Jurisdiction
United Kingdom
- Source
- Editorial review of primary sources — not yet re-anchored
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01Framework
The UK regulates personal data through the UK GDPR and the Data Protection Act 2018, both substantially amended by the Data (Use and Access) Act 2025. The most consequential change for AI is that Article 22 has been replaced by Articles 22A to 22D, in force since 5 February 2026, which restate the automated decision-making rules on a different footing. There is no cross-sector AI statute; regulation runs through existing regulators, and a 2026 statutory instrument requires the Information Commissioner to prepare a code of practice on AI and automated decision-making.
- Region
- Europe
- ISO code
- GB
- Privacy framework
- UK GDPR, as retained and amended, together with the Data Protection Act 2018. The core duties are unchanged in shape — lawful basis, transparency, purpose limitation, security, processor contracts, international transfers — but the automated decision-making regime now sits in Articles 22A to 22D rather than Article 22. Article 22A defines a decision as based solely on automated processing where there is no meaningful human involvement, and a significant decision as one producing a legal or similarly significant effect. Whether human involvement is meaningful must be considered in light of the extent to which the decision is reached by profiling.
- AI-specific rules
- No horizontal AI statute. Government policy remains the pro-innovation approach set out in the 2023 white paper and its 2024 response: existing regulators apply cross-sectoral principles within their own remits rather than a new AI regulator being created. A search of UK Public General Acts by title returns no result for artificial intelligence. The binding instrument closest to AI regulation is the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, in force since 12 May 2026, which obliges the Information Commissioner to prepare a statutory code. The ICO’s existing Guidance on AI and Data Protection was last updated in March 2023 and carries a notice that it is under review because of the Data (Use and Access) Act.
- Last reviewed
- 20 Aug 2026
- Status
- published
Cross-border transfer
Chapter V of the UK GDPR governs transfers out of the UK. Where no adequacy regulations cover the destination, the usual routes are the ICO’s International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, supported by a transfer risk assessment. Two things trip teams up in an AI deployment: the EU and the UK have separate lists and separate instruments, so an EU-facing contract does not automatically cover the UK leg; and the transfer is often the inference call rather than the storage contract.
Regulators
Primary sources
- LegislationUK GDPR — Regulation (EU) 2016/679 as retained, legislation.gov.uk
- LegislationUK GDPR Article 22A — Automated processing and significant decisions
- LegislationData Protection Act 2018
- LegislationData (Use and Access) Act 2025
- LegislationThe Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026
- Regulator guidanceICO — Guidance on AI and data protection
- Regulator pageA pro-innovation approach to AI regulation (white paper)
02Regulations and guidance
| Instrument | Status |
|---|---|
| UK AI White PaperThe government policy paper setting out a framework in which existing regulators apply cross-sectoral principles within their remits, rather than a new statute or AI regulator. It remains the stated approach: no UK Public General Act carries artificial intelligence in its title. | In force |
| DPA 2018The domestic statute sitting alongside the UK GDPR. Carries the general processing regime, exemptions, law enforcement and intelligence services parts, and the Information Commissioner’s functions and enforcement powers. Provisions replacing the Commissioner with an Information Commission are on the statute book but not commenced. | In force |
| DUAA 2025The Act that reshaped UK data protection. Part 5 covers data protection and privacy; section 80 substituted Articles 22A to 22D of the UK GDPR for Article 22. Commencement is staged and incomplete — a number of sections, including those abolishing the office of Information Commissioner, are not in force. | Partly in force |
| ICO AI GuidanceThe ICO’s principal AI guidance, covering accountability and governance, lawfulness, fairness across the AI lifecycle, transparency, security, and individual rights, with an AI and data protection risk toolkit. The page carries a notice that the guidance is under review because of changes made by the Data (Use and Access) Act. | In force |
| ICO AI Code Regulations 2026Statutory instrument requiring the Information Commissioner to prepare a code of practice on artificial intelligence and automated decision-making, using powers inserted into the Data Protection Act 2018 by the Data (Use and Access) Act 2025. It creates no AI regulator and imposes no direct duty on a deployer; the duties will come from the code. | In force |
| UK GDPRThe retained EU regulation as amended for the UK. Automated decision-making now sits in Chapter III Section 4A: Article 22A defines a decision based solely on automated processing as one taken without meaningful human involvement, and a significant decision as one with a legal or similarly significant effect, with profiling expressly relevant to the assessment. | In force |
03Common enterprise issues
Automated decision-making
Article 22 has been replaced
Articles 22A to 22D have applied since 5 February 2026. Policies, DPIAs and vendor questionnaires written against Article 22 need re-checking, and the meaningful-human-involvement test is now defined in the text rather than only in guidance.
Transparency
ICO AI guidance is authoritative on principles and stale on mechanics
The guidance still explains the impact of Article 22 and was last updated in March 2023. The ICO says it is under review. Use it for the fairness and accountability reasoning, not for the current wording of the ADM rules.
High-risk AI
No AI Act to comply with, and that is not the same as no obligations
UK teams sometimes read the absence of an AI statute as an absence of duties. The duties come from data protection law, sector regulation and employment law, and a statutory ICO code on AI and automated decision-making is on its way.
Cross-border transfers
The UK leg needs its own instrument
An EU SCC package does not cover a UK transfer without the UK Addendum, and the two adequacy pictures are maintained separately.
04Vendor restrictions
Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.
No vendor restriction has been recorded for this jurisdiction.
05Stacks with notes for this jurisdiction
No published stack carries a compliance note for this jurisdiction yet.
06Evidence
Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.
No sources were recorded for this answer. Nothing on this page should be treated as verified.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.