The UK's new automated decision-making regime, explained
26 August 2026
If your organisation uses software to screen, score, rank or price people — candidates, applicants, customers, tenants — the legal position on that automation changed in 2026. This is a plain-English summary of what changed, sourced from the primary legislation and the regulator's own published material. It is not legal advice, and it does not cover what any specific sector or organisation should do.
What actually changed
Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D, from 5 February 2026. The old regime worked as a general prohibition: significant automated decisions about a person were banned unless a specific exception applied. The new regime flips that default. Significant solely automated decisions are now permitted for ordinary personal data, provided the organisation making them can document three things: transparency about the decision, a genuinely meaningful human review available to the person affected, and a route for that person to contest the outcome.
"Meaningful human review" is doing a lot of work in that sentence. A reviewer who glances at an automated output without any real ability to change it does not satisfy the requirement — the review has to be capable of altering the outcome, not just rubber-stamping it.
Special category data — health, biometric, and similarly sensitive information — is treated more strictly. Automated decisions built on that kind of data stay restricted to three narrow legal bases: explicit consent, contractual necessity, or statutory authorisation.
A live duty, with the rulebook still being written
A second piece of legislation, the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, came into force on 12 May 2026. It does not regulate AI directly — instead, it instructs the Information Commissioner's Office to write the UK's first statutory code of practice on AI and automated decision-making. The ICO ran a public consultation on draft ADM and profiling guidance, which closed on 29 May 2026, but the finished statutory code is not expected before 2027.
That gap matters more than it might first appear. It means the legal duty under Articles 22A–22D is already in force and already enforceable, while the detailed regulatory interpretation of exactly how to satisfy it is still being finalised. Organisations that use automated decision-making cannot wait for a finished rulebook before addressing their exposure, because the exposure already exists.
What is actually at stake
The maximum penalty for the most serious UK GDPR breaches is £17.5 million, or 4% of global annual turnover, whichever is higher. Separately, the ICO has already been active in this area: its published Recruitment Rewired report, based on engagement with recruitment-sector employers, found that organisations frequently believed automated decision-making in their hiring process was "unlikely" — while the ICO concluded some of them were doing it in practice regardless. That gap between self-perception and reality is, by the regulator's own account, common.
Where this leaves an ordinary business
Three practical questions are worth asking now, independent of any sector: does any tool your organisation uses make a solely automated decision with a significant effect on a person? If so, is there a human reviewer with genuine, documented authority to change that decision before it takes effect? And can you point to the lawful basis you are relying on for that processing, in writing, today?
If the honest answer to any of those is "we haven't checked," that is itself useful information — it is exactly the position the ICO's own findings describe as common. Getting a clear, documented answer does not require waiting for the 2027 statutory code.
This is general awareness content, not legal advice, and does not cover the specific circumstances of any organisation or sector.