Skip to main content
v2026.11,858 entries · CC-BY 4.0

The UK’s AI Code of Practice Regulations 2026: What SI 2026/425 Requires

In April and May 2026, a UK statutory instrument quietly did something the 2023 AI White Paper only promised: it gave the Information Commissioner a binding legal direction to write a statutory code of practice on AI and automated decision-making, with a built-in carve-out excluding national security from the panel that reviews it. This is regulatory background, not breaking news — here is what SI 2026/425 actually requires, and what it doesn’t.

Written and maintained by CASRAI Editorial Board

Last updated

Short answer: The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 — UK Statutory Instrument 2026 No. 425 — is a short, mechanical instrument. It does not itself write AI rules; it legally directs the Information Commissioner to produce a statutory code of practice covering AI development/use and automated decision-making, tells the Commissioner the code must specifically address children’s personal data, and amends the advisory-panel process so the panel reviewing the code cannot consider or report on anything relating to national security. This is regulatory background material, dated to when the instrument was made and came into force — 16 April 2026 (made), 21 April 2026 (laid before Parliament), and 12 May 2026 (in force) — not a current-week development. CASRAI’s own NIKOLAI project, an independent, unendorsed reference dictionary of frontier-AI-safety elements, maps a closely related set of documentation and review obligations in its N8 track; the connection is laid out below.

What SI 2026/425 Actually Is

SI 2026/425’s full title is The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026. It was made by the Secretary of State on 16 April 2026, laid before Parliament on 21 April 2026, and came into force on 12 May 2026 (21 days after laying, per its own regulation 1) — extending to England, Wales, Scotland, and Northern Ireland. The full text is published at legislation.gov.uk/uksi/2026/425, verified directly against the instrument’s own introductory text and regulations for this guide.

The instrument is short: three regulations plus an explanatory note. It exists because the Data (Use and Access) Act 2025 inserted two new sections into the Data Protection Act 2018 — section 124A (the Secretary of State’s power to direct the Commissioner to prepare a code of practice) and section 124B (the advisory-panel mechanism that reviews a draft code) — and SI 2026/425 is the Secretary of State exercising that new section 124A power for the first time on AI and automated decision-making specifically, citing sections 124A(1) and (2) and 124B(11) of the 2018 Act as its enabling powers, after consulting the Commissioner as section 182(2) of the Act requires.

What It Requires, Regulation by Regulation

Regulation 1 is citation, commencement, extent, and interpretation — the 21-day-after-laying commencement and UK-wide extent noted above. The two regulations that actually do something:

  • Regulation 2 — directs the code’s scope. It requires the Information Commissioner to prepare a code of practice giving guidance on good practice in processing personal data in connection with (a) developing and using artificial intelligence, and (b) automated decision-making. It explicitly requires the code to address the processing of children’s personal data as part of that guidance. “Automated decision-making” here is defined by cross-reference to UK GDPR Article 22C(1) and Data Protection Act 2018 section 50C(1) — the provisions covering decisions made solely by automated processing that produce a “significant decision” about a data subject.
  • Regulation 3 — carves national security out of the panel’s review. It amends section 124B of the 2018 Act to add that the advisory panel reviewing the draft code “must not consider or report on any aspect of the code relating to national security.” Section 124B otherwise requires the Commissioner to convene a panel of people with subject-matter expertise plus people affected by (or representing people affected by) the code, have that panel examine the draft and produce a report, and then either adopt the panel’s recommended changes or publish a public explanation of why it didn’t — publishing the draft code, the panel’s report (or a summary of it), and any such explanation. Regulation 3’s carve-out means that whole public-accountability loop simply doesn’t apply to anything in the code touching national security; that material can go into the final code without ever passing through the panel-report-and-public-explanation cycle regulation 3 exempts.

What SI 2026/425 does not do: it doesn’t write the code of practice itself. The code is a separate document the Commissioner produces under the section 124A/124B process the regulations trigger, following the consultation, panel-review, and publication steps in section 124B. As of this guide’s research pass, CASRAI could not confirm via the ICO’s own published AI guidance that the code’s substantive text has itself been finalized and published — the regulations are the legal direction to produce it, not the code.

Atomic Facts

Fact Detail
Instrument UK Statutory Instrument 2026 No. 425
Full title The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026
Made 16 April 2026
Laid before Parliament 21 April 2026
In force 12 May 2026 (21 days after laying)
Extent England, Wales, Scotland, Northern Ireland
Enabling powers Data Protection Act 2018, ss.124A(1)-(2) and 124B(11), both inserted by the Data (Use and Access) Act 2025, ss.92(2) and 93
Consultation duty DPA 2018 s.182(2) — Secretary of State must consult the Commissioner before making the regulations
What reg 2 requires ICO must prepare a code of practice on AI development/use and automated decision-making, expressly covering children’s personal data
ADM definition used UK GDPR Art. 22C(1) / DPA 2018 s.50C(1) — “significant decisions” based solely on automated processing
What reg 3 does Amends DPA 2018 s.124B so the code’s advisory panel must not consider or report on national-security-related aspects

The Advisory Panel, and What the Carve-Out Changes

Section 124B’s panel process is itself the accountability mechanism: the Commissioner must assemble people with expertise in the code’s subject matter, plus people likely to be affected by it (or their representatives), have them examine the draft together, and produce a report. The Commissioner then has a binary choice — adopt the panel’s recommended changes, or publish an explanation of why not — and must publish the draft code, the panel’s report (or a summary), and any such explanation. That is a real, structured transparency requirement, on paper stronger than “the regulator wrote guidance and put it online.”

Regulation 3’s amendment removes one category of content from that entire loop. Anything in the code “relating to national security” is not examined by the panel, is not the subject of a panel report, and is not something the Commissioner has to publicly adopt-or-explain a rejection of. It is a narrow, explicit statutory carve-out — not a general national-security exemption from data protection law (which already exists elsewhere in the DPA 2018), but a specific removal of the panel-review and public-explanation steps for that one category of code content.

Where NIKOLAI Fits

SI 2026/425 is, structurally, a documentation-and-review-process regulation: it specifies what a disclosure document (the code of practice) must cover, sets up an independent review body (the panel), and defines exactly what falls outside that reviewer’s scope (national security). CASRAI’s own NIKOLAI project — an independent, unendorsed reference dictionary of frontier-AI-safety elements, live at casrai.org/nikolai, organized into ten tracks (N1–N10) — maps that same shape of problem in its N8 (Transparency and Review) track, through three elements in particular:

  • Publication Rights Clause, which NIKOLAI defines as “the contractual or policy term(s) governing what an external evaluator may publish about a review — specifically who may redact content and whether the developer retains editorial control or approval rights over the evaluator’s findings,” verified live on its own element page. Regulation 3’s national-security carve-out is, in substance, a statutory version of the same question this element is built to record: what is a reviewing body permitted to see and report on, and what is withheld from it by rule rather than by the reviewer’s own discretion.
  • AI-Model Review, which records “an assurance task — review, monitoring, grading, red-teaming, or analysis” and who is accountable for its disposition — the same basic shape as the section 124B panel examining a draft code and the Commissioner owning the final adopt-or-explain decision.
  • Evaluator Independence and Conflict of Interest, which records “declared financial, organisational and personal relationships between an evaluator and the developer being evaluated, and the independence test applied to clear the evaluator” — the structural question section 124B answers for the ICO’s own panel by specifying who must sit on it (subject-matter experts plus people affected by the code).

None of this means NIKOLAI is referenced by, compliant with, or endorsed under the ICO’s code of practice, SI 2026/425, or the Data Protection Act 2018 — it isn’t, and no such claim is made anywhere in NIKOLAI’s own material. NIKOLAI is CASRAI’s own project: an independent, unendorsed reference a reader can use to think through what “who gets to review this, on what terms, with what left out” looks like as a structured, repeatable question, separate from and unaffiliated with the statutory process SI 2026/425 sets in motion.

Frequently Asked Questions

What is SI 2026/425?

SI 2026/425 is The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, a UK statutory instrument made 16 April 2026, laid before Parliament 21 April 2026, and in force since 12 May 2026. It legally directs the Information Commissioner to prepare a statutory code of practice on AI development/use and automated decision-making.

Does SI 2026/425 itself contain the AI code of practice?

No. The regulations direct the Information Commissioner to prepare the code and specify what it must cover (including children’s personal data) and how it must be reviewed (the section 124B advisory-panel process). The code’s own substantive text is a separate document the Commissioner produces through that process.

What does the national-security carve-out in regulation 3 actually exclude?

It amends section 124B of the Data Protection Act 2018 so the advisory panel reviewing the draft code “must not consider or report on any aspect of the code relating to national security.” That removes national-security-related content from the panel-review, adopt-or-explain, and publication steps section 124B otherwise requires for the whole code — it is not a blanket national-security exemption from data protection law generally.

How does “automated decision-making” get defined for purposes of the code?

Regulation 2 cross-references UK GDPR Article 22C(1) and Data Protection Act 2018 section 50C(1), which cover decisions based entirely or partly on personal data that are made solely by automated processing and produce a “significant decision” about the data subject — the category of decision Article 22C requires safeguards for, including information about the decision, the ability to give the controller the data subject’s point of view, human intervention, and the ability to contest the decision.

Is CASRAI’s NIKOLAI project referenced by, or compliant with, the ICO’s AI code of practice?

No. NIKOLAI is CASRAI’s own, independent, unendorsed reference dictionary. It is not affiliated with, reviewed by, or endorsed under SI 2026/425, the resulting ICO code of practice, or the Data Protection Act 2018. This guide draws a structural parallel between NIKOLAI’s N8 track and the regulations’ documentation/review requirements — it does not assert any formal relationship between them.

Related Reading

Why This Matters for Research Administration

UK university Data Protection Officers and research-ethics-committee offices processing children’s personal data — developmental psychology, education research, paediatric health studies — have a direct, trackable stake in SI 2026/425, because Regulation 2 specifically requires the forthcoming ICO code of practice to address processing of children’s personal data in AI/automated-decision-making contexts. Under UK GDPR Article 22C(1) and DPA 2018 s.50C(1), a “significant decision” made solely by automated processing about a research participant — automated eligibility screening or automated scoring of an assessment instrument, for example — triggers specific safeguards: information to the subject, the right to express their point of view, human intervention, and a right to contest. Because the code’s substantive text isn’t published yet, the genuine action for a DPO or research-ethics office is to open a compliance-tracking item now, not to act on specific guidance yet.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about The UK’s AI Code of Practice Regulations 2026: What SI 2026/425 Requires

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

AI policy question? Get an answer citing the framework.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.