Most AI automation projects in UK SMEs start with admin: sorting email, drafting replies, pulling data out of documents. Sooner or later, though, the automation starts making decisions about people. It sifts CVs, sets payment terms for a new account, flags a customer for fraud or decides who qualifies for a quote. At that point you are no longer just automating a process. You are doing automated decision-making, and the UK rules on it changed this year.
On 5 February 2026 the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with a new set of provisions, Articles 22A to 22D. The headline sounds like deregulation: solely automated decisions with significant effects are no longer prohibited by default. The detail is more demanding. The change swaps a ban for a set of safeguards you have to build in and prove you run. The ICO has also made clear, in draft guidance and a recruitment report, that it expects to see those safeguards working in practice.
This guide explains what changed, how to tell whether your AI tool is making the kind of decision the rules cover, and what to build in before you switch it on. It is practical guidance rather than legal advice. If a decision carries real legal risk, get your data protection adviser involved early.
Under the old Article 22, people had a right not to be subject to a decision based solely on automated processing that produced legal or similarly significant effects. The only exceptions were contract necessity, legal authorisation or explicit consent. In practice many SMEs read that as “keep a human in the loop or don’t do it”.
The new regime flips the default:
The same commencement brought other changes worth knowing about. Maximum fines under PECR, the UK’s electronic marketing and cookie rules, rose to £17.5 million or 4% of global turnover. And from 19 June 2026, organisations must run a data protection complaints process: acknowledge complaints within 30 days and deal with them without undue delay. A challenge to an automated decision is exactly the kind of complaint that will arrive through that channel.
Whether your automation falls inside the regime comes down to two questions.
A decision is solely automated when there is no meaningful human involvement. The ICO’s draft guidance, consulted on between 31 March and 29 May 2026, sets a high bar for what counts as meaningful:
Two points trip people up. First, the humans who designed the system do not count: design happens before any real-world decision is made. Second, rubber-stamping does not count either. If a manager clicks “approve” on 200 AI rejections in ten minutes, the ICO is likely to treat those decisions as solely automated.
The rules cover decisions with a legal or similarly significant effect on a person. The obvious examples are recruitment, credit, access to services and employment decisions. The ICO’s draft takes a broad view and adds newer examples such as algorithmic recommendations and dynamic pricing where they meaningfully affect someone’s choices. Systems that merely apply fixed rules a human set, such as accepting or declining a card by type, fall outside the scope.
Most AI automation in a small business never gets near these rules. An AI that triages your inbox and routes messages to the right team is not deciding anything significant about the sender. The places to look are narrower:
The tool does not matter. The rules apply whether the decision is made by a Copilot Studio agent, a Power Automate flow with an AI step or a bespoke tool on the Claude API. What matters is what the automation does to a person and whether a human genuinely takes part. If you are choosing an engine for one of these processes, our automation engine comparison covers the cost side; this guide covers the compliance side.
If your automation does make solely automated significant decisions, Article 22C requires four safeguards. They need to be part of the workflow, not a paragraph buried in your privacy notice:
Behind all four sits record-keeping. The ICO expects clear records of how and when human involvement took place for each decision. For an AI tool, that means logging the input, the model’s output, who reviewed it, what they decided and when. It is much easier to design that in than to bolt it on after the first complaint.
Take an illustrative (not client-specific) recruitment agency receiving around 400 applications for a role and using an AI model to score CVs against the job criteria.
Design A — AI recommends, a recruiter decides. The AI produces a ranked shortlist with a short rationale for each candidate. A trained recruiter reads every rationale, can see each full CV and makes the progress-or-reject decision before any email goes out. This is not solely automated, but only if the review is genuine and logged. If the recruiter approves the AI’s list wholesale in minutes, the ICO would probably see it differently.
Design B — AI auto-rejects below a threshold. Candidates scoring under a set mark get an automatic rejection. This is a solely automated significant decision. It is now lawful on legitimate interests, but only with all four Article 22C safeguards in place: telling candidates automation is used, a route to make representations, human review on request and a way to contest. A data protection impact assessment is the sensible starting point.
The special category trap. CVs and cover letters routinely reveal health conditions, disabilities or religion. If the model’s score draws on that information, Design B moves into the special category regime, which in a recruitment context is very hard to satisfy. That is a strong argument for Design A, or for stripping such information before scoring.
Neither design is wrong. Design A costs recruiter time on every application; Design B costs a documented safeguard process and more legal care. The mistake is building Design B while believing you built Design A.
The ICO’s consultation on its automated decision-making guidance closed on 29 May 2026. Its guidance plans list the final version for winter 2026, and separate guidance on agentic AI is being drafted for consultation, with the final version targeted for spring 2027. Expect the final text to keep the emphasis on genuine human involvement and visible safeguards; that is where the draft and the recruitment report both point. UK SMEs that sell into the EU should also watch the EU AI Act. Its high-risk obligations, which cover recruitment tools, have been deferred under the EU’s Digital Omnibus agreement but not cancelled.
The practical message is simple. The law now lets you automate decisions that used to need a human, but only if you can show the safeguards working. Decide which design you are building, document it, and build the safeguards into the tool from the start.
We help UK SMEs design AI automation that stays on the right side of the new automated decision-making rules — the two tests, the four safeguards and the audit trail built in from day one, alongside a practical AI usage policy. Get in touch or book a 30-minute call — no sales theatre.
Book a Free Discovery Call