arrow_back Back to Insights GOVERNANCE

AI Automated Decisions After the Data (Use and Access) Act: What UK SMEs Must Do Before Automating

September 2026 9 min read

Most AI automation projects in UK SMEs start with admin: sorting email, drafting replies, pulling data out of documents. Sooner or later, though, the automation starts making decisions about people. It sifts CVs, sets payment terms for a new account, flags a customer for fraud or decides who qualifies for a quote. At that point you are no longer just automating a process. You are doing automated decision-making, and the UK rules on it changed this year.

On 5 February 2026 the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with a new set of provisions, Articles 22A to 22D. The headline sounds like deregulation: solely automated decisions with significant effects are no longer prohibited by default. The detail is more demanding. The change swaps a ban for a set of safeguards you have to build in and prove you run. The ICO has also made clear, in draft guidance and a recruitment report, that it expects to see those safeguards working in practice.

This guide explains what changed, how to tell whether your AI tool is making the kind of decision the rules cover, and what to build in before you switch it on. It is practical guidance rather than legal advice. If a decision carries real legal risk, get your data protection adviser involved early.

What changed on 5 February 2026

Under the old Article 22, people had a right not to be subject to a decision based solely on automated processing that produced legal or similarly significant effects. The only exceptions were contract necessity, legal authorisation or explicit consent. In practice many SMEs read that as “keep a human in the loop or don’t do it”.

The new regime flips the default:

The same commencement brought other changes worth knowing about. Maximum fines under PECR, the UK’s electronic marketing and cookie rules, rose to £17.5 million or 4% of global turnover. And from 19 June 2026, organisations must run a data protection complaints process: acknowledge complaints within 30 days and deal with them without undue delay. A challenge to an automated decision is exactly the kind of complaint that will arrive through that channel.

The two tests that decide whether the rules apply

Whether your automation falls inside the regime comes down to two questions.

1. Is the decision solely automated?

A decision is solely automated when there is no meaningful human involvement. The ICO’s draft guidance, consulted on between 31 March and 29 May 2026, sets a high bar for what counts as meaningful:

Two points trip people up. First, the humans who designed the system do not count: design happens before any real-world decision is made. Second, rubber-stamping does not count either. If a manager clicks “approve” on 200 AI rejections in ten minutes, the ICO is likely to treat those decisions as solely automated.

2. Is it a significant decision?

The rules cover decisions with a legal or similarly significant effect on a person. The obvious examples are recruitment, credit, access to services and employment decisions. The ICO’s draft takes a broad view and adds newer examples such as algorithmic recommendations and dynamic pricing where they meaningfully affect someone’s choices. Systems that merely apply fixed rules a human set, such as accepting or declining a card by type, fall outside the scope.

Where UK SMEs actually hit this

Most AI automation in a small business never gets near these rules. An AI that triages your inbox and routes messages to the right team is not deciding anything significant about the sender. The places to look are narrower:

The tool does not matter. The rules apply whether the decision is made by a Copilot Studio agent, a Power Automate flow with an AI step or a bespoke tool on the Claude API. What matters is what the automation does to a person and whether a human genuinely takes part. If you are choosing an engine for one of these processes, our automation engine comparison covers the cost side; this guide covers the compliance side.

The four safeguards you must build in

If your automation does make solely automated significant decisions, Article 22C requires four safeguards. They need to be part of the workflow, not a paragraph buried in your privacy notice:

  1. Information. Tell people that a decision about them is automated, in plain language, when you collect their data, when they ask, and when the decision is made. The ICO warns against explanations so technical they confuse the reader.
  2. Representations. Give people a real way to put their side: a named inbox or form, not a no-reply address.
  3. Human intervention. Let them get a genuine human review from someone with the authority and discretion to change the outcome.
  4. Contest. Let them challenge the decision, with a process that can actually overturn it.

Behind all four sits record-keeping. The ICO expects clear records of how and when human involvement took place for each decision. For an AI tool, that means logging the input, the model’s output, who reviewed it, what they decided and when. It is much easier to design that in than to bolt it on after the first complaint.

Worked illustration: one recruitment workflow, two designs

Take an illustrative (not client-specific) recruitment agency receiving around 400 applications for a role and using an AI model to score CVs against the job criteria.

Design A — AI recommends, a recruiter decides. The AI produces a ranked shortlist with a short rationale for each candidate. A trained recruiter reads every rationale, can see each full CV and makes the progress-or-reject decision before any email goes out. This is not solely automated, but only if the review is genuine and logged. If the recruiter approves the AI’s list wholesale in minutes, the ICO would probably see it differently.

Design B — AI auto-rejects below a threshold. Candidates scoring under a set mark get an automatic rejection. This is a solely automated significant decision. It is now lawful on legitimate interests, but only with all four Article 22C safeguards in place: telling candidates automation is used, a route to make representations, human review on request and a way to contest. A data protection impact assessment is the sensible starting point.

The special category trap. CVs and cover letters routinely reveal health conditions, disabilities or religion. If the model’s score draws on that information, Design B moves into the special category regime, which in a recruitment context is very hard to satisfy. That is a strong argument for Design A, or for stripping such information before scoring.

Neither design is wrong. Design A costs recruiter time on every application; Design B costs a documented safeguard process and more legal care. The mistake is building Design B while believing you built Design A.

A practical checklist before you automate decisions

  1. Inventory the decisions. List every AI or automated process that produces an outcome about a person. Our AI readiness checklist is a good place to start the inventory.
  2. Apply the two tests. For each one, is it significant, and is there meaningful human involvement on every decision?
  3. Check the inputs for special category data, including data the model could infer, not just fields you collect deliberately.
  4. Run a DPIA for anything significant, and record your lawful basis. Remember that recognised legitimate interests is off the table.
  5. Build the four safeguards into the workflow and route challenges into your complaints process.
  6. Log human involvement for each decision if you are relying on it.
  7. Update your privacy notice and your AI usage policy so staff know which tools may make decisions about people and which may only recommend.

What’s coming next

The ICO’s consultation on its automated decision-making guidance closed on 29 May 2026. Its guidance plans list the final version for winter 2026, and separate guidance on agentic AI is being drafted for consultation, with the final version targeted for spring 2027. Expect the final text to keep the emphasis on genuine human involvement and visible safeguards; that is where the draft and the recruitment report both point. UK SMEs that sell into the EU should also watch the EU AI Act. Its high-risk obligations, which cover recruitment tools, have been deferred under the EU’s Digital Omnibus agreement but not cancelled.

The practical message is simple. The law now lets you automate decisions that used to need a human, but only if you can show the safeguards working. Decide which design you are building, document it, and build the safeguards into the tool from the start.

FAQ

Yes, with conditions. Since 5 February 2026 the Data (Use and Access) Act 2025 has replaced the old Article 22 prohibition with Articles 22A to 22D. Solely automated decisions with legal or similarly significant effects can now rest on any lawful basis, including legitimate interests, provided the organisation implements the Article 22C safeguards: telling people about the decision, letting them make representations, letting them obtain human intervention and letting them contest the decision. Decisions based on special category data remain restricted to explicit consent or contract or legal necessity with a substantial public interest condition, and the new recognised legitimate interests basis cannot be used for automated decision-making.
According to the ICO’s draft guidance, human involvement is meaningful only if a person reviews the decision before it is applied, has the authority and ability to change the outcome, is trained on how the system works and its limitations, and considers the relevant information rather than simply accepting the AI’s output. It must happen for every decision; ad hoc spot checks are not enough, and the people who designed the system do not count. Rubber-stamping large batches of AI recommendations is likely to be treated as solely automated decision-making.
It depends on the design. If an AI tool ranks or scores CVs and a trained recruiter genuinely reviews each candidate and makes the decision before it is applied, the decision is not solely automated, although the review should be logged. If the tool automatically rejects candidates below a threshold, that is a solely automated significant decision and the Article 22C safeguards apply. If the scoring draws on special category data such as health or disability information revealed in a CV, much stricter rules apply. The ICO’s March 2026 report on AI in recruitment found employers often underestimate when their tools are making decisions.
The ICO consulted on draft guidance on automated decision-making and profiling from 31 March to 29 May 2026. Its published guidance plans list the final version for winter 2026. The ICO is also drafting separate guidance on agentic AI, with a public consultation planned and the final version targeted for spring 2027. Until the final text lands, the draft guidance is the best indication of what the regulator expects.

Automating decisions about customers or staff?

We help UK SMEs design AI automation that stays on the right side of the new automated decision-making rules — the two tests, the four safeguards and the audit trail built in from day one, alongside a practical AI usage policy. Get in touch or book a 30-minute call — no sales theatre.

Book a Free Discovery Call