Can you answer a subject access request about AI processing?
Only if you can search everywhere your AI puts personal data, and most organisations cannot yet do that.
Under UK GDPR Article 15, an individual can demand the personal data an organisation holds about them, and that reaches AI processing directly: prompts and outputs that contain their data, profiles and inferences drawn about them, and meaningful information about the logic of any solely automated decision with legal or similarly significant effects. The deadline is one calendar month, extendable by two for complex requests. Most organisations, honestly assessed, cannot yet search their full AI estate well enough to answer a request like this accurately.
The question matters because AI has spread personal data processing across places most subject access processes were never built to search: vendor logs, embeddings, generated documents, and chat histories inside tools nobody added to the data map.
Where does personal data actually end up inside an AI system?
In more places than a traditional records search covers. Prompts typed by staff often contain a customer's name, case details or health information without anyone flagging it as a data protection event at the time. Outputs generated by the system can restate, summarise or infer personal data even when the prompt did not explicitly request it. Embeddings derived from documents containing personal data carry the same personal data in numerical form. And profiles or scores an AI system builds about a person, even informally, are personal data if they relate to an identifiable individual.
Can you search a vendor's logs for one person's prompts?
Often not well, which is the practical problem. Many AI services log prompts and outputs on the vendor's infrastructure under retention and access terms the customer did not fully design, and searching that log for everything relating to one named individual, across every member of staff who might have typed their name, is frequently impossible through the tools the vendor exposes. A gap between what a vendor logs and what the customer can actually query is a gap in the customer's own Article 15 capability, not the vendor's problem to solve.
Does the DUAA 2025 change what has to be disclosed about automated decisions?
It reworks parts of the UK automated-decision regime in stages following royal assent in June 2025, and organisations relying on solely automated decision-making with significant effects should track the commencement of those changes closely. The detail of that reform sits outside this article's scope, but the underlying duty to give meaningful information about the logic of such decisions is not new, and an AI system that cannot explain its own logic in terms a subject access response can use is a gap regardless of which version of the regime applies.
How do you separate one requester's data from everyone else's in an AI record?
This is the third-party redaction problem, and AI makes it harder because outputs frequently blend several people's data in one generated document, a summary, a report, a case note. Answering a request accurately means being able to isolate the requester's own data within that blend without simply handing over the whole document, which requires the underlying record to be structured enough to filter, not just a wall of unstructured text.
What happens if you simply do not log AI activity?
The duty does not disappear, only the ability to comply with it does. Choosing not to log does not remove the Article 15 obligation, it removes the evidence that would let the organisation answer accurately, which converts a data protection compliance gap into a credibility problem the moment a request or a complaint arrives. Regulators are unlikely to treat the absence of logs as a defence; if anything it reads as a design choice that avoided accountability.
What does a genuinely answerable AI estate look like?
One boundary, one sealed and queryable record, one place to search. An organisation that can point to a single system of record for everything its AI touched, prompts, outputs, embeddings, decisions, can answer where does this person's data appear inside our AI processing with a query rather than an investigation. That is the practical difference between an organisation that treats Article 15 as achievable and one that treats it as a risk to manage after the fact.
“A firm that cannot enumerate where its AI put someone's data cannot answer Article 15 accurately, whatever its policy says.”
How a single sealed record makes an AI estate searchable and answerable is set out at /sovereign-ai, and the film at /film shows the interface in operation.
Frequently asked questions
Does a subject access request cover what an AI chatbot said about someone, not just what they typed?
Yes. Article 15 reaches personal data an organisation holds about the requester regardless of whether it originated in their own input or was generated as output, so AI-generated content about a person is in scope alongside their own prompts.
How long do we have to respond to a subject access request that involves AI processing?
One calendar month from receipt as standard, extendable by a further two months for complex or numerous requests, with the requester informed of the extension and the reason within the first month. AI complexity, such as needing to search multiple systems, can be a legitimate reason for extension if genuinely necessary.
Do we have to disclose the logic of an automated decision an AI system made?
Where a decision is made solely by automated means and has legal or similarly significant effects on the individual, UK GDPR requires meaningful information about the logic involved, alongside the significance and envisaged consequences, and the Data (Use and Access) Act 2025 is reworking parts of this regime in stages.
Can we redact other people's data from an AI-generated document before disclosure?
Yes, and doing so accurately requires the underlying record to be structured enough to identify and separate different individuals' data within a generated document, rather than treating the whole output as one indivisible block belonging only to the requester.
Is it a defence to say our AI vendor does not let us search prompt logs?
No. The obligation sits with the data controller regardless of vendor tooling limitations, so an inability to search vendor logs is a capability gap to close, not a reason the request can go unanswered.