The ICO’s AI Action Plan – AI and Biometrics

Monday 14th September 2026

Fast adoption of Artificial Intelligence (AI) by organisations has the potential to drive advancements across the private sector, science, public services and the economy more widely.

However, the responsible use of AI is a pressing concern given its potential impact on individual rights and freedoms, proprietary interests, and privacy.

Organisations have increasingly deployed AI across their operations, from customer experience to security and supply chain optimisation. Effective governance and compliance, however, remain essential to staying on the right side of the law.

The Information Commissioner’s Office (ICO)’s AI and Biometrics Strategy signals a response of stronger regulatory expectations for organisations developing, deploying or using AI and biometric technologies across the public and private sectors, with a core component of the strategy being the implementation of a Code of Practice on AI and automated decision-making (ADM).

Organisations should not overlook this: trust, compliance, and accountability are the foundation of robust data protection frameworks and underpin long-term organisational integrity. Fines for breaching data protection laws can reach up to four per cent of annual global turnover or £17.5 million, whichever is greater, and many other pieces of legislation will also apply to the development and deployment of AI and biometric solutions. With AI and novel technologies in the spotlight, it is more important than ever for organisations to ensure compliance before adopting these technologies.

AI and Biometrics

The EU AI Act defines AI as ‘a machine-based system designed to operate with varying levels of autonomy, and which may adapt after deployment. For explicit or implicit objectives, it infers from the inputs it receives how to generate outputs, such as predictions, content, recommendations or decisions, that can influence physical or virtual environments.’

Biometric data is ‘personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person.’ Examples include fingerprints, voice data and facial images. Where biometric data is processed for the purpose of uniquely identifying an individual, it becomes special category data, meaning organisations must satisfy additional legal requirements before processing it.

One area receiving increasing regulatory attention is facial recognition technology (FRT), which uses digital images of a person’s face to identify or verify their identity. For example, employee access systems that use facial scans rather than key cards for monitoring and site access.

The ICO’s role is focused on the use of personal data, meaning any information relating to an identified or identifiable individual. This strategy deals specifically with the use of personal data within AI and biometric systems. This will include how organisations collect, use and govern personal information when developing, procuring or deploying these technologies.

What does the ICO want to achieve with this strategy?

The ICO knows that these technologies are already in use in a wide range of industries, but the main target of their strategy is to prioritise these key aspects: clarity, fairness and governance:

Clarity

People want to know how AI will affect them, especially if important decisions are being made about them. Often, people do not have clarity on how AI, ADM and FRT affects them. As part of this strategy, the ICO’s research has shown that people expect transparency, meaningful explanations to facilitate informed decisions and a clear notification where these are being used.

Fairness

There is a concern that AI systems and biometric technologies can amplify bias because they may be trained on inaccurate and unrepresentative information. The ICO wishes to tackle this because research shows that there is a significant risk of bias. For example, FRT has produced inaccurate results in retail settings, such as incorrectly identifying individuals as having previously shoplifted. Similarly with ADM, in recruitment these systems may discriminate against individuals whose backgrounds were not represented in the training data. It goes to the very core of ensuring data processing is in line with protecting individuals from unfair automated outcomes.

Governance

The ICO attributes public confidence in AI technologies to how organisations effectively deal with issues when they arise. Organisations need to understand that any errors arising from AI affects the lives of individuals, therefore they want to know what safeguards are in place and want to have the ability to challenge outcomes when harm arises. Individuals will be less likely to trace back decisions to a human controller with the growth of agentic AI. Governance is an important aspect for organisations to consider when implementing these technologies as that enables you to remain accountable and offer appropriate redress.

How to demonstrate compliance with data protection laws

The ICO’s guidance should be used as a prompt for organisations to implement the recommended practices into their operations.

  • Understand how you are using data: understand what data is being fed to AI systems, whether it is personal data or special category data, and how the AI system uses it to produce outputs. The best way to do this is to have a data map in place showing what systems are used with a key risk assessment for each.
  • Assess any high-risk uses: is ADM producing discrimination in hiring, are FRT models trained on biased data which may misidentify individuals?
  • Strengthen governance: organisations should risk assess any AI deployment, understand what personal data is being processed, carry out a DPIA where appropriate, ensure suitable contractual protections are in place with providers, map the processing activities involved and adopt an AI policy or governance framework to support responsible use.
  • Enhance human oversight: automated outputs should never be used to make decisions or used in operations without a human verifying its accuracy.
  • Clear communication: provide transparency to all stakeholders about the role of AI, especially customers and employees.

Next Steps – The ICO’s “Action Plan”

The ICO commits itself to ensuring organisations can develop and use AI and biometric technologies with confidence, while safeguarding individuals. ICO’s action plan is to give organisations certainty on how to use these technologies, therefore they will develop a statutory Code of Practice which provides clear guidance on transparency, bias and redress.

The ICO will set clear expectations about how ADM should be used in a responsible way, particularly in recruitment. In this context, the automated screening or filtering of job applications without meaningful human involvement may improve efficiency, but it can also create risks where decisions are based on biased or inaccurate training data, potentially resulting in candidates being unfairly excluded from opportunities. Regulatory expectations will be published to hold employers accountable if they fail to respect people’s rights.

Developers of AI models will be asked to provide assurances that personal information used in training models is safeguarded, to prevent misuse of data. The ICO will be able to ask developers to strengthen compliance where they fall short of the required standards.

The ICO’s “Action Plan” should not be seen as a crackdown on emerging AI and biometric technologies but a warning about the risks which accompany the rapid development and adoption of AI. The core objective is to promote economic growth and foster innovation while ensuring there are robust safeguards for individuals whose personal data is being used.

For more information about this or advice, please contact one of our experts.

To stay up to date with the latest developments in data protection and privacy law, sign up to receive our quarterly Privacy Snapshot.