RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026Start here · 100 retrospective records ↗
AI Use Field Guide

Start here / Privacy & safety

Privacy & safety / Start-here guide · Start-here guide · prepared 16 September 2026

A UK regulator separates data accuracy from AI accuracy

ICO guidance on AI and data protection sets a lawful-basis test and a distinct meaning for accuracy that a chatbot's fluency can hide.

ico.org.ukprimary record

How do we ensure lawfulness in AI?

Document
undated document
Event
no single event
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

Start here

Someone reading that a chatbot can hallucinate might reasonably ask why that is legal if the company also has to comply with a data protection law that requires accuracy. The UK's Information Commissioner's Office answers that directly, by separating two things that sound identical but are not: accuracy as a data protection principle, and accuracy as an AI performance measure.

What the documents say

The ICO's chapter on accuracy and statistical accuracy, part of its wider AI and data protection guidance as retrieved on 16 September 2026, states that data protection accuracy 'requires you to ensure that personal data is accurate and, where necessary, kept up to date,' while statistical accuracy in AI 'refers to how often an AI system guesses the correct answer, measured against correctly labelled test data.' The guidance is explicit these are separate obligations: a system can be well calibrated statistically while still producing a factually wrong output about a real person, and the data protection duty applies regardless. On what allows an organisation to use personal data at all, the ICO's lawfulness chapter sets a three-part legitimate-interest test, covering a genuine interest, necessity of the processing, and a documented balancing against a person's rights, worked through with an example of a firm training a machine learning model.

Check this

The check the guidance points toward is a naming exercise: when a company says a model is highly accurate, ask which sense is meant. A benchmark score describing how often a system's guesses match a test set is a statistical-accuracy claim. Whether a specific answer about a named person is correct is a data-protection accuracy question, and the guidance states that improving the first does not resolve the second. If an AI tool states something false about you or someone you know, treat that as a distinct, correctable data protection issue, not an unavoidable side effect of the technology.

What holds and what fails

The two-accuracy distinction holds as a durable way to read any AI accuracy claim, because it names exactly what a benchmark number does and does not cover. It does not resolve how an organisation should apply the legitimate-interest balancing test in a specific case; that assessment is fact-specific and the guidance describes criteria rather than a fixed answer. This guidance is also presented as under active review following changes to UK law, so treat the current text as a snapshot rather than a permanent statement.

  • Ask which kind of accuracy a vendor means the next time you see the word in marketing copy.
  • If an AI tool states something false about a real person, treat it as a correctable data issue.
  • Check the ICO page's own note on whether a chapter is currently under revision.

Two words that look the same on a page, accurate and accurate, are doing different jobs in these documents. Separating them keeps a fluent wrong answer from being mistaken for a solved data protection question.

Sources & reading trail

How do we ensure lawfulness in AI? ↗

Sets out the legitimate-interest test, covering legitimate interest, necessity and balancing, that organisations must document to use personal data for training an AI model.

Source published: Not established · Retrieved: 16 September 2026

What do we need to know about accuracy and statistical accuracy? ↗

Distinguishes data-protection accuracy from statistical accuracy and states that improving one does not satisfy the other.

Source published: Not established · Retrieved: 16 September 2026

Guidance on AI and data protection ↗

The guidance hub organising the ICO's AI and data-protection chapters, as retrieved.

Source published: Not established · Retrieved: 16 September 2026

Documentation, regulator guidance and studies establish the record; the checks and the boundary are AI Use Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.