and seven non-executive members appointed back in July. The regulator says it will “continue to be known as the ICO” and that its powers over UK GDPR, freedom of information and direct marketing are unchanged.
Why it matters for you
Nothing in your compliance programme needs to change this week. But it’s worth a line in your next board or risk update, if only so nobody is confused when correspondence starts arriving from the “Information Commission” rather than the ICO. Treat it as a prompt to check you’re still watching the right guidance pages under the new structure, not a reason to do anything differently.
Action: Note the name change in your next data protection update and confirm your monitoring of ICO guidance still points to the right place.
2. Workplace monitoring consultation closes 30 September
Source: UK Government consultation on workplace monitoring technologies
The government’s consultation on regulating monitoring tools in the workplace, covering AI-driven tracking, productivity software and similar tech, closes on 30 September. The eight proposed principles (purpose, transparency, worker engagement, fairness, proportionality, human oversight, dignity, and accuracy) largely mirror obligations you already have under UK GDPR and the Data Protection Act 2018.
Why it matters for you
If your organisation uses or is considering monitoring software, this is a useful checklist even before any new rules land, because the underlying data protection obligations already apply. If you haven’t responded to the consultation and have views worth registering, this week is your last chance.
Action: Run your current or planned monitoring tools against the eight principles now, rather than waiting for the consultation outcome.
3. UKJT: existing law can handle AI liability, no new legislation needed (yet)
Source: UK Jurisdiction Taskforce legal statement
The UKJT has concluded that English common law is equipped to deal with AI-related harm without immediate legislative reform. The headline points for in-house teams:
Liability across the AI supply chain flows primarily through contract, so your vendor agreements are doing more legal work than you might think.
Where contracts are silent, ordinary negligence principles fill the gap, including potential liability for not using AI where a competent professional would have.
If you deploy a customer-facing chatbot, you’re likely to be treated as responsible for what it tells your customers.
Record-keeping, human oversight, due diligence and transparency are likely to be decisive when liability questions arise.
Why it matters for you
This is the clearest steer yet that your AI governance paperwork isn’t a box-ticking exercise, it’s your actual legal defence if something goes wrong. If your AI vendor contracts don’t clearly allocate liability, or your team can’t show how AI-assisted decisions were reviewed, that’s the gap to close first.
Action: Pull your top three AI vendor contracts this week and check they actually address liability allocation, not just data processing and IP.
This week’s prompt
Copy this into Claude or ChatGPT and adapt the bracketed details:
You are reviewing an AI vendor contract for legal liability gaps,
and flagging what our insurers need to know.
I am in-house counsel reviewing a contract with an AI vendor
([vendor name / type of tool, e.g. “AI-powered contract review tool”]).
Read the liability, warranty and indemnity clauses I paste below and:
1. Identify whether the contract clearly allocates responsibility
for harm caused by the AI system’s outputs (not just data
protection or IP infringement).
2. Flag any clauses that appear to exclude or cap liability for
AI-generated errors, and note if the cap looks disproportionate
to the risk of the use case.
3. List what governance evidence I should be keeping on my side
(oversight records, review logs, sign-offs) so that, if a dispute
arose, I could show reasonable human oversight was exercised.
4. Suggest two or three specific amendments I could propose to the
vendor to close the biggest gap you find.
5. List, in plain English, what our insurance broker or insurer
would need to be told about this specific use of AI, for example
what decisions the system influences or makes, whether it’s
customer-facing, what data it touches, and how much human review
sits between the AI’s output and any action taken on it. Flag
anything here that looks like the kind of material fact an
insurer would expect to be disclosed at renewal.
6. Set out what to check for in the relevant insurance policy
(professional indemnity, cyber, technology E&O, or D&O, whichever
applies), specifically:
- Whether the policy contains an AI exclusion, or wording that
could be read to exclude AI-related claims (e.g. exclusions for
“automated decision-making” or “non-human agents”)
- Whether “professional services” or “your product” definitions
are wide enough to cover AI-assisted or AI-generated work
- Whether cover responds to claims arising from a vendor’s AI
acting autonomously or outside expected parameters (relevant
given the Australia story this week)
- Any notification or disclosure conditions that our AI
governance evidence (from point 3) would help us satisfy
- Whether sub-limits or aggregate caps on “technology” or “cyber”
claims would meaningfully cover the exposure in this contract
Keep the output as two short tables: one for the contract review
(clause / issue / suggested fix), and one for the insurance points
(question / why it matters / who to ask, i.e. broker or insurer),
followed by a three-sentence summary I could put in front of a
non-lawyer stakeholder.
[Paste the relevant contract clauses here]
For the full contract review agent consider upgrading to a paid subscription.
That’s it for this week. If you’re working through any of this and want a second pair of eyes on a vendor contract or your governance paperwork, just reply to this email.
Richard



