Who Owns AI-Generated Personal Information?

Navigating Special Cases in Personal Data for DSARs
Summary 

AI-generated information about individuals creates new challenges for privacy and DSAR compliance. While individuals may not technically “own” AI-generated outputs, they may still have rights over personal data and inferences relating to them. Organisations should therefore ensure their AI systems, data governance and DSAR processes work together to provide appropriate transparency, access and accountability under the UK GDPR. 

Who Owns AI-Generated Personal Information? 

Artificial Intelligence (AI) can generate profiles, predictions, risk scores and behavioural insights about individuals using personal data. This raises an important question: who owns AI-generated personal information—the individual, the organisation, or the AI provider? Under the UK data-protection framework, the focus is less on ownership and more on whether the information constitutes personal data and what rights individuals have over its processing. 

Under the UK GDPR, individuals have rights regarding their personal data, including the right of access. Through a Data Subject Access Request (DSAR), an individual can ask an organisation for access to their personal data and information about how it is being processed. Where AI creates profiles or inferences about an identifiable individual, organisations should assess whether this information falls within the scope of the individual’s data-protection rights. 

For example, if a bank uses AI to analyse a customer’s transactions and generate a prediction about their financial behaviour, the organisation should understand what personal data was used, why it was processed, and how the resulting information is managed. The fact that information was generated by AI does not automatically place it outside UK GDPR considerations.