AI regulation and compliance

AI and Automated Decision-Making

Short answer: section 80 of the Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A to 22D from 5 February 2026. For ordinary personal data, a significant decision based solely on automated processing is permitted if the Article 22C safeguards are in place. Article 22A(1) supplies both definitions: a decision is based solely on automated processing if there is no meaningful human involvement in taking it, and it is significant if it produces a legal effect for the data subject or has a similarly significant effect. Where the decision is based entirely or partly on special-category data, Article 22B(1) to (3) permits it only on explicit consent, or where contract necessity or legal authority is combined with the substantial-public-interest condition in Article 9(2)(g). Article 22B(4) is a separate bar and applies whatever the data: a significant solely automated decision may not be taken where the processing is carried out entirely or partly in reliance on the recognised legitimate interests basis in Article 6(1)(ea). Article 22C requires information about the decision, an opportunity to make representations, human intervention and a right to contest. See DUAA 2025, section 80 and SI 2026/82. Last updated 18 July 2026.

Automated decision-making under the UK GDPR has been reformed. The Data (Use and Access) Act 2025, section 80 replaced Article 22 with new Articles 22A to 22D, which came into force on 5 February 2026 under SI 2026/82, regulation 2(j). The old prohibition on solely automated decisions with significant effects has been replaced with a safeguards regime: such decisions are now permitted for most personal data, provided controllers put the required safeguards in place. Special category data is treated more restrictively. AI-enabled products are regulated in the UK through data protection and sector regulation rather than a single AI statute; our guide to UK AI regulation sets out that position.

A controller or processor deploying an AI or automated decision-making system must work through each of these under the UK GDPR: model training, lawful basis, the Article 22C safeguards, DPIAs, transparency, vendor contracts and international transfers. The ICO’s guidance on automated decision-making, including profiling covers most of that ground.

Key findings (UK automated decision-making regime, 2026)

  • Article 22 of the UK GDPR was replaced by new Articles 22A to 22D on 5 February 2026, under section 80 of the Data (Use and Access) Act 2025 commenced by SI 2026/82, reg 2(j). Source: DUAA 2025, s 80; SI 2026/82, reg 2(j).
  • Solely automated decisions with significant effects are now permitted for most personal data, subject to the Article 22C safeguards: information about the decision, an opportunity to make representations, human intervention on the part of the controller, and the ability to contest the decision. The separate duty to give meaningful information about the logic, the significance and the envisaged consequences sits in Articles 13(2)(f), 14(2)(g) and 15(1)(h), each of which now refers to Article 22C. Source: UK GDPR, Articles 22C(2), 13(2)(f), 14(2)(g) and 15(1)(h).
  • Special category data remains subject to the narrower Article 22B gateway. A significant solely automated decision is permitted only where the explicit-consent condition in Article 22B(2) is met, or where the second condition in Article 22B(3) is met, namely that the decision is necessary for entering into or performing a contract between the data subject and a controller, or is required or authorised by law, and point (g) of Article 9(2) applies. Source: UK GDPR, Article 22B(1) to (3).
  • The ICO has investigatory and sanctioning powers strengthened by the DUAA, including a PECR penalty cap raised from GBP 500,000 to the higher maximum amount, which for an undertaking is GBP 17.5 million or 4% of total annual worldwide turnover, whichever is higher. Source: DPA 2018, s 157(5), as applied to PECR by PECR Sch 1 para 18 (Sch 1 substituted by DUAA 2025, Sch 13).
  • Since 19 June 2026 a controller must facilitate the making of complaints by data subjects about infringement of the UK GDPR, and must acknowledge a complaint within 30 days of receiving it. Source: DPA 2018, s 164A, inserted by DUAA 2025, s 103(2) and Sch 10; SI 2026/82, reg 3(a).
ConceptPosition from 5 February 2026Source
Solely automated decision-making (most personal data)Permitted, subject to the Article 22C safeguardsDUAA 2025, s 80; UK GDPR, Art 22C
Solely automated decision-making (special category data)Permitted only on a condition in Article 22B(2) or (3)UK GDPR, Art 22B
Required safeguardsInformation about the decision; opportunity to make representations; human intervention; ability to contestUK GDPR, Art 22C(2)
PECR penalty capHigher maximum amount: GBP 17.5 million, or 4% of total annual worldwide turnover if higher (was GBP 500,000)DPA 2018, s 157(5), as applied by PECR Sch 1 para 18
Controller complaints dutyIn force from 19 June 2026; acknowledgement within 30 daysDPA 2018, s 164A

When AI becomes a data protection problem

AI becomes a data protection problem the moment personal data enters the pipeline. That includes training data, inference inputs, model outputs that identify or profile individuals and logs that record who decided what. The lawful basis, transparency and accountability obligations in the UK GDPR apply to each of those stages, not just to the final decision.

The controllers most exposed are those taking significant decisions solely by automated processing, meaning without meaningful human involvement: credit scoring, fraud detection, recruitment screening, benefits eligibility, insurance underwriting and tariff personalisation. Since 5 February 2026 these decisions have been governed by Articles 22A to 22D rather than the former Article 22 prohibition. The compliance task is to identify each significant solely automated decision and make the Article 22C safeguards operational, whatever the category of data, because Article 22C(1) turns on the decision rather than on the data type. Article 22B adds a narrower gateway for special-category data and, in Article 22B(4), bars reliance on Article 6(1)(ea) altogether.

Old Article 22 and new Articles 22A to 22D compared

IssueOld Article 22 (pre-5 February 2026)New Articles 22A to 22D (in force)
Default positionProhibition on solely automated decisions with legal or significant effectsPermitted for most personal data, subject to safeguards
Special category dataProhibited unless explicit consent or substantial public interestProhibited unless explicit consent, or contract necessity or legal authority combined with point (g) of Article 9(2) (Article 22B(2) and (3))
SafeguardsRight to human intervention, to express a view, to contest the decisionInformation, human review on request, ability to make representations, ability to contest (Article 22C)
Partial automationNot clearly addressedArticle 22A(1)(a) turns on whether there is meaningful human involvement, so involvement amounting only to a rubber-stamp with no meaningful review leaves the decision inside Articles 22B and 22C; Article 22A(2) requires the extent to which the decision is reached by profiling to be taken into account
TransparencyArticles 13 to 15 reference to Article 22Retained; Articles 13(2)(f), 14(2)(g) and 15(1)(h) now refer to automated decision-making subject to the safeguards required under Article 22C
SourceArticle 22 UK GDPR (substituted 5 February 2026 by Chapter III, Section 4A)DUAA 2025 section 80, commenced by SI 2026/82

Why AI governance matters now

The statutory default has loosened, and the practical compliance burden on a controller has grown at the same time.

Section 80 of the Data (Use and Access) Act 2025 rewrote the rules for automated decision-making. Article 22C(2) requires the controller to put safeguards in place which consist of or include measures giving the data subject information about the decision, enabling representations, enabling human intervention on the part of the controller and enabling the decision to be contested. The safeguards must be in place before the decision is taken, not added after complaint. Part 5 of the DUAA also changes the ICO’s structure, powers and complaints handling, which has operational consequences for every controller.

The ICO’s AI and biometrics strategy, published on 25 June 2025, sets out four priorities: a statutory code of practice for organisations developing or deploying AI and automated decision-making, generative AI foundation models, automated decision-making in recruitment and public services, and facial recognition technology in law enforcement. The ICO’s guidance on automated decision-making, including profiling has been redrafted for the DUAA and is out for consultation; the pre-DUAA version remains available as a PDF and the ICO will withdraw it once the updated guidance is finalised. No statutory code on AI and automated decision-making has been issued, and on the ICO’s own account the redrafted guidance will inform the code it intends to develop.

Most organisations buy AI-enabled products rather than train foundation models themselves, so the training data, model weights and inference pipelines sit with third-party processors or sub-processors. Controller accountability under Article 5(2) UK GDPR does not transfer with the software: the controller remains responsible for lawful basis, transparency, data subject rights and DPIA.

A UK organisation with EU operations must comply with both regimes: the EU AI Act has applied in general since 2 August 2026, but Regulation (EU) 2026/1744 rewrote its application timetable, so the Chapter III obligations for high-risk AI systems now apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems, and the EU GDPR retains the Article 22 prohibition. The UK/EU data protection divergence page sets out the gaps between them.

Common AI governance failures

A controller carries the same UK GDPR obligations for an AI system as for any other processing of personal data, and the recurring failures are failures to meet them.

Article 35(1) UK GDPR requires a DPIA before processing likely to result in a high risk to the rights and freedoms of individuals, and the ICO’s list of processing likely to result in high risk gives artificial intelligence and machine learning as examples of innovative technology, which requires a DPIA when combined with any other criterion on the list, and gives the application of AI to an existing process as an example of large-scale profiling, which requires one on its own. The controller carries that obligation, so the assessment comes before a model or a vendor is selected and before training data is ingested. Where it comes after launch, the lawful basis is being recorded after the event.

The lawful basis must fit the processing it is claimed for. Consent does not work for training data scraped from the open web, employee data used for productivity models or legacy customer data repurposed for machine learning. Legitimate interests under Article 6(1)(f) requires the ICO’s three-part test of purpose, necessity and balance, recorded in a legitimate interests assessment. Contract performance covers only the processing the contract requires.

Since 5 February 2026, Article 22C has required a controller taking a decision with a legal or similarly significant effect solely by automated processing to provide information about the decision, allow representations, provide human intervention and allow the decision to be contested. The notice must be clear, the review pathway must reach a person able to influence or reverse the decision, and the complaints process must identify a challenge to an automated decision as such.

A processor contract must carry the Article 28 UK GDPR terms in full, map the sub-processor chain for any foundation model, and give audit rights that reach training data provenance rather than a SOC 2 report alone. Where the model is hosted in the United States, Article 46(1A) requires an appropriate safeguard, in practice the UK International Data Transfer Agreement or the Addendum to the EU standard contractual clauses, together with the controller’s own assessment that the data protection test in Article 46(6) is met, which the ICO still calls a transfer risk assessment.

A privacy notice must name the purposes, the logic, the categories of data used and the consequences of the decision. “We use AI” does not meet the requirement in Articles 13(2)(f) and 14(2)(g) UK GDPR to give meaningful information about the logic involved, the significance and the envisaged consequences of the processing.

What good AI governance looks like

Governance of an AI system runs from before procurement until the system is decommissioned.

The controller records a lawful basis for each processing activity rather than for the project as a whole. Legitimate interests must be supported by a legitimate interests assessment; consent by granular, freely given, informed and withdrawable consent mechanics; special category processing by a condition in Article 9(2), supported, where that condition requires domestic authorisation, by a condition in Schedule 1 to the DPA 2018.

The DPIA must be completed before the AI system goes live and updated at each material change. It must name the controller, the processor, the data categories, the lawful basis, the risks to data subjects and the mitigations. The DPIA page sets out the process.

The Article 22C safeguards must work in operation. The notice to data subjects must be specific. The human review pathway must be reachable, the reviewer must be competent and independent of the automated decision, and the reviewer must have authority to overturn the decision. The ability to make representations and to contest must be described in the privacy notice and delivered in the customer journey.

The processor contract reflects the Article 28 obligations in full, with specific provisions on training data, model outputs, audit rights, sub-processor flow-down, incident notification and international transfers. The data governance, transfers and accountability page covers the transfer mechanics.

The controller tells the data subject what is happening, in plain language: meaningful information about the logic, the significance and the envisaged consequences. The ICO’s guidance sets that standard.

The incident response plan covers AI-specific failure modes: hallucination in customer-facing outputs, model drift, adversarial inputs, training data leakage through inference, data subject complaints about automated decisions and regulator enquiries. It runs alongside the general data breach response procedures rather than replacing them.

When to instruct specialist data protection advice on AI

Specialist advice earns its cost at design, at procurement, at launch, and on a complaint or an investigation.

The lawful basis, the Article 22C safeguards and the DPIA scope are set at the design stage, and correcting them later means re-papering the arrangement or switching the system off.

The vendor contract, the Article 28 terms, the international transfer mechanism and the audit rights are negotiated at procurement, and vendor standard terms routinely fall short of the UK GDPR requirements.

The privacy notice, the customer communications and the human review pathway are tested before launch, which is the last point at which a transparency failure can be corrected before a data subject complains.

On a complaint or an investigation, the ICO or a sector regulator (the FCA, Ofcom or the PSR) starts asking questions, and the 30-day acknowledgement duty in section 164A of the DPA 2018 applies. The UK GDPR compliance page covers ICO investigations.

Frequently asked questions about AI and automated decision-making

Has Article 22 of the UK GDPR been repealed?

Yes. Section 80 of the Data (Use and Access) Act 2025 replaced the old Article 22 with new Articles 22A to 22D. The change came into force on 5 February 2026 under SI 2026/82. The old prohibition on solely automated decisions with legal or similarly significant effects has been replaced with a safeguards regime that permits such decisions for most personal data, subject to the Article 22C(2) safeguards of information about the decision, an opportunity to make representations, human intervention and the ability to contest.

Do we need consent to use AI systems that process personal data?

Usually not. Consent under Article 6(1)(a) UK GDPR must be freely given, specific, informed and withdrawable, which is difficult to achieve for AI training and inference across large volumes of personal data. Legitimate interests under Article 6(1)(f) is more often the right basis, provided you have done a documented legitimate interests assessment. Article 6(1)(ea), the recognised legitimate interests basis added on 5 February 2026, takes the lawful bases in Article 6(1) to seven; it removes the balancing test but is available only where the processing meets one of the five conditions in Annex 1, it does not apply to a public authority acting in the performance of its tasks, and Article 22B(4) bars any significant solely automated decision taken in reliance on it. Special category data needs an Article 9(2) condition in addition. The lawful basis should be set per processing activity before the system goes live, not retro-fitted.

When is a DPIA required for an AI system?

Article 35 UK GDPR requires a DPIA for processing likely to result in high risk. The ICO’s list of processing likely to result in high risk requires a DPIA for large-scale profiling, and for decisions about a person’s access to a product, service, opportunity or benefit that are based to any extent on automated decision-making. It requires one for innovative technology, including AI, where that is combined with any other criterion on the list. The ICO has flagged that this list is under review because of the DUAA. The DPIA must be completed before processing starts and updated whenever the purpose, data or risk profile materially changes.

What do the Article 22C safeguards require in practice?

Article 22C(1) applies where a significant decision about a data subject is based entirely or partly on personal data and based solely on automated processing. Article 22A(1) supplies both definitions: solely automated means no meaningful human involvement in taking the decision, and significant means a legal effect or a similarly significant effect. Article 22C(2) requires safeguards consisting of or including information about the decision, an opportunity to make representations, human intervention on the part of the controller and the ability to contest the decision. A nominal human check is not enough if the reviewer cannot genuinely influence the result.

Can we use AI on special category data?

Yes, but only through the narrower gateway in Article 22B. A significant decision based solely on automated processing of special category data is permitted where the decision is based entirely on processing to which the data subject has given explicit consent. The alternative route, in Article 22B(3), requires the decision to be necessary for entering into or performing a contract between the data subject and a controller, or to be required or authorised by law, and point (g) of Article 9(2) must apply. The safeguards in Article 22C also apply, and Article 22B(4) bars the decision altogether if the processing is carried out entirely or partly in reliance on Article 6(1)(ea).

Are there different rules for generative AI?

The UK GDPR applies in the same way to generative AI as to any other processing of personal data. The ICO’s AI and biometrics strategy makes generative AI foundation models one of its four priorities, and commits the ICO to working with developers to ensure they use people’s information responsibly and lawfully in training those models. Using a public large language model with personal data in the prompt is a disclosure to the model provider and must be treated as a processor relationship (or, in some architectures, as an independent controller relationship) with appropriate contractual and transfer protections.

Is there a statutory ICO code of practice on AI?

Not yet. Section 124A of the DPA 2018, inserted by section 92(2) of the DUAA 2025 and in force since 20 August 2025, requires the ICO to prepare a code of practice on the processing of personal data if the Secretary of State makes regulations requiring one; the regulations must describe the data or processing the code is to cover. The ICO’s own position, in its AI and biometrics strategy and in its automated decision-making guidance, is that the statutory code on AI and automated decision-making is still to be developed. What it has consulted on is redrafted guidance on automated decision-making, not the code. Until a code is made, the compliance references are the UK GDPR as amended by the DUAA, the DPA 2018 and the ICO’s guidance on automated decision-making, including profiling.

How is UK regulation diverging from the EU AI Act?

Materially. The EU AI Act is a dedicated, horizontal regulation. Its Chapter II prohibitions have applied since 2 February 2025, apart from those added in 2026, which apply from 2 December 2026; the general application date was 2 August 2026; and the Chapter III obligations for high-risk AI systems now apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems, following Regulation (EU) 2026/1744. The UK has no equivalent statute. UK AI regulation is delivered through sector regulators (ICO, Ofcom, FCA, CMA) plus the DUAA 2025 reforms to automated decision-making. The EU GDPR still includes the Article 22 prohibition; the UK GDPR now has the Article 22C safeguards regime. Organisations operating in both jurisdictions face divergent compliance obligations. We track the gaps on our UK/EU data protection divergence page and in our guide to UK AI regulation.

Data protection advice for AI-enabled products

AI regulation and compliance

Data protection for AI

Representative experience

Recent and representative matters include:

  • Advised a telecoms operator on the data protection framework for an AI-driven customer churn prediction model, including the Article 22 implications of automated retention offers and pricing decisions.
  • Prepared a DPIA for a financial services firm deploying machine learning for fraud detection, assessing the lawful basis for profiling under Article 6(1)(f) and the safeguards required under Article 22C (UK GDPR as amended by the Data (Use and Access) Act 2025, section 80).
  • Advised on the transparency obligations under Articles 13 and 14 for an AI recruitment screening tool, including the requirement to provide meaningful information about the logic involved in automated shortlisting.
  • Reviewed the data protection compliance of a large language model deployment by a professional services firm, addressing training data provenance, purpose limitation, and the application of the research processing exemption.
  • Advised a health-tech company on the interaction between the UK GDPR automated decision-making provisions and the Equality Act 2010 in the context of algorithmic triage of patient referrals.

Related data protection pages

See also our other data protection pages:

UK GDPR Compliance
Lawful Basis and Legitimate Interests
Data Protection Impact Assessments
Data Governance, Transfers and Accountability
UK/EU Data Protection Divergence
The EU AI Act: what UK businesses need to know
Sector-Specific Data Protection
Data Breach Response and ICO Notification
PECR and ePrivacy

Independent directory rankings

Our specialist expertise is recognised in major independent legal directories:

  • Chambers & Partners: Rob Bratby is ranked as a Band 2 lawyer in the UK Guide 2026 in the “Telecommunications” category: Chambers
  • The Legal 500: Rob Bratby is listed as a Leading Partner for Telecoms in London (TMT: IT and Telecoms). The Legal 500
  • Lexology: Rob Bratby is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection: Lexology
Chambers and Partners accreditation
Legal 500 accreditation
Lexology Global Elite Thought Leader accreditation

The TelXL case study sets out an example of this work on AI analytics and automated decision-making.

Discuss your matter