“I am exercising my statutory right of access under Article 15 of the UK GDPR, and I will not tolerate any delay. You will provide every single piece of personal data including metadata, slack messages, chats and deleted data that you hold about me — in full and unredacted.
“The one-month deadline under Article 12(3) is not a suggestion, and rest assured I am fully prepared to escalate to the ICO the moment you fall short.”
Polished. Confident. Correctly cited. And almost certainly drafted by a chatbot.
If you handle data subject access requests, you’ve probably noticed the change. The requests landing in your inbox are better worded than they used to be. They quote articles but misunderstand their rights and the law. They quote case law, and some of it doesn’t exist. And a growing number of them weren’t really written by the person who sent them – they were written by a generative AI tool the person asked for help.
This is the new reality of access requests, and it cuts both ways. Applicants are using AI to make requests and organisations are using AI to answer them. Both bring genuine benefits and some real traps.
The applicant has an AI now, too
For years, exercising the right of access took a bit of effort. You had to know the right existed, work out who to send the request to and write something coherent. That friction kept volumes manageable for a lot of organisations.
That friction is disappearing. Anyone can now ask a free, widely available tool to “write me a subject access request to my former employer” and get back something that looks like it came from a law firm. The barrier to making a well-framed request has dropped close to zero.
The privacy community has been talking about a rise in DSAR volumes for a while, and AI is widely blamed for accelerating it. It’s a plausible link – and it matches what a lot of practitioners are seeing – but be a little careful with the causation. Volumes have been climbing for several years for lots of reasons, including better public awareness of data rights generally. AI is part of the story; it probably isn’t the whole of it.
What’s less debatable is the change in character. AI-drafted requests tend to be:
- Broader
“All personal data you hold about me, in any format, from any system” is a typical AI flourish – maximal scope, often wider than the person wants or needs. They often ask for “metadata”, but if you ask the requestor what types, they can’t tell you or don’t understand what it is. - More confident and sometimes confidently wrong
AI tools hallucinate. You may receive requests that cite articles that don’t say what the requester thinks, invent deadlines that don’t exist or reference case law that was never decided. A common one is referencing the Data Protection Act section 45 in a request to a private organisation, while that section is only applicable to law enforcement bodies. - Harder to read
A longer, more formal request is not necessarily a clearer one. - More aggressive
Requests imply regulatory action, threaten ICO complaints and use intimidating language designed to pressure a faster or broader response. - More follow-up and challenge
Requesters can quickly and easily generate detailed follow-up correspondence, challenge your response and escalate disputes often at volume.
The reassuring part: the law hasn’t changed
Here’s what I’ve been reminding my clients: the fact that a request was generated by AI changes nothing about its validity or your internal process or obligations. A request is valid however it was produced – by the individual, by a chatbot or on the back of an envelope. You cannot refuse a request simply because you think AI wrote it, and you shouldn’t try.
The ICO made exactly this point in May 2026, when it published guidance for public authorities on AI generated requests under the Freedom of Information Act. That guidance is FOIA-specific rather than DSAR specific, so read it with some care, but the underlying principle travels: AI origin has no bearing on validity. Existing rules on timescales, clarification and exemptions al apply exactly as they did before. The guidance is framed as practical support, not as a new obligation, and it includes example wording authorities can use to nudge requesters towards more responsible use of AI. There is, as yet, no equivalent DSAR-specific guidance, but it would be reasonable to expect the ICO’s thinking to point in the same direction.
So, the message to staff is simple: don’t be intimidated by polished wording, and don’t be thrown by confident legal assertions that happen to be wrong. Assess the substance, not the style.
Where AI actually helps you
If an AI-drafted request quotes the law incorrectly, you don’t have to argue with it — but you may need to address it. Where AI has muddied a request or introduced inaccuracies, it’s good practice to politely point that out and ask the requester to confirm what they’re actually looking for. Far from being obstructive, that clarification helps both sides.
This is where two recent developments work in your favour. The Data (Use and Access) Act 2025 has clarified the ability to “stop the clock” – pausing the one-month deadline while you wait for a requester to clarify a request where clarification is genuinely needed. The Act also confirms the standard for searches: reasonable and proportionate, not exhaustive. An overly broad, AI generated “everything you hold” request doesn’t oblige you to turn your organisation upside down; it obliges you to conduct a proportionate search and, where appropriate, to seek clarification first.
Those two tools – clarification and proportionality – are your main defence against scope-creep, and they apply regardless of who or what drafted the request.
And where AI helps your team answer
The other side of the coin is your own use of AI. Tools are increasingly marketed to help with DSAR fulfilment: searching across mailboxes and file shares, de-duplicating near-identical documents, flagging likely personal data and third-party data, and assisting with redaction. Used well, these can speed up the time to respond to requests.
Three cautions before you lean on them:
- You remain accountable. If an AI redaction tool misses third-party data and you disclose it, that’s your breach, not the vendor’s. A human still needs to review the output, particularly around exemptions and the rights of others.
- Your own AI processing is in scope. If you use AI to handle a request, the personal data that AI processes can itself fa l within the scope of access rights. Build that into your thinking rather than discovering it later.
- Mind what you feed it. DSAR information should never be put into an AI chatbot. Putting request material through a third party model raises questions about where the data goes, whether it’s used for training, your Article 28 processor terms and any international transfers. Due diligence on the tool is not optional.
An AI-specific DPIA before you deploy a DSAR handling AI tool is the sensible starting point. It forces exactly these questions to the surface while you can still do something about them.
One more thing: knowing who you’re dealing with
When a request arrives in the requester’s own words, you often get incidental signals about who they are. A fluent, AI-generated request strips a lot of that away. It makes identity verification more important, not less – you’re relying on it more heavily because the request itself tells you less.
It’s also worth remembering that DSARs are increasingly used tactically – in employment disputes, ahead of litigation or as a form of pressure. AI makes that cheaper and easier, so expect to see more requests where access to data is not really the point. The legal framework still tells you how to respond, but it’s helpful for your team to recognise the pattern.
If there’s sufficient evidence, you may also consider whether the request is excessive or manifestly unreasonable.
A final thought
AI hasn’t rewritten the right of access. It has changed how easily and at what volume. The organisations that cope well won’t be the ones that try to spot and reject “robot” requests. They’ l be the ones that treat every request on its merits, lean on clarification and proportionality, keep a human firmly in the loop on the answering side and document their reasoning so that a confident, AI-assisted complainant has nothing to push against. The robots are already here, but the rules of engagement haven’t shifted. An AI-drafted DSAR is still a valid DSAR, and an aggressive tone doesn’t change the threshold for compliance.
So, when the next one lands, remember: your obligations haven’t changed. Assess the scope of the request, ignore the style and try not to get into an argument with a robot.