AI Agents: A New Frontier of Risk

For the past few years, legal, compliance and data protection professionals have largely focused on the risks associated with deploying large language models (LLMs) such as ChatGPT and Claude. The focus is now expanding to agentic AI, defined by IBM as: 

“…an artificial intelligence system that can accomplish a specific goal with limited supervision. It consists of AI agents – machine learning models that mimic human
decision-making to solve problems in real time.” 

The key difference between LLMs and agentic AI is autonomy. Traditional AI tools usually operate within a defined task and rely on people to decide what happens next. By contrast, agentic AI can adjust its actions as information changes, tools become available or the task develops. In this sense, “agentic” describes technology that can act purposefully, rather than merely produce a response. 

Let’s take a customer service scenario. An AI agent could receive a complaint, review the customer’s previous interactions in Salesforce, check delivery information in a logistics system, draft a response, create a follow-up case and route the issue to a human member of staff where judgement is needed. That is materially different from an AI chatbot that helps with basic tasks like write an email or answer queries. 

Many organisations are now deploying AI agents in areas such as sales and customer service, using tools offered by the likes of OpenAIGoogle and Salesforce. In the health sector, tools such as Oracle Health Clinical AI Agent help clinicians by supporting documentation and workflow automation within electronic health record systems. 

Cybersecurity Risks 

But the deployment of AI agents is not without risk. An AI agent may have the ability to act, rather than simply advise. Depending on the use case, it could connect to business applications, recommend or make decisions, trigger workflows, send messages, alter records or begin a financial process. These capabilities mean that there is much more that can go wrong compared with a traditional LLM, where the main risk is
over-reliance on an output that may not be accurate. 

One of the key risks associated with deploying AI agents is cyber security. An agentic system may be linked to internal systems, third-party services, customer information, APIs and external tools. Each connection creates potential exposure. If an agent has excessive permissions or is badly configured, an attacker may be able to influence its actions, redirect it towards an unintended outcome or gain access to sensitive commercial or personal information. 

Testing an AI agent before deployment is crucial. Just yesterday, OpenAI revealed that its AI agent went rogue and hacked a start-up after it lost control of it during a security test. The joint guidance Careful adoption of agentic AI services, co-authored by the NCSC and international partners, recommends that organisations start small, use agents initially for low-risk tasks and apply established cyber security controls from the outset. 

In practice, this means applying secure design, least privilege, access management, monitoring, incident response planning and supplier assurance. For a detailed discussion on the impact of AI on cybersecurity, listen to the Guardians of Data podcast with Caroline Wong. 

Data Protection Risks 

Data protection risk can also increase where an AI agent needs broad access to information to carry out its objective. It may pull together customer records, identify patterns, summarise communications, classify individuals, suggest next steps or trigger further action. Much of this will involve personal data and so the UK GDPR will come into play. 

The ICO has taken a keen interest in this area. In its Tech Futures report on agentic AI, it states: 

“One of our key findings from this initial work is that the specific design and architecture of agentic systems impact how data protection law applies and how people exercise their data protection rights. Choices such as the data and tools that a system can access and which governance and control measures to put in place really matter.” 

The ICO’s AI and data protection toolkit helps organisations assess how AI systems may affect individuals’ rights and freedoms. Key data protection risk questions for organisations deploying an AI agent include: 

  • What personal data does the agent need to perform the task? 
  • Can the same outcome be achieved using less data? 
  • Is the agent making or informing decisions about individuals? 
  • Are special category data, children’s data or vulnerable individuals involved? 
  • Can individuals understand when AI is being used and how to challenge decisions? 
  • Are prompts, outputs, logs and feedback data retained, and if so for how long? 
  • Have the controller/processor roles been properly analysed? 

Governance 

Any organisation adopting AI will need an AI governance policy. With agentic AI, however, governance must be more than a static document. It should be a working process that follows each proposed use case from initial idea through to deployment, monitoring and later review. 

Higher-risk use cases should be assessed before launch by legal, data protection, security, product and operational stakeholders. That assessment should cover the agent’s purpose, degree of autonomy, access to data and systems, impact on users, contractual arrangements, supplier terms, monitoring approach and exit plan. 

Good governance also depends on records. Organisations should keep evidence of risk assessments, testing, known limitations, approvals, training materials, monitoring outcomes, complaints, incidents, remedial steps and changes to prompts or workflows. That evidence may become important if a customer, regulator or court later asks what happened, when things go wrong. The organisation will need to show not only that it had a governance framework, but that the framework was followed in practice. 

AI agents bring exciting possibilities, but also many risks. They may also change the structure of organisations for good. Caroline Wong, an AI expert speaking on the  Guardians of Data podcast, predicts that the future workforce could be a mix of human and agentic AI “workers.” You can listen to a short clip here

Learn more about AI agents and their safe deployment on our forthcoming webinar. You can also hear more on building trustworthy and responsible AI systems with AI expert Tahir Latif in this podcast.

New Podcast: Managing Workplace Data Protection Risks 

The biggest data protection challenges facing organisations do not stem solely from cyber-attacks or AI deployment; they also arise from employees. Sometimes it’s an innocent mistake; an email sent to the wrong person, confidential information shared inadvertently or a document uploaded to the wrong system. In other cases, the issues are more serious; employees accessing information they have no business looking at, taking confidential data when they leave, or deliberately misusing personal information. 

When those situations arise, employers need to investigate what has happened, decide whether a breach needs to be reported to the ICO and manage employment law issues such as disciplinary action; all the while protect the rights of the individuals whose data is involved, including employees.  

And then there’s the inevitable employee Data Subject Access Request, or DSAR to deal with. Often made alongside a grievance or before Employment Tribunal proceedings, DSARs can present significant legal and practical challenges for employers trying to balance transparency with confidentiality and legal privilege. 

In Episode 13 of the Guardians of Data podcast we explore: 

  • what happens when employees are involved in personal data breaches; 
  • the legal and practical issues arising when employees misuse personal data; 
  • how employers should approach workplace investigations involving personal data; and 
  • how to respond effectively to employee Data Subject Access Requests. 

Our guest is Andrew Latham, a partner in the Public Law team at Capsticks, who specialises in data protection and privacy law.  

Listen on your preferred platform via our podcast page, or download the episode directly.

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’tdesigned for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Caroline Wong talking about responsible the impact of AI on Cybersecurity, Jen Persson, a privacy campaigner, explaining the privacy implications of the Government’s new plans for children’s data, and Ilyas Nagdee analysing the impact of predictive policing in human rights.

Advanced Certificate in GDPR Practice

Are you an experienced Data Protection Officers seeking to refine and expand your DPO skills and expertise? 

The Act Now Advanced Certificate in GDPR Practice is one of the UK’s leading advanced qualifications for DPOs.   

Since its launch in 2020, this innovative course has attracted DPOs from across the public and private sectors. Feedback has been consistently positive with many participants commenting on how the course has given them the confidence and skills to be able to dissect complex data protection scenarios and give clear and practical compliance advice.  

Further advances in technology, especially in AI, has led us to revise the syllabus to ensure participants are engaging with the most up to date data protection issues and ICO/Tribunal decisions to inform their day to day work.  

New Assessment Format 

Based on extensive feedback from delegates over our suite of certificate programmes, we learned that delegates would prefer not to have to write extensive reports and want the opportunity to showcase their critical thinking and communication skills. 

The new assessment consists of two parts. The first part requires participants to submit a personal development plan about how their learning from the course will inform and improve their practice as a data protection practitioner. The second part requires them to draft an executive summary setting out the issues and recommendations in relation to the fictional case study discussed in Masterclass 4. This summary will then be presented by participants in an oral examination, known as a Viva.  

Watch Alex, one of our recent delegates, give his verdict on the course. 

There are just three places left on the next course starting on 21st October 2026. Click below to learn more.

Schools Warned After Criminals Manipulate Children’s Photos from Websites

Many school websites and social media feeds contain photographs of students in a variety of settings; from participating in lessons or sports to performing on stage or enjoying educational visits. This practice is often justified on the basis that such images showcase achievement and attract prospective families. Some have even said to this author, “It looks good with Ofsted.” But the dangers of this practice have been highlighted recently by the Internet Watch Foundation (IWF) and the National Crime Agency (NCA).  

The IWF and NCA report an increase in criminals exploiting publicly available images of children to create realistic sexualised content using Artificial Intelligence. Analysts found 3,440 AI-generated videos of child sexual abuse in 2025, compared to just 13 in 2024. Most worryingly, IWF report that an unnamed UK secondary school was recently subjected to a blackmail attempt after criminals downloaded photos of children from the school’s website or social media accounts and then, using AI tools, turned them into child sexual abuse material. The criminals then demanded payment from the school to prevent the images from being shared online. 

The IWF and NCA are recommending that educational institutions remove identifiable pictures of children from their websites and social media accounts.  

AI Enabled Sextortion 

Blackmailing people over intimate images, also known as sextortion, has a become increasingly prevalent in recent years following the trend to share the most intimate details online. Children, especially young girls, are particularly vulnerable. Sometimes they face pressure from boys to show their “commitment” to a relationship by sharing intimate images.
The Children’s Charity, The NSPCC, and The Report Remove service, which allows children in the UK to confidentially report sexual images and videos of themselves and remove them from the internet, have recently reported a sharp rise in children being blackmailed over sexual images. There have also been cases of British teenagers who have killed themselves after receiving extortion threats

The advancement in Generative AI tools now mean that any image, no matter how innocent, can be sexualised. Readers may remember the controversy involving Grok; the AI companion built into X, Elon Musk’s social media platform.  It began in May 2025 when users prompted Grok to alter photos of real women into sexualised images. By late 2025 it had escalated dramatically; users simply replied to public photos with requests like “put her in a bikini,” and Grok posted the generated images directly to X, publicly and instantly. Estimates suggest it produced around 4.4 million images in nine days, with 41 to 65 per cent sexualised. Some of those images involved children. X has since made changes to Grok to prevent abuse. More recently Meta was forced to withdraw its new AI tool Muse Image, following a public backlash. It could generate new photos using other people’s social media profile photoswithout telling them.  

Data Protection  

Publishing photos of children is also a data protection issue and so needs to comply with the UK GDPR. Like all processing of personal data it needs to be, amongst other things, fair, lawful and transparent. Data subjects, including children, have rights including the right to object and receive a copy of their data, including images, and ask for them to be deleted (subject to some exceptions).  

The Information Commissioner’s Office guidance about photos in schools emphasises the importance of complying with the UK GDPR but needs an update to cover the dangers of AI. Most schools will have a privacy policy and a procedure for collecting consent from parents before publishing images of their children. However research by Northumbria University, and published by Defend Digital Me, a children’s rights campaign group, states that only 7% of education authorities who disclosed their schools image guidance (following FOI requests) mentioned that posting photographs on social media may pose a risk to children’s privacy. The research authors suggest that parents are therefore being asked to provide consent to photographs being shared online without being told of the risks that this may pose. 

Raising Awareness 

There is a clear need here to educate parents, children and schools about the dangers (as well as the legal issues) posed by AI when it comes to public images of children. 

The Internet Watch Foundation and the National Crime Agency have produced a new guide for parents and carers which recommends amongst other things, reviewing privacy settings on apps, talking to their children, and knowing what to do if something goes wrong. This follows similar advice they issued to education professionals last year, on how to protect student images from AI manipulation. 

In the Guardians of Data podcasts we delve deeper into the issues raised here:  

  • In Episode 2 we explore the Grok AI controversy. 
  • In Episode 6  we discuss the legal, ethical and societal issues around taking photographs in public for social media.  
  • In Episode 8 we analyse the Government’s plans for our children’s data, discuss children’s privacy in the internet age and the role Big Tech is playing in the collection storage and analysis of all our data.  

Our GDPR Essentials E Learning course is ideal for school staff and education professionals who require foundational knowledge about GDPR compliance and the key risk areas. Click here to watch a preview.

See also our workshop: Working with Children’s Data

New Podcast: The Hidden Algorithms Behind Modern Policing

“There’s a significant lack of transparency around police use of predictive policing systems in the UK. Most people don’t even know about their use in policing… People don’t know, if they are ever stopped and searched by police, it’s as a result of a predictive profiling or risk assessment system… So there is a significant lack of transparency, which is particularly worrying given the lack of regulation.” 

Ilyas Nagdee, Amnesty International 

Episode 12 of the Guardians of Data Podcast is out now. In this episode we discuss something that sounds like science fiction, but is already part of everyday policing in the UK; predictive policing. These are tools that use data and algorithms to help the police forecast crime, where it might happen and sometimes who might be involved. The idea is to use resources efficiently and cut crime. 

But a recent report by Amnesty International, (“Automated Racism”) argues that predictive policing tools aren’t neutral; they may be reinforcing and scaling existing inequalities. The report argues that the data they use is biased, particularly against black and racialised communities in deprived areas.  

In this conversation, we unpack what these tools actually are, how they’re being used, whether they work, and what the risks are, especially when combined with other technologies like facial recognition. 

Our guest is Ilyas Nagdee who is a human rights campaigner and the Racial Justice Director at Amnesty International UK. He has also written for The Guardian and is the co-author of a book entitled, Race to the Bottom: Reclaiming Antiracism, a critical study of anti-racist politics in the UK. 

Listen on your preferred platform via our podcast page, or download the episode directly.

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’t designed for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Caroline Wong discussing the impact of AI on cyber security, Emma Martins explaining the importance of data protection legislation, Tahir Latif talking about responsible AI deployment and Jen Persson explaining the privacy implications of the Government’s new plans for children’s data. 

New FOI Style Requirements for Housing Associations

From October, tenants of non-local authority social landlords, such as housing associations and housing co-operatives, will have new rights to access information about how their homes are managed. Tenants of local authority-owned housing can already access this information under the Freedom of Information Act 2000.  

In Autumn last year, The Ministry of Housing, Communities and Local Government published a policy statement following a consultation on the introduction of Social Tenant Access to Information Requirements (STAIRs). Some have dubbed this “FOI for the housing sector.”  

The Regulator of Social Housing has been directed to introduce a new standard requiring all non-local authority social landlords (also known as private registered providers or “PRPs”) such as housing associations to comply with the new requirements.

Publication Scheme 

From 1st October 2026, PRPs must proactively publish information that they hold relating to various matters such as governance and decision making, spending, housing stock management, performance, housing services, lists and registers and social housing management. 

They must make tenants aware of the publication scheme so that they can easily identify and access information. Just like under FOI, there is no requirement to create any new records to comply with this obligation and redactions may be made in certain circumstances e.g. to protects commercially sensitive or personal information. 

Information Requests 

From 1st  April 2027, PRPs must respond to their tenants’ requests for information that relate to the management of their social housing. Only tenants can make requests, unlike FOI where anyone can do so. Matters determined by local councils and information about property management that is not related to the social housing functions are not part of this obligation. 

Requests must be in writing. There will be a deadline of 30 calendar days to respond to a request for information, which may be extended in certain circumstances.  

PRPs cannot delete or alter information to prevent disclosure but the same exemptions set out in the FOI will apply under STAIRs. 

Review Process 

PRPs will also need to put in place a STAIRs review process to deal with any complaints related to either the publication scheme or information requests. Reviews will need to be completed within 30 calendar days. If the complainant is unhappy with the response they can they escalate this to the Housing Ombudsman. Responses to review requests should inform tenants of their right to access the Housing Ombudsman Scheme

Training 

PRPs need to prepare now for the new  STAIRs regime. They should ensure they have adequate policies and procedures in place including staff training.  

Please see our new STAIRS workshop with Naomi Mathews. We can also deliver this course on an in house basis customised to the needs of your staff (online or classroom). Get in touch for a quote.

Predictive Policing and the Think Family Database

Predictive Policing, or Predictive Analytics, is increasingly being promoted as a tool to help police forces prevent crime before it happens. Supporters argue that analysing vast amounts of data can help identify vulnerable people, allocate resources more effectively and enable earlier intervention. However, a recent investigation published by WIRED magazine raises important questions about whether these systems are accurate, transparent or fair enough to justify their growing use. 

WIRED, working in partnership with the nonprofit newsroom Liberty Investigates, plus the Bristol Cable and Lighthouse Reports, obtained hundreds of pages of documentation, using FOI requests, to build a comprehensive picture of a long-running partnership between Avon and Somerset Police and Bristol City Council to develop predictive policing and safeguarding tools. It reveals how the two organisations worked together to combine public sector data, develop machine-learning models and deploy risk-scoring systems intended to support policing and child protection.  

The Think Family Database 

One of these systems was the Think Family Database which was launched in 2016. According to WIRED, the database brought together information held by multiple public bodies, creating records covering almost half a million Bristol residents.
The council played a central role by contributing and managing information from housing, education, children’s services, social care and other local authority functions, while police intelligence and crime data were also incorporated. The intention was to provide practitioners across organisations with a more complete understanding of individuals and families who might require support, enabling earlier intervention and better coordination between agencies. 

Using this shared data, the two organisations developed numerous machine-learning models designed to predict a range of outcomes. These included identifying people considered at greater risk of offending, becoming victims of crime, going missing or failing to appear in court. Other models sought to identify children who might be vulnerable to criminal or sexual exploitation. 

On paper, these objectives reflected a broader ambition shared by many public sector organisations: using data more effectively to improve services and prevent harm before it occurs. Former project leaders interviewed by WIRED argued that combining information from different public bodies could provide frontline professionals with a richer understanding of vulnerability than any single agency could achieve alone. However, the investigation suggests that the practical reality proved far more challenging.  

Accuracy and Transparency  

One of the most significant findings reported by WIRED is that at least two of the predictive models were eventually withdrawn because staff no longer trusted their results. Bristol City Council commissioned independent evaluations of the programme, and council practitioners reportedly questioned whether some of the safeguarding models were accurately identifying the children they were intended to protect. According to the investigation, staff expressed concern that some vulnerable children were no longer appearing within the highest-risk groups, while other individuals received unexpectedly high risk scores. Internal reviews ultimately concluded that the models lacked sufficient reliability to support operational decision-making, leading to their withdrawal. 

The investigation also highlights wider concerns surrounding transparency and governance. Independent reviewers reportedly found that documentation explaining how some of the predictive models had been developed was incomplete or unavailable. In some, reviewers were unable to fully assess the systems because source code, technical documentation and records describing how models had been trained or validated could not be located. 

Predictive AI systems depend heavily on the information used to train them.
If historical datasets contain gaps, inaccuracies or existing biases, those weaknesses may also be reflected in the predictions generated by the models. 
Researchers interviewed by WIRED note that some variables used within the aforementioned systems could act as indirect indicators of poverty or wider social disadvantage. Factors such as housing support, school attendance or eligibility for free school meals may correlate with vulnerability, but they may also reflect structural inequalities rather than future criminal behaviour. This raises concerns that predictive systems could unintentionally reinforce existing patterns of disadvantage rather than objectively identifying risk. 

The investigation also reports that one external audit found many of the predictive models demonstrated relatively weak performance. According to WIRED, an independent AI auditing company concluded that several models produced a high number of false positives, meaning many individuals identified as high risk would never actually experience the outcomes the models were predicting. False positives are particularly significant within policing and safeguarding because they have the potential to influence professional judgement and the allocation of limited public resources. Even where algorithmic scores do not determine decisions directly, they may shape how practitioners prioritise cases or assess individuals. 

The investigation further explores issues surrounding public awareness and consent. Many residents reportedly had little knowledge that their information had been brought together within the Think Family Database. One campaigner only discovered that his information had been included within a police offender management system after pursuing legal action to obtain details of the records held about him.  

Interestingly, former project leaders interviewed by WIRED argued that frontline professionals often relied more heavily on their own experience than on the algorithmic predictions themselves. Social workers and other practitioners reportedly viewed the models as one source of information rather than definitive guidance.
While this may have reduced the practical impact of inaccurate predictions, it also raises legitimate questions about the value of developing complex predictive systems if experienced professionals ultimately lacked confidence in the results. 

Future Use 

The investigation also highlights Bristol City Council’s role in reviewing the future of the programme. The council has since stated that the current administration no longer uses predictive analytics for policing or safeguarding decisions, with the exception of analytical work aimed at identifying young people who may become Not in Education, Employment or Training (NEET) after leaving school. The council also maintained that predictive tools never replaced professional judgement and were intended only to support practitioners rather than automate decisions. 

Automated Racism 

In the next episode of the Guardians of Data Podcast (published on Wednesday we discuss predictive policing and its impact in detail. Our guest is Ilyas Nagdee who is the Racial Justice Director at Amnesty International UK and one of the authors of Amnesty’s report into predictive policing (“Automated Racism). Ilyas helps us unpack what the predictive policing tools actually are, how they’re being used, whether they work, and what the risks are, especially when combined with other technologies like facial recognition.  

Listen to a clip here. 

Follow the podcast to be the first to know when this episode is published on Wednesday.   

Also available on Apple Podcasts, Spotify, and all major podcast platforms.

ICO Publishes Edtech Report

Educational technology is now embedded in everyday school life, from classroom apps and learning platforms to safeguarding systems, behaviour tools and management information systems. While these technologies can support teaching, administration and pupil wellbeing, they also involve the collection and use of large amounts of children’s personal data, often in circumstances where pupils and parents have limited ability to opt out. From a data protection perspective schools and edtech providers must be clear about who is responsible for processing the data, why it is being used, how long it is kept, and whether the requirements of UK GDPR are being met in practice. 

Last week, the Information Commissioner’s Office (ICO) published ‘Edtech examined’, a report outlining how they “have worked directly with edtech providers to review and improve data protection practices within the sector.” The report details the findings from a programme of consensual audits carried out by the ICO during 2024 and 2025 with 28 edtech providers, whose products are widely used across primary and secondary schools in the UK. The audits examined a range of products including management information systems, safeguarding tools, behaviour management platforms, learning management systems, classroom apps, and data integration services.  

The ICO found positive practices, particularly around information security. 
However, they also identified and addressed compliance gaps across the sector. Common issues included providers not correctly identifying whether they were acting as data processors or controllers — particularly where children’s data was used for product development or analytics.   

The ICO also found: 

  • insufficiently detailed contracts with schools 
  • incomplete data flow mapping 
  • weak application of data minimisation and storage limitation principles  
  • outdated or inaccessible privacy information, and  
  • gaps in Data Protection Impact Assessments.  

The ICO says that, through the audits, it has successfully driven improvements across the sector, with providers accepting and putting in place 98% of the 596 recommendations that were made. It is now engaging with the Department for Education and devolved authorities on their work with schools to help improve how children’s personal information is handled in educational settings. It is also discussing introducing a new edtech code which could contribute to ensuring children’s data is better protected across the tools and platforms schools use widely. 

The Government’s Plans for Children’s Data 

Recent initiatives from the UK Government, such as the Schools White Paper and the Children’s Wellbeing and Schools Act 2026, have major implications for children’s privacy; from age verification to plans for a “Data Spine” to link information across the public sector.   

In Episode 8 of the Guardians of Data podcast, we analyse the Government’s plans for our children’s data, discuss children’s privacy in the internet age and the role Big Tech is playing in the collection storage and analysis of all our data.  We ask if the government is simply trying to do a better job of protecting children or if it is quietly building a surveillance system which will impact all of us. Listen here. 

See also our workshop: Working with Children’s Data.

How to Build and Deploy Responsible, Trustworthy, and Ethical AI Systems

AI can improve productivity, support better services and unlock social benefit at scale. However, if it is deployed without good governance, it can automate discrimination, intensify inequality, undermine privacy and damage public trust. 

In Episode 7 of the Guardians of Data podcast, AI expert Tahir Latif argued that ethical and responsible AI cannot remain a collection of impressive slogans. Principles such as fairness, transparency, accountability and safety only matter if organisations can translate them into practical governance, day-to-day 
decision-making and evidence of responsible deployment. This is an urgent challenge because AI is being adopted faster than many organisations are maturing.  

Defining the Use Case 

Tahir says that businesses and public bodies often see AI as a strategy in itself:
an answer to cost reduction, efficiency, competitive advantage or service improvement. But AI is not a strategy. It is a tool. The question is not simply “Can we deploy this?” but “Why are we deploying it, who may be affected, what could go wrong, and how will we know whether it is working fairly?” 

A responsible AI programme starts with a clearly defined use case. Organisations should resist the temptation to apply “AI everywhere for everything”. A use case should explain the problem being solved, the people affected, the intended benefits, the lawful basis for processing data, the decision points where AI will be used and the limits of the system. This matters because the ethical risk of AI depends heavily on context. A tool that recommends music is very different from one that influences access to housing, healthcare, benefits, policing or credit. 

Strong Information Governance  

The next foundation a responsible AI programme is data quality. AI systems inherit the strengths and weaknesses of the data on which they are trained, tested and deployed. If data is biased, incomplete, unlawfully sourced, poorly classified or disconnected from its original purpose, the organisation is not innovating on solid ground; it is scaling risk. Ethical AI therefore requires strong information governance: clear data provenance, lawful and fair processing, purpose limitation, data minimisation, retention controls, accuracy checks and ongoing monitoring for bias or drift. 

Governance should begin at the ideation stage, not after a model has been purchased, built or released. Organisations need an AI governance framework that identifies ownership, risk appetite, approval routes, documentation standards, testing requirements, escalation processes and independent review. The UK’s regulatory approach highlights five relevant principles: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. The OECD AI Principles similarly emphasise human-centred, trustworthy AI that respects human rights and democratic values. 

The Human in the Loop 

Governance cannot be a paper exercise. Tahir warns against organisations claiming to have “human in the loop” oversight when the human does not understand what they are reviewing or lacks authority to stop a problematic deployment. Responsible oversight requires trained and empowered people. They must understand the limits of AI outputs, be able to challenge results, know when to escalate concerns and have permission to say no where risks are disproportionate. 

This is particularly important because AI systems can be fluent, persuasive and wrong. A confident output is not the same as a reliable one. AI often produces plausible answers rather than verifiable truth. That creates a risk of misplaced reliance, especially where users assume that machine-generated outputs must be objective or authoritative. Organisations should therefore build in validation, sampling, audit trails, performance monitoring and clear thresholds for human review. 

Transparency and Explainability 

Tahir says that central to trustworthy AI is transparency and explainability. But these terms must be understood realistically. Transparency means being open about when and how AI is used, what data it relies on, what role it plays in decisions and what rights affected individuals have. Explainability is about providing a meaningful account of how a system reaches or supports an outcome. In low-risk settings, a simple explanation may be enough. In high-impact contexts, such as credit, employment, welfare or healthcare, people need understandable reasons, routes to challenge and access to human review. 

Tahir’s mortgage example makes the point. If an applicant with a strong credit history, stable income and low debt is refused by an AI-assisted system, “computer says no” is not acceptable. The organisation must be able to explain the relevant factors, identify whether the decision was fair and provide a meaningful mechanism for contesting it. The more opaque the model, the stronger the justification must be for using it, especially where simpler and more interpretable methods would achieve the purpose. 

Privacy and data protection also sit at the heart of responsible AI. The healthcare example discussed in the podcast shows both the opportunity and the caution required. AI can assist radiographers by reviewing large volumes of labelled X-ray images quickly and accurately, helping clinicians identify patterns that may be difficult for the human eye to detect. But the same sector also illustrates why governance matters: patients must be able to trust that sensitive data is used lawfully, securely and proportionately, and that AI supports rather than replaces accountable clinical judgment. 

Lifecycle Management 

Tahir emphasise that AI risk does not end at product launch. Models can degrade, data can change, users can misuse outputs and social impacts may emerge over time. Organisations should monitor performance, fairness, security, complaints, incidents, and unintended consequences. They should also be prepared to suspend, retrain, restrict or retire systems that no longer meet legal, ethical or operational standards. 

Respecting Rights 

Copyright and training data add another ethical dimension. AI systems depend on data, but innovation cannot simply override the rights of creators, authors, artists and performers. Organisations should ask whether training data has been lawfully obtained, whether rights holders have been respected, whether outputs may reproduce protected material and whether transparency is owed to users or creators. Ethical AI is not only about avoiding biased outputs; it is also about respecting the labour and rights embedded in the data ecosystem. 

IG Officer Skills 

For information governance professionals, the message is clear: AI governance is not a side issue. It is becoming a core professional responsibility. The most valuable skills will include judgment, translation, evidence and humility.  

Judgment means asking whether a system is proportionate, fair, defensible and wise. Translation means communicating risk across technical, legal, governance and executive audiences. Evidence means documenting decisions, testing, approvals, safeguards and monitoring. Humility means recognising that AI is developing quickly and that continuous learning is essential. 

Tahir says that ultimately, building responsible, trustworthy and ethical AI systems is not about choosing between innovation and regulation. It is about designing the conditions for AI to serve people well. That means clear use cases, good data, meaningful accountability, trained humans, transparent explanations, privacy by design, challenge mechanisms and ongoing assurance. AI may be powered by technology, but trust is built by people, governance and the choices organisations make before, during and after deployment. 

Listen to the full Episode 7 with Tahir Latif.

AI and Cyber Security 

In recent weeks, governments, regulators and cyber security professionals have been gripped by the emergence of Mythos, the powerful AI model developed by Anthropic. Touted as capable of identifying software vulnerabilities at a level that rivals some of the world’s most skilled human researchers, the model has generated excitement, concern and intense debate.   

Against this backdrop, our guest in Episode 11 of the podcast is an internationally renowned cybersecurity leader, educator and technology strategist, Caroline Wong

In this conversation, Caroline explains how cybercriminals are using AI to launch sophisticate cyber-attacks. We also discuss how organisations can use the same technology to strengthen their cyber defences. But this conversation goes beyond the technical. We discuss why trust is becoming the central battleground in cybersecurity, how deepfakes and AI-generated content are reshaping the way we verify information, and why human judgment remains critical despite rapid advances in automation. We also take a closer look at Mythos itself and what it means for the future of cybersecurity.    

Listen to Episode 11 with Caroline Wong 

New Podcast: The Impact of AI on Cybersecurity  

“Today, it’s actually very, very easy for attackers to take a piece of malware and effectively launch one hundred different versions all at once.” 

Caroline Wong, Author and Cybersecurity Expert 

Episode 11 of the Guardians of Data Podcast is out now. In this episode we discuss how AI is reshaping trust, identity, cybersecurity, and organisational accountability.  

In recent weeks, governments, regulators and cyber security professionals have been gripped by the emergence of Mythos, the powerful AI model developed by Anthropic. Touted as capable of identifying software vulnerabilities at a level that rivals some of the world’s most skilled human researchers, the model has generated excitement, concern and intense debate.   

Against this backdrop, our guest on this podcast is an internationally renowned cybersecurity leader, educator and technology strategist. Caroline Wong is Chief Strategy Officer at Axari and the author of The AI Cybersecurity Handbook.  

In this conversation, Caroline explains how cybercriminals are using AI to launch sophisticate cyber-attacks. We also discuss how organisations can use the same technology to strengthen their cyber defences.  

But this conversation goes beyond the technical. We discuss why trust is becoming the central battleground in cybersecurity, how deepfakes and AI-generated content are reshaping the way we verify information, and why human judgment remains critical despite rapid advances in automation. We also take a closer look at Mythos itself and what it means for the future of cybersecurity.  

Whether you’re a privacy practitioner, cybersecurity professional or simply interested in understanding how AI is transforming the digital world around us, this is a conversation packed with practical insights and thought-provoking ideas.   

Listen on your preferred platform via our podcast page, or download the episode directly.

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’t designed for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Tahir Latif talking about responsible AI deployment, Jen Persson, a privacy campaigner, explaining the privacy implications of the Government’s new plans for children’s data, Naomi Mathews and Ibrahim Hasan explaining the law on filming people in public for social media and Olu Odeniyi analysing recent cyber breaches and discussing the lessons learnt.