← BlogAI Consultancy

The UK Just Rewrote the Rules for AI Agents That Make Decisions About People

By Aditya JhaAugust 19, 20269 min read

The UK Just Rewrote the Rules for AI Agents That Make Decisions About People

A UK lettings platform runs every rental application through an AI agent that scores and ranks applicants, and quietly auto-rejects anyone below a threshold before a human ever opens the file. It's fast, it's consistent, and until earlier this year it sat in a genuine legal grey zone: making a significant decision about a person by solely automated means was prohibited by default under the old UK GDPR unless a narrow exception applied. As of 5 February 2026 that default flipped. It's no longer a flat prohibition, it's a permission with specific conditions attached, and a lot of teams running exactly this kind of agent haven't yet checked whether they meet them.

What actually changed under the Data (Use and Access) Act 2025?

Section 80 of the Data (Use and Access) Act 2025 came into force on 5 February 2026 and deleted Article 22 of the UK GDPR outright, replacing it with four new articles, 22A through 22D. Under the old rule, a business could not make a decision based solely on automated processing that produced a legal or similarly significant effect on someone, unless it fell into one of three narrow exceptions (contract necessity, authorization by law, or explicit consent). The new structure inverts that: solely automated significant decisions are now generally permitted, but only where specific safeguards are actually in place.

What counts as a "significant decision" an AI agent might be making?

  • A decision is "solely automated" if there is no meaningful human involvement in reaching it, and the law specifically requires considering how much the outcome was actually driven by profiling versus genuine human judgment.
  • A decision is "significant" if it produces a legal effect for the person or has a similarly significant effect on them, credit and loan approvals, insurance pricing, job application screening, tenant or buyer shortlisting, and account-blocking fraud flags all fall squarely in this category.
  • An AI agent that scores, ranks, or filters people, not just processes documents, is the exact category this reform is built around; a chatbot answering product questions generally isn't.

The safeguards Article 22C actually requires

RequirementWhat it means in practice
Information about the decisionThe person must be told a significant decision was made about them by automated means, with a way to find out more about how
Meaningful human intervention on requestA human who can genuinely change the outcome reviews the decision, a rubber stamp on the model's output does not satisfy this
Right to contestA defined, working path for the person to challenge the decision and receive a different outcome if they're right
The "meaningful human involvement" barAssessed by how much profiling actually drove the outcome, a human clicking approve without seeing the model's reasoning is unlikely to count as meaningful

Requirements under the new Article 22C UK GDPR, introduced by Section 80 of the Data (Use and Access) Act 2025, in force since 5 February 2026.

The second track: the ICO's statutory Code of Practice

Separately, regulations that came into force on 12 May 2026 require the ICO to produce a statutory code of practice specifically on AI and automated decision-making, with a public consultation that ran through late May 2026 and final guidance expected later in the year. That code will add detail and examples, but it doesn't delay anything, the substantive Article 22C safeguards are already in force. Waiting for the final code before building human-intervention and contestability paths into an AI agent means running that agent out of compliance in the meantime.

How AIBOOTSTRAPPER helps

AIBOOTSTRAPPER built ComplySpark, a compliance document copilot, with human-in-the-loop review and version control baked into the architecture itself, not bolted on afterward, exactly the pattern Article 22C's "meaningful human involvement" and contestability requirements ask for in any AI system making decisions about people. That design discipline is a direct part of why the platform ships with zero off-policy language slip-ups and a single traceable source of truth. Full results are on the case studies page.

If your AI agent scores, ranks, or filters people and you haven't checked it against the new Article 22C safeguards yet, book a call and we'll walk through where it stands.

Want this done for you?

Book a free strategy call and we'll show you how to build and market your business with AI.

FAQ

Questions, answered

Everything you might want to know before we hop on a call.

Yes, and more broadly than before. Since 5 February 2026, Section 80 of the Data (Use and Access) Act 2025 replaced the old default prohibition (solely automated significant decisions banned unless a narrow exception applied) with a general permission, provided specific safeguards under the new Article 22C, information, human intervention on request, and a right to contest, are actually in place.

A decision that produces a legal effect for someone or has a similarly significant effect on them, credit approvals, insurance pricing, job screening, and applicant or tenant shortlisting are typical examples. An AI agent that scores, ranks, or filters people is the category this reform targets directly.

The law requires assessing how much a decision was actually driven by profiling versus genuine human judgment. A person reviewing and having real capacity to change the AI's output counts; a human clicking approve without seeing or understanding the model's reasoning is unlikely to meet the bar, which would make the decision solely automated after all.

The substantive change, Section 80 of the Data (Use and Access) Act 2025 replacing Article 22 UK GDPR, came into force on 5 February 2026. A separate set of regulations requiring the ICO to produce a statutory AI and automated decision-making code of practice came into force on 12 May 2026, with final guidance expected later in the year.

Keep reading

Let's talk

Ready to build and sell with AI?

Book a free 30 minute strategy call. We'll map the highest ROI AI move for your business, no pitch, just value.