Do we need AI governance if we only use ChatGPT and Copilot?
Yes. UK GDPR (the General Data Protection Regulation, as retained in UK law) applies to any AI tool that processes personal data. Your organisation needs a DPIA if the tool involves high-risk processing, and an acceptable use policy so teams know what data they can and cannot enter. 70% of employees using AI have not told their employer (DSIT), so the gap is likely larger than leadership realises.
The tools themselves are not the problem. ChatGPT and Copilot are used productively across millions of UK organisations. The risk comes from how your specific teams use them with your specific data. A staff member pasting beneficiary records into a public AI tool is a UK GDPR breach regardless of intent. A manager using AI to assist with recruitment decisions triggers additional obligations under the Data (Use and Access) Act 2025 (which reformed automated decision-making rules in UK law from February 2026), requiring mandatory safeguards, individual notification, and the right to request human intervention.
41% of local government staff use AI outside approved channels (DSIT research summary). The pattern is consistent across sectors. Staff are using tools because those tools help them work. Governance gives them a legitimate route to keep using them, within defined limits, with the documentation in place to show oversight.
This service connects naturally with AI at Work, where we work through your team's actual tasks and build solutions during the engagement. Every AI at Work engagement produces a governance pack per use case. An overarching policy framework should be in place first.
One objection that comes up regularly: "Our GDPR policies already cover this." They do not. UK GDPR policies and privacy notices address personal data processing. They do not cover AI-specific risks: tool approval processes, algorithmic bias, shadow AI, opaque automated decisions, or the EU AI Act's Article 26 deployer obligations. AI introduces categories of risk that have no equivalent in a standard data protection policy, and the ICO treats them separately.