
AI and Data Privacy: What UK Boards Need to Know
The real AI data privacy risk for a board is rarely the AI tool the company officially approved — it is everything else. Information typed into AI tools is usually sent to external servers, may be retained or used to improve the provider's models, can be shared with subprocessors, and is often entered by staff using personal AI accounts the board has never reviewed. UK GDPR and the Data Protection Act 2018 apply to all of this, the ICO has published specific AI guidance, and the EU AI Act can reach a UK company that never signed up for it.
Key takeaways
- Data entered into AI tools is typically transmitted to external servers, and — unless retention is explicitly restricted — may be stored, logged, or used to improve the provider's models.
- 71% of UK employees have used AI tools not sanctioned by their employer, and 51% do so weekly, according to Microsoft UK & Ireland (Censuswide survey, 2025).
- UK GDPR and the Data Protection Act 2018 apply to AI processing of personal data without exception, and most AI use will trigger the legal requirement for a Data Protection Impact Assessment.
- Updated ICO guidance on automated decision-making is due in summer 2026, ahead of a statutory code of practice on AI and automated decision-making that has no confirmed publication date.
- The EU AI Act's extraterritorial reach means a UK board can be in scope even if the company has no EU office — the test is where the AI system or its output is used, not where the company is registered.
What actually happens to data entered into an AI tool?
Every AI privacy question a board asks eventually comes back to one thing: where does the information go once someone types it in? For most consumer and general-purpose AI tools, the answer has four parts, and a board's oversight should cover all four rather than stopping at the first.
It is sent to external servers. Text, documents, or files entered into an external-server AI tool leave the user's device and are processed on infrastructure run by the AI provider, often outside the UK. This is true even for a single question typed into a chat window — the exchange does not stay local.
It may be retained. Unless a user or organisation has actively restricted retention, conversations and uploaded content can be stored by the provider for logging, abuse-monitoring, or product-improvement purposes. Retention periods and defaults vary by provider and by account type (consumer versus enterprise).
It may be used to train future models. Consumer-tier AI accounts frequently default to allowing user content to improve the underlying model, unless the user has found and switched off that setting. Enterprise agreements typically exclude training use, but the default assumption for an unmanaged, personal account should be that it is not excluded.
It may reach third parties. AI providers use subprocessors for hosting, safety review, and related services, each of whom may have some access to the data passing through the system. A privacy policy describes this chain in outline; it rarely gives a board the specific, auditable answer of who saw what.
None of this makes AI unusable for board work. It does mean the privacy question is not "is this AI tool safe?" but "what happens to what we put into it, and did we decide that deliberately?" — a distinction covered in more detail in Is It Safe to Upload Board Papers to ChatGPT? and in the hidden risks of AI systems.
What is "shadow AI," and why should the board care?
Shadow AI is staff use of AI tools the organisation has not approved, assessed, or even necessarily noticed. It is the largest practical AI data privacy exposure most boards carry, precisely because it happens outside any process the board can currently see.
71% of UK employees have used consumer AI tools not sanctioned by their employer, and 51% do so weekly, according to Microsoft UK & Ireland, based on Censuswide research among UK employees.1 Nearly a third of those employees — 32% — said they were concerned about the privacy of company or customer data in the tools they were using, and close to half reported using them for workplace communications.1
The Institute of Directors' NEDs Reimagined review — a post-Higgs review of the non-executive director role — makes AI literacy an explicit recommendation for NEDs, on the basis that director-level AI use is already running ahead of any formal board oversight of it.2 That mirrors the employee-level pattern above: adoption outpacing governance, at board level as well as employee level.
Shadow AI matters to a board specifically because it sits outside every control the organisation thinks it has. A Data Protection Impact Assessment covers the tools it was written for; a data processing agreement covers the vendor it was signed with. Neither covers the AI tool an employee opened in a personal browser tab to summarise a document. The board's oversight question is not whether staff are using AI — they almost certainly are — but whether that use has ever been reviewed at all.
What does UK GDPR require when AI processes personal data?
UK GDPR and the Data Protection Act 2018 apply to AI processing of personal data exactly as they apply to any other processing — there is no AI-specific carve-out or lighter regime. The core principles (lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability) all have to be satisfied by whichever system, human or automated, is doing the processing.
In practice, that has one specific consequence a board should know by name: a Data Protection Impact Assessment (DPIA) is a legal requirement under Article 35 of UK GDPR before certain high-risk processing begins, and the ICO's own guidance states that AI use will trigger this requirement in the vast majority of cases — for example, systematic profiling or automated evaluation that feeds decisions with a legal or similarly significant effect on people.3
Automated decision-making rules also changed materially in the past year. The Data (Use and Access) Act 2025 received Royal Assent in June 2025 and, from 5 February 2026, replaced the previous blanket restriction on solely automated significant decisions (the former Article 22 regime) with a new framework under Articles 22A–22D UK GDPR, permitting such decisions in a wider range of circumstances provided specified safeguards are in place.4 For a board, that is a governance question worth a specific line in the risk register: any AI system that could be described as making a "significant decision" about a person — credit, recruitment, insurance, benefits eligibility — now sits under a materially different legal test than it did eighteen months ago.
What does the ICO say about AI and data protection?
The Information Commissioner's Office publishes a standing document, Guidance on AI and data protection, which maps the UK GDPR principles directly onto AI systems and sets out what a DPIA for an AI system needs to cover.3 It is not the ICO's only current work on the subject. The regulator has also published a dedicated AI and Biometrics Strategy, is due to publish updated guidance on automated decision-making in summer 2026, and is separately developing a statutory code of practice on AI and automated decision-making for which no publication date has yet been confirmed, alongside direct engagement with major foundation-model developers on training-data compliance.5
As John Edwards, the UK Information Commissioner, put it on the launch of the ICO's AI and Biometrics Strategy: "The same data protection principles apply now as they always have — trust matters, and it can only be built by organisations using people's personal information responsibly."6 For a board, that framing is worth taking literally: nothing about the arrival of AI changes what UK GDPR requires. It changes how much oversight is needed to know whether it is being met.
Does the EU AI Act reach UK boards?
It can, and the mechanism is the same extraterritorial logic UK boards already know from GDPR. The EU AI Act applies to a UK organisation if it is a provider placing an AI system or its output on the EU market, a deployer outside the EU whose AI system's output is used within the EU, or an importer or distributor placing a third-party AI system on the EU market from the UK.7 Registration in the UK, not the EU, does not put a company outside scope — what matters is where the system or its output is used.
The compliance timeline has also moved. Prohibited practices and AI-literacy obligations were already in force from 2025, and duties for providers of general-purpose AI models applied from August 2025. Following the EU's Digital Omnibus reform, agreed in mid-2026, the deadline for high-risk AI system obligations — the tier most relevant to hiring tools, credit scoring, and biometric identification — was pushed back to 2 December 2027 for standalone systems, and 2 August 2028 for high-risk AI embedded in regulated products.8 A board should treat "the EU AI Act doesn't apply to us, we're a UK company" as a scope question to actually check, not an assumption — and treat the deadline as later than the Act's original text suggested, not earlier.
How do the frameworks compare?
| Framework | What it covers | Applies to a UK-only board? | Current status (2026) |
|---|---|---|---|
| UK GDPR + Data Protection Act 2018 | All processing of personal data, including by AI systems; DPIA required for most AI use | Yes — always | In force; automated decision-making rules updated Feb 2026 |
| ICO guidance on AI and data protection | How UK GDPR principles apply specifically to AI | Yes — guidance, not new law | In force; updated ADM guidance due summer 2026, statutory code of practice date unconfirmed |
| EU AI Act | AI systems placed on the EU market, or whose output is used in the EU | Only if the company's AI touches the EU market | Prohibited practices and GPAI duties live; high-risk duties delayed to Dec 2027 / Aug 2028 |
What questions should a NED actually ask?
None of the above is legal advice, and a NED is not expected to become a data protection lawyer. The oversight role is to ask questions that surface whether the organisation has actually thought about this, and to keep asking until the answer is specific rather than reassuring.
- Where does information entered into our approved AI tools actually go — whose servers, and under what retention terms?
- Has any AI system in use had a Data Protection Impact Assessment, and if not, why not?
- Do we have any visibility into unsanctioned AI use by staff — shadow AI — or are we assuming there isn't any?
- Has anyone assessed whether the EU AI Act applies to us, given where our AI systems or their output are actually used?
- If an AI system contributes to a decision about a customer or employee, has anyone checked whether that decision now falls under the new automated decision-making rules?
The bottom line
AI data privacy risk for a board is less about any single tool and more about visibility: whether the organisation can actually answer where information goes once it is typed into an AI system, sanctioned or not. UK GDPR and the Data Protection Act 2018 already apply to that processing without exception, the ICO has specific guidance and more coming in 2026, and the EU AI Act can apply even to a UK-only board depending on where its AI systems are used. The practical answer for board papers specifically is the same one that applies to any confidential document: understand where the data goes before it goes there. Local AI vs cloud AI sets out that comparison in detail, and meetinginsight.ai is built to keep board material on your own device throughout. Compare local AI to cloud AI, or download meetinginsight.ai to see it working on your own board papers.
Notes
Footnotes
-
Microsoft UK & Ireland, Censuswide survey of 2,003 UK employees, October 2025. https://ukstories.microsoft.com/features/rise-in-shadow-ai-tools-raising-security-concerns-for-uk/ ↩ ↩2
-
Institute of Directors, NEDs Reimagined: A post-Higgs review of the role and contribution of non-executive directors, January 2026. https://www.iod.com/resources/governance/neds-reimagined-a-post-higgs-review-of-the-role-and-contribution-of-non-executive-directors/ ↩
-
Information Commissioner's Office, Guidance on AI and data protection, updated 15 March 2023. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/ ↩ ↩2
-
Burges Salmon, "The Data (Use and Access) Act 2025: navigating the new rules around automated decision-making," 2025–2026. https://www.burges-salmon.com/articles/102mmuc/the-data-use-and-access-act-2025-navigating-the-new-rules-around-automated-dec/ ↩
-
Information Commissioner's Office, AI and Biometrics Strategy: Preventing Harm, Promoting Trust, 5 June 2025. https://ico.org.uk/about-the-ico/our-information/our-strategies-and-plans/artificial-intelligence-and-biometrics-strategy/our-plan-of-action/ ↩
-
John Edwards, UK Information Commissioner, "Information Commissioner: People must trust their information is protected in the age of AI," ICO press release, 5 June 2025. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/06/information-commissioner-people-must-trust-their-data-is-protected-in-the-age-of-ai/ ↩
-
Data Privacy & Security Insider, "Extraterritorial Scope of the EU AI Act," February 2026. https://www.dataprivacyandsecurityinsider.com/2026/02/extraterritorial-scope-of-the-eu-ai-act/ ↩
-
Pinsent Masons, "Rules on high-risk AI delayed under EU Omnibus deal," 2026. https://www.pinsentmasons.com/out-law/news/rules-high-risk-ai-delayed-under-eu-omnibus-deal ↩