AI and data regulation: what organisations need to know
The UK government has opened a call for evidence on data regulation in the age of AI and other data-intensive technologies.
Published by the Department for Science, Innovation and Technology on 15 July 2026, the call for evidence asks how current data regulation interacts with emerging technologies, where uncertainty remains and whether further guidance or reform may be needed.
For organisations using, testing or considering AI, this is a timely reminder that AI governance and data protection cannot be treated as separate issues.
What has happened?
The call for evidence looks at how personal and non-personal data regulation affects AI and other data-intensive technologies.
It asks for practical examples of how existing rules apply in real settings, including where organisations face uncertainty, friction or barriers to responsible data use.
It also considers how legal, technical and governance arrangements could support data sharing and reuse while managing potential harms.
You can read the call for evidence on GOV.UK here: Data regulation in the age of AI and other data-intensive technologies.
Why does this matter?
AI systems rely on data. In many cases, they rely on large volumes of data from different sources, used in ways that may not have been expected when the data was first collected.
That creates a practical challenge for organisations.
They need to understand not only what the technology can do, but whether the data behind it is being used lawfully, fairly and transparently.
For example, an organisation may need to consider whether the data was collected for a compatible purpose, whether people have been told how their data may be used, whether outputs can be explained and whether bias, accuracy or security risks have been assessed.
This is not simply a compliance exercise. It is about trust, accountability and good decision-making.
What questions should organisations be asking?
Before using AI or data-intensive tools, organisations should be able to answer some basic questions about the data involved.
- What data is being used?
- Does it include personal data?
- Why is the data being used?
- Is there a lawful basis for using it?
- Has the purpose changed since the data was collected?
- Can the organisation explain how decisions or outputs are produced?
- Who is accountable for the tool and its outcomes?
- How are bias, accuracy, transparency and security risks being managed?
- Has a Data Protection Impact Assessment been considered?
A Data Protection Impact Assessment, often called a DPIA, is a process used to identify and reduce data protection risks before processing begins. It is especially important where new technology may affect people’s rights or freedoms.
Good AI governance starts with good data governance
AI governance means the rules, roles and checks an organisation uses to make sure AI is used safely and responsibly.
Data governance means the way an organisation manages data, including who owns it, how it is accessed, how it is used, how it is protected and when it should be deleted.
The two are closely linked.
If an organisation does not understand its data, it will struggle to explain its AI. If it cannot explain its AI, it may struggle to evidence compliance, respond to concerns or build trust with customers, staff, regulators and the public.
This is why data protection should be involved early in AI projects, not added at the end.
Catarina Santos, Consultant Manager at Data Protection People, said:
“Whilst this call for evidence does not introduce any new guidance or changes to the law, it is a positive step. It provides an opportunity to identify where the current framework may not be clear enough and to better understand the challenges organisations face when using AI. Listening to the experiences of businesses, regulators and other stakeholders should help shape future guidance and ensure that any changes strike the right balance between encouraging innovation and protecting individuals’ personal data.”
What should organisations do now?
The call for evidence does not change the law today. However, it is a useful signal of where future debate, guidance and possible reform may focus.
Organisations should use this moment to review how they assess AI tools and data-intensive technologies.
Practical steps include:
- Mapping what data is used in AI tools.
- Checking whether personal data is involved.
- Reviewing lawful basis and transparency information.
- Considering whether a DPIA is needed.
- Recording who is accountable for each tool.
- Reviewing supplier and processor arrangements.
- Training staff on when AI use creates data protection risk.
Good AI use depends on clear roles, clear records and clear decisions.
FAQ
What is the government call for evidence about?
It is about how data regulation interacts with AI and other data-intensive technologies. The government is asking for practical examples of what works, where uncertainty remains and where further guidance or reform may be needed.
Does this change the law?
No. A call for evidence does not change the law. It is a way for government to gather information before deciding whether further guidance, policy changes or legal reform may be needed.
Why does this matter for organisations using AI?
It matters because AI often depends on large amounts of data. Organisations need to understand what data they are using, why they are using it and how they will manage legal, ethical and security risks.
What is AI governance?
AI governance means the rules, roles and checks an organisation uses to make sure AI is used safely, responsibly and in line with the law.
What is data governance?
Data governance means how an organisation manages data. This includes ownership, access, use, protection, retention and deletion.
When should data protection be considered in an AI project?
Data protection should be considered at the start of an AI project. This helps organisations identify risks early, document decisions and avoid problems later in the project.
Data Protection Made EasyAt Data Protection People, we help organisations understand data protection in practical terms.
If your organisation is reviewing AI tools, updating governance or trying to understand how data protection applies to new technology, we can help make the next steps clearer.