Question to the Department for Science, Innovation & Technology:
To ask His Majesty's Government what steps they are taking to ensure that all workplaces in the United Kingdom use of generative AI tools, including chatbots and content-generation systems, is limited to technologies which are compliant with cybersecurity and data protection regulations.
DSIT supports the use of AI tools in UK workplaces and has established voluntary baseline cyber security requirements for all AI systems and models. The Government’s Code of Practice for the Cyber Security of AI, published in 2025, identifies requirements for securing AI systems with an implementation guide to support adoption. DSIT officials are working with AI companies, and sectors adopting AI, to raise awareness and uptake of the Code. The ICO has issued employment practices and guidance on AI and data protection regulations to employers and has the authority to investigate and impose penalties for non-compliance.