If Your App Makes Decisions About People Using AI, the UK’s Rules Just Got More Specific and Wider

 

Why poor tech infrastructure can cost investors millions and how to spot it early 

If your product uses AI or an algorithm to decide who gets approved, what price someone sees, who gets shortlisted, or anything else that affects a real person without a human properly checking it first, the UK’s data regulator has just told you, in unusually specific terms, what “properly checking it” now means.

And it’s broader than most founders assume.

What’s actually happening

On 31 March 2026, the UK Information Commissioner’s Office (ICO) published a coordinated package of draft guidance on automated decision-making (ADM), covering new rules introduced by the Data (Use and Access) Act 2025 into the UK GDPR (specifically Articles 22A–22D).

The public consultation on this draft guidance ran until 29 May 2026 and has now closed. The final guidance is expected in the coming months and will feed into the ICO’s forthcoming statutory AI and ADM code of practice.

This matters regardless of whether you’ve been following the consultation. The direction of travel in the draft is already clear, and the ICO is actively enforcing in this area rather than waiting for the final text.

Separately, on 12 May 2026, a statutory instrument (SI 2026/425) came into force placing the Information Commissioner under a formal legal duty to produce that AI/ADM code of practice.

Three things worth checking in your product

1. “Decision” is broader than you think.

The draft guidance defines it as any “conclusion or outcome, reached after consideration or analysis” that could affect someone’s rights.

A system that just applies a rule a human already set (e.g., “decline this payment card type”) doesn’t count. A system that evaluates information about a person and passes judgement, like scoring someone’s eligibility for a service, does.

If your product has any kind of AI-driven eligibility scoring, ranking, or recommendation, it’s worth checking which side of that line you’re on.

2. “Significant effect” now explicitly includes things founders don’t usually think of as high-stakes.

The ICO’s examples include AI-driven “dynamic pricing and discriminatory offers” as a decision with a significant effect on someone’s choices, and algorithmic content recommendations that nudge behaviour as a decision with a significant effect on behaviour.

If you run dynamic pricing, personalised offers, or an AI recommendation engine, the ICO’s own examples suggest you may be closer to ADM obligations than “we’re just a small SaaS tool” might suggest.

3. “A human looked at it” is not enough on its own.

The guidance raises the bar on what counts as genuine human involvement. The person reviewing an AI decision must be “suitably trained and qualified to understand the system’s logic, outputs, limitations, and risks,” their involvement must happen before the decision is applied to a person, and ad hoc spot-checking doesn’t count.

If your “human in the loop” is a founder or ops hire glancing at outputs without understanding how the model actually scores things, that’s unlikely to satisfy the exemption the ICO is describing.

The guidance also strengthens individuals’ information rights. Privacy notices alone don’t satisfy your obligations. If someone asks why an automated decision went a certain way for them specifically, you need to be able to give them decision-specific reasoning, not a repeat of your generic privacy policy.

Why this is a live risk, not a future one

The ICO isn’t waiting for the final guidance to act.

Alongside the March 2026 consultation package, it published a statement and report specifically on ADM in recruitment, explicitly calling for action from businesses now and setting out its findings from existing regulatory focus on this area.

That’s a clear signal. Hiring tools, candidate screening, and performance-evaluation AI are an active ICO priority today, not a 2027 problem.

Separately, and worth knowing even though it’s not this article’s main subject, the EU AI Act’s own high-risk employment-AI obligations (recruitment screening, performance evaluation, and similar Annex III use cases) were delayed by 16 months to 2 December 2027 by a European Parliament vote on 16 June 2026.

That EU delay does not touch the UK ICO’s ADM rules described above, which are a separate legal framework moving on its own, faster timeline. Don’t let “the EU pushed its deadline” create false comfort about UK obligations.

What to actually do this month

  1. List anything in your product that scores, ranks, prices, or filters people, even loosely (a lead-scoring tool, a dynamic-pricing feature, an applicant screener).
  2. For each one, ask: does a human meaningfully review it before it affects someone, and could that human explain the system’s logic if challenged? If the honest answer is “not really,” that’s a gap worth closing before a regulator or an investor asks the same question.
  3. Check your privacy notice. Does it explain automated decisions in a way a real user could understand, or is it boilerplate?

Sources

Editorial Note: Content on this site is initiated via AI automation and reviewed by our team. While we check our articles before publishing, we cannot guarantee absolute factual accuracy or completeness. Readers should verify critical information independently.