ICO guidance
ICO guidance on AI, explained for small businesses
The ICO is the UK's data protection regulator. It hasn't written a separate AI law — it applies existing data protection rules to AI, and it has published guidance on what good looks like. Here's the short version for a business without a compliance department.
Last reviewed: August 2026
Who the ICO is, and when it's your problem
The Information Commissioner's Office enforces UK data protection law. It becomes relevant to your AI use the moment an AI tool touches personal data — anything about an identifiable living person. Customer emails, support tickets, CVs, staff records, call transcripts and sales notes all count.
If an AI tool only handles things like public marketing copy, generic code, or internal documents with no names in them, the ICO's AI guidance largely doesn't bite. That distinction is the single most useful sorting question you can ask about your tools.
The practical test
What the ICO actually expects
The guidance is long, but for a small business it reduces to five practical obligations.
- Accountability — someone in the business is named as responsible for each AI tool. Not the vendor, not "IT". A person.
- Lawful basis — you can state why you're allowed to use that personal data in that tool. For most business uses this is legitimate interests or contract, and you should have written down which.
- Transparency — the people affected are told, in language they'd understand, that AI is involved. This is what your privacy notice is for.
- Fairness and accuracy — you've thought about whether the tool could produce a worse outcome for one group of people than another, and you check its output rather than trusting it blindly.
- Data minimisation and security — the tool gets the data it needs and no more, and you know where that data goes, especially if the vendor is outside the UK.
When you need a DPIA
A DPIA — Data Protection Impact Assessment — is a written assessment of what could go wrong for the people whose data you're processing, and what you're doing about it. The ICO treats it as mandatory, not optional, in several AI scenarios.
- The AI is used to make or significantly influence a decision about someone — hiring, credit, pricing, eligibility, disciplinary action.
- You're processing data about a large number of people, or data of a sensitive kind (health, ethnicity, biometrics, criminal records).
- The AI is used to monitor people systematically, including staff monitoring or public-facing video and audio analysis.
- You're combining datasets, or using data for something the person wouldn't reasonably expect when they gave it to you.
If none of these apply, a short written record of what the tool does and who owns it is usually proportionate. The mistake most small businesses make isn't producing a bad DPIA — it's having nothing written down at all.
Automated decisions: the rule people miss
UK GDPR gives people a specific right about decisions made purely by a machine, with no meaningful human involvement, where the decision has a legal or similarly significant effect on them. Rejecting a job application, declining credit, and cancelling an account all qualify.
In those cases you generally need a human who can actually review and overturn the outcome — a person who clicks "approve" on whatever the model said, without the authority or information to disagree, does not count. You also have to tell the person the decision was automated and let them contest it.
What enforcement looks like in practice
The ICO's usual first step is not a fine. It is a request for your documentation: your record of processing, your DPIA, your privacy notice, and your explanation of how the tool works. Businesses get into trouble at that moment — not because their AI use was outrageous, but because they can't evidence that anyone thought about it.
Being able to hand over a current register of your AI tools, with an owner and a risk rating against each, changes that conversation entirely.
A realistic first week
- List every AI tool anyone in the business uses, including free ones staff signed up for themselves.
- Mark which ones touch personal data.
- Give each of those a named owner.
- Write a DPIA for anything that influences a decision about a person.
- Add a line to your privacy notice saying where AI is involved.
- Publish a short usage policy so staff know what they may and may not put into an AI tool.
See where your own AI use actually stands
Register the AI tools your team uses and get a risk rating for each one, in plain English. Free, and it takes about ten minutes.
Not legal advice. This guide explains how the rules are generally understood and is here to help you get organised. It isn't a substitute for advice from a qualified solicitor or your own compliance team.
