Skip to content
Artificial Intelligence

The Whistle the MP & the Structural Hole in AI Self-Governance

Jamie Bykov-Brett Jamie Bykov-Brett · 10 September 2026 · 4 min read
The Whistle the MP & the Structural Hole in AI Self-Governance

We are going political today.

Last week something small happened in British politics that I think says a great deal about where we are with AI. Darren Jones, an MP who chairs the House of Commons Business & Trade Committee, used a hearing to press the UK government on AI regulation. The trigger was a researcher at Anthropic, one of the firms building the most capable systems on the planet, going public with concerns about what his own employer is shipping, as reported in the news.

A person inside the building, a select committee, a headline, & the firm itself. Nobody in that list is a regulator.

I have spent years watching how new technologies get governed in the UK, & the pattern is consistent enough to predict. A new capability lands. The firms building it publish a glossy safety framework. Ministers give a speech welcoming investment. A committee takes evidence. Then the firms go back to competing, the speech ages, & the committee report sits on a shelf with the others until the next panic. Voluntary commitments become the ceiling.

When it comes to UK tech & its governance, we act as if sometimes the government hasn't got any information on being able to see these things coming. I remember when I was doing my TEDx talk in 2015, I was reading a state of automation report. I think Matt Hancock's name was on the front of it, who was working in employment at the time. I don't remember the name of the report but I have a quote from it in my notes from way back when...

"Technological innovation drives the automation of white-collar work and brings large-scale job losses..."

And a lot of the information that I had was from government reports that showed how I thought AI was working. The pattern goes back further still. I was at a Costain Group talk in 2012 about the impact of automation what the jobs of tomorrow might look like. Maybe I just travel in the right circles but I'm always surprised that other people are surprised and act as if the impact of AI and automation has come out of no where.

I think that's the problem with government reports: they spend so much time producing the reports, & then use very little of it in order to be able to actually go & make decisions from it. More data doesn't mean better decision making if you can't cognitively process all of that data to make better decisions.

The UK government for the last 30 years has been reactive rather than proactive. It's not that they don't have the answers that are there, it's that they're always thinking in election cycles. And that means they are trying to use short term thinking to solve long term problems. That's not going to work, particularly in an age where the technology is going to evolve faster than the institutions that are designed to regulate it are able to regulate it.

This Anthropic moment is a useful test of whether anything has changed.

Jones is a senior committee chair using the only real lever his office gives him, which is parliamentary scrutiny. He is asking whether the frontier-model labs can credibly mark their own homework, & the answer has been no for two years.

Insiders going public with safety concerns inside frontier AI labs are rare, & they usually come after internal channels have failed. When someone burns that bridge, it is because the alternative was worse. The political economy of being a safety researcher at a frontier lab is brutal: your job is to slow the machine down, & the machine has shareholders.

Both halves of the same problem sit in one story. The internal whistleblower has almost no structural power. The MP has some, but only intermittently, & only when a story breaks that lets him point at it. The regulator, whoever they end up being, has not yet been built. The firms continue to set the pace of deployment.

Two things are true at once, & the conversation usually fudges one of them. AI safety researchers who speak up are doing something difficult & often personally costly, & they deserve protection. A system that depends on individual moral courage inside private firms, with no statutory backstop, is a lottery. Some labs will have people willing to burn their careers. Others will not. The public cannot tell the difference until it is too late.

Jones is reportedly pushing for binding rules. Good. But which binding rules, & enforced by whom, is where UK debates have repeatedly stalled. Three things I would want to see, none of them new:

  • A statutory duty on frontier-model deployers to publish pre-deployment evaluations of capability & misuse risk, with the assessor named.

  • Whistleblower protection that actually covers AI safety staff, mirroring the financial-services regime, so the next researcher does not have to choose between their career & the public.

  • A procurement rule that bars UK public bodies from buying models whose providers refuse external red-team access.

I'm not going to name all of the organisations that I've done security checks with, with AI, out of respect for those organisations. But the kind of flaws that you can find are exactly what you would expect from something that has been coded by someone with limited development knowledge. We're talking security vulnerabilities, API keys hard coded, user accounts visible, being able to proxy in as admin without having to have admin authority. Standard stuff for anything live coded, where there's a gap between what someone has built & what they understand of it.

None of this is radical. All of it exists in some form in adjacent sectors, financial services most obviously. What's missing is the political will to extend it, & before that, the constituency pressure that would create the will.

Sometimes you can produce all the reports in the world, you can do all of the research in the world. But if you don't have enough capacity or capability to process that information into an informed strategy, it doesn't matter what you do, you're not going to be able to go & make informed decisions based on it. That's where I think sometimes there's a difference between having the knowledge accessible & being able to process that into a strategy.

Ministers are also not experts in the field they are handed. They may have been in the department for two or three years. They don't have the industry knowledge to make informed decisions in those sectors. They are politicians, they are not industry leaders, they are talking to things that they don't understand, what they understand is politics. That gap in knowledge is going to become even more problematic when it comes to the advancements that we see in technology.

Here is my prediction, & you can hold me to it. Within eighteen months, AI safety whistleblowing will become a standard line in UK procurement questionnaires for any public-sector AI contract, in the same way that modern slavery statements are now routine. The main reason is liability. Once a council or a hospital buys a model & it goes wrong, the first question their lawyers ask is what disclosures the vendor made about internal dissent. The AI can't be held accountable but people and organisations can. Vendors will start demanding those disclosures from each other, & the practice will harden into a norm.

I would change my mind if a major incident produced a successful no-fault settlement for the vendor, because that would tell ministers the political cost of inaction is still lower than the cost of legislating. Watch for any carefully dropped AI clauses in the next Data (Use & Access) Bill amendments. That will be the tell.

These institutions were not built to regulate technology moving at this pace, the UK government least of all. The UK government is almost 1000 years old. Parliament was designed to govern a feudal world. It was adapted for the agricultural revolution & again for the Industrial Revolution. It has not been adapted for this one. The age of AI is going to need a different form of government, that's going to need a different form of regulation & different ways of working.

Until then, we are running on the courage of researchers who did not have to speak up, & the attention span of MPs who happened to be in the room. That is a small number of good people, doing the work that an institution has not yet been built to do. Building real AI literacy across your organisation starts with naming that gap honestly, & then deciding, on the record, who you want to close it.


Frequently Asked Questions

Why is UK MP Darren Jones calling for stronger AI regulation?

Darren Jones, who chairs the House of Commons Business & Trade Committee, has used recent hearings to press the government on AI regulation after an Anthropic researcher publicly raised safety concerns about frontier AI development. His intervention treats voluntary lab self-governance as structurally inadequate.

What did the Anthropic researcher actually raise concerns about?

The public reporting describes the researcher flagging risks in the AI systems the firm is building & shipping. What makes it notable is the position of the speaker: an insider with internal knowledge, going on the record externally.

Is voluntary AI self-governance by companies enough?

No, not as a sole mechanism. Voluntary commitments set a ceiling that firms can lower at will, & they come with no inspectorate & no whistleblower protection. They are useful as one input, alongside statutory rules that constrain how firms deploy their systems.

What kind of AI regulation are UK politicians actually proposing?

Jones & like-minded MPs are pushing for binding rules rather than further voluntary frameworks. The proposals set out above include pre-deployment evaluation duties for frontier-model deployers, formal whistleblower protection for AI safety staff, & procurement conditions barring public bodies from buying opaque models.

How can ordinary leaders & teams prepare for tighter AI rules?

Build literacy now. Map which AI tools your organisation actually uses, ask vendors what pre-deployment evaluations they publish, & document internal channels for raising safety concerns before a regulator makes you. When procurement rules land, that is the paperwork you will be asked for.

Share this article
LinkedIn X Email
Jamie Bykov-Brett

Jamie Bykov-Brett

Listed as one of Engatica's World's Top 200 Business and Technology Innovators, Jamie is an AI and automation consultant who helps organisations move from curiosity to confident daily use. As founder of Bykov-Brett Enterprises and co-founder of the Executive AI Institute, he designs AI upskilling programmes that have delivered 86% daily adoption rates and a 9.7/10 NPS. His work sits at the intersection of technology implementation and human development, with a focus on responsible governance, practical tooling, and making AI accessible to every level of an organisation.

Get AI Insights Delivered

Practical perspectives on AI adoption and the future of work. No spam.

Related Articles