UK compliance hub

The ICO’s position on generative AI and personal data

Response to the consultation series on generative AI

Issued by
Information Commissioner’s Office
Published
12 December 2024
Updated
March 2026
We reviewed
17 July 2026
In one minute

The ICO ran a five-part consultation on generative AI and data protection through 2024 and published its response in December 2024, holding firm on purpose limitation, accuracy, and controllership. Its AI and biometrics strategy (June 2025) went further: the direction is a statutory code of practice for AI and automated decision-making, now in development following the Data (Use and Access) Act. The regulator has said plainly it will use formal powers where personal information is used recklessly. For firms, UK GDPR applies to AI prompts today — there is no AI exemption.

What the guidance says

As a first step, we expect generative AI developers to significantly improve their approach to transparency.
Information Commissioner’s OfficeTransparency expectations for generative AI developers are explicit and immediate.
we will not hesitate to use our formal powers to safeguard people’s rights if organisations are using personal information recklessly
Information Commissioner’s OfficeThe enforcement posture is stated, not implied.

The June 2025 AI and biometrics strategy sets four priorities, including a statutory code of practice for AI and automated decision-making — in development following the DUAA.

The consultation response held the ICO’s positions on purpose limitation, accuracy, and controllership for generative AI development and deployment.

What this means for your firm

  • Personal data in AI prompts is a data protection question under UK GDPR now — waiting for the statutory code is not a strategy.
  • A firm that can show a masking control ran before AI use has a materially better answer to "how do you protect personal data in AI workflows?" than one relying on policy alone.
  • Data minimisation is the principle doing the work: send the model only what it needs, which for most legal and financial tasks excludes real identifiers.
  • The statutory AI/ADM code will raise evidence expectations — audit trails built now become the compliance surface later.

Guidance → control, line by line

How each expectation maps to a NeutralAI control. The full cross-regulator table lives on the UK guidance map.

Data minimisation in AI processing

Mask before send

Identifiers are stripped from prompts by default, so the AI provider processes de-identified content — minimisation applied at the exact point of exposure.

Demonstrable accountability (UK GDPR Art. 5(2))

Audit trail + DPIA evidence pack

Masking events are logged by category and policy, and can be exported as a signed evidence pack that slots into a DPIA or an ICO enquiry response.

Lawful, controlled data flows to processors

BYOK + on-prem deployment

Firms that need tighter control can run the gateway in their own environment and use their own LLM contracts and keys, keeping the processing chain theirs.

Common questions

Is there an ICO fine for pasting client data into ChatGPT?

Not yet, as at the last review of this page. The ICO’s first fine against a law firm (DPP Law, April 2025, £60,000) was about basic security failures, not AI use. The regulator’s stated posture on reckless personal-data use suggests the gap is opportunity, not safety.

Does UK GDPR apply to AI prompts?

Yes. If a prompt contains personal data, entering it into an AI tool is processing — lawful basis, minimisation, and accountability apply. There is no AI exemption in UK data protection law.

What is the statutory AI code and when is it coming?

Following the Data (Use and Access) Act 2025, the government and ICO are developing a statutory code of practice covering AI and automated decision-making. Timing is not fixed; the ICO’s March 2026 strategy update describes it as in development. Build evidence habits now rather than retrofitting.

This page summarises third-party guidance for convenience and is not legal advice. Summaries can go stale — always read the original at the source link above before relying on it. Last reviewed: 17 July 2026.

See what this control looks like in practice

The AI Confidentiality Checklist walks through usage discovery, exposure, policy, controls, and evidence in about 20 minutes — or bring one low-risk workflow to a live review.

The control

detect → mask → send → restore → audit

Reversible vault, 15-minute TTL. The model only ever sees placeholders.