Article 22 and Automated Decisions: What HR, Credit and Insurance Firms Need to Know
If your business uses AI to screen CVs, score credit applications, price insurance, or make any other significantly-automated decision about a person, the reformed Article 22 rules, now Articles 22A to 22D of UK GDPR, are the rulebook that already applies to you under UK law. This is the field guide to automated decisions under the new regime.
What changed on 5 February 2026
Section 80 of the Data (Use and Access) Act 2025 (DUAA) substituted four new articles, 22A to 22D, for Article 22 of UK GDPR. The change commenced on 5 February 2026, under the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82).
Be clear about the direction of travel, because it's the opposite of what most summaries assume: the reform opened the gateway, it didn't close it. Before 5 February 2026, a solely automated decision with a legal or similarly significant effect was prohibited by default, subject to three narrow exceptions. Under Article 22B, that decision is now permitted on any lawful basis for ordinary personal data. The prohibition survives only where the processing involves special category data, or relies on the new Article 6(1)(ea) "recognised legitimate interests" basis, where the older, narrower exceptions still apply.
The protection people had hasn't disappeared. It has relocated. Article 22C now sets out the safeguards a controller must have in place whenever it makes a qualifying automated decision, on any lawful basis, not just when one of the old exceptions applied. That's the part of the reform that actually does the work, and it's testable: an ICO investigation, an employment tribunal or a credit dispute will ask you to demonstrate the 22C safeguards, not to justify which of the old exceptions you relied on.
These rules apply whether or not the EU AI Act applies to you, and they're enforced by the Information Commissioner's Office, which has the power to issue fines, enforcement notices and reputational findings. The ICO consulted on draft guidance on automated decision-making and profiling during 2026, with a particular focus on AI in recruitment; that guidance had not been finalised against the reformed regime at the time of writing. Building your safeguards now, against the statutory text, is cheaper than retrofitting them once that guidance lands. Knowing where to start is the first step: our AI compliance consulting work maps your Article 22 and broader AI obligations before any audit engagement begins.
When do Articles 22A to 22D apply?
Article 22A sets the gateway test. Three conditions need to be met:
- A decision is being made about a person. Not a generic output, but a decision that affects someone specifically.
- The decision is based solely on automated processing, with no meaningful human involvement. Article 22A requires you to weigh, among other things, the extent to which the decision was reached by profiling when judging this, and in ICO and tribunal practice a human nominally "in the loop" doesn't take the decision outside this test if they always rubber-stamp the algorithm's output.
- The decision has a legal or "similarly significant" effect. Being denied credit, missed for a job interview, charged a higher insurance premium, refused a service, or denied a benefit: all qualify.
If all three are true, you're squarely inside the Article 22 regime, and, since 5 February 2026, that no longer means the decision is off-limits. It means Article 22B governs which lawful basis you need, and Article 22C's safeguards are mandatory.
"If your ATS auto-ranks CVs or your recruiters use generative AI to shortlist, you're inside Article 22 and the Equality Act. The EU AI Act stacks on top if you hire across borders."
The four highest-risk use cases we see
1. AI-assisted CV screening and candidate ranking. Applicant tracking systems that auto-score, auto-rank or auto-reject candidates are textbook Article 22. So is using a generative AI tool to summarise CVs into a yes/no shortlist. The Equality Act also bites here: if your model disadvantages a protected characteristic, the unintended-bias defence is weaker than people imagine.
2. Automated credit decisions. Consumer credit, BNPL, business lending, mortgage pre-qualification. These have always been Article 22 country. Since 5 February 2026 a solely automated credit decision no longer needs to fit one of the old narrow exceptions, but it does need an Article 22B lawful basis and the full set of Article 22C safeguards, plus clear information rights for the applicant. The PRA also has views on model risk in lending (see SS1/23, its supervisory statement on model risk management for banks). If you operate cross-border, the EU AI Act explicitly classifies credit scoring as high-risk.
3. Insurance underwriting and pricing. Solely-automated risk assessment, automated quote generation, dynamic premium adjustment: all in scope. Add the Equality Act for any factor that proxies for a protected characteristic, plus your PRA expectations on model risk.
4. Dynamic and personalised pricing. If you're an online retailer adjusting prices based on profile signals, you're probably inside Article 22 (the "similarly significant effect" threshold is lower than people think), and the CMA has already set out its concerns: its 2021 paper on algorithms names personalised pricing as a specific consumer harm it watches for.
Your lawful basis under Article 22B
This is the part of the old advice that has changed the most, and it's the part most worth getting right. Under Article 22B:
- Ordinary personal data: a qualifying solely automated decision is permitted on any Article 6 lawful basis, not just contract necessity, consent or specific legal authorisation. If you already process the data lawfully under, say, legitimate interests, you don't need to re-engineer your basis just to automate the decision.
- Special category data (health, ethnicity, religion, sexual orientation, trade union membership, biometric data used for identification, and similar): the old, narrower gateway still applies. The decision is only permitted where it's necessary for a contract (with suitable safeguards), based on the person's explicit consent, or authorised by law (again, with suitable safeguards).
- Processing under Article 6(1)(ea), the DUAA's new "recognised legitimate interests" basis: the same narrower gateway applies as for special category data. You can't use recognised legitimate interests as your basis for an automated decision, then rely on the wider Article 22B permission.
In practice: work out whether your automated decision touches special category data or relies on recognised legitimate interests first. If neither applies, the lawful-basis question is largely solved by whatever basis you already use for the underlying processing. If either applies, you're back on the pre-reform track: contract necessity, explicit consent, or specific legal authorisation, and nothing else.
The Article 22C safeguards: what you owe the person
Getting a lawful basis under Article 22B is the easy half. Article 22C is where the actual obligation sits, and it applies to every qualifying automated decision, regardless of which lawful basis permits it. You need to be able to demonstrate, on demand and to the ICO, that you provide:
- Information about the decision. As soon as reasonably practicable after the decision is made, the person must be told that a qualifying solely automated decision has been taken about them, and given information about that decision that is clear and accessible enough for them to exercise their rights to contest it and to obtain human intervention.
- The right to make representations. The person must be able to put their point of view to the controller before it's treated as final, in a way that could actually change the outcome.
- The right to obtain meaningful human intervention. Not a formality: the reviewer needs the information to assess the case, the authority to overturn the automated output, and to actually exercise that authority when the case warrants it.
- The right to contest the decision. A real route to challenge the outcome, separate from and in addition to the right to human intervention.
Article 22D gives the Secretary of State the power to make regulations that add to what counts as a "significant effect" decision, clarify when a decision is or isn't "based solely" on automated processing, and vary the 22C safeguards themselves. None of that has been exercised yet, but it's the mechanism to watch: it means the safeguards list can be tightened by secondary legislation without a fresh Act of Parliament.
Two things sit alongside, not inside, Article 22C, and firms still need both: a DPIA documenting the risk assessment and your safeguards, mandatory under Article 35 for this kind of high-risk processing, and Equality Act due diligence, evidence that you've tested the model for disparate impact across protected characteristics.
What "meaningful human involvement" actually means
Article 22A codifies this test in the statute itself: a decision is "based solely on automated processing" wherever there is no meaningful human involvement in taking it. The single most common compliance failure we see is the "rubber stamp" pattern: an algorithm produces a recommendation, a human ticks a box, and the firm claims the decision wasn't solely automated. ICO and the courts have been clear: that doesn't count. In ICO and tribunal practice, human involvement is only treated as meaningful if the reviewer (a) has the information needed to overrule the algorithm, (b) has the authority to do so, and (c) actually does sometimes override the output. If your reviewers approve the model's recommendation 99.8% of the time, you're effectively running an automated process, and Article 22A treats it as one.
"The 'rubber stamp' defence (a human ticks a box on the algorithm's recommendation) doesn't work. Meaningful human involvement means the reviewer has the information, the authority, and the practice of overriding the model when it's wrong."
The Equality Act overlay
Articles 22A to 22D protect individuals' procedural rights: a lawful basis, information, representations, human intervention, contestability. The Equality Act protects them from discrimination. Both apply, simultaneously, to AI-driven decisions about people, and the wider Article 22B gateway makes this overlay more important, not less: a decision that's now permitted under UK GDPR can still be unlawful under the Equality Act. A model can be fully compliant with the Article 22C safeguards and still produce unlawfully discriminatory outcomes. In fact, that's the more common failure pattern.
If your model uses any feature that correlates with a protected characteristic (postcode for race, employment-gap features for sex via maternity, voice patterns for disability), you need evidence that you've tested for disparate impact and either eliminated it or have an objective justification. "We didn't know it was biased" is not a defence.
The EU AI Act overlay (for the firms it applies to)
If you screen EU candidates, lend to EU consumers, insure EU policyholders, or operate AI procured from EU vendors, the EU AI Act stacks on top. It explicitly classifies recruitment, credit scoring and employment-decision AI as high-risk, with its own documentation, oversight and registration obligations. Our EU AI Act Rapid Audit covers this for cross-border firms.
What our Article 22 Audit covers
Our Automated Decision-Making Audit is a focused, 2–3 week engagement designed for HR, credit, insurance and pricing teams. We inventory every solely or significantly automated decision your AI makes about a person, assess your safeguards against ICO expectations, stress-test for Equality Act exposure across protected characteristics, and deliver DPIA-aligned documentation plus a contestability process you can actually operate.
If you'd rather start lighter, take the free Scorecard. The questions on automated decisions will surface whether you have Article 22 exposure within minutes.