Where the rules bite.
The privacy question is the one people raise last and worry about most. It is also the one that quietly kills projects, usually nine months in, when somebody senior finally asks it out loud and nobody has an answer.
Certified Information Systems Security Professional. Seventeen years continuously certified, which means access control, third-party risk and incident handling are not topics I have to bring somebody in for.
Most of a thirty-year career spent inside banking, defence and healthcare, where the data question was never optional and someone always had to be accountable for the answer.
The same person who can write the risk paper for an executive committee can read the data model underneath it. That combination is what makes the answer quick.
Four things I cover
Is this lawful
Lawful basis for each processing purpose. Whether you need a data protection impact assessment and what goes in it. Special category data and why it usually needs a different route from the one being proposed. The automated decision-making rules changed under the Data (Use and Access) Act 2025, and anything that makes a decision about a person now sits under a conditions-based test with transparency and challenge rights attached.
Who can reach it
What actually leaves your estate and where it lands. Access control and least privilege applied to AI tools, which is where most shadow usage hides. Retention, deletion and what happens to backups, logs and derived data. Third-party and supply chain risk, including the sub-processors your vendor has not mentioned. Exit and portability, because not every AI vendor will still exist in three years.
How wrong can it be
Where a confident wrong answer costs you money, a customer or a regulatory conversation. Human review that is real rather than nominal. What the audit trail has to capture so that a challenge in eighteen months is answerable. How you notice degradation rather than finding out from a complaint. Accuracy is not a technical footnote when the output goes to a customer.
Which rules apply
The UK has no single AI statute. Obligations arrive through existing regulators, each on their own timetable, which is harder to track than one deadline. If you sell into the EU, the transparency duties around chatbots and generated content have their own dates, while the heavier high-risk regime was deferred to the end of 2027. Most businesses are over-worrying about one part and under-worrying about another.
Regulatory dates in this area moved twice in 2026 alone, and a good deal of published guidance is now out of date. I check the position rather than repeat it from memory, and I will tell you where the answer is genuinely unsettled rather than inventing certainty.
Ten questions for any AI vendor
Use this without me. Send it to whoever is trying to sell you something, before you sign. The quality of the answers, and how quickly they arrive, will tell you more than the demo did.
- Does our data train your models, on any tier, ever?Ask about every tier, not the one you are on. Terms differ between free, team and enterprise, and they change.
- Where is it processed and stored, under whose jurisdiction?"The cloud" is not an answer. You want country, legal entity and transfer mechanism.
- Who at your company can see it, and in what circumstances?Support access for debugging is the usual gap. Ask how it is logged and who approves it.
- What is the retention period, and how do we get data deleted?Including from backups, logs and any derived embeddings, which people routinely forget.
- Who are your sub-processors, and how are we told when the list changes?Your exposure is the whole chain, not just the company you signed with.
- What happens to our data if you are acquired, or if you fail?Exit and portability. Small AI vendors do not all survive, and 2026 is not a stable market.
- What are the accuracy limits, and how do we detect when it is wrong?Any vendor who will not discuss failure modes has not thought about them, or is hoping you will not.
- What audit trail do we get of what the system did and why?If a customer or a regulator challenges an output in eighteen months, this is the only thing that helps you.
- What is your incident notification commitment, in hours?A number, in the contract. "Promptly" is not a commitment.
- Can you evidence a lawful basis for each processing purpose?If they look blank at this question, they have not done a data protection assessment and neither have you.
Where I stop
I am not a solicitor and I am not your data protection officer. I will not draft your contracts, I will not sign off your compliance position, and I will not tell you that something is legal.
What I will do is find where the exposure sits, separate the routine from the genuinely difficult, and make sure that when you do pay for legal advice you are paying for judgement rather than for someone to discover basic facts about your own systems. Knowing when to hand over is part of the service, and it usually saves more than it costs.