# Human in the loop AI: UK GDPR Article 22A explained

> What human in the loop AI means under UK GDPR Articles 22A to 22D: meaningful human involvement, banned decisions, the four safeguards and fines.

Guide · Safe AI in regulated firms · By Syed Husnain Khalid · Published 6 October 2026 · Last checked 8 October 2026
Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.
Canonical: https://vexralabs.com/insights/human-in-the-loop-ai-uk-gdpr

Short answer

Human in the loop AI means a person reviews an AI output and decides before it takes effect. [UK GDPR Article 22A](https://www.legislation.gov.uk/eur/2016/679/article/22A), in force since 5 February 2026, treats a significant decision as solely automated when there is **no meaningful human involvement**. Solely automated significant decisions need the four Article 22C safeguards, and Article 22B bans some outright.

This guide is for UK accountancy practices, financial advice firms and immigration advisers that are adding AI to read documents and draft work. Articles 22A to 22D replaced Article 22 of the UK GDPR on 5 February 2026, and the regulator’s guidance on them is still a draft. We build review steps into software: Filyst, our case management product for immigration firms, rejects an approval from the person who did the work. The sections below define human in the loop AI, set out who the articles apply to, what meaningful human involvement means, which decisions are banned, the four safeguards, the maximum fine, and how to design and record a review step.

**Diagram: Human in the loop AI: the review step before a decision takes effect.** Five steps left to right: client data, rules that decide anything with a right answer, an AI draft with sources, a reviewer who can approve, edit or send back, and the decision, applied only after sign-off. A loop returns rejected drafts from the reviewer to the AI draft step. Every step writes to an audit log of who, when and what changed. A meaningful reviewer acts before the decision is applied, has the authority to change it, and is trained to understand the system.

*The reviewer acts before the decision is applied and has the authority to change it. The log records how the person was involved.*

## What is human in the loop AI?

Human in the loop AI is a way of building a system so that a person reviews what the AI produces and takes the decision before anything happens to the individual concerned. It is sometimes called human oversight or human review.

The UK GDPR does not use the phrase. Its legal test is **meaningful human involvement**: [Article 22A(1)(a)](https://www.legislation.gov.uk/eur/2016/679/article/22A)says a decision is “based solely on automated processing if there is no meaningful human involvement in the taking of the decision”. A human in the loop only changes a firm’s legal position when the involvement meets that test.

## Who do Articles 22A to 22D apply to?

Articles 22A to 22D apply to a controller, the organisation that decides why and how personal data is used, when a significant decision about a person is taken by it or on its behalf, is based entirely or partly on personal data, and is based solely on automated processing ([Article 22C(1)](https://www.legislation.gov.uk/eur/2016/679/article/22C)).

A **significant decision**is one that produces a legal effect for the person or has a similarly significant effect for them (Article 22A(1)(b)). The regulator’s [draft guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/what-does-the-uk-gdpr-say-about-adm/) gives approving or refusing a visa, determining tax liabilities due and automatically refusing an online credit application as examples. The same draft says the rules apply only when three factors are present:

1. a system is making a decision about a person;
2. the decision is a significant decision; and
3. the decision is solely automated.

The regulator is the Information Commission. It took over the functions of the Information Commissioner on 30 September 2026 under the [Data (Use and Access) Act 2025 (Commencement No. 9) Regulations 2026](https://www.legislation.gov.uk/uksi/2026/1015/made), and the organisation’s [own announcement of the change](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/09/ico-welcomes-transition-to-new-information-commission-and-marks-new-chapter-with-manchester-head-office-opening/) still uses the name ICO.

## What changed in UK GDPR on 5 February 2026?

[Section 80 of the Data (Use and Access) Act 2025](https://www.legislation.gov.uk/ukpga/2025/18/section/80) substituted four new articles, 22A to 22D, for Article 22 of the UK GDPR, fully in force from 5 February 2026.

The old Article 22 gave a person the right not to be subject to a solely automated decision with legal or similarly significant effects, with exceptions. The new articles allow such decisions, subject to two restrictions in Article 22B and the safeguards in Article 22C. The old rules still apply to decisions taken before 5 February 2026 ([S.I. 2026/82, regulation 5](https://www.legislation.gov.uk/uksi/2026/82/regulation/5)).

| Article | What it does |
| --- | --- |
| 22A | Defines the terms. A decision is “based solely on automated processing” if there is no meaningful human involvement in taking it. A “significant decision” produces a legal effect or a similarly significant effect for the person. |
| 22B | Restricts solely automated significant decisions based entirely or partly on special category data (Article 9(1)) to two conditions. Bans any solely automated significant decision where the processing relies, entirely or partly, on recognised legitimate interests (Article 6(1)(ea)). |
| 22C | Requires the controller to have safeguards in place for solely automated significant decisions: information, representations, human intervention and the ability to contest. |
| 22D | Lets the Secretary of State make regulations on what counts as meaningful human involvement, what counts as a similarly significant effect, and further safeguards. |

## What counts as meaningful human involvement?

The UK GDPR does not define meaningful human involvement. Article 22A(2) gives one factor: a person considering the question must consider, among other things, the extent to which the decision is reached by means of profiling, the automated evaluation of personal aspects such as someone’s economic situation, health or behaviour.

The detail comes from the regulator’s [guidance on automated decision-making](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/), which is a **draft**. The ICO updated it on 31 March 2026 and [consulted on it until 29 May 2026](https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/2026/03/ico-consultation-on-the-draft-guidance-about-automated-decision-making-including-profiling/). On 8 October 2026 the page still describes it as draft guidance that will be finalised after the consultation. The draft says involvement must be “active and not just a token gesture”, and that a human should:

- assess and review the decision at an appropriate point to ensure actual impact on the outcome;
- have the ability to influence the outcome;
- have discretion and authority to alter the decision;
- be suitably trained and qualified to understand the system’s logic, outputs, limitations and risks; and
- take into account the relevant data and factors on which the decision was based.

The draft calls these criteria non-exhaustive and says the human should apply them every time a decision is made about a person. It adds two limits. Ad hoc spot-checking is not sufficient. A person who only designed or built the system, or who only inputs the data for it to process, is not meaningfully involved.

Approving is not the same as reviewing

The draft guidance says involvement must be active, not a token gesture, and applied to every decision. A reviewer who approves each AI output unchanged without reading it does not meet that description, whatever the process document says. This is our reading of the draft, not a test the regulator has published.

## When are solely automated decisions banned?

[Article 22B](https://www.legislation.gov.uk/eur/2016/679/article/22B) bans a solely automated significant decision in two cases: where it uses special category data without meeting one of two conditions, and where the processing relies on recognised legitimate interests.

**Special category data.** Article 9(1) lists the special categories: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person, and data concerning health, sex life or sexual orientation. A significant decision based entirely or partly on that data may be solely automated only if one of two conditions is met:

1. the decision is based entirely on processing of personal data to which the person has given explicit consent (Article 22B(2)); or
2. the decision is necessary for entering into or performing a contract between the person and a controller, or is required or authorised by law, **and in either case** Article 9(2)(g) (substantial public interest) applies (Article 22B(3)).

The [draft guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/when-can-we-use-special-category-data-in-our-adm/) says these rules apply even where a small amount of special category data is used, including data that is inferred.

**Recognised legitimate interests.** Article 6(1)(ea) is a lawful basis for processing that is necessary for a recognised legitimate interest, meaning one that meets a condition in Annex 1 of the UK GDPR. Article 22B(4) bans any solely automated significant decision where the processing for it relies entirely or partly on that basis. This ban covers all personal data, not only the special categories.

Immigration files and health-related financial advice hold special category data, so a human decision-maker who meets the Article 22A test keeps those decisions outside Article 22B.

## What safeguards does Article 22C require?

[Article 22C](https://www.legislation.gov.uk/eur/2016/679/article/22C) says the controller must ensure safeguards are in place for every solely automated significant decision. The safeguards must consist of or include measures which:

1. provide the person with information about the decisions taken in relation to them;
2. enable the person to make representations about those decisions;
3. enable the person to obtain human intervention on the part of the controller; and
4. enable the person to contest those decisions.

These four are a minimum: Article 22C also requires compliance with any regulations made under [Article 22D(3)](https://www.legislation.gov.uk/eur/2016/679/article/22D). The [draft guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/what-are-the-adm-safeguards/) says a controller must act on a request under the safeguards without undue delay and at the latest within one month of receipt, with an extension of two further months for complex or multiple requests.

Human intervention is different from human involvement. Human involvement happens while the decision is being taken, and decides whether Articles 22B and 22C apply at all. Human intervention is the safeguard a person asks for after a solely automated significant decision has been made about them.

## What is the penalty for breaching Article 22B or 22C?

An infringement of Article 22B or 22C falls in the higher tier of UK GDPR fines: up to **£17,500,000 or, for an undertaking, 4% of total worldwide annual turnover** of the preceding financial year, whichever is higher ([Article 83(5)(ba)](https://www.legislation.gov.uk/eur/2016/679/article/83)). That is the maximum, not a tariff.

## How do you design a review step that holds up?

A review step holds up when the software enforces it: the reviewer sees the inputs, has the permission to change the output, acts before anything is applied, and leaves a record. This table is the design we use when we build AI workflows. It is our design, not a list from the regulator.

| Principle | What it looks like in the software |
| --- | --- |
| Rules decide what has a right answer | Totals, thresholds and deadlines are calculated, not generated. The model never decides eligibility on its own. |
| AI reads and drafts | Extraction, classification and first drafts, each shown with the source it came from. |
| The reviewer sees everything | Inputs, the AI output and the reasons, side by side, with the fields that need judgement highlighted. |
| The reviewer can change it | Edit, reject or send back are as easy as approve. No “approve all” button. |
| The reviewer is trained and authorised | Only named roles can approve, and nobody can approve their own work. |
| Review comes first | Nothing is sent, posted or applied until a person has signed off. |
| Everything is logged | Who reviewed, when, what changed and why. |
| The review itself is monitored | How often outputs are approved unchanged, and how quickly, is reported to the person responsible for the process. |

We learnt the fifth row building Filyst. A case in Filyst cannot move to its next stage on the approval of the person who did the work: the server rejects self-approval, and the check is on by default for every stage. A rule that lives only in a policy document is skipped on a busy day. A rule in the software is not.

The target system sets where the review step sits. Xero’s [Accounting API specification](https://github.com/XeroAPI/Xero-OpenAPI/blob/master/xero_accounting.yaml) gives invoices, bills and manual journals a draft status, so AI-prepared entries of those kinds can wait in Xero for a person to approve. Bank transactions have no draft status, so their approval step has to sit in the integration, before anything is sent. Our [Xero API integration guide](https://vexralabs.com/insights/xero-api-integration-accounting-practices) covers the access, pricing and limits that such an integration works within.

Human review is one of several duties that apply when a regulated firm uses AI. Our pillar guide, [AI in regulated industries: UK rules and human review](https://vexralabs.com/insights/ai-in-regulated-firms), places Article 22A alongside the sector regulators’ rules, and [our services](https://vexralabs.com/services) page sets out how we build software with AI that a person signs off.

## What records should you keep?

The draft guidance says you should keep a record of how the human was involved in each decision. A firm that relies on human review to stay outside Articles 22B and 22C needs that record as its evidence. We would keep:

- a short description of each AI step: what it does, what data it uses and who reviews its output;
- an entry per decision: the AI output, the reviewer, the time and any changes;
- a list of who may approve what, and the training each reviewer has had;
- a note of how a client can ask for a human review or contest an outcome, and what happened when one did; and
- for any solely automated significant decision: the lawful basis, the Article 22B condition where special category data is used, and how the four Article 22C safeguards are delivered.

The per-decision entry is an AI audit trail, and [AI audit trail for UK regulated firms: what to log](https://vexralabs.com/insights/ai-audit-trail) lists its fields. The [draft guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/what-else-do-we-need-to-consider/) also says you must carry out a data protection impact assessment (DPIA) for systematic and extensive automated decision-making, and should do one for any solely automated significant decision. [DPIA for AI tools: when a UK firm needs one](https://vexralabs.com/insights/dpia-for-ai-tools) explains that assessment.

Not legal advice

This guide explains the law as published on legislation.gov.uk and the regulator’s draft guidance as at the date checked. Draft guidance can change when it is finalised. For a decision about your own processing, take advice from a data protection specialist.

## Frequently asked questions

### Is Article 22 of the UK GDPR still in force?

No. Section 80 of the Data (Use and Access) Act 2025 substituted Articles 22A to 22D for it, fully in force from 5 February 2026. The old Article 22 still applies to decisions taken before that date.

### Does clicking “approve” count as meaningful human involvement?

Not on its own. The regulator's draft guidance says involvement must be active and not just a token gesture. The reviewer should have the discretion and authority to alter the decision, be suitably trained, and review at a point where they can still affect the outcome.

### What is the difference between human involvement and human intervention?

Human involvement happens while a decision is being taken and determines whether it is solely automated. Human intervention is an Article 22C safeguard: a review the person can ask for after a solely automated significant decision has been made about them.

### Do we need consent to use AI on client files?

Articles 22A to 22D do not require consent for AI-assisted work that a person reviews. Explicit consent is one of two conditions for a solely automated significant decision based on special category data (Article 22B). Your other UK GDPR duties, including a lawful basis, still apply.

### Is the ICO now the Information Commission?

Yes. The Information Commission took over the Information Commissioner's functions on 30 September 2026. The organisation's own announcement still uses the name ICO.

## Sources

1. [UK GDPR Article 22A, legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/22A)
2. [UK GDPR Article 22B, legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/22B)
3. [UK GDPR Article 22C, legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/22C)
4. [UK GDPR Article 22D, legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/22D)
5. [UK GDPR Article 83(5)(ba), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/83)
6. [Data (Use and Access) Act 2025, section 80, legislation.gov.uk](https://www.legislation.gov.uk/ukpga/2025/18/section/80)
7. [S.I. 2026/82, regulation 5 (saving for earlier decisions), legislation.gov.uk](https://www.legislation.gov.uk/uksi/2026/82/regulation/5)
8. [ICO, Automated decision-making, including profiling (draft guidance, updated 31 March 2026)](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/)
9. [ICO draft guidance, What does the UK GDPR say about ADM?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/what-does-the-uk-gdpr-say-about-adm/)
10. [ICO draft guidance, When can we use special category data in our ADM?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/when-can-we-use-special-category-data-in-our-adm/)
11. [ICO draft guidance, What are the ADM safeguards?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/what-are-the-adm-safeguards/)
12. [ICO draft guidance, What else do we need to consider? (DPIAs)](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making/what-else-do-we-need-to-consider/)
13. [ICO, consultation on the draft ADM guidance (31 March to 29 May 2026)](https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/2026/03/ico-consultation-on-the-draft-guidance-about-automated-decision-making-including-profiling/)
14. [ICO, transition to the Information Commission, 30 September 2026](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/09/ico-welcomes-transition-to-new-information-commission-and-marks-new-chapter-with-manchester-head-office-opening/)
15. [S.I. 2026/1015, Data (Use and Access) Act 2025 (Commencement No. 9) Regulations 2026](https://www.legislation.gov.uk/uksi/2026/1015/made)
16. [Xero, Accounting API OpenAPI specification (status codes)](https://github.com/XeroAPI/Xero-OpenAPI/blob/master/xero_accounting.yaml)
