UK AI data regulation is back on the policy table. The Department for Science, Innovation and Technology launched a call for evidence on 15 July examining how personal and non-personal data regulation interacts with AI and other data-intensive technologies.

The government is asking businesses and other stakeholders where existing legal, technical and governance arrangements work, where uncertainty remains and whether guidance, targeted changes or more substantial reform may be required.

For British companies trying to deploy AI, the exercise goes directly to a problem that is often less visible than model performance: whether organisations can legally, securely and practically use the data needed to make AI useful.

AI deployment is becoming a data-governance problem

The first wave of generative AI adoption was largely driven by general-purpose tools. The next phase is more difficult.

Companies want AI systems that can search internal documents, analyse customer interactions, automate workflows and make recommendations based on proprietary business information. That requires access to data that may be sensitive, fragmented, contractually restricted or covered by overlapping governance policies.

The challenge is especially acute in finance, healthcare, professional services and other regulated sectors. Even when a use case is technically possible, legal and compliance teams may be reluctant to approve it without clear rules on data reuse, model training, retention, explainability and third-party access — questions the new UK data rules only partly settle.

The UK is trying to make regulation a competitive advantage

Britain's AI strategy has generally avoided creating a single horizontal AI regulator. Instead, the government has relied on existing regulators and sector rules while trying to encourage adoption and investment.

That approach is now being tested by the pace of commercial AI development. If companies believe data law is too uncertain, they may delay projects or choose lower-risk applications with limited commercial impact. If rules are loosened too aggressively, the UK risks weakening trust and creating new privacy or consumer-protection problems.

The policy opportunity is to reduce ambiguity without removing safeguards. Clearer guidance on lawful data reuse, anonymisation, synthetic data and cross-organisational data sharing could be more valuable to many businesses than a broad promise of deregulation.

Smaller companies may have the most to gain

Large enterprises can afford specialist legal teams, privacy counsel and internal AI governance functions. Startups and mid-sized companies often cannot.

That creates a hidden compliance advantage for incumbents. A regulation may technically apply equally to all firms while imposing a much greater relative burden on a smaller business.

If the government can standardise acceptable approaches to common AI data questions, it could reduce the cost of experimentation for smaller companies without changing the underlying rights of individuals. This is one reason regulatory sandboxes and approved technical standards are gaining attention across the UK's technology policy.

What business leaders should watch

The call for evidence does not itself change the law. Its importance lies in the questions being asked.

Executives should watch whether the government moves toward more explicit rules for data reuse, whether regulators align their interpretation of AI-related data responsibilities and whether businesses receive practical safe-harbour-style guidance for lower-risk applications.

The deeper issue is strategic. Britain wants to be one of the fastest AI-adopting major economies. That ambition will depend not only on access to models and computing power, but on whether companies can confidently use their own information to build useful systems.