There is a date that every organisation in the United Kingdom should have in its calendar, and most do not. In October 2026, a new duty under the Employment Rights Act comes into force, and it quietly raises the bar for what employers are legally required to do about harassment. The change is contained in three words that are easy to skim past and expensive to underestimate: all reasonable steps.
Until now, the expectation on employers has hovered around having reasonable measures in place. A policy. A reporting channel. Some training, delivered at some point. The new duty asks for something categorically more demanding. Not reasonable steps, but all reasonable steps. And the difference between those two phrasings is where a great many organisations are about to discover they are exposed.
What “all reasonable steps” actually demands
The shift from reasonable steps to all reasonable steps is not cosmetic. It moves the burden from having made an effort to having made every effort a reasonable organisation could be expected to make. In practice, that means an employer can no longer point to the existence of a policy as evidence of compliance. They will need to demonstrate that they took active, ongoing, and comprehensive measures to prevent harassment before it occurred, and that they responded properly to what they knew or should have known.
The phrase that matters most there is should have known. The new duty is not satisfied by waiting for a formal complaint and then following a process. It reaches toward a positive obligation to identify and address harmful dynamics proactively, which means an organisation’s ignorance of a problem is no longer automatically a defence. If the signals were there and the organisation had no mechanism capable of noticing them, all reasonable steps have not been taken.
This is a meaningful expansion of what compliance requires, and it lands in an area most organisations are genuinely ill-equipped to handle, because the thing they are now expected to detect is precisely the thing that is hardest to see.
Why a policy cannot close this gap
Here is the uncomfortable centre of the problem. The harassment and coercive dynamics that the new duty is most concerned with are, by their nature, the ones a policy is least able to catch.
A policy works on incidents that are visible, nameable, and reportable. A single egregious act that someone is willing to formally report fits the machinery of a harassment policy well. But the most corrosive workplace dynamics do not look like that. They accumulate. They live in patterns rather than incidents: the manager whose individual comments are each just about defensible but whose cumulative effect is the systematic undermining of one person. The team culture where exclusion is done quietly enough that no single instance would survive scrutiny. The behaviour that everyone experiences and no one reports, because no individual moment feels large enough to justify the risk of speaking up.
None of that is caught by a policy, because a policy waits to be triggered by a report, and these dynamics are specifically the ones that do not generate reports. The reasons they do not are well documented: the people experiencing them frequently doubt their own perception, cannot point to a single provable incident, and calculate, often correctly, that raising a pattern made of individually deniable parts will cost them more than it gains. Recent surveys continue to show that the majority of people who experience workplace bullying or harassment say nothing at all.
So an organisation that relies on its policy and its reporting channel to satisfy the all reasonable steps duty is relying on a mechanism that structurally cannot see the problem it is now legally required to address. The policy is not useless. It is simply blind to exactly the category of harm that matters most under the new standard.
What “all reasonable steps” looks like in practice
If a policy is necessary but not sufficient, the question becomes what else all reasonable steps actually requires, and the answer points toward capabilities most organisations do not currently have.
It requires the ability to identify patterns of harmful behaviour before they escalate to formal complaint, which means looking at accumulation rather than waiting for incidents. It requires the ability to document what was happening and when, in a form that could later evidence that the organisation was paying attention rather than looking away. And it requires the ability to demonstrate, after the fact, that the organisation had mechanisms in place capable of surfacing problems that no one had formally reported.
That is not the work of a policy document. It is the work of a forensic capability: something that can read the actual patterns in workplace communication and dynamics, surface the accumulating harm that no single incident would reveal, and give an organisation genuine visibility into what is happening beneath the level that reporting channels capture. This is a different kind of tool than the compliance industry has historically offered, because it addresses a different kind of problem. The old problem was documenting that you had a process. The new problem is actually being able to see.
Preparing for October
CultureScan AI was built for exactly this gap. It applies forensic analysis to the patterns of behaviour and communication that policies cannot see, surfacing the accumulating dynamics that never generate a formal report but that the all reasonable steps duty now expects organisations to identify and address. It is the difference between an organisation that can say it had a policy and one that can demonstrate it had genuine visibility, which, after October, is the difference that will matter.
If you lead an organisation, sit in an HR or people function, or advise businesses on culture and compliance, the arrival of this duty is not a distant regulatory footnote. It is a change in what the law expects you to be able to see, and the organisations that treat it as a paperwork exercise will find that their paperwork was aimed at the wrong problem. The ones that prepare properly will build the capability to identify harm before it becomes a complaint, which is both what the new duty requires and, incidentally, what a decent workplace should have wanted all along.
October is closer than it looks. The organisations that use the time between now and then to move beyond policy, and toward actual visibility, are the ones that will meet the new standard rather than discover, too late, that they fell short of it.



