-
What is AI Governance – and Why Does it Matter?
Artificial Intelligence is rapidly becoming part of everyday organisational life. It can help us draft documents, analyse information, automate routine tasks, identify patterns, support decision-making and find new ways of delivering services. But as organisations become increasingly comfortable asking “What can AI do for us?”, another question is becoming equally important: “How do we make sure we are using it properly?” That, in essence, is what AI governance is about. What is AI Governance? AI governance is the framework through which an organisation makes sure that Artificial Intelligence is used responsibly, safely, legally and effectively. It brings together the policies, processes, responsibilities and controls that determine how AI can be introduced and used within an...
-
Publication of judgments in care proceedings
A High Court judge in the Family Division recently considered the question of the extent to which judgments he had handed down should be anonymised and whether the transparency order in force in respect of care proceedings should be varied accordingly. Molly Giles considers the key points from the ruling. The case of Blackpool Borough Council v Langley and Ors (No.2) (re-opening of Findings) [2026] EWFC 69 (MacDonald J) concerned the welfare of RR following the sad death of her sister Edith in 2020. The court was concerned with whether or not Edith’s mother had inflicted injuries upon Edith causing her death. In 2023, the family court made findings that Edith’s death was caused as a result of compressive chest trauma inflicted upon her by her mother. In October 2023, the matter came for...
-
AI in education: the importance of transparency
The debate around AI in education often focuses on capability. What can it do? How much time can it save? Yet some of the most important questions are not technical at all. Adam Halsey looks at why transparency should come before implementation. When schools consider using AI-based tools and products, many experience the stages of intrigue, caution, optimism and concern. Sometimes one after the other – sometimes all in one! Intrigue as to the capability of the software and whether it delivers the world on a plate as is seemingly often promised. Caution when thinking of the legal and regulatory risks, on top of the impact on students if things were to go wrong. Optimism when schools realise there are often ways of onboarding and using AI that are GDPR-compliant, and can genuinely help...
-
Shadow AI in the workplace: the risks for public sector employers
The use of AI tools by staff and contractors without formal organisational approval is a growing risk with serious consequences for the public sector write Declan Goodwin and Frederick Lambert. Artificial intelligence is already embedded in the day-to-day work of public sector employees whether their employers know it or not. The use of AI tools without formal organisational approval is no longer an emerging risk. It is a present one, and it is growing. We refer to this as "shadow AI": staff reaching for consumer-grade or third-party AI tools outside of any procurement process, policy framework or governance structure. The scale of it should concern every monitoring officer, data protection officer and head of legal in local government. A recent government survey confirmed that one in...
-
Shalini Patel and Omid Golahmadi examine how the proposed AI age assessment technology would work, the legal framework surrounding age assessments, and the challenges that Facial Age Estimation may present within the UK's existing safeguarding system. As artificial intelligence (AI) becomes an increasingly familiar part of everyday life through tools such as ChatGPT and Claude, it is also beginning to play a greater role in public services. As a result, questions are increasingly being asked about how far the technology should influence decisions that affect people's rights. The Home Office’s plans to use AI-assisted Facial Age Estimation (FAE) in age assessments for asylum seekers which has prompted a significant legal and ethical debate about the role of AI in decisions affecting...
-
AI in local decision-making: Old duties, new risks
Bill Cordingley looks at the legal implications of authorities adopting AI. Artificial intelligence (AI) is steadily embedding itself across local government. From triaging housing applications to supporting social care assessments and analysing planning data, AI promises greater efficiency at a time when resources remain under acute pressure. Yet, for all its potential, AI does not sit comfortably within the traditional frameworks of public law. The legal duties governing decision-making have not changed, but the means by which decisions are reached are evolving in ways that make compliance harder to evidence, and failure more difficult to detect. For local authorities, the question is no longer whether AI will be used, but whether it can be used in a way that is consistent with the...
-
The New Data Protection Complaints Regime
From Friday, 19 June 2026, organisations can no longer rely on complaints going straight to the ICO. The Data (Use and Access) Act 2025 introduces a new regime requiring them to receive, investigate and resolve data protection complaints themselves. Maggie Burns and Charlotte Smith explain what you need to know. The Data (Use and Access) Act 2025 (the “Act”) introduces a new complaints framework for UK data protection law. For the first time, organisations will be legally required to put in place and operate a formal process for handling data protection complaints. In practice, this marks a shift away from a system in which individuals could go straight to the Information Commissioner’s Office (“ICO”), towards one in which concerns are expected to be raised with organisations in the...
-
Case Management doesn’t stop at the case
Why collaboration, communication and visibility are becoming increasingly important across legal and public sector services. As a provider of legal and case management software, Iken Cloud supports public sector and legal teams managing increasingly complex casework, collaboration, and communication across internal and external stakeholders. Where collaboration starts breaking down Over the last year, we’ve spent a lot of time speaking with clients about the day-to-day pressures around collaboration, communication, and managing work across teams and external stakeholders. Across legal and public sector services, the same challenges kept appearing. Communication was often spread across inboxes, systems and departments. Information could become disconnected from the case itself. And too...
-
Key Data Protection Issues for Automated Recruitment in the Public Sector
The need to recruit faster in a competitive market, the need to minimise costs in the recruitment process, and the need to secure the best candidate quickly, makes the use of AI an appealing option for any employer including public bodies. But there are pitfalls for the unwary write David Leach and Charlotte Smith. David Leach is a Senior Associate specialising in employment law and Charlotte Smith a Technology and Data specialist at Sharpe Pritchard LLP. The use of automated recruitment processes is becoming more common for all employers, and new Articles 22A – 22D of the UK GDPR (introduced by the Data (Use and Access) Act 2025) arguably provide more freedom to employers to deploy such technology. Nonetheless, the ICO announced in March 2026 that the use of automated decision-making...
-
Cyber Security and Resilience Bill: Why Local Authorities Cannot Afford to Wait
The UK Government’s proposed Cyber Security and Resilience Bill is likely to mark a significant shift in regulatory expectations. Jonathan Askin, Partner at Hugh James, explores the reasons why. The UK Government’s proposed Cyber Security and Resilience Bill (“CSRB”) is expected to become law later this year and represents the most significant overhaul of the UK’s cyber security framework since the Network and Information Systems Regulations 2018. For local authorities in England and Wales, the Bill is likely to mark a significant shift in regulatory expectations. Cyber security is rapidly moving beyond the IT function and into the core of governance, operational resilience and public service delivery. Local authorities are increasingly dependent on complex digital infrastructure and...
-
The date for assessing whether a request is vexatious or manifestly unreasonable, in the context of freedom of information and environmental information refusal decisions, is an issue with a surprisingly long tail - particularly given its practical importance to public bodies when faced with information rights requests. Even though the test of vexatiousness (FOIA) and the test of manifest unreasonableness (EIR) is now accepted to be the same (the ‘two-tests one meaning’ approach), the relevant date, at which the public authority should make its assessment under the two regimes, is not the same. The issue has practical importance because, of course, the relevant date of assessment provides the principal ‘cut-off’ date as to the matters that the public body is entitled to consider when...
-
Procuring trust: managing AI risks in public sector contracts
Alexi Markham and Jocelyn S Paulley consider what public sector and in‑house teams typically need most at procurement stage, the key AI risks that show up in public sector contracts and the practical steps that help manage them. AI is already part of public sector delivery, from decision support and monitoring to service delivery and internal efficiency. The procurement challenge is not simply buying an “AI‑powered” tool. It is identifying the right use case, setting the right requirements, allocating risk fairly and putting governance in place so the system stays safe and reliable once it is live. If you are looking for a short definition of AI and how it works, we have covered that in our recent insight: Artificial Intelligence in business: a starter for boards. AI in the public...
-
Generative AI in complaints and requests: Opportunities, risks and implications for public bodies
George McLellan, Fred Groves & Christopher Watkins discuss the impact of generative AI on the public's interactions with public bodies. Introduction Generative AI can offer a host of benefits to members of the public when interacting with public bodies, particularly to individuals who may previously have faced difficulties in composing formal correspondence, such as a complaint or request for information. However, the increasing use of generative AI is placing strain on public bodies, who are under legal duties to properly consider, verify and meaningfully respond to complaints and requests. The challenge for public bodies is in maintaining fairness, consistency and transparency when handling increasing volumes of AI-generated submissions. Access to justice, information and redress Used...
-
AI in Education: Why Data Protection Must Come First
Artificial Intelligence promises a lot. It can undoubtedly do amazing things. But secretly (or maybe not so secretly), it also makes us slightly nervous. Adam Halsey looks at what this means for schools, and why data protection needs to sit at the centre of any decision to use AI. When it comes to AI, we always hear about risks and opportunities. You’ll be challenged to find an article or piece of analysis on AI, particularly relating to the education sector, that doesn’t refer to both. Whether or not your school is using generative AI at the moment, many of us are aware of the potential uses. It may be taking on or assisting with written tasks such as reports and emails, or supporting feedback for students – possibly including that crucial tailored approach for individual learners and...
-
Preparing for the new complaints regime
From 19 June 2026, all organisations acting as data controllers are required to have in place an effective process to enable individuals to raise complaints about how their personal data is handled. Ashleigh Dibb looks at what this will mean in practice. The Data (Use and Access) Act 2025 (DUAA) introduces an important obligation for organisations handling personal data. Organisations will be required to ensure that individuals can easily raise concerns, and that those concerns are properly acknowledged and addressed within appropriate timeframes. Organisations with existing complaints procedures should not assume these will be sufficient. A thorough review of any existing policies will be necessary to ensure current processes meet the standards set by the DUAA. Where no suitable...
-
When data protection doesn’t protect you
Recently, the Information Commissioner’s Office published the outcome of a criminal prosecution. The title? Just two names: Christopher Munro and William Chipoma. No explanation. No softening. No anonymity. And that, in itself, is a powerful lesson in how data protection law really works. Data protection isn’t about secrecy There’s a persistent myth that data protection is about hiding information. It isn’t. It’s about using personal data lawfully, fairly and appropriately. In this case, the ICO has deliberately published the names of two individuals convicted of unlawfully accessing and selling personal data. That information is now: - Public - Searchable - Permanently associated with them That’s not a failure of data protection. That’s data protection law working exactly as intended....
-
New Regulations for the Use of AI in Court Documents?
Fred Groves and Christopher Watkins provide insight into growing judicial concern about accuracy, professional responsibility and the efficient administration of justice in the face of Artificial Intelligence. The increasing use of generative artificial intelligence in the preparation of court documents has prompted growing judicial concern about accuracy, professional responsibility and the efficient administration of justice. Recent cases have highlighted the risks associated with AI-generated “hallucinations”, including the citation of non-existent authorities, with significant consequences for parties and court resources. Against that background, the Civil Justice Council (“CJC”) has launched a consultation on whether new procedural rules are required to govern the use of AI in...
-
Does the rollout of AI in public sector policy making and delivery comply with public law principles? There are numerous pitfalls for public bodies writes Nicola Cain. When public authorities, or entities exercising public functions, deploy artificial intelligence (AI) technologies, compliance with their public and administrative law obligations effectively requires them to comply not only with data protection, human rights, health and safety and other applicable laws, but with concepts of fairness, transparency and the elimination of bias, and to be aware of specific public sector applications and AI use cases that present unique challenges. The government and public bodies should be under no illusions that unleashing AI across the UK to deliver the AI Opportunities Action Plan...
-
FOI and information held on computer systems
Do public authorities ‘hold’ all information on their computer systems? Conor Monighan analyses a recent Upper Tribunal ruling. In Farfan v Information Commissioner [2026] UKUT 16 (AAC) the Upper Tribunal dismissed an appeal which argued that, for the purposes of the Freedom of Information Act 2000 (“FOIA”), public authorities ‘hold’ all information stored on their computer systems. In doing so, the UT issued valuable guidance on when data is ‘held on behalf of’ a third-party for the purposes of s.3(2) of the Freedom of Information Act 2000. Background The Appellant requested from the University of Central Lancashire (“the University”) all communications sent to/ from an individual called Professor Baldwin about Queen’s University Belfast. The University stated it did not hold any...
-
Care leavers and redaction of records
Is redaction of records necessary for privacy, or a cause of harm and frustration? Peter Garsden of the Access to Care Records Campaign Group explores the issues. When the Information Commissioner’s Office announced their new policy and related materials entitled the “Better Records Together” campaign before Christmas, I was delighted that all my campaigning as an executive officer of the Access to Care Records Campaign Group (ACRGG) was coming to fruition. Whilst we welcomed it, if I was being critical, I would say that the message to local authorities, overwhelmed and lacking in resources as they are, was more of a stick than a carrot. I will explain why I think this below. History Until the Access to Personal Files Act 1987, no child in care had a right to see their records. We were...

