If your business uses AI to make or inform decisions about customers or employees — even in a relatively simple way — the legal ground shifted in February 2026. Section 80 of the Data (Use and Access) Act 2025 came into force on 5 February, replacing Article 22 of the UK GDPR. This is the law that governs automated decision-making: when AI can make significant choices, what rights people have to challenge those choices, and what you are required to tell them.

The ICO has a statutory code of practice on AI and automated decisions expected this summer. Now is the right moment to understand what has changed — before the formal guidance lands and the clock starts on compliance.

What changed on 5 February

Article 22 of the UK GDPR gave individuals a right not to be subject to decisions made solely by automated means where those decisions had a legal or significantly significant effect on them. The rule was relatively narrow: purely automated, high-stakes decisions.

Section 80 of the Data (Use and Access) Act reshapes this considerably. The new framework:

  • Expands beyond “solely automated” decisions to cover AI-assisted decisions where a human may be nominally involved but AI is doing the substantive work
  • Requires proactive transparency: businesses must explain when AI is being used in decisions, rather than waiting to be asked
  • Strengthens individual rights to challenge AI-influenced outcomes
  • Makes the ICO responsible for publishing a statutory code that sets specific compliance expectations for organisations

For most UK SMEs, the practical question is straightforward: are you currently using AI in any way that touches decisions about people? That includes credit checks, marketing targeting, recruitment screening, customer segmentation, or personalised pricing. If yes, the new rules apply to you.

Agentic AI adds a separate layer of risk

The ICO has also published early thinking specifically on agentic AI — systems that take sequences of actions autonomously on a user’s behalf. If you deploy an agentic AI that processes personal data, the ICO’s position is unambiguous: you are fully responsible for what it does.

This matters because agentic AI is moving rapidly from enterprise tools to products accessible to small businesses. If you are using or building anything that acts autonomously — booking things, sending communications, pulling records, making recommendations without human sign-off at each step — and that system touches customer data, the ICO expects you to have assessed the data protection implications before deploying it.

The specific ICO guidance on agentic AI is expected later in 2026. Getting your data handling in order now is considerably easier than retrofitting compliance after formal requirements are published.

What to check now

You do not need a dedicated legal or compliance team to handle this, but you do need honest answers to a few questions.

List your AI tools and what they touch. Go through every AI product your business uses: email drafting assistants, CRM plugins, customer service chatbots, recruitment screening tools, automated pricing. For each one, note whether it uses data about identifiable people to make or influence a decision.

Update your privacy documentation. If your privacy policy was written before 2025, it almost certainly does not address AI-assisted decision-making in the way the new rules require. The Smallprint template library includes privacy notice templates that can be updated quickly to cover AI processing disclosures — removing the need to write from scratch.

Establish a genuine human checkpoint. For any significant decision that AI informs — a quote, a credit limit, an applicant shortlist — ensure a human review step exists in your actual workflow. Even under the new rules, keeping a substantive human in the loop reduces legal exposure and demonstrates good faith to the ICO.

The window before formal guidance

The ICO’s statutory code on AI and automated decisions will set specific compliance benchmarks. Once published, businesses will be assessed against it. Organisations that have already audited their AI use, updated their documentation, and put review processes in place will find that compliance is largely already done. Those starting from scratch will face a much steeper catch-up under scrutiny.

Summer 2026 is the right moment to get ahead of this quietly, rather than scrambling once the formal expectations arrive.