Artificial Intelligence Acceptable Use Policy

FCY-ICT-POL-029
Policy InternalReview: 1 Apr 2026 
CAF A2 information-security-managementv3.2

Approved by: Service Director for Corporate Resources

Roles and Responsibilities

The following posts hold responsibilities in relation to this document. Post names are used throughout; personal names are not recorded in policy documents.

Role / Post Responsibilities
Head of IT Maintains the approved AI tools list. Reviews and approves new tool requests and receives reports of policy breaches.
Projects and Innovation Lead Assesses new AI tools for security, compliance, and fitness for purpose. Maintains tool assessment records and acts as a point of advice for staff on appropriate use in a project or innovation context.
Data Protection Officer Approves AI tools for use with personal data. Advises on the data protection implications of specific use cases and outputs.
All Staff Use only approved AI tools for work purposes. Do not input restricted, personal, or commercially sensitive data into unapproved tools. Verify AI outputs before use and report concerns to the Head of IT.

1. Purpose

This policy sets out the rules for staff use of artificial intelligence tools in the course of their duties at Fylde Council. It is designed to enable staff to benefit from AI-assisted productivity while managing the risks of data leakage, inaccurate outputs, and reputational harm.

2. Scope

This policy applies to all staff using any AI tool, whether embedded in approved Council software or accessed independently, for work purposes.

3. Approved AI Tools

Only AI tools that have been assessed and approved by the Head of IT and Data Protection Officer may be used for Council work. The approved tools list is maintained by the ICT team and published on the Council intranet. Microsoft 365 Copilot, where licensed and deployed, is an approved tool for general productivity use within the scope defined by the Copilot data protection assessment.

4. Data Input Rules

Staff must not input any of the following into any AI tool unless it has been specifically approved for that data type:

  • Personal data about residents, employees, or elected members.

  • Commercially sensitive information, including contract details, tender documents, or financial data.

  • Information classified as Restricted under the Data Classification Policy.

  • Draft legal advice or privileged communications.

  • Any data subject to a court order or embargo.

Staff who are uncertain whether it is appropriate to input specific data into an AI tool must seek advice from the Data Protection Officer before doing so.

5. Output Verification

AI-generated outputs must be treated as drafts requiring human review and verification before use. Staff must not: publish AI-generated content without checking it for accuracy, factual errors, or hallucinations; use AI-generated legal, medical, or financial advice as a substitute for professional advice; or pass off AI-generated work as entirely their own in contexts where the use of AI is material and should be disclosed.

6. Accountability and Transparency

Staff remain accountable for any decision or output produced with AI assistance. The use of AI does not transfer responsibility for errors or harm. Where AI is used to produce content or recommendations that affect residents, the responsible officer must be able to explain and stand behind the output.

7. Prohibited Uses

Staff must not use AI tools to: generate content that is discriminatory, misleading, or contrary to the Council’s values; make or communicate decisions about individuals (for example, eligibility for services) without human review; impersonate another person or organisation; or create content intended to mislead residents about Council policy or services.

8. Review

This policy will be reviewed annually and the approved tools list reviewed quarterly.

References and Further Guidance

The following standards, frameworks and legislation have informed the development of this document:

Artificial Intelligence Ethics and Sustainability Principles

FCY-ICT-SOP-002SOP
InternalReview: 1 Jun 2026
CAF D1knowledge-managementv2.1

Approved by: Head of IT

Roles and Responsibilities

The following posts hold responsibilities in relation to this document. Post names are used throughout; personal names are not recorded in policy documents.

Role / Post Responsibilities
Head of IT Owns these principles. Ensures they are applied in all AI procurement and deployment decisions and reports on ethical compliance annually to the Senior Management Team.
Projects and Innovation Lead Applies these principles during AI project scoping and delivery. Includes an ethics assessment in project documentation and flags concerns to the Head of IT.
Senior Management Team Champions ethical AI adoption. Receives the annual AI ethics assurance report and is accountable to elected members and the public for the Council’s AI practices.
All Staff Expected to be aware of and guided by these principles when using AI tools in their work. Report concerns about AI behaviour or fairness to the Head of IT.

1. Purpose

This document sets out the ethical and sustainability principles that will guide Fylde Council’s approach to artificial intelligence. These principles do not replace the governance requirements in the AI Governance Framework, but provide the values foundation from which all Council AI activity flows. They are intended to give staff, elected members, and residents confidence that AI will be used responsibly, fairly, and with regard to its broader impacts.

2. Principle 1: Human Dignity and Respect

AI will be used in ways that respect the dignity, autonomy, and rights of individuals. The Council will not deploy AI in ways that diminish human agency, remove meaningful human oversight from significant decisions, or treat individuals as data points rather than people with rights and interests.

3. Principle 2: Fairness and Non-Discrimination

The Council is committed to using AI only in ways that promote fair outcomes. All AI systems used in service delivery or decision-support will be assessed for potential bias before deployment and monitored for discriminatory outcomes throughout operation. Protected characteristics under the Equality Act 2010 will be considered explicitly in every AI risk assessment.

4. Principle 3: Transparency and Explainability

The Council will be open about where AI is used in its operations. Where AI assists in decisions that affect residents, the Council will be able to explain, in plain language, how the AI reached its output and what human oversight was applied. The Council will not use ‘black box’ AI systems for consequential decisions without first ensuring adequate explainability.

5. Principle 4: Accountability

Every AI system in use at the Council will have a named responsible officer (by post). That officer is accountable for the outcomes of the AI system and cannot delegate accountability to the AI itself or to the supplier. Staff must be able to explain and stand behind AI-assisted work they produce or approve.

6. Principle 5: Privacy and Data Minimisation

The Council will minimise the personal data processed by AI systems to that which is strictly necessary. Where AI can be used with anonymised, pseudonymised, or synthetic data to achieve the same objective, that approach will be preferred. Privacy-preserving AI techniques will be considered during the design and procurement of AI systems.

7. Principle 6: Environmental Sustainability

The Council recognises that large-scale AI models, particularly large language models, have significant energy and environmental footprints. Before deploying an AI system, an assessment of its environmental impact will be conducted. The Council will prefer AI solutions that are proportionate in their resource consumption, and will avoid deploying large-scale AI for tasks where a simpler solution would suffice. Where cloud AI services are used, providers with verified net-zero commitments will be preferred.

8. Principle 7: Democratic Accountability

The use of AI in public service must remain accountable to elected members and the communities they represent. Significant AI deployments affecting service delivery will be reported to the relevant committee of the Council. Residents will have access to clear information about AI use in services that affect them and a means to raise concerns.

9. Applying the Principles

These principles will be considered at every stage of the AI lifecycle, from use case identification and procurement through to deployment, monitoring, and decommissioning. Any proposal to deploy an AI system that cannot be reconciled with these principles should be escalated to the Head of IT and, if necessary, to the Senior Management Team.

References and Further Guidance

The following standards, frameworks and legislation have informed the development of this document:

Artificial Intelligence Transparency Statement

FCY-ICT-SOP-003SOP
InternalReview: 1 Jun 2026
CAF B2knowledge-managementv3.3

Approved by: Head of IT

Roles and Responsibilities

The following posts hold responsibilities in relation to this document. Post names are used throughout; personal names are not recorded in policy documents.

Role / Post Responsibilities
Head of IT Responsible for maintaining this statement and ensuring its accuracy. Notifies the Communications team when updates are required.
Projects and Innovation Lead Provides the AI Register data on which the statement is based. Notifies the Head of IT of new AI deployments requiring disclosure.
Communications Team Publishes and updates the public-facing version of this statement on the Council website when directed by the Head of IT.
Data Protection Officer Reviews the statement for accuracy of data protection disclosures and advises on any ICO transparency expectations.

1. Purpose

This statement explains how Fylde Council uses artificial intelligence in its operations. It is intended to provide transparency to residents, staff, elected members, and other stakeholders about the Council’s current and planned AI activity. The Council is committed to being open about its use of AI and to ensuring that residents can understand and, where appropriate, challenge AI-assisted decisions that affect them.

2. Our Approach to AI

The Council adopts AI only where it can demonstrate a clear public benefit, where appropriate safeguards are in place, and where the use is consistent with the Council’s AI Ethics and Sustainability Principles. Every AI system used by the Council has been assessed for risk and data protection implications before deployment.

3. Current AI Systems in Use

A summary of AI systems currently in operational use is maintained in the Council’s AI Register, held by the Projects and Innovation Lead. At the date of this statement, the Council uses or is piloting the following categories of AI capability: Microsoft 365 Copilot for staff productivity (summarisation, drafting, and data analysis within the Council’s Microsoft 365 tenant); AI-enhanced security monitoring via Microsoft Defender XDR for threat detection across the Council’s ICT estate; and AI-assisted data analytics for planning and performance reporting. A full list of current AI deployments, with descriptions of their purpose and risk classification, is available on request from the Head of IT.

4. AI and Decision-Making

Fylde Council does not currently use AI to make fully automated decisions about residents that produce legal or similarly significant effects. Where AI provides recommendations or decision support in service delivery, a trained Council officer reviews and is accountable for the final decision. The Council will not introduce automated decision-making without completing the required risk assessment and DPIA, and without considering any rights individuals have under UK GDPR Article 22.

5. Data Protection and AI

Personal data is only shared with AI systems where: a lawful basis for processing exists; a Data Protection Impact Assessment has been completed where required; appropriate data processing agreements are in place with the AI supplier; and the AI system has been assessed and approved by the Head of IT and Data Protection Officer. The Council does not input resident personal data into publicly available generative AI tools without specific approval.

6. How to Find Out More or Raise a Concern

Residents who have questions about how the Council uses AI, or who believe that an AI-assisted decision has affected them unfairly, may contact the Council’s Data Protection Officer. Residents retain the right to request human review of any decision made about them. Enquiries can be directed to: Data Protection Officer, Fylde Council, Town Hall, Lytham St Annes FY8 1LW, or by email via the Council’s website.

7. Updates to This Statement

This statement will be reviewed and updated at least annually and whenever a significant new AI system is deployed. The version history at the front of this document records all updates. The public-facing version on the Council’s website will be updated in line with this internal document.

References and Further Guidance

The following standards, frameworks and legislation have informed the development of this document:

Artificial Intelligence Governance Framework

FCY-ICT-POL-030
PolicyRestrictedReview: 1 May 2026
CAF A1information-security-managementv2.1

Approved by: Senior Management Team

Roles and Responsibilities

The following posts hold responsibilities in relation to this document. Post names are used throughout; personal names are not recorded in policy documents.

Role / Post Responsibilities
Senior Management Team Ultimate approval authority for this framework and for high-risk AI deployments. Receives quarterly AI governance reports and approves significant changes to the governance structure.
Service Director for Corporate Resources Provides executive oversight of AI governance. Approves limited and high-risk AI deployments in line with delegated authority and escalates to the SMT where required.
Head of IT Responsible AI Assurance Officer. Oversees the AI governance framework, maintains the AI Register, and chairs the periodic AI governance review.
Projects and Innovation Lead Operational AI lead. Manages the AI Register, coordinates risk assessments and DPIAs, and acts as secondary approver for AI deployments to confirm appropriate and forward-thinking implementation.
Data Protection Officer Provides independent oversight of AI data protection compliance. Reviews high-risk AI DPIAs and advises on compliance with UK GDPR and the EU AI Act.
Service Directors Accountable for AI use within their service area. Act as the sponsoring authority for AI deployments in their service and are responsible for outcomes.

1. Purpose

This framework establishes the governance structure for the responsible adoption, oversight, and accountability of artificial intelligence at Fylde Council. It ensures that all AI systems are deployed within a consistent framework of approval, monitoring, and review, and that the Council can demonstrate compliance with the EU AI Act, UK GDPR, and public sector accountability obligations.

2. Scope

This framework applies to all AI systems deployed or used by the Council, including procured AI services, AI embedded in enterprise software, and AI tools used by individual staff members for work purposes.

3. AI Register

The Projects and Innovation Lead will maintain an AI Register recording all AI systems in use or under evaluation by the Council. Each entry will include: system name and supplier; purpose and service area; EU AI Act risk classification; date of initial risk assessment and DPIA where applicable; approval status and date; responsible post; and next scheduled review date. The AI Register will be reviewed quarterly by the Head of IT.

4. Approval Gateway

All new AI deployments must pass through an approval gateway before operational use. The gateway stages are: identification and initial scoping (Projects and Innovation Lead); risk classification (using the AI Risk Assessment Procedure); DPIA completion where required (Data Protection Officer); Head of IT approval (all deployments); Service Director approval (limited and high risk); Senior Management Team approval (high risk only). No AI system may enter production without completed gateway documentation.

5. Ongoing Oversight

All deployed AI systems will be subject to periodic performance and governance review. Review frequency will be: annually for minimal and limited risk systems; quarterly for high-risk systems. Reviews will assess whether the system is performing as intended, whether any new risks have emerged, whether bias or discriminatory outcomes have been observed, and whether the original DPIA and risk assessment remain valid. Review outcomes will be recorded in the AI Register.

6. AI Incident Reporting

Staff must report AI-related incidents, including: AI outputs that appear significantly incorrect or harmful; AI-assisted decisions that appear discriminatory or unfair; data leakage attributable to an AI system; and unexpected AI behaviour. AI incidents will be logged in the ITSM system and managed under the ICT Incident Management Policy. The Head of IT will determine whether an AI incident requires reporting to the ICO or other regulator.

7. Procurement Requirements

All AI systems procured from third parties must meet the supplier security requirements in the Supplier Security Policy. Procurement specifications must include: the AI Act compliance status of the system; the supplier’s data protection and security certifications; the supplier’s approach to model explainability and bias testing; and contractual commitments to notify the Council of significant changes to the AI model.

8. Review

This framework will be reviewed annually and following any material change to AI legislation or significant AI incident.

References and Further Guidance

The following standards, frameworks and legislation have informed the development of this document:

 

 

Policy on AI-Generated, Computationally Manipulated, and Falsified Evidence in External Submissions

 

v1.0  |  May 2026

Document Owner: Head of IT

 

 

Document Control

 

Document Control
Document Title Policy on AI-Generated, Computationally Manipulated, and Falsified Evidence in External Submissions
Document Reference FCY-GOV-POL-001
Document Type Policy
Version v1.0
Status Active
Classification Internal
Service Area Cross-Service (Planning, Building Control, Licensing, Enforcement, Legal)
CAF Control Area N/A
Document Owner Head of IT
Approval Authority Service Director for Corporate Resources
Review Cycle Annual
Date of Issue May 2026
Next Review Date July 2027
AI Applicable Yes
DPIA Required No
LGR / Data Sharing Digital Transformation Planning

 

Version History

 

Version Date Author (Post) Approved By Summary of Changes
v1.0 May 2026 Head of IT Service Director for Corporate Resources Initial issue. Policy developed in response to operational experience of AI-generated and computationally manipulated evidence submitted in external applications and regulatory proceedings. First council policy of this type.

 

 

Roles and Responsibilities

The following posts hold responsibilities under this policy. Post names are used throughout; personal names are not recorded in policy documents.

 

Role / Post Responsibilities
Head of IT Policy owner. Provides technical guidance to service areas on detection methods, tools, and emerging AI capabilities relevant to evidence falsification. Coordinates with ICT and Digital on any technical investigation support required.
Service Director for Corporate Resources Approves this policy. Receives escalations involving confirmed or strongly suspected falsification. Authorises referral to the police and legal counsel.
Head of Planning Responsible for implementing this policy within Planning and Development Management. Ensures officers are trained to identify indicators of AI-generated or manipulated photographic and documentary evidence in planning applications and appeals.
Head of Building Control Responsible for implementing this policy within Building Control. Ensures that site inspection photography and compliance documentation submitted in lieu of physical inspections is subject to verification checks. The operational trigger for this policy.
Licensing Manager Responsible for implementing this policy within Licensing. Ensures that photographic and documentary evidence submitted in support of licence applications and representations is subject to appropriate scrutiny.
Legal Services Advises on the legal consequences of confirmed falsification, prepares referrals to the police, and manages any proceedings arising from fraudulent submissions. Advises on the evidential standards required to sustain enforcement action.
All Decision-Making Officers Responsible for applying the verification checks defined in this policy when assessing evidence submitted with external applications, representations, or regulatory proceedings. Must escalate suspected falsification in accordance with this policy.

 

 

1. Purpose

This policy establishes Fylde Council’s position on, and response to, the submission of artificially generated, computationally manipulated, post-processed, or otherwise falsified photographic, video, or documentary evidence in external applications, representations, appeals, and regulatory proceedings.

The rapid advancement and increasing accessibility of generative artificial intelligence tools, including large image generation models, video synthesis tools, and AI-assisted document drafting, has materially lowered the barrier to producing convincing but entirely fabricated evidence. The Council has direct operational experience of submissions where photographic evidence is suspected to have been generated or altered using such tools rather than captured at the actual site or location claimed.

This policy does not presume dishonesty on the part of applicants or agents. It establishes the framework within which officers assess, verify, and respond to evidence that raises legitimate concerns about authenticity, and the process by which confirmed or strongly suspected falsification is escalated and, where appropriate, referred to the police.

2. Scope

This policy applies to all external submissions received by Fylde Council that include photographic, video, or documentary evidence used to support or contest a decision, including:

  • Planning applications, pre-application enquiries, and planning appeals.
  • Building regulations applications, completion certificates, and compliance documentation, including site inspection photographs submitted in lieu of physical inspections.
  • Licensing applications, representations, and licence review proceedings.
  • Enforcement investigations and appeals.
  • Statutory consultations where evidence is submitted in support of a position.
  • Complaints and representations where photographic or documentary evidence is provided to support a claim.
  • Any other regulatory or decision-making process in which the Council relies on externally submitted evidence.

 

This policy applies to all officers involved in the receipt, assessment, and determination of the above, regardless of service area.

3. Background and Context

3.1 The Emerging Risk

Until recently, the production of convincing falsified photographs or documents required significant technical skill and was therefore relatively rare. Modern generative AI tools, including text-to-image models, inpainting tools, and large language models capable of drafting professional reports, can be used by individuals without technical expertise to produce evidence that is superficially plausible.

Specific risks the Council has identified or assessed include:

  • Photographs of building works or site conditions generated by AI or edited to show a state of completion or compliance that does not exist, submitted in place of genuine site inspection photography.
  • Photographs of a site submitted to support a planning application that have been manipulated to remove or add features, alter conditions, or misrepresent the visual impact of a proposal.
  • Professional reports, heritage assessments, structural surveys, or ecological surveys generated using AI tools without genuine site investigation, submitted as supporting evidence.
  • Falsified compliance certificates, warranty documents, or statutory approvals submitted as part of a building control completion package.
  • Video evidence submitted in enforcement or licensing proceedings that has been synthetically generated or materially edited.

3.2 Legal Context

The submission of falsified evidence to a local planning authority, building control body, or licensing authority is a serious matter with potential criminal consequences. The relevant legal framework includes:

  • Fraud Act 2006: fraud by false representation (section 2) applies where a person dishonestly makes a false representation with the intent to make a gain or cause a loss. Submitting AI-generated photographs as genuine site evidence may constitute fraud.
  • Forgery and Counterfeiting Act 1981: the making of a false instrument (section 1) applies where a document is falsified with the intention that it be used to induce another person to accept it as genuine. Fabricated certificates or falsified professional reports may fall within this provision.
  • Town and Country Planning Act 1990, section 65: it is a criminal offence to knowingly or recklessly make a false or misleading statement in connection with a planning application.
  • Building Safety Act 2022: imposes enhanced duties of competence and honesty on those submitting information to building control bodies, particularly for higher-risk buildings. False statements in building control submissions may attract criminal liability under the Act.
  • Perjury Act 1911: false statements made on oath or in a statutory declaration carry criminal liability.
  • Computer Misuse Act 1990: may apply where AI tools are used in conjunction with unauthorised access to systems to obtain or manipulate data.

4. General Verification Principles

Officers are not expected to be forensic specialists. This policy does not require technical expertise in AI detection. What it does require is that officers apply reasonable professional judgement, that they are alert to the indicators set out in Section 5, and that they escalate promptly when concerns arise rather than proceeding to determination on the basis of evidence whose authenticity is in doubt.

The following general principles apply to all submissions involving photographic or documentary evidence:

  • Evidence should be consistent. Photographs submitted together should be internally consistent in terms of lighting, weather, season, site conditions, and the presence or absence of site features. Inconsistency across a submission is a material indicator of concern.
  • Evidence should be corroborable. Genuine site photographs can generally be corroborated against aerial imagery, street-level imagery, neighbouring properties, or previous records. Where evidence cannot be corroborated by any independent source, further verification should be sought.
  • Metadata matters. Digital photographs and documents contain metadata that records the device, date, time, location, and, in the case of documents, the software used and modification history. Absent, incomplete, or inconsistent metadata is a legitimate basis for requesting further information.
  • Professional documentation should be verifiable. Reports and certificates produced by professionals should be traceable to a named individual with verifiable registration in the relevant professional body. Where this cannot be confirmed, the document should not be accepted at face value.
  • The burden of demonstrating authenticity rests with the submitter. If an officer has reasonable grounds to question the authenticity of submitted evidence, it is appropriate to request original files, additional verification, or a physical site inspection. The Council is not required to proceed on the basis of evidence it cannot verify.

5. Indicators of Falsification and Detection Approaches

The following table sets out the common indicators of AI-generated or manipulated evidence by evidence type, together with the primary detection approach officers should apply.

 

Evidence Type Common Indicators of Falsification Detection Approach
AI-generated photographs Unnatural lighting or shadows inconsistent with time of day or season. Architectural features that do not match known site characteristics. Background elements that are blurred, distorted, or repeat in a pattern. Absence of expected site features (scaffolding, skips, signage, adjacent properties). Metadata absent or inconsistent with the claimed date and time of capture. Cross-reference with aerial imagery (Google Maps, Bing, or Council GIS). Check EXIF metadata for device, timestamp, and GPS data. Request original unprocessed files. Compare with previous application photographs or known site records. Request a physical site inspection.
Post-processed or digitally altered photographs Inconsistencies in pixel density or compression artefacts at boundaries of edited areas. Evidence of cloning or patching (repeating texture patterns). Colours or lighting that change abruptly between areas of an image. Objects or features removed or added that are inconsistent with other images of the same site. EXIF data showing editing software use or a modification timestamp later than the capture timestamp. EXIF metadata analysis including software field. Request original RAW or uncompressed files. Compare with other photographs from the same submission and previous records. Use image forensics tools to detect cloning or splicing artefacts.
AI-generated documents and reports Generic or non-specific content that does not reference the actual site, address, or application in sufficient detail. Inconsistencies between the document and other submitted materials. References to standards, legislation, or guidance that do not exist or are incorrectly cited. Lack of professional registration details, signatory credentials, or firm identity. Formatting inconsistencies suggesting assembly from template fragments. Verify professional credentials of signatories against relevant registers (RICS, RIBA, CABE, relevant professional bodies). Cross-reference specific claims against other submitted documents and known site records. Request original source data or survey records underlying the report. Contact the purported author to confirm authorship.
Falsified compliance certificates and statutory documents Certificate or document not traceable to the issuing body. Reference numbers that do not conform to the format used by the relevant authority or certification body. Names of certifiers not registered with the relevant scheme. Inconsistencies in font, layout, or logo compared with genuine examples. Verify directly with the issuing body or certification scheme. Cross-reference reference numbers against scheme databases where publicly available. Contact the purported certifier by an independently obtained number, not a number provided in the submission.
Synthetic or manipulated video evidence Inconsistent lighting or shadow movement. Unnatural movement of people, vehicles, or environmental elements. Faces or number plates that are blurred, distorted, or absent where they would be expected. Temporal inconsistencies (clock faces, seasonal indicators, passing vehicles inconsistent with the claimed date or time). Request original uncompressed video files with metadata. Cross-reference with independently obtained CCTV or third-party footage for the same location and time period. Consult with the Head of IT for technical analysis support.

 

This table is not exhaustive. AI technology is developing rapidly and new indicators will emerge. Officers should apply professional judgement and consult the Head of IT where they encounter concerns that are not clearly addressed by this framework.

6. Process for Handling Suspected Falsification

6.1 Initial Concern

Where an officer identifies indicators of potential falsification, they should:

  1. Document the specific concern in writing, describing the indicator or indicators that have given rise to it, before taking any further action.
  2. Not proceed to determine the application or make a decision that relies on the evidence in question.
  3. Notify their line manager and the relevant Head of Service of the concern on the same working day.
  4. Where technical assistance is required, contact the Head of IT.

6.2 Verification Step

The officer, in consultation with their line manager, will determine the appropriate verification approach from the following options:

  • Request original unprocessed photographic files (RAW format or full-resolution JPEG with EXIF intact) from the applicant or agent.
  • Request a physical site inspection, either conducted by a Council officer or by the applicant’s professional adviser under an agreed inspection protocol.
  • Cross-reference submitted imagery against aerial or street-level imagery from independent sources, including the Council’s own GIS systems.
  • Verify professional credentials of the author of any report or certificate against the relevant professional body register.
  • Contact the purported author of a document directly using independently obtained contact details to confirm authorship.
  • Consult the Head of IT for technical metadata analysis or AI detection tool assessment where the above steps are inconclusive.

6.3 Outcome of Verification

Following verification, one of three outcomes applies:

  • Evidence confirmed as authentic: proceed with the determination in the normal way. Document the verification steps taken and the basis for the conclusion.
  • Evidence cannot be verified but concerns are not confirmed: seek further information from the applicant. If the applicant fails to provide satisfactory further information within a reasonable period, treat the evidence as unreliable and proceed accordingly. Document the position.
  • Falsification confirmed or strongly suspected: escalate in accordance with Section 7.

7. Consequences and Escalation

The following table sets out the consequences of confirmed or strongly suspected falsification at each stage of a regulatory process.

 

Finding Consequence
Suspected falsification identified during assessment Officer pauses determination and escalates to line manager and Head of Service. Verification checks initiated. Applicant or agent notified that further information is required. Application clock may be suspended pending receipt of verified evidence where permitted under the relevant statutory procedure.
Confirmed falsification prior to determination Application invalidated or refused. Applicant and agent formally notified of the finding in writing. Matter referred to Legal Services for advice on referral to the police. Record created in the Council’s case management system. Agent or professional may be referred to their regulatory body.
Falsification discovered post-determination Legal Services instructed immediately. Enforcement action considered in accordance with the relevant statutory regime (planning enforcement, building control, licensing review). Referral to the police for investigation of fraud or forgery. Any consent, approval, or licence granted on the basis of falsified evidence reviewed for revocation.
Referral to the police Legal Services prepares the referral in coordination with the relevant Head of Service and the Head of IT where technical evidence is required. All digital evidence preserved and documented in accordance with Section 8 of this policy. The Council will cooperate fully with any police investigation.

 

Where an agent or professional adviser is implicated in the submission of falsified evidence, the Head of Service will consider referral to the relevant professional body (for example the Royal Institution of Chartered Surveyors, the Royal Institute of British Architects, or the Chartered Institute of Building) in addition to any police referral.

8. Evidence Preservation

Where falsification is confirmed or strongly suspected, all digital evidence must be preserved immediately and handled in a manner that maintains its integrity for potential criminal proceedings or enforcement action. The following steps apply:

  • The original submission, including all files and correspondence, must be preserved in its current state. No files should be deleted, moved, or modified.
  • The Head of IT must be notified so that any relevant system records, email metadata, or upload logs can be preserved.
  • A contemporaneous written record of all actions taken, observations made, and decisions reached must be created and stored alongside the case file.
  • Any copies of the evidence made for verification purposes must be clearly labelled as copies and stored separately from the originals.
  • Access to the preserved evidence should be restricted to the officers directly involved in the case and Legal Services.

The principles of the ACPO (College of Policing) Digital Evidence Guidelines should be followed where possible to ensure that any evidence gathered is admissible in subsequent proceedings.

9. Communication with Applicants and Agents

Where verification is requested or concerns are raised, communication with the applicant or agent must be carefully managed to avoid compromising any subsequent investigation:

  • Initial communication should request further information without disclosing the specific nature of the concern where possible. A request for original files or a site inspection is a routine verification step that does not require the Council to disclose its suspicion at the outset.
  • Where the Council has confirmed or strongly suspects falsification and is considering a criminal referral, Legal Services must be consulted before any further communication with the applicant or agent. Premature disclosure of the Council’s findings may prejudice any criminal investigation.
  • All communications in a case involving suspected falsification must be in writing and retained on the case file.
  • Officers must not conduct informal conversations with applicants or agents about suspected falsification without prior agreement from their Head of Service and Legal Services.

10. Training and Awareness

The Head of IT, in consultation with Heads of Service, will ensure that relevant officers receive awareness training covering:

  • The types of AI-generated and manipulated evidence now in circulation and the indicators described in Section 5 of this policy.
  • The practical verification steps available to officers without specialist technical expertise.
  • The escalation process and the importance of documentation.
  • The legal framework and the potential consequences of falsification.

Training will be incorporated into the relevant service induction programmes and refreshed annually or following any significant development in AI-generated evidence capabilities. The Head of IT will maintain a watching brief on developments in AI image and document generation and will update the training and the indicators in Section 5 as required.

11. Relationship with Other Policies and Processes

This policy operates alongside the following Council policies and should be read in conjunction with them:

  • ICT Acceptable Use Policy (FCY-ICT-POL-002): governs staff use of AI tools in their own work and is distinct from this policy, which concerns external submissions.
  • Artificial Intelligence Acceptable Use Policy (FCY-ICT-POL-029): sets out the standards for staff use of generative AI, including the prohibition on using AI to generate or falsify records.
  • Artificial Intelligence Governance Framework (FCY-ICT-POL-030): the Council’s overarching AI governance framework.
  • Data Protection and Information Governance Policy (FCY-ICT-POL-019): governs the handling of personal data in connection with any investigation under this policy.
  • The Council’s Anti-Fraud and Corruption Policy and Whistleblowing Policy: apply where falsification involves or is connected to suspected fraudulent activity by or in connection with the Council.
  • The relevant service-specific procedural guidance for planning, building control, licensing, and enforcement: this policy sets the cross-service framework; service-specific procedures govern the operational steps within each regulatory regime.

12. Review

This policy will be reviewed annually by the Head of IT in consultation with Heads of Service. Given the pace of development in generative AI capabilities, the indicators table in Section 5 will be reviewed and updated at least annually and following any significant development in AI-generated evidence that comes to the Council’s attention through its operational experience or through national guidance from MHCLG, the Planning Inspectorate, or the Health and Safety Executive.

The Head of IT will maintain a log of all cases in which this policy has been invoked, including the nature of the concern, the outcome of verification, and whether a referral was made. This log will be used to inform the annual policy review.

 

 

 

 

References and Further Guidance

The following legislation, standards, and guidance have informed the development of this document:

 

  • Fraud Act 2006. legislation.gov.uk.
  • Forgery and Counterfeiting Act 1981. legislation.gov.uk.
  • Town and Country Planning Act 1990, section 65 – False statements in planning applications. legislation.gov.uk.
  • Planning and Compulsory Purchase Act 2004. legislation.gov.uk.
  • Building Safety Act 2022. legislation.gov.uk.
  • Building Regulations 2010. legislation.gov.uk.
  • Perjury Act 1911. legislation.gov.uk.
  • Computer Misuse Act 1990. legislation.gov.uk.
  • EU AI Act (Regulation (EU) 2024/1689) Article 50 – Transparency obligations for AI-generated content. European Parliament and Council.
  • College of Policing: Digital Evidence and Cybercrime Guidelines (2020). https://www.college.police.uk
  • NCSC: Deepfakes and Emerging Synthetic Media Threats (2023). https://www.ncsc.gov.uk
  • Planning Inspectorate: Evidence in Planning Appeals – Guidance for Parties (2024). https://www.gov.uk/planning-inspectorate
  • RICS: Professional Standards and Ethical Practice – Integrity of Reports (2023). https://www.rics.org
  • Royal Institute of British Architects: Code of Professional Conduct (2021). https://www.architecture.com
  • MHCLG: Planning Practice Guidance – Use of Digital Technology in Planning (2024). https://www.gov.uk
  • Health and Safety Executive: Competence Requirements for Building Control (2023). https://www.hse.gov.uk
  • ICO: AI and Data Protection – Synthetic Data and Deepfakes (2023). https://ico.org.uk
  • Fylde Council: ICT Acceptable Use Policy FCY-ICT-POL-002.
  • Fylde Council: Artificial Intelligence Acceptable Use Policy FCY-ICT-POL-029.
  • Fylde Council: Artificial Intelligence Governance Framework FCY-ICT-POL-030.
  • Fylde Council: Data Protection and Information Governance Policy FCY-ICT-POL-019.