Policy submission

DRCF Call for Input on Consumer interest and AI - Which? Response

3 min read
Cressida O'DonoghueSenior Policy Adviser
Andrew LaughlinPrincipal researcher & writer

We welcome the opportunity to contribute to the DRCF’s Call for Input on Consumer interest and AI: Regulatory, policymakers, industry & consumers tools. 

Our response suggests that any work the DRCF undertakes in this area will require a more defined focus which targets particular types or use cases of AI specifically. It will be key to identify specific risks from AI-driven services before analysing and shaping interventions to tackle these, and the CfI’s broad, tools-focussed approach risks this step being missed. 

Further general observations we make that are relevant to the CfI as posing challenges to AI regulation include: the lack of current consistency in AI terminology usage, the predominant focus of current discussion on chatbot-type implementations of AI only, and a potential lack of co-ordination between all relevant UK regulatory bodies in shaping AI governance. 

Beyond this, we share detailed evidence on two sectors we have conducted analysis in during 2026 (General Retail / E-commerce and Retail Financial Services) which has informed the following positions in relation to the themes raised by the CfI questions: 

  • Risks and Harms: The use of AI-based services can bring risks of harm to consumers, and they are ill-equipped to understand, manage or ‘tolerate’ those risks. All markets must be underpinned by strong regulation to address this. The level of acceptable risk for a consumer to bear may vary depending on the context of the AI use, but consumers should never be left exposed to high levels of risks or expected to take on the burden of self-protection when an organisation chooses to deploy AI. 
  • Accountability and Liability: It is essential that liability and accountability in AI-based services are clearly attributed by regulators, particularly for agentic AI. Consumers should not be expected to bear disproportionate levels of responsibility. Regulators including the CMA and FCA have both stated that firms remain liable for outcomes driven by AI they deploy, and we support this position. 
  • Tools and Frameworks: Existing consumer protections could apply effectively to consumer-facing AI services although some adaptation may be required to maximise effect. As AI services become more autonomous, this will place greater strain on tools and frameworks which may require regulatory change.

In General retail/e-commerce, near-term AI applications could be covered by existing consumer protections, although only with strengthened regulatory oversight. However, autonomous AI agents will pose challenges to existing regulatory frameworks, such as the CRA, DMCCA and CCRs. Elements such as human-in-the-loop assumptions, redress routes, average consumer benchmarks and transparency requirements, will need to be reconsidered to remain effective in the context of autonomous AI shopping agents. 

In Financial Services, specific tools such as the Consumer Duty, SM&CR, and the FCA’s Supercharged Sandbox provide effective foundations for AI regulation. However, the regulatory frameworks lack clarity at times regarding their application to AI, rely on strong enforcement, and will likely need to be adapted to be effective in the case of more autonomous future AI systems. 

We would like to see the DRCF gain acknowledgement from its member regulators of the AI regulation concerns and opportunities we have raised in this CfI and support the future co-ordination of relevant regulatory interventions.