Let’s get one thing out of the way: we’re not here to throw a blanket on innovation. We believe AI is genuinely changing how work gets done, and tasks that used to eat entire afternoons now take minutes. That’s worth celebrating but it’s also changing your business’s legal risk profile, and that shift can become easy to miss while everyone’s busy being impressed by the technology.
When change like this arrives, businesses tend to fall into one of three camps: embrace and plan, cover your eyes and pray, or slam the hammer of “no.” We’re firmly in the first camp.
Use it. But use it with your eyes open.
“Is there an AI law I need to comply with?”
This is the question we get most, so here’s the straight answer, there is at date of this blog no dedicated AI law in force in the UK. That does not mean AI use is unregulated. The government’s approach so far has been to let existing laws and regulators do the work, which means UK GDPR and the Data Protection Act 2018, consumer protection law, online safety and equality law, intellectual property law and your sector’s own regulators all apply to how you build and use AI.
And the ground is moving. The Data (Use and Access) Act 2025 made meaningful changes to UK data protection law, including loosening the rules on solely automated decision-making, with key provisions taking effect in early 2026. On top of that, under new regulations in force since May 2026, the ICO is now under a statutory duty[1] to prepare a code of practice on AI and automated decision-making (including specific guidance on children’s data). That code hasn’t been published yet – in the meantime, the ICO’s existing guidance on AI and data protection is the benchmark to work to. So “no AI law” doesn’t mean “nothing to do.” It means the rules that already bind you are being applied to a new technology, and regulators are sharpening their guidance.
Our view: don’t wait for a statute with “AI” in the title. Apply your energy to the areas where AI touches your business. You’re not trying to reinvent the wheel – a proportionate, risk-based approach that integrates into how you already operate beats hitting “stop” on the future every time.
Therefore, focus on what you can control:
1 – Map where AI actually lives in your business
Go back to basics. Is AI the cornerstone of your product, or is it enabling better service delivery in the background? Which teams use it, which tools, fed with what data? Are AI agents being wired into your workflows? You can’t assess a risk you haven’t found, so the first job is an honest inventory of every service line and process that touches AI. From what we’ve seen, businesses are often surprised by what this turns up.
2 – Risk-assess each use case (yes, that means a DPIA)
The UK’s approach to AI draws heavily on data protection principles: accountability, transparency, fairness, data minimisation, lawfulness. Where AI processes personal data – and it usually does – an AI-specific DPIA (data protection impact assessment) per use case is the single most useful exercise you can do. It tells you whether you have a lawful ground, whether you need consent or a legitimate interests assessment, and what to fix before a regulator or a customer asks.
We’ve builtg an AI-focused DPIA template you can download free, right here.
3 – Update your privacy notices and your own business or service terms
If AI touches how you use personal data, your customers, employees and other data subjects should be told, plainly. And if AI supports your service or is baked into your product, your business terms should say so and deal with it properly. Both flow from the same discipline: accurate internal records means it’s easier to draft (and prove) accurate public-facing documents.
4 – Look hard at your vendor agreements
Whether you’re buying AI-enabled services or you are the vendor (example, a SaaS provider), contracts deserve a careful read where AI is involved: liability and indemnities, intellectual property, data clauses, and whether your data processing agreements and schedules still reflect reality now that AI is in the mix. Watch in particular for whether your data can be used to train a vendor’s models, how anonymisation is handled, and what the licensing provisions actually let each side do.
5 – Sort out employee use and hiring
Probably the most missed area. Your people are almost certainly using AI at work already – and we don’t think that’s a bad thing. But the difference between AI use going wrong and AI lifting your bottom line could be clear, actively communicated workplace guardrails. Hiring deserves attention too: AI in recruitment (screening, recordings, automated decisions) needs a lawful basis, and small changes to employment procedures or existing policies could get everyone on the same page.
A few extra thoughts from us
Think about your business’s IP: if your logo, brand assets or creative work were generated with AI (by you or a third party), ownership is not automatic. Check what you actually own before you build a brand on it.
And if you sell into the EU, the EU AI Act can apply to UK businesses whose AI systems affect people in the EU, regardless of where the business is based, with obligations phasing in over the next couple of years. It’s outside the scope of this piece, but if you think you might be in scope, that’s a conversation worth having early.
Where to start?
If this list feels like a lot, start with No. 1 and No. 2 – everything else naturally flows from knowing where AI sits in your business and what risk it carries.
To make that easier, we’ve put together a AI-focused DPIA template you can use to assess any AI use case in your organisation. If you’d like to grab a copy of it reach out to us at onwards@lawboxlegal.com
And if you’d like an extra hand with your legals, we’re here when you’re ready. Send us your contracts or policies to review or tell us what you need. We’ll send over a SoW for sign-off and get moving to get your house in order.
* General note: This post is general information, not legal advice. For advice on your specific circumstances, get in touch – that’s literally what we’re here for.
[1] The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 https://www.legislation.gov.uk/uksi/2026/425/made