AI Governance Institute

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
EmergingPendingUKHigh riskLimited risk

Regulations Requiring the ICO to Produce a Statutory AI and Automated Decision-Making Code of Practice

Issued by

UK Government (Department for Science, Innovation and Technology)

liveICO-ADMCPVerified August 2026
Official document →

The UK Government has laid statutory regulations directing the Information Commissioner's Office to produce a binding code of practice governing AI systems and automated decision-making that process personal data. The code will apply to any organisation subject to UK data protection law that uses AI or automated systems to make or inform decisions affecting individuals. Once finalised, the code will carry statutory weight, meaning departure from its provisions can be used as evidence of non-compliance in regulatory proceedings.

Applies To

Large enterpriseSMBPublic sectorAI developerAI deployer

Overview

These regulations, laid before Parliament in August 2026, invoke powers under UK data protection legislation to mandate that the ICO draft a statutory code of practice specifically addressing AI and automated decision-making. The scope covers the use of personal data in AI systems, including profiling, solely automated decisions with legal or similarly significant effects, Data Protection Impact Assessments for high-risk AI processing, and records of processing activities. Organisations will be expected to demonstrate alignment with the code as part of their existing accountability obligations under the UK GDPR and the Data Protection Act 2018. The ICO will be required to consult publicly before finalising the code, and the resulting instrument will be subject to parliamentary approval. Enforcement will sit with the ICO, which retains existing powers to issue reprimands, enforcement notices, and fines of up to 17.5 million GBP or 4 percent of global annual turnover. The timeline for the final code has not yet been confirmed, but the laying of these regulations marks the formal start of the statutory process.

Key Requirements

  • Organisations using AI or automated decision-making that processes personal data must comply with the forthcoming ICO code once enacted, with non-compliance admissible as evidence in ICO enforcement actions.
  • Data Protection Impact Assessments must be conducted for AI processing activities that present high risk to individuals, with documented outcomes retained as evidence of accountability.
  • Records of processing activities must accurately reflect the use of AI systems and automated decision-making, including the logic involved and the significance of outcomes for data subjects.
  • Where solely automated decisions produce legal or similarly significant effects, organisations must implement internal review mechanisms allowing individuals to contest those decisions.
  • ICO fines for serious non-compliance with UK data protection law, which the code will sit within, can reach 17.5 million GBP or 4 percent of global annual turnover, whichever is higher.
  • Organisations will need to monitor the ICO's public consultation process and respond to draft code provisions before the instrument is finalised.

What Your Organization Must Do

  • Audit all AI systems and automated decision-making tools currently in operation to determine which involve personal data processing and could fall within the code's scope.
  • Review and update existing Data Protection Impact Assessments to ensure they specifically address AI-related risks, including model bias, opacity, and disproportionate impact on individuals.
  • Map all instances of solely automated decision-making across the organisation and verify that human review mechanisms are documented and accessible to affected individuals.
  • Update records of processing activities to include detailed entries for AI systems, capturing the nature of the logic used, data inputs, and the significance of outputs for data subjects.
  • Assign responsibility for monitoring the ICO's public consultation to a named individual in the privacy or compliance function, and prepare a formal response to the draft code.
  • Review contracts with AI vendors and data processors to ensure they include obligations that will support compliance with the forthcoming code, including audit rights and documentation requirements.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Does the ICO AI and automated decision-making code of practice apply to SMEs or only large organisations?
The code will apply to any organisation subject to UK data protection law that uses AI or automated systems processing personal data, regardless of size. SMEs are not exempt, though proportionality in how obligations are met may be addressed during the ICO's public consultation phase.
What is the deadline for complying with the ICO statutory AI code of practice?
No compliance deadline has been confirmed yet. The regulations were laid before Parliament in August 2026 to initiate the statutory drafting process, but the ICO must first consult publicly and obtain parliamentary approval before the final code takes effect.
Can ICO enforcement action be taken against organisations before the statutory AI code is finalised?
Enforcement under the code itself cannot proceed until the code is enacted, but existing UK GDPR and Data Protection Act 2018 obligations apply now. The ICO retains full powers to investigate and fine organisations for current AI-related data protection failures.
How do the ICO AI code penalties compare to EU AI Act fines?
ICO fines follow existing UK data protection thresholds, reaching up to 17.5 million GBP or 4 percent of global annual turnover. EU AI Act penalties for prohibited practices can reach 35 million euros or 7 percent of global turnover, making the EU regime more severe at the upper end.
What must organisations document about solely automated decisions to prepare for the ICO code?
Organisations should document the logic underpinning automated decisions, the data inputs used, the significance of outputs for affected individuals, and the human review mechanisms available to data subjects who wish to contest a decision. Records of processing activities must reflect all of this detail.
Should AI vendor contracts be updated in anticipation of the ICO automated decision-making code?
Yes. Compliance with the code will depend partly on what AI vendors provide, so contracts should be reviewed now to include audit rights, documentation obligations, and provisions requiring vendors to support DPIA processes. Waiting until the code is finalised may leave insufficient time to renegotiate agreements.