Home / AI at work: are new tools creating data protection risks?
28th August 2026
Laura Crowe, Senior Associate
Artificial intelligence (AI) use is now part of everyday life, both personally and in business. This comes with advantages and disadvantages, and adoption is often moving faster than governance can keep pace.
This increased use of AI is unsurprising. Teams are under pressure to work more efficiently, people are curious about what new tools can do, and many AI products are easy to access without a formal procurement or implementation process. As a result, AI is often used in live environments long before anyone has properly assessed the data protection implications.
In late 2026, the issue is no longer simply whether AI is coming. For many organisations, it is already here. In my view, that is where a lot of the risk lies.
It is easy to focus on formal AI projects, major system roll-outs, and high-profile initiatives. However, for many organisations, the greater risk comes from informal day-to-day use.
Employees may upload meeting notes for summarisation, use AI to draft emails, review documents, generate content, or test ideas. In doing so, personal data, confidential material, and commercially sensitive information can be entered into systems without sufficient consideration of whether it should be there at all.
The challenge is not whether AI is being used, but whether organisations have enough visibility over how it is being used, what data is involved, who has approved it, and whether appropriate safeguards are in place.
The ICO’s guidance on AI and data protection continues to emphasise governance, fairness, transparency, lawful processing, and accountability where personal data is involved. More widely, the direction of regulatory scrutiny points towards automated decision-making, meaningful human oversight, and the practical safeguards organisations put in place.
From a practical perspective, there are a few questions worth asking:
Many organisations still do not have a complete picture. Without a clear view of which AI tools employees are using across the organisation, it is difficult to identify, assess and manage AI-related risks effectively.
Employees may not appreciate the risks of entering personal data, confidential information or sensitive business material into AI tools, making clear internal policies and approved-use guidance essential.
Organisations need to ensure that there is a clear purpose, lawful basis, appropriate transparency, and documented risk assessment, including a DPIA where required.
One recurring theme with AI is that responsibility can become blurred. Define responsibility for AI governance across functions such as IT, business, legal and compliance to ensure risks are identified, managed and escalated effectively.
Where AI influences decisions about individuals, ensure appropriate transparency, human oversight, accuracy checks, bias mitigation, challenge processes and record-keeping, particularly in higher-risk contexts.
For most organisations, preventing the use of AI is neither realistic nor desirable. The preferred approach is usually to create enough structure that people can use these tools more safely and more confidently.
Focus on governance controls that employees can understand and apply in their day-to-day work, supported by approved tools, training, risk-based assessments and clear accountability, rather than complex policies that create a false sense of security through poor adoption.
AI impacts data protection, confidentiality, security, accountability and trust, particularly where individuals do not understand how their information is used or how decisions are made.
If your organisation is already using AI, even in a light-touch way, this is a good time for a practical sense-check and ask the questions that matter most right now:
If you would like advice regarding data protection policies in your organisation, please get in contact with our commercial law team on 0161 832 3434, or at [email protected].