When you think about sharing personal information with artificial intelligence, you might picture typing a question into ChatGPT or uploading a document to an AI assistant. But that’s only part of the story.
AI is increasingly working behind the scenes in services we use every day. It can recommend what we watch, flag suspicious payments, screen job applications, personalise advertising and analyse images.
And all of that relies on data. So how much of that data could be about you?
AI can process more personal information than you might think
Personal data isn’t limited to your name, address or email.
Depending on the circumstances, it can include photographs, voice recordings, location information, online activity and device identifiers. Even information that doesn’t include your name could still be personal data if it can be linked back to you.
AI can encounter this information in different ways.
You might provide it directly by entering a prompt or uploading a photograph or document.
Information can also come from apps and digital services, licensed data or publicly accessible parts of the internet.
AI can even analyse existing information to make predictions or inferences about people’s interests and behaviour.
If it's online, is it fair game?
AI companies can automatically collect large amounts of information from public websites through a process known as web scraping. But personal information doesn’t lose its legal protection simply because somebody has posted it publicly.
Companies still need to comply with UK data protection law when it applies, including having a valid reason for using personal data and being fair and transparent about what they are doing.
And consent isn’t the only issue.
Depending on the circumstances, a company may be able to use personal information without asking for consent. But that doesn’t give it a free pass to do whatever it wants with people’s data.
What about information you give directly to AI?
This is becoming increasingly relevant as people turn to AI assistants and search tools for everyday help.
You might ask an AI tool to improve your CV, summarise a work document, explain a financial letter or help you think through a health concern.
Without really noticing, you could be sharing highly personal information about yourself — or someone else. Different providers have different policies covering how prompts, conversations and uploads are processed and stored. That’s why it’s worth understanding what you’re sharing and what controls are available when you use these tools.
But protecting personal data isn’t simply the user’s responsibility. Companies using AI also have responsibilities over how they collect, use and protect people’s information.
Your data rights don't disappear because AI is involved
The technology might be new, but many of the rights protecting your personal information aren’t. UK data protection law gives you rights over how organisations use your information. Depending on the circumstances, these can include asking what information an organisation holds about you, correcting inaccurate information, objecting to certain uses and requesting deletion.
And where companies misuse personal information through AI, they could potentially face regulatory action or legal claims.
Find out what happens to your data
As AI becomes more deeply embedded in everyday products and services, understanding how personal information fits into the picture is becoming increasingly important.
Our new guide explains where AI gets personal data, what companies are expected to do with it, and what to do if you’re concerned about how your information is being used.