PDP Data Protection and AI Conference 2026: What Regulators, Lawyers, and AI Practitioners Are Actually Saying
In brief: The PDP Data Protection and AI Conference 2026, hosted by Shoosmiths at their London offices, brought together regulators, lawyers, and AI practitioners to address the practical realities of governing AI in 2026. The day covered the ICO’s current priorities, agentic AI liability, DPIAs for LLMs, AI copyright disputes, and bias mitigation. What follows are the key takeaways for GCs, CTOs, and anyone responsible for deploying AI systems in a business.
What Are the ICO’s Current Priorities for AI Governance?
Dr Declan McDowell-Naylor, Group Manager for AI and Biometrics at the Information Commissioner’s Office, opened the day with a keynote that managed to be both historically grounded and practically sharp. He quoted John von Neumann writing in 1955 about automation to make the point that every generation believes it is witnessing a uniquely transformative moment in technology. The conceptual framework von Neumann described, sweeping automation entering accounting, research, and workplace processes, remains remarkably familiar today.
The substance, however, was firmly in 2026. McDowell-Naylor identified three key trends shaping the ICO’s approach.
First, transparencyaround first-party data use for model fine-tuning: organisations are increasingly using their own customer data to train or adapt AI systems, and a lack of transparency about this risks undermining public trust.
Second, downstreamandcumulative risks: common failures include assessing AI models in isolation rather than considering how they will be used at scale, combined with other tools, or exposed to vulnerable users.
Third, cross-border regulatory divergence: while harmonisation across jurisdictions is unlikely, the ICO sees potential for convergence around foundational principles of fairness, transparency, and accountability.
The headline announcement was the forthcoming AI and ADM Code of Practice. The statutory instrument has been made in UK Parliament. This Code will give organisations clear, practical guidance on deploying AI and automated decision making responsibly under data protection law, including changes from the Data Use and Access Act. McDowell-Naylor would not preview the contents, but indicated it could cover third-party assessments, supply chain accountability, and technical governance approaches.
On automated decision making specifically, the ICO’s "Recruitment Rewired" report (March 2026) found that 16 of 30 employers reviewed were within scope of Article 22. Human involvement alone does not disapply Article 22 if the human is effectively rubber-stamping AI outputs. The ICO’s challenge to employers was direct: either apply the ADM safeguards or adapt your processes to ensure meaningful human involvement in each decision about each candidate.
Dr Declan McDowell-Naylor, Group Manager for AI and Biometrics at the Information Commissioner’s Office
How Does Agentic AI Change Governance and Liability?
Sarah Reynolds, Partner at Shoosmiths, delivered a session on agentic AI that cut through the noise with a clear thesis:
Agentic AI does not just automate outputs. It delegates judgment.
The governance question for organisations is no longer "is our AI compliant?" but "what have we delegated authority to do, and how do we govern that delegation?"
Reynolds drew on OpenAI’s white paper to argue that agentic risk emerges from system design and deployment, not the model itself. The same underlying model can produce radically different risk profiles depending on the permissions, constraints, and monitoring wrapped around it. An AI agent authorised to transfer funds is a fundamentally different legal proposition from one that drafts a summary for human review, even if both run on the same model.
The legal analysis was thorough. On consumer law, she noted that retailer terms are already being updated to state that transactions made by an AI agent are considered authorised by the customer, even while acknowledging the agent may not act exactly as intended. Under UK consumer protection law (now the Digital Markets, Competition and Consumers Act 2024), you cannot simply contract out of statutory protections or rely on clever wording if the outcome is misleading or unfair.
On product liability, the new EU Product Liability Directive treats software and AI systems as products for strict liability purposes. In an agentic context, harm can be triggered by a chain of autonomous actions rather than a single human decision. On negligence, the Hedley Byrne v Heller doctrine on assumption of responsibility maps uncomfortably well onto AI deployments that are framed as tailored, authoritative, and designed to be relied upon.
Reynolds proposed four governance primitives for organisations deploying agentic AI:
clear human accountability for harms,
action ledgers capturing what the agent actually did (not just design intent),
capability boundaries with approval gates for consequential actions, and
reversibility with shutdown mechanisms.
What Are the Most Common Failures in DPIAs for LLMs?
The workshop on DPIAs for large language models was one of the most practically useful sessions of the day. The presenters identified five systemic failures.
First, sequencing: organisations often try to answer the Article 22 question first (is this automated decision making?) and assume that if the answer is no, the DPIA question falls away. The ICO is clear: start with Article 35. Most LLM deployments will involve processing likely to result in high risk, regardless of whether Article 22 applies.
Second, scoping: DPIAs are frequently scoped too narrowly around the model itself rather than the full lifecycle of how data enters, how prompts are designed, how outputs are generated, how humans rely on those outputs, and how the system is monitored over time. Scope creep happens quietly and without reassessment.
Third, lawful basis: LLM deployments usually involve multiple distinct processing activities (prompting, output generation, training data use), and each needs its own lawful basis analysis. Treating the lawful basis as a single decision covering the whole system is a common oversimplification.
Fourth, necessity: organisations frequently justify LLM deployment with arguments like "it will save money" or "everyone else is doing it." The DPIA requires demonstrating that there is no less intrusive alternative, not that the technology is popular.
Fifth, vendor reliance: bringing in a third-party LLM does not shift accountability. The ICO cautions against relying on vendor documentation as a substitute for your own assessment. A vendor DPIA tells you what they want to tell you, not necessarily what you need to know.
What Are the Key AI Copyright Risks for Businesses?
The IP session covered the ongoing Getty Images v Stability AI litigation and the broader risks of using generative AI outputs commercially. The core risks fall into three categories: data provenance (was the training data properly licensed?), output infringement (does the AI-generated output resemble protected third-party IP?), and confidentiality (are prompts containing proprietary information being fed into public models?).
In the UK, there is currently no text and data mining exemption for AI training, unlike the EU and US. The government consulted on this approximately a year ago and, in what can only be described as a strategic punt, concluded it was too difficult and shelved it. This leaves UK businesses in a position where scraping third-party content to train models without a licence remains legally exposed.
The practical demonstration of generating a branded deodorant through Copilot illustrated the risks vividly: the AI-generated brand name "Zen Guard" turned out to be similar to an existing trademark registration, and may have been influenced by the existing "Right Guard" brand in the training data. The lesson: generative AI outputs need IP clearance before commercial use, not after.
Can AI Bias Be Eliminated?
The closing panel on AI bias was the most candid session of the day. Summer Zhao from Santander described the lifecycle approach her team takes: collecting balanced data, avoiding demographic features, penalising biased outputs during training, monitoring model performance for drift, and maintaining human review throughout.
Mark Round from Problem Connecting was blunter. Large language models have learned from everything we have ever written, and everything we have ever written contains bias. Take the word "doctor," subtract "man," add "woman," and the model returns "nurse." That is not a bug. It is a statistical reflection of the corpus of human text. De-biasing these models, he argued, is like performing brain surgery on a system we stopped understanding at GPT-2.
His conclusion: do not try to fix the AI. Build structures around it. Measure the bias in outputs. Design guardrails that catch biased decisions before they reach people. Create governance frameworks that treat bias as an ongoing operational risk, not a one-off technical fix. The parallel he drew was to human societies: we have built functioning institutions out of biased human beings who try not to be biased. We can do the same with AI systems.
Zhao also spoke about the Women in AI community she founded at Santander, now over 2,000 members globally. Her point was simple: if you want AI that serves everyone in the population equally, you need more balanced teams building it, from researchers to decision makers to developers.
Alice Wallbank, Shoosmiths
Mark Round, QinetiQ Plc
Summer Zhao, Santander UK
Key Takeaways for GCs, CTOs, and In-House Counsel
The ICO’s forthcoming AI and ADM Code of Practice will be the practical governance playbook for UK businesses. Engage with the consultation.
Agentic AI requires system-level governance, not just enterprise policies. Enterprise governance tells you "we value transparency." System-level governance tells you whether this agent has permission to execute a refund.
DPIAs for LLMs should start with Article 35, not Article 22. Most deployments will trigger the requirement.
AI copyright risk in the UK remains unresolved. No text and data mining exemption exists. Scraping without a licence is legally exposed.
AI bias is a structural problem. Guardrails, monitoring, and governance frameworks are the answer, not attempts to de-bias the models themselves.
Vendor-provided DPIAs are not a substitute for your own assessment.
Rory O’Keeffe is the founder of RMOK Legal, a City of London commercial law practice specialising in AI governance, technology contracts, and fractional general counsel services. He is an SCL-accredited Leading IT Lawyer, AI Committee member of the Society for Computers and Law, and author of AI Advantage (2025).
FAQs
-
The ICO is focused on transparency in first-party data use for AI model fine-tuning, downstream and cumulative AI risks, cross-border regulatory cooperation, and developing a statutory Code of Practice on AI and automated decision making.
-
A forthcoming statutory code that will provide practical guidance on deploying AI and automated decision making responsibly under data protection law, including changes from the Data Use and Access Act.
-
Scoping too narrowly around the model, treating lawful basis as a single decision, poor sequencing of Article 35 and Article 22 analysis, inadequate necessity justification, and over-reliance on vendor-provided DPIAs.

