Skip to content
Dies ist eine Ubersetzung zur Orientierung. Die englische Version ist die massgebliche und rechtsverbindliche Version. Englische Version anzeigen
UKDEEP coverage2 enforcement actions

UK AI Governance Framework (UK GDPR Arts. 22A-22D + ICO + Sectoral Regulators): AI Compliance Requirements

The UK uses a sector-led, principles-based approach to AI governance. The ICO enforces AI requirements under UK GDPR (retained from EU GDPR post-Brexit). Current binding obligations come from UK GDPR Articles 22A-22D (automated decision-making — the Data (Use and Access) Act 2025 s. 80 SUBSTITUTED these for the old Article 22, in force 19 June 2025 for specified purposes and fully from 5 February 2026 per S.I. 2026/82; solely automated significant decisions are now generally permitted subject to mandatory Art. 22C safeguards, with a restriction for special-category data under Art. 22B), the ICO's Guidance on AI and Data Protection (updated 15 March 2023; under review for DUAA changes), the FCA and PRA's AI risk management expectations for financial services, and Ofcom's duties for regulated services under the Online Safety Act 2023. The UK AI Safety Institute (AISI) — renamed AI Security Institute 2025 — leads AI safety standards. As of mid-2026 the UK has NOT introduced a comprehensive AI Act and is not expected to: an anticipated AI bill did not materialise in 2025, and the government has confirmed a sectoral, pro-innovation route instead — DSIT published its Blueprint for AI Regulation on 21 October 2025 (centred on the AI Growth Lab, a programme of issue-specific regulatory sandboxes spinning up sector-by-sector through 2026-2027), and the May 2026 King's Speech announced a "Regulating for Growth Bill" creating sandbox powers rather than horizontal EU-style AI obligations. A private member's Artificial Intelligence (Regulation) Bill [HL] remains before Parliament but is not government legislation.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2025

Maximum Penalty

£17.5M or 4% of total worldwide annual turnover (UK GDPR Art. 83(5), incl. new Art. 83(5)(ba) for automated-decision breaches); Online Safety Act 2023: greater of £18M or 10% of qualifying worldwide revenue (Sch. 13 para. 4(1))

What Your Business Must Do

5 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

AI Transparency Notice (UK GDPR Arts. 13-15 + Art. 22C(2)(a))

High Priority

Inform UK data subjects about automated decision-making. Privacy notices and access responses must disclose "the existence of automated decision-making, including profiling, which is subject to the requirement to provide safeguards under Article 22C and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences" (Arts. 13(2)(f), 14(2)(g), 15(1)(h) as amended by DUAA 2025 Sch. 6, in force 5 Feb 2026). Separately, Art. 22C(2)(a) requires controllers taking solely automated significant decisions to provide the data subject with information about those decisions as part of the mandatory safeguards.

Deadline: February 5, 2026

UK GDPR Art. 22C(2)(a); Arts. 13(2)(f), 14(2)(g), 15(1)(h) (as amended by Data (Use and Access) Act 2025, s. 142(1), Sch. 6 paras. 3-5)

Data Protection Impact Assessment (DPIA)

High Priority

Conduct a DPIA "prior to the processing" where processing — in particular using new technologies — is likely to result in a high risk to rights and freedoms (Art. 35(1)). A DPIA is mandatory for a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based (Art. 35(3)(a)) — which covers most significant-decision AI systems — and for large-scale special-category processing (Art. 35(3)(b)) or large-scale systematic monitoring of publicly accessible areas (Art. 35(3)(c)).

UK GDPR Art. 35(1), (3)(a)-(c)

Art. 22C Safeguards — Information, Representations, Human Intervention, Contest

High Priority

REGIME CHANGE (in force 5 Feb 2026): DUAA 2025 s. 80 replaced UK GDPR Art. 22 with Arts. 22A-22D. Solely automated significant decisions are now generally PERMITTED, but the controller must ensure safeguards that (a) provide the data subject with information about such decisions, (b) enable them to make representations, (c) enable them to obtain human intervention, and (d) enable them to contest the decision (Art. 22C(2)). A decision is "solely automated" when there is no meaningful human involvement (Art. 22A(1)(a)). EXCEPTION: where the decision uses special-category (Art. 9(1)) data, it may NOT be solely automated unless based entirely on data with the data subject's explicit consent, or necessary for a contract / required or authorised by law AND the Art. 9(2)(g) substantial-public-interest condition applies (Art. 22B(1)-(3)).

Deadline: February 5, 2026

UK GDPR Arts. 22A, 22B, 22C (substituted for Art. 22 by Data (Use and Access) Act 2025, ss. 80(1), 142(1)(2)(h); S.I. 2026/82, reg. 2(j))

ICO AI Auditing Expectations

Medium Priority

The ICO expects organizations using high-risk AI to: document AI system purpose and training data, assess bias and fairness, maintain audit logs of AI decision outputs, conduct periodic reviews, and provide explanations for individual decisions. ICO guidance is not legally binding but informs enforcement decisions. The Guidance on AI and Data Protection was last updated 15 March 2023 (fairness restructure) and the ICO states it is under review following the Data (Use and Access) Act 2025 changes — re-check before relying on chapter-level detail.

ICO Guidance on AI and Data Protection (updated 15 Mar 2023; under review for DUAA 2025)

Online Safety Act — Illegal Content Duties Incl. AI-Generated Content

Medium Priority

All regulated user-to-user services (not only large platforms) must carry out "a suitable and sufficient illegal content risk assessment" (s. 9(2), timing per Sch. 3) and comply with the illegal content safety duties (s. 10) — these cover AI-generated illegal content such as CSAM and illegal deepfakes with risk-proportionate systems. Services designated Category 1, 2A or 2B additionally receive annual Ofcom transparency-report notices (s. 77). Sections 9, 10 and 77 in force since 10 Jan 2024 (S.I. 2023/1420); assessment deadlines are set by Ofcom under Sch. 3.

Online Safety Act 2023 ss. 9-10 (illegal content duties, all regulated user-to-user services), s. 77 (transparency reports, Category 1/2A/2B); Sch. 13 para. 4(1) (penalties)

Who Does This Apply To?

Binding obligations under UK GDPR apply to any organization processing personal data of UK residents — extraterritorial reach. AI-specific: since 5 February 2026, Articles 22A-22C (substituted by the Data (Use and Access) Act 2025) govern decisions "based solely on automated processing" (no meaningful human involvement, Art. 22A(1)(a)) that produce a legal or similarly significant effect (Art. 22A(1)(b)) — such decisions are permitted but require Art. 22C safeguards (information, representations, human intervention, contest), and are restricted for special-category data (Art. 22B). ICO guidance extends obligations broadly to AI systems with substantial influence on decisions. FCA/PRA AI expectations apply to UK-regulated financial institutions. Online Safety Act illegal-content duties apply to all regulated user-to-user services with UK links; transparency-report duties to Category 1/2A/2B services. The UK has confirmed a sectoral, sandbox-based route — no horizontal AI Act is expected.

Recent Enforcement Actions

ICO (UK Information Commissioner's Office)2023-10-06NONE — no fine, reprimand, or enforcement notice was ultimately issued (see summary)Source verified· as of 2026-08-22

Against: Snap Inc.

ICO issued a PRELIMINARY (provisional) enforcement notice on 2023-10-06 alleging Snap's "My AI" chatbot DPIA inadequately assessed data-protection risk, particularly to children, under Arts. 35 (DPIA) and 36 (prior consultation). This was NOT a final finding — Snap made representations and revised its DPIA, and the ICO's FINAL decision (2024-06-19) concluded Snap DID meet Art. 35 and had NOT breached Art. 36; no penalty, reprimand, or enforcement notice was issued in the end. Illustrates that a completed, adequate DPIA (even if it took several revisions) can fully resolve an ICO investigation with zero penalty — the opposite lesson from a "penalty reduced after appeal" framing.

Source
ICO2022-05-18£7,552,800 as originally imposed — OVERTURNED then remitted for reconsideration; not confirmed reinstated as of this cycle (see summary)Source verified· as of 2026-08-22

Against: Clearview AI

ICO originally fined Clearview AI £7,552,800 (announced 2022-05-23) for collecting and using UK residents' facial images without lawful basis via its facial-recognition database built by scraping billions of public images. Clearview appealed and the First-Tier Tribunal OVERTURNED both the enforcement notice and the monetary penalty on 2023-10-17 ([2023] UKFTT 819) — not on the merits, but on a narrow jurisdictional ground: Clearview's processing (for foreign law-enforcement/national-security clients) fell outside UK GDPR Art. 3 material scope even though it met the Art. 2 territorial-scope "monitoring of UK data subjects" test. The ICO appealed; the Upper Tribunal found IN FAVOUR of the ICO on 2025-10-07, holding the ICO does have jurisdiction, and REMITTED the case to the FTT to reconsider reinstating the original fine. As of this cycle, no source confirms the FTT has completed that reinstatement — left unresolved rather than asserted as a currently-collectible fine. Do not present this as a simple, standing £7.5M fine.

Source

Recent Regulatory Guidance

guidance2024-03-01

ICO Updated AI Guidance — Data Protection and Generative AI

ICO published updated guidance on generative AI and UK GDPR, addressing: (1) training AI on personal data requires lawful basis and minimization; (2) using customer data for AI training constitutes new processing requiring re-notification or consent; (3) individuals have the right to access information about how their data is used in AI systems; (4) accuracy obligation applies to AI outputs — businesses must check AI factual accuracy before acting on it.

Source
guidance2025-02-01

UK AI Security Institute — AI Safety Evaluation Framework

UK AI Safety/Security Institute published technical evaluation framework for frontier AI systems. Voluntary for most businesses; with no horizontal UK AI Act expected, its likeliest route to bite is via sector regulators and the AI Growth Lab sandboxes. Framework covers: dangerous capability evaluations, safety case methodology, pre-deployment testing standards. Businesses with advanced AI systems should align with the AISI framework ahead of any sectoral adoption.

Source

Key Case Law & Precedent

Clearview AI Inc v The Information Commissioner [2023] UKFTT 819; ICO v. Clearview AI (Upper Tribunal, 2025)

First-Tier Tribunal (General Regulatory Chamber) 2023; Upper Tribunal 2025 · 2023

Originally, ICO enforcement (2022) held that scraping UK residents' public images to train an AI facial-recognition model violates UK GDPR lawful-basis, transparency, and data-minimization requirements. On appeal, the FTT overturned the fine on a narrow jurisdictional ground (Clearview's law-enforcement-client processing held outside UK GDPR Art. 3 material scope, 2023-10-17); the Upper Tribunal then held FOR the ICO on jurisdiction (2025-10-07) and remitted the case to the FTT for reconsideration. Applies to any business training AI on publicly available UK personal data, but the case is a live illustration that a live enforcement action can be overturned, appealed, and remain unresolved for years — do not cite the original £7.55M figure as a settled, collectible fine.

Outcome: ICO originally imposed £7,552,800 (2022). Overturned by the FTT (2023) on jurisdictional grounds. Upper Tribunal ruled for the ICO on jurisdiction and remitted to the FTT (2025-10-07) to reconsider reinstating the fine — NOT CONFIRMED reinstated as of this cycle.

Case reference

Drivers v. Uber B.V. & Ola (Amsterdam Court of Appeal, 2023)

Gerechtshof Amsterdam (Amsterdam Court of Appeal), the Netherlands · 2023

On appeal, the Amsterdam Court of Appeal (4 April 2023) held that several of Uber's automated processes — including ride assignment, pricing, driver ratings, fraud-probability scoring and account deactivation — qualify as automated decision-making under GDPR Article 22, and that Uber's human "review" of deactivations was "not much more than a purely symbolic act", so the decisions were solely automated and engaged drivers' Art. 22 / Art. 15 rights. Leading EU precedent on meaningful human involvement; persuasive for UK GDPR Art. 22 (which mirrors the EU text the UK retained). Not a UK case.

Outcome: Court of Appeal upheld drivers' appeal: Uber/Ola ordered to provide access/explanation and to reinstate drivers deactivated by automated fraud-detection. (Dutch ruling.)

Case reference

Quarterly Enforcement Digest

Q3 2026: The headline change is the Data (Use and Access) Act 2025 automated-decision regime — UK GDPR Arts. 22A-22D fully in force since 5 February 2026, replacing Art. 22. Solely automated significant decisions are now generally permitted WITH mandatory Art. 22C safeguards (information, representations, human intervention, contest); special-category data decisions remain restricted (Art. 22B); breaches sit in the top fine tier (Art. 83(5)(ba), £17.5M/4%). The ICO's Guidance on AI and Data Protection is under review to reflect the DUAA. No horizontal UK AI Act is coming — the confirmed route is sectoral sandboxes (DSIT Blueprint, Oct 2025; "Regulating for Growth Bill"). CYCLE 10 CORRECTION (2026-08-22): both enforcementActions entries were materially wrong — the Clearview £7.5M fine was OVERTURNED on appeal (FTT, 2023-10-17) and remains only remitted-for-reconsideration after the Upper Tribunal sided with the ICO on jurisdiction (2025-10-07), not a simple standing fine; the Snap "My AI" matter ended with NO penalty at all (ICO's final 2024-06-19 decision found Snap compliant), not the fabricated "£500 reduced after appeal" previously stated — both fixed, see enforcementActions/caseCitations above. Businesses should: re-map their Art. 22 compliance to Arts. 22A-22C, update privacy notices to the amended Arts. 13(2)(f)/14(2)(g)/15(1)(h) wording, keep DPIAs current for high-risk AI, and monitor their sector regulator rather than prepare for horizontal AI legislation.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.

Industry Playbooks covering UK AI Governance Framework (UK GDPR Arts. 22A-22D + ICO + Sectoral Regulators)

These industry playbooks include jurisdiction-specific checklist items and guidance for UK AI Governance Framework (UK GDPR Arts. 22A-22D + ICO + Sectoral Regulators).

Frequently Asked Questions

Does UK AI Governance Framework (UK GDPR Arts. 22A-22D + ICO + Sectoral Regulators) apply to my business?

The UK uses a sector-led, principles-based approach to AI governance. The ICO enforces AI requirements under UK GDPR (retained from EU GDPR post-Brexit). Current binding obligations come from UK GDPR Articles 22A-22D (automated decision-making — the… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under UK AI Governance Framework (UK GDPR Arts. 22A-22D + ICO + Sectoral Regulators) is: £17.5M or 4% of total worldwide annual turnover (UK GDPR Art. 83(5), incl. new Art. 83(5)(ba) for automated-decision breaches); Online Safety Act 2023: greater of £18M or 10% of qualifying worldwide revenue (Sch. 13 para. 4(1)). Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with UK AI Governance Framework (UK GDPR Arts. 22A-22D + ICO + Sectoral Regulators)?

The 5 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.legislation.gov.uk/eur/2016/679

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan