AI at work: are new tools creating data protection risks?

28th August 2026

Laura Crowe, Senior Associate

Artificial intelligence (AI) use is now part of everyday life, both personally and in business. This comes with advantages and disadvantages, and adoption is often moving faster than governance can keep pace.

This increased use of AI is unsurprising. Teams are under pressure to work more efficiently, people are curious about what new tools can do, and many AI products are easy to access without a formal procurement or implementation process. As a result, AI is often used in live environments long before anyone has properly assessed the data protection implications.

AI and the modern workplace

In late 2026, the issue is no longer simply whether AI is coming. For many organisations, it is already here. In my view, that is where a lot of the risk lies.

It is easy to focus on formal AI projects, major system roll-outs, and high-profile initiatives. However, for many organisations, the greater risk comes from informal day-to-day use.

Employees may upload meeting notes for summarisation, use AI to draft emails, review documents,  generate content, or test ideas.  In doing so, personal data, confidential material, and commercially sensitive information can be entered into systems without sufficient consideration of whether it should be there at all.

The challenge is not whether AI is being used, but whether organisations have enough visibility over how it is being used, what data is involved, who has approved it, and whether appropriate safeguards are in place.

Practical considerations for AI governance

The ICO’s guidance on AI and data protection continues to emphasise governance, fairness, transparency, lawful processing, and accountability where personal data is involved. More widely, the direction of regulatory scrutiny points towards automated decision-making, meaningful human oversight, and the practical safeguards organisations put in place.

From a practical perspective, there are a few questions worth asking:

  1. Do you know where AI is already being used?

Many organisations still do not have a complete picture. Without a clear view of which AI tools employees are using across the organisation, it is difficult to identify, assess and manage AI-related risks effectively.

  1. Do people understand what should and should not be entered into these tools?

Employees may not appreciate the risks of entering personal data, confidential information or sensitive business material into AI tools, making clear internal policies and approved-use guidance essential.

  1. Have you assessed the data protection impact in a meaningful way?

Organisations need to ensure that there is a clear purpose, lawful basis, appropriate transparency, and documented risk assessment, including a DPIA where required.

  1. Is responsibility clear?

One recurring theme with AI is that responsibility can become blurred. Define responsibility for AI governance across functions such as IT, business, legal and compliance to ensure risks are identified, managed and escalated effectively.

  1. Are automated decisions being handled with appropriate safeguards?

Where AI influences decisions about individuals, ensure appropriate transparency, human oversight, accuracy checks, bias mitigation, challenge processes and record-keeping, particularly in higher-risk contexts.

  1. Are you balancing innovation with realistic protections?

For most organisations, preventing the use of AI is neither realistic nor desirable. The preferred approach is usually to create enough structure that people can use these tools more safely and more confidently.

Focus on governance controls that employees can understand and apply in their day-to-day work, supported by approved tools, training, risk-based assessments and clear accountability, rather than complex policies that create a false sense of security through poor adoption.

AI impacts data protection, confidentiality, security, accountability and trust, particularly where individuals do not understand how their information is used or how decisions are made.

If your organisation is already using AI, even in a light-touch way, this is a good time for a practical sense-check and ask the questions that matter most right now:

  • What tools are in use?
  • What information is going into them?
  • Who has approved that use?
  • What safeguards are in place?
  • What internal guidance exists?
  • And if someone asked you to explain your current approach, could you do it clearly?

If you would like advice regarding data protection policies in your organisation, please get in contact with our commercial law team on 0161 832 3434, or at [email protected].

 

Kuits FSQS registered
Kuits good employment supporter