In June, the Information Commissioner’s Office (ICO) launched its new AI and biometrics strategy, focusing on preventing harm and building public trust in AI and biometric solutions.
On AI, the strategy highlights several priorities:
- Providing organisations with clarity on how to use AI and automated decision-making (ADM) responsibly under data protection law. This includes plans for a statutory code of practice on AI and ADM, with guidance on transparency, explainability, bias, discrimination and individual rights.
- Ensuring high standards of ADM in central government, focusing on fairness, accountability and lessons learned from early adopters.
- Setting expectations for the responsible use of AI in recruitment.
- Scrutinising foundation model developers to ensure data protection and minimise harm, including the safety of training data.
- Anticipating and responding to emerging AI risks.
In line with this last point, it’s essential for organisations to understand their approach to AI and ensure risks are identified, assessed and managed appropriately.
Key Considerations for Implementing AI
To embed AI effectively and securely within your organisation, there are several areas to review:
- Current use and future need: What AI tools are already in use (authorised or otherwise)? Where could AI add value? What functionality have suppliers introduced?
- AI Policy: Define accountability, relevant legislation and standards (e.g. EU AI Act, ISO 42001), acceptable and prohibited uses, and your approach to supplier due diligence.
- Risk assessment: Adapt existing approaches to address AI-specific risks such as transparency, how easy it is to explain/understand, bias, accuracy, cyber risks and the use of personal data in training. Consider whether you need an AI-specific DPIA template.
- Supplier assurance: Review whether your third-party due diligence process covers AI risks.
- Automated decision-making: Ensure appropriate human oversight remains possible.
- Procurement and contracts: Add AI-specific requirements, including obligations for suppliers to notify you of new AI functionality.
- Testing and validation: Assess solutions before deployment and continue to monitor outputs against expectations.
- Staff awareness: Update training to include AI-specific risks and organisational responsibilities.
Next Steps
AI offers clear opportunities but also brings new responsibilities. Taking a structured approach now will help ensure adoption is secure, compliant and trusted.
If you would like to understand more about how Data Protection applies to AI in your organisation, or need support with AI policies, risk assessments or DPIAs, please get in touch with the team at Evolve North at info@evolvenorth.com or follow us on LinkedIn for real-time updates.
