The Digital Regulation Cooperation Forum (DRCF) (which includes the CMA, FCA, ICO and Ofcom), has published insights about how it aims to advance the safe and effective use of generative AI across its member regulators. It aims to strengthen regulatory capability, consumer protections and ensure alignment with the UK Government’s AI Opportunities Action Plan. The insights focus on key areas including strengthening governance, building capability and identifying harmful online design patterns.
Regulators have focused heavily on the development of robust governance frameworks aimed at making sure that AI systems are transparent, secure and well-managed. These frameworks can help to reduce risks such as hallucinations, bias and data misuse. The FCA has introduced policies relating to data management, privacy and risk. Strong governance is viewed as vitally important across the DRCF to ensure AI supports regulatory outcomes and maintains public trust.
Regulators are also investing in prompt engineering skills to improve reliability and usefulness of large language model outputs. Examples of these include contextual prompting, persona definition and constraint-based instructions. Some regulators are trying more advanced methods like chain-of-thought reasoning or linking multiple prompts. Shared prompt libraries and training sessions enable consistent AI capability across teams and regulators.
DRCF members have also started using AI tools to detect harmful online design patterns, such as drip pricing, misleading scarcity claims and manipulative choice architecture which may distort consumer decision-making. The CMA and ICO have published classification frameworks and guidance to support enforcement, and Ofcom has used behavioural audits to assess compliance under the Online Safety Act 2023. This type of detection supports regulators in monitoring practices at scale and allows quick responses to emerging risks.
In addition, regulators are experimenting with AI systems that can simulate consumer journeys across digital services. The CMA’s AI model can scan multiple websites to identify infringements such as drip pricing, while the FCA’s pilot that used large language models to detect “sludge practices” demonstrated efficiency gains while highlighting the need to ensure careful prompt design and human oversight. These types of tools offer a potential solution to more scalable, proactive regulatory monitoring.
Steps have also been taken to ensure AI systems are safe and effective, with member regulators developing evaluation frameworks assessing model outputs against reference answers using predefined criteria. These frameworks help to identify failure modes, standardise testing and support controlled scaling. Shared frameworks can help reduce duplication and improve consistency across different regulators.
The DRCF’s work demonstrates a transition from an experimental approach to more practical, scalable use of generative AI across UK regulators. In sharing insights, developing common practices and aligning with the UK government’s strategy, the DRCF aims to shape a regulatory ecosystem which embraces innovation and safeguards the public. The regulators say that they will continue to collaborate to respond to and support further AI evolution and ensure responsible use across regulators.