Scotland’s Artificial Intelligence Strategy 2026-31: Addressing the Environment, Intellectual Property and Liability

By Angus Gibson (University of Glasgow), Maria Macfie (Abertay University) and Oumer Tariq (University of Stirling).

Angus, Maria and Oumer participated in the WS Society Summer Scholars programme during August 2026. This article summarises their research and presentation.

Scotland’s AI Strategy

In March 2026, the Scottish Government published its AI Strategy, setting out a five year plan for the development and use of artificial intelligence. Its aim is to support responsible economic growth through four pillars: People and Skills, Data and Regulation, Companies and Innovation, and Infrastructure.

Delivery is led by AI Scotland, a national programme involving the Scottish Government and its partners. The Strategy also sets out an ‘AI Stack’ covering areas such as skills, data, innovation, infrastructure and regulation. It recognises that AI creates new risks as well as opportunities and stresses the need for trust, privacy, fairness and public benefit.

Scotland currently has no comprehensive AI specific legislation. Instead, AI is regulated through existing laws and sector specific rules. Scotland can regulate AI in devolved areas, but significant aspects remain reserved to Westminster. The Strategy therefore proposes reviewing devolved regulation and seeking closer alignment with the European Union’s approach.

This report examines the Strategy’s legal implications in three areas: the environment, intellectual property and liability for AI-related harm. It assesses whether Scotland’s existing legal framework is capable of managing the opportunities and risks created by AI.

Environmental Regulation

The environmental impact of AI has been described as the “elephant in the room” and “the blind spot of AI ethics”. However, the environmental concerns are not unknown. For example, in a 2025 report from the United Nations Environment Programme, the problematic nature of AI on the environment was discussed, with concerns being raised in regard to: the often environmentally destructive methods used to create AI data centres; the amount of electronic waste generated by AI data centres; the significant use of water during both construction and throughout an AI data centres operation; and the amount of energy required to power AI data centres. Therefore, while AI has been suggested to be used for sustainability by means of monitoring deforestation, air, and water quality, it simultaneously may create environmental risks. 

Within the strategy, the principal focus is on how AI can be developed to increase productivity and innovation. However, it does address the environmental concerns around AI and its necessary infrastructure to a limited degree. The strategy recognises that AI infrastructure development will be ‘sustainable’, with suggestions that continued development in the area will lead to increasingly environmentally friendly infrastructure planning. Further, it suggests that ‘energy-aware’ planning will reduce pressure on renewable energy systems to support sustainable infrastructure growth. However, while this shows that there is regard for environmental concerns around AI, they are often discussed from an  anthropocentric viewpoint. For example, in reference to developing infrastructure, the benefits are suggested to be supporting long-term competitiveness in the AI sphere but does not mention how broader environmental concerns, such as that of any potential effect on biodiversity, will be addressed. 

Under the European Union (Continuity) (Scotland) Act 2021, environmental law principles are embedded into domestic legislation. Consequently, these principles—such as the precautionary principle—ensure that protection and improvement of the environment is considered in decision making across all sectors and policies. This is crucial, as the potential harm incurred by the continued growth of AI and its infrastructure is dependent on the adherence of human made policies to environmental law and principles. 

Therefore, in implementing the AI strategy going forward, the environmental impact of AI should be at the forefront of decision making on all levels. In doing so, transparency around the AI  development of infrastructure is key, especially in consideration of the fact that potential negative effects include renewable energy capacity, use of valuable resources, and pollution. As such, AI infrastructure development should have stringent regulation and governance to ensure compliance with environmental law, particularly due to the fragmentation of this area of law. Thus, the use of Environmental Impact Assessments to encourage public participation and scrutiny of decision-making, in conjunction with easily accessible policies that outline all potentially relevant areas of environmental law, would ensure transparency and adherence to environmental law and policies to ensure sustainable development in the development of AI.

Intellectual Property

Scotland’s AI Strategy recognises the importance of AI to economic growth while acknowledging the particular challenges it presents for key sectors, such as the creative industries. The UK Government’s March 2026 report on AI and copyright considered issues including input transparency, output labelling, computer-generated works and digital replicas. Although a broad data-mining exception with a right-holder opt-out had initially been proposed, this approach was rejected by both creative industry respondents and AI developers. The Government subsequently stated that it had “no preferred option” and would not legislate until further information was available.

A key issue concerns the use of copyrighted material to train AI models. Developers may scrape large quantities of creative content, while rights holders may argue that this involves unauthorised copying. The uncertainty is illustrated by Getty Images v Stability AI, where Getty was unable to establish that the Stable Diffusion model itself constituted an infringing copy of its images. The German courts adopted a different approach in GEMA v OpenAI, finding that the reproduction of protected song lyrics by OpenAI’s models constituted infringement. This contrast demonstrates the difficulty of applying existing copyright concepts to AI training and highlights the need for greater transparency. Creators cannot effectively enforce their rights without knowing whether their work has been used to train AI systems. Greater transparency may also facilitate a licensing or rights-reservation mechanism, enabling creators to exercise greater control over the use of their work.

Patent law currently presents a more settled position. In Emotional Perception AI v Comptroller General, the Supreme Court confirmed that an artificial neural network is a computer program but is not excluded from patentability “as such” where the invention has the necessary technical character. AI-related inventions can therefore obtain patent protection provided they satisfy the ordinary requirements of patentability. This provides greater certainty for Scottish businesses seeking to commercialise AI research and highlights how patent law has adapted relatively effectively to technological development.

A more fundamental issue concerns ownership of AI-generated material. In Thaler v Comptroller General, the Supreme Court confirmed that an AI system cannot be an inventor under the Patents Act 1977 and that ownership of the AI system does not confer the right to obtain a patent for an invention generated by that system. The UK therefore retains a human-centred approach, broadly consistent with the United States. However, if AI eventually becomes capable of making genuinely inventive contributions independently, simply insisting that the inventor must be human may become increasingly difficult to justify.

Overall, IP law is developing unevenly. Patent law provides comparatively clear protection for AI-related inventions, whereas copyright law remains uncertain regarding training data and AI-generated material. Scotland cannot resolve these issues independently because IP is largely reserved to the UK Parliament. Its role should instead be to identify the protections required to support responsible AI adoption and advocate for greater transparency, certainty and international alignment. Ultimately, the success of the Strategy will depend on balancing the economic benefits of AI innovation with the interests of the creators, researchers and businesses whose work underpins the industry.

Liability and Accountability through the lens of the Post Office scandal

The Post Office Horizon scandal is usually remembered as a story about a faulty accounting system. Legally, it is better understood as two protections failing at once: trust in computer evidence, and accountability when institutions trust a system over the people it affects. Both problems share a common weakness: the law was not designed for systems like Horizon, and is even less prepared for AI.

The evidence problem

Before 2019, sub-postmasters had no access to Horizon's source code, error logs, or the Post Office's reliability data, even though Fujitsu held detailed records of the system's faults. The law made this worse: section 69 of the Police and Criminal Evidence Act 1984 once required the prosecution to prove a computer was working properly before its output could be used as evidence. That requirement was removed in 1999, leaving a presumption that computer generated evidence is reliable unless the defence proves otherwise.

That approach suited computer systems governed by clear, predictable rules, but is harder to justify for AI, where outputs are complex, uncertain, and hard to explain.

The Data (Use and Access) Act 2025 gives people affected by significant automated decisions rights to information and human review, an important development, since Horizon sub-postmasters had no equivalent protection. But these safeguards address how decisions are made and challenged, not the reliability of the system producing them, leaving the underlying assumption that computer generated evidence can be trusted largely untouched.

Accountability

Scotland's prosecution system was formally independent of the Post Office. The Crown Office and Procurator Fiscal Service (COPFS), not the Post Office, decided whether to prosecute. That independence helped, but wasn't enough. COPFS knew of concerns about Horizon's reliability by 2013, yet relied on Post Office assurances for years. In 2024, the Lord Advocate acknowledged COPFS had been "repeatedly misled".

The key lesson is that independence alone is insufficient when the decision making institution lacks an effective means of independently testing or verifying the evidence it relies upon.

R v Chief Constable of South Wales Police shows a public body can be challenged where it fails to properly assess an algorithm's risks, with the Public Sector Equality Duty (s.149 Equality Act 2010) providing a legal basis for that challenge.

But the Data Act's right to "human intervention" leaves a key question unanswered: how much intervention is enough? If a reviewer simply accepts the AI's decision without questioning it, the requirement could still be satisfied, risking the same problem seen in Horizon, where human involvement existed without genuine scrutiny of the output.

Australia’s Robodebt scandal shows this is a real risk. Human oversight did not prevent unlawful outcomes because reviewers failed to properly question the system’s assumptions.

A law written for the last problem

The common thread is that these protections were designed for earlier technological risks, including unreliable computer evidence, human decision making and specific algorithmic harms, rather than AI systems that can be unpredictable, opaque and difficult to understand.

Scotland is better protected against another Horizon than it was in 2015, but not yet fully protected against an AI version of the same failure. The law has developed, but remains largely untested against these newer risks.

Conclusion

Scotland’s AI Strategy provides an ambitious framework for harnessing AI to promote economic growth, innovation and improved public services while recognising that this development must be accompanied by responsible governance. The common theme across all three areas is not that Scotland lacks regulation, but that existing regulation was largely developed before the emergence of AI, and is being required to adapt to technology that is evolving faster than the law itself. This is particularly significant because there is currently no comprehensive legislation specifically regulating AI, while many relevant areas of law are reserved to Westminster.

The Scottish Government therefore cannot address these challenges through the AI strategy alone. Its role should be to ensure that AI adoption within devolved areas is responsible, transparent and sustainable, while using its influence to advocate for appropriate UK-wide legal reform. This should include stronger environmental safeguards, greater certainty and transparency in intellectual property law, and meaningful mechanisms for challenging AI-driven decisions. Ultimately, the success of Scotland’s AI strategy should be measured by whether it can realise the benefits of AI while still ensuring that the risks are properly identified and regulated.