Automation

The legal side of A.I.: what I learned while automating small businesses

You want A.I. to take the boring work off your plate. The tools make it feel effortless. The law didn't get easier at the same rate. This is what I learned about the legal side of A.I. while building automation for small businesses.

This article is not legal advice. It's a record of my own research and experience as an automation consultant, shared for general information only. If you're implementing A.I. in your business, engage a qualified legal practitioner before acting on anything here. I accept no liability for any action taken, or not taken, on the basis of this article.

You want A.I. to take the boring work off your plate. Answering the same enquiry for the fortieth time, chasing leads, drafting copy, sorting a spreadsheet. The tools make it feel effortless. Sign up, connect your data, watch it go.

The law didn't get easier at the same rate. That's the uncomfortable part nobody mentions on Instagram, or wherever you get your news from.

I build automation for small businesses, and over the past few months I've been deep in the legal side of it: ICO guidance, the marketing rules, the copyright cases working through the courts. Partly for my own protection, mostly for my clients'. This post is what stuck. It's my experience as a practitioner, not legal advice, and I've linked every claim to the relevant governing body so you can check it yourself rather than take my word for it.

I'm going to go through the pitfalls I fell into along the way so you can avoid doing it yourself. Because, if you get it wrong and someone takes offence, you're leaving yourself open to some pretty significant legal action.

"It's publicly available, surely I can use it?"

Finding information off the internet at scale has often been an issue. Many people and organisations claim they can do this for you by 'scraping LinkedIn profiles' or looking at Google Maps data, but the truth is, from what I've found, not strictly legal.

This one causes more trouble than anything else, and I believed it myself until I read the guidance properly.

A name and work email found on a company website or LinkedIn is still personal data under UK GDPR the moment you collect and store it. Public availability doesn't switch the law off. You still need a lawful basis for holding it, and the person still has rights over it. The ICO's UK GDPR guidance covers this in plain English.

The related myth is that "B2B data isn't personal data". Company data isn't. The people inside companies are. info@company.com is corporate; jane.smith@company.com is personal data. And a sole trader's business data is personal data in its entirety, because legally the person and the business are the same.

If any of your automations collect, score or store information about identifiable people, this applies to you.

When the A.I. speaks for your business, you own what it says

A.I. chatbots and other written documentation - I'm thinking about blog posts here too, are the voice of your business. So if you're doing this and not validating what it says then you're, again, leaving yourself open.

In 2024 a tribunal ordered Air Canada to honour a bereavement discount its chatbot invented. The airline argued the chatbot was responsible for its own words. The tribunal disagreed.

You're probably not an airline, but the principle scales down. If a chatbot on your site quotes a price, promises a refund or gives advice a customer relies on, that's your business talking.

Meanwhile, read the terms of the A.I. tools you use. OpenAI's terms, for example, cap their liability at what you paid them in the last 12 months, or $100 if that's greater. So if a hallucinated output costs you a client or a contract, the provider's exposure is pocket change and yours is the full loss. The fix sits in your own paperwork: disclaimers where appropriate, human review before outputs reach customers, and insurance you've actually confirmed covers A.I.-related claims (many professional indemnity policies quietly exclude them).

The trap almost nobody has heard of

If you do any cold outreach by email, please pay attention to this. I will guess there's a good chance you aren't aware of what I'm about to say.

The marketing rules (PECR, enforced by the ICO) treat limited companies and sole traders differently. Cold-emailing a limited company is lawful if you identify yourself and offer an opt-out. Cold-emailing a sole trader without prior consent is unlawful. Full stop.

Here's why that bites: in most lead lists, sole traders look identical to companies. A trading name, a website, a work email. If your automation can't tell the difference, some slice of your outreach is breaking the law and you won't know which slice.

Two things I now treat as non-negotiable in any outreach automation. First, verify legal form against Companies House rather than guessing from a website, and if a record can't be verified, it doesn't get contacted. Second, screen any cold calling against the TPS and Corporate TPS registers.

The penalties stopped being trivial, too. Recent legislation aligned PECR fines with GDPR levels, up to £17.5m or 4% of turnover, replacing the old £500k cap.

Ouch. Not something you want to get stung by.

Who owns what your A.I. makes?

The next issue relates to ownership of the actual thing your A.I. creates. We could be talking about a widget or an app or a document.

Two questions here, and they also cause confusion.

Can you protect it? The US Copyright Office refused to register artwork created entirely by A.I., and the courts backed them: no human author, no copyright (US Copyright Office A.I. guidance). The practical takeaway for your marketing and products is that the more human creativity you put into shaping the output, the stronger your claim to own it.

Could it infringe someone else's rights? The Getty Images case against Stability AI is still live on appeal (August 2026), and the UK government has been consulting on copyright and A.I., with the direction of travel pointing toward licensing and away from unrestricted scraping. Asking a tool for something "in the style of" a living artist is exactly where I'd be careful.

Your obligation: tell people where you got their details from

This one surprised me most. If you collect someone's data from anywhere other than the person themselves (a scraper, a register, a bought list), UK GDPR requires you to actively tell them, within a month or at first contact. A privacy policy sitting on your website doesn't count on its own; the notice has to reach the person. The ICO calls this the right to be informed, and it has named invisible processing as a priority area for A.I.-era enforcement.

The practical fix is small: a "where we got your details" line with a link in your first message. But it has to be designed in. Bolting it on later might mean re-engineering your sequences.

My take on this is this: open rates of emails are likely to be no more than 50% (based on my anecdotal evidence). So half won't even open the email you send them.

Next there'll be a portion of people who won't read the content past the heading or first paragraph - let's call this another 50% (25% of the total you've emailed).

Then there'll be a drop off in the number of people who read all the way to the bottom - no more than 10%. In which case, you've only got 2.5% of your entire list who are actually scrolling to the bottom of the page. So if your notice is at the bottom of the page, most won't even see that you got their details from a particular source.

Ultimately, it's not too much of a chore, and it shouldn't affect things much - it'll likely never get read anyway: this legislation shouldn't be a problem to adhere to.

The free-tool problem: you might be training someone else's model

Here's the question I ask every business owner, and almost nobody can answer it: when you paste something into ChatGPT, where does it go?

If you're on a free or standard consumer plan, the honest answer for several major tools is that your conversations may be used to train future models, and some may be reviewed by humans as part of that process. OpenAI documents this in its data usage policy, and it's the default unless you switch it off. Most small businesses I speak to are on exactly these plans, because free is free.

Now think about what actually gets pasted in on a normal working day. A client's email thread you want summarised. A draft proposal with your pricing in it. A spreadsheet of customer names. Once that content has gone into a tool that trains on inputs, you've disclosed it outside your business, and if it contains personal data you've done so without a lawful basis, a processor agreement or a mention in your privacy notice. The ICO's guidance on A.I. and data protection is clear that using these tools doesn't suspend your obligations.

Three habits fix most of it. Treat any free A.I. tool as if you were posting to a public forum, and keep client and personal data out of it. If A.I. is doing real work in your business, pay for a business tier or use the API, where training on your data is off by default, then check the setting and screenshot it so you can evidence your due diligence. And give your team and freelancers a written rule about what they may paste into their own accounts, because their free-tier habits create your data breach.

Five questions to ask about your own setup

I now run every automation project, my own included, through a version of these questions. They help me to ensure I'm building things correctly and am not making more problems for myself along the way.

  1. If an A.I. tool gets something wrong in front of a customer, do your terms say who carries that risk, and does a human check outputs before they land?
  2. Do you know exactly what personal or client information goes into each A.I. tool you use, and have you checked where that provider stores and processes it?
  3. Could you show, if asked, that the people in your CRM know you have their data and where you got it?
  4. Can your outreach tell a limited company from a sole trader, with evidence rather than a guess?
  5. Do your team and freelancers have any rules about what they're allowed to paste into ChatGPT?

If you can answer all five with a straight yes, genuinely, you're ahead of almost every small business I've looked at. Most owners I speak to get to about question two before the room goes quiet.

That silence is normal. None of this is taught anywhere, the guidance is scattered across a dozen regulator websites, and you have a business to run. It doesn't make you reckless. It makes you someone who hasn't had a reason to look yet.

What I'd suggest doing next

You could work through the ICO guidance linked above yourself. It's genuinely readable, and if you have the time, do it.

If you'd rather shortcut it, this is the work I do. While I'm not a legal professional, the information is out there for you to read and digest yourself. I would, however, always ensure you get it checked before putting your reputation on your interpretation.

If you would like assistance, I offer a free discovery call. It's a half hour free, and jargon-free conversation. If you can tell me how your business runs and where you're using (or planning to use) A.I. and automation, I'll tell you where the gaps I've described above show up in your setup, and what closing them might involve.

If there's an automation worth building, I can build it with the guardrails designed in from the start, because retrofitting compliance costs more than doing it right the first time.

Worst case, you leave the call with a clearer picture of your risk than you had before, for free.

Want to read into it more?

Everything above traces back to a governing body or primary source. The ones worth bookmarking:

I build automations for SMEs, I'm not a solicitor, and nothing here is legal advice. It's a record of what I've learned doing this work, shared so you can ask better questions, and I accept no liability for decisions made on the strength of it. For contract wording or anything where real money is at stake, engage a qualified legal practitioner. Details above were accurate to the best of my knowledge at the time of writing; this area moves quickly, so use the links to verify the current position.

Ready to transform your business?

Book a FREE discovery call and get a clear roadmap for your next stage of growth.

Finding the root cause, then fixing it. Lake District based, working across Cumbria and North Lancashire.

© 2026 Xtreme Exposures Ltd

Privacy Policy