There is no single UK AI law that you need to read. What matters more is that the rules you already live under, particularly data protection, apply just as much when a task is done by an AI tool as when it is done by a person. This lesson is general information to help you ask better questions, not legal advice. For anything specific, take proper advice.
UK GDPR applies whenever personal data is involved
If you put information about an identifiable person into an AI tool, you are processing personal data and the usual duties apply: a lawful basis, only using what you need, keeping it secure, and being honest with people about what happens to their information. Using a third party tool does not move that responsibility off you.
Extra care with decisions about people
Recruitment shortlisting, performance assessment, and credit or eligibility style decisions are sensitive areas. Data protection law places limits on decisions made purely by automated means with significant effects, so keep a person genuinely in the loop, someone who reviews the substance and can overrule it, not someone who rubber stamps a result.
The EU AI Act, in outline
The EU has adopted an AI Act that sorts uses into risk levels, with the heaviest duties on high risk uses and outright prohibitions on a small number. It is EU law, so it matters to a UK firm mainly if you sell into the EU, or if your AI system's output is used there. Most everyday office use sits well below the high risk tier.
Copyright is genuinely unsettled
Questions about training on copyrighted material, and about who owns purely machine generated output, are still being argued and litigated. Practically, treat AI output as a draft you then make your own, and do not assume you have clear ownership of something the tool produced unaided.
Be straightforward with customers
If people are dealing with an automated system rather than a person, do not disguise it. Transparency is a running theme across data protection, consumer expectations, and emerging AI rules, and it costs you very little to be plain about it.
Common mistakes
- Assuming data protection duties do not apply because a third party tool is doing the processing.
- Letting a tool screen job applicants with no meaningful human review of the outcome.
- Treating a confident AI answer as legal, employment, or tax advice.
- Publishing AI generated text or images with no thought about ownership or copyright.
- Presenting an automated chat as a named member of staff.
- Assuming EU rules can be ignored while actively selling to EU customers.
Check yourself
0/41.You want to use an AI tool to sift job applications and produce a shortlist. What is the key legal caution?
2.When is the EU AI Act most likely to matter to a UK small business?
3.You paste a customer's details into a public AI tool to help draft a reply. From a UK GDPR point of view, what have you done?
4.An AI tool gives you clear, confident wording about your obligations when making someone redundant. How should you treat it?
This is general guidance, not a substitute for advice on your specific setup. Want a hand putting it into practice? Talk to us or see our care plans.
