
From Bans to Ownership: A Privacy-First Framework for Regulating AI
Putting Privacy First in the Age of AI
By Tom Greenwood
Artificial intelligence is advancing at remarkable speed. Across government, industry, and civil society, there is a shared objective to ensure these technologies develop in ways that are safe, ethical, and aligned with public trust. The UK has already taken important steps in this direction through its AI principles and regulatory approach.
As the debate continues, there is an opportunity to strengthen the conversation by focusing less on banning individual platforms and more on reinforcing a foundational principle: personal privacy, grounded in individual control over identity.
A Changing Landscape for Privacy
AI systems are increasingly capable of analysing, reproducing, and synthesising human faces at scale. This raises understandable concerns about , misuse, and loss of control. Much of the current discussion understandably centres on specific tools or platforms that appear to cross social or ethical boundaries.
However, technology evolves faster than any single regulatory intervention. New models, new companies, and new methods emerge continuously. Regulation that focuses too narrowly on individual platforms risks becoming reactive rather than durable.
The more enduring question is not which AI systems exist, but who controls the use of human identity within them.
Where the Gap Has Emerged
At present, most individuals have limited practical control over how their face or likeness is used once it enters the digital ecosystem. Social media and online services typically rely on broad terms and conditions that allow images to be reused, analysed, and repurposed in ways that users rarely fully anticipate.
This was already a challenge before AI. Machine learning has simply made the consequences more visible and more scalable.
Importantly, this is not a failure of intent. It reflects the pace of technological change outstripping legal concepts that were designed for an earlier digital era.
Reframing Privacy as Ownership
One constructive way forward is to strengthen privacy by grounding it in legal ownership of personal identity, beginning with face and likeness.
Under such an approach:
- An individual's face and biometric representation would be recognised as legally theirs.
- Use beyond the original context would require explicit and informed consent.
- Commercial or synthetic reuse would not be assumed by default.
- Rights would apply regardless of platform, model, or technology used.
This reframing moves privacy from a largely defensive concept to an active one. Ownership creates clarity for citizens, companies, and regulators alike.
A Proportionate Enforcement Model
Ownership-based rights also allow for proportionate enforcement.
Rather than relying primarily on platform-level bans, enforcement could operate through:
- Civil remedies for individuals whose likeness is used without consent
- Collective or representative actions where impacts are widespread
- Regulatory escalation where misuse is persistent or systemic
In this model, restrictions or bans remain available, but as targeted responses to repeated breaches rather than blanket preventative measures.
This aligns accountability with behaviour, not innovation.
Supporting Innovation While Protecting Citizens
Crucially, a privacy-first ownership framework does not oppose AI development. It provides clearer rules of the road.
For innovators, it offers:
- Legal certainty
- Clear consent pathways
- Reduced reputational and regulatory risk
For citizens, it restores agency over something deeply personal: their identity.
For government, it offers a future-proof approach that remains relevant as technologies evolve.
A Strategic Opportunity for the UK
The UK has consistently positioned itself as a leader in responsible AI governance. By advancing the concept of legal ownership of personal identity, the UK can continue to shape international norms in a way that reflects democratic values and individual dignity.
This approach complements existing data protection frameworks rather than replacing them. It recognises that in an AI-enabled world, identity itself has become an asset that deserves explicit legal recognition.
Conclusion
AI regulation will be most effective when it is anchored in first principles rather than individual technologies.
By re-establishing legal ownership of personal identity, privacy can be meaningfully placed back in citizens' hands while allowing innovation to continue responsibly. This offers a constructive, durable foundation for governing AI in the years ahead.
Ownership, not prohibition, is how privacy becomes real in the AI era.