ICO AI Code of Practice: What UK Boards Must Do in 2026
Regulations enacted on 12 May 2026 now require the Information Commissioner’s Office (ICO) to produce a statutory code of practice for AI and automated decision-making — creating a new layer of compliance accountability for every UK organisation deploying AI systems.
What Is the ICO AI Code of Practice and What Triggered It?
The Data (Use and Access) Act 2025 (DUAA) significantly expanded the ICO’s remit in relation to artificial intelligence. One of the most consequential provisions — now in force — is the requirement for the Secretary of State to enact regulations directing the ICO to prepare a code of practice specifically covering AI systems and automated decision-making. Those regulations came into force on 12 May 2026, formally triggering the ICO’s obligation to consult, draft, and publish this new code.
The code, once finalised, will sit alongside the UK GDPR and the ICO’s existing data protection guidance as a binding accountability framework for AI deployments. Organisations that fail to follow an ICO code of practice can face enforcement action — and crucially, failure to comply with a statutory code is likely to be treated as evidence of non-compliance in regulatory proceedings and litigation.
This is not a distant regulatory development. The ICO has been signalling its intent to move aggressively on AI accountability since 2023, and the DUAA has given it the statutory foundation and the explicit mandate to do so. According to the ICO’s own enforcement record, the regulator issued a £14.47 million fine to Reddit in February 2026 for failures in processing children’s personal data — a signal that ICO is prepared to levy significant penalties where data protection obligations are not met. Under the DUAA, the maximum fine ceiling has been raised to £17.5 million for breaches of the Privacy and Electronic Communications Regulations, and this appetite for enforcement is expected to extend to AI-related obligations.
Executive Action
- Instruct your Data Protection Officer (DPO) and legal team to monitor ICO consultation activity on the AI code of practice and engage in the consultation process when it opens.
- Begin an internal inventory of all AI and automated decision-making systems currently in use — this is a prerequisite for assessing compliance against any code.
- Ensure your board receives a briefing on the ICO’s AI code timeline and what it will mean for your organisation’s AI governance framework.
What Does Automated Decision-Making Accountability Mean for Boards?
Automated decision-making (ADM) — where AI or algorithmic systems make or materially influence decisions about individuals without meaningful human review — is already regulated under UK GDPR Article 22. The ICO’s new AI code is expected to significantly expand on these obligations, moving from a narrow prohibition on certain fully automated decisions to a broader framework of transparency, explainability, and human oversight requirements.
For boards, this matters because ADM is pervasive in modern enterprises in ways that are often not fully visible at board level. Credit scoring, HR recruitment screening, customer service triage, fraud detection, and pricing algorithms are all forms of automated or AI-assisted decision-making that may engage the new obligations. Many organisations have deployed these systems incrementally, without the governance infrastructure — data protection impact assessments, human review processes, explainability mechanisms — that the ICO’s code is likely to require.
The board’s role is not to approve each algorithm, but to ensure that an AI governance framework exists that covers the identification, assessment, and ongoing monitoring of ADM systems — and that accountability for compliance is clearly allocated at executive level. According to the ICO’s 2026 guidance framework, organisations should be able to demonstrate that AI decision-making is subject to human oversight, is explainable to affected individuals, and is reviewed periodically for bias and accuracy.
Executive Action
- Commission a cross-functional review of all AI and algorithmic systems that influence decisions about customers, employees, or other individuals — many will require DPIA updates or new assessments.
- Allocate named senior accountability for AI governance — whether a Chief AI Officer, DPO, or board-level sponsor — so that responsibility is clear before the code is published.
- Require your technology and data teams to demonstrate that human review mechanisms are built into high-risk ADM systems, and that outcomes can be explained to individuals on request.
How Does This Interact with Existing UK GDPR and Data Protection Obligations?
The ICO’s AI code of practice will not replace UK GDPR — it will supplement and interpret it. Under UK GDPR Article 22, individuals already have the right not to be subject to decisions based solely on automated processing that produces legal or similarly significant effects. The code is expected to give detailed regulatory interpretation of what “solely automated” means in the context of modern AI systems, what “meaningful human involvement” requires in practice, and what information organisations must provide when ADM is used.
The DUAA has also modified the UK GDPR’s provisions on automated decision-making, creating new rights and clarifying existing ones. In particular, the Act introduces a more explicit framework for transparency when AI systems are used in significant decisions — including the right to receive a meaningful explanation of the logic involved. For regulated sectors such as financial services, this intersects with FCA expectations on algorithmic accountability and the PRA’s requirements for model risk governance.
Organisations that have already invested in AI explainability, data lineage documentation, and robust DPIA processes will find the transition to the new code more manageable. Those that have not will face a more significant uplift — and boards should be asking their executive teams now whether current AI governance infrastructure is fit for the post-DUAA regulatory environment.
Executive Action
- Review your existing UK GDPR Article 22 compliance position and assess whether it covers the AI systems your organisation now operates — including those procured from third-party vendors.
- Ensure your privacy notices and data subject rights processes cover AI-assisted decisions and reflect the enhanced transparency obligations under the DUAA.
- For organisations in financial services, confirm that AI governance frameworks align with both ICO obligations and FCA/PRA model risk and algorithmic accountability expectations.
How Should Boards Prepare Before the Code Is Finalised?
The ICO’s AI code of practice will go through a formal consultation process before it is published in final form. This creates both a risk and an opportunity for boards. The risk is that organisations that wait for the final code before beginning to prepare will find themselves significantly behind — both competitively and in terms of regulatory readiness. The opportunity is that the consultation period allows organisations to shape the code and to begin building compliance infrastructure against draft requirements before they become mandatory.
Boards that act now should focus on three priorities. First, governance structure: ensure that AI accountability is clearly allocated within the executive team, with board visibility through regular reporting. Second, system mapping: build a comprehensive register of AI and ADM systems, including those embedded in enterprise software procured from vendors, which are often overlooked in internal assessments. Third, documentation readiness: ensure that for each significant AI system, there is a documented rationale, a DPIA (where required), explainability provisions, and a process for handling individual rights requests arising from automated decisions.
The INFORMD AI governance self-assessment and executive briefings library provide practical frameworks for boards building their AI compliance posture ahead of the ICO code. The INFORMD templates include AI governance board reporting checklists and DPIA frameworks relevant to the new regulatory environment.
Executive Action
- Build an AI system register before the ICO consultation opens — it will be the foundation of any compliance assessment against the code.
- Engage with the ICO’s consultation process when it opens to understand the code’s likely requirements and to provide input on proportionality for your sector.
- Treat the period before the code is finalised as a governance uplift window — not a reason to delay. Boards that begin now will be significantly better positioned when obligations become binding.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
Frequently Asked Questions
What is the ICO AI code of practice?
The ICO AI code of practice is a statutory code that the Information Commissioner’s Office is required to produce under regulations enacted on 12 May 2026 pursuant to the Data (Use and Access) Act 2025
