UK ICO Must Draft Statutory AI Code of Practice Affecting All AI Deployers
Any organization using AI or automated decision-making tools that affect individuals in the UK must begin mapping and documenting those systems now, because the ICO is legally required to issue a binding Code of Practice that will shape enforcement and litigation risk.
The UK Information Commissioner’s Office is now under a statutory duty to prepare a Code of Practice on AI and automated decision-making under the Data Protection Act 2018, following the Data (Use and Access) Act 2025 and related 2026 regulations. The Code will carry the same weight as the Children’s Code and Data Sharing Code, meaning courts and the ICO must take it into account in proceedings and enforcement. It applies to any controller using AI or automated systems to make decisions about people, including third-party tools, and covers organizations with no UK presence if they target or monitor UK individuals. The ICO has already signaled its expectations through draft ADM guidance, emphasizing meaningful human involvement and robust documentation. Businesses should audit AI use, update data protection impact assessments, review vendor contracts for AI-specific terms, and monitor for final guidance and the 2027 Code to reduce enforcement, litigation, and reputational exposure.