Do training and deploying an AI model need separate lawful bases?

Answered

Often yes. The ICO says it usually makes sense to separate research and development (including training and model selection) from deployment, because they are distinct purposes with different circumstances and risks. Identify a purpose and lawful basis for each operation.

From the guidance

Primary (how) ICO: How do we ensure lawfulness in AI?

In many cases, when determining your purpose(s) and lawful basis, it will make sense for you to separate the research and development phase (including conceptualisation, design, training and model selection) of AI systems from the deployment phase. This is because these are distinct and separate purposes, with different circumstances and risks.

Section: How should we distinguish purposes between AI development and deployment?

Read this in ICO: How do we ensure lawfulness in AI? (opens in new tab)

Secondary (normative) ICO: How do we ensure lawfulness in AI?

The development and deployment of AI systems involve processing personal data in different ways for different purposes. You must break down and separate each distinct processing operation, and identify the purpose and an appropriate lawful basis for each one, in order to comply with the principle of lawfulness.

Section: What should we consider when deciding lawful bases?

Read this in ICO: How do we ensure lawfulness in AI? (opens in new tab)

Related questions