MICKAI®ArticlesDoes the UK Data (Use and Access)…
Article · 21 July 2026

Does the UK Data (Use and Access) Act change the rules for AI decisions?

Yes, the UK is moving from prohibition to permission with safeguards for most automated decisions, which makes the evidence burden sharper.

Author
Micky Irons
Published
21 July 2026
Follow Micky Irons
LinkedInX
sovereign aidata use and access actautomated decision makinguk gdprai governance

Yes, materially. The Data (Use and Access) Act 2025 reworks the UK GDPR Article 22 regime: instead of a general prohibition on solely automated decisions with legal or similarly significant effects, UK law moves to a permissive regime with safeguards for most personal data, while keeping the stricter prohibition where special category data is involved. The Act received royal assent in June 2025 and its provisions are being brought into force in stages through 2025 and 2026.

The question matters in 2026 because organisations are automating decisions that used to sit with people, from credit and claims to recruitment sifting, and many do so across the UK and EU regimes at once. The UK has just made more of that automation lawful, and lawful is not the same as defensible.

What did UK GDPR Article 22 prohibit before the Act?

The inherited regime treated solely automated decisions with legal or similarly significant effects as prohibited unless one of a short list of exceptions applied, such as explicit consent. In practice most organisations kept a human somewhere in the loop, sometimes meaningfully and sometimes as decoration, to stay outside the prohibition altogether. That prohibition-first structure shaped a decade of system design.

What does the Data (Use and Access) Act change?

It inverts the default for most personal data. Solely automated decisions with legal or similarly significant effects become permitted subject to safeguards, rather than prohibited subject to exceptions. The stricter prohibition is retained where special category data is involved, so significant decisions resting on data such as health or ethnicity remain in the restricted class. The direction is unmistakable: the UK has chosen a more permissive posture on automated decision-making than the EU.

Which safeguards must still operate?

The permissive regime is conditional, not unconditional. Where a significant automated decision is taken, the safeguards include:

  • information for the individual about the decision that has been taken,
  • the right to make representations about it,
  • human intervention on request.

These are not paperwork. Human intervention on request means the organisation must be able to reconstruct the decision, put a competent person in front of it, and change it if it was wrong.

When do the new rules actually apply?

In stages, and the staging matters. The Act as enacted sets the framework; individual provisions are brought into force by commencement regulations through 2025 and 2026. An organisation planning to rely on the permissive regime should check the commencement position of the specific provisions it needs before building on them, and should record the basis on which it proceeds. Treating the whole Act as switched on from royal assent is the simplest mistake available.

Does the change help if you also operate in the EU?

Only on the UK side. EU GDPR Article 22 is unchanged, and the general prohibition on solely automated significant decisions continues to apply to processing within its scope. A firm operating in both markets therefore runs two regimes at once, and its systems must know which decision falls under which law. A single undifferentiated decision pipeline built to the UK rules can quietly put EU processing on the wrong side of a line the UK no longer draws.

Why does permission make the evidence question sharper?

Because relying on the permissive regime is a claim the organisation must be able to prove, decision by decision. It must show what the automated decision was, what data it used, and that the safeguards operated: that the individual was informed, that representations could be made, and that human intervention happened when requested. Under the old regime the safest evidence was that automation was not used for the final decision. Under the new one the evidence is the decision record itself, and a missing record looks like a missing safeguard.

How does a sovereign deployment produce that evidence?

By making the record a property of the architecture rather than a policy. On Mickai, a Sovereign Intelligence Operating System running offline on operator-owned hardware, every automated action is sealed to an audit ledger signed under FIPS 204, the primary post-quantum digital signature standard, and bound to hardware-attested identity. The record of a decision, the data it drew on and the human intervention that followed verifies offline, without trusting our infrastructure or anyone else's. Versioned model artefacts add the part cloud services struggle to offer: the exact model version that made a decision in March is still held on the operator's own hardware, identified in the sealed record, when that decision is contested in November.

A regime that permits more automated decisions demands better evidence for each one, not less.

The decision-record architecture is described in full at /sovereign-ai, and the film at /film shows the system producing that record as it operates.

Frequently asked questions

Can I now make fully automated decisions about customers in the UK?

For most personal data, yes in principle: the reworked regime permits solely automated decisions with legal or similarly significant effects, provided the safeguards operate and special category data is not involved. The commencement position of the relevant provisions should be checked first, because the Act is being brought into force in stages through 2025 and 2026.

Do I still need human review of automated decisions under the new Act?

Human intervention on request remains a required safeguard, so a working route to a competent human reviewer must exist. What changes is the default: a human no longer needs to sit inside every decision, but the individual can summon one, which means the organisation must be able to reconstruct any decision on demand.

Does the Act change EU GDPR Article 22?

No. The EU regime is unchanged, and the general prohibition on solely automated significant decisions continues to apply to processing within EU GDPR scope. Organisations operating across both regimes need to know, decision by decision, which law governs, and apply the stricter analysis where the EU rules bite.

What records should we keep for each automated decision?

Enough to prove the regime was honoured: the decision and its effect, the data and model version that produced it, the information given to the individual, any representations received, and any human intervention with its outcome. A sealed, tamper-evident record of those elements turns a regulatory enquiry into a lookup rather than an investigation.

Can we automate decisions that use health or ethnicity data?

Decisions involving special category data remain under the stricter prohibition rather than the new permissive regime. The prudent course is to treat any significant automated decision resting on such data as restricted, route it to human decision-making, and keep the record that shows the human decision actually happened.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/does-the-uk-data-use-and-access-act-change-the-rules-for-ai-decisions. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles