Guardians of Data

Handling AI Generated Information Requests

Act Now Training Season 1 Episode 14

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 40:15

If your organisation is being overloaded with AI generated Freedom of Information requests or GDPR Subject Access Requests (SARs) this podcast episode is for you.  

Some would say AI has democratised and powered access to information. Large Language Models, like ChatGPT and Claude, can produce ‘perfectly written’ FOI requests and SARs at the touch of a button. But these are causing problems for over worked information governance departments. Not only are more requests coming through; they are often longer, broader and difficult to interpret. 

In this episode we guide you on how to manage and lawfully respond to AI generated information requests. Our guest is Saara Idelbi from 39 Essex Chambers. Saara is recognised by the Legal 500 as a ‘leading junior’ barrister. She practises in administrative law, human rights, data protection and information rights. Saara is a recognised voice on AI and the law and is the co-founder of Advocatr, an AI legal training platform.

Listen now for practical guidance on dealing with AI generated information requests whilst respecting the key principles of information rights legislation; openness, transparency and accountability. 

You can also listen to episode 13 where information lawyer, Andrew Latham, gives his tips on AI generated subject access requests. More useful resources below:

ICO Guidance

Building Trustworthy AI Systems Podcast

AI Blogs

FOI Blogs

Phaselaw

This podcast is sponsored by Phaselaw - a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn't designed for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days.

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment.

Ibrahim Hasan

Welcome to Guardians of Data, the show where we explore the world of information law and information governance, from privacy and AI to cybersecurity and freedom of information. I'm your host, Ibrahim Hassan. In each episode, we speak with experts and practitioners to unpack the big issues shaping the IG profession. Before we continue, hit the follow button to ensure you never miss an episode. Many organizations are seeing a big increase in freedom of information requests and GDPR subject access requests, which have been generated using artificial intelligence. Not only are more requests coming through, they are often longer, broader, and difficult to interpret. In this podcast, we want to guide information governance practitioners to help them manage and lawfully respond to these requests. My guest is Sara Idelby from 39 Essex Chambers. Sara is recognized by the Legal 500 as a leading junior barrister. She practices in administrative law, human rights, data protection, and information rights. Sara is a recognized voice on AI and the law and is the co-founder of Advocata, an AI legal training platform. Stay tuned for practical guidance on dealing with AI-generated information requests whilst respecting the key principles of information rights legislation: openness, transparency, and accountability. Let's jump in. Sara, thank you very much for joining us.

Saara Idelbi

Thank you so much for having me. It's good to see you again.

Ibrahim Hasan

Likewise, I thought I'd start by asking you, Sara, how you got into this area of artificial intelligence and what excites you about it?

Saara Idelbi

Well, so what got me into artificial intelligence is it comes across all aspects of my work. And I have spent my career acting for and against public authorities in a variety of different arenas. Artificial intelligence creeps into every single one of them. And because I have a broad practice that deals with aspects of data, aspects of freedom of information, basically how the state interacts with the individual, AI inevitably came up in it. And so it was a natural progression as it became more and more prominent. I have also founded a legal tech startup called Advocator, which provides AI feedback to aspiring and junior lawyers who are practicing their advocacy. So I started to learn more and more about it, both in my work and for the startup. And I just find it fascinating because it's one of those tools that has great opportunity, but often with those also comes great risk. And you have to learn how to navigate something because there is such a thing as too much of a good thing.

Ibrahim Hasan

Now, Sarah, we've seen an increase in information requests using AI, according to polling by the Information Commissioner's Office. One in eight recent requests to public authorities under the Freedom of Information Act, they suggest were created by AI tools. Now, before we look at how to deal with such requests, I'd like to discuss how we can spot the use of AI more generally. For me, the clues are the long dash and the formulaic way in which generative AI like Chat GPT write. So usually one of the big clues is it's not this, this, or this, but it's actually this. Those kind of formulas I find are a giveaway. What are the clues for you?

Saara Idelbi

Definitely those. I think we've become very attuned to the it's not this, it's that, which is a shame because it's a device I like. I also am personally a big fan of the M dash, but now unfortunately, I have had to reduce its use in my writing. At the moment, the big ones for me is it obviously produces plausible sounding nonsense. So on the face of it, it seems like it makes sense. But then actually, when you delve into it, which is apparently also a tell, um, I shouldn't be using words like delve anymore. But once you dig into it, you realize it's just very broad strokes. Usually it will give you formatting in calibri or a house style in Word. You'll also note that in headings, it will produce documents where the headings will come up as blue. Headings will be a varying size to the actual text in a document. You often get lines in between sections or paragraphs that will usually tell me that AI has been involved in some sort of way. I like to justify my written work, so it'll be a line to be across the page as a standard. AI will have it left justified and it would need to be adjusted. And I think that is sort of broadly the stuff that you get used to. And of course, as we see across the legal cases that come through and through the hallucinated citations, but probably not something that you'll note straight off the bat.

Ibrahim Hasan

Yeah, a point which resonates with me is that we're writers and we're having to change our habits to show to the readers that actually I am not AI.

Saara Idelbi

Absolutely. It's such a shame as well, because these devices exist for a reason. There's a reason why we have the M-Dash, there's the reason why we have the comparator, there's the, I think the rule of three reflex, so clear, structured, comprehensive. It's the sort of Winston Churchill type speech. The rule of threes are persuasive, they embed, but actually it's so common in AI that you start to doubt whether or not it's getting written by a person or by AI again.

Ibrahim Hasan

Absolutely. A lot of people are using AI, and in a way, it's a democratizer. But this has led to a massive increase in FOI requests to public authorities, adding strain to under-resource departments. Lincashire County Council say that they've had an increase of 18% in freedom of information requests in the last financial year, and they've put that down to the likes of Chat GPT. Of course, we're not saying that just because someone's used AI to generate an information request means that it's automatically invalid. Let's talk about how we can deal with such requests, especially as often they can be unclear, too wide, or asking for relevant information.

Saara Idelbi

So you touched on something that's really important to underscore. The use of AI is democratizing and it reflects to some extent the fact that there is a disconnect, that people feel ill-equipped to deal with things on their own, that the proliferation of policy guidance, et cetera, hasn't helped people to really process what they need to do to be able to engage with public authorities. And AI, from my perspective, is more of a symptom than a cause of these issues. And why have I started my answer to your question with that? I have done it because it's helpful to have that lens when you are dealing with the requests that have been AI generated. You're probably dealing with somebody who feels somewhat disenfranchised, who maybe doesn't feel confident in just asking for what they want, and really having some sympathy and some care in your mind for the person requesting. And I know that's difficult, especially if you get repeated, abusive, frustrating requests that you have had to deal with over and over again. But to think that coming to it with some degree of kindness is a useful starting point, especially if you're having to deal with these sorts of long requests. And that brings us again to the start point, which is if it's long, is it telling you what they want? You can get some that are incoherent. They're just pages and pages, citing law, sometimes citing the law incorrectly, taking the wrong emphases. Or you can get some AI requests where the majority of what's referenced is coherent. It just takes you a little bit longer to read what they're seeking. If you're unsure, these are the opportunities to use section 16 in FOIA or I think the new section 76 provisions from Jua that have been imported into UK GDPR to ask and just going back with a very simple one-page letter and just say, we think that this is what you are asking for. Is that right? Because you want to make it simple, and that's part of that discourse that is encouraged in FOIA. So first appraising, can you really deal with this? Because you're not going to cover yourself in glory if you push back simply because it's long. Can you really discern what they want is a really great starting point. And then taking a realistic view of how much energy it will take for you to comply with the request. Because obviously, then if you look at the request and it's going to take you an exceptionally long time, you have grounds for charging, and in some circumstances, you can, well, for subject access requests, you can refuse because it goes beyond what's reasonable and proportionate.

Ibrahim Hasan

We're going to come back to look at uh charging in particular, Sarah, because that's uh an area of interest for me, dealing with a lot of clients who have these issues with AI-generated requests. But before we do, I think it's important to emphasize the section 16 duty of advice and assistance. Go back to the individual, pick up the phone, have the dialogue with them, ask them exactly what they're looking for. And I think that would reduce a lot of the burden of these requests and to show them that there is a human on the other side who will be impacted by your actions. And hopefully that could lead to a more reasonable FOI request.

Saara Idelbi

I I wholeheartedly agree. I think unless you are dealing with strategic litigation foyers, which do come up, if you're getting a request from an individual, there is nothing better than trying to establish a rapport with them to understand them, because they're trying to understand their public authority, right? This is all an exercise in some strange way of interpersonal understanding. So if you don't know for sure what they're going for, you're not going to hopefully offend anyone by, as you say, picking up the phone or just writing that in very simple language. Over the years, we have corporatized the way that we speak, which means that letters come out, they're full of words, but not necessarily cutting through to the heart of it. And actually, if you just cut through to the heart of it yourself, you're setting a framework to say to the requester, just tell me the guts of what you want.

Ibrahim Hasan

And say, for example, if we do receive a request, it's perfectly legitimate, but AI generated, and we receive one request after another, as often happens, you're in that sort of a loop where they're never satisfied.

Saara Idelbi

Yeah, but you can already push back if you're getting repeated requests of the same variety that you have answered, and you're getting into that vexatious territory where you can just simply push back and say that we answered it. Also, if you answered the substance of the request already and it's available online, you can exploit the existing mechanisms of it's also already publicly available, it's available here, all of that sort of stuff. But if you're just constantly getting a back and forth with more and more developing requests that are unreasonable, that is the opportunity to refuse under section 14. So if you're getting repeated substantially similar requests, requests that are intended to disrupt, it's always an issue with intention because that's a little bit more difficult to prove. But you might have surrounding features, publicly available information, historic requests that will indicate that requests that have effectively been closed, or you have high-volume campaign-style requests. And those are all sorts of scenarios where the ICO recognized you can use section 14 to refuse to comply after you you've had that sort of first engagement.

Ibrahim Hasan

And is there a difference between section 14 under FOI, the vexatious and repeated requests, and the manifestly unfounded or excessive exemption under subject access? Is the test similar or are there things that listeners should be aware of?

Saara Idelbi

They're different words, but the thresholding, in my view, is about the same. You're still looking at really high thresholds for all of them. Almost at the level of being abusive, that is inconsistent with the teleological purpose of either UK GDPR or FOIA. And it's different through those lenses, if that makes sense. What's the ultimate purpose of the access to the information? And is the request inconsistent with that?

Ibrahim Hasan

I see. So just to summarize, Sarah, in terms of freedom of information, I suppose it's the same for subject access as well. Look at the purpose of the request. Don't be afraid to pick up the phone, to enter into a dialogue with the individual, ask them to clarify. And above all, particularly in terms of FOI, don't forget your duty of advice and assistance. And also don't forget the basics of FOI, where the burden is going to be more than the appropriate limit. You can apply the cost exemption. And in extreme cases, there's always vexatious and repeated requests, section 14.

Saara Idelbi

Yes, that's right. There's all of the mechanisms that exist already to deal with it. The fact of vexatious doesn't change, it's just the methodology. Sometimes I'm concerned that the focus on AI distracts us from what we would do if we got the same volume that had been human generated? And if the answer is you would treat it as vexatious, you should treat it as vexatious.

Ibrahim Hasan

I agree. Don't get tied up too much in whether they're using AI or not. Look at the substance of the request and apply the normal principles. Turning to the other side, what advice would you give to people who use AI to generate FOI requests?

Saara Idelbi

The first piece of advice I would give to anybody who is using AI to generate FOI requests, generate subject access requests, or indeed to generate any document that you're going to send for an official purpose is once you get the answer from the LLM, the chatbot, whatever tool you're using, you need to ask it this one question. And it's really vital that you ask it. You ask that LLM, that AI, what is wrong with what you have drafted for me? Because it's really important for you to see how AI can contradict itself so that you can adjust and remind yourself to read through it in detail. So that's the kind of overarching point. If you forget anything else that I say about using AI, that is the one question you should always ask, always challenge what you get given. Because it does hallucinate, it is sycophantic, it wants to please you. And part of the way that it pleases you is to give you something that you think is great. But it is also capable of self-evaluation. And then when you see it make its mistakes and correct it, that means that you can be alive to how you need to adjust and also what you might get as a response from the public authority or organization that you're sending your request to. Other ways of dealing with it is Notebook LM, which is a Google tool, I think is a really useful place to go. If you collate resources from the ICO or if you have already done some search for information policies, etc., that are around FOIA requests or subject access requests, put it into a notebook LM folder and then try and generate your request through that ecosystem. Because then rather than just relying on the whole internet to give you a good quality letter, you are relying on the reliable sources that you have accumulated to draft you that letter, and that will give you a much better request. And then finally, fundamentally, what do you want? Make sure it's clear in your mind what you want, what are you seeking? Plain language is indisputable. Don't be persuaded or seduced by the ridiculous legal language that we all like to trot out. No one can disagree if you can explain what you want in plain language.

Ibrahim Hasan

That's wonderful advice, Sarah. I particularly like the idea of asking the LLM to check its own homework and also then double-checking it with your own sources. If requesters follow that advice, then I'm sure our other listeners, our FOI practitioners, data protection practitioners, will find that they get a better quality request, but also that means that they give a better quality answer as well. So everyone's a winner, as they say. Turning to the other side, Sarah, public authorities increasingly are using AI to manage information systems, deal with FYI requests, find information, map their data flows as you'd expect. They're making use of the technology themselves. Some may even be using LLMs to generate their response. Of course, all this means that this is generating more information, and that could be the subject of freedom of information requests. So any advice to public authorities when they're making use of AI in terms of their information governance function?

Saara Idelbi

Yes. Well, it's the old adage: never put in writing what you wouldn't want a judge to see. And that applies just as much for prompts, AI use, etc. So AI workflows, as you say, AI prompts are likely to be disclosable, are likely to be part of what might be caught by information requested. It will might well be part of the data that you process because obviously your question will be seeking an opinion about a data subject. So you can see how all of that will start to fall within the scope of processing personal data. So be mindful that everything you put in might be seen by somebody else eventually. There is the flip side of it as well. Public authorities and people working there have to ask themselves the same question, challenge the answers and outputs that you get. Is this good enough? I think that in some organizations where they're exploiting the agent workflows, you need to be mindful of the quality of the design of the AI agent and ensuring that you focus each task. So I have found over time that if I'm using AI agents, if you just give the AI agent one very small basic task, the likelihood of it making a mistake reduces because it has so little to get wrong. And then you pass it along. So the later agents then verify the work of the earlier agents. I also think that for public authorities responding to requests, your letters should, as a standard, include that question that I suggested for those who are using AI to generate responses and requests. Have you asked the AI to check its work? Because, like I said at the beginning, the lens through which we can look at it is the requester, may be disenfranchised, may feel that the public authority is not sympathetic, is not going to help them, even if you put in suggestions or give them advice or try and support them. But asking them to reflect themselves using AI is much more powerful for them than you turning around and saying there are lots of problems with your answer. So having as a standard when you're communicating with a requester, if you use AI to assist you in generating your correspondence, don't forget to ask AI what's wrong with the output it's provided to you before you send it to us. It's an extra sentence in any letter and it costs you nothing, but it might encourage them to take those steps themselves. It's emphasizing autonomy and agency. Then when it comes to using AI for decision making, there's obviously a whole host of issues that are coming up with algorithmic decision making, real problems with it. Bearing in mind that there are extra duties and real concerns around the use of AI on a day-to-day basis. Everyone talks about how AI for summarizing is much safer. I don't think it is unless you are also reading the document itself. So I find it really helpful to use AI to summarize a long document before I start reading it. And I have said before, it's a little bit like when you are walking to a new place. So let's say you're going to a friend's party or something, it's a destination you've never been to before. When you walk there, it feels like ages because your brain is coding everything for the first time. It hasn't seen this route before. And then you'll notice when you're walking back, it's much faster. That actually the whole time, it was the same amount of time to walk. It's just that your brain is working extra and that feels more tiresome. The same applies when dealing with summarization. AI summarizing it helps you walk through for the first time so that when you read the whole document, it's much faster for you to absorb the information and also much faster for you to notice the differences in the summary to what you read. But summaries are not safe just relying on AI alone because if you don't read the request itself, you might miss something that might end up tripping you up later on down the line.

Ibrahim Hasan

That's great advice. I would emphasize the importance of checking your work and understanding that AI is not a shortcut. It'll make the journey easier, but in the end, there's no replacement for your own knowledge and your skills. Why give them up to AI and why lose those skills? That's particularly important.

Saara Idelbi

That's exactly right. People who get the most out of AI are those who treat it like a coach training partner, work partner, rather than a replacement. You don't need your coach to be the best athlete, but you need them to know enough to push you. And as you say, if you already qualify, you've got all of these skills, don't hand it over, use it to elevate what you already have. AI is an amplifier. So if your amplification is this great knowledge base, why wouldn't you want to take that to a next level?

Ibrahim Hasan

I particularly like the analogy of the coach. More generally, Sara, what trends are you seeing in the world of AI use by organizations, especially when it comes to litigation?

Saara Idelbi

So in the same way that people are experiencing an uptick in requests, subject access FOIA requests, we're seeing an increase in the number of cases that are being issued, and that's across all sorts of sectors. I was reading a report from, admittedly, it's from the United States, but actually they had done an analysis of the increase in cases, I think, in the last year due to AI. And what was fascinating about it was that the number of cases had gone up overall. But taking it as a percentage, the number of cases that have been dismissed for being vexatious, abusive, et cetera, have not changed. And what that tells us is that you definitely get an increase in the number of vexatious, unfounded cases. But that also means that you're getting an increase of cases that were viable, that had good prospects, that perhaps people didn't feel like they were able to bring them in the first place. And so if you're looking on a pure percentage basis, everything staying relatively stable reflects what I've said as an amplifier. You're getting the same pattern, just bigger. And it's the bigger that we really need to be thinking about. And that is the trend that everyone is seeing. You're also seeing things that are coming up in courts. So you may have heard that people are self-represented, going into court, typing in what the judge says to them and using AI to respond to the judge. That's happening a lot. I suspect that I haven't come across it personally, but it is entirely possible that people are taking their computers in, pressing the microphone function in their chatbot interface and recording the proceedings in order to then respond, because it's much faster than typing. So where I have had a litigant in person on the other side, and I have noted that there'd been a small issue with a citation that they had included in their authorities bundle, I did write to the court copying them in and say it might be sensible to reiterate in the standardized virtual remote hearing warning that any recording, including recording through an LLM chatbot interface, counts as a contempt of court. I don't think people necessarily connect the two, that just enabling your voice mic is the same as a tape recording that we might envisage as being the typical contempt of court. Obviously, in the legitimate uses, people are using it for disclosure tasks, people are using it to summarize papers, but again, it always needs to be summary and then read. And then we unfortunately have an increasing banquet cases where people are using AI to draft, and it doesn't seem to have staved that inclination despite the numerous referrals to regulators. Hopefully one day that is a trend that will subside. But I guess I keep coming back to it. It's an amplifier. I suspect that some people had already not been as diligent with their work as they had been before. It's just more obvious now with AI.

Ibrahim Hasan

Yes, and I did come across a number of cases involving uh lawyers quoting made-up cases and uh using AI to draft pleadings. So, yeah, those are important words of caution, particularly the point about contempt of court. You mentioned previously, Sarah, AI agents. And I'd just like to finish off perhaps with your views about the future. Is it going to be that our lawyers will be AI agents arguing with each other in court, perhaps in front of an AI judge? Is that where we're heading?

Saara Idelbi

I think what's most exciting about AI is the idea that it might facilitate a system that we haven't even thought of as yet. Which means that the idea of AI bots arguing with AI bots in front of an AI judge is almost down a parallel path. I don't think that we'll end up there. And I think that there are multiple reasons for it. There's obviously the accuracy, the concern, etc., but it comes back to the original idea of why we have the system, the court system in any event, which is the idea of justice. People come to court because they're seeking justice. Now, whether or not the type of justice they are seeking is achievable in court, or whether or not they can get access to X through the court system is not necessarily the same as justice. And as you know, Ibrahim, uh, we as we all got taught, justice and law are not necessarily the same things. But because the intention of most litigants is to achieve justice, I don't think that we as a society will be comfortable with everything being computerized. You only have to look at post-op this inquiry to recognize that computer systems are not infallible. And I don't think everybody is willing to take the risk of a computer system, especially if the entire purpose or the current designer of LLMs is probabilistic. You want to see your case as an individual. You are unique, you have a unique problem that needs to be solved in a unique way, and therefore the probability outcome is not going to serve you. So you're not going to see that. What I think that we will see for legal practice is a lot of the lower level cases being dealt with by AI. But that's not a huge surprise because small value road traffic accident claims were mostly dealt with by algorithmic decision making anyway, by insurance companies. It just means that there'll be fewer cases for very junior practitioners to cut their teeth on. But on the other side of it, AI might give them the opportunity to practice in an ecosystem where they can try their submissions, develop their skills, and prepare themselves for that higher level case that will not be overtaken by AI. Hopefully, it will make us more efficient. Because if you can look at your job in the constituent part and decide that does not require the energy I put into it. And obviously, in my mind, I'm thinking of my billing because that is the thing that I least like to do, even though it is probably the most critical part of my job, so that I eventually can eat and pay for my mortgage. But those parts take loads of time, and you don't really need to spend that time, so you can cut that out. And I use AI agents for aspects of research sometimes. And because I've got very strict parameters, I know to check it, I also know to read everything. I have created an AI vault ecosystem where now I took all of my billing data for about seven years, removed all of the personal data out of it so everyone can not panic. And I asked it to analyze the median time it took me to undertake a particular task in a particular type of case. So I've got all of this data, and now if I get asked if I'm going to have capacity to take on a new case, I can just ask the vault that I've created do I have capacity to take this case in a standard data protection case? That the deadline is a month away, and it will crunch the numbers, crunch the occupied time in my diary, also expunged the personal data, and tell me whether or not I have capacity. And if that's slightly wrong, that's not going to end the world or my life. But that is the way that can make us more efficient. And I think it's starting to look at the boring stuff and how that can make your life a little bit better.

Ibrahim Hasan

I'd agree with that, that we need to look at how AI can do the tasks that perhaps we're not particularly good at or that are time consuming, freeing time to do other tasks which are perhaps more rewarding, both from a sort of a personal cognitive level as well as more rewarding in terms of the commercial side of things. It's interesting you mentioned the horizon scandal, and as you say, that's a case in point which shows that we don't want to leave everything to technology, to computers. They can get things spectacularly wrong. But also, it's important for people to understand that this technology is not neutral. There are people behind the technology who may not have the same views about democracy as we do. They may not have the same value systems as we do. A lot of AI is a black box. We don't know how it's programmed. There have been lots of cases involving Chat GPT suggesting harm to young people. So it's about not over-relying on the technology thinking it's completely neutral because it's not.

Saara Idelbi

Absolutely. And you've got to be alive to the risks. You mentioned about ChatGPT, who eventually suggested that the user should commit suicide. That's obviously awful. It's reacting, it doesn't have it doesn't have any feelings. It's just spitting out a logical follow-on from the prompt that goes in. And that also gets affected by a variety of different things, your gender, and got lots of data that talks about how AI can discriminate. An answer it gives to you may be entirely different to an answer it gives to me based solely on our gender. I mean, that's not what we wanted to do. If we amplify, we don't want to amplify the worst parts of the data set that it was trained on, even if the frontier model providers have no malintent. So you have to be alive to it. You've got to remember if you're dealing with requests, for instance, just because you've got a request from somebody, I don't know, who might have mental health issues doesn't mean that you should focus on dealing with their mental health issues. And so making sure that when you're using AI, you don't accidentally follow the skew that AI might prompt you in that direction, having a neutral thought process about it is important.

Ibrahim Hasan

Absolutely. We've just published a podcast with Amnesty International where they did a very detailed study of the police's use of predictive analytics and AI to score individuals and areas for the purpose of policing. And what they discovered, the technology actually accentuated and almost industrialized biases against certain communities. So they end up being overpoliced. That data then feeds back into the system, which means that there's even more stop and searches and there's even more policing in those particular areas. So your point with regards to the quality of the data and what it's suggesting is very important. And it just shows that we have to approach all these systems with caution and not delegate our agency to these technologies.

Saara Idelbi

That I couldn't agree more. And that again comes back to the problem that AI is not human, it has no feelings. It's just giving you that sort of raw, unfiltered. So if you're getting that kind of analysis, the police are getting that kind of analysis, they're working on the basis, but the numbers are suggesting causation rather than just pure correlation. You just don't know why that happened because I can't remember who I was reading recently. It was probably probably Kahneman, but the idea that, well, if you take data from an area and then you decide, right, we need to police this area more because this is where more crime happens, but then you're going to catch more criminals because there are more police there. So you're densely packed an area, so you're more able to facilitate policy crime detection because there's more people there. And then you go and amplify more crime in the area by making more arrests. And that's where you get that sort of AI slop because you're starting to see a repetition created by its own repetition, created by reliance on something that may not have been legitimate in the first place. It might be, but the exercise in deciding that has to be a conscious one.

Ibrahim Hasan

Sara, it's been a fantastic conversation. I've really enjoyed our time. If people want to continue the conversation and perhaps learn a bit more about your work, where can they get hold of you?

Saara Idelbi

You can find me on LinkedIn. It's uh Sara Idelby. And you can also see my profile in Chambers. I tend to give talks all over and yeah, get in touch.

Ibrahim Hasan

Excellent. And we'll be sure to put those links in the show's notes. Sarah, thank you very much for your time.

Saara Idelbi

Thank you so much for having me. It's been a delight. I know that we've kind of come a point away from the focus on FOIA and SARS, but I think it is such a fascinating area that could go on about it forever.

Ibrahim Hasan

That's all for this episode of Guardians of Data. My thanks once again to Sara Idelby for sharing her insights. One of the key takeaways from our conversation is that while AI is changing the volume and the nature of information requests, it doesn't change the fundamentals. The existing legal framework still applies. So a good knowledge of the specific access provisions in FOI and the UK GDPR is important alongside critical thinking and an understanding of AI's strengths and limitations. On the other side of the coin, AI can be a valuable assistant, whether it's helping to draft responses, summarize information, or manage records. But as Sara explained, AI should support decision making and not replace it. It's still up to us to question the AI, look out for bias, and make sure the final output is accurate, fair, and legally sound. If you'd like to explore this topic in more detail, there are links to further resources in the show's notes, including a very useful guidance note from the Information Commissioner's Office. You can also listen to episode 13 where Andrew Latham, an information lawyer, gives his tips on AI-generated subject access requests. If you enjoyed this episode, please share it with colleagues and others who work in information governance. It's a great way to help grow the IG community and support professional learning. Thanks for listening and join us next time on Guardians of Data.