No UK AI Act — so what actually binds you? The DUAA, explained
Data (Use and Access) Act 2025 (c. 18)
- Issued by
- UK Parliament (legislation.gov.uk)
- Published
- 19 June 2025 (Royal Assent)
- Updated
- 5 February 2026 (main provisions in force)
- We reviewed
- 17 July 2026
The UK has no AI Act — but the Data (Use and Access) Act 2025 changes the data protection rules that govern AI use. Royal Assent came on 19 June 2025; the main data-protection provisions, including the automated decision-making changes (section 80), commenced on 5 February 2026, and the mandatory data-subject complaints procedure follows on 19 June 2026. The ADM reform expands when organisations can make significant automated decisions, in exchange for safeguards. For firms using AI on personal data, the compliance frame is DUAA-amended UK GDPR — not a hypothetical AI law.
What the guidance says
“This section expands the circumstances in which an organisation can make significant decisions based solely on its automated processing of personal information”
“a decision is based solely on automated processing if there is no meaningful human involvement in taking it”
Commencement is staged: main data-protection provisions and the ADM changes (s.80, Sch.6) in force 5 February 2026; the data-subject complaints procedure requirement (s.103, Sch.10) from 19 June 2026.
The Act paves the way for the ICO’s statutory code of practice on AI and automated decision-making.
What this means for your firm
- When someone says "there’s no AI regulation in the UK", the accurate answer is: the DUAA-amended UK GDPR regime is the AI regulation for personal data, and its provisions are in force now.
- The meaningful-human-involvement test makes documentation of AI workflows matter — you need to be able to show where humans sit in the loop.
- From June 2026, firms need a proper complaints procedure for data subjects — AI-related complaints will arrive through it.
- The safest way to keep AI workflows out of the hardest ADM questions is to keep personal identifiers out of the automated processing in the first place.
Guidance → control, line by line
How each expectation maps to a NeutralAI control. The full cross-regulator table lives on the UK guidance map.
Lawful processing under DUAA-amended UK GDPR
Removing identifiers before AI processing reduces the personal-data footprint of the workflow — the strongest form of data minimisation.
Evidence for the meaningful-human-involvement test
Logged masking and routing events document how the AI step fits into the wider workflow, supporting the human-involvement narrative.
Answering data-subject complaints (from June 2026)
Exportable, signed summaries of what was masked and when give a concrete artefact for complaint responses and ICO correspondence.
Common questions
Is the DUAA fully in force?
No — commencement is staged. The main data-protection provisions, including the ADM changes, commenced on 5 February 2026 (Commencement No. 6 Regulations, SI 2026/82). The mandatory complaints-procedure requirement follows on 19 June 2026. Say "main provisions in force", not "fully in force".
Does the DUAA replace UK GDPR?
No. It amends UK GDPR and the Data Protection Act 2018. Your existing data protection obligations continue, with modified rules in areas like automated decision-making, recognised legitimate interests, and complaints handling.
What should a firm using AI do about the ADM changes?
Map where AI makes or shapes significant decisions about individuals, document where meaningful human involvement sits, and reduce the personal data entering those workflows. If identifiers are masked before processing, many workflows simply carry less ADM exposure.
This page summarises third-party guidance for convenience and is not legal advice. Summaries can go stale — always read the original at the source link above before relying on it. Last reviewed: 17 July 2026.
See what this control looks like in practice
The AI Confidentiality Checklist walks through usage discovery, exposure, policy, controls, and evidence in about 20 minutes — or bring one low-risk workflow to a live review.
The control
detect → mask → send → restore → audit
Reversible vault, 15-minute TTL. The model only ever sees placeholders.