Six months ago, this update would have been about Keir Starmer’s government. It is now about Andy Burnham’s. Former Prime Minister Keir Starmer’s two years in office have left three markers worth noting. Shortly before his resignation, he announced a ban on social media use for under-16s, accompanied by unresolved questions on age assurance and digital rights. Two additional pieces of work also substantively shaped the Government’s wider AI and technology agenda during Keir Starmer’s term: the January 2025 Artificial Intelligence (AI) Opportunities Action Plan that sets out 50 recommendations behind the government’s AI superpower ambition, and most prominently, the June 2025 Data (Use and Access) Act. You can find a more detailed account of further tech policy developments in 2025, including the Bills introduced at the King’s Speech, here and here.
Machinery of Government
Prime Minister Burnham has made three significant changes in his first month. The first was the abolition of the Department for Science, Innovation and Technology (DSIT), with most of its functions merging with the Department for Business and Trade to form the Department for Business, Innovation, Science and Trade (DBIST), led by Jonathan Reynolds MP. The second was the return of digital policy to the Department for Digital, Culture, Media and Sport (DCMS). The third was the elevation of the AI brief. Kanishka Narayan MP, previously a junior minister for AI and online safety, has been made Minister of State for AI and now attends cabinet, the first time the role has carried that status. Although all of these announcements come with warnings attached; the changes replace what had been a single point of contact for the tech sector with several separate departments, heightening the risk of a significantly reduced pace of action on policy developments. In his first few days in office, Prime Minister Burnham also scrapped the mandatory Digital ID scheme. The scheme, first introduced by Keir Starmer in September 2025, drew sustained criticism and had been estimated to cost £1.8 billion over three years.
Sovereignty and Compute
The line from government has stayed much the same across both prime ministers, with a determined aim for a sovereign and safe AI sector. This includes efforts to increase UK compute capacity, attract frontier labs such as Anthropic and DeepMind, and back the UK AI Security Institute. There is still, however, some missing detail on how this will be delivered. Funding has been committed without a clear mechanism to spend it, while building a data centre in the UK costs significantly more than in the US. As a result, current funding commitments are unlikely to deliver the compute capacity the Government has described.
On the theme of sovereignty, in June 2026, the US Department of Commerce issued an export control directive covering Anthropic’s Claude Fable 5 and Claude Mythos 5, citing a suspected method of bypassing Fable’s safety measures. Access was suspended for all users, including those in the UK, for about three weeks from 12 June to 1 July, and the decision was made without any input from UK institutions. As things stand, UK access to frontier models depends in part on decisions taken elsewhere. This is an important weakness to address, regardless of the Government’s stated ambition to attract frontier labs to the UK.
Cyber and AI Regulation
The departmental changes have also split responsibility for related policy areas. Cyber policy now sits with DCMS, while AI policy becomes the responsibility of the Cabinet Office, splitting two areas that are becoming more connected than ever in practice. The Cyber Security and Resilience Bill will proceed under Prime Minister Burnham’s government; it is currently at committee stage in the House of Lords, having cleared the Commons in June, with Royal Assent expected around the turn of the year. The Bill brings well over 1,000 organisations into scope, including managed service providers and data centres, overseen by 12 sector regulators. This raises questions of consistency and capacity for regulators without existing cyber expertise. As currently drafted, the Bill places obligations on organisations that deploy AI. It does not place equivalent obligations on organisations that build AI systems.
There is also no horizontal AI law, but recent movements in Parliament suggest the appetite for one has not gone away. The Joint Committee on Human Rights, now chaired by Alex Sobel MP, published a report on 14 September calling for a dedicated AI Bill and a single statutory regulator. Alex Sobel MP had already pushed, unsuccessfully, for an AI “kill switch” amendment to the Cyber Security and Resilience Bill, an idea peers revived and the Government again rejected in the Lords in early September; separately, he introduced his own AI Security Bill on 8 September, aimed at restricting the development of artificial superintelligence. Chi Onwurah MP has also introduced a Bill of her own, on personal data and so-called digital twins, which would require explicit consent before a company could use someone’s data to model their behaviour or likeness. None of this amounts to a single cross-sector AI law yet, but taken together, it’s a sign the question has not gone away. The Government’s own position, set out in its pro-innovation approach to AI regulation, remains to regulate AI at the point of use through existing sectoral regulators rather than new cross-sector legislation. Members of the House of Lords have raised concerns about the gaps this leaves in regulatory coverage, and the issue remains unresolved.
Online Safety and Age Verification
The mandatory Digital ID scheme was scrapped on the grounds of trust and privacy. The social media ban for under-16s, however, depends on comparable infrastructure. It requires the collection of user data through face scans, credit cards or government identification to verify age. On 8 September, Culture Secretary Lisa Nandy told the House of Commons that the Government will legislate to require Apple and Google to build device-level protections preventing under-18s from taking, sharing or viewing nude images. The announcement followed a three-month deadline set in June, during which voluntary commitments from both companies fell short of what the Government judged necessary. The proposed protections would apply by default across devices, cameras and third-party apps, with access restored only once age has been verified. Child safety groups have welcomed the move, while privacy advocates have raised concerns about what amounts to on-device scanning. All three measures depend on verifying age at scale, and doing so without expanding surveillance of everyone in order to protect a minority of users remains an unresolved tension.
Then Technology Secretary Liz Kendall had raised the possibility of restricting VPN use to prevent circumvention of age checks, but confirmed on 15 July that the Government would not age-gate or ban VPNs, citing their legitimate privacy and security uses. The onus instead falls on platforms to detect and prevent circumvention themselves, with Ofcom due to publish guidance on this by the end of October.
Copyright
Copyright and AI remains unresolved, and is an issue the music industry has already raised directly with the new Prime Minister, given his history of supporting Manchester’s music scene as Mayor of Greater Manchester. UK Music has called on Burnham to rule out new copyright exceptions for AI, while the House of Lords Communications and Digital Committee published a report in March setting out options for a licensing market that works for both rights holders and AI developers. Our meeting in June on this topic produced a number of proposals for resolving the current deadlock, aimed at allowing innovation to proceed without undermining the intellectual property rights of creators.
Industry Is Already Moving
In August, OpenAI launched a version of ChatGPT for 13 to 17 year olds. Its central feature, ‘Study Mode’, responds to homework questions with guided questions and step-by-step prompts rather than a finished answer. Our July report, Count on It: Numeracy, AI and Social Mobility, argued that the risk from AI tools is not only inaccurate output; it’s confident output that users lack the numerical judgement to question. ‘Study Mode’ responds to that risk directly by making its reasoning visible rather than presenting a conclusion alone.
In June, Anthropic changed Claude’s privacy policy to allow age and identity verification for consumer users, including facial age estimation and document checks, taking effect on 8 July. Neither change was required by UK law and both were made by companies, not government, in areas where government has not yet settled its own position on numeracy, online safety or AI governance.
The All-Party Parliamentary Group for Data and Emerging Technologies’ (APGDET) upcoming programme of work aims to address a range of these priorities.
For more information on our upcoming events and inquiries, please contact Lavanya Rangarajan (Lavanya.rangarajan@policyconnect.org.uk)