What actually changed on 5 February 2026
Section 80 of the Data (Use and Access) Act 2025 came into force on 5 February 2026, replacing Article 22 of the UK GDPR. For nearly a decade, the old rule gave people a fairly blunt right: a decision made “solely” by a machine, with no human involved, and no legal or similarly significant effect on them, couldn’t happen without their consent or a specific legal basis. The new rule is more permissive about when you can use automation, and more specific about what you owe the person on the other end of it.
We think that trade-off is the story most small businesses have missed. It is now easier to justify using AI to screen a job application, score a credit request or triage a customer complaint. It is also now clearer, in law, what you have to tell people, and what you have to let them challenge, if you do.
Why this affects you even if you’ve never said “automated decision-making”
Nobody buys an “ADM system.” Businesses buy an applicant tracking tool that ranks CVs, a chatbot that decides which support tickets get escalated, or a scoring plug-in that flags which invoices to chase first. Under the ICO’s own guidance on the Act, that is exactly the kind of processing the new rules cover, the moment the outcome has a legal or similarly significant effect on someone and no human meaningfully reviews it before it lands.
We build AI workflows for small businesses and trades for a living, and this is the conversation we now have on nearly every build: not “can the AI do this,” but “who signs off before it acts on a real person.” That second question used to be a nice-to-have. Since 5 February, it is the difference between compliant automation and a live regulatory exposure.
The ICO checked, and most employers failed
This isn’t theoretical. On 31 March 2026 the ICO published a report drawn from evidence gathered across more than 30 employers using AI in recruitment, alongside draft guidance on automated decision-making and profiling. The ICO’s own summary is blunt: most of the employers it looked at were using AI to screen and score candidates in ways that count as automated decision-making, and most of them were not applying the safeguards the law requires. A lot of them did not even recognise they were doing ADM in the first place.
That matters because the penalty regime behind this is not small-business-friendly. Breaches of UK GDPR, which is what the automated decision-making safeguards sit inside, carry fines of up to £17.5 million or 4% of annual global turnover, whichever is higher. Most small firms will never approach that ceiling in practice, but the ICO has shown in 2025 and 2026 that it is willing to issue seven-figure penalties, and “we didn’t realise our software was making the decision” is not a defence it has accepted.
What counts as a “significant decision” under the new rules
The threshold is “legal or similarly significant effect,” and the examples the ICO and legal advisers keep coming back to are the ones small businesses actually run into:
- Rejecting a job applicant based on an automated screening score, before a person looks at the CV.
- Declining or pricing a credit, insurance or finance application using an automated risk model.
- Refusing a refund, cancelling an account or suspending access based on an automated fraud or abuse score.
- Any AI triage that changes someone’s access to a service, a job opportunity or money, without a human checking the outcome first.
If a human genuinely reviews the recommendation and can overturn it before it takes effect, you are in a materially safer position. If the system’s output is what actually happens, you are doing ADM, whether or not you call it that.
Four things to sort this month
The good news in the reforms, as Clifford Chance and other firms have noted since commencement, is that the law is more workable than the old Article 22 regime, not less. You are not being asked to stop automating. You are being asked to do four concrete things:
- Map it. List every tool that scores, ranks, filters or triages people, whether it’s recruitment software, a chatbot, or a spreadsheet formula that auto-rejects applications under a threshold. If it decides something about a real person with no human check, write it down.
- Add a human checkpoint, or document why one isn’t needed. For anything with a legal or significant effect, someone competent needs to be able to look at the case and change the outcome before it lands, not just after a complaint.
- Update what you tell people. Privacy notices need to say, in plain language, where automated decisions happen, what logic is involved at a level people can actually understand, and how to challenge the outcome or ask for a human to look again.
- Keep the record. An audit trail of what the system decided, when a human overrode it, and why, is the single best thing to have ready if the ICO or a customer ever asks.
The uncomfortable bit
According to the DLA Piper summary of the ICO’s findings, the most common failure was not bad intent. It was businesses not realising a tool they bought off the shelf was making legally significant decisions on their behalf. That is the trap for small firms specifically: you don’t need to build your own AI to be caught by this. You just need to switch on a feature in software you already use.
We would rather our clients hear the uncomfortable number now than from a regulator later. If you are already using AI anywhere in hiring, lending, refunds or access decisions, the honest first move is a short audit, not a rewrite. We offer a free 30 minute AI audit for exactly this, and it usually surfaces two or three automated touchpoints a business didn’t realise counted.