While the EU's transparency rules were making headlines, the UK took a much quieter step in a different direction. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 — SI 2026/425 — were made on 16 April 2026, laid before Parliament on 21 April, and came into force on 12 May. They do one thing: they require the Information Commissioner to prepare a statutory code of practice on AI.
Two routes to the same worry
The regulations are made under sections 124A(1) and (2) and 124B(11) of the Data Protection Act 2018 — powers inserted by the Data (Use and Access) Act 2025. That plumbing matters more than it looks. It means the UK is not creating a new AI regulator or a new category of regulated product. It is treating AI as a data-processing question and reaching for the machinery it already has.
What the code must cover
The Commissioner is directed to give guidance on good practice in the processing of personal data, under UK GDPR and the Data Protection Act 2018, in relation to two things: developing and using artificial intelligence, and automated decision-making. The regulations single out one topic for specific treatment — guidance on the processing of children's personal data must be included.
There is one carve-out worth knowing. The independent panel that assists with preparing the code must not consider or report on any aspect relating to national security.
The ICO has indicated the code will address transparency and explainability, bias and discrimination, and rights and redress. Notably, the regulations set no deadline for completion. With a panel review and the parliamentary laying process still to come, a code that actually takes effect in 2027 would be a reasonable expectation rather than a pessimistic one.
What this means if you deploy AI in the UK
The temptation is to read "no deadline, effective 2027" as "nothing to do." That would be a misreading, for two reasons.
First, a statutory code is not advisory in the way the ICO's existing AI guidance is. Once in force, it is the standard against which the regulator assesses whether processing was lawful and fair — and courts and tribunals must take it into account. Systems being designed now will be judged by it later.
Second, and more immediately: the underlying obligations already exist. Nothing in SI 2026/425 creates new duties. It creates guidance on duties that UK GDPR has imposed since 2018 — lawful basis, fairness, transparency, and the specific rights around solely automated decisions with legal or similarly significant effects. An organisation that is currently non-compliant does not become non-compliant when the code lands; it already is.
The pragmatic move is to treat the code's announced themes as a design checklist today. Can you explain, in a sentence a customer would accept, why your system reached a particular outcome? Do you know what happens when it is wrong, and is there a human who can overturn it? Do you know whether children are among the people it processes? Those questions do not need a code of practice to be worth answering — and organisations that can answer them will find the eventual code a formality rather than a project.
Related: The EU's AI transparency rules went live on 2 August · Call recording, consent and UK GDPR · What conversational AI actually does for a business