🤖

This article is AI-generated, it is researched, drafted and then edited by AI. We're open about this, it's part of how we demonstrate what's possible with AI.

Matters now May 2026 · 4 min read

Most UK small businesses have no rules about AI and client data. Here's how to fix it.

Only a quarter of UK businesses using or considering AI have security practices in place to manage the risks. For small business owners, the fix is simpler than it sounds.

N
Written by Nous · Edited by Greg Shaw
Nous is Greg's AI writing assistant, named after the Greek concept of mind and reason. Every article written by Nous is reviewed before publication.

While every effort is made to ensure accuracy, AI-generated content may contain errors or omissions and is provided for general information only, not professional, legal, or financial advice. Opinions expressed are those of our AI personas using skills created for the very purpose of researching, drafting and writing articles on AI for small businesses. Just AI Talking accepts no liability for any loss arising from reliance on content published on this site.

The takeaway

Write one simple rule for your business about what customer or client information can and cannot go into AI tools. Write it down, share it with anyone else in your business, and review it once a year. That is enough to be responsible and significantly more than most small businesses are currently doing.

The government's Cyber Security Breaches Survey, published at the end of April, found that around a third of UK businesses are now using AI, adopting it, or actively considering it, and that only 24% of them have security practices in place to manage the risks1. Most of those businesses are using tools like ChatGPT, Copilot, or AI transcription software without any clear rule about what's acceptable to put into them.

Why this matters for small businesses specifically

The UK GDPR applies to any personal data you handle, including data you enter into AI tools2. If you type a client's name, email address, phone number, or any detail that could identify them into ChatGPT, you are technically processing that data and it should be covered by your privacy practices.

In practice, most AI providers (OpenAI, Microsoft, Google) have terms of service that cover this, and many offer settings that prevent your data being used for training. But knowing which setting to turn on, and having a basic rule about what to enter and what not to, is something every business using AI should have worked out by now.

One-off session

AI Fit Session

Not sure where to start? Over 1 week and three 60-minute 1-to-1 sessions, we map your business, find the quick wins, and build a practical starting point specific to you.

Eight-week programme

AI Foundations

Eight weeks, one coaching session a week, seven recorded modules. By the end you'll have AI working across real areas of your business and a 90-day plan to keep building.

Monthly coaching

AI Growth

Already using AI but want to keep developing it? Each month we work on real tasks from your business together, refining what's in place and building what's next.

The practical steps

  • Check your privacy policy. If it does not mention AI tools, add a line explaining that you use AI assistance for internal tasks and that client personal data is not entered into these tools.
  • Turn off AI training on your tools. In ChatGPT, go to Settings then Data Controls and turn off 'Improve the model for everyone'3. This stops your inputs being used as training data, and it is available on the free tier as well as paid plans.
  • Set a simple rule for your team. What can go in (general questions, drafting tasks, non-identifiable information) and what cannot (client names, addresses, financial details, health information).

What about the EU AI Act?

This is worth getting right, because the picture is more nuanced than the headlines suggested. The EU's Digital Omnibus deferred the Act's high-risk obligations to 2 December 20274 — but it left the transparency rules alone, and those became enforceable on 2 August 20265. So "it's all been delayed" is not quite right.

For a UK-only business, none of this applies directly — the EU Act binds you only if you sell into the EU or your AI output is used there. UK GDPR, however, applies now and always did. The steps above are sensible for GDPR regardless of what happens with the EU AI Act.

Frequently asked questions
Is using ChatGPT with client data a GDPR breach?

It can be. Under UK GDPR, any personal data you enter into an AI tool, including client names, addresses, or identifying details, is subject to your data processing obligations. The ICO's guidance on AI and data protection sets out what that means in practice, including lawful basis, data minimisation, and when a Data Protection Impact Assessment is required. Most major AI providers have acceptable terms of service, but you should also have a simple internal rule about what can and cannot go into these tools.

How do I turn off ChatGPT training on my data?

In ChatGPT, go to Settings, then Data Controls, and turn off Improve the model for everyone. This prevents your inputs from being used as training data. The setting is available on all ChatGPT plans including the free tier.

What should a small business AI policy cover?

At minimum: what client or customer information can and cannot go into AI tools, which tools your business uses and for what purpose, and a review date. It does not need to be a formal document. One clear paragraph written down and shared with anyone else in your business is sufficient.

Does the EU AI Act apply to UK small businesses?

Not directly, unless you sell into the EU or your AI system's output is used there. UK GDPR already applies to how you handle data in AI tools regardless. Note also that only the Act's high-risk obligations were deferred to December 2027 — the transparency obligations became enforceable on 2 August 2026, so it is not accurate to say the whole Act has been delayed.

Book a call → ← Back to May 2026