AI and Cybersecurity: Why Trust Is the New Battleground 

Artificial intelligence is reshaping cybersecurity. Recent examples of AI behaving in unexpected ways have added urgency to the debate about how these systems should be controlled and where responsibility lies. The first such case involved ChatGPT-maker OpenAI acknowledging that its model had hacked the Hugging Face website. Anthropic and Meta have also reported similar cases. 

In a recent episode of the Guardians of Data podcast, host Ibrahim Hasan spoke with Caroline Wong, cybersecurity expert and author of The AI Cybersecurity Handbook, about how AI is impacting cyber security; from accelerating attacks and strengthening defences to changing the skills cyber professionals need.  

Lowering the barrier for attackers 

AI is making sophisticated cyber hacking capability available to people with far less training. Tasks once requiring extensive manual effort can now be automated or guided by readily available tools. Caroline explained that someone with only “ten to one hundred hours” of experience may now conduct activities that previously demanded “a thousand or ten thousand hours” of expertise. 

Reconnaissance is a good example of this. Attackers can rapidly gather public information about an individual or organisation, including writing style, vocabulary, voice and professional relationships. A task that once took an hour may now take minutes. This brings privacy, data protection and cybersecurity closer together: organisations must consider what information is public, who can access it and how easily AI can turn scattered data into actionable intelligence. 

Social engineering becomes more convincing 

Social engineering targets human behaviour rather than a technical flaw. AI enables criminals to generate fluent, personalised messages in any language and adopt a credible persona; perhaps a senior executive, a worried relativeor a hurried delivery worker. Old advice about spotting poor grammar or suspicious graphics is no longer enough. Deepfake audio and video can imitate familiar people so convincingly that seeing or hearing is no longer believing. 

Modern scams exploit excitement, pressure and trust, and their quality makes occasional mistakes increasingly understandable. Caroline’s practical test for spotting deepfakes and scams is simple: Did I expect this message? Is it asking me to act, disclose information or transfer money? If anything feels unusual or urgent, verify the request through a separate channel. A call apparently from a relative, for example, should be checked by sending a message using trusted contact details; not by relying on the communication that triggered suspicion. As Caroline says, “You’ve got to pay attention to your nervous system, and you’ve got to learn how to pause.” 

Malware at machine speed 

AI is also changing malware. Traditional cyber defences often rely on signatures: recognisable technical characteristics used to identify and block malicious code.
But attackers can now create many variants quickly, including malware that changes inside a system. As Caroline puts it, “Rule-based detection can’t keep pace with
AI-generated novelty.” 

Defenders therefore need to focus increasingly on behaviour rather than appearance. The challenge is to identify what software is doing, such as unusual access or suspicious movement across a network, rather than relying on a fixed fingerprint that may disappear with the next iteration. 

AI gives defenders an advantage too 

The discussion with Caroline was not all doom and gloom. AI can help defenders not just attackers. It can accelerate repetitive security work, including third-party vendor risk assessments, customer due-diligence questionnaires and information gathering. Automating coordination and routine analysis can free security professionals to spend more time on judgement, governance and strategic risk management. 

However, Caroline cautioned against seeing AI as a product that can simply be purchased to make problems disappear. “AI is not a silver bullet,” she stressed. It remains error-prone, requires experimentation and does not remove the need for human communication or sound security basics. Budget disparities also remain: a small organisation cannot deploy the same resources as a multinational. Even AI usage itself carries ongoing token, operational and environmental costs that leaders must assess over time. 

The vulnerability-fixing gap 

The podcast also explored advanced AI systems capable of finding and exploiting software vulnerabilities far faster than humans. Caroline’s key concern is an emerging imbalance: discovery can be compressed from months or days into minutes, while remediation has not accelerated at the same rate. “We now have a significantly improved approach for finding vulnerabilities, but we don’t yet have an equally speedy approach for fixing vulnerabilities,” she warned. 

She was sceptical that banning powerful AI tools, such as Mythos, would provide a durable solution. Equivalent models are likely to emerge elsewhere and prohibition may concentrate access among a privileged few rather than eliminate the capability. The stronger response is therefore governance, controlled access, coordinated disclosure and investment in faster remediation. 

Trust, judgement and the future workforce 

Ultimately, trust is the new battleground. AI-generated voices, faces and “digital twins” complicate how people establish authenticity. Yet Caroline does not foresee cybersecurity becoming a fully automated discipline. Her five-year vision is a blended workplace in which humans communicate with both human and agentic AI colleagues. The crucial question will be where human oversight is required and at what level of abstraction. 

For professionals in cybersecurity, privacy and data protection, Caroline’s advice is to remain curious, learn quickly and gain hands-on experience with AI. Technical knowledge matters, but so do communication, judgement and the ability to work across organisational boundaries 

The enduring takeaway from this podcast is that AI will amplify capability, not abolish human responsibility. Organisations that combine useful automation with strong governance, verification and experienced judgement will be best placed to manage what comes next. As Caroline observed, “Judgment and opinion and experience are things that the machines cannot take away from us.” 

Listen to the full episode with Caroline Wong here.  

We have two workshops coming up (How to Increase Cyber Security in your Organisation and Cyber Security for DPOs) which are ideal for organisations who wish to upskill their employees about cyber security.

New Podcast: Handling AI Generated Information Requests

Many organisations are seeing a massive increase in AI generated Freedom of Information requests and GDPR Subject Access Requests (SARs). For example, Lincolnshire County Council received almost 2000 FOI requests in the last financial year; an increase of 18% compared to the previous year. No doubt the same is the case for SARs. 

AI has democratised and powered access to information. Large Language Models, like ChatGPT and Claude, can produce ‘perfectly written’ FOI requests and SARs at the touch of a button. But these are causing problems for over loaded information governance departments. Not only are more requests coming through; they are often longer, broader and difficult to interpret.  

In the latest episode of the Guardians of Data podcast we guide information governance practitioners to help them manage and lawfully respond to AI generated information requests. Our guest is Saara Idelbi from 39 Essex Chambers. Saara practises in administrative law, human rights, data protection and information rights. She is named by the Legal 500 as a ‘leading junior’ barrister. Saara is a recognised voice on AI and the law and is the co-founder of Advocatr, an AI legal training platform. 

Listen on your preferred platform via our podcast page, or download the episode directly, for practical guidance on how to handle AI generated information requests whilst respecting the key principles of information rights legislation: openness, transparency and accountability.  

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’tdesigned for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Caroline Wong talking about the impact of AI on Cybersecurity, Jen Persson, a privacy campaigner, explaining the privacy implications of the Government’s new plans for children’s data, and Ilyas Nagdee analysing the impact of predictive policing in human rights.

AI Agents: A New Frontier of Risk

For the past few years, legal, compliance and data protection professionals have largely focused on the risks associated with deploying large language models (LLMs) such as ChatGPT and Claude. The focus is now expanding to agentic AI, defined by IBM as: 

“…an artificial intelligence system that can accomplish a specific goal with limited supervision. It consists of AI agents – machine learning models that mimic human
decision-making to solve problems in real time.” 

The key difference between LLMs and agentic AI is autonomy. Traditional AI tools usually operate within a defined task and rely on people to decide what happens next. By contrast, agentic AI can adjust its actions as information changes, tools become available or the task develops. In this sense, “agentic” describes technology that can act purposefully, rather than merely produce a response. 

Let’s take a customer service scenario. An AI agent could receive a complaint, review the customer’s previous interactions in Salesforce, check delivery information in a logistics system, draft a response, create a follow-up case and route the issue to a human member of staff where judgement is needed. That is materially different from an AI chatbot that helps with basic tasks like write an email or answer queries. 

Many organisations are now deploying AI agents in areas such as sales and customer service, using tools offered by the likes of OpenAIGoogle and Salesforce. In the health sector, tools such as Oracle Health Clinical AI Agent help clinicians by supporting documentation and workflow automation within electronic health record systems. Anthropic’s “2026 State of AI Agents” report, says that 57% of the 500 U.S. companies surveyed were deploying agents for multi-stage workflows and 56% planned to deploy agents for research and reporting in 2026.

Cybersecurity Risks 

But the deployment of AI agents is not without risk. An AI agent may have the ability to act, rather than simply advise. Depending on the use case, it could connect to business applications, recommend or make decisions, trigger workflows, send messages, alter records or begin a financial process. These capabilities mean that there is much more that can go wrong compared with a traditional LLM, where the main risk is
over-reliance on an output that may not be accurate. 

One of the key risks associated with deploying AI agents is cyber security. An agentic system may be linked to internal systems, third-party services, customer information, APIs and external tools. Each connection creates potential exposure. If an agent has excessive permissions or is badly configured, an attacker may be able to influence its actions, redirect it towards an unintended outcome or gain access to sensitive commercial or personal information. 

Testing an AI agent before deployment is crucial. Just yesterday, OpenAI revealed that its AI agent went rogue and hacked a start-up after it lost control of it during a security test. The joint guidance Careful adoption of agentic AI services, co-authored by the NCSC and international partners, recommends that organisations start small, use agents initially for low-risk tasks and apply established cyber security controls from the outset. 

In practice, this means applying secure design, least privilege, access management, monitoring, incident response planning and supplier assurance. For a detailed discussion on the impact of AI on cybersecurity, listen to the Guardians of Data podcast with Caroline Wong. 

Data Protection Risks 

Data protection risk can also increase where an AI agent needs broad access to information to carry out its objective. It may pull together customer records, identify patterns, summarise communications, classify individuals, suggest next steps or trigger further action. Much of this will involve personal data and so the UK GDPR will come into play. 

The ICO has taken a keen interest in this area. In its Tech Futures report on agentic AI, it states: 

“One of our key findings from this initial work is that the specific design and architecture of agentic systems impact how data protection law applies and how people exercise their data protection rights. Choices such as the data and tools that a system can access and which governance and control measures to put in place really matter.” 

The ICO’s AI and data protection toolkit helps organisations assess how AI systems may affect individuals’ rights and freedoms. Key data protection risk questions for organisations deploying an AI agent include: 

  • What personal data does the agent need to perform the task? 
  • Can the same outcome be achieved using less data? 
  • Is the agent making or informing decisions about individuals? 
  • Are special category data, children’s data or vulnerable individuals involved? 
  • Can individuals understand when AI is being used and how to challenge decisions? 
  • Are prompts, outputs, logs and feedback data retained, and if so for how long? 
  • Have the controller/processor roles been properly analysed? 

Governance 

Any organisation adopting AI will need an AI governance policy. With agentic AI, however, governance must be more than a static document. It should be a working process that follows each proposed use case from initial idea through to deployment, monitoring and later review. 

Higher-risk use cases should be assessed before launch by legal, data protection, security, product and operational stakeholders. That assessment should cover the agent’s purpose, degree of autonomy, access to data and systems, impact on users, contractual arrangements, supplier terms, monitoring approach and exit plan. 

Good governance also depends on records. Organisations should keep evidence of risk assessments, testing, known limitations, approvals, training materials, monitoring outcomes, complaints, incidents, remedial steps and changes to prompts or workflows. That evidence may become important if a customer, regulator or court later asks what happened, when things go wrong. The organisation will need to show not only that it had a governance framework, but that the framework was followed in practice. 

AI agents bring exciting possibilities, but also many risks. They may also change the structure of organisations for good. Caroline Wong, an AI expert speaking on the  Guardians of Data podcast, predicts that the future workforce could be a mix of human and agentic AI “workers.” You can listen to a short clip here

Learn more about AI agents and their safe deployment on our forthcoming webinar. You can also hear more on building trustworthy and responsible AI systems with AI expert Tahir Latif in this podcast.

Schools Warned After Criminals Manipulate Children’s Photos from Websites

Many school websites and social media feeds contain photographs of students in a variety of settings; from participating in lessons or sports to performing on stage or enjoying educational visits. This practice is often justified on the basis that such images showcase achievement and attract prospective families. Some have even said to this author, “It looks good with Ofsted.” But the dangers of this practice have been highlighted recently by the Internet Watch Foundation (IWF) and the National Crime Agency (NCA).  

The IWF and NCA report an increase in criminals exploiting publicly available images of children to create realistic sexualised content using Artificial Intelligence. Analysts found 3,440 AI-generated videos of child sexual abuse in 2025, compared to just 13 in 2024. Most worryingly, IWF report that an unnamed UK secondary school was recently subjected to a blackmail attempt after criminals downloaded photos of children from the school’s website or social media accounts and then, using AI tools, turned them into child sexual abuse material. The criminals then demanded payment from the school to prevent the images from being shared online. 

The IWF and NCA are recommending that educational institutions remove identifiable pictures of children from their websites and social media accounts.  

AI Enabled Sextortion 

Blackmailing people over intimate images, also known as sextortion, has a become increasingly prevalent in recent years following the trend to share the most intimate details online. Children, especially young girls, are particularly vulnerable. Sometimes they face pressure from boys to show their “commitment” to a relationship by sharing intimate images.
The Children’s Charity, The NSPCC, and The Report Remove service, which allows children in the UK to confidentially report sexual images and videos of themselves and remove them from the internet, have recently reported a sharp rise in children being blackmailed over sexual images. There have also been cases of British teenagers who have killed themselves after receiving extortion threats

The advancement in Generative AI tools now mean that any image, no matter how innocent, can be sexualised. Readers may remember the controversy involving Grok; the AI companion built into X, Elon Musk’s social media platform.  It began in May 2025 when users prompted Grok to alter photos of real women into sexualised images. By late 2025 it had escalated dramatically; users simply replied to public photos with requests like “put her in a bikini,” and Grok posted the generated images directly to X, publicly and instantly. Estimates suggest it produced around 4.4 million images in nine days, with 41 to 65 per cent sexualised. Some of those images involved children. X has since made changes to Grok to prevent abuse. More recently Meta was forced to withdraw its new AI tool Muse Image, following a public backlash. It could generate new photos using other people’s social media profile photoswithout telling them.  

Data Protection  

Publishing photos of children is also a data protection issue and so needs to comply with the UK GDPR. Like all processing of personal data it needs to be, amongst other things, fair, lawful and transparent. Data subjects, including children, have rights including the right to object and receive a copy of their data, including images, and ask for them to be deleted (subject to some exceptions).  

The Information Commissioner’s Office guidance about photos in schools emphasises the importance of complying with the UK GDPR but needs an update to cover the dangers of AI. Most schools will have a privacy policy and a procedure for collecting consent from parents before publishing images of their children. However research by Northumbria University, and published by Defend Digital Me, a children’s rights campaign group, states that only 7% of education authorities who disclosed their schools image guidance (following FOI requests) mentioned that posting photographs on social media may pose a risk to children’s privacy. The research authors suggest that parents are therefore being asked to provide consent to photographs being shared online without being told of the risks that this may pose. 

Raising Awareness 

There is a clear need here to educate parents, children and schools about the dangers (as well as the legal issues) posed by AI when it comes to public images of children. 

The Internet Watch Foundation and the National Crime Agency have produced a new guide for parents and carers which recommends amongst other things, reviewing privacy settings on apps, talking to their children, and knowing what to do if something goes wrong. This follows similar advice they issued to education professionals last year, on how to protect student images from AI manipulation. 

In the Guardians of Data podcasts we delve deeper into the issues raised here:  

  • In Episode 2 we explore the Grok AI controversy. 
  • In Episode 6  we discuss the legal, ethical and societal issues around taking photographs in public for social media.  
  • In Episode 8 we analyse the Government’s plans for our children’s data, discuss children’s privacy in the internet age and the role Big Tech is playing in the collection storage and analysis of all our data.  

Our GDPR Essentials E Learning course is ideal for school staff and education professionals who require foundational knowledge about GDPR compliance and the key risk areas. Click here to watch a preview.

See also our workshop: Working with Children’s Data

New Podcast: The Hidden Algorithms Behind Modern Policing

“There’s a significant lack of transparency around police use of predictive policing systems in the UK. Most people don’t even know about their use in policing… People don’t know, if they are ever stopped and searched by police, it’s as a result of a predictive profiling or risk assessment system… So there is a significant lack of transparency, which is particularly worrying given the lack of regulation.” 

Ilyas Nagdee, Amnesty International 

Episode 12 of the Guardians of Data Podcast is out now. In this episode we discuss something that sounds like science fiction, but is already part of everyday policing in the UK; predictive policing. These are tools that use data and algorithms to help the police forecast crime, where it might happen and sometimes who might be involved. The idea is to use resources efficiently and cut crime. 

But a recent report by Amnesty International, (“Automated Racism”) argues that predictive policing tools aren’t neutral; they may be reinforcing and scaling existing inequalities. The report argues that the data they use is biased, particularly against black and racialised communities in deprived areas.  

In this conversation, we unpack what these tools actually are, how they’re being used, whether they work, and what the risks are, especially when combined with other technologies like facial recognition. 

Our guest is Ilyas Nagdee who is a human rights campaigner and the Racial Justice Director at Amnesty International UK. He has also written for The Guardian and is the co-author of a book entitled, Race to the Bottom: Reclaiming Antiracism, a critical study of anti-racist politics in the UK. 

Listen on your preferred platform via our podcast page, or download the episode directly.

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’t designed for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Caroline Wong discussing the impact of AI on cyber security, Emma Martins explaining the importance of data protection legislation, Tahir Latif talking about responsible AI deployment and Jen Persson explaining the privacy implications of the Government’s new plans for children’s data. 

Predictive Policing and the Think Family Database

Predictive Policing, or Predictive Analytics, is increasingly being promoted as a tool to help police forces prevent crime before it happens. Supporters argue that analysing vast amounts of data can help identify vulnerable people, allocate resources more effectively and enable earlier intervention. However, a recent investigation published by WIRED magazine raises important questions about whether these systems are accurate, transparent or fair enough to justify their growing use. 

WIRED, working in partnership with the nonprofit newsroom Liberty Investigates, plus the Bristol Cable and Lighthouse Reports, obtained hundreds of pages of documentation, using FOI requests, to build a comprehensive picture of a long-running partnership between Avon and Somerset Police and Bristol City Council to develop predictive policing and safeguarding tools. It reveals how the two organisations worked together to combine public sector data, develop machine-learning models and deploy risk-scoring systems intended to support policing and child protection.  

The Think Family Database 

One of these systems was the Think Family Database which was launched in 2016. According to WIRED, the database brought together information held by multiple public bodies, creating records covering almost half a million Bristol residents.
The council played a central role by contributing and managing information from housing, education, children’s services, social care and other local authority functions, while police intelligence and crime data were also incorporated. The intention was to provide practitioners across organisations with a more complete understanding of individuals and families who might require support, enabling earlier intervention and better coordination between agencies. 

Using this shared data, the two organisations developed numerous machine-learning models designed to predict a range of outcomes. These included identifying people considered at greater risk of offending, becoming victims of crime, going missing or failing to appear in court. Other models sought to identify children who might be vulnerable to criminal or sexual exploitation. 

On paper, these objectives reflected a broader ambition shared by many public sector organisations: using data more effectively to improve services and prevent harm before it occurs. Former project leaders interviewed by WIRED argued that combining information from different public bodies could provide frontline professionals with a richer understanding of vulnerability than any single agency could achieve alone. However, the investigation suggests that the practical reality proved far more challenging.  

Accuracy and Transparency  

One of the most significant findings reported by WIRED is that at least two of the predictive models were eventually withdrawn because staff no longer trusted their results. Bristol City Council commissioned independent evaluations of the programme, and council practitioners reportedly questioned whether some of the safeguarding models were accurately identifying the children they were intended to protect. According to the investigation, staff expressed concern that some vulnerable children were no longer appearing within the highest-risk groups, while other individuals received unexpectedly high risk scores. Internal reviews ultimately concluded that the models lacked sufficient reliability to support operational decision-making, leading to their withdrawal. 

The investigation also highlights wider concerns surrounding transparency and governance. Independent reviewers reportedly found that documentation explaining how some of the predictive models had been developed was incomplete or unavailable. In some, reviewers were unable to fully assess the systems because source code, technical documentation and records describing how models had been trained or validated could not be located. 

Predictive AI systems depend heavily on the information used to train them.
If historical datasets contain gaps, inaccuracies or existing biases, those weaknesses may also be reflected in the predictions generated by the models. 
Researchers interviewed by WIRED note that some variables used within the aforementioned systems could act as indirect indicators of poverty or wider social disadvantage. Factors such as housing support, school attendance or eligibility for free school meals may correlate with vulnerability, but they may also reflect structural inequalities rather than future criminal behaviour. This raises concerns that predictive systems could unintentionally reinforce existing patterns of disadvantage rather than objectively identifying risk. 

The investigation also reports that one external audit found many of the predictive models demonstrated relatively weak performance. According to WIRED, an independent AI auditing company concluded that several models produced a high number of false positives, meaning many individuals identified as high risk would never actually experience the outcomes the models were predicting. False positives are particularly significant within policing and safeguarding because they have the potential to influence professional judgement and the allocation of limited public resources. Even where algorithmic scores do not determine decisions directly, they may shape how practitioners prioritise cases or assess individuals. 

The investigation further explores issues surrounding public awareness and consent. Many residents reportedly had little knowledge that their information had been brought together within the Think Family Database. One campaigner only discovered that his information had been included within a police offender management system after pursuing legal action to obtain details of the records held about him.  

Interestingly, former project leaders interviewed by WIRED argued that frontline professionals often relied more heavily on their own experience than on the algorithmic predictions themselves. Social workers and other practitioners reportedly viewed the models as one source of information rather than definitive guidance.
While this may have reduced the practical impact of inaccurate predictions, it also raises legitimate questions about the value of developing complex predictive systems if experienced professionals ultimately lacked confidence in the results. 

Future Use 

The investigation also highlights Bristol City Council’s role in reviewing the future of the programme. The council has since stated that the current administration no longer uses predictive analytics for policing or safeguarding decisions, with the exception of analytical work aimed at identifying young people who may become Not in Education, Employment or Training (NEET) after leaving school. The council also maintained that predictive tools never replaced professional judgement and were intended only to support practitioners rather than automate decisions. 

Automated Racism 

In the next episode of the Guardians of Data Podcast (published on Wednesday we discuss predictive policing and its impact in detail. Our guest is Ilyas Nagdee who is the Racial Justice Director at Amnesty International UK and one of the authors of Amnesty’s report into predictive policing (“Automated Racism). Ilyas helps us unpack what the predictive policing tools actually are, how they’re being used, whether they work, and what the risks are, especially when combined with other technologies like facial recognition.  

Listen to a clip here. 

Follow the podcast to be the first to know when this episode is published on Wednesday.   

Also available on Apple Podcasts, Spotify, and all major podcast platforms.

How to Build and Deploy Responsible, Trustworthy, and Ethical AI Systems

AI can improve productivity, support better services and unlock social benefit at scale. However, if it is deployed without good governance, it can automate discrimination, intensify inequality, undermine privacy and damage public trust. 

In Episode 7 of the Guardians of Data podcast, AI expert Tahir Latif argued that ethical and responsible AI cannot remain a collection of impressive slogans. Principles such as fairness, transparency, accountability and safety only matter if organisations can translate them into practical governance, day-to-day 
decision-making and evidence of responsible deployment. This is an urgent challenge because AI is being adopted faster than many organisations are maturing.  

Defining the Use Case 

Tahir says that businesses and public bodies often see AI as a strategy in itself:
an answer to cost reduction, efficiency, competitive advantage or service improvement. But AI is not a strategy. It is a tool. The question is not simply “Can we deploy this?” but “Why are we deploying it, who may be affected, what could go wrong, and how will we know whether it is working fairly?” 

A responsible AI programme starts with a clearly defined use case. Organisations should resist the temptation to apply “AI everywhere for everything”. A use case should explain the problem being solved, the people affected, the intended benefits, the lawful basis for processing data, the decision points where AI will be used and the limits of the system. This matters because the ethical risk of AI depends heavily on context. A tool that recommends music is very different from one that influences access to housing, healthcare, benefits, policing or credit. 

Strong Information Governance  

The next foundation a responsible AI programme is data quality. AI systems inherit the strengths and weaknesses of the data on which they are trained, tested and deployed. If data is biased, incomplete, unlawfully sourced, poorly classified or disconnected from its original purpose, the organisation is not innovating on solid ground; it is scaling risk. Ethical AI therefore requires strong information governance: clear data provenance, lawful and fair processing, purpose limitation, data minimisation, retention controls, accuracy checks and ongoing monitoring for bias or drift. 

Governance should begin at the ideation stage, not after a model has been purchased, built or released. Organisations need an AI governance framework that identifies ownership, risk appetite, approval routes, documentation standards, testing requirements, escalation processes and independent review. The UK’s regulatory approach highlights five relevant principles: safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. The OECD AI Principles similarly emphasise human-centred, trustworthy AI that respects human rights and democratic values. 

The Human in the Loop 

Governance cannot be a paper exercise. Tahir warns against organisations claiming to have “human in the loop” oversight when the human does not understand what they are reviewing or lacks authority to stop a problematic deployment. Responsible oversight requires trained and empowered people. They must understand the limits of AI outputs, be able to challenge results, know when to escalate concerns and have permission to say no where risks are disproportionate. 

This is particularly important because AI systems can be fluent, persuasive and wrong. A confident output is not the same as a reliable one. AI often produces plausible answers rather than verifiable truth. That creates a risk of misplaced reliance, especially where users assume that machine-generated outputs must be objective or authoritative. Organisations should therefore build in validation, sampling, audit trails, performance monitoring and clear thresholds for human review. 

Transparency and Explainability 

Tahir says that central to trustworthy AI is transparency and explainability. But these terms must be understood realistically. Transparency means being open about when and how AI is used, what data it relies on, what role it plays in decisions and what rights affected individuals have. Explainability is about providing a meaningful account of how a system reaches or supports an outcome. In low-risk settings, a simple explanation may be enough. In high-impact contexts, such as credit, employment, welfare or healthcare, people need understandable reasons, routes to challenge and access to human review. 

Tahir’s mortgage example makes the point. If an applicant with a strong credit history, stable income and low debt is refused by an AI-assisted system, “computer says no” is not acceptable. The organisation must be able to explain the relevant factors, identify whether the decision was fair and provide a meaningful mechanism for contesting it. The more opaque the model, the stronger the justification must be for using it, especially where simpler and more interpretable methods would achieve the purpose. 

Privacy and data protection also sit at the heart of responsible AI. The healthcare example discussed in the podcast shows both the opportunity and the caution required. AI can assist radiographers by reviewing large volumes of labelled X-ray images quickly and accurately, helping clinicians identify patterns that may be difficult for the human eye to detect. But the same sector also illustrates why governance matters: patients must be able to trust that sensitive data is used lawfully, securely and proportionately, and that AI supports rather than replaces accountable clinical judgment. 

Lifecycle Management 

Tahir emphasise that AI risk does not end at product launch. Models can degrade, data can change, users can misuse outputs and social impacts may emerge over time. Organisations should monitor performance, fairness, security, complaints, incidents, and unintended consequences. They should also be prepared to suspend, retrain, restrict or retire systems that no longer meet legal, ethical or operational standards. 

Respecting Rights 

Copyright and training data add another ethical dimension. AI systems depend on data, but innovation cannot simply override the rights of creators, authors, artists and performers. Organisations should ask whether training data has been lawfully obtained, whether rights holders have been respected, whether outputs may reproduce protected material and whether transparency is owed to users or creators. Ethical AI is not only about avoiding biased outputs; it is also about respecting the labour and rights embedded in the data ecosystem. 

IG Officer Skills 

For information governance professionals, the message is clear: AI governance is not a side issue. It is becoming a core professional responsibility. The most valuable skills will include judgment, translation, evidence and humility.  

Judgment means asking whether a system is proportionate, fair, defensible and wise. Translation means communicating risk across technical, legal, governance and executive audiences. Evidence means documenting decisions, testing, approvals, safeguards and monitoring. Humility means recognising that AI is developing quickly and that continuous learning is essential. 

Tahir says that ultimately, building responsible, trustworthy and ethical AI systems is not about choosing between innovation and regulation. It is about designing the conditions for AI to serve people well. That means clear use cases, good data, meaningful accountability, trained humans, transparent explanations, privacy by design, challenge mechanisms and ongoing assurance. AI may be powered by technology, but trust is built by people, governance and the choices organisations make before, during and after deployment. 

Listen to the full Episode 7 with Tahir Latif.

AI and Cyber Security 

In recent weeks, governments, regulators and cyber security professionals have been gripped by the emergence of Mythos, the powerful AI model developed by Anthropic. Touted as capable of identifying software vulnerabilities at a level that rivals some of the world’s most skilled human researchers, the model has generated excitement, concern and intense debate.   

Against this backdrop, our guest in Episode 11 of the podcast is an internationally renowned cybersecurity leader, educator and technology strategist, Caroline Wong

In this conversation, Caroline explains how cybercriminals are using AI to launch sophisticate cyber-attacks. We also discuss how organisations can use the same technology to strengthen their cyber defences. But this conversation goes beyond the technical. We discuss why trust is becoming the central battleground in cybersecurity, how deepfakes and AI-generated content are reshaping the way we verify information, and why human judgment remains critical despite rapid advances in automation. We also take a closer look at Mythos itself and what it means for the future of cybersecurity.    

Listen to Episode 11 with Caroline Wong 

New Podcast: The Impact of AI on Cybersecurity  

“Today, it’s actually very, very easy for attackers to take a piece of malware and effectively launch one hundred different versions all at once.” 

Caroline Wong, Author and Cybersecurity Expert 

Episode 11 of the Guardians of Data Podcast is out now. In this episode we discuss how AI is reshaping trust, identity, cybersecurity, and organisational accountability.  

In recent weeks, governments, regulators and cyber security professionals have been gripped by the emergence of Mythos, the powerful AI model developed by Anthropic. Touted as capable of identifying software vulnerabilities at a level that rivals some of the world’s most skilled human researchers, the model has generated excitement, concern and intense debate.   

Against this backdrop, our guest on this podcast is an internationally renowned cybersecurity leader, educator and technology strategist. Caroline Wong is Chief Strategy Officer at Axari and the author of The AI Cybersecurity Handbook.  

In this conversation, Caroline explains how cybercriminals are using AI to launch sophisticate cyber-attacks. We also discuss how organisations can use the same technology to strengthen their cyber defences.  

But this conversation goes beyond the technical. We discuss why trust is becoming the central battleground in cybersecurity, how deepfakes and AI-generated content are reshaping the way we verify information, and why human judgment remains critical despite rapid advances in automation. We also take a closer look at Mythos itself and what it means for the future of cybersecurity.  

Whether you’re a privacy practitioner, cybersecurity professional or simply interested in understanding how AI is transforming the digital world around us, this is a conversation packed with practical insights and thought-provoking ideas.   

Listen on your preferred platform via our podcast page, or download the episode directly.

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’t designed for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Tahir Latif talking about responsible AI deployment, Jen Persson, a privacy campaigner, explaining the privacy implications of the Government’s new plans for children’s data, Naomi Mathews and Ibrahim Hasan explaining the law on filming people in public for social media and Olu Odeniyi analysing recent cyber breaches and discussing the lessons learnt.

Filming Strangers in Public for Social Media: Are UK Privacy Laws Keeping Pace? 

The growth of social media platforms such as YouTube, TikTok, Instagram and Snapchat has fundamentally changed the way people are photographed and filmed in public. What was once the preserve of professional photographers, journalists and documentary makers has become an everyday activity undertaken by millions of smartphone users. Increasingly, concerns are being raised about people filming strangers without consent and uploading those videos online for entertainment, influence and profit. 

In Episode 6 of the Guardians of Data podcast Ibrahim Hasan spoke with Naomi Mathews  about the legal, ethical and societal issues arising from this trend. The conversation highlighted a difficult reality: while many people feel uncomfortable about being filmed and uploaded to social media without their consent, there is no single law in the UK that directly prohibits such conduct. Instead, individuals (and content creators) must navigate a complex legal framework involving human rights law, data protection, criminal law and platform policies. 

The following is a summary of the podcast:

From the 1970s to TikTok: How Society Has Changed 

For those who grew up in the 1970s and 1980s, photography was a relatively deliberate activity. Cameras were expensive, photographs were limited and normally only shared with family and friends. If a photograph appeared in a newspaper, it would usually have been taken by a professional photographer or journalist. 

Today, nearly everyone carries a high-definition camera in their pocket. Videos can be recorded instantly and uploaded to a global audience within seconds. Social media platforms reward engagement, views and shares, creating powerful incentives for content creators to film members of the public, often without their knowledge. 

The emergence of so-called “street content”, “prank videos” and “nightlife content” has intensified concerns about privacy, dignity and consent. Individuals who have done nothing more than walk down a street, visit a restaurant or enjoy a night out can find themselves the subject of viral videos viewed by millions. 

Do People Have a Right to Privacy in Public? 

One of the most common misconceptions is that people have no privacy rights once they enter a public place; but the law is more nuanced than that. 

Article 8 of the European Convention on Human Rights, incorporated into UK law through the Human Rights Act 1998, protects the right to respect for private and family life. Although public spaces are generally considered less private than homes, the courts have repeatedly recognised that privacy rights can still exist in public settings. 

The leading case is Campbell v MGN Ltd [2004], involving the model Naomi Campbell. She was photographed in a public street while leaving a Narcotics Anonymous meeting. Despite being in a public place, the House of Lords held that she had a reasonable expectation of privacy regarding the sensitive information revealed by the photographs. Similarly, in Murray v Express Newspapers plc [2008], J.K. Rowling successfully argued that photographs of her young child taken in a public street engaged privacy rights. These cases confirmed that privacy is not solely determined by location but also by context. 

Through these cases and others, the courts have developed the tort of misuse of private information, allowing individuals to bring civil claims where private information has been disclosed without justification. However, each case requires a careful balancing exercise between privacy rights under Article 8 and freedom of expression under Article 10. 

Data Protection Law 

Many people are surprised to learn that filming an identifiable individual may engage the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Images and videos of identifiable people constitute personal data. Recording, storing, uploading and sharing such footage can amount to the processing of personal data. Where the UK GDPR applies, those carrying out the processing must have a lawful basis, comply with the data protection principles and respect individuals’ rights. 

However, the law contains important exemptions. The domestic purposes exemption means that filming for purely personal or household activities is generally outside the scope of the UK GDPR. The difficulty lies in determining where personal activity ends and commercial activity starts. A video shared with close family members is very different from content uploaded to a monetised YouTube channel with hundreds of thousands of subscribers. Once filming moves beyond personal use, data protection obligations will arise. 

The law also provides a journalism exemption. This exemption can apply not only to traditional media organisations but also to bloggers, citizen journalists and some social media creators, provided the material is published for journalistic purposes and in the public interest. However, the exemption is not unlimited and must be assessed on a case-by-case basis. 

The Manchester Nightlife Videos 

The legal and ethical tensions surrounding public filming became particularly visible following widespread media coverage of the “Manchester nightlife” videos

These videos involved women being filmed during nights out in Manchester city centre, with the footage subsequently uploaded to social media platforms where it attracted substantial audiences. Critics argued that the content objectified women, encouraged online harassment and generated profit from individuals who had never consented to being filmed. 

The controversy prompted police investigations and widespread public debate about whether existing laws adequately protect people from becoming unwilling participants in online content. 

Greater Manchester Police initially arrested an individual on suspicion of stalking and harassment. However, the investigation was later discontinued, with the police citing limitations within the current legislative framework. The outcome highlighted the gap between conduct that many regard as morally objectionable and conduct that is clearly unlawful. 

Criminal Law: Significant Gaps Remain 

While some forms of filming can constitute criminal offences, the criminal law remains limited in scope. The Protection from Harassment Act 1997 can apply where there is a course of conduct that causes alarm or distress. However, a single act of filming is unlikely to satisfy this threshold. 

Similarly, offences under the Sexual Offences Act 2003, including voyeurism, generally require specific elements to be proved. Historically, these provisions have been criticised for failing to keep pace with modern technology. 

Recent reforms have expanded protections against the sharing of intimate images without consent and introduced new offences targeting image-based abuse. Nevertheless, many forms of public filming remain outside the reach of criminal law. 

The challenge for lawmakers is identifying where legitimate filming ends and harmful conduct begins. Few would support criminalising all photography in public places. Equally, many people are uncomfortable with a world in which anyone can be filmed, uploaded and monetised without their knowledge.  

What Can Victims Do? 

Individuals who find themselves featured in unwanted online content have several options available. 

They can complain directly to the platform hosting the content and request removal. They may also raise complaints with the Information Commissioner’s Office where data protection concerns arise. 

In some cases, civil claims for misuse of private information or breaches of data protection law may be available. However, these remedies are often costly and time-consuming. Legal aid is generally unavailable, meaning individuals must fund litigation themselves. 

Law Reform 

The discussion ultimately highlighted a broader concern: the law has struggled to keep pace with technological change. This is particularly where women and girls are targeted. See for example, the Grok AI controversy and its impact on equality for women and girls. (This is covered in Episode 2of the Guardians of Data podcast.) 

Whether a new law is needed remains controversial. Any reform would need to balance two fundamental rights: freedom of expression and the right to privacy. Neither automatically overrides the other. 

Listen to the full Episode 6 with Naomi. 

Previous episodes of the Guardians of Data podcast have featured Jen Persson, a privacy campaigner, explaining the privacy implications of the Government’s new plans for children’s data and Tahir Latif discussing how to build responsible and ethical AI systems.  

New Podcast: Beyond GDPR – The Real Purpose of Data Protection 

“Think clarity of purpose. Find your why. Find the reason that you’re doing what you do. It just puts fire in my belly every day knowing that I have such a clarity of purpose.” 

Emma Martins, Former Data Protection Commissioner for Guernsey 

Episode 10 of the Guardians of Data Podcast is out now. It is a fascinating and deeply human conversation with one of the most thoughtful voices in the world of privacy and information governance.  

Emma Martins served as Data Protection Commissioner for the Bailiwick of Guernsey for over a decade. In our conversation, Emma reminds us that data protection is about far more than compliance checklists, privacy notices, or subject access requests.
At its core, data protection is about people, power, democracy and human dignity. 

We explore the historical roots of data protection law, including the lessons Europe learned from surveillance and authoritarianism after World War Two, and why those lessons matter now more than ever in the age of AI, predictive policing, algorithmic bias, and mass data collection. 

Emma also shares her reflections on: 

  • The need for data protection professionals need to reconnect with their “why” 
  • The importance of diversity, curiosity, and collaboration in the IG profession 
  • And how we can all move from being seen as blockers to becoming trusted cultural leaders inside our organisations 

This is not a conversation about technology or the minutiae of data protection law; it’s a conversation about humanity and why we are here as data protection professionals.  

Listen on your preferred platform via our podcast page, or download the episode directly.

Emma also shared her recommended books and films/dramas about privacy, AI and data protection. You can find these in the episode show notes.

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’t designed for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Tahir Latif talking about responsible AI deployment, Jen Persson, a privacy campaigner, explaining the privacy implications of the Government’s new plans for children’s data, Naomi Mathews and Ibrahim Hasan explaining the law on filming people in public for social media and Olu Odeniyi analysing recent cyber breaches and discussing the lessons learnt.