Responsible AI
Using AI with personal data? Check the current ICO guidance
A practical privacy check for businesses considering AI tools that may handle information about customers, staff or other identifiable people.
Know what information the tool will handle
Before staff put personal information into an AI service, identify what data is involved, why it is needed and who can access it. Check the provider’s terms and settings for retention, reuse, access and deletion, and use the minimum information needed for the task.
A tool being easy to access does not automatically make it suitable for customer or staff information. Set clear rules for approved services and give people a safe alternative when a task cannot use AI.
Check risks and responsibilities early
Consider whether the AI use could affect people’s rights or make decisions about them. Decide who is accountable, how outputs will be checked and how someone can challenge or correct an error. For uses likely to create higher risks to people, obtain appropriate privacy advice before proceeding.
- Define the purpose and the information needed.
- Check the provider, account controls and data terms.
- Restrict access and set a retention approach.
- Keep human review for outputs that could affect a person.
Use the ICO’s live pages
The ICO notes that parts of its AI and data protection guidance are under review following the Data (Use and Access) Act. Check the ICO’s current pages before relying on a checklist or making a compliance decision, as guidance may change.
Authoritative sources
This guidance is informed by the following primary sources and Secure AI's practical, security-first delivery approach.
Continue reading
