15 September 2025
At the Strident AI Event last week, Rebecca Richards, Compliance Specialist for Strident, offered an informative and slightly scary presentation of the issues of implementing artificial intelligence without testing and controls put in place.
"There are a wide number of issues, both internal and external, that businesses need to consider and have written procedures," explains Rebecca. "This isn't just a 'nice to do', this is a legal requirement under UK law. The ICO can fine businesses heavily if there is an issue and no documented controls in place for processing personal data with AI."
Businesses must ask: who has access to AI and what are they doing with it? Is your sensitive data being supplied to AI models and does that model retain the data for further use? Are you making decisions about customers using AI and do those customers know?
Artificial intelligence is transforming the way businesses operate, from automating tasks to uncovering valuable insights. But with these opportunities come responsibilities — especially when it comes to handling personal data. Under the General Data Protection Regulation (GDPR), companies are accountable for how data is used, even if decisions are made by AI systems.
This is where documented controls and procedures become essential.
Proof of compliance – GDPR requires businesses to show they are following the rules. Having written policies, risk assessments, and audit trails helps demonstrate that data is processed fairly and lawfully.
Consistency – Clear procedures reduce mistakes and ensure the same standards are applied across the business, whether it’s about data access, storage, or AI-driven decisions.
Respecting rights – People have the right to access, correct, or object to the way their data is used. Documented processes make it easier to respond quickly and avoid breaches.
Building trust – Customers and partners want reassurance that AI is being used responsibly. Strong governance shows commitment to protecting data and strengthens reputation.
In short, documenting how AI systems are controlled is not just about ticking a compliance box. It’s about creating transparency, consistency, and trust — key ingredients for using AI responsibly and legally in any business.
To discuss putting the necessary AI controls in place for your business, please get in touch with Rebecca Richards.