About
The control model
Audit and review
People oversight
Policy and process
Technical controls
Your AI use case
Audit and review
DPIA documentation for high-risk use cases, board or trustee briefing materials, and the evidence the ICO expects to see during an audit. Refreshed as the law changes.
People oversight
Named accountability, staff training on approved tools and data handling, and a person able to intervene in any consequential decision.
Policy and process
A tailored AI usage policy and a risk register covering your specific tools. Every use case goes through a governance gate before it scales.
Technical controls
Which tools are approved and which are not, and an acceptable use policy so teams know what data they can and cannot enter.
How Insightful AI approaches responsible AI
Insightful AI is a UK artificial intelligence consultancy based in North West England. We help SMEs, charities, and public sector organisations adopt AI safely and effectively. Governance is built into every engagement from day one, not added as an afterthought. Our advice is independent, our recommendations are grounded in evidence, and we tell clients when AI is not the right answer.
That position is not an aspiration. It describes how we work on every project we take on.
How does responsible AI run through your work?
Responsible AI is not a service we sell separately. It is how every engagement operates. We structure our work around three foundations: people, process, and principles. Each one carries governance requirements that apply from the first conversation through to delivery and beyond.
People. AI adoption succeeds or fails based on whether teams trust the tools and understand how to use them safely. We build confidence and capability through practical training and change management, not slide decks about the future of work.
Process. We identify and test real-world use cases through controlled pilots before scaling anything. Every use case goes through a governance gate. If a task involves data that creates regulatory or ethical risk, that surfaces early and we either find a safe approach or advise against it.
Principles. Ethics, compliance, and accountability are part of every stage. Every engagement begins with governance establishment or assessment. We produce documentation that organisations can present to regulators, trustees, or boards, not just internal teams.
We do not receive commissions from technology vendors, maintain preferred supplier relationships, or push proprietary platforms. Our recommendations serve client interests only. That independence is why organisations in regulated and high-accountability environments choose to work with us.
You can read more about our delivery process at how we work.
What UK regulations govern AI use?
Any organisation processing personal data through AI is already subject to enforceable UK law. The Information Commissioner's Office (ICO) treats any AI system that processes personal data as falling under the full requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. That means lawful basis, transparency, data minimisation, accuracy, and accountability all apply specifically to how AI tools collect, process, and act on personal data.
Data (Use and Access) Act 2025 (DUA Act). This Act received Royal Assent and its first commencement regulations brought provisions into force on 20 August 2025. The Act's AI and copyright reporting obligations led to a government report published on 18 March 2026, confirming that a broad copyright exception for AI training will not be pursued. Any future changes are expected to focus on licensing and technical measures. We monitor these developments and update our practices as the law moves.
ICO supervisory activity. The ICO launched its AI and Biometrics Strategy in June 2025, setting out a risk-focused approach to regulating AI. In January 2026, the ICO published a Tech Futures report on agentic AI (autonomous AI systems that use tools and make decisions with minimal human input), confirming that these systems remain within UK GDPR's existing requirements. The ICO is developing a statutory code on AI and automated decision-making. Fines under UK GDPR reach £17.5 million or 4% of global annual turnover.
The UK's domestic approach. As of April 2026, the UK has not enacted a dedicated AI Act. The government applies a principles-based, regulator-led approach. The Department for Science, Innovation and Technology (DSIT) set out five cross-sector AI principles in its 2023 white paper: safety, security and robustness; transparency and explainability; fairness; accountability and governance; and contestability and redress. Sectoral regulators apply these principles under their existing powers. The government has signalled intent to legislate for frontier AI models, and a separate Private Member's Artificial Intelligence (Regulation) Bill has been progressing in the House of Lords, but neither has yet become law.
EU AI Act. The EU AI Act entered into force on 1 August 2024. Prohibited AI practices and AI literacy requirements became enforceable on 2 February 2025. General-purpose AI model obligations applied from 2 August 2025. Transparency obligations under Article 50 have applied since 2 August 2026. Core high-risk AI obligations, covering risk management, data governance, human oversight, and conformity assessment, apply from 2 December 2027 under the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026). The Act applies to UK organisations if their AI system's output is used in the EU or they serve EU customers. We monitor and align with the EU AI Act where clients develop or deploy systems for EU markets.
Insightful AI tracks regulatory changes across all of these areas and briefs clients on developments relevant to their operations and sector. We do not offer legal advice, but we ensure the work we deliver reflects the current regulatory position.
What frameworks and standards does Insightful AI work with?
We anchor our work in recognised external frameworks and standards rather than relying on internal principles alone. Naming these is not decorative. It means our governance recommendations can be checked against published, independent sources, and that clients can verify our approach against the same materials.
The frameworks we draw on include:
ICO AI and data protection risk toolkit. A practical spreadsheet toolkit from the ICO that maps AI lifecycle stages to UK GDPR principles. We use it alongside Data Protection Impact Assessments (DPIAs, the formal risk assessments required under UK GDPR for high-risk processing) for projects involving personal data.
ICO Guidance on AI and data protection. The ICO's core guidance on how UK data protection law applies to AI systems. This is our default interpretation of UK GDPR in AI projects.
DSIT five cross-sector AI principles. The UK government's current approach to AI regulation, covering safety, transparency, fairness, accountability, and contestability. These principles shape how we structure governance for every client engagement.
DSIT Introduction to AI Assurance and AI assurance toolkit. Government guidance on assurance techniques for trustworthy AI systems. We use these resources when clients need to demonstrate the trustworthiness of their AI systems to regulators, boards, or partner organisations.
UK Data and AI Ethics Framework. The government's updated framework and self-assessment tool for public sector AI projects. We apply this when supporting central and local government teams.
ISO/IEC 42001:2023. The first international management system standard for AI, covering governance, risk assessment, data protection, and security. BSI (the British Standards Institution) is accredited to certify against it in the UK.
NIST AI Risk Management Framework (AI RMF). A voluntary framework from the US National Institute of Standards and Technology that organises AI risk management into four functions: Govern, Map, Measure, and Manage. Widely used as a global benchmark for structuring AI governance.
AI Playbook for the UK Government. Ten core principles for AI use in government and public sector organisations. We reference this when supporting public sector teams with AI adoption.
Alan Turing Institute and the UK AI Standards Hub. A UK initiative coordinating engagement with global AI standards, led by the Alan Turing Institute with the British Standards Institution and the National Physical Laboratory. We track emerging ISO and IEC AI standards through this initiative.
How does responsible AI apply to different organisations?
Responsible AI looks different depending on your sector, your size, and the regulatory bodies you answer to. We work across three audiences and tailor our approach to match.
SMEs. 49% of UK non-adopters cite data privacy and security as their primary concern about AI (YouGov B2B Omnibus, August 2025). 61% of businesses allow generative AI use, but only 31% have formal policies in place. We help SMEs put governance in place before a data incident forces the issue, not after.
Charities. 76% of UK charities lack any AI policy. Trustees carry fiduciary duties that extend to how AI is used across the organisation. The Charity Commission and the Fundraising Regulator set expectations that governance must address. We understand these obligations and the budget constraints charities operate within. Our responsible AI training for charities is designed around these realities.
Public sector. The AI Playbook for the UK Government sets ten core principles for AI use in public sector organisations. The Public Accounts Committee found implementation of responsible AI practices severely lacking across government. We support public sector teams with governance aligned to these requirements, including the UK Data and AI Ethics Framework and the National Cyber Security Centre's (NCSC) expectations on AI security.
What should you do next?
If your organisation needs help putting AI governance in place, or if you want an independent assessment of how well your current approach holds up, book a free discovery call or visit our AI ethics and governance service page to see how we can help.
Insightful AI is led by co-founders Ben Sefton and Kane Lukassen, with a team of specialists across AI governance, AI Operations, and implementation. You can also read more about how we protect client data on our security and data protection page.
