Freedom of information request
Data-breaches resulting from the use of artificial intelligence (AI) tools
- Freedom of information request reference
- CAS-324018
- Request resolved
Request
I am requesting information relating to personal data incidents and GDPR breaches that have occurred as a result of the use of artificial intelligence (AI) tools within your organisation. For the purposes of this request, this includes incidents arising from or connected to:
- AI chatbots (including but not limited to ChatGPT, Google Gemini, Microsoft Copilot, or any equivalent large language model tool)
- AI tools that were not formally authorised or approved for use by your department or organisation
- AI tools used in an unauthorised manner — that is, tools which may have been approved in principle but were used outside their permitted scope, purpose, or in contravention of departmental policy
- AI tools designed to summarise, transcribe, or record meetings or communications (including, for example, Otter.ai, Fireflies.ai, Microsoft Copilot meeting summaries, or equivalent tools)
- Any other AI system or tool through which personal data or special category data was entered, processed, shared, or transmitted without appropriate authorisation or adequate data protection safeguards.
- The time period covered by this request is 1 January 2022 up to and including the date on which this request is processed by your organisation.
Information requested:
For each personal data incident of GDPR breach falling within the scope set out above, please provide the following:
Nature of the data involved
- Whether the data was personal data or special category data (as defined under the UK GDPR and the Data Protection Act 2018)
- A general description of the category or type of data involved (for example: names, contact details, health or medical information, financial data, immigration status, criminal records, etc.
Number of individuals affected
- The number of data subjects whose personal data was involved in or affected by the incident
- Date and Time of the Incident
- The date and time at which the incident occurred, or - where the exact time is not recorded - the approximate date
Reporting to the Information Commissioner's Office (ICO)
- Whether the incident was reported to the Information Commissioner's Office (ICO)
- Where applicable, the date and time the incident was reported to the ICO.
Outcome and remedies
- The outcome of any internal investigation into the incident
- Any remedial, corrective, or preventive action taken by your organisation as a result
- A copy of any documentation recording the outcome or remedies applied, including any written decisions, reports, or correspondence with the ICO arising from the breach.
Notification of affected individuals
- Whether the individuals directly affected by the breach were informed of the incident
- If so, the date on which notification was provided to them.
Confidential and sensitive information
In addition to the personal data incidents described above, I also request information on the broader use of AI tools in circumstances where confidential or sensitive government information was entered into or processed by such tools, regardless of whether this constituted a formally recorded personal data breach. When referring to confidential or sensitive government information I am referring to any documentation or information not intended or not cleared for publication.
Specifically, please provide:
Number of recorded incidents
- The total number of occasions on which confidential or sensitive government information was entered into, uploaded to, or otherwise processed by an AI tool during the period 1 January 2022 to the date of processing
- A breakdown of these incidents by year, where this information is held
Classification or sensitivity of information involved
- Whether any of the information involved was classified under the Government Security Classifications (GSC) policy (i.e. official, official-sensitive, secret, or top secret)
- The number of incidents involving each classification level, where recorded
- Whether any incidents involved information subject to legal professional privilege, commercially sensitive data, or information relating to national security
Type of AI tool
- Whether the AI tool used was an externally hosted or third-party tool (i.e. not hosted on government or departmental infrastructure)
- Whether the AI tool was authorised for use by the department at the time of the incident
- The name or category of AI tool involved, where this information is held and can be disclosed
Policy and guidance
- Whether your organisation had a policy or guidance in place governing the use of AI tools in relation to confidential or sensitive information at the time the incidents occurred
- If so, the date from which such a policy was in place
- Whether any policy or guidance has been updated or introduced as a direct result of incidents of this nature
Outcome and action taken
- Whether any formal investigation, disciplinary action, or security review was carried out as a result of any such incident
- A summary of the outcomes or actions taken, in aggregate where individual details cannot be disclosed
Where the volume of incidents permits, I would be grateful if the information could be provided in a structured tabular format, with each incident recorded as a separate entry. Any supporting documentation requested at question 5 above may be provided as attachments or annexes.
If any part of this request is refused, I ask that you please identify the specific exemption(s) under the Freedom of Information Act 2000 being relied upon, and confirm whether a partial disclosure can be made in respect of the remaining information.
Outcome
Information not held.
Response
I can confirm that The National Archives does not hold this information.
There were nil incidents of AI tool data breaches at The National Archives up to this date.