The government's Cyber Security Breaches Survey, published at the end of April, found that around a third of UK businesses are now using AI, adopting it, or actively considering it, and that only 24% of them have security practices in place to manage the risks1. Most of those businesses are using tools like ChatGPT, Copilot, or AI transcription software without any clear rule about what's acceptable to put into them.
Why this matters for small businesses specifically
The UK GDPR applies to any personal data you handle, including data you enter into AI tools2. If you type a client's name, email address, phone number, or any detail that could identify them into ChatGPT, you are technically processing that data and it should be covered by your privacy practices.
In practice, most AI providers (OpenAI, Microsoft, Google) have terms of service that cover this, and many offer settings that prevent your data being used for training. But knowing which setting to turn on, and having a basic rule about what to enter and what not to, is something every business using AI should have worked out by now.
AI Fit Session
Not sure where to start? Over 1 week and three 60-minute 1-to-1 sessions, we map your business, find the quick wins, and build a practical starting point specific to you.
AI Foundations
Eight weeks, one coaching session a week, seven recorded modules. By the end you'll have AI working across real areas of your business and a 90-day plan to keep building.
AI Growth
Already using AI but want to keep developing it? Each month we work on real tasks from your business together, refining what's in place and building what's next.
The practical steps
- Check your privacy policy. If it does not mention AI tools, add a line explaining that you use AI assistance for internal tasks and that client personal data is not entered into these tools.
- Turn off AI training on your tools. In ChatGPT, go to Settings then Data Controls and turn off 'Improve the model for everyone'3. This stops your inputs being used as training data, and it is available on the free tier as well as paid plans.
- Set a simple rule for your team. What can go in (general questions, drafting tasks, non-identifiable information) and what cannot (client names, addresses, financial details, health information).
What about the EU AI Act?
This is worth getting right, because the picture is more nuanced than the headlines suggested. The EU's Digital Omnibus deferred the Act's high-risk obligations to 2 December 20274 — but it left the transparency rules alone, and those became enforceable on 2 August 20265. So "it's all been delayed" is not quite right.
For a UK-only business, none of this applies directly — the EU Act binds you only if you sell into the EU or your AI output is used there. UK GDPR, however, applies now and always did. The steps above are sensible for GDPR regardless of what happens with the EU AI Act.
Is using ChatGPT with client data a GDPR breach?
It can be. Under UK GDPR, any personal data you enter into an AI tool, including client names, addresses, or identifying details, is subject to your data processing obligations. The ICO's guidance on AI and data protection sets out what that means in practice, including lawful basis, data minimisation, and when a Data Protection Impact Assessment is required. Most major AI providers have acceptable terms of service, but you should also have a simple internal rule about what can and cannot go into these tools.
How do I turn off ChatGPT training on my data?
In ChatGPT, go to Settings, then Data Controls, and turn off Improve the model for everyone. This prevents your inputs from being used as training data. The setting is available on all ChatGPT plans including the free tier.
What should a small business AI policy cover?
At minimum: what client or customer information can and cannot go into AI tools, which tools your business uses and for what purpose, and a review date. It does not need to be a formal document. One clear paragraph written down and shared with anyone else in your business is sufficient.
Does the EU AI Act apply to UK small businesses?
Not directly, unless you sell into the EU or your AI system's output is used there. UK GDPR already applies to how you handle data in AI tools regardless. Note also that only the Act's high-risk obligations were deferred to December 2027 — the transparency obligations became enforceable on 2 August 2026, so it is not accurate to say the whole Act has been delayed.
- Cyber security breaches survey 2025/2026 — GOV.UK
- Artificial intelligence — Information Commissioner's Office (ICO)
- Data Controls FAQ — OpenAI Help Center
- EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes — Gibson Dunn
- Not Delayed, Not Deferred: EU AI Act Transparency Obligations Are Now in Force — Goodwin