AI in local government: what council staff can and cannot use
· Updated · Written and maintained by Joaquín Trapero, Nonimo
A council officer can use AI at work. What cannot happen is a resident’s case leaving the building inside a prompt, and the rule that decides it is not an AI rule at all: it is UK GDPR, the Data Protection Act 2018 and whatever your own council has written down. If your council has nothing written down, every officer is making that decision alone, several times a day.
That is the position, and it is worth saying first because almost everything published about AI in local government is written for someone else. The Local Government Association writes for the head of IT. The government’s own guidance writes for civil servants. The consultancies write for the chief executive. Nobody writes for the housing officer with forty minutes to answer a complaint and a chat window open on the second screen.
This guide is for that officer, and for the person who has to tell them what the rules are. It covers what councils are already doing, what the law actually requires, what the government’s guidance says, and where a tool helps and where it does not.
How AI in local government is actually being used
Adoption has not followed the pattern the sector talks about at conferences. Councils did not start with predictive risk models in children’s services. They started in the back office: minutes, drafting, procurement paperwork and cyber monitoring.
That matters, because the back office is also where resident data turns up without anyone expecting it. A set of committee minutes has names in it. A procurement file has complainants in it. The general case for treating this as a data protection question rather than a technology question is set out in putting client data into ChatGPT; what follows applies it to a council.
The Local Government Association ran its survey from December 2024 to February 2025 and published it on 2 June 2025. Of the councils that answered, 95 per cent were using or exploring AI. A third of English councils responded, which the LGA says makes the results a snapshot of that group rather than a picture of the whole sector. Read with that caveat, the shape is clear enough.
The back office, where it started
Among respondents using or exploring AI, 84 per cent were doing it in corporate functions: human resources, administration including meeting minutes, procurement, finance and cyber security. Adult health and social care came next at 44 per cent, and children’s at 31 per cent.
Generative AI was the most common kind by a distance. Perceptive and predictive systems, which are the ones that attract the headlines, were far behind.
That ordering matters for this guide. A perceptive or predictive system arrives through a procurement, which means somebody wrote a specification, somebody did an assessment and somebody signed a contract. Generative AI arrives through a browser tab. It is the category where an officer types free text, and free text is where a resident’s name, address and circumstances travel without anyone having decided that they should.
What councils say worries them
The LGA also asked respondents what they saw as a great or moderate risk. The answers say something about where councils think the danger sits, and it is not where this guide says it sits.
Deepfakes and disinformation came second at 69 per cent, and damage to reputation and resident trust third at 68 per cent. Those are all risks that arrive from outside: an attacker, a fake video, a bad headline. Ordinary disclosure by a member of staff doing their job properly is not on the list, and it is the one that happens every day.
The tools councils have actually declared
The Algorithmic Transparency Recording Standard register on GOV.UK is the only public list of algorithmic tools in UK public bodies. On 20 September 2026 it held 152 records, and a keyword search for “council” returned 18 of them.
| council | tool | what it does |
|---|---|---|
| London Borough of Barnet | Ami Chatbot | automated webchat on the council website |
| Camden Council | RentSense | prioritises council housing rent arrears cases for contact |
| Bristol City Council | NEET model | helps safeguarding staff support families at risk of becoming NEET |
Source: the ATRS record repository on GOV.UK, records published 28 January 2025, read on 20 September 2026.
Three things are worth noticing. These are procured systems, not chat windows. They are declared voluntarily, because councils are not required to declare anything. And none of them is what happens most often, which is an officer putting a case into a chat assistant because it is quicker.
The data a council holds, and why it is not ordinary business data
A law firm holds client matters. An accountant holds books. A council holds the parts of a person’s life that they did not choose to share with anyone.
That is the reason the ICO treats council services the way it does, and the reason a single careless prompt in local government is worse than the same prompt almost anywhere else.
It also changes where the data ends up mattering. A commercial assistant retains, routes and in some cases shows conversations to human reviewers, and each vendor does it differently; we have read what each of the four main vendors publishes, starting with Microsoft Copilot.
The files that carry the most risk
| service | what the record contains | why it bites |
|---|---|---|
| Children’s social care | assessments, referrals, family history | special category data and children |
| Adult social care | diagnoses, care plans, financial assessments | health data, and the person may lack capacity |
| Homelessness | reasons for leaving accommodation, fleeing violence | safety of the person, not only their privacy |
| Revenues and benefits | income, debt, enforcement | financial harm, and it reaches the whole household |
| Licensing and enforcement | allegations, statements, criminal matters | Article 10 data on convictions and offences |
The registers nobody else has
There is a second reason council data behaves differently, and it has nothing to do with sensitivity: a council can identify people that other organisations cannot.
Between the Council Tax account, the electoral register, the housing tenancy and the property address, a council can put a name to a household with a confidence that a bank or a retailer would envy. It knows who lives where, who else lives there, and what they pay. Data that would be genuinely ambiguous coming out of a private company is rarely ambiguous coming out of a council.
That matters when someone argues a prompt was fine because it had no name in it. In a council, a postcode plus a household size plus a service is very often enough. The ICO says the same of documents generally: whether a file with the names taken out is still personal data depends on what is left in it.
What a single case note contains
Take one ordinary line from a housing file: a name, a date of birth, an address with a postcode, an NHS number, a mobile number and one sentence about why the tenancy is at risk. That is six identifiers and a piece of special category data in about thirty words. Taking the identifiers out does not touch that sentence, and special category detail left in a prompt still needs the council’s second condition.
An officer who pastes that into a public AI tool is sharing a person, not a document. And the question the law asks next is not whether the tool was useful, but whether the council agreed to that disclosure. Where a note like it comes from adult social care, the Caldicott Principles apply as well, and what they ask before a paste into AI is worked through for NHS staff.
The law that binds a council today, and the section that binds the officer
There is no AI statute to look up. The Artificial Intelligence (Regulation) Bill was a private member’s bill sponsored by Lord Holmes of Richmond and introduced in the House of Lords in March 2025. Parliament’s own page for it, last updated on 30 April 2026, shows it never reached Royal Assent. What binds a council is the law it already had.
That is good news for anyone trying to write a policy this month. There is no new regime to interpret and no regulator to get to know: there is UK GDPR, the Data Protection Act 2018 and the ICO, all of which a council has been living with since 2018.
UK GDPR, and the articles that do the work
Five provisions carry almost all of the weight in an AI question, and none of them mentions AI. An officer who can hold these five in their head does not need to know anything else about the subject.
| article | what it requires | what it means in a council |
|---|---|---|
| 5(1)(c) minimisation | only what the purpose needs | most prompts fail here first |
| 6 lawful basis | usually public task for a council | public task does not stretch to convenience |
| 9 special categories | a second condition on top of Article 6 | social care records are full of them |
| 28 processors | a written contract binding the supplier | a consumer account has not got one |
| 33 breach reporting | 72 hours to tell the ICO where there is risk | the clock starts when the council knows |
The ICO’s own guidance on AI and data protection, last updated on 15 March 2023, works through all of these in detail. It is written for people building systems rather than for people typing into one, but the articles do not change depending on which end you are at.
What does change is where the decision sits. In a procurement, all five questions get asked by somebody whose job it is. In a chat window at half past four, they get asked by whoever is at the keyboard, or not at all.
Section 170, and the defence a written policy creates
Most council guidance leaves this out, and it changes how an officer reads the question.
Section 170 of the Data Protection Act 2018 makes it an offence for a person, knowingly or recklessly, to obtain or disclose personal data without the consent of the controller. The verb that matters in a council is the second one. The controller is the council. The person is the officer.
Pasting a resident’s details into a service the council has not approved is, on the face of the section, a disclosure. Whether it is an offence turns on the officer’s state of mind and on the defences in section 170(3), the most important of which is that the person acted in the reasonable belief that they would have had the controller’s consent if the controller had known.
That defence is exactly what a written AI policy supplies or withholds. With a clear policy, an officer who stays inside it has a reasonable belief. With no policy at all, nobody knows what the council would have consented to, including the council.
What the ICO does when a council’s systems are misused
The ICO does prosecute in local government, and the most recent council case is worth reading for its scale rather than its subject. In July 2026 it brought proceedings against an employee of Herefordshire Council in the Children and Young People directorate, who over four days accessed around 490 records and downloaded 94 documents.
That case was about unauthorised access, not about AI, and it was charged under section 1 of the Computer Misuse Act 1990 rather than under section 170. It is here for one reason: it shows what the ICO does when a council’s own systems are used in a way the council did not sanction, and it shows how four days of misuse can end in a criminal conviction.
There is no UK AI Act, and the EU one almost never reaches you
The EU AI Act binds organisations outside the Union only where the output of the system is used in the Union. A council in Doncaster or Dumfries will rarely be in that position. Our guide to whether the EU AI Act applies to you outside the EU sets out who it does reach, and when.
Automated decisions: what the Data (Use and Access) Act 2025 changed
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and the ICO states that all of its provisions affecting data protection law are now in force. Its section 80 replaced Article 22 of UK GDPR with a new set, Articles 22A to 22D, and the change matters to councils more than to most organisations.
It matters more because councils take significant decisions about individuals all day: a benefit, a placement, a licence, a priority band. It is also the one place where UK law and the EU AI Act point at the same problem from different angles, so a council reading the European material by mistake will come away with the wrong obligations.
Meaningful human involvement is the test
Article 22A(1)(a) defines a decision as based solely on automated processing “if there is no meaningful human involvement in the taking of the decision”. Article 22A(2) adds that when you assess that, you must consider how far the decision was reached by profiling.
The old blanket restriction is gone. Under Article 22B, the hard prohibition now applies to significant decisions taken on special category data, unless explicit consent or a substantial public interest condition applies. Outside that, a solely automated significant decision is permitted, with safeguards.
For a council this cuts both ways. It removes a barrier to automating routine determinations. It also means the question shifts entirely onto whether the human in the loop is doing anything. An officer who reads a generated recommendation and clicks approve is the case Article 22A was written to catch.
The four safeguards a council owes the resident
Where a significant decision is solely automated, Article 22C requires safeguards covering four things, and each of them already exists somewhere in a council under a different name.
| what Article 22C requires | where a council already has it |
|---|---|
| Information about the decision | the decision letter |
| The ability to make representations | the review or reconsideration stage |
| Human intervention by the controller | the officer review |
| The ability to contest the decision | the complaints procedure, then the Ombudsman |
The work therefore lies less in building something new than in making sure the letter that goes out actually says an automated process was involved, which most standard letters do not, and that the review offered is a real one rather than the same system running twice.
The DPIA, and when a council has no choice about it
Article 35(1) of UK GDPR requires a data protection impact assessment where processing is likely to result in a high risk. The ICO’s screening guidance treats innovative technology as one indicator, and defines it to include “the novel application of existing technologies (including AI)”.
A DPIA is not paperwork for its own sake here. It records what data the tool sees, on what basis and with what safeguards, and it is the first thing the ICO asks for. It is also what a sensible AI policy points staff at when they ask whether a new tool is allowed yet.
Innovative technology plus one more criterion
The ICO is precise about how that indicator works. A DPIA is required where innovative technology is combined with any of the criteria from the European guidelines. Those criteria include evaluation or scoring, sensitive data, data processed on a large scale, and data about vulnerable individuals.
In most council services, that criterion is vulnerable people
The ICO names processing data about people who may be deemed vulnerable as one of the triggering criteria. Children’s social care, adult social care, homelessness, SEND and safeguarding are all built on exactly that population.
So for a large part of what a council does, the combination is automatic: AI plus vulnerable people equals a mandatory DPIA. Far from a cautious reading, that is what the screening test says when you apply it to a council’s caseload.
| what you are doing | DPIA likely required? |
|---|---|
| Summarising a social care assessment with AI | yes, innovative technology plus vulnerable individuals |
| Scoring rent arrears cases for contact | yes, innovative technology plus evaluation or scoring |
| Drafting a press release with AI, no personal data | no, there is no personal data to assess |
| Transcribing a public committee meeting | depends on who speaks and what is said about individuals |
Transparency: the ATRS, and why it does not bind your council
The Algorithmic Transparency Recording Standard is the UK’s public register of algorithmic tools in government, run by the Government Digital Service. Its hub page was last updated on 8 May 2025.
Councils tend to hear about it from someone else and assume it is another return to file. The scope question is worth getting right first. It is also a different kind of transparency from the one the EU AI Act imposes, which is about labelling generated content rather than registering tools.
Who is in scope, and who is only encouraged
GDS states that the ATRS “is mandatory for all government departments, and for arm’s-length bodies which deliver public or frontline services, or directly interact with the general public”, and that it “remains recommended by the Data Standards Authority for use in the broader public sector”.
Councils are the broader public sector. The AI Playbook says the same thing in the other direction: the standard “is not a requirement for all arm’s length bodies and other public sector institutions yet, but we still encourage you to use it”.
That word “yet” is the one to plan around. A scope and exemptions policy was published in December 2024 and the Blueprint for Modern Digital Government of January 2025 committed to building on the standard. A council that starts recording now is not gold-plating.
What the AI Playbook asks for instead
Whatever the register requires, one line of Principle 7 of the AI Playbook applies to any council with a chatbot on its website: you should clearly identify any automated response to the public, and the example given is a chatbot reply that says so in words.
That sentence costs nothing and it is the single most visible thing a council can do. It is also the piece of transparency a resident actually encounters, as against a register entry that almost nobody outside the sector will ever open.
The official guidance, and where it comes from
There is more UK guidance on AI in local government than most councils realise, and it is scattered across two governments and a membership body. None of it binds a council in the way a statute does, and all of it is what a regulator would expect a competent council to have read.
Four documents do the work. It is worth knowing which one answers which question before spending an afternoon in the wrong one.
| document | who it is written for | the question it answers |
|---|---|---|
| AI Playbook for the UK Government | civil servants | what may go into a public tool at all |
| Responsibly buying AI | councils in England | what to ask a supplier |
| State of the sector: AI | the sector | what other councils are doing |
| Scotland’s AI strategy 2026 to 2031 | Scottish public bodies | the Scottish policy frame |
The AI Playbook, and the two lines that matter at a desk
The AI Playbook for the UK Government was published by the Government Digital Service on 10 February 2025. It runs to 118 pages and ten principles, and it replaced the Generative AI Framework for HMG of January 2024. It is addressed to civil servants, so it does not formally bind a council, but two of its lines are the clearest statement of the problem in any UK document.
On public tools, it says that with a publicly available commercial application “you cannot easily control the data input to the models: you must rely on educating users on what data they can and cannot enter into these services”. That is an admission, from the centre of government, that training is the only control it has.
And then it draws a hard line anyway: “When using public AI applications, you must not enter official information unless it has been published or is cleared for publication.”
The transcription problem, stated twice
The Playbook is unusually firm about meeting notetakers. It says that transcription tools from outside suppliers “present a serious risk of data leakage as they silently upload meeting recordings to an AI service”, and that organisers should state up front that their use is not allowed.
Meanwhile, the Ministry of Housing, Communities and Local Government set up a team called Local AI on 16 March 2026 to work with councils, and one of its stated deliveries is “a new transcription tool” for staff who deal with the public, built on the Incubator for AI’s Minute tool.
Those two positions are not in conflict, and reading them together gives a council its policy in one sentence: transcription is fine, as long as nobody brings their own transcriber.
If the transcriber a council already owns is the one built into its own tenant, the terms behind it are worth reading before anybody relies on them: we have gone through what Microsoft says about Copilot and where the Microsoft 365 boundary stops.
Scotland, Wales and Northern Ireland are not the same country here
“UK councils” is a phrase that hides four legal settlements. If your council is not in England, some of the guidance above is the wrong guidance.
| nation | the information regime | where the AI guidance comes from |
|---|---|---|
| England | FOIA 2000, ICO | GDS, MHCLG Local AI, LGA |
| Scotland | FOISA 2002, Scottish Information Commissioner | Scottish Government, plus its AI strategy 2026 to 2031 |
| Wales | FOIA 2000, ICO | Welsh Government and the WLGA |
| Northern Ireland | FOIA 2000, ICO | NI Executive departments and NILGA |
Data protection is reserved, so UK GDPR and the ICO apply everywhere. Freedom of information is not: Scottish councils answer under the Freedom of Information (Scotland) Act 2002 to the Scottish Information Commissioner, not to the ICO. Scotland’s Artificial Intelligence strategy 2026 to 2031 was published on 20 March 2026 and is the document a Scottish council should be reading alongside the UK material, not instead of the ICO’s.
Northern Ireland’s eleven councils are also a genuinely different animal. The official list of their responsibilities on nidirect covers waste, planning, environmental health, licensing, registration of births, deaths and marriages, and leisure. Education and social services are not on it, so the files with the highest risk described earlier largely sit elsewhere.
Which tools, and which accounts
Most of the risk in a council lies not in the tool but in the account it is signed in to. The same product can be a properly contracted processor or a consumer service with no contract at all, and the difference is invisible on screen.
We have gone through the four products councils actually have, using each vendor’s own published pages rather than their sales pages.
| product | the question that decides it | our guide |
|---|---|---|
| Microsoft Copilot | work account or personal account, and which of the four Copilots | Is Microsoft Copilot safe for confidential information? |
| ChatGPT | who the controller is for a UK user, and what the training switch does not stop | Does ChatGPT share your data? |
| Claude | consumer plan or commercial terms, and the retention clocks | Does Claude train on your data? |
| Gemini | the human reviewers, and what survives deletion | Does Gemini use your data? |
The same logo, two different legal arrangements
For a council, it comes down to this: a work account inside the council’s own tenant, with the council’s data protection terms behind it, is a different thing in law from the same brand used on a personal account. The interface is identical. The contract is not.
Article 28 of UK GDPR requires that where a supplier processes personal data on the council’s behalf, it does so under a contract that binds it to the council’s instructions, to confidentiality, to security measures, to restrictions on subcontracting and to deletion at the end. A consumer chat account has none of that. It has terms of service between the vendor and the individual who signed up, and the council is not a party to them.
So when an officer uses a personal account on a council laptop, three things are true at once. The council has no processor contract. The council cannot retrieve what was sent. And the officer, not the council, agreed to the terms. That is the situation section 170 is written for, and no amount of goodwill fixes it after the fact.
The device is not the control
Councils that have thought about this tend to reach for device management: lock the browser down, block the domain, done. It helps, but it is not enough.
The phone in the officer’s pocket is not managed. A resident’s details read off a screen and typed into a personal handset leave no trace on any council system, so a council that has blocked the domain and stopped there has bought itself silence rather than safety.
The control the AI Playbook actually names is the other one: educating users on what data they can and cannot enter, and then giving them something approved that is good enough that they do not go looking elsewhere.
The staff policy, and what it has to say to be worth anything
Under half of the councils in the LGA survey had a specific AI policy. Just under half were managing AI risk with existing policies, which in practice means an acceptable use policy written before any of this existed.
A general acceptable use policy does not answer the question an officer has. “Use council systems appropriately” does not tell anyone whether a redacted assessment can go into Copilot.
The five lines that settle a section 170 question
A policy that is worth writing answers five questions in plain words.
| the line | what it has to say |
|---|---|
| Which tools are approved | named, and on which account |
| What may never be entered | case files, safeguarding records, anything with an NHS or National Insurance number |
| What may be entered | a policy of nothing but prohibitions is ignored by lunchtime |
| Who to ask when it is unclear | a person’s name, not a mailbox |
| What to do afterwards | the first hour, if someone has already sent something |
If your council has none of this, our AI policy template is a starting point to adapt rather than adopt. What matters is less the document than an officer being able to say what the council would have consented to.
Councillors are not covered by it
This is the gap almost every council policy has, and it is not a technicality.
The ICO states that elected representatives are separate controllers for work carried out for the purpose of being an elected representative, such as constituency casework. A councillor working a ward case is not acting under the council’s controllership, is not covered by the council’s policy, and is very often not on the council’s tenant.
So the officer is governed and the member is not, while both are handling the same resident’s problem. A council that briefs its staff and not its members has covered the smaller half of the risk.
What to ask a supplier before a public contract
Councils buy AI far more often than they build it. Of the LGA’s respondents who were using or exploring AI, 68 per cent were paying external suppliers for AI tools or were in the process of procuring them. That makes procurement the real control point, and it is the one place where UK local government has a genuinely good, genuinely specific document of its own.
It is also the moment when a council has the most leverage it will ever have. Before signature, a supplier will answer questions it will not answer afterwards, and a clause that is trivial to insert now is impossible to insert in year three.
The guide four bodies wrote together
“Responsibly buying AI” was published on 16 April 2025 by the LGA with the Information Commissioner’s Office, the Equality and Human Rights Commission and the London Office of Technology and Innovation. It is written for councils in England and it is organised by role: commissioners, procurement officers, contract owners, and a set of questions to put to bidders.
Its frame is the one central government guidance misses. It covers the Public Sector Equality Duty under section 149 of the Equality Act 2010 alongside data protection, because a council buying a system that sorts people has two duties, not one.
The clause that survives a contract variation
The guide makes one point that is easy to miss and expensive to learn late: the assessment runs through the life of the contract rather than standing as a gate at the start, “including where AI is introduced during a contract variation, upgrades to products, or when new features are added”.
That is how AI arrives in most councils: not through a procurement, but through a supplier switching on a feature in a system the council bought in 2019. A contract that does not require notice of that has no control over it at all. The same question belongs in the council’s insurance paperwork, where underwriters have started asking about AI use directly, and in the supplier questionnaire the council sends out.
When a resident asks: transparency, subject access and FOI
A council is asked to explain itself for a living. That is the part of this that has no equivalent in the private sector, and the part most AI guidance ignores entirely.
A commercial organisation that sends data somewhere awkward can usually keep the awkwardness internal. A council cannot: the same resident has a statutory right to ask what it holds about them, and a separate statutory right to ask what it holds full stop. What each vendor keeps and for how long therefore stops being a procurement detail and becomes an accountability problem, which is why we went through what ChatGPT keeps and what Anthropic keeps from their own pages.
| what the resident asks for | the law | what it reaches | what the council needs |
|---|---|---|---|
| Subject access | Article 15 UK GDPR | their personal data in a prompt, wherever the council holds it | a way to search its AI tools |
| Freedom of information | FOIA 2000, s. 3(2); FOISA 2002 in Scotland | information held by another person on the council’s behalf | to know which arrangement it has before anyone asks |
| Human review | Article 22C UK GDPR | a significant decision that was solely automated | a review that is more than the same system running twice |
Complaints go to the ICO, except freedom of information in Scotland, which goes to the Scottish Information Commissioner.
A subject access request reaches the prompt
If an officer typed a resident’s circumstances into a tool, that text is that resident’s personal data, and a subject access request under Article 15 of UK GDPR covers it wherever the council holds it. “It was in a chat window” is not a category the law recognises.
The practical consequence is a retrieval problem. A council that cannot search its AI tools cannot answer a subject access request completely, and an incomplete response is itself something the ICO takes complaints about.
Held on behalf of the authority
Freedom of information adds a second reach. Section 3(2) of the Freedom of Information Act 2000 provides that information is held by a public authority if it is held by the authority, or if it is “held by another person on behalf of the authority”.
Whether a given prompt sits on the council’s side of that line depends on the arrangement: a tool inside the council’s tenant under a processor contract is a very different answer from a consumer account nobody agreed to. A council should know which of those it has before someone asks, because it will have twenty working days to answer, and the answer will be on the record.
What to tell a resident, before they ask
Three things belong in a council’s privacy notice and in the standard letters, and none of them requires a legal opinion:
- that AI assists with some drafting and administration, in general terms;
- that decisions affecting the resident are taken by a person, if that is true;
- how to ask for a human review, which under Article 22C is a right where a significant decision was solely automated.
A worked example: answering a complaint without the case leaving
Here is the ordinary case. A housing officer has a complaint to answer, twenty minutes, and a case note in front of them. They want help structuring the reply, not help deciding it.
Nothing about that is unreasonable, and a policy that answers it with “no” will be ignored. What a council can do instead is separate the part of the task that needs a person from the part that needs the resident’s identity, and only the first of those has to travel. The account the tool runs on decides how much that separation is worth.
What the officer sees, and what should leave
Here is the case note line by line, with what should reach the model beside it:
| what is on the officer’s screen | what should leave the machine |
|---|---|
| Ms Amara Boateng, d.o.b. 14 March 1979 | [PERSON_1], [BIRTH_DATE_1] |
| 42 Threadneedle Rise, Manchester M12 4QT | [ADDRESS_1] |
| NHS number: 999 456 0018 | [REFERENCE_1] |
| Mobile: 07700 900 512 | [PHONE_1] |
| a.boateng@example.com | [EMAIL_1] |
| “reports damp in the rear bedroom since June” | unchanged, because it is the actual question |
Those are the labels Nonimo uses in English.
It has already happened: what to do in the first hour
Assume somebody in your council has already put a resident’s details into an assistant. With 83 per cent of responding councils using or exploring generative AI and 41 per cent holding a specific policy for it, that is the reasonable planning assumption rather than a worst case. The question is what happens next, and most councils have never been asked it.
The instinct in the moment is to delete the conversation and hope. That instinct is the thing to design out, because it destroys the only record of what was sent and it leaves the council unable to answer the question a regulator will ask first, which is what left and where it went.
The four questions that decide whether this is a breach
Article 4(12) of UK GDPR defines a personal data breach to include an unauthorised disclosure of personal data. Whether a paste qualifies turns on four things, in this order:
- Was there personal data in it? Not “was there a name in it”. A case reference plus a service plus a street can identify a person perfectly well in a council.
- Where did it go? An approved tool inside the council’s tenant, under a processor contract, is a different answer from a personal account on a consumer plan.
- Was it authorised? This is where the written policy earns its keep, and where its absence is the council’s problem rather than the officer’s.
- Is there a risk to the person? Article 33 turns on risk to rights and freedoms, and a homelessness record with an address in it is not the same as a parking appeal.
The 72 hour clock, and who starts it
If the answer comes out as a reportable breach, Article 33 gives the council 72 hours from becoming aware of it to tell the ICO. “Becoming aware” is the council becoming aware, not the data protection officer finishing an investigation.
| in the first hour | who |
|---|---|
| Write down what was typed, into what, and when | the officer, before they forget |
| Stop using that tool for that case | the officer |
| Tell the data protection officer, in writing | the line manager |
| Check whether the account can delete the conversation, and do it | the DPO with IT |
| Note the clock start time | the DPO |
The first row is the one that gets skipped and the one that matters most. An officer who deletes the chat and says nothing has removed the evidence and started nothing, and if the council finds out three weeks later it will be dealing with an attempt to hide it as well as the disclosure itself.
For the general version of this assessment, we have written about whether putting client data into ChatGPT is a data breach, and the AI policy template has a section for exactly this moment.
What a tool fixes, and what it does not
A policy, a DPIA, a sentence on a chatbot and a line in a decision letter cost staff time and no money, and they are what a regulator would look for first.
Software only becomes relevant after that, for the part of the work that survives the policy: the genuine free text an officer needs help with, on a case that genuinely cannot leave the council. Here is what our own tool does about that part, and what it does not.
What Nonimo does
Nonimo is a Mac and Windows application that sits between the person and the assistant. When you use it, it replaces identifiers with labels before the text leaves the machine, and puts the real values back in the answer. The matching runs on the computer, the mapping stays there, and the policy is set by IT rather than by each user.
It covers the UK identifiers that appear on council paper, and each British number it takes out, from the NHS number to the National Insurance number, is shown to the officer, who can undo the change before anything is sent.
One thing to be precise about, because the name invites the wrong reading: this is pseudonymisation, not anonymisation. The mapping is reversible and encrypted on the user’s own machine, which is what makes the answer usable. Under Article 4(1)(5) of UK GDPR that is still personal data, and it still needs a lawful basis.
A council that wants it on every desk has IT roll out the browser extension by policy, with the admin dashboard and the monthly report on top. What the app keeps on the officer’s computer is set out on Nonimo’s security page.
When the answer is not to buy anything
For a good number of councils reading this, the right next step is already within their own gift.
If your council has no written AI policy, write one before you buy anything, because a policy is what turns an officer’s decision into a defensible one under section 170(3). If you have not done a DPIA on a tool that is already in use in a service dealing with vulnerable people, do that next. If your chatbot does not tell residents it is a chatbot, fix the sentence.
Those three cost staff time and nothing else, and they move a council further than any purchase would. A tool earns its place only once the question has narrowed to the residue: the free text that an officer legitimately needs help with, on a case that legitimately cannot leave.
If the conclusion for your council this year is “not yet, and here is the policy instead”, that is a perfectly good conclusion, and this guide is willing to reach it, as are the other guides on AI and personal data.
Sources
Algorithmic Transparency Recording Standard Hub, Government Digital Service, published 5 January 2023, last updated 8 May 2025. Scope: mandatory for government departments and for arm’s length bodies delivering public or frontline services; recommended for the broader public sector. gov.uk
ATRS record repository, GOV.UK. 152 records held and 18 matching a keyword search for “council” on 20 September 2026; Barnet Ami Chatbot, Camden RentSense and Bristol City Council NEET model all published 28 January 2025. gov.uk
AI Playbook for the UK Government, Government Digital Service, 10 February 2025, 118 pages. Source of the ten principles, of the ATRS scope statement in Principle 7, of the chatbot disclosure example, of “you must not enter official information unless it has been published or is cleared for publication”, and of the passage on meeting transcription tools from outside suppliers. gov.uk
State of the sector: Artificial intelligence, 2025 update, Local Government Association, published 2 June 2025, fieldwork December 2024 to February 2025, a third of English councils responding. Source of 95 per cent using or exploring, 83 / 28 / 20 per cent by type, 84 / 44 / 31 per cent by function, 41 per cent with a specific AI policy and 49 per cent relying on existing ones, and of the risk ranking. local.gov.uk
Responsibly buying AI, Local Government Association with the ICO, the EHRC and LOTI, 16 April 2025. Source of the procurement questions organised by role, of the Public Sector Equality Duty framing and of the requirement to reassess at contract variation, upgrade or new feature. local.gov.uk
Artificial Intelligence Hub, Local Government Association. The sector’s own collection of guidance and case studies for councils. local.gov.uk
Introducing Local AI, MHCLG Digital blog, 16 March 2026. Source for the existence and remit of the Local AI team, and for the transcription tool for staff who deal with the public, based on i.AI’s Minute. mhclgdigital.blog.gov.uk
Data (Use and Access) Act 2025, section 80, legislation.gov.uk. Substitutes Articles 22A to 22D for Article 22 of UK GDPR: the meaningful human involvement test, the restriction on special category data, and the four safeguards. legislation.gov.uk
Data (Use and Access) Act 2025, ICO. Royal Assent 19 June 2025, and the statement that all provisions affecting data protection law are now in force. ico.org.uk
When do we need to do a DPIA?, ICO. Source of the innovative technology indicator including AI, of the requirement that it be combined with another criterion, and of vulnerable individuals as one of those criteria. ico.org.uk
Guidance on AI and data protection, ICO, updated 15 March 2023. The regulator’s detailed treatment of the UK GDPR articles in an AI context. ico.org.uk
Data Protection Act 2018, section 170, legislation.gov.uk. The offence of knowingly or recklessly obtaining or disclosing personal data without the controller’s consent, and the reasonable belief defence in subsection (3). legislation.gov.uk
Freedom of Information Act 2000, section 3, legislation.gov.uk. Section 3(2): information is held by a public authority if held by the authority, or held by another person on behalf of the authority. legislation.gov.uk
Equality Act 2010, section 149, legislation.gov.uk. The Public Sector Equality Duty, which applies to a council buying a system that sorts people. legislation.gov.uk
Herefordshire employee handed suspended sentence for illegally accessing personal information, ICO, 21 July 2026. Approximately 490 records accessed and 94 documents downloaded over four days in a Children and Young People directorate; guilty plea under section 1 of the Computer Misuse Act 1990. ico.org.uk
Controllers, joint controllers and processors, ICO. Source of the statement that elected representatives are separate controllers for constituency casework. ico.org.uk
Scotland’s Artificial Intelligence strategy 2026-2031, Scottish Government, published 20 March 2026, ISBN 9781807750046. gov.scot
Freedom of Information (Scotland) Act 2002, Schedule 1, legislation.gov.uk. Entry 21 lists a council constituted by section 2 of the Local Government etc. (Scotland) Act 1994, which is why Scottish councils answer under FOISA rather than FOIA. legislation.gov.uk
Local councils, nidirect. The official list of the eleven Northern Ireland councils and of their service responsibilities, which does not include education or social services. nidirect.gov.uk
Artificial Intelligence (Regulation) Bill [HL], UK Parliament. Private member’s bill sponsored by Lord Holmes of Richmond, introduced in the Lords in March 2025; the page, last updated 30 April 2026, shows it did not reach Royal Assent. bills.parliament.uk
Guidelines for secure AI system development, NCSC. The UK technical authority’s baseline for organisations deploying AI systems. ncsc.gov.uk
Common questions
Can council staff use ChatGPT at work?
Only within whatever the council has decided, and on a tool the council controls, which is the starting point for any use of AI in local government. The government's AI Playbook of 10 February 2025 is blunt about public tools: you must not enter official information unless it has been published or cleared for publication.
Is it illegal to put resident data into an AI tool?
It can be. Section 170 of the Data Protection Act 2018 makes it an offence to disclose personal data knowingly or recklessly without the controller's consent. A written policy is what gives an officer the reasonable belief defence in section 170(3).
Do councils have to publish their AI tools on the ATRS?
No. GDS states the Algorithmic Transparency Recording Standard is mandatory for government departments and for arm's length bodies delivering public services. For the wider public sector, including councils, it is recommended rather than required.
How many councils are using AI?
In the LGA's survey of English councils, run from December 2024 to February 2025, 95 per cent of respondents were using or exploring AI. Only a third of councils answered, so the figure describes that group rather than the whole sector.
Does a council need a DPIA before using an AI tool?
Usually yes. The ICO treats AI as innovative technology, which requires a data protection impact assessment when combined with another criterion on the ICO's list. Processing data about vulnerable people is one of those criteria, and most council services qualify.
Can a resident ask what the council typed into an AI tool?
They can ask. A subject access request under UK GDPR covers their personal data wherever the council holds it, and section 3(2) of the Freedom of Information Act 2000 covers information held by another person on the council's behalf.
Does the EU AI Act apply to UK councils?
Almost never. It reaches organisations outside the EU only where the output of the system is used in the Union, which is unusual for a council serving a UK area. UK GDPR and the ICO are what bind a council today.
Are councillors covered by the council's AI policy?
Not for ward casework. The ICO states that elected representatives are separate controllers for work done as an elected representative, so a councillor handling constituency casework is not covered by the council's own arrangements.
What should a council ask an AI supplier?
Start with the questions the LGA, ICO, EHRC and LOTI published together on 16 April 2025 in Responsibly buying AI. They cover the Public Sector Equality Duty and data protection, and include a set written specifically for bidders.