Automated decision making by AI agents – what does the law say?

05/10/26 – As agentic AI evolves from reactive reporting to proactive systems executing workflows, AI agents will be making business decisions of increasingly consequential importance. This is something that jobseekers are already familiar with – AI being used for the screening of CVs and now increasingly also for interviewing and shortlisting of job candidates.

What does the law say about using AI for these purposes?
Since 2018 the EU GDPR and the UK GDPR have prohibited organisations from using automated decision-making (ADM) about individuals if the decision is solely automated (i.e. without any human involvement) and results in legal or “similarly significant” effects on individuals, unless:
• the organisation has obtained the individual’s explicit consent or
• use of the ADM was necessary to perform a contract or
• the ADM was authorised by law
(UK GDPR, Art 22(1), now repealed).

In practice this meant that if an organisation wanted to use AI for, for example, shortlisting job applicants, approving/rejecting loan applications, or adjusting insurance premiums based on risk scoring, the organisation would in the vast majority of cases need to get individuals’ explicit, opt-in consent.

Earlier this year however the UK’s approach to ADM was comprehensively updated with the introduction of a new framework (UK GDPR, Arts 22(A) – 22(D), as introduced by Section 80 of the Data (Use and Access) Act 2025).

So what’s changed?
The most significant change is that there are now separate rules for ADM depending on whether the processing involves special category data or only ordinary personal data. (By way of reminder, special category data is “personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation” (UK GDPR, Art 9(1)); special category data does not include details of an individual’s income or financial circumstances.)

ADM with special category data
Where special category data is involved the previous ADM rules requiring individuals’ explicit consents still apply. Accordingly ADM used for activities such as employee absence monitoring (which involves health data) or biometric access controls remains prohibited, unless the individual has given explicit consent or the processing is necessary for contractual or legal reasons alongside substantial public interest grounds.

ADM with ordinary personal data only
Where no special category data is being processed the new framework allows organisations to use any lawful basis to process individuals’ personal data for ADM purposes. This means that an organisation which proposes, for example, to deploy AI agents to carry out employee performance reviews may no longer need to obtain their employees’ consents but instead use legitimate interests as the legal bases.

However this more permissive regime is subject to the organisation implementing and maintaining newly-introduced safeguards (Art 22(C) safeguards) which require the organisation to ensure that individuals are:
• Provided with specific information about the decision.
• Able to make representations on or contest decisions.
• Able to obtain human intervention in relation to decisions.

In practice this means that organisations which are transparent about their use of AI agents and employees’ right in relation to automated decisions can crack on with their agentic AI employee performance reviews, if they think that’s the right thing to do.  And for that matter, deploy AI agents to make decisions relating to promotions, disciplinary actions, redundancies and dismissals of employees.

This all sounds like a recipe for disaster. What does the ICO say?
Well first of all no longer the ICO.  On 30th September 2026 the Information Commissioner’s Office transitioned into the Information Commission. But to answer your question…

In March 2026 the ICO launched a public consultation on an update to its ADM guidance. Following some delays the final updated guidance is now scheduled to be published by the end of 2026.

Key areas which are expected to make the final version of the Information Commission’s ADM guidance:
• ADM decisions: More detailed analysis on what constitutes a decision for the purposes of the ADM rules. To fall within the ADM rules a decision must result in “a conclusion or outcome, reached after consideration or analysis” which may impact actions taken or engage a person’s rights (e.g. eligibility to rent a property), rather than just applying a rule already set by a human (e.g. whether a specific credit card may be accepted as payment).
• Significance: The Information Commission is likely to take a broader view of whether a decision has significance, having regard to impacts not only on finance, health or employment but also behaviour and choices. For example, the guidance now refers to automated recommendations that ‘nudge’ teenagers towards content that promotes unhealthy eating as potentially being a decision with a behavioural impact.
• Human involvement: To avoid falling within the ADM rules human involvement must be active and it must not be tokenistic. Ad hoc spot checking isn’t sufficient. Furthermore the relevant person must be “suitably trained and qualified to understand the system’s logic, outputs, limitations, and risks”, and the human involvement must come before the ADM decision is applied to a person.
• Art 22(C) safeguards: Individuals must be given information to allow them to “meaningfully understand the decision and the specific aspects of their case that influenced it”. This must be “decision-specific information about the actual outcome, rather than simply repeating information you provide in your privacy notice”.

In short we can expect the Information Commission to encourage and support the use of AI and ADM but at the same time take a robust approach to enforcing the requirements for human involvement and the Art 22(C) safeguards.  Whether that will be enough remains to be seen.

Receive email updates

Subscribe to updates on topics relevant to you. We won’t use your email address for any other purpose, and you can of course unsubscribe at any time.

Subscribe