Many small UK businesses assume that because Parliament has not passed an "AI Act", nobody is regulating how they use AI. That assumption is the most expensive one to make. Here are seven myths worth retiring before you roll out another AI tool.
Status note: the details below reflect the position as of September 2026. Guidance from the Information Commissioner's Office (ICO) is still evolving, so check the official source before you rely on any of it.
Myth 1: "The UK has no AI law, so I have no obligations"
Fact: The UK has chosen not to pass a single, EU-style AI Act. Instead, existing laws and existing regulators apply to how you use AI. If a tool processes personal data, UK GDPR and the Data Protection Act 2018 apply. If it affects hiring, the Equality Act 2010 is relevant. If it shapes what you tell customers, consumer protection rules apply. The absence of one headline statute simply means the rules are spread across several places.
Myth 2: "UK GDPR only cares about the tool provider, not me"
Fact: If you decide why and how staff or customer data goes into an AI tool, you are usually acting as the controller for that data. The supplier may carry duties too, but yours do not disappear. In practice this means knowing what data goes in, having a lawful basis, being open with people about it, and checking what the supplier does with the data afterwards.
Myth 3: "The 2025 data reforms mean AI is now a free-for-all"
Fact: The Data (Use and Access) Act 2025 changed parts of UK data protection law, including the rules on automated decision-making. It loosened some restrictions, but it kept safeguards for decisions made solely by automated means that have significant effects on people. The ICO's updated guidance describes safeguards such as telling people about the decision, letting them make representations, providing human intervention and allowing them to contest the outcome. Treat the reforms as a change in shape, not a green light.
Myth 4: "A human clicking approve makes it compliant"
Fact: Regulators and commentators stress that human involvement has to be meaningful. A person who rubber-stamps whatever the software suggests, without the time, information or authority to disagree, is unlikely to count. If you use AI to screen CVs, flag customers or set prices, ask whether the reviewer could realistically overturn the result, and whether they ever do.
Myth 5: "An ICO code of practice already tells me exactly what to do"
Fact: The 2025 Act requires the ICO to produce a statutory code of practice on AI and automated decision-making. Regulations bringing that duty into force were made in May 2026, and the code itself was still being developed at the time of writing, with publication anticipated later. Until it lands, you are working from the ICO's existing AI and data protection guidance and its draft automated decision-making guidance. That is a reason to document your reasoning now, not to wait.
Myth 6: "Only businesses that build AI need to worry"
Fact: Most small businesses are users, not builders. Using an AI writing assistant, a chatbot on your website, a scheduling tool or an applicant tracker still counts as using AI in your business. The risks are practical ones: personal data pasted into public tools, inaccurate output published as fact, biased screening, and customers who feel misled about whether they are talking to a person.
Myth 7: "Compliance means a huge policy document"
Fact: For a small business, a short, honest set of records usually does more good than a long policy nobody reads. A workable starting point looks like this:
- List every AI tool anyone in the business uses, including free ones staff signed up to themselves.
- Note what personal data, if any, goes into each one.
- Record who reviews the output and what they can change.
- Check each supplier's terms on data retention and on using your inputs for training.
- Set a simple rule for staff on what must never be pasted into a public tool.
- Diarise a review every few months, because both the tools and the guidance move quickly.
Where the Real Risk Sits
Trouble rarely starts with a sophisticated system. It starts with an ordinary decision: a manager pastes a grievance letter into a chatbot, a recruiter lets a tool rank applicants unsupervised, or a shop owner switches on a chat widget without saying it is automated. Each is fixable if you catch it early, and each is much harder to explain after a complaint.
A Sensible First Week
If you do only one thing after reading this, spend an hour on the tool inventory. Ask each team member what they use, including anything on a personal login, and do it without blame, otherwise people will simply stop telling you. Once you can see the list, the priorities usually become obvious: tools touching customer or employee data come first, tools influencing decisions about people come second, and everything else can wait for the next review.
FAQ
Do I need to register anything with the ICO because I use AI?
Not because of AI alone. Most UK organisations that process personal data pay a data protection fee unless exempt, so check the ICO's fee self-assessment rather than assuming.
Can I use ChatGPT-style tools with customer data?
Only if you have a lawful basis, have told people, and have checked the supplier's data terms. Many businesses find it simpler to keep personal data out of general-purpose tools entirely.
Will there be a UK AI Act later?
Government positions have shifted over time, and I cannot promise either way. Watch GOV.UK and your sector regulator for updates.
Who enforces this?
It depends on the issue: the ICO for data protection, the Equality and Human Rights Commission and tribunals for discrimination, the Competition and Markets Authority and Trading Standards for consumer matters, and others by sector.
Read next: The AI Compliance Patchwork Is Real — What Small Businesses Actually Need to Do in 2026
Read next: Does Your Business Have to Tell Customers They’re Talking to a Bot?
Where to Go From Here
If you want the whole picture in one place, AI Compliance for Small Business (UK Edition) is written for owners who are already using AI and want to understand the framework they are operating inside. It covers the reformed UK GDPR, the patchwork of sector regulators and the ICO code of practice that is still to be published.
It is an independent guide and a starting point for your own checks, not a substitute for advice tailored to your business.
Get AI Compliance for Small Business (UK Edition) →
This article is general information only and is not legal, tax, financial or medical advice. Laws and regulator guidance change, so check current official guidance from the ICO and GOV.UK, or speak to a qualified adviser, before making decisions.