Select Committee seeks clarity on UK government’s plans for science, innovation and tech policy
After the UK government announced plans distribute the Department for Science, Innovation and Technology (DSIT) responsibilities amongst other departments, MPs have written to three Secretaries of State asking them for further details about how this will work in practice. The Prime Minister announced his Cabinet members on 21 July, revealing that DSIT’s responsibilities will be allocated to the Cabinet Office and two bolstered departments for Business, Innovation, Science and Trade, and for Digital, Culture, Media and Sport. Dame Chi Onwurah, Chair of the House of Commons Science, Innovation and Technology Select Committee, asks if media reports detailing the destinations of former DSIT teams are accurate and when these details will be confirmed; when the transition of DSIT teams to their new departments will be finalised, and when the portfolios of all relevant ministers will be confirmed.
Legal Services Advisory AI Growth Lab launched
The UK government has launched the Legal Services Advisory AI Growth Lab, a new regulatory sandbox aimed at accelerating the safe adoption of AI in the legal sector by giving organisations coordinated access to key regulators and government bodies. The initiative is designed to help AI developers, law firms, conveyancers and other legal services providers navigate complex regulatory and professional obligations, address novel compliance questions, and bring innovative products to market more quickly. Led by the Department for Business, Innovation and Trade alongside the Ministry of Justice, the Solicitors Regulation Authority, Information Commissioner’s Office, Legal Services Board and Council for Licensed Conveyancers, the programme will support real-world AI use cases such as legal service delivery tools, access to justice technologies and AI-assisted conveyancing. Applications are open until 27 September 2026, with successful participants receiving up to nine months of engagement with regulators. Importantly, participation does not constitute regulatory approval or exemption from existing legal obligations.
OPRC issues statement on future priorities and next steps
The Online Procedure Rule Committee (OPRC) has set out its vision for a more accessible, user-focused digital justice system and announced that its immediate priority is to develop a voluntary Code of Practice covering inclusion, technology and data standards, and the responsible use of AI across digital justice services. The code is intended to promote accessibility, support vulnerable users, improve interoperability between systems, and facilitate earlier and more efficient dispute resolution. The OPRC is developing the framework in collaboration with stakeholders across the justice sector and plans to publish it alongside its response to the 2025 consultation on the Pre-Action Model and Inclusion Framework. The announcement also confirms that the Online Procedure (Rules and Practice Directions) Rules 2026 have been laid before Parliament and will come into force on 7 September 2026, with the first substantive procedural rules, covering possession proceedings, expected later this year,
ICO issues blog post on evolving regulatory sandboxes to meet the demands of AI and emerging tech
The Information Commissioner’s Office (ICO) has announced plans to evolve its regulatory sandbox approach to better support AI and other emerging technologies, recognising that traditional sandboxes can struggle to address complex, cross-regulatory issues and the use of live personal data in innovative projects. Drawing on research commissioned through the Regulatory Innovation Office’s AI Capability Fund, the ICO has concluded that a data protection “Statutory Regulatory Sandbox” could be feasible, potentially allowing innovators limited, time-bound flexibility from certain data protection requirements while maintaining equivalent safeguards for individuals’ rights. The ICO emphasises that public trust and clear public benefit must underpin any such model, and notes that while demand may be relatively niche, the potential economic and societal benefits could be significant. Alongside this work, the ICO is supporting initiatives such as the government’s Advisory AI Growth Lab and the FCA’s AI Lab, and has committed to improving its existing sandbox programme to provide faster, clearer outcomes for organisations developing innovative technologies.
ACRO reprimanded following cyber security failings
The Information Commissioner’s Office has reprimanded the ACRO Criminal Records Office (ACRO) after cyber-security failings left the personal information of up to 10,000 people, including some individuals’ sensitive data, potentially exposed. Its investigation found that, between August 2022 and March 2023, a hacker gained unauthorised access to ACRO’s website and content management system (CMS). The attacker was able to stage personal information to be stolen, although ACRO could not conclusively determine whether the information was removed from its systems. The data potentially exposed included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and highly sensitive criminal offence and special category information. Those affected included applicants for Police Certificates and International Child Protection Certificates, subject access request applicants, and third parties connected to those applications. The ICO found ACRO had engaged third-party providers to deliver certain security services, including patch management. However, ACRO did not ensure clear responsibility for identifying and monitoring critical security updates, failed to maintain an effective patch management process, and did not adequately investigate security alerts that could have identified the hacker’s activity earlier. In deciding to issue a reprimand, the ICO considered several mitigating factors. Network segmentation prevented the hacker from moving beyond the compromised website environment into core systems, reducing the potential scale of harm. The ICO also welcomed the remedial action taken by ACRO following the incident, including decommissioning the compromised infrastructure, migrating services elsewhere, implementing security monitoring, improving visibility of cyber threats and strengthening network segmentation.
Metropolitan Police Service issued with enforcement notice and reprimand following data protection failures
The ICO has also issued an enforcement notice and reprimand to the Metropolitan Police Service (MPS) after personal information in two highly sensitive police cases was erroneously disclosed. It found that the MPS failed to put in place appropriate technical and organisational measures to protect people’s personal information, an infringement of section 40 of the Data Protection Act 2018. The ICO’s investigation revealed a common issue of poor data protection training compliance rates at the MPS, with inadequate monitoring and governance. Its investigation revealed that the breaches were not isolated mistakes. They reflected wider weaknesses in MPS policies, procedures and assurance arrangements for handling sensitive personal information. The ICO also found serious and ongoing shortcomings in MPS data protection training. The ICO issued the MPS with a reprimand for the infringements identified and issued an enforcement notice requiring the MPS to take steps to improve its data protection training compliance, monitoring and governance arrangements.
UK government issues response to DEMAT Implementation Plan
The UK government has accepted the Dematerialisation Market Action Taskforce’s implementation plan for the first phase of its wider programme to modernise share ownership and eliminate paper share certificates. Under the proposals, all publicly traded UK companies will be required to maintain digital share registers, and paper share certificates will cease to be evidence of ownership, with legislation expected to come into force before the end of 2027. Existing paper shareholders will not be required to take any immediate action, as companies and registrars will manage the digitisation process and provide support for affected investors, while shareholder rights will remain unchanged. The reforms form part of a broader three-stage programme intended to reduce costs, improve the efficiency of UK capital markets, make it easier for investors to hold and trade shares, and ultimately support a transition to a fully intermediated system of share ownership.
FCA announces new FCA Handbook API
The FCA has announced the launch of a new FCA Handbook API, aiming to give firms direct access to Handbook content in a structured, machine-readable format. The FCA says the move is designed to make compliance simpler by enabling firms, technology providers and RegTech businesses to integrate regulatory rules, guidance and updates directly into their own systems, reducing reliance on manual processes and helping them respond more quickly to regulatory change. The FCA highlights potential benefits including real-time rule mapping, improved tracking of rule updates, enhanced compliance tools and support for AI-based solutions using trusted regulatory data. The initiative forms part of the FCA’s broader strategy to become a “smarter regulator”, with the aim of reducing unnecessary compliance burdens, supporting innovation and enabling firms to focus more on delivering good outcomes for consumers and markets. The FCA has also issued FAQs.
Irish law
Irish courts service issues practice direction on responsible use of genAI in court documents
The Irish Courts Service has issued a Practice Direction that provides guidance on the Court’s expectations concerning the appropriate and responsible use of generative artificial intelligence tools in connection with legal proceedings, and the implications for practice and procedure in the High Court. It highlights the risks associated with the use of GenAI tools, including the risk of inaccuracy, and addresses the duties and obligations of parties and their legal representatives when such tools are used. It comes into operation on 1 September 2026.