Quick answer: If your team is pasting customer names, emails, or contract details into ChatGPT or similar AI tools without a data processing agreement in place, you may already be breaching UK GDPR or EU data protection law. Two regulatory shifts landed in 2026: the UK Data (Use and Access) Act 2025 (in force since 5 February 2026, the biggest rewrite of UK privacy law since GDPR in 2018) and the EU AI Act's enforcement phase beginning 2 August 2026. The practical fix is not to ban AI — it is to decide what data your staff may send to AI tools, document that decision, and put a simple policy in place. Most small businesses can close the biggest gaps in under a day.
What is AI data security?
AI data security is the set of practices that protect personal and business data when it is processed by AI systems — covering where data goes, who can access it, whether the AI provider can use it for training, and what happens if a breach occurs.
For a small business, this usually means three things: knowing which AI tools your staff use, knowing what data those tools receive, and ensuring you have a lawful basis for sending personal data to a third-party AI provider. The ICO's guidance on AI and data protection is clear: organisations remain responsible for how personal data is handled, regardless of whether an AI tool processes it on their behalf.
Why does this matter now? Two 2026 rule changes
The UK Data (Use and Access) Act 2025
On 5 February 2026, the Data (Use and Access) Act 2025 came into force — the most significant rewrite of UK privacy law since GDPR landed in 2018. Several changes affect small businesses directly:
| Change | What it means |
|---|---|
| Cookie banner fines increased up to 35× | Non-compliant cookie banners now carry substantially higher penalties |
| Automated decision-making rules eased | Some legitimate automated processing is simpler, but documentation requirements increased |
| Scientific research definition broadened | Covers private-sector data analytics for product development |
| Data subject rights streamlined | Some request handling is easier, but timelines and accountability tightened |
The practical takeaway: if you treated data protection as "done" after 2018, that assumption no longer holds. The rules have shifted, and some penalties are now significantly higher.
The EU AI Act enforcement phase
The EU AI Act has been phasing in since February 2025. From 2 August 2026, the EU AI Office and Member State authorities take on full implementation, supervision, and enforcement powers. High-risk AI system obligations apply in stages — certain high-risk areas (biometrics, critical infrastructure, education, employment) from December 2027, and product-integrated systems from August 2028.
For most small businesses, the immediate impact is not that you operate a "high-risk AI system." It is that:
- Any AI tool you use that processes EU residents' data must itself comply, and your contract with that provider matters.
- If you serve EU customers, the AI Act can reach your business regardless of where you are based.
- General-purpose AI model rules are already active (since August 2025), meaning the tools you rely on are under regulatory scrutiny.
How to use AI tools without breaching data protection
The most common compliance gap is invisible: staff pasting customer data into public AI chatbots. Under UK GDPR Article 33(2), a data processor that suffers a breach must notify the controller without undue delay. If your contractor uses an AI tool to process your client data and that tool exposes it, you may be liable — and you may not even know which tool was used.
Here is a practical five-step framework:
Step 1: Inventory your AI tools
List every AI tool your team uses — ChatGPT, Gemini, Copilot, Otter.ai, transcription services, AI-powered CRMs. You cannot protect data you have not mapped.
Step 2: Classify what may and may not go in
Decide explicitly: customer names, emails, phone numbers, contract values, health data, financial details. Create a simple one-page policy: "You may paste X into AI tools. You may never paste Y."
Step 3: Check your AI provider's data terms
Most consumer AI plans allow the provider to use your inputs for model training. Business and enterprise plans typically opt out. The difference matters: if your data trains a public model, it may resurface in another user's output. Check whether your plan includes a data processing agreement (DPA) and a no-training guarantee.
Step 4: Document your decision
Under the Data (Use and Access) Act 2025, accountability requirements have tightened. Write down what you decided, when, and why. A simple document stored with your other policies is sufficient for most small businesses.
Step 5: Train your team
A policy that no one reads is not a policy. Spend 30 minutes walking your team through what they may and may not do with AI tools. The ICO's data analytics toolkit provides a structured starting point.
What are the penalties for getting it wrong?
UK GDPR penalties remain up to £17.5 million or 4% of global annual turnover, whichever is higher. The Data (Use and Access) Act 2025 did not lower these ceilings — and for some specific offences (such as cookie banner non-compliance), fines have increased sharply.
The EU AI Act carries its own penalty structure: fines of up to €35 million or 7% of global turnover for prohibited AI practices, and up to €15 million or 3% for other violations. These are unlikely to hit a typical small business directly, but they raise the stakes for any AI provider you rely on — and a provider forced to shut down or change its service can disrupt your operations overnight.
How does this differ for UK vs EU businesses?
| Aspect | UK | EU (including Portugal) |
|---|---|---|
| Primary law | Data (Use and Access) Act 2025 + UK GDPR | EU GDPR + EU AI Act |
| AI-specific regulation | ICO guidance (no standalone AI Act) | EU AI Act (phased enforcement) |
| Key 2026 date | 5 February 2026 (DUA Act in force) | 2 August 2026 (enforcement phase begins) |
| Small business focus | Practical data governance | AI Act compliance + national incentives |
Portugal is particularly interesting: the Agenda Nacional de Inteligência Artificial (ANIA), published in January 2026, found that only 9.4% of small Portuguese companies use AI, compared to 18.2% of medium-sized and 49.1% of large firms. The government has reinforced the "IA nas PME" funding line — up to €300,000 per company in non-repayable grants covering 75% of eligible costs, from a €100 million pot managed through the IFIC. For Portuguese SMEs, the combination of new EU AI rules and available funding makes this the moment to adopt AI properly and compliantly.
How CortexLeap helps: Our Business Optimisation audit maps your AI data flows, flags compliance gaps against the 2026 rule changes, and gives you a prioritised action list in a single two-hour session.
Frequently asked questions
Can I ban my staff from using AI tools entirely?
You can, but it rarely works. Shadow AI use — staff using unapproved tools without telling you — is the bigger risk. A clear policy with approved tools and defined data boundaries is more effective than a blanket ban.
Does the EU AI Act apply to my UK business?
Yes, if your AI systems are offered to users in the EU or process data relating to EU residents. The Act applies regardless of where your business is based.
What is a data processing agreement and do I need one?
A DPA is a contract between you (the data controller) and an AI provider (the data processor) defining how personal data is handled. You need one whenever a third-party AI tool processes personal data on your behalf. Most business-tier plans from major AI providers include one.
What data should I never put into a public AI tool?
Never paste special category data (health, religion, ethnicity, biometric, sexual orientation), financial account credentials, government ID numbers, or any data covered by a confidentiality agreement. When in doubt, anonymise or do not send it.
Is the UK Data (Use and Access) Act 2025 simpler than GDPR?
In some areas, yes — automated decision-making and scientific research provisions are more flexible. But accountability requirements have tightened and certain penalties (cookie banners) have increased sharply. Treat it as a new law, not a relaxation.
Get your AI data house in order
The regulatory landscape has shifted under most small businesses without them noticing. The good news is that the fixes are practical, not theoretical: inventory your tools, set boundaries, check your contracts, document your decisions, and train your team. An afternoon's work now can save you a compliance crisis later.
Book a Business Optimisation audit — we map your AI data flows and flag every compliance gap in a single session.
Prefer to talk it through first? Book a free 15-minute discovery call and we will point you in the right direction.
Last updated: 2026-08-01