LEGAL & COMPLIANCE
How to manage the legal risks of AI in your business — before they land on your desk
Privacy, copyright and employment law don’t pause just because you used a chatbot.
If you’ve started using AI tools in your business, there’s a good chance nobody sat you down and explained where the legal lines are. You’ve probably just been getting on with it, the way most small business owners do.
That’s understandable. But UK law on privacy, copyright and employment didn’t get rewritten for AI. It still applies, in full, to whatever you generate, paste in, or decide with the help of a chatbot.
This article walks through where the real risks sit, and what to actually check before you press “generate” again.
The short answer
The rules that already governed your data, your content and your staff decisions still apply when AI is involved, and you can’t blame the software if something goes wrong.
Your biggest practical risks are:
- Pasting personal or customer data into tools that store or train on it
- Publishing AI content without checking who owns it
- Using AI to help with hiring or performance decisions without a human properly checking the outcome
None of this means avoid AI. It means know what you’re responsible for before you use it.
We’ll send a password for the resource area and regular UK-focused AI updates. Unsubscribe anytime.
Why “the AI did it” isn’t a defence
Here’s the thing that trips up a lot of business owners: you don’t get to point at the software when something goes wrong.
If an AI tool discriminates against a job applicant, breaches someone’s data, or produces content that infringes someone else’s copyright, the responsibility sits with you, not the vendor.
That’s not scaremongering. It’s just how UK law has always worked. If you hired a consultant who gave you bad advice and you acted on it, you’d still be the one accountable to your customers, your staff and your regulator. AI tools are no different. They’re a resource you’re using, not a shield.
Does that mean AI is too risky to bother with? Not at all. It means you treat it the way you’d treat any other business decision: understand what you’re agreeing to, check the output, and don’t switch your brain off just because the tool sounds confident.
“AI should help your people do better work. It shouldn’t remove human judgement from important decisions.”
What actually counts as “your” data going into an AI tool?
This is where most small businesses run into trouble first, usually without realising it.
Customer names, email addresses, order histories, staff records, supplier contracts – all of this is personal or commercially sensitive data, and UK GDPR and the Data Protection Act 2018 apply to it whether you’re typing it into a spreadsheet or pasting it into ChatGPT.
Ask yourself this before you paste anything into an AI tool: would you be comfortable if the customer whose details you just typed in could see exactly what you did with their information? If the answer’s no, don’t do it.
Check the settings, not just the terms
Most consumer AI tools let you turn off “improve the model with my data” somewhere in settings. Do this before you use the tool for anything involving real customer or staff information. It won’t fix every issue, but it’s a genuinely free five-minute step that closes off one of the biggest risks.
A simple example
A hairdresser uses an AI chatbot to draft a follow-up email to a client who complained about a colour treatment. If she pastes in the client’s full name, contact details and a description of a health condition mentioned in conversation, she’s now processed special category data through a third-party tool she may not have checked.
If she instead writes “a client had an allergic reaction to a colour product, draft an apologetic follow-up email” with no name attached, she gets the same useful output without the data risk.
Same task. Much less information. That’s data minimisation in practice.
Free tools aren’t always “just for you”
Many free or low-cost AI tools use what you type to help train their models, unless you’ve specifically opted out or you’re on a business tier with different terms.
Before you use any AI tool with real business or customer information, check the privacy settings and the terms of service for how your inputs are used and stored. Don’t assume a tool is safe just because a competitor uses it.
A simple data traffic light system for your business
You don’t need expensive software to start managing AI risk. Use this simple colour-coded system with your team:
| Colour | What it means |
|---|---|
| Green | Information that’s already public and low risk. Safe to use with most AI tools (but still check terms). |
| Amber | Internal business information that needs care. Think contracts, pricing, strategy, internal memos. |
| Red | Sensitive personal information, confidential customer data, passwords, financial information, commercially sensitive material, or anything that could seriously harm someone if exposed. Think twice – often don’t enter at all. |
Do you need to tell customers you’re using AI?
In some cases, yes. Transparency is one of the core principles of UK GDPR, which means your privacy notice should explain, in plain terms, when AI is being used to process someone’s personal data.
That doesn’t mean flashing “AI INSIDE” on every email. It means being straightforward if AI plays a real role in decisions that affect someone, like automated responses, chatbots handling enquiries, or any kind of scoring or filtering.
Think about how this lands from the customer’s side. Nobody minds a chatbot answering “what are your opening hours”. People do mind finding out, after the fact, that an algorithm decided whether their complaint got escalated, without anyone telling them that’s how it works.
A retailer running a customer service chatbot on their website is a useful example. Being upfront that customers are talking to an AI assistant first, with a clear route to a human, avoids most of the trust problems. Hiding it, or letting customers assume they’re messaging a person, is the version that tends to generate complaints.
Copyright and plagiarism – what you need to know
This is one of the most misunderstood areas, and it’s where small businesses can get caught out.
There are two separate risks.
First, you might not own what AI creates. UK law on AI and copyright is genuinely unresolved. The government’s March 2026 report confirmed that the rules haven’t been settled, and it’s not clear whether AI-generated work with minimal human input is protected at all.
Second, you might accidentally copy someone else’s work. AI tools are trained on existing content, and outputs can sometimes closely resemble copyrighted material – especially with images, logos, and distinctive styles.
What about plagiarism? Plagiarism isn’t the same as copyright infringement. It’s about passing off someone else’s work as your own – an ethical and reputation issue, not necessarily a legal one. But if someone notices, the damage to your credibility could be significant.
What should you do?
- Use AI as a drafting tool, not a final author
- Rewrite and personalise AI output before publishing
- For images and logos, be especially careful – don’t use AI-generated visuals for core brand assets without getting legal advice
- Keep records of your prompts and the outputs you use
If you’re using AI to generate your logo, packaging, or anything central to your brand, get it checked properly before you build a business around it. A quick IP consultation is worth it here.
What should you check before publishing AI-generated content?
Before anything AI-generated goes out under your business name, run through a short mental checklist:
- Is it accurate?
- Does it sound like something a real customer could recognise as coming from you?
- Could any part of it resemble someone else’s existing work closely enough to cause a problem?
A small professional services firm publishing an AI-drafted article on its website is a good example of where this matters. If the AI has confidently invented a statistic, a case study, or a claim about a regulation, and nobody checks it before it’s published, that’s now the firm’s error, not the tool’s.
The Advertising Standards Authority and, depending on your sector, other regulators don’t distinguish between claims a human wrote and claims AI wrote. If it’s on your website, it’s yours.
Don’t let AI make factual claims you haven’t verified
AI tools can produce statistics, quotes and legal or regulatory claims that sound completely plausible and are entirely wrong. Before publishing anything AI has generated that states a fact, a figure or a legal position, check it against a real source. This applies especially to anything involving pricing, health claims, safety information or legal advice to customers.
Using AI to help with hiring: where does it actually stand?
This is one of the fastest-moving areas of AI regulation, and it’s worth getting right, because the consequences of getting it wrong land in an employment tribunal, not just an inbox.
The Equality Act 2010 doesn’t have an AI exemption. If an AI tool you’re using to screen CVs or rank candidates systematically disadvantages people with a protected characteristic, even unintentionally, that’s a discrimination risk you carry.
Here’s a question worth asking yourself: if a rejected candidate asked you to explain exactly why the tool ranked them lower, could you actually answer that? If the honest answer is “I don’t really know, the software just did it”, that’s a sign you need more human oversight in the process, not less.
What “human oversight” actually means here matters
Regulatory guidance has been direct on this point: human review that amounts to a token gesture doesn’t take a decision outside the automated decision-making rules. If a manager glances at an AI-generated shortlist for a few seconds before approving it, that’s not meaningful oversight, and it won’t protect you if the decision is challenged.
A builder taking on an apprentice, or a café hiring seasonal staff, might not think any of this applies to them. But if you’re using any tool that filters, scores or ranks applicants automatically, even a basic one built into a job board, this is relevant to you, not just to large employers running sophisticated recruitment software.
Practical steps for safe AI recruitment:
- Check what any recruitment tool you use actually does with applicant data, and for how long it’s kept.
- Make sure a real person reviews every shortlist or rejection with the genuine ability to change it, not just approve it.
- Keep a record of who reviewed what, and when. If a claim comes years later, you’ll need this.
- Ask your tool provider directly what bias testing they’ve done, and get the answer in writing.
Using AI to monitor or manage existing staff
Hiring isn’t the only place this shows up. AI is increasingly used for performance monitoring, shift scheduling, and even flagging when staff might be underperforming.
There’s a human side to this that’s easy to lose sight of when you’re focused on efficiency. Being managed, even partly, by an algorithm affects how people feel about their job. If your staff find out an AI system is quietly scoring their performance and nobody explained that to them, don’t be surprised if trust takes a hit, regardless of whether the tool itself was accurate.
Tell your team before you tell the tool
If you’re introducing any AI system that touches how staff are monitored, scheduled or assessed, explain it to your team before it goes live, not after someone notices. If certain roles are expected to begin using AI, that may amount to a change in terms and conditions, which means you may need to consult staff formally, not just send a memo.
When should you simply not use AI?
This is perhaps the most important question in the whole article.
There’s a tendency to assume that because AI can do something, you should use it. You don’t.
The right question isn’t “Can AI do this?” It’s “Should AI do this?”
That small change in thinking can save you a lot of trouble.
Steer clear of relying on AI, without heavy human checking, for:
- Any decision about hiring, promoting or dismissing a specific person
- Anything involving a customer’s health, safety or financial vulnerability
- Legal or regulatory claims you’re making publicly
- Anything where you couldn’t clearly explain the reasoning to the person it affects
If you can’t confidently explain why a decision was made, that’s usually a sign a human needs to be more involved, not less.
Other situations where you should pause:
- The cost of getting something wrong is very high
- You can’t explain how an important decision is being made
- The information is highly sensitive
- You don’t understand what happens to the data
- You can’t check the AI’s output properly
- The system could discriminate against someone
- The task requires professional judgement
- The supplier can’t answer basic questions about security or data
- The supposed time saving is tiny
- A simple non-AI solution would work just as well
Build a simple AI legal check – a one-page checklist
You don’t need a 40-page policy. Start with this one-page checklist for every new AI use.
Before approving an AI task, ask:
1. What is AI actually doing?
Is it drafting, summarising, recommending, scoring, deciding or taking action?
2. What information am I giving it?
Identify personal, confidential, commercially sensitive and copyrighted material.
3. Who could be affected?
Think about customers, employees, applicants, suppliers and other people.
4. What happens if it’s wrong?
Would a wrong answer be annoying, expensive, embarrassing or harmful?
5. What law might apply?
Consider data protection, copyright, employment, equality, consumer law and any sector-specific rules.
6. Who checks the result?
For important decisions, identify the person responsible for reviewing the output.
7. Can I explain what we’re doing?
If you can’t explain the AI process in plain English to a customer or employee, that’s a warning sign.
8. Is AI actually worth it?
Compare the benefit with the cost and risk.
This process can take 10 minutes. It can also prevent you spending months building an AI process that you later discover you shouldn’t be using.
What if something goes wrong?
Don’t panic.
First, stop the process if necessary. Then work out what happened.
- If an employee accidentally puts customer information into the wrong AI service, don’t simply delete the chat and hope for the best. You need to consider whether you’ve had a personal data breach and whether any reporting or other action is required.
- If copyrighted material has been used incorrectly, stop using the material and investigate the rights involved.
- If AI has made a recruitment or employment decision that may have disadvantaged someone, review the decision and the process that produced it.
- If an AI customer service system has given incorrect information, correct it and consider whether other customers may have received the same information.
The key is to treat AI mistakes as business incidents, not just software glitches.
Keep an AI incident log
It can be a simple spreadsheet with four columns:
- Date
- What happened
- Who was affected
- What you did about it
You may never need it. But if something does go wrong, you’ll have a record of what happened and how you responded.
What should you ask an AI supplier before using its tool?
You don’t need to understand the supplier’s entire technical architecture. You do need sensible answers to a few basic questions.
Before putting business information into a tool, ask:
- What happens to the information I enter?
- Is my information used to train or improve the model?
- Where is my data stored?
- Who can access it?
- How long is it retained?
- Can I delete it?
- Does the supplier use other companies to process the information?
- What security measures are in place?
- Can I control user access?
- What happens to my data if I cancel?
- Does the service support the data protection requirements I need to meet?
- What happens if the supplier suffers a security incident?
Don’t accept vague answers just because the software looks impressive. And don’t assume the cheapest free version has the same controls as a paid business product.
AI FAQs
Questions people ask about AI legal risks
These are the practical questions UK business owners are asking about the legal side of using AI.
Can I use ChatGPT with customer information?
You can, but be careful what you paste in. Avoid putting in full names alongside sensitive details like health information, and check the tool’s settings for whether your inputs are used to train the model. For anything involving real customer data at scale, a business-tier tool with clearer data handling terms is safer than a free consumer account.
Who owns content my business creates with AI?
It depends, and UK law on this hasn’t fully settled. The more genuine creative input and editing you put in, the stronger your position. Don’t build a core brand asset, like a logo, entirely on AI output without getting that checked.
Can I get in trouble for using AI to reject job applicants?
Yes, if the process results in discrimination against someone with a protected characteristic under the Equality Act 2010, it doesn’t matter that software made the decision. You remain responsible.
Do I need to tell customers I’m using an AI chatbot?
If it’s making or influencing decisions that affect them, you should be upfront about it. At minimum, make it clear they’re talking to an automated assistant and give them an easy way to reach a person.
Do I need a Data Protection Impact Assessment to use AI?
Not for everyday tasks like drafting emails. You likely do if you’re using AI to screen customers, score risk, or make decisions that significantly affect people. If you’re unsure, that uncertainty is itself a reason to check rather than assume.
Is it illegal to use AI-generated images in my marketing?
Not illegal, but it carries two separate risks: you may not fully own the image, and it could unintentionally resemble someone else’s existing copyrighted work. Check both before it becomes central to your branding.
Can my employees refuse to use AI tools at work?
If using an AI tool is being introduced as part of someone’s role, this can count as a change to their terms and conditions, which usually means proper consultation is needed, not just an instruction.
What happens if an AI tool gets something wrong and I publish it?
Legally, that’s treated as your error, not the tool’s. Regulators like the Advertising Standards Authority don’t distinguish between human-written and AI-written claims once they’re published under your business name.
Sources
-
Information Commissioner’s Office — Guidance on AI and data protection
★★★★★
Regulator
The ICO’s core guidance on how UK GDPR principles apply to AI systems, including fairness and automated decision-making. -
Acas — AI in the workplace guidance
★★★★★
Regulator/official body
Acas guidance on consulting staff, checking AI outputs for bias, and recognising changes to terms and conditions. -
UK Government (DSIT, IPO, DCMS) — Report on Copyright and Artificial Intelligence, March 2026
★★★★★
Official government report
Sets out the current, unresolved state of UK policy on AI and copyright ownership. Confirms the government has stepped back from its preferred opt-out exception. -
Turnitin — Reaping Rewards. Risking Reputation: Corporate publishing in the GenAI Era
★★★★☆
Industry research
Survey findings showing 75% of companies are increasing GenAI use but only 22% feel prepared to manage the risks. -
GOV.UK — Data (Use and Access) Act 2025: data protection and privacy changes
★★★★★
UK government
Provides an overview of the statutory changes affecting UK GDPR, including automated decision-making. -
GOV.UK — Responsible AI in recruitment
★★★★★
UK government guidance
Provides practical guidance on human oversight, accessibility, equality and the risks of AI in recruitment. -
GOV.UK — Using AI agents: complying with consumer law
★★★★★
UK regulator
Explains the responsibilities businesses retain when using AI agents to interact with customers. -
GOV.UK — How copyright protects your work
★★★★★
UK government
Provides the underlying UK copyright principles relevant to businesses using and creating protected works.
⚠️ Evidence note: Some of what’s covered here is settled law: UK GDPR, the Data Protection Act 2018 and the Equality Act 2010 all apply to AI-assisted decisions in the same way they apply to any other business decision.
Other parts, particularly AI and copyright ownership, are genuinely unresolved. The UK government’s own March 2026 report on copyright and AI reached no firm policy position and set no legislative timetable.
Where this article describes legal risk, it’s describing the current regulatory direction and existing case law, not settled certainty. If a decision carries real money or real risk for your business, get advice specific to your situation rather than relying on general guidance like this.
Make a better AI decision
You don’t need to become a data protection expert or a copyright lawyer to use AI safely in your business. You need to know where the real risk sits, and check those specific things before you publish, hire or process someone’s data with AI involved.
Start with one AI task you’re currently using or considering. Write down what information goes into it, what the AI produces, who could be affected, and what happens if it gets it wrong.
And in the next ten minutes, open the settings of one AI tool you’re already using and check one thing: whether it’s using what you type to train its model. If it is, and you’ve been putting in real customer or staff information, turn that off now.
You don’t need to become an AI lawyer. You just need to make a better AI decision.
Explore more practical guidance →