Skip to content
Is there an AI for this?

Jurisdiction

United Kingdom

Source
Editorial review of primary sources — not yet re-anchored
Verified
Evidence not verified
Confidence
Low

Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.

01Framework

The UK regulates personal data through the UK GDPR and the Data Protection Act 2018, both substantially amended by the Data (Use and Access) Act 2025. The most consequential change for AI is that Article 22 has been replaced by Articles 22A to 22D, in force since 5 February 2026, which restate the automated decision-making rules on a different footing. There is no cross-sector AI statute; regulation runs through existing regulators, and a 2026 statutory instrument requires the Information Commissioner to prepare a code of practice on AI and automated decision-making.

Region
Europe
ISO code
GB
Privacy framework
UK GDPR, as retained and amended, together with the Data Protection Act 2018. The core duties are unchanged in shape — lawful basis, transparency, purpose limitation, security, processor contracts, international transfers — but the automated decision-making regime now sits in Articles 22A to 22D rather than Article 22. Article 22A defines a decision as based solely on automated processing where there is no meaningful human involvement, and a significant decision as one producing a legal or similarly significant effect. Whether human involvement is meaningful must be considered in light of the extent to which the decision is reached by profiling.
AI-specific rules
No horizontal AI statute. Government policy remains the pro-innovation approach set out in the 2023 white paper and its 2024 response: existing regulators apply cross-sectoral principles within their own remits rather than a new AI regulator being created. A search of UK Public General Acts by title returns no result for artificial intelligence. The binding instrument closest to AI regulation is the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, in force since 12 May 2026, which obliges the Information Commissioner to prepare a statutory code. The ICO’s existing Guidance on AI and Data Protection was last updated in March 2023 and carries a notice that it is under review because of the Data (Use and Access) Act.
Last reviewed
20 Aug 2026
Status
published

Cross-border transfer

Chapter V of the UK GDPR governs transfers out of the UK. Where no adequacy regulations cover the destination, the usual routes are the ICO’s International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, supported by a transfer risk assessment. Two things trip teams up in an AI deployment: the EU and the UK have separate lists and separate instruments, so an EU-facing contract does not automatically cover the UK leg; and the transfer is often the inference call rather than the storage contract.


02Regulations and guidance

6 instruments
InstrumentStatus
UK AI White PaperThe government policy paper setting out a framework in which existing regulators apply cross-sectoral principles within their remits, rather than a new statute or AI regulator. It remains the stated approach: no UK Public General Act carries artificial intelligence in its title.In force
DPA 2018The domestic statute sitting alongside the UK GDPR. Carries the general processing regime, exemptions, law enforcement and intelligence services parts, and the Information Commissioner’s functions and enforcement powers. Provisions replacing the Commissioner with an Information Commission are on the statute book but not commenced.In force
DUAA 2025The Act that reshaped UK data protection. Part 5 covers data protection and privacy; section 80 substituted Articles 22A to 22D of the UK GDPR for Article 22. Commencement is staged and incomplete — a number of sections, including those abolishing the office of Information Commissioner, are not in force.Partly in force
ICO AI GuidanceThe ICO’s principal AI guidance, covering accountability and governance, lawfulness, fairness across the AI lifecycle, transparency, security, and individual rights, with an AI and data protection risk toolkit. The page carries a notice that the guidance is under review because of changes made by the Data (Use and Access) Act.In force
ICO AI Code Regulations 2026Statutory instrument requiring the Information Commissioner to prepare a code of practice on artificial intelligence and automated decision-making, using powers inserted into the Data Protection Act 2018 by the Data (Use and Access) Act 2025. It creates no AI regulator and imposes no direct duty on a deployer; the duties will come from the code.In force
UK GDPRThe retained EU regulation as amended for the UK. Automated decision-making now sits in Chapter III Section 4A: Article 22A defines a decision based solely on automated processing as one taken without meaningful human involvement, and a significant decision as one with a legal or similarly significant effect, with profiling expressly relevant to the assessment.In force

03Common enterprise issues

4
  • Automated decision-making

    Article 22 has been replaced

    Articles 22A to 22D have applied since 5 February 2026. Policies, DPIAs and vendor questionnaires written against Article 22 need re-checking, and the meaningful-human-involvement test is now defined in the text rather than only in guidance.

  • Transparency

    ICO AI guidance is authoritative on principles and stale on mechanics

    The guidance still explains the impact of Article 22 and was last updated in March 2023. The ICO says it is under review. Use it for the fairness and accountability reasoning, not for the current wording of the ADM rules.

  • High-risk AI

    No AI Act to comply with, and that is not the same as no obligations

    UK teams sometimes read the absence of an AI statute as an absence of duties. The duties come from data protection law, sector regulation and employment law, and a statutory ICO code on AI and automated decision-making is on its way.

  • Cross-border transfers

    The UK leg needs its own instrument

    An EU SCC package does not cover a UK transfer without the UK Addendum, and the two adequacy pictures are maintained separately.


04Vendor restrictions

0

Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.

No vendor restriction has been recorded for this jurisdiction.


05Stacks with notes for this jurisdiction

0

No published stack carries a compliance note for this jurisdiction yet.


06Evidence

0 records · 0 of 6 instruments

Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.

No sources were recorded for this answer. Nothing on this page should be treated as verified.

Improve this page

Sign in to contribute

From the field

0 deployments · 0 questions

Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.