Do Organisations Need To Update Their Breach Response Plans Because Of AI?
If your breach response plan has not been reviewed recently, the answer is almost certainly yes. The way data breaches occur is changing, and a plan designed for an older threat environment may no longer reflect the speed, scale, or nature of incidents your organisation is likely to face.
In May 2026, the Information Commissioner's Office published guidance on how AI has changed the threat picture organisations face. Attacks are now faster to execute, easier to scale, and in many cases harder to identify before damage is done. Phishing emails can be generated and personalised with minimal effort on the attacker's side. System vulnerabilities can be scanned and exploited automatically, giving attackers a speed advantage that makes early detection more important than ever.
A plan needs to answer several questions clearly before any incident occurs. Who is responsible for identifying and escalating a potential breach? Who decides that a reportable breach has occurred? Who notifies the ICO, and how? Who communicates with affected individuals if that is required? And who owns the post-incident review?
The 72-hour notification window under UK GDPR is unforgiving, and teams that have to figure out the answers to these questions in the middle of an incident are far less likely to meet it. The ICO's breach reporting guidance sets out exactly what information you need to provide when you notify, which makes it practical to prepare templates and process notes in advance.