Skip to content
11 items · Free checklist

UK AI Governance Framework (UK GDPR Arts. 22A-22D + ICO + Sectoral Regulators) Compliance Checklist 2026

The UK uses a sector-led, principles-based approach to AI governance. The ICO enforces AI requirements under UK GDPR (retained from EU GDPR post-Brexit). Current binding obligations come from UK GDPR

Maximum penalty: £17.5M or 4% of total worldwide annual turnover (UK GDPR Art. 83(5), incl. new Art. 83(5)(ba) for automated-decision breaches); Online Safety Act 2023: greater of £18M or 10% of qualifying worldwide revenue (Sch. 13 para. 4(1))

Complete each item below to achieve compliance. Use Aegis Firma to generate all required documentation automatically.

Regulatory Requirements

1. AI Transparency Notice (UK GDPR Arts. 13-15 + Art. 22C(2)(a))

Inform UK data subjects about automated decision-making. Privacy notices and access responses must disclose "the existence of automated decision-making, including profiling, which is subject to the requirement to provide safeguards under Article 22C and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences" (Arts. 13(2)(f), 14(2)(g), 15(1)(h) as amended by DUAA 2025 Sch. 6, in force 5 Feb 2026). Separately, Art. 22C(2)(a) requires controllers taking solely automated significant decisions to provide the data subject with information about those decisions as part of the mandatory safeguards.

Due: February 5, 2026

2. Data Protection Impact Assessment (DPIA)

Conduct a DPIA "prior to the processing" where processing — in particular using new technologies — is likely to result in a high risk to rights and freedoms (Art. 35(1)). A DPIA is mandatory for a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based (Art. 35(3)(a)) — which covers most significant-decision AI systems — and for large-scale special-category processing (Art. 35(3)(b)) or large-scale systematic monitoring of publicly accessible areas (Art. 35(3)(c)).

3. Art. 22C Safeguards — Information, Representations, Human Intervention, Contest

REGIME CHANGE (in force 5 Feb 2026): DUAA 2025 s. 80 replaced UK GDPR Art. 22 with Arts. 22A-22D. Solely automated significant decisions are now generally PERMITTED, but the controller must ensure safeguards that (a) provide the data subject with information about such decisions, (b) enable them to make representations, (c) enable them to obtain human intervention, and (d) enable them to contest the decision (Art. 22C(2)). A decision is "solely automated" when there is no meaningful human involvement (Art. 22A(1)(a)). EXCEPTION: where the decision uses special-category (Art. 9(1)) data, it may NOT be solely automated unless based entirely on data with the data subject's explicit consent, or necessary for a contract / required or authorised by law AND the Art. 9(2)(g) substantial-public-interest condition applies (Art. 22B(1)-(3)).

Due: February 5, 2026

4. ICO AI Auditing Expectations

The ICO expects organizations using high-risk AI to: document AI system purpose and training data, assess bias and fairness, maintain audit logs of AI decision outputs, conduct periodic reviews, and provide explanations for individual decisions. ICO guidance is not legally binding but informs enforcement decisions. The Guidance on AI and Data Protection was last updated 15 March 2023 (fairness restructure) and the ICO states it is under review following the Data (Use and Access) Act 2025 changes — re-check before relying on chapter-level detail.

5. Online Safety Act — Illegal Content Duties Incl. AI-Generated Content

All regulated user-to-user services (not only large platforms) must carry out "a suitable and sufficient illegal content risk assessment" (s. 9(2), timing per Sch. 3) and comply with the illegal content safety duties (s. 10) — these cover AI-generated illegal content such as CSAM and illegal deepfakes with risk-proportionate systems. Services designated Category 1, 2A or 2B additionally receive annual Ofcom transparency-report notices (s. 77). Sections 9, 10 and 77 in force since 10 Jan 2024 (S.I. 2023/1420); assessment deadlines are set by Ofcom under Sch. 3.

Implementation Steps

6. Review UK AI Security Institute (formerly AI Safety Institute, renamed Feb 2025) guidance for your sector

7. Assess your AI systems against ICO AI auditing framework

8. Ensure UK GDPR compliance for AI-driven profiling decisions, including the DUAA Art. 22A-22D automated-decision provisions

9. Do not wait for a general UK AI Act — none is currently before Parliament; comply now via UK GDPR + sectoral-regulator rules

10. Engage with relevant sector regulator (FCA for finance, CQC for health, Ofcom for platforms)

11. Document AI governance procedures aligned with the Alan Turing Institute/CDEI guidance