The United Kingdom has no AI Act. If your company uses AI on people in the UK, the binding rules are the UK GDPR and the Data Protection Act 2018, both amended by the Data (Use and Access) Act 2025. Two changes took effect in 2026, and between them they put most older UK guidance out of date. Since 5 February 2026, a significant decision about a person can be taken with no human involved, provided four safeguards are in place. Since 30 September 2026, the regulator is a different legal body: the office of Information Commissioner has been abolished and its functions moved to the Information Commission.
Neither change reduces what you have to prove. The first one adds to it.
Last verified: 10 October 2026, against the text of the Data (Use and Access) Act 2025 and commencement regulations SI 2026/82 and SI 2026/1015 on legislation.gov.uk, the ICO's guidance and consultation pages, Parliament's bill records, the King's Speech 2026 briefing notes, and the Bank of England and FCA websites.
Is there a UK AI law?
No. The government's background briefing notes to the King's Speech of 13 May 2026 list the bills planned for the session, and none of them is an AI bill. The one bill that carried the name, Lord Holmes's private member's Artificial Intelligence (Regulation) Bill, received a first reading in the Lords on 4 March 2025 and went no further. Parliament's record lists it only under the session that has since ended.
So the regime is data protection law, plus sector rules, plus voluntary codes. It still reaches most enterprise AI use, because most of it touches personal data.
| Instrument | Status as of October 2026 | Who it binds | What you need to evidence |
|---|---|---|---|
| UK GDPR Articles 22A to 22D (inserted by section 80 of the 2025 Act) | In force since 5 February 2026 | Any controller taking significant decisions about people by solely automated means | Which decisions are in scope; that people were told; that they could make representations, get a human to step in, and contest the result; for special category data, the Article 22B condition relied on |
| Sections 118 and 119 of the 2025 Act (SI 2026/1015) | In force since 30 September 2026 | Everyone the regulator supervises | Nothing new; pending matters carry over |
| ICO guidance on AI and data protection | Last updated 15 March 2023; marked as under review | Guidance, not law | Its account of Article 22 is out of date |
| ICO guidance on automated decision-making and profiling | Draft; consultation closed 29 May 2026; final version listed for winter 2026 | Guidance, not law | Will shape how the safeguards are judged |
| Code of Practice for the Cyber Security of AI; ETSI EN 304 223 | Voluntary | No one, unless a contract or customer requires it | Only what you choose to adopt |
| Cyber Security and Resilience (Network and Information Systems) Bill | A bill; Lords report stage scheduled for 26 October 2026 | No one yet | Nothing yet |
| PRA SS1/23, model risk management principles for banks | Effective 17 May 2024; current version published 23 April 2026 | Banks, building societies and PRA-designated investment firms with internal model approval | Model inventory, validation and governance, including AI and machine learning models |
What changed for automated decisions on 5 February 2026?
The old Article 22 of the UK GDPR matched the EU text. It gave people a right not to be subject to a solely automated decision with legal or similarly significant effects, and allowed such decisions only in three cases: contract, legal authorization, or explicit consent. Section 80 of the 2025 Act removed that article and put four new ones in its place. SI 2026/82, the sixth commencement regulations, brought section 80 into force on 5 February 2026.
The new structure runs the other way. There is no general ban. Instead, Article 22C says that where a significant decision is "based solely on automated processing" and rests entirely or partly on personal data, the controller "must ensure that safeguards for the data subject's rights, freedoms and legitimate interests are in place".
Two definitions in Article 22A do most of the work. A decision is solely automated "if there is no meaningful human involvement in the taking of the decision". A decision is significant if "it produces a legal effect for the data subject" or "has a similarly significant effect". When judging whether involvement is meaningful, you must consider "the extent to which the decision is reached by means of profiling". The Act defines "meaningful" no further.
What are the four safeguards?
Article 22C(2) lists them. The safeguards must consist of or include measures which:
- "provide the data subject with information about decisions" of this kind taken about them;
- "enable the data subject to make representations about such decisions";
- "enable the data subject to obtain human intervention on the part of the controller";
- "enable the data subject to contest such decisions".
Read the verbs. Each one describes something a person must be able to do, so a policy statement is not enough. You need a working route, and a record that the route was used.
Where do the tighter rules apply?
Article 22B keeps two restrictions. First, a significant decision based entirely or partly on special category data, such as health data or ethnic origin, "may not be taken based solely on automated processing" unless one of two conditions is met. Either the person has given explicit consent, or the decision is necessary for a contract with them or "required or authorised by law" and Article 9(2)(g), the substantial public interest ground, also applies.
The second restriction is easy to miss. Article 22B(4) bars solely automated significant decisions where the processing relies on Article 6(1)(ea), the new lawful basis of recognized legitimate interests that the same commencement regulations switched on. So "any lawful basis" is close to right, but one basis is excluded by name.
Can ministers change the rules later?
Yes, within limits. Article 22D lets the Secretary of State make regulations saying that particular cases do or do not count as having meaningful human involvement, that particular kinds of decision do or do not have a similarly significant effect, and what the safeguards must include. Those regulations need approval by both Houses, and they cannot amend Article 22C itself. We found none made as of 10 October 2026.
What happened to the ICO on 30 September 2026?
SI 2026/1015, the ninth commencement regulations, brought three provisions into force that day. Section 118 abolishes the office of Information Commissioner. Section 119 transfers its functions to the Information Commission, a corporate body with a board. Regulation 3 handles continuity: anything done, or in the process of being done, by or in relation to the Commissioner is treated as done by or in relation to the Commission. Open investigations and proceedings carry on.
The name on the door has barely moved. The regulator's own announcement says it "formally transitioned to the Information Commission" and still calls itself the ICO.
For most companies this is a housekeeping point. Contracts, privacy notices and DPIA templates that name "the Information Commissioner" will read as dated, so correct them at the next review. Nothing in the regulations asks you to reissue them.
Which ICO guidance can you still rely on?
Less than you would like, for now. The ICO's guidance on AI and data protection was last updated on 15 March 2023 and carries a banner: "Due to changes made by the Data (Use and Access) Act, this guidance is under review and may be subject to change." Its description of automated decisions predates Articles 22A to 22D.
Replacement guidance is in the pipeline. The consultation on draft guidance about automated decision-making and profiling ran from 31 March to 29 May 2026, and the ICO's guidance plans list the final version for winter 2026. The same page lists agentic AI guidance as being drafted, with a final version due in autumn 2026, and a call for evidence on agentic AI opened on 8 October 2026. A statutory code of practice on AI and automated decision-making is also in development, with no date given.
Agents are where this gets practical. The ICO's Tech Futures report on agentic AI, published in 2026, names "rapid automation of increasingly complex tasks resulting in a larger amount of automated decision-making" as a new risk. The report adds that "you should not read it as ICO guidance". The direction is clear all the same: an agent that approves, refuses, ranks or routes people can cross into Article 22C without anyone having decided that it should.
What about security and financial services rules?
On security, the reference point is voluntary. The government published its Code of Practice for the Cyber Security of AI on 31 January 2025, and the text became ETSI TS 104 223 and then the European Standard ETSI EN 304 223 V2.1.1, adopted on 8 December 2025. The National Cyber Security Centre's blog post of the same date, "Prompt injection is not SQL injection (it may be worse)" explains why AI systems need damage limits and not only input filters. Our prompt injection guide maps both to controls. The Cyber Security and Resilience (Network and Information Systems) Bill is still a bill: Parliament's record shows Lords report stage scheduled for 26 October 2026.
Banks have one more document. The PRA's SS1/23 took effect on 17 May 2024, and the Bank of England's page shows the current version as published and effective on 23 April 2026. It is addressed to banks, building societies and PRA-designated investment firms that have internal model approval, and its principles cover AI and machine learning models. The FCA's position is short: "We do not plan to introduce extra regulations for AI," says its AI approach page, last updated on 2 October 2026. Our financial services AI security playbook sets the wider map.
What should a company with UK operations do now?
The sequence starts with an inventory, because every later step depends on it.
- List the AI tools and agents in use. Include the ones staff adopted without asking. In a Cloud Security Alliance and Token Security survey published in April 2026, 82% of organizations discovered previously unknown AI agents in the past year.
- Mark the ones that make or shape significant decisions about people. Hiring, credit, pricing, insurance, access to a service, disciplinary action. For each, write down whether a human is involved and what that human can change.
- Record what personal data reaches each one, and flag special category data, since Article 22B turns on it.
- Check the lawful basis. If a solely automated significant decision relies on Article 6(1)(ea), it is barred.
- Build and test the four routes: the notice, the way to make representations, the human who can intervene, and the way to contest. Then keep proof that each was offered and what happened.
- Review your complaints process. For complaints received on or after 19 June 2026, the new section 164A of the 2018 Act requires a controller to acknowledge a data subject's complaint within 30 days.
- Refresh DPIAs that describe the old Article 22, and update references to the regulator when you do.
If you are unsure where your gaps are, our AI governance maturity assessment is a free self-assessment that takes about 12 minutes. It is useful here because it scores your inventory, data controls and evidence across 30 questions and returns a ranked list of gaps, so you know what to fix first.
What can software do here, and what can it not?
Deciding whether a human's involvement is meaningful is a legal and design judgment. So is writing the notice, and so is staffing the review. No product does those for you.
What software can carry is the inventory and the record. AccuroAI discovers 1,400+ AI tools, which covers the first step, including tools nobody approved. It applies 40+ data classifiers to prompts and responses and redacts or blocks sensitive data in line, so special category data can be stopped before it reaches a tool that should not have it. Each event is logged against a user and a tool, and the evidence is mapped to 8 frameworks. That log shows what data went where and what control applied. It does not show that a person received a notice or that a reviewer changed an outcome; those records live in your case and HR systems.
Frequently asked questions
Does the EU AI Act apply in the UK?
Not as UK law. A UK company can still fall under it when it places AI systems on the EU market or its outputs are used there. The AI compliance hub covers the EU position.
Is the UK rule now the same as the EU's Article 22?
No. The EU GDPR keeps the right not to be subject to solely automated significant decisions, with three exceptions, as our GDPR and enterprise AI guide sets out. A company operating in both needs the stricter EU test for EU data subjects and the UK safeguards for UK ones. Australia is taking a third route, based on disclosure, described in our note on the Australian automated decision rule.
Does a human clicking "approve" take a decision out of Article 22C?
Only if the involvement is meaningful, and the Act leaves that word open apart from the profiling factor. The final ICO guidance and any Article 22D regulations will fill it in. Until then, record what the reviewer saw and what they were able to change.
This is not legal advice. Quotations are from the legislation and regulator pages linked below; ask UK counsel how they apply to your decisions.
Sources
- Data (Use and Access) Act 2025 (2025 c. 18); section 80 inserts Articles 22A to 22D
- SI 2026/82 (Commencement No. 6), made 29 January 2026
- SI 2026/1015 (Commencement No. 9), made 10 September 2026
- ICO: Guidance on AI and data protection; ADM consultation; guidance plans; Tech Futures: Agentic AI; transition news release, 30 September 2026
- King's Speech 2026: background briefing notes, 13 May 2026
- UK Parliament: Artificial Intelligence (Regulation) Bill [HL]; Cyber Security and Resilience (Network and Information Systems) Bill
- Code of Practice for the Cyber Security of AI; ETSI EN 304 223 V2.1.1 (PDF); NCSC, Prompt injection is not SQL injection (it may be worse)
- PRA SS1/23; FCA: AI and the FCA, our approach