The UK still has no AI Act, and there is a common assumption that this means AI is unregulated here. It is not. It is regulated through data protection law, and that law changed in 2026 in a way that lands directly on employers.
In short: The Data (Use and Access) Act 2025 came into force in stages from February 2026 and rewrote the UK GDPR rules on automated decision making, replacing Article 22 with a new framework. Solely automated decisions are now permitted more broadly, but with statutory safeguards: people must be given meaningful information about the logic, be able to obtain human review, and be able to contest the outcome. The threshold for meaningful human involvement now sits in statute rather than guidance. The ICO published a recruitment automated decision making report in March 2026 drawing on evidence from over 30 UK employers, and a statutory code of practice on AI and automated decision making is being produced.
What changed, in practical terms
The old position was restrictive by default: solely automated decisions with legal or similarly significant effects were largely prohibited, with narrow exceptions. The new framework is more permissive about whether you can do it, and much more specific about what you owe the person when you do.
That trade is easy to misread as a relaxation. For most employers it is the opposite, because the safeguards are now concrete obligations rather than principles, and they attach to systems many organisations did not think of as automated decision making at all.
The three rights you have to be able to honour
If a decision about a person is made solely by automated means and it significantly affects them, you need to be able to deliver all three of these on request. Not in principle. In practice, within a reasonable time, for a named individual.
- Meaningful information about the logic. Not the model weights, and not a marketing description. Something that lets a person understand what factors drove the outcome.
- Human review. A real person, with the authority and the information to reach a different conclusion. Someone clicking approve on a queue is not review, and that distinction is now the statutory threshold rather than a matter of ICO opinion.
- The right to contest. A route for the person to challenge the outcome and have that challenge considered.
"If your human reviewer cannot overturn the machine, and does not have the information to want to, you do not have human review. You have a rubber stamp with a job title."

Where this catches employers
The uncomfortable part is that most of these systems were bought as efficiency tools, not as decision makers, and nobody classified them at purchase.
- Recruitment. CV screening, ranking, keyword filtering, video assessment scoring. The ICO's March 2026 recruitment work looked at exactly this, with draft guidance and letters to named organisations, so this is the area under active scrutiny.
- Performance and workforce management. Productivity scoring, automated flagging, shift allocation driven by an algorithm.
- Credit, pricing and access decisions where a customer is affected.
- Anything an AI feature quietly added. This is the one to watch. A vendor ships a ranking or scoring feature into a product you already use, it gets switched on, and a system that was not doing automated decision making now is.
What to do about it
This is a documentation and process exercise more than a technical one, and it is considerably cheaper to do before someone asks.
- Inventory where automated decisions happen. Include the vendor features you did not commission. If you have not run a discovery pass, finding shadow AI in your business covers how.
- For each one, decide whether it is solely automated. If a human is genuinely in the loop with authority to differ, you are in a different position, but you have to be able to evidence that, not assert it.
- Fix the privacy notice. It has to say automated decision making is in use and describe the likely consequences. Vague coverage is a common and easily corrected failing.
- Name the reviewer and give them what they need. Human review only exists if someone has the time, the information and the standing to overturn an outcome.
- Keep the records. Which system, what logic, who reviewed, what happened. The request will arrive months after the decision.
Where the two regimes meet
UK organisations selling into the EU now have two frameworks pointing the same way. The EU AI Act's transparency duties have applied since August 2026, which we covered in what actually started in August, and the UK route arrives at a similar destination through data protection law. Both come down to the same principle: if a machine is shaping an outcome for a person, that has to be visible, explicable and challengeable.
Getting the inventory and the notices right serves both, which makes it good value work. If you want help mapping where automated decisions already sit in your systems, that is part of our AI advisory work, and the policy and evidence side sits with our compliance packs service.



