ICO’s Statutory AI Code of Practice: What UK CIOs Must Govern Now
The Data Protection Act 2018 (AI Code of Practice) Regulations 2026, which came into force on 12 May 2026, require the ICO to produce a statutory code governing AI and automated decision-making across all UK organisations.
What Are the AI Code of Practice Regulations 2026 — and Why Do They Matter Now?
The AI Code of Practice Regulations 2026 (SI 2026/425) place a statutory obligation on the Information Commissioner to prepare a code of practice on artificial intelligence and automated decision-making under section 124B of the Data Protection Act 2018. The ICO must consult the Secretary of State, the Human Rights Commission, and others before finalising it.
This is not advisory guidance. When published, the statutory code will carry weight in enforcement proceedings, regulatory investigations, and subject access disputes. Organisations that cannot demonstrate they have regard to the code will face harder questions from the ICO, from data subjects, and from their own boards.
The code will address both the development and use of AI, with a mandatory component covering automated decision-making affecting children. For enterprise CIOs, this means the governance gap must be closed before consultation drafts land — not after.
Executive Action:
- Register the ICO’s AI and Biometrics Strategy timeline in your governance calendar and appoint an AI legal lead to track consultation milestones.
- Audit which of your AI systems process personal data and flag any that make or substantially influence decisions affecting individuals.
- Commission a pre-code gap assessment now — remediating gaps after the code is finalised is more costly and more visible to regulators.
Why Are Most UK Enterprise AI Governance Frameworks Not Yet Fit for Purpose?
According to Logicalis’ 2026 UK CIO survey, only 31% of UK CIOs express high confidence in their current AI governance frameworks, and 96% identify AI-driven data leakage as a significant risk. A further finding from the same research shows just 29% of UK CIOs actively measure the environmental impact of their AI systems — a gap the forthcoming code is expected to address.
The problem is structural. Many organisations deployed AI tools reactively — through procurement channels, employee self-adoption, or vendor bundling — without integrating those systems into a coherent governance structure. The result is a proliferation of AI use cases that sit outside the CIO’s risk register, without a named owner, without data flow documentation, and without a process for reviewing automated outputs.
The ICO has made clear where it will ask hard questions: who owns AI use, where personal data flows, when automated decisions affect individuals, and what evidence supports meaningful human oversight. Organisations that cannot answer these questions before a complaint lands are operating with unquantified regulatory exposure.
Executive Action:
- Establish a central AI register covering all AI systems that process personal data, with ownership, risk classification, and data flow documented for each.
- Identify which AI systems make or assist automated decisions and assess whether current human review processes constitute meaningful oversight under UK GDPR Article 22.
- Brief the CISO and DPO on the intersection between AI governance and the UK GDPR accountability principle — the two frameworks are now inseparable.
What Must CIOs Build Before the ICO Finalises the Code?
The ICO’s 2026/27 AI work programme, confirmed on 29 May 2026, includes the statutory code, dedicated guidance on agentic AI, and consumer-facing support for people interacting with personalised AI products. CIOs should treat this as a multi-front governance build — not a single compliance exercise.
The governance architecture the ICO expects enterprises to demonstrate includes: a named AI risk owner at director level, an AI register with quarterly review, a vendor due diligence framework covering AI procurement, staff training on AI decision accountability, and a documented incident response procedure for AI failures involving personal data.
Agentic AI — systems that take autonomous actions on behalf of users — will attract specific ICO guidance. CIOs deploying agentic workflows now should treat existing UK GDPR accountability requirements as the floor, and begin building decision-trail documentation that will satisfy whatever the dedicated guidance prescribes.
Those building AI governance frameworks should also explore the AI governance assessment tools at INFORMD, which map enterprise AI controls against emerging UK regulatory expectations.
Executive Action:
- Appoint a named AI risk owner — ideally at CIO or Chief Data Officer level — with board-reported accountability for AI governance.
- Include AI vendor due diligence in every technology procurement process, covering data processing agreements, model transparency, and incident notification obligations.
- Build a decision-trail logging capability for all AI systems that affect individuals — this will be a central expectation of the forthcoming code.
How Should CIOs Brief the Board on AI Governance Risk Before the Code Lands?
The board’s role is to set risk appetite and approve the governance framework — not to manage AI systems. But the ICO’s statutory code elevates AI governance from a technical IT matter to a director accountability issue. The Companies Act 2006 duty to act in good faith and promote long-term success requires directors to understand material regulatory risks facing the company.
According to the ICO, human involvement in automated decisions must be meaningful — the reviewer must have the authority, discretion, and relevant information to change the outcome, not simply endorse it. This principle applies not just to automated customer decisions but to any AI output that shapes a significant business decision: credit allocation, hiring, performance management, or pricing.
CIOs should present the board with a quarterly AI governance dashboard covering the number and classification of AI systems in use, the status of human oversight mechanisms, open incidents, and progress against the pre-code governance build. The board should formally approve the AI risk appetite before the ICO consults on the code — taking a position after enforcement action is always more expensive.
Executive Action:
- Present the board with a concise AI governance briefing covering SI 2026/425, the forthcoming code timeline, and the organisation’s current exposure.
- Propose a formal board resolution approving the AI risk appetite, the governance framework, and the accountability structure before the ICO’s consultation period opens.
- Ensure board minutes reflect AI governance as a standing agenda item — this creates the audit trail regulators will look for.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.
The AI Code of Practice Regulations 2026 (SI 2026/425) came into force on 12 May 2026, requiring the ICO to draft the code. The ICO must consult on a draft before finalising — consultation is expected during 2026/27, with the final code likely arriving in 2027.
Yes. The code will apply to all organisations using AI that processes personal data under UK GDPR and the Data Protection Act 2018, covering both public and private sector entities regardless of size. The mandatory children’s data component applies wherever AI systems may be used by or affect under-18s.
An AI register is a centralised inventory of all AI systems used by an organisation that documents each system’s owner, data flows, risk classification, and human oversight mechanism. The ICO expects organisations to maintain one as part of the UK GDPR accountability framework.
The ICO can impose fines of up to £17.5 million or 4% of global annual turnover under UK GDPR. Failure to demonstrate regard to the statutory AI Code of Practice will be treated as aggravating evidence in enforcement decisions, increasing both the likelihood and size of fines.
