How To Meet the UK Data (Use and Access) Act 2025 Rules on Automated Decisions
The Act reforms Article 22 but keeps the safeguards, so a sealed on-premise audit ledger proves each automated decision's basis without exporting personal data.

Meeting the UK Data (Use and Access) Act 2025 rules on automated decisions means keeping the safeguards the Act preserves: give the individual clear information, a route to meaningful human intervention, and a way to contest the outcome, and hold an auditable record of how each decision was reached. The DUAA reforms the old UK GDPR Article 22 into a more permissive regime under new Articles 22A to 22D, but it does not abolish the duty to protect people from unsafe solely automated decisions. We meet it by running the decision on operator-owned hardware and sealing each step to a post-quantum signed audit ledger, so the basis of every decision is provable without exporting any personal data.
This matters because much of the market is still advised as though nothing changed. Law firms and vendors quote the old Article 22 prohibition, yet the reformed regime changes what compliant actually looks like. Solely automated decisions with legal or similarly significant effects are now broadly lawful, provided the safeguards hold and special category data is handled with extra care. The burden has moved from asking whether you may automate to proving how the automated decision was made and that a person could challenge it.
What did the Data (Use and Access) Act 2025 actually change?
The Act received Royal Assent on 19 June 2025 and reforms the UK GDPR treatment of solely automated decisions, brought into force by commencement regulations. It replaces the single Article 22 with new provisions, Articles 22A to 22D, that move from a general prohibition to a qualified permission. A solely automated decision is one taken without meaningful human involvement that produces a legal effect or a similarly significant effect on a person. Under the reform such decisions are broadly permitted, with tighter restrictions kept where the decision relies on special category data such as health, biometrics or beliefs. The safeguards themselves survive. The reform is a change of default, not a removal of duty.
Which safeguards must a compliant automated decision keep?
The reformed regime keeps four practical duties for a qualifying automated decision:
- Tell the individual that a solely automated decision has been or will be made.
- Give them a way to make representations about it.
- Provide meaningful human intervention on request, from a person with authority to change the outcome.
- Let them contest the decision and have it reconsidered.
These duties are only credible if you can show the state of the system at the moment the decision was taken. A safeguard you cannot evidence is a safeguard a regulator will not accept.
“The reformed law did not end the duty to justify an automated decision: it raised the value of being able to prove, offline and after the fact, exactly how each decision was made.”
How does an on-premise audit ledger prove the basis of a decision?
Every material step is written to an append-only ledger that runs on the operator's own hardware. Each entry records the inputs considered, the model or rule version applied, the output, and the identity of any human who reviewed or overrode it. Entries are sealed with a post-quantum digital signature under FIPS 204, the ML-DSA standard, with FIPS 205, the stateless hash-based SLH-DSA standard, available as a second scheme. Because the signature covers the ordered chain, a single altered or deleted entry breaks verification. The sealing method and the binding of identity to the audit chain are among the mechanisms described in our 104 filed UK patent applications, approximately 2,340 claims, owned by Mickai LTD, and patent pending. The result is a record whose integrity can be checked years later without trusting the vendor who produced it.
Why does keeping the decision on-premise matter for personal data?
Article 22 duties sit inside wider UK GDPR obligations on transfer and security. A public cloud AI service processes the input on infrastructure you do not control, which for an automated decision means the personal data behind it leaves your estate. Mickai is a Sovereign Intelligence Operating System, a SIOS, that runs offline on operator-owned hardware behind a zero-egress inbound perimeter. Nothing about the individual is sent to an external model to reach the decision, so the audit trail and the personal data stay in the same controlled place. That also keeps the decision outside the reach of foreign disclosure regimes such as the US CLOUD Act.
What can an auditor or regulator actually check?
An auditor can take the sealed ledger and verify it independently. The test is simple: recompute the signature over the chain and confirm every entry verifies under FIPS 204, then read any single decision back to its inputs, model version and human reviewer. Because identity is hardware-attested and bound to the audit chain, the auditor can also confirm which physical machine and which operator acted. Where the decision drew on more than one sovereign model, the ledger shows the cross-model consensus that produced the output. None of this requires the auditor to be online or to receive a copy of the personal data.
How does this sit with the EU AI Act, DORA and other 2026 rules?
The DUAA does not stand alone. DORA has applied to financial entities since January 2025 and demands operational resilience and auditable controls. NIS2 places similar duties on essential and important entities. The EU AI Act adds obligations for high-risk systems: the Annex III high-risk duties once due on 2 August 2026 were deferred by the Digital Omnibus to 2 December 2027, with embedded Annex I high-risk moving to 2 August 2028 and the Article 50 transparency duties largely unchanged. We read that deferral as a build window, not a reprieve. A sovereign, sealed, on-premise record satisfies the common thread across all of these: prove what the system did, and prove a person could intervene. The same audit ledger also supports an ISO/IEC 42001 AI management system.
Frequently asked questions
Did the Data (Use and Access) Act 2025 repeal Article 22?
No. It replaces the single Article 22 with new Articles 22A to 22D and moves from a general prohibition to a qualified permission. Solely automated decisions with significant effects are more broadly allowed, but the safeguards of information, human intervention and the right to contest remain. Tighter rules apply where the decision relies on special category data.
Are solely automated decisions now allowed under UK law?
Broadly yes, where they do not rely on special category data and where the safeguards are in place. The controller must inform the individual, allow representations, provide meaningful human intervention and let them contest the outcome. Decisions using special category data stay more restricted and need a lawful basis plus additional protection.
What counts as meaningful human intervention?
Review by a person with the authority and competence to change the outcome, not a rubber stamp. The reviewer must be able to consider the individual's representations and reach an independent decision. An audit ledger that records who reviewed the decision and whether they altered it is how you evidence that the intervention was real.
Can we use a public cloud AI service for regulated automated decisions?
It is risky. Sending the personal data behind a decision to an external model means it leaves your control and may fall under foreign disclosure law such as the US CLOUD Act. A sovereign system that runs on your own hardware with a sealed audit ledger keeps both the decision and the data inside your estate.
How do we prove to a regulator how a decision was made?
Keep an append-only, cryptographically sealed record of each decision's inputs, model version, output and human review. Sealing under FIPS 204 lets an auditor verify the chain independently and offline. Bind identity to the hardware so the record also shows which machine and operator acted.