Plain English

The data law around AI is changing. Your duty of confidence is not.

New rules are landing on both sides of the Channel. Here is what the Data (Use and Access) Act 2025 and the EU AI Act mean for a professional using AI on confidential work, what stays exactly the same, and what to do about it.

The rules are shifting, but the thing that puts you at risk is not. If you paste a client's, a patient's or an employee's confidential information into a public AI tool, you may be handing it to a system that stores it, trains on it, or sits under another country's legal reach. No new Act changes that. What changes it is the tool you use.

The Data (Use and Access) Act 2025.

The Act received Royal Assent on 19 June 2025 and is the biggest change to UK data protection since the UK GDPR. It amends the existing regime rather than replacing it, and it is phasing in over roughly a year, touching areas that matter to professionals, including automated decision-making. It does not lower the bar on confidentiality; if anything it keeps the spotlight on how personal data is handled by new technology.

Primary source, read it yourself: Data (Use and Access) Act 2025 on legislation.gov.uk.

The EU AI Act.

The EU AI Act's high-risk obligations were first set for 2 August 2026, then deferred to 2 December 2027 by the EU's 2025 Digital Omnibus package, a change the Council confirmed in June 2026. Some transparency duties still fall due sooner. The UK is charting its own course rather than adopting the EU regime, which means professionals who work across both, or who use tools built to EU rules, face a picture that is shifting and, at times, confusing. The steadying move is the same one it always was: keep confidential data on a tool you control, so you are compliant whichever way the rules settle.

Primary source, read it yourself: the Council of the EU on the AI Act simplification package.

The duty stays with you, not the tool.

Through every new Act, one thing holds: your professional duty of confidentiality is yours, and you cannot delegate it to a technology provider. Every UK regulator has already said so in its own words.

A UK tribunal has now put the same point from the bench: uploading confidential material into a public AI tool can place it in the public domain and waive privilege. The law around AI is new; the duty is old.

Three steps that keep you steady whatever the rules do.

Free to take now, no email and no sign-up: the staff AI policy template and pre-filled DPIA on our resources page.

Try Hush free →

This page is general information for professionals, not legal advice. The law changes and each situation differs. Check the primary sources linked above and take your own advice before acting.

Written and maintained by the founder, Dr W.J Carter. Last reviewed July 2026.