Written and maintained by CASRAI Editorial Board
Last updated
Short answer: The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 — UK Statutory Instrument 2026 No. 425 — is a short, mechanical instrument. It does not itself write AI rules; it legally directs the Information Commissioner to produce a statutory code of practice covering AI development/use and automated decision-making, tells the Commissioner the code must specifically address children’s personal data, and amends the advisory-panel process so the panel reviewing the code cannot consider or report on anything relating to national security. This is regulatory background material, dated to when the instrument was made and came into force — 16 April 2026 (made), 21 April 2026 (laid before Parliament), and 12 May 2026 (in force) — not a current-week development. CASRAI’s own NIKOLAI project, an independent, unendorsed reference dictionary of frontier-AI-safety elements, maps a closely related set of documentation and review obligations in its N8 track; the connection is laid out below.
What SI 2026/425 Actually Is
SI 2026/425’s full title is The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026. It was made by the Secretary of State on 16 April 2026, laid before Parliament on 21 April 2026, and came into force on 12 May 2026 (21 days after laying, per its own regulation 1) — extending to England, Wales, Scotland, and Northern Ireland. The full text is published at legislation.gov.uk/uksi/2026/425, verified directly against the instrument’s own introductory text and regulations for this guide.
The instrument is short: three regulations plus an explanatory note. It exists because the Data (Use and Access) Act 2025 inserted two new sections into the Data Protection Act 2018 — section 124A (the Secretary of State’s power to direct the Commissioner to prepare a code of practice) and section 124B (the advisory-panel mechanism that reviews a draft code) — and SI 2026/425 is the Secretary of State exercising that new section 124A power for the first time on AI and automated decision-making specifically, citing sections 124A(1) and (2) and 124B(11) of the 2018 Act as its enabling powers, after consulting the Commissioner as section 182(2) of the Act requires.
What It Requires, Regulation by Regulation
Regulation 1 is citation, commencement, extent, and interpretation — the 21-day-after-laying commencement and UK-wide extent noted above. The two regulations that actually do something:
- Regulation 2 — directs the code’s scope. It requires the Information Commissioner to prepare a code of practice giving guidance on good practice in processing personal data in connection with (a) developing and using artificial intelligence, and (b) automated decision-making. It explicitly requires the code to address the processing of children’s personal data as part of that guidance. “Automated decision-making” here is defined by cross-reference to UK GDPR Article 22C(1) and Data Protection Act 2018 section 50C(1) — the provisions covering decisions made solely by automated processing that produce a “significant decision” about a data subject.
- Regulation 3 — carves national security out of the panel’s review. It amends section 124B of the 2018 Act to add that the advisory panel reviewing the draft code “must not consider or report on any aspect of the code relating to national security.” Section 124B otherwise requires the Commissioner to convene a panel of people with subject-matter expertise plus people affected by (or representing people affected by) the code, have that panel examine the draft and produce a report, and then either adopt the panel’s recommended changes or publish a public explanation of why it didn’t — publishing the draft code, the panel’s report (or a summary of it), and any such explanation. Regulation 3’s carve-out means that whole public-accountability loop simply doesn’t apply to anything in the code touching national security; that material can go into the final code without ever passing through the panel-report-and-public-explanation cycle regulation 3 exempts.
What SI 2026/425 does not do: it doesn’t write the code of practice itself. The code is a separate document the Commissioner produces under the section 124A/124B process the regulations trigger, following the consultation, panel-review, and publication steps in section 124B. As of this guide’s research pass, CASRAI could not confirm via the ICO’s own published AI guidance that the code’s substantive text has itself been finalized and published — the regulations are the legal direction to produce it, not the code.
Atomic Facts
| Fact | Detail |
|---|---|
| Instrument | UK Statutory Instrument 2026 No. 425 |
| Full title | The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 |
| Made | 16 April 2026 |
| Laid before Parliament | 21 April 2026 |
| In force | 12 May 2026 (21 days after laying) |
| Extent | England, Wales, Scotland, Northern Ireland |
| Enabling powers | Data Protection Act 2018, ss.124A(1)-(2) and 124B(11), both inserted by the Data (Use and Access) Act 2025, ss.92(2) and 93 |
| Consultation duty | DPA 2018 s.182(2) — Secretary of State must consult the Commissioner before making the regulations |
| What reg 2 requires | ICO must prepare a code of practice on AI development/use and automated decision-making, expressly covering children’s personal data |
| ADM definition used | UK GDPR Art. 22C(1) / DPA 2018 s.50C(1) — “significant decisions” based solely on automated processing |
| What reg 3 does | Amends DPA 2018 s.124B so the code’s advisory panel must not consider or report on national-security-related aspects |
The Advisory Panel, and What the Carve-Out Changes
Section 124B’s panel process is itself the accountability mechanism: the Commissioner must assemble people with expertise in the code’s subject matter, plus people likely to be affected by it (or their representatives), have them examine the draft together, and produce a report. The Commissioner then has a binary choice — adopt the panel’s recommended changes, or publish an explanation of why not — and must publish the draft code, the panel’s report (or a summary), and any such explanation. That is a real, structured transparency requirement, on paper stronger than “the regulator wrote guidance and put it online.”
Regulation 3’s amendment removes one category of content from that entire loop. Anything in the code “relating to national security” is not examined by the panel, is not the subject of a panel report, and is not something the Commissioner has to publicly adopt-or-explain a rejection of. It is a narrow, explicit statutory carve-out — not a general national-security exemption from data protection law (which already exists elsewhere in the DPA 2018), but a specific removal of the panel-review and public-explanation steps for that one category of code content.
Where NIKOLAI Fits
SI 2026/425 is, structurally, a documentation-and-review-process regulation: it specifies what a disclosure document (the code of practice) must cover, sets up an independent review body (the panel), and defines exactly what falls outside that reviewer’s scope (national security). CASRAI’s own NIKOLAI project — an independent, unendorsed reference dictionary of frontier-AI-safety elements, live at casrai.org/nikolai, organized into ten tracks (N1–N10) — maps that same shape of problem in its N8 (Transparency and Review) track, through three elements in particular:
- Publication Rights Clause, which NIKOLAI defines as “the contractual or policy term(s) governing what an external evaluator may publish about a review — specifically who may redact content and whether the developer retains editorial control or approval rights over the evaluator’s findings,” verified live on its own element page. Regulation 3’s national-security carve-out is, in substance, a statutory version of the same question this element is built to record: what is a reviewing body permitted to see and report on, and what is withheld from it by rule rather than by the reviewer’s own discretion.
- AI-Model Review, which records “an assurance task — review, monitoring, grading, red-teaming, or analysis” and who is accountable for its disposition — the same basic shape as the section 124B panel examining a draft code and the Commissioner owning the final adopt-or-explain decision.
- Evaluator Independence and Conflict of Interest, which records “declared financial, organisational and personal relationships between an evaluator and the developer being evaluated, and the independence test applied to clear the evaluator” — the structural question section 124B answers for the ICO’s own panel by specifying who must sit on it (subject-matter experts plus people affected by the code).
None of this means NIKOLAI is referenced by, compliant with, or endorsed under the ICO’s code of practice, SI 2026/425, or the Data Protection Act 2018 — it isn’t, and no such claim is made anywhere in NIKOLAI’s own material. NIKOLAI is CASRAI’s own project: an independent, unendorsed reference a reader can use to think through what “who gets to review this, on what terms, with what left out” looks like as a structured, repeatable question, separate from and unaffiliated with the statutory process SI 2026/425 sets in motion.
Frequently Asked Questions
What is SI 2026/425?
SI 2026/425 is The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, a UK statutory instrument made 16 April 2026, laid before Parliament 21 April 2026, and in force since 12 May 2026. It legally directs the Information Commissioner to prepare a statutory code of practice on AI development/use and automated decision-making.
Does SI 2026/425 itself contain the AI code of practice?
No. The regulations direct the Information Commissioner to prepare the code and specify what it must cover (including children’s personal data) and how it must be reviewed (the section 124B advisory-panel process). The code’s own substantive text is a separate document the Commissioner produces through that process.
What does the national-security carve-out in regulation 3 actually exclude?
It amends section 124B of the Data Protection Act 2018 so the advisory panel reviewing the draft code “must not consider or report on any aspect of the code relating to national security.” That removes national-security-related content from the panel-review, adopt-or-explain, and publication steps section 124B otherwise requires for the whole code — it is not a blanket national-security exemption from data protection law generally.
How does “automated decision-making” get defined for purposes of the code?
Regulation 2 cross-references UK GDPR Article 22C(1) and Data Protection Act 2018 section 50C(1), which cover decisions based entirely or partly on personal data that are made solely by automated processing and produce a “significant decision” about the data subject — the category of decision Article 22C requires safeguards for, including information about the decision, the ability to give the controller the data subject’s point of view, human intervention, and the ability to contest the decision.
Is CASRAI’s NIKOLAI project referenced by, or compliant with, the ICO’s AI code of practice?
No. NIKOLAI is CASRAI’s own, independent, unendorsed reference dictionary. It is not affiliated with, reviewed by, or endorsed under SI 2026/425, the resulting ICO code of practice, or the Data Protection Act 2018. This guide draws a structural parallel between NIKOLAI’s N8 track and the regulations’ documentation/review requirements — it does not assert any formal relationship between them.
Related Reading
- G7 Hiroshima AI Process: the Code of Conduct and the HAIP Reporting Framework
- The UK’s AI White Paper: A Regulatory Framework Without a Regulator
- AI Regulations Around the World: A Jurisdiction Map
- The Algorithmic Accountability Act: What the Federal Bill Would Require
- Frontier AI Law: 10 Jurisdictions Compared
- When AI Reviews AI: Inside NIKOLAI’s AI-Model-Review Element
- Who Checks the Checkers: Evaluator Independence in AI Safety
- NIKOLAI N8 — Transparency and Review
- NIKOLAI’s Track System: A Map of the Frontier AI Safety Landscape (N1-N10)
- What Is NIKOLAI? CASRAI’s Frontier-AI-Safety Dictionary Explained
Why This Matters for Research Administration
UK university Data Protection Officers and research-ethics-committee offices processing children’s personal data — developmental psychology, education research, paediatric health studies — have a direct, trackable stake in SI 2026/425, because Regulation 2 specifically requires the forthcoming ICO code of practice to address processing of children’s personal data in AI/automated-decision-making contexts. Under UK GDPR Article 22C(1) and DPA 2018 s.50C(1), a “significant decision” made solely by automated processing about a research participant — automated eligibility screening or automated scoring of an assessment instrument, for example — triggers specific safeguards: information to the subject, the right to express their point of view, human intervention, and a right to contest. Because the code’s substantive text isn’t published yet, the genuine action for a DPO or research-ethics office is to open a compliance-tracking item now, not to act on specific guidance yet.








