Consultations

IB1 response to DSIT’s Data regulation in the age of AI and other data-intensive technologies call for evidence 

EG
Emma Gray 10 September 2026

This is Icebreaker One’s response to DSIT’s Call for evidence: Data regulation in the age of AI and other data-intensive technologies. It can be published openly.

Please note that throughout this consultation, Icebreaker One uses the terms Open, Shared and Closed data as defined here.

If you have any questions about our submission or require clarifications please do not hesitate to contact us via policy@ib1.org. We have omitted questions which we did not answer. 

Thank you for considering our submission.

Call for Evidence response:

Theme 1 – Accessing and using data

Question 1: What are the challenges you face, or can foresee emerging, when accessing and using personal and non-personal data when developing or using AI and data‑intensive technologies? 

Icebreaker One (IB1) is an independent, nonprofit organisation working to make data sharing trusted, interoperable and scalable across sectors and markets. We support the development of  data governance, trust frameworks, and policy mechanisms that enable AI and make it possible to deploy other data-intensive technologies responsibly. 

IB1 convenes organisations across energy, finance, water, transport and agriculture to co-design and implement governance, trust frameworks and technical infrastructure required for secure, operable data flow. Our approach is grounded in practical implementation: defining data purposes and rights, establishing roles and responsibilities, creating common standards, assuring participants and data, and making data flows auditable. We do not access or use large amounts of data ourselves, but we help design and operate ecosystems that enable economy-scale data sharing.

The IB1 NOVA principles – Networked, Open, Verifiable Architecture – guide our approach to data sharing governance and associated responsibilities. This approach recognises that trusted data sharing requires more than technical infrastructure: it requires coordinated governance, clear rights and responsibilities, interoperable systems, and transparent, adaptive rules. In many use cases, relevant data is distributed across multiple organisations and across sector boundaries. Unlocking value and investment depends on trusted interactions between many market participants with different characteristics. NOVA guides us to consider architecture supporting trusted, permissioned and auditable data flows in a manner that reduces friction, supports open participation, and encourages scalable reuse of data and data-sharing infrastructure. It provides the foundation for aligning technical, legal, policy and commercial requirements needed to turn fragmented energy data into a trusted, usable and investable resource within a thriving wider digital ecosystem.

IB1 sees data governance as an enabling layer for AI. Our work has demonstrated that clear, machine-readable rules, trusted identities, provenance, permissions and assurance can reduce friction while strengthening protections. This is exemplified by Project Perseus: the UK’s first cross-sector Smart Data Scheme that enables assured smart meter data to flow from energy providers through carbon accounting platforms to financial services, supporting SMEs to access green finance. Perseus embodies the importance of permissions, identity, provenance, licensing and data rights needed to operate data flows across organisational boundaries. 

Chapter 3 on Responsible AI from Stanford HAI’s 2026 AI Index Report makes clear that AI and data governance is lagging behind AI capabilities, and the gap is widening. AI, and agentic AI in particular, requires tighter definition on elements of data protection than are typically used by organisations in their policies, and the policies must be capable of being exercised reliably by machines in real-time to govern AI workflows. The majority of UK organisations lack the legal, governance and technical expertise to design, implement and monitor such policies, with Trustmarque reporting in 2025 that 93% of UK organisations use AI, but only 7% have fully embedded governance. Standards in this area are at best emerging, and typically based on security, rather than data protection, concerns. 

Organisational immaturity with data governance is compounded when data is shared and combined across data ecosystems. Data users need clear signals to establish which data they can access, whether the data is trusted, what rights they have to use the data and how those permissions and responsibilities evolve once data flows across data ecosystems. Poorly defined rights can both stifle legitimate use of data and open the door to data misuse.

Question 2: Regarding data protection, how do you assess and justify the lawful use of personal data in these contexts?

Lawful use of personal data in AI and other data-intensive technologies is not fundamentally different from lawful data use elsewhere. IB1’s approach treats data governance, communications and stakeholder engagement as interconnected parts of responsible data use. We establish clear purposes, make them accessible to data subjects, and maintain trust as data is reused, shared, and applied in various environments. This is why communication is an inherent part of data governance that is always incorporated in our work: members and external stakeholders define how the Scheme is communicated to participants, regulators, and the public. This manages the ongoing narrative that sustains engagement and maintains trust over time as data use, technology and stakeholder expectations evolve.

IB1 supports the integrated framing of AI governance and data governance. It is important to note that personal data is not the only type of data subject to data protection regulation. For example, business smart data enabled by the Data Use and Access Act, and intellectual property protection frameworks, must also be taken into account. 

Question 3: How appropriate are the data protection framework’s definitions/obligations outlined above and are they likely to remain fit for purpose as data-intensive technologies continue to evolve?

No response 

Theme 2 – Data quality, accuracy, and downstream impacts 

Question 1: What approaches do you take in practice to assess and ensure the quality and accuracy of data, including personal data, and what challenges do you encounter?

No response

Question 2: How do you assess and manage fairness and impacts on individuals when using AI or other data‑intensive technologies?

No response

Question 3: How appropriate are the data protection framework’s principles of fairness and accuracy when applied to data-intensive technologies, and are they likely to remain fit for purpose as these technologies continue to evolve?

No response

Theme 3 – Governing data use across organisations 

Question 1: How do you collect and then govern data across supply chains or between organisations in practice, including allocating responsibility and enabling data sharing or access?

IB1 distinguishes between data collection/processing and data governance. In trusted data sharing ecosystems, the organisation(s) that  govern how data is accessed, shared, reused or managed are often not the ones that collect, hold or process the data itself. Effective data governance depends on clear, agreed and enforceable rules for how data can be used and shared in compliance with existing regulatory frameworks.

Our work defining and operating schemes and trust frameworks provides a practical example of this approach. A scheme defines what can be shared, why, by whom, how, and what protections exist. This gives organisations confidence that they can process and share data within the trust framework that underpins the scheme. While this can be achieved through bilateral data sharing agreements between participants, a more scalable and interoperable approach is to enact multilateral scheme-wide agreements that anchor the scheme rules and governance processes for all participants. IB1 has developed formal machine-readable definitions of scheme rules that are used by scheme participants to develop and maintain compliant, assured data services within the scheme.

A mutual understanding of the purpose for data sharing is key to governing data sharing. It underpins assurance, participant credentials, access control (including for agentic use), licensing and liability, and ensures clear scheme boundaries. Human users, and their AI agents, need a clear understanding of whether they can access the data, are allowed to use it for their intended purposes, and can rely on it for those purposes. Without clarity of purposes, these determinations are hard or impossible to make. Work is ongoing at IB1 to develop decision-making approaches and supporting information such that machines can determine reliably whether their intended purpose and processing aligns with the rights the organisations that operate the machines hold to the data.

The NOVA principles outlined in our response to Theme 1 Question 1 provide a structure for considering whether the architecture and governance of an ecosystem support networked, open and verifiable data exchange. Schemes and Trust Frameworks provide a mechanism for achieving this at scale while approaches like NOVA principles help assess whether the resulting ecosystem is capable of supporting trustworthy, interoperable and sustainable data sharing. 

Question 2: How do you approach automated decision-making, and will this approach remain fit-for-purpose as technology advances?

Automated decision making requires three layers of governance: 

  1. Definition & design: establishing clarity of the purpose for the decision, the data requirements for it, and the methodology to reach the decision.
  2. Operation: applying the implementation of the design to a specific decision, ensuring the data on-hand is adequate, enacting guardrails, flagging or escalating anomalies, logging reasoning and decisions
  3. Monitoring: ensuring that operation is delivering the design, enabling audit, supporting investigation and resolution of disputes, informing improvements, building trust.

The Perseus smart meter data scheme enacts these governance layers to enable SME energy consumption data to be used to inform eligibility for green finance. IB1 supports scheme governance through a well-defined process for convening, specifying and designing the scheme (we term this Icebreaking), and then using trust services to implement and publish the rules in formats that machines and humans can understand. Scheme monitoring is supported by auditability, traceability and provable permission. While this approach may require different tooling as technology advances, the three layers of consideration are likely to remain relevant.

In operation, automated decision-making is only as sound as the data underpinning it. Assurance that the data meets a defined quality bar, clarity about what the data actually represents and how it may be used, and provenance that traces the data back to its origin are all needed for effective decisions. Within provenance, particular weight should be placed on understanding how the data was gathered in the first place, including, critically, whether the data itself was generated or transformed through AI processing, since AI-derived data carries its own risk and quality profile that needs to be surfaced. This includes factors such as the model, the quality of the data used to train it, and the potential for biases to have been incorporated in the training data that would have a material effect on reasoning and decision making.

Particular attention should be paid when smart data is used in automated decision-making, because it must be constrained to the purpose agreed at the point the data was originally shared. The consent or permission under which it was collected has to travel with the data into whatever automated process later uses it. AI’s potential to unlock data-driven innovation has to be balanced against privacy, security, and ethical considerations. This is why IB1 advocated in its response to Ofgem’s AI Assurance in the Energy Sector consultation for AI models that respect consumer consent and data sovereignty using decentralised identity frameworks, that support open standards to ensure interoperability between AI-driven systems, and that embed transparency and explainability to mitigate AI biases and prevent regulatory fragmentation.

Question 3: How effective and appropriate are the data protection framework’s definitions in assigning responsibilities (e.g. controller/processor), and are they likely to remain fit-for-purpose over time as technology advances?

IB1 doesn’t perceive a current need to change the controller/processor responsibilities, but as set out in our response to DSIT’s consultation – Empowering people through data intermediaries, we agree that clarification of delegation has the potential to be beneficial to data subjects. However, any amendment to UK GDPR must be made carefully, in consultation with EU and other international data protection counterparts alongside operators of UK governance schemes that incorporate GDPR – such as Open Banking and the Smart Energy Code. In particular, the change must not put EU adequacy determinations at risk, as the economic and social impacts of a weakened or lost adequacy status are likely to be disproportionate to the benefit.

If UK GDPR is amended, the purpose of, and limits to operation of, data intermediaries need to be made clear in the drafting in order to build trust. The drafting should include requirements for them to be: 

  1. Neutral – the purpose for the data processing cannot be set by the intermediary.
  2. Fiduciary – acting strictly in the data subject’s interest, not in their own or a third party’s.
  3. Permissioned – possessing reliable evidence for permission to act as delegate for a scoped purpose.

Theme 4 – Transparency and rights in complex environments

Question 1: What approaches have you found effective for providing transparency and for enabling individuals to exercise their data protection rights in complex data processing environments?

In complex data environments, transparency is more effective when the rules governing data use are openly published, structured and understandable. Open standards allow participants, regulators and individuals to understand how a data-sharing ecosystem operates, what purposes data can be used for, who has responsibilities and how rights can be exercised. They also reduce the need for organisations to develop their own approach to explaining complex data flows, decrease friction between organisations, support interoperability and make governance more scalable (Shaharudin et al., 2024)

There is strong precedent for this approach in the UK’s Open Standards Principles: Open standards allow organisations of various sizes to compete fairly, enable citizens to audit data and decisions based on it, meet user needs, support sustainable costs and avoid vendor lock-in. 

This is reflected in IB1’s NOVA approach. At NOVA level 5, the trusted, open market is interoperable across the economy (a desirable default state for UK data infrastructure). 

In order for individuals to trust the systems of processing, transparency of operation is needed alongside transparency of design. Clarity about the identity and credentials of the organisations processing the data and their role in data processing for the given purposes is required. Signals indicating anomalous or adverse events must be surfaced and communicated to those affected, along with information on how they were corrected. As stated in our response to Theme 3 Question 2, data flows and processing must carry and retain enough information to enable audit and support the investigation and resolution of disputes.

Question 2: How effective are the data protection framework’s transparency requirements and data subject rights in the context of data-intensive technologies and will these remain fit for purpose over time as technology advances?

The boundaries of the data protection framework are being tested but not necessarily exceeded. IB1 highlights three areas where work is needed by those developing or deploying complex data processing technologies in order to bring their processing into line with the framework.

1. Explainable AI

When a data process is a “black box” making complex decisions without being able to provide reliable information about the data and processes that led to the decisions, data subjects cannot be given the transparency required by the framework.

2. Personal data in models and memory

When personal data is included in model training, many Rights of the data subject, including rights to access, deletion and correction, are not possible with current Large Language Model (LLM) implementations. If personal data becomes embedded when a model is training, the model cannot unlearn it on-demand. Ideally models should only be trained on text which was explicitly produced for public use (Brown et al., 2022). There is a growing practice of de-identification and private association editing but these are still not entirely effective (Venditti et al., 2026; Patil, Hase, and Bansal, 2024).

In addition to model training data, many LLMs carry contextual memory to aid processing for an interaction or sequence of interactions. This memory may contain personal data from the data subject, and controls must be provided for data subjects to access, correct or delete that data.

3. Agentic systems and delegation

Agentic developments and delegation require further exploration as a potential area of growing challenge to transparency. Effective governance should make the scope and purpose of delegated authority clear, including who is authorised to act, on whose behalf, for what defined purpose and within what limitations. Accountability for the actions of software or equipment always sits with those deploying and operating it, even when it is autonomous. It is these individuals or organisations that must be identified clearly. Open and interoperable governance approaches can make complex data ecosystems more transparent, accountable and scalable. 

Theme 5 – Effectiveness of data frameworks in regulating AI

Question 1: Overall, what is working well, where have you observed disproportionate or unintended barriers in practice, and where have risks to data protection arisen?

No response

Question 2: Are the existing data frameworks sufficiently adaptable to future developments in AI, and where might rapid technological advances give rise to future difficulties? Or are there any alternative approaches that may be more effective, both now and in the future?

As highlighted in our response to Theme 1 Question 1, AI and data governance is lagging behind AI capabilities, and the gap is widening. The challenge for current data frameworks is not that their requirements are inappropriate, but that governability isn’t being designed into the models, agentic systems and data sharing ecosystems that are being deployed, often at huge scale. Where advances in technology fail to demonstrate governability, they must be limited in application until appropriate controls can be provided.

Our responses throughout this consultation set out ways in which data sharing and processing can be made more trustworthy, transparent and compliant with existing regulations. Regulation must reinforce key principles in responsible AI such as clarity of purpose, machine executable rules enforced at the point of data processing, open and transparent processes, methods to prove correct operation, and clear routes to redress when systems fail.

As IB1’s work, including Perseus, demonstrates, there is significant scope to improve data protection, particularly where AI is involved, by supporting the rapid rollout of voluntary data sharing schemes based on common open standards, to provide clear rules, well-communicated purposes and meaningful assurance and accountability.  This would unlock data value while maintaining trust and transparency and reducing the risk that regulation becomes obsolete as technology evolves.