Lawful and accountable
UK Bailiffs remains responsible for its work, including work supported by a third-party AI service.
Responsible technology. Human accountability.
How UK Bailiffs uses AI to improve accuracy, consistency and service while keeping lawful enforcement, professional judgment and accountability firmly in human hands.

Our position is straightforward: AI may support our people, but it does not acquire legal powers, exercise an enforcement agent's statutory authority, replace professional judgment or remove UK Bailiffs' responsibility for an outcome.
This policy explains how UK Bailiff Services Ltd, trading as UK Bailiffs ("UK Bailiffs", "we", "us" or "our"), governs artificial intelligence, machine learning, generative AI, automated tools and AI-enabled decision support.
It applies to our directors, employees, enforcement agents, contractors and approved suppliers whenever they design, buy, configure or use AI for UK Bailiffs. It covers internal administration and public-facing services, including enforcement, recovery, possession, investigations, security support, client reporting, communications, payments and complaints.
UK Bailiffs remains responsible for its work, including work supported by a third-party AI service.
People with the right competence and authority review matters requiring legal judgment, discretion or a significant decision.
We test for unjustified bias, avoid discriminatory proxies and consider the effect on vulnerable people and protected groups.
We provide clear information about material AI use and an understandable explanation where the law or fairness requires one.
We minimise personal data, approve suppliers, control access and apply appropriate retention and transfer safeguards.
AI output is treated as assistance, not unquestionable fact. Relevant people can raise errors and request human consideration.
Approved AI may assist with tasks such as:
The permitted use, data, approval level and monitoring requirements must be recorded in our AI system register before a material use goes live.
AI must not be the sole or final decision-maker where a decision requires the exercise of legal powers, professional judgment or discretion, or may have a legal or similarly significant effect. In particular, AI will not by itself:
A human review is meaningful only where the reviewer has sufficient information, training, time and authority to question, change or reject the AI output. A rubber-stamp approval is not meaningful human involvement.
We may use ChatGPT and comparable AI models only through approved business or API deployments that meet the non-persistence requirements below. Before approval, we assess and document the provider, purpose, data flow, security, contractual terms, sub-processors, hosting, international transfers, deletion arrangements and ability to support data-subject rights.
Depending on the approved task, the data processed may include instruction and contact details, identifiers, case status, correspondence, documents, images, payment status, accessibility needs and information indicating possible vulnerability. We use only data relevant and reasonably necessary for the recorded purpose. The applicable privacy information identifies the controller, purposes, lawful bases, recipients, retention position and individual rights in more detail.
Approved AI models are processing tools, not UK Bailiffs' official system of record. They do not create or retain the authoritative record of an instruction, personal transaction, payment, enforcement action or decision. Authoritative records, evidence, approvals and accountable human decisions are held separately in UK Bailiffs' controlled case, finance and document systems for the appropriate lawful retention period.
Where necessary and proportionate for accountability, subject access, complaint handling or audit, UK Bailiffs records the minimum relevant input, output, source references, human checks and decision outcome in its controlled systems. We do not retain unnecessary prompt content or duplicate personal data merely because AI was used.
ChatGPT or another external model may therefore be used with live case content only where the particular business or API deployment has been technically verified and contractually confirmed to prevent retention of prompt and response content. Saved-chat, memory, training and equivalent storage features must be disabled. If a provider, model, feature or endpoint cannot satisfy and evidence this requirement, it must not be used with personal or case data. We retain proportionate evidence of the technical configuration, verification and applicable contractual terms for each approved deployment.
Limited operational metadata may be retained where necessary to secure and audit the service, such as the time of a request, approved user, model version, token volume and success or failure status. Such metadata must exclude prompt and response content and case identifiers wherever reasonably practicable, be access-controlled and follow a documented retention period.
Staff and contractors must not place live case data in personal, consumer or unapproved AI accounts. We remove or replace identifiers where reasonably practicable, disclose only the minimum data needed, and do not use case data to train or fine-tune any general-purpose or supplier model.
Where we are the controller, we determine the purpose and lawful basis. Where we act for a client, the allocation of controller and processor responsibilities is documented. Special-category and criminal-offence data receive additional protection and are only processed where the required UK GDPR and Data Protection Act 2018 conditions are met.
Your data-protection rights apply where AI is used. Their precise scope depends on the circumstances and lawful exemptions, but you may ask us to:
We do not ordinarily use solely automated processing to make significant enforcement decisions. If a proposed use could do so, it must not begin until we have identified a lawful basis, completed the required impact assessment, introduced the statutory safeguards and provided appropriate privacy information.
Access rights do not necessarily require disclosure of source code, security information, another person's data or legally privileged material. We will provide the information the law requires in an intelligible and useful form. Requests can be made through our Data Subject Access page or by emailing legal@ukbailiffs.org.
UK Bailiffs is a private limited company and is not generally a public authority for the purposes of the Freedom of Information Act 2000 ("FOIA"). However, information we hold on behalf of a council, government body or other public-authority client may be treated as held by that authority for the purposes of FOIA or the Environmental Information Regulations 2004 ("EIR"). Our contractual duties may also require us to assist the authority with information requests.
Where a request relates to information that may be held on behalf of a public authority, we will:
FOIA and EIR apply to recorded information already held; they do not normally require information to be created that is not held. Because approved AI models do not persist prompts or responses, the model cannot later retrieve content that ceased to exist when transient processing ended. This does not affect disclosure of any relevant information that was separately adopted into, or is otherwise held within, UK Bailiffs' official systems.
A request for the requester's own personal data is normally handled as a data-protection subject access request rather than an FOI request. We will identify the appropriate route and will not use an incorrect label to deprive anyone of a legal right.
We will not intentionally design or use AI to discriminate unlawfully on grounds protected by the Equality Act 2010. Protected characteristics, health information, postcode, language, disability indicators and other proxy data must not be used to produce an unjustified adverse outcome.
An AI-generated vulnerability or risk flag is a prompt for trained human consideration, not a diagnosis or final conclusion. Absence of a flag does not mean absence of vulnerability. Staff and agents must consider the person's actual circumstances, make reasonable adjustments where required and follow applicable vulnerability, safeguarding and ability-to-pay procedures.
Where reasonably possible, we provide a non-AI route or direct human contact for anyone who cannot use, does not understand or is materially disadvantaged by an AI-enabled channel.
AI can produce incomplete, outdated or incorrect material. We apply risk-based checking proportionate to the impact. Names, addresses, identity matches, sums, payments, fees, dates, legal authorities, statutory wording, ownership assertions, vulnerability indicators and instructions affecting enforcement require verification against reliable source material.
Original evidence must be preserved. AI-generated summaries or image descriptions must be traceable to the source and must not be presented as if they were contemporaneous evidence. Material legal content is checked against legislation, court directions, current official guidance or suitably qualified advice before reliance.
Controls are selected according to risk and may include:
A supplier's assurance does not remove our accountability. A material model, provider, integration, retention or hosting change triggers reassessment before continued high-impact use.
There is no single UK Act that replaces all existing duties whenever AI is used. We apply the law to the particular purpose, data and outcome. As at 9 August 2026, the principal framework considered by this policy includes, as applicable and as amended or replaced:
This list identifies the principal framework and is not a claim that every law applies to every use case. Other sector, employment, health and safety, safeguarding, surveillance, insolvency, property, contract or jurisdiction-specific requirements are included in the assessment where relevant. Work outside England and Wales follows the law and authorised professional arrangements of the relevant jurisdiction.
The Compliance Manager owns this policy. Senior management retains overall accountability. Each material AI system has a named business owner responsible for purpose, data, controls, testing, monitoring and withdrawal.
Before a new or materially changed AI use is approved, we assess its necessity, proportionality, lawful basis, data sources, accuracy, explainability, equality and vulnerability impact, security, supplier risk, retention, human oversight and means of challenge. A Data Protection Impact Assessment is completed where processing is likely to create high risk, including relevant innovative technology, large-scale sensitive data, systematic monitoring, profiling or significant automated decisions. Other assessments, including legitimate-interest, equality, security and legal assessments, are completed where applicable.
A statement that a policy will "automatically adapt" cannot by itself change systems, contracts or working practices. We use the following controlled update process:
You may ask whether AI materially supported a process concerning you, report an inaccurate output, request a human review or raise a data-protection or service complaint. Raising a concern will not by itself cause adverse treatment.
We investigate in accordance with our Complaints Policy, Privacy Notice and applicable statutory timescales. Data-protection complaints are acknowledged within the period required by law, and we keep complainants appropriately informed.
This policy takes effect on 9 August 2026 and applies until replaced. References to legislation and standards include amendments, re-enactments and replacements to the extent applicable; however, operational change is implemented through the controlled review process above.
Version: 1.2 | Owner: Compliance Manager | Approved by: Senior Management | Scheduled review: by 9 February 2027.
Version 1.2 change record: strengthened the technical verification, contractual confirmation and evidence requirements for non-persistent AI; clarified proportionate internal recording for accountability while avoiding unnecessary prompt duplication; and retained the FOIA/EIR contractor procedure introduced in version 1.1.
Reference links are provided for transparency. Guidance and standards may change and do not replace the legislation itself or case-specific legal advice.
For an AI-related question, access request, correction or human review, contact our Compliance Manager or use the relevant form below.
Email:
legal@ukbailiffs.org
Telephone:
0330 133 1818
Post:
Compliance Manager, UK Bailiff Services Ltd, 223 Bacup Road, Rossendale, BB4 7PA
UK Bailiff Services Ltd, company number 11337729, trading as UK Bailiffs.
Press Enquiries:
Media@ukbailiffs.org
🛑 TELL THE BOSS – Complain about our conduct
ICO Registration: ZA379866
VAT Number: GB306547801
UK Bailiffs | Enforcement Support
Need to instruct enforcement action or speak to UK Bailiffs?
Structured, defensible support for landlords, agents, property managers, housing providers and commercial clients.
UK Bailiffs