There is a line most people cross without noticing. An AI agent that drafts a reply for you to send is a tool. An AI agent that decides whether to accept a booking, what price to quote, or which applicant to reject is something else: it is taking a decision about a person, on its own.
UK law treats those two things very differently, and the rules for the second one were rewritten by the Data (Use and Access) Act 2025. They are in force now. The Information Commissioner’s Office confirmed in June that all of the Act’s data protection provisions have commenced.
Almost nobody building a small business automation has read them. Here is what they actually say.
What changed
Before the Act, Article 22 of the UK GDPR was close to a prohibition. You could not make a decision with a legal or similarly significant effect on someone using solely automated processing, except in three narrow cases: contract necessity, explicit consent, or authorisation by law.
Section 80 of the Act ↗ replaced that with Articles 22A to 22D. The prohibition is gone for ordinary personal data and a permission-plus-safeguards model has taken its place.
The ICO’s own summary of what the Act means for organisations ↗ describes the effect plainly. The Act “opens up the full range of reasons, or ‘lawful bases’, that you can rely on when you use people’s personal information to make significant automated decisions about them. So long as you continue to apply appropriate safeguards.”
That is genuinely a loosening. It is also a trap, because the safeguards are now the whole of your obligation, and they are more concrete than the old regime’s exceptions ever were.
Two questions decide whether this applies to you
Is it a significant decision?
Article 22A defines one as a decision that “produces a legal effect for the data subject, or … has a similarly significant effect for the data subject.”
“Similarly significant” is doing a lot of work there and the Act does not list examples. Credit, employment, insurance and access to a service are the standard cases. The ICO’s position is that context matters: the same decision can be significant for one person and trivial for another.
Is it based solely on automated processing?
This is the question that actually decides most cases, and the Act answers it in one sentence. Article 22A: “a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision.”
Then it adds a test that catches a lot of real systems: “When considering whether there is meaningful human involvement in the taking of a decision, a person must consider, among other things, the extent to which the decision is reached by means of profiling.”
Read that as the law anticipating the obvious dodge. Putting a human at the end of the process does not help if that human is rubber-stamping an output they cannot interrogate. Meaningful involvement means the person has real authority to go the other way, understands what the model did, and sometimes actually overrides it.
A review step that has never once reversed the agent’s decision is evidence about what that step is for.
The four safeguards
Where a significant decision is solely automated, Article 22C requires safeguards that include measures to:
- “provide the data subject with information about decisions … taken in relation to the data subject”
- “enable the data subject to make representations about such decisions”
- “enable the data subject to obtain human intervention on the part of the controller in relation to such decisions”
- “enable the data subject to contest such decisions”
Four things, and none of them is a policy document. They are features. Somebody has to be told a decision was made automatically, be able to argue about it, reach a human, and challenge the outcome.
If you are specifying an agent that declines, prices or ranks people, those four requirements belong in the brief, not in a compliance review afterwards. Retrofitting a contest-and-appeal path into a system that was built as a one-way pipe is expensive, and we have been asked to do it.
Special category data is still off limits
The loosening does not extend to Article 9 data: health, race, religion, sexual orientation, biometrics, trade union membership, political opinion.
Article 22B keeps the old position for those. A significant decision based entirely or partly on that kind of processing “may not be taken based solely on automated processing” unless explicit consent or a specific statutory exception applies. The ICO’s summary is blunt: the new flexibility “doesn’t apply to special category data which is more protected.”
This matters more than it sounds for small businesses, because special category data arrives by accident. A booking form with a free-text “anything we should know?” box collects health data the moment somebody types a condition into it. If an agent then reads that field and decides something, you are in Article 22B, not 22C.
Where the line actually falls
Across the agents we see small businesses building, the split looks roughly like this.
| What the agent does | Significant decision? | Likely position |
|---|---|---|
| Drafts a quote for you to approve and send | No, you decide | Out of scope, if your approval is real |
| Sets and sends a price automatically | Possibly | In scope, apply the safeguards |
| Books an appointment into a free slot | No | Out of scope |
| Declines a booking based on past no-shows | Yes | In scope |
| Screens job applicants and rejects some | Yes | In scope, and high risk |
| Decides payment terms or a credit limit | Yes | In scope |
| Routes an enquiry to the right inbox | No | Out of scope |
| Flags an account for suspension | Yes | In scope |
The two rows worth sitting with are “sets and sends a price automatically” and “declines a booking based on past no-shows”. Both get built constantly, by people who would be astonished to hear they were doing automated decision-making in the legal sense. Both are the kind of thing an agent is genuinely good at.
Neither is prohibited. Both need the four safeguards.
What to do about it
- List the decisions, not the features. Go through your automations and write down every point where an outcome lands on a person without a human choosing it. That list is usually longer than anyone expects.
- Check each one against the two questions. Significant effect, and solely automated. Most items fail one of them and drop out.
- For what is left, build the four things. Notice, representations, human intervention, contest. Features, not wording.
- Find the special category data. Free-text fields are where it hides. If an agent reads them, you have a harder problem than Article 22C.
- Make the human step real or stop pretending it exists. A reviewer with no authority and no visibility is worse than no reviewer, because it creates a record of a safeguard that was not one.
If you are at the stage of deciding what an agent should be allowed to touch at all, giving an AI agent access to business data safely covers the data side of the same question, and what an AI agent costs a small business covers what the build looks like. If you are earlier than that, AI agents for business is the starting point.
The short version
The old rule said you mostly could not let software make significant decisions about people. The new rule says you can, provided the person can find out, argue, reach a human and object.
That is a better law. It is also a bigger engineering obligation than the thing it replaced, and it lands on whoever specified the agent. If your automation decides something that matters about somebody, those four capabilities are part of the system, and the right time to discover that is before it is built.