A quiet reading corner in a modern office at blue hour, an armchair and floor lamp by tall glazing

Data protection

What the ICO actually says about AI, and what it has not said yet

The Information Commissioner's Office publishes detailed guidance on applying data protection law to AI, along with a risk toolkit and separate guidance on explaining AI decisions. What it does not do is approve products. Its main AI guidance is also currently under review, which is worth knowing before anyone quotes it at you as settled.

Last checked 19 September 2026

The thing nobody mentions: the guidance is under review #

The ICO's Guidance on AI and data protection is the document everybody cites.

That is easy to verify and takes about thirty seconds, and it changes how you should read every consultant and vendor page that presents the guidance as the current settled word. It is the best available statement of the regulator's thinking, and it is explicitly provisional.

What the ICO actually publishes #

The AI section of the ICO site collects five things, and they serve different purposes.

Resource What it is for
Guidance on AI and data protection The detailed treatment of how UK GDPR principles apply across an AI system. Dense, and currently under review
Explaining decisions made with AI Practical material on explaining AI assisted decisions to the people affected by them
AI and data protection risk toolkit Structured support for assessing the risks your own AI use poses to people. The most usable of the set for a business
Biometric data guidance Biometric recognition specifically, which is a different and stricter subject
Data analytics toolkit Tailored advice for data analytics projects rather than AI specifically

Separately, the ICO runs a section for small and medium organisations written in far plainer language than any of the above. For a business of a few people that is the sensible entry point, and the main guidance is what you reach for when a specific question needs settling.

Three positions worth knowing verbatim #

Outputs are guesses, and that is allowed

On accuracy, the ICO distinguishes the data protection accuracy principle from statistical accuracy, which it describes as how often a system guesses the correct answer against correctly labelled test data. It states that an AI system does not need to be one hundred per cent statistically accurate to comply with the accuracy principle.

statistically informed guesses rather than facts
ICO, What do we need to know about accuracy and statistical accuracy?

That is how it advises treating AI outputs, with records showing what they are and what produced them.

That is a more workable position than most businesses expect, and it is the foundation of everything in what happens when AI gets it wrong.

Training and using are separate purposes

On lawfulness, the ICO advises separating each distinct processing operation and identifying a purpose and lawful basis for each, and treats developing an AI system and deploying one as distinct, with different circumstances and risks. A basis appropriate for using a system may not be appropriate for developing one.

Data minimisation still applies

On data minimisation, the ICO acknowledges directly that AI systems generally require large amounts of data and that it may therefore seem hard to comply, then says the requirement stands regardless: identify the minimum personal data needed for your purpose and process only that.

What the ICO has not done #

  • It does not approve or certify products. There is no list of compliant tools, and a supplier claiming ICO approval is misdescribing something.
  • It does not tell you which tool to buy. Its material is about your processing, which is why two businesses using the same product can be in different positions.
  • It has not finished updating for the Data (Use and Access) Act. That work is under way and its own page says so.

How to use this without a compliance department #

A business does not need to read the full guidance. The proportionate version is to work through the ordinary duties, which are set out in what UK GDPR asks of a business using AI, use the risk toolkit if the project touches personal data in any volume, and write down what you decided and when. That written record is what turns a reasonable decision into a demonstrable one.

If the project is significant enough that you are unsure whether it needs a formal assessment, that question has its own page in do you need a DPIA. And before any of this matters, it is worth knowing how much repeated work you have at all, which the cost of admin time calculator will tell you.

Check it yourself #

Every claim on this page is a link away, and that is deliberate. The ICO publishes its guidance openly, dates it, and marks what is under review. If anyone tells you the regulator requires something, ask which page, then read that page. It is usually shorter and less alarming than the summary you were given.

Questions people ask

Has the ICO banned any AI tool?
No. Its published position is about how data protection law applies to the use of AI, not about approving or prohibiting particular products. Anyone telling you a tool is ICO approved is describing something that does not exist.
Why is the ICO guidance dated 2023?
Because that is when it was last updated. When we checked on 19 September 2026 the page was still marked as last updated on 15 March 2023, with a notice at the top saying it is under review following the Data (Use and Access) Act.
Should we wait for the updated guidance before doing anything?
No, and waiting carries its own risk, because staff are usually already using these tools. The underlying principles are not the part in flux. A business that minimises what it puts in, has contracts in place and keeps a person in front of consequential decisions is on solid ground either way.
What is the AI and data protection risk toolkit?
A practical resource the ICO publishes alongside its guidance, intended to help organisations assess the risks their own AI systems pose to people. It is more useful to a business than the main guidance document, because it is structured as questions rather than prose.

Where these numbers come from

  1. ICO, Guidance on AI and data protection , read 19 September 2026 . Marked last updated 15 March 2023, with a notice that it is under review because of changes made by the Data (Use and Access) Act.
  2. ICO, Artificial intelligence hub , read 19 September 2026 . Lists the AI guidance, Explaining decisions made with AI, biometric recognition guidance, the AI and data protection risk toolkit and the data analytics toolkit.
  3. ICO, What do we need to know about accuracy and statistical accuracy? , read 19 September 2026

Last checked 19 September 2026.

Our workings are on the methodology page .

Free audit

Find out what the repeated work costs you

The audit counts every job the business repeats, ranks them by the hours they eat, and maps the five worth automating first. It is free, you keep everything, and there is no obligation at the end of it.

AI automation, explained

Plain answers to what businesses ask before they automate anything.

All of ai automation, explained

Read next