Does My Business Need an AI Risk Assessment?

In many cases, yes, and this is not simply best practice but a legal requirement. Under Article 35 of UK GDPR, you must carry out a Data Protection Impact Assessment before starting any processing likely to result in a high risk to individuals' rights and freedoms, and the ICO specifically lists AI, machine learning and large-scale profiling among the types of processing that typically trigger this requirement. If your AI system makes or supports decisions with legal or similarly significant effects on people, such as decisions about employment, credit or access to services, a DPIA is very likely required rather than optional.

A proper DPIA should set out clearly how personal data flows through the system, what your lawful basis is, what risks you have identified to individuals, and what mitigations you have put in place, written in plain English. The ICO also expects you to show that you considered less risky alternatives before proceeding.

If your business operates in or sells into the EU, you also need to consider a separate assessment under the EU AI Act, which classifies AI systems by risk level and imposes distinct obligations on high-risk systems regardless of whether personal data is involved. A GDPR DPIA and an AI Act risk classification address different questions, so treat them as two separate pieces of work rather than assuming one automatically covers the other. If you are unsure whether a specific AI system in your business meets the threshold for either, it is worth getting this checked rather than guessing, since the consequences of getting it wrong can be significant.

Next
Next

Does My Company Need an AI Policy?