# AI in regulated industries: UK rules and human review

> Is AI regulated in the UK? The rules for AI in regulated firms: UK GDPR Articles 22A–22D, the Information Commission, DPIAs, records and the EU AI Act.

Pillar guide · Safe AI in regulated firms · By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026
Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.
Canonical: https://vexralabs.com/insights/ai-in-regulated-firms

Short answer

The UK has **no AI-specific Act**. AI in regulated industries is governed by existing law: UK GDPR, with Articles 22B and 22C only for significant decisions taken without meaningful human involvement; sector regulators’ rules, whatever tool did the work; and the EU AI Act where output is used in the EU. A person who can change the outcome signs off.

This guide is for owners and compliance leads at UK accountancy practices, financial advice firms and immigration advisers who want to use AI on client work. Three things changed in 2026. The new UK GDPR rules on automated decisions came fully into force on 5 February 2026. A duty to write a statutory code on AI took effect on 12 May 2026. The Information Commission replaced the Information Commissioner on 30 September 2026. We build Filyst, case management software for immigration firms, so one section says what we built into its sign-off. The sections cover the rules, automated decisions, the regulator, impact assessments, staff tools, records, clients, the EU AI Act, workflow design and where to start.

## What is AI regulation in the UK?

AI regulation in the UK is a set of existing laws and regulators, not a single AI Act. The government’s [response to the AI regulation white paper](https://www.gov.uk/government/consultations/ai-regulation-a-pro-innovation-approach-policy-proposals/outcome/a-pro-innovation-approach-to-ai-regulation-government-response)(updated 6 February 2024) chose five cross-sectoral principles “for existing regulators to interpret and apply within their remits” (paragraph 10), set on a non-statutory basis (paragraph 16).

The five principles, in full, are:

- safety, security and robustness;
- appropriate transparency and explainability;
- fairness;
- accountability and governance;
- contestability and redress.

No government AI Bill has followed. A law firm review of [UK AI legislation dated 14 September 2026](https://www.lewissilkin.com/insights/2026/09/14/ai-judgment-day-on-the-horizon-while-uk-lawmakers-play-catch-up)says “the UK remains without a comprehensive legislative framework for regulating artificial intelligence”. A private member’s bill proposing to prohibit the development of artificial superintelligence is due its second reading on 13 November 2026. Until Parliament passes something, a regulated firm’s AI duties come from the laws below.

## Which rules apply when a UK regulated firm uses AI?

Three layers of rules apply at once: data protection law (the UK General Data Protection Regulation, or UK GDPR), your sector regulator’s rules and, for EU-facing work, the EU AI Act. Sector rules mostly don’t name AI; they apply to the work, whatever tool produced it.

| Layer | Who it applies to | What it means for AI |
| --- | --- | --- |
| UK GDPR, as amended by the Data (Use and Access) Act 2025 | Any firm that processes personal data as a controller | Lawful basis, transparency, security, data protection impact assessments (DPIAs), processor contracts, and Articles 22A–22D for solely automated significant decisions |
| FCA rules | Advice firms authorised by the Financial Conduct Authority | The FCA says its rules “do not usually mandate or prohibit specific technologies” (AI Update, para 3.2); the Senior Managers and Certification Regime keeps senior managers accountable (para 3.40) |
| ICAEW ethics guidance | Chartered accountants following ICAEW guidance | The five fundamental principles “apply to the use of technology”; AI tools “are not fully qualified accountants” |
| IAA Code of Standards 2024 | Anyone giving immigration advice or services in the UK, except those listed in Schedule 5, paragraph 3(3) of the Immigration and Asylum Act 1999 | The Code does not mention AI; it applies to the advice and the client file whatever tool helped |
| EU AI Act | Third-country providers and deployers whose AI output is used in the EU (Article 2(1)(c)) | AI literacy since 2 February 2025; general application from 2 August 2026, with exceptions (Article 113) |

The Financial Conduct Authority (FCA) regulates advice firms; its [AI Update](https://www.fca.org.uk/publication/corporate/ai-update.pdf) is the source for the FCA row. The Institute of Chartered Accountants in England and Wales (ICAEW) is a professional body for accountants; its [generative AI ethics guide](https://www.icaew.com/technical/technology/artificial-intelligence/generative-ai-guide/ethics) is the source for that row. The Immigration Advice Authority (IAA) regulates immigration advisers; the [Code of Standards 2024](https://assets.publishing.service.gov.uk/media/6776b2ef6c34906cc84c9499/IAA_Codes_of_Standards_2024.pdf)“applies to any organisation or person providing immigration advice”. Because sector rules apply to the advice whatever tool produced it, the professional stays accountable for AI-assisted work.

## When does an AI decision count as solely automated?

A decision is “based solely on automated processing if there is no meaningful human involvement in the taking of the decision” ([UK GDPR Article 22A(1)(a)](https://www.legislation.gov.uk/eur/2016/679/article/22A)). It is a significant decision if it produces a legal effect or a similarly significant effect for the person (Article 22A(1)(b)).

Articles 22A to 22D replaced the old Article 22 under the Data (Use and Access) Act 2025, partly from 19 June 2025 and fully from 5 February 2026. Article 22A defines the terms “for the purposes of Articles 22B and 22C”, so those two articles only bite on solely automated significant decisions. A firm that keeps a reviewer who can genuinely change the outcome stays outside them.

[Article 22B](https://www.legislation.gov.uk/eur/2016/679/article/22B)restricts solely automated significant decisions based on special category data, such as health data. They are allowed only with the person’s explicit consent, or where the decision is necessary for a contract or required or authorised by law and Article 9(2)(g) applies. They are never allowed where the processing relies on the recognised legitimate interests basis in Article 6(1)(ea).

[Article 22C(2)](https://www.legislation.gov.uk/eur/2016/679/article/22C) requires four safeguards for every solely automated significant decision. The safeguards are measures that:

- provide the person with information about the decision;
- enable the person to make representations about it;
- enable the person to obtain human intervention from the controller;
- enable the person to contest the decision.

[Article 22D](https://www.legislation.gov.uk/eur/2016/679/article/22D) is different. It gives the Secretary of State power to make regulations on what counts as meaningful human involvement and on the safeguards. It places no duty on firms.

The UK data protection regulator, known as the ICO, updated its [draft guidance on automated decision-making](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/what-does-the-uk-gdpr-say-about-adm/)on 31 March 2026. It says human involvement must be “active and not just a token gesture”. It lists five non-exhaustive criteria. The reviewer should assess and review the decision at a point where it has an actual impact on the outcome. They should be able to influence the outcome, and have discretion and authority to alter it. They should be trained to understand the system’s logic, outputs, limitations and risks. They should take into account the data and factors the decision was based on. The draft adds that ad hoc spot-checking isn’t sufficient. [Human in the loop AI: UK GDPR Article 22A explained](https://vexralabs.com/insights/human-in-the-loop-ai-uk-gdpr) applies this test to firm workflows step by step.

## Who regulates AI and data protection, and is the guidance final?

The Information Commission regulates UK data protection, including AI that processes personal data. It took over from the Information Commissioner on 30 September 2026, when [section 118 of the Data (Use and Access) Act 2025](https://www.legislation.gov.uk/ukpga/2025/18/section/118) abolished the office of Information Commissioner (statutory instrument[SI 2026/1015, regulation 2](https://www.legislation.gov.uk/uksi/2026/1015/made)).

Regulation 3 of that instrument carries over anything done by or in relation to the Commissioner, so existing guidance and investigations continue. The [government’s announcement](https://www.gov.uk/government/news/information-commission-succeeds-the-ico-as-uks-data-protection-regulator)says the change “does not change the regulator’s role, responsibilities, or powers”. The regulator’s [website](https://ico.org.uk/) is still ico.org.uk and still uses the initials ICO.

[SI 2026/425](https://www.legislation.gov.uk/uksi/2026/425/made), in force since 12 May 2026, requires the regulator to prepare a code of practice on developing and using AI and on automated decision-making, including guidance on children’s data. The regulations set no date for the code. Until it exists, the guidance below is what the regulator has published, and much of it is marked as changing.

| Guidance | Status on 8 October 2026 | What it covers |
| --- | --- | --- |
| ICO, When do we need to do a DPIA? | Under review after the Data (Use and Access) Act | Mandatory DPIA triggers, including AI as innovative technology |
| ICO, Guidance on AI and data protection | Under review after the Data (Use and Access) Act | Fairness, transparency and accountability for AI systems |
| ICO, Automated decision-making, including profiling | Draft; consultation ran 31 March to 29 May 2026 | Articles 22A–22D and meaningful human involvement |
| Statutory code on AI and automated decision-making | Required by SI 2026/425; no date set | Good practice for developing and using AI |
| FCA AI Update | Published statement of approach | How existing FCA rules apply to AI |

**Diagram: UK and EU AI rule dates for regulated firms, 2025 to 2026.** Six dates. 2 February 2025: EU AI Act Chapter I, including the AI literacy duty, applies. 19 June 2025: UK GDPR Articles 22A to 22D in force for specified purposes. 5 February 2026: Articles 22A to 22D fully in force. 12 May 2026: regulations requiring a statutory code on AI and automated decision-making come into force. 2 August 2026: most of the EU AI Act applies. 30 September 2026: the Information Commission replaces the Information Commissioner.

*Sources: AI Act Article 113; legislation.gov.uk annotations to Article 22A; SI 2026/425; SI 2026/1015.*

## Does a firm need a DPIA before using AI?

Often, yes. A data protection impact assessment (DPIA), sometimes called a privacy impact assessment, is required before processing that is “likely to result in a high risk to the rights and freedoms of natural persons” ([UK GDPR Article 35(1)](https://www.legislation.gov.uk/eur/2016/679/article/35)).

The ICO’s page [When do we need to do a DPIA?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/when-do-we-need-to-do-a-dpia/)lists innovative technology, “(including AI)”, as a trigger: a DPIA is required where it is combined with any of the criteria from the European guidelines. [DPIA for AI tools: when a UK firm needs one](https://vexralabs.com/insights/dpia-for-ai-tools) gives the screening test and the minimum contents.

## What should staff be allowed to do with general AI tools?

A short written policy decides it: which tools are approved, what client data may go into them and who reviews the output. Without one, the firm cannot show which vendors hold client data.

[Is ChatGPT GDPR compliant? An AI policy for UK firms](https://vexralabs.com/insights/chatgpt-client-data-policy)gives a one-page policy for staff use of general tools. Where an AI vendor processes personal data on the firm’s behalf, it is a processor, and [Article 28(3)](https://www.legislation.gov.uk/eur/2016/679/article/28) requires a binding contract with it. [UK GDPR Article 28(3): what a processor contract must say](https://vexralabs.com/insights/uk-gdpr-article-28-processor-contract) lists the terms that contract needs.

## What should a firm record about AI-assisted work?

[UK GDPR Article 5(2)](https://www.legislation.gov.uk/eur/2016/679/article/5)makes the controller “responsible for, and be able to demonstrate compliance with” the data protection principles. The article names no log. For AI, a practical way to show compliance is a record of the input, the AI output, the reviewer, any change and the time.

The ICO’s draft automated decision-making guidance also says “you should keep a record of how the human was involved in the decision”. [AI audit trail for UK regulated firms: what to log](https://vexralabs.com/insights/ai-audit-trail) lists the fields and how long to keep them.

## How should a firm tell clients it uses AI?

[UK GDPR Article 13(1)(c)](https://www.legislation.gov.uk/eur/2016/679/article/13)requires privacy information to give “the purposes of the processing” and its legal basis; Article 14 does the same where data comes from someone else. If AI processes client data, say so in the privacy notice, name the purpose and state that a qualified person reviews every output.

Telling clients a person checks the work also commits the firm to keeping that check. Where a decision is solely automated and significant, Article 22C adds the information and contest rights listed above.

## Does the EU AI Act apply to UK firms?

The EU AI Act applies to providers and deployers in a third country, such as the UK, “where the output produced by the AI system is used in the Union” ([Article 2(1)(c)](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-2)). A UK firm serving only UK clients, with no AI output used in the EU, falls outside that test.

Since 2 February 2025, providers and deployers have had an AI literacy duty ([Article 4](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-4); dates in [Article 113(a)](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113)). Since the 2026 Digital Omnibus amendment, it reads: take measures to support the development of AI literacy of their staff, with no requirement to guarantee “any specific level of AI literacy of any individual”. The Act applies generally from 2 August 2026, with the exceptions listed in Article 113. [Does the EU AI Act apply to UK firms? 2026 deadlines](https://vexralabs.com/insights/eu-ai-act-deadlines-uk-firms) sets out every date that matters to a UK firm.

## How should AI be designed into a regulated workflow?

The workflow design decides whether review is real. This is the pattern we design AI workflows to:

| Principle | In practice |
| --- | --- |
| Rules decide what has a right answer | Totals, deadlines, thresholds and eligibility are calculated, not generated |
| AI reads and drafts | Extraction, classification and first drafts, each with its source shown |
| A person signs off | A qualified, named reviewer approves, edits or rejects before anything takes effect |
| Everything is logged | Input, output, reviewer, change and time |
| Review is monitored | Approval-without-change rates show if sign-off has become a rubber stamp |

**Diagram: Five steps to using AI in a UK regulated firm.** Screen each AI use for a data protection impact assessment; design the workflow so rules decide what has a right answer, AI drafts and a person signs off; set a staff policy and processor contracts for AI tools; record every AI-assisted decision; and review approval patterns so human sign-off stays meaningful.

*Each step has its own guide on this page. The design step is what keeps a decision outside Articles 22B and 22C.*

Building Filyst taught us that sign-off has to be enforced by the system, not by a policy. Filyst makes four-eyes sign-off the default for every case stage, and the server rejects an approval from the person who prepared the work. Filyst also keeps an audit log. The check gates case stage advances; it does not cover everything a firm sends outside the system, so the firm’s own procedures still matter.

## What mistakes do firms make with AI?

Most problems come from skipping one of the five steps above. The table pairs each gap with the rule it touches.

| Mistake | Why it matters | Fix |
| --- | --- | --- |
| Staff choose their own AI tools | Client data reaches vendors with no Article 28 contract | An approved-tool list and a processor contract for each |
| Approval becomes a click | Review stops being meaningful, so decisions can count as solely automated | Show the source beside the output; monitor approval rates |
| No record of what the AI did | The firm cannot demonstrate compliance under Article 5(2) | Log input, output, reviewer and change for every decision |
| AI decides what rules should decide | Totals and deadlines get guessed instead of calculated | Calculate with rules; let AI read and draft only |
| No DPIA screening | High-risk processing starts without the Article 35 assessment | Screen every new AI use against Article 35 and the ICO list |

## Where should a firm start?

Start with one workflow where staff re-type or read documents by hand, and add AI there with a named reviewer and a log. That limits risk and gives you something to measure within the first month.

Each sector applies these rules differently. [AI for accountants in the UK](https://vexralabs.com/insights/ai-for-accounting-practices) covers practice workflows, [AI software for financial advisers under Consumer Duty](https://vexralabs.com/insights/software-ai-advice-firms) covers FCA-regulated advice, and the [IAA Code of Standards 2024 guide](https://vexralabs.com/insights/iaa-compliance-guide) covers the rules AI-assisted immigration work must still meet.

[Our workflow audit](https://vexralabs.com/services) is the step before any build: £950, credited in full against a build agreed within 90 days. We map your systems and send a written plan, flagging questions for your compliance person. It is not a compliance review.

Track two numbers once AI is live: hours saved per week, and the share of AI outputs the reviewer changed. A change rate near zero with very fast approvals is the warning sign that review has become the “token gesture” the ICO’s draft guidance says does not count.

Not legal advice

This guide summarises UK GDPR, the Information Commission’s published guidance and the EU AI Act as at the date checked. The ICO’s DPIA and AI guidance is under review after the Data (Use and Access) Act 2025, and its automated decision-making guidance is a draft. For decisions about your own processing, take advice from a data protection specialist.

## Frequently asked questions

### Is there a UK AI Act?

No. The government chose five non-statutory principles applied by existing regulators, and no government AI Bill had been introduced by 14 September 2026. UK GDPR and sector rules apply to AI use instead.

### Is the ICO still the UK data protection regulator?

Since 30 September 2026 the Information Commission is the regulator; it took over the Information Commissioner's functions and powers. It still uses the initials ICO.

### Does the EU AI Act apply to a UK firm?

Only where the firm places AI on the EU market or the AI's output is used in the EU (Article 2). Purely UK work falls under UK GDPR and your regulator's rules.

### Who is responsible if AI makes a mistake?

Sector rules apply to the advice whatever tool produced it, so the firm and its professionals stay accountable. The FCA says its rules do not usually mandate or prohibit specific technologies.

### What is the first step?

Pick one document-heavy workflow, screen it for a DPIA, and add AI there with a named reviewer who signs off and a log.

## Sources

1. [DSIT, A pro-innovation approach to AI regulation: government response (paras 10, 16)](https://www.gov.uk/government/consultations/ai-regulation-a-pro-innovation-approach-policy-proposals/outcome/a-pro-innovation-approach-to-ai-regulation-government-response)
2. [Lewis Silkin, AI judgment day on the horizon while UK lawmakers play catch up (14 September 2026)](https://www.lewissilkin.com/insights/2026/09/14/ai-judgment-day-on-the-horizon-while-uk-lawmakers-play-catch-up)
3. [UK GDPR Article 22A, legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/22A)
4. [UK GDPR Article 22B, legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/22B)
5. [UK GDPR Article 22C, legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/22C)
6. [UK GDPR Article 22D, legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/22D)
7. [UK GDPR Article 5 (accountability), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/5)
8. [UK GDPR Article 13 (privacy information), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/13)
9. [UK GDPR Article 28 (processors), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/28)
10. [UK GDPR Article 35 (DPIA), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/35)
11. [Data (Use and Access) Act 2025, section 118, legislation.gov.uk](https://www.legislation.gov.uk/ukpga/2025/18/section/118)
12. [SI 2026/1015, DUAA Commencement No. 9 Regulations, legislation.gov.uk](https://www.legislation.gov.uk/uksi/2026/1015/made)
13. [SI 2026/425, Code of Practice on AI and Automated Decision-Making Regulations, legislation.gov.uk](https://www.legislation.gov.uk/uksi/2026/425/made)
14. [GOV.UK, Information Commission succeeds the ICO (30 September 2026)](https://www.gov.uk/government/news/information-commission-succeeds-the-ico-as-uks-data-protection-regulator)
15. [ICO, home page](https://ico.org.uk/)
16. [ICO, What does the UK GDPR say about ADM? (draft)](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/what-does-the-uk-gdpr-say-about-adm/)
17. [ICO, Consultation on draft guidance about automated decision-making](https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/2026/03/ico-consultation-on-the-draft-guidance-about-automated-decision-making-including-profiling/)
18. [ICO, When do we need to do a DPIA?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/when-do-we-need-to-do-a-dpia/)
19. [ICO, Guidance on AI and data protection](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/about-this-guidance/)
20. [FCA, AI Update (paras 3.2, 3.40)](https://www.fca.org.uk/publication/corporate/ai-update.pdf)
21. [ICAEW, Generative AI guide: ethics](https://www.icaew.com/technical/technology/artificial-intelligence/generative-ai-guide/ethics)
22. [IAA, Code of Standards 2024](https://assets.publishing.service.gov.uk/media/6776b2ef6c34906cc84c9499/IAA_Codes_of_Standards_2024.pdf)
23. [EU AI Act Article 2 (scope), AI Act Service Desk](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-2)
24. [EU AI Act Article 4 (AI literacy), AI Act Service Desk](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-4)
25. [EU AI Act Article 113 (application dates), AI Act Service Desk](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113)
