5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

United Kingdom

Automated decision-making after the DUAA: what changed on 5 February 2026

UK GDPR Article 22 no longer exists. Section 80 of the Data (Use and Access) Act 2025 replaced it with a new Section 4A containing Articles 22A to 22D, commenced on 5 February 2026. The headline effect is a relaxation: for decisions that do not involve special category data, the old general prohibition is gone and controllers may rely on the full range of lawful bases, including legitimate interests. The subtler and more consequential effect is that the whole regime now turns on a phrase — meaningful human involvement — which decides whether a decision is caught at all. For anyone deploying AI agents that act on people, that phrase is the compliance boundary.

How Barzel applies here Start free with BarzelVault

What actually changed on 5 February 2026?

Section 80 of the Data (Use and Access) Act 2025 (c. 18) substitutes Article 22 with four new articles. Commencement came via the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), regulation 2 — 5 February 2026. The ICO states that all DUAA data protection provisions were in force by 19 June 2026.

The change is prospective. Regulation 5 saves the position for decisions taken before 5 February 2026, which remain governed by the old Article 22(3). A system that has been running since 2024 therefore sits across two legal regimes, and any audit of historic decisions has to respect that line.

ArticleWhat it covers
22ADefines the scope — what counts as a significant decision based solely on automated processing
22BRestrictions where special category data is involved
22CThe safeguards that must accompany a qualifying decision
22DSecretary of State regulation-making powers

The relaxation, precisely

Under the old Article 22, solely automated decisions with legal or similarly significant effects were prohibited unless one of three narrow gateways applied. Under Article 22A, for decisions not involving special category data, that prohibition is replaced by a permission-plus-safeguards model: any lawful basis will do, including legitimate interests, provided the Article 22C safeguards are in place.

Where special category data is involved, the restrictions remain. Article 22B requires explicit consent, or contract necessity or legal authorisation within specified exemptions. This is the distinction that determines how much of your existing control set you can retire — and the answer for most enterprises is: less than the headlines suggest, because special category data has a way of entering models through the side door.

Two definitions that now carry the weight

"Significant decision"

A decision producing a legal effect, or a similarly significant effect, for the individual. Familiar territory from the old regime, and the case law and guidance around it largely carry over.

"Meaningful human involvement" — the pivotal concept

This is the new and genuinely important one. It determines whether a decision is solely automated, and therefore whether Articles 22A to 22C engage at all. A decision with meaningful human involvement falls outside the regime entirely.

The practical implication is uncomfortable for a lot of deployed systems. The common architecture — a model scores or classifies, a person approves a queue of outputs, the decision issues — has always been described internally as human-in-the-loop. Whether it supplies meaningful involvement depends on whether the person actually engaged with the individual case, had the authority and information to reach a different conclusion, and can be shown to have done so.

Three failure patterns recur:

  • Batch approval. A reviewer confirms two hundred outcomes in a sitting. The involvement is real in the sense that a human clicked; it is hard to argue it was meaningful for any given case.
  • Insufficient information. The reviewer sees a score and a recommendation but not the factors that produced them, and so cannot in practice disagree.
  • No recorded basis. The involvement may have been entirely genuine, but nothing records what was reviewed. When the question is asked eighteen months later, the answer is unavailable.

The third is the one that turns a defensible position into an indefensible one, and it is a records problem rather than a legal one.

The Article 22C safeguards

Where a decision does qualify, the controller must:

  1. provide information about the decision to the individual;
  2. enable them to make representations;
  3. allow human intervention;
  4. permit them to contest the decision.

Points three and four have an architectural consequence that is easy to underestimate. To intervene meaningfully in a decision after the fact, someone must be able to reconstruct what the system did: the inputs it acted on, the model or rule version in force at the time, and the output. If the model has since been updated — and in an agent deployment it will have been — re-running the case does not reconstruct the original decision. It produces a new one.

That is why version capture, not just outcome logging, is the load-bearing control here.

Where do AI agents sit under the DUAA?

An agent that interprets a situation and then acts raises the scope question more sharply than a scoring model does, for two reasons.

The decision may not have been designed as a decision. A model that outputs a credit score was built to make a decision and was governed accordingly. An agent asked to "resolve outstanding queries" that ends up closing accounts, refusing refunds or declining applications has made significant decisions that nobody scoped as such. Article 22A does not care what the workflow was called.

The human cannot be the agent. If the determination of whether a case needs human review is itself made by the model, the involvement is not independent, and the argument that it is meaningful becomes hard to sustain. The threshold has to be enforced in a layer the agent passes through and cannot reconfigure.

What has the ICO published on automated decisions?

This is worth getting right, because a lot of current UK content cites guidance that no longer states the law.

  • ICO Guidance on AI and data protection still carries a 15 March 2023 date and states that it is under review because of the DUAA. Do not cite it as current on Article 22.
  • Draft updated guidance on automated decision-making and profiling was consulted on from 31 March to 29 May 2026. It remains draft; the final version has not been published.
  • A statutory code of practice is coming. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 — SI 2026/425, made 16 April 2026, in force 12 May 2026 — require the Information Commissioner to prepare a code of practice on good practice in processing personal data in relation to developing and using AI, and in relation to automated decision-making, with specific provision for children's data. A statutory code carries more weight than guidance. No publication date has been set.

The ICO's March 2026 AI and biometrics strategy update names automated decision-making in central government, ADM in recruitment, foundation model developers and facial recognition as priorities, and the ICO published a Tech Futures report on agentic AI in January 2026. Until the statutory code lands, the defensible citation is the statute itself.

There is still no UK AI Act

Worth stating plainly, because it shapes what compliance work is actually required. The King's Speech in May 2026 contained no dedicated AI bill. The Regulating for Growth Bill announced in the accompanying briefing notes creates cross-economy regulatory sandbox powers and a strengthened growth duty on regulators — it is not an AI Act. The AI (Regulation) Bill [HL] is a private member's bill that has not reached second reading and is not government policy.

The former AI Safety Institute was renamed the AI Security Institute in February 2025. It is a research and evaluation body with no regulatory or statutory powers; describing it as a regulator is a common and visible error.

So the operative UK obligations for enterprise AI come from data protection law, sector regulators, and — for those in scope — the incoming cyber regime rather than from any AI statute.

Adjacent obligations worth tracking

  • Cyber Security and Resilience Bill — introduced 12 November 2025, currently at Lords committee stage. Not yet law. It will bring managed service providers, data centres and designated critical suppliers into scope, with 24-hour initial notification and 72-hour full reporting, but most substantive duties arrive later through secondary legislation.
  • FCA PS26/2 — operational incident and third-party reporting rules, published 18 March 2026, in force 18 March 2027. This is the live forward deadline for financial services; the operational resilience deadline of 31 March 2025 has passed and is now a baseline, not an upcoming milestone.
  • PRA SS1/23 Model Risk Management Principles for Banks — updated version effective 23 April 2026. Technology-agnostic but expressly covers AI and machine learning in modelling.
  • NCSC published Thinking carefully before adopting agentic AI in May 2026 — least privilege, ephemeral credentials, monitoring, AI-specific incident response and explicit human accountability chains. Voluntary, but a well-sourced statement of expected practice.

Implementation checklist

  1. Inventory every system that produces significant decisions about individuals — including agentic workflows nobody classified as decision-making.
  2. For each, determine whether special category data is involved. That single question decides which regime applies.
  3. Assess whether the human involvement in each flow is meaningful in substance, not just present in the workflow diagram.
  4. Ensure the reviewer sees enough to reach a different conclusion, and record what they were shown.
  5. Capture model or rule version alongside every decision, so intervention and contest can operate on the original decision rather than a fresh one.
  6. Enforce the human-review threshold in a layer the agent cannot bypass or reconfigure.
  7. Check that decisions taken before 5 February 2026 are handled under the saved Article 22(3) position.
  8. Track SI 2026/425 — the statutory code will set the benchmark once published.

Frequently asked questions

Does UK GDPR Article 22 still exist?

No. It was substituted by Articles 22A–22D under DUAA s.80, in force 5 February 2026 via SI 2026/82. The change is prospective only.

Can I rely on legitimate interests now?

For decisions not involving special category data, yes, subject to the Article 22C safeguards. Where special category data is involved, Article 22B keeps the tighter conditions.

What is "meaningful human involvement"?

The test for whether a decision is solely automated. If involvement is meaningful, the regime does not engage. Rubber-stamping a queue of outputs is unlikely to qualify, and in practice the involvement has to be demonstrable.

Is the ICO's AI guidance still current?

Not on automated decision-making. The 2023 guidance is under review and the replacement is still in draft. Cite the statute.

Is there a UK AI Act?

No, and none is before Parliament. The AI Security Institute is a research body, not a regulator.

Does this apply to AI agents specifically?

It applies to any significant decision based solely on automated processing, whatever produced it. Agents raise the question more sharply because they make decisions the workflow was never scoped to include.

Where this leads

The DUAA loosened the lawful-basis constraint and tightened, in practice, the evidential one. The question a regulator or a complainant will ask is not whether your policy says a human reviews the decision. It is whether you can show what that human saw, when, and on what version of the system.

BarzelVault enforces approval thresholds in a layer that sits in front of the agent, and records the inputs, policy version and approver for each action before it executes — which is the record Articles 22C and 22D turn on. FinOps Atlas covers the cost dimension of the same automated workflows.

In practice

Permission before the action. Evidence after it.

The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.

In forceDUAA automated-decision rules in force since 5 February 2026

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Barzel FinOps Atlas

Intelligent financial operations for AI agents and automation.

  • Cost per action, workflow and business outcome, allocated as it happens.
  • Spend limits and anomaly detection before the bill, not after.
  • Financial evidence tracing and close-readiness for SOX, SOC 2 and external audit.

Free tier: 500 calls a monthPaid plans from $29 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.


Sources

  1. Data (Use and Access) Act 2025 (c. 18), section 80 — legislation.gov.uk.
  2. The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, SI 2026/82.
  3. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, SI 2026/425.
  4. ICO, The Data Use and Access Act 2025: what does it mean for organisations; ICO consultation on draft ADM and profiling guidance, March–May 2026.
  5. ICO, AI and biometrics strategy update, March 2026.
  6. NCSC, Thinking carefully before adopting agentic AI, 15 May 2026.
  7. FCA PS26/2 (March 2026); PRA SS1/23 (updated April 2026).

This article is for information and does not constitute legal advice. Position as at 2 September 2026.