Articles in this section
-
Automated decision-making after the DUAA: what changed on 5 February 2026
Section 80 of the Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A–22D, in force 5 February 2026. What 'meaningful human involvement' now means for AI agents, and why the ICO's 2023 AI guidance no longer states the law. -
AI governance
Analysis for organisations automating financial processes and deploying AI agents. Every regulatory claim is sourced and dated. -
The Cyber Security and Resilience Bill: what it will require, and what applies today
The Cyber Security and Resilience Bill is at Lords committee stage — not law. Even at Royal Assent most duties do not commence: data centres, managed service providers and critical suppliers arrive via secondary legislation. How the UK compares with Germany, Denmark, Belgium and Norway. -
Cyber security
Analysis for organisations automating financial processes and deploying AI agents. Every regulatory claim is sourced and dated. -
E-invoicing
Analysis for organisations automating financial processes and deploying AI agents. Every regulatory claim is sourced and dated. -
UK e-invoicing from 2029: what has actually been decided
The UK mandate for all VAT invoices from 2029 was announced at Budget 2025, with a decentralised model and Peppol confirmed as the core interoperability network in June 2026. The month is not confirmed, no legislation exists yet, and UK B2G rules oblige authorities to receive — not suppliers to send. -
AI governance in UK financial services: what the regulators actually require
There is no AI-specific FCA or PRA rulebook and none is planned. The Bank of England confirmed it on 1 April 2026. The live obligations are SM&CR, PRA SS1/23, operational resilience and the critical third parties regime — with FCA PS26/2 in force 18 March 2027. -
Financial services
Analysis for organisations automating financial processes and deploying AI agents. Every regulatory claim is sourced and dated.
In practice
Permission before the action. Evidence after it.
The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.
In forceDUAA automated-decision rules in force since 5 February 2026
BarzelVault
The AI action firewall: decide what an agent may do before it does it.
- Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
- Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
- Credential isolation, spend and action limits, and an emergency kill switch.
Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize
Barzel Central Gateway
The AI governance control plane: one inventory and one policy layer across every MCP server and agent.
- Registers and synchronises every tool; enforces identity, policy, region, cost and health per tool.
- Identity mapping through OIDC, Entra ID, Okta, SAML and SPIFFE, with credential brokerage.
- Trace and SIEM export (W3C trace context, OTLP) for the security team and the regulator.
Free tier: 1,000 calls a monthPaid plans from $10 a monthLive on MCPize
Enterprise: written quote by email within two business days. No sales call.
Markets in English
In local languages
- Polska
- Deutschland
- France
- Schweiz / Suisse
- United States
- Danmark
- Belgique / België
- Norge
- Slovensko
- Eesti
- Kenya