The thing nobody mentions: the guidance is under review #
The ICO's Guidance on AI and data protection is the document everybody cites.
That is easy to verify and takes about thirty seconds, and it changes how you should read every consultant and vendor page that presents the guidance as the current settled word. It is the best available statement of the regulator's thinking, and it is explicitly provisional.
What the ICO actually publishes #
The AI section of the ICO site collects five things, and they serve different purposes.
| Resource | What it is for |
|---|---|
| Guidance on AI and data protection | The detailed treatment of how UK GDPR principles apply across an AI system. Dense, and currently under review |
| Explaining decisions made with AI | Practical material on explaining AI assisted decisions to the people affected by them |
| AI and data protection risk toolkit | Structured support for assessing the risks your own AI use poses to people. The most usable of the set for a business |
| Biometric data guidance | Biometric recognition specifically, which is a different and stricter subject |
| Data analytics toolkit | Tailored advice for data analytics projects rather than AI specifically |
Separately, the ICO runs a section for small and medium organisations written in far plainer language than any of the above. For a business of a few people that is the sensible entry point, and the main guidance is what you reach for when a specific question needs settling.
Three positions worth knowing verbatim #
Outputs are guesses, and that is allowed
On accuracy, the ICO distinguishes the data protection accuracy principle from statistical accuracy, which it describes as how often a system guesses the correct answer against correctly labelled test data. It states that an AI system does not need to be one hundred per cent statistically accurate to comply with the accuracy principle.
statistically informed guesses rather than facts
That is how it advises treating AI outputs, with records showing what they are and what produced them.
That is a more workable position than most businesses expect, and it is the foundation of everything in what happens when AI gets it wrong.
Training and using are separate purposes
On lawfulness, the ICO advises separating each distinct processing operation and identifying a purpose and lawful basis for each, and treats developing an AI system and deploying one as distinct, with different circumstances and risks. A basis appropriate for using a system may not be appropriate for developing one.
Data minimisation still applies
On data minimisation, the ICO acknowledges directly that AI systems generally require large amounts of data and that it may therefore seem hard to comply, then says the requirement stands regardless: identify the minimum personal data needed for your purpose and process only that.
What the ICO has not done #
- It does not approve or certify products. There is no list of compliant tools, and a supplier claiming ICO approval is misdescribing something.
- It does not tell you which tool to buy. Its material is about your processing, which is why two businesses using the same product can be in different positions.
- It has not finished updating for the Data (Use and Access) Act. That work is under way and its own page says so.
How to use this without a compliance department #
A business does not need to read the full guidance. The proportionate version is to work through the ordinary duties, which are set out in what UK GDPR asks of a business using AI, use the risk toolkit if the project touches personal data in any volume, and write down what you decided and when. That written record is what turns a reasonable decision into a demonstrable one.
If the project is significant enough that you are unsure whether it needs a formal assessment, that question has its own page in do you need a DPIA. And before any of this matters, it is worth knowing how much repeated work you have at all, which the cost of admin time calculator will tell you.
Check it yourself #
Every claim on this page is a link away, and that is deliberate. The ICO publishes its guidance openly, dates it, and marks what is under review. If anyone tells you the regulator requires something, ask which page, then read that page. It is usually shorter and less alarming than the summary you were given.