If your board has already ticked "AI regulation" off the risk register because you mapped your exposure to the EU AI Act, you've covered maybe half the picture. A second, entirely UK-domestic regime is now moving through Parliament and unlike the EU Act, it applies whether or not a single one of your customers is in the EU.
On 12 May 2026, the government laid The Data Protection (Automated Decision-Making and Profiling) (Code of Practice) Regulations 2026 UKSI 2026/425 requiring the Information Commissioner's Office to produce the UK's first statutory code of practice on AI and automated decision-making. The ICO's consultation on the underlying draft guidance closed on 29 May, final guidance is expected this summer, and the statutory code itself is due to take effect in 2027.
For a board that has spent the last year focused on EU exposure and Shadow AI risk, this is the regulation most likely to catch mid-market UK operators off guard because it doesn't require an EU footprint to bite.
Where UKSI 2026/425 actually comes from
The code isn't a freestanding AI law. It's a mechanism inside the Data (Use and Access) Act 2025(DUAA), which rewrote the UK GDPR's rules on solely automated decision-making and gave the Secretary of State power to direct the ICO to write binding codes of practice. UKSI 2026/425 is that direction, specifically for AI and automated/partly-automated decisions and profiling.
The practical effect: this isn't the ICO offering advice. It's Parliament instructing the regulator to produce a code that, once in force, courts and the ICO itself must take into account when deciding whether an organisation has complied with data protection law with all the enforcement weight that implies.
How it's different from the EU AI Act
Boards that have already run an EU AI Act gap assessment sometimes assume it covers this too. It doesn't, for three reasons worth putting in front of your audit committee:\
- Trigger is different. The EU AI Act applies when your AI "touches" EU consumers or EU-regulated decisions. The ICO code applies to any UK organisation making automated or partly-automated decisions about people using their personal data a UK-only supply chain, workforce, or customer base is squarely in scope.
- Subject matter is narrower but sharper. Where the EU Act classifies systems by risk tier across many use cases, the ICO code is laser-focused on one thing: decisions about individuals, and whether a human is genuinely not nominally involved.
- Enforcement mechanism is different. This sits inside UK GDPR/data protection law, enforced by the ICO's existing powers (fines up to the higher of £17.5m or 4% of global turnover), not a new standalone regulator or penalty regime.\
Running an EU AI Act assessment and calling AI governance "done" is the gap this piece exists to close.
The three things the guidance already tells you to fix now
Even ahead of the final statutory code, the direction of travel from the draft ADM guidance is clear enough to act on:
- Genuine human involvement, not a rubber stamp. If your business uses AI to screen CVs, approve credit or trade terms, set dynamic pricing, or flag transactions for fraud, a human "reviewing" the AI's output in name only won't satisfy the code. The guidance is explicit that oversight has to be meaningful someone with the authority, time, and information to actually change the outcome.
- Children's data gets extra scrutiny. Where AI systems process data belonging to under-18s loyalty programmes, marketing personalisation, recruitment for under-18 hires the code layers additional obligations on top of the existing Children's Code.
- DPIAs have to be contemporaneous. Written before or during deployment, not reconstructed after a complaint or ICO inquiry lands. This is the one most mid-market AI programmes will fail today, because DPIAs are frequently treated as a paperwork step done retrospectively to satisfy a checklist.
If any of this sounds familiar, it's the same discipline we set out in our AI governance audit readiness guide this is now the specific UK legal hook that makes that audit non-optional.
A pre-2027 readiness checklist
You don't need to wait for the final statutory code to start closing gaps:
- Inventory every automated or partly-automated decision about a person hiring, pricing, credit, deductions, fraud flags, performance management not just your headline "AI initiatives." Our Shadow AI governance gap piece is a good starting template, since the same unofficial-tool blind spots apply here.
- Test human oversight for real, not on paper. Can the human reviewer actually override the system, and do they have the information to do it? If the honest answer is "they click approve," that's your top remediation item.
- Pull DPIAs forward. Any AI system already live without a contemporaneous DPIA needs one now, not after the code takes effect.
- Flag anything touching under-18 data for separate sign-off under the Children's Code overlay.
- Put ICO code readiness on the same board cadence as your EU AI Act tracking they're separate obligations with separate triggers, and treating them as one line item is how gaps get missed.
What to expect in 2027
The ICO has signalled it will publish updated "in brief" and public-facing guidance alongside the fuller code, but hasn't given a firm publication date beyond "this summer." What is fixed is the direction: UK mid-market businesses making automated decisions about employees, customers, or supply chain partners will have a binding compliance benchmark, not just best-practice guidance, by 2027.
The firms that treat this as a live compliance project now inventory, human oversight testing, DPIA discipline will be doing incremental work over the next twelve months. The firms that wait for the final code will be doing a scramble.
Sources: UKSI 2026/425, legislation.gov.uk · ICO consultation on draft ADM guidance · ICO: The Data (Use and Access) Act 2025 what it means for organisations
Related reading: Does the EU AI Act Apply to Your UK Business? · Shadow AI in UK Mid-Market CPG & Logistics: The Board-Level Breach Risk Before the 2027 Deadlines · AI Governance Audit Readiness · What Is an AI Check?
