← All articles

Practical guide

ICO AI Guidance: A Practical Guide for UK SMEs

How UK SMEs can use the ICO's AI guidance and risk toolkit while key pages are under review following the Data (Use and Access) Act.

Key takeaways

  • The ICO's AI guidance and risk toolkit help organisations apply UK data-protection law to AI. They are guidance and practical support, not a separate AI law or a compliance certificate.
  • The guidance covers accountability, transparency, lawfulness, accuracy, fairness, security, data minimisation, and individual rights.
  • The ICO currently warns that its AI guidance is under review following the Data (Use and Access) Act 2025. Some pages still discuss the repealed UK GDPR Article 22.
  • For solely automated significant decisions, use current UK GDPR Articles 22A–22D rather than the old Article 22 explanation.
  • A DPIA is required where processing is likely to result in high risk. AI or profiling alone does not make every project a mandatory DPIA, but several common AI uses warrant a careful screen.

The Information Commissioner's Office regulates data protection in the UK. Its artificial-intelligence guidance is a useful starting point when an AI system processes personal information.

It is not a substitute for reading current law. That distinction is especially important now: the Data (Use and Access) Act 2025 changed the UK's automated-decision rules, and the ICO says the relevant guidance is under review.

What the ICO resources do

The ICO publishes three resources that are particularly useful to a small business:

  1. Guidance on AI and data protection explains how UK GDPR principles and rights apply across an AI lifecycle.
  2. The AI and data protection risk toolkit is a downloadable spreadsheet for identifying, recording, and reducing risks to people's rights and freedoms.
  3. Explaining decisions made with AI, produced with The Alan Turing Institute, provides practical explanation-design guidance for decisions delivered or assisted by AI.

The main guidance is organised around foundational data-protection principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; security and accountability. It also covers individual rights.

The toolkit is not an “eight-area certification,” and completing it does not prove compliance. The ICO describes it as practical support for reducing risks caused by an organisation's own AI systems. Its value is the structured record: what risk you found, how serious it was, what control you chose, who owns it, and what remains.

The current-law warning

The ICO's AI and data-protection pages currently carry a notice that they are under review because of the Data (Use and Access) Act. Some material still explains automated decisions using UK GDPR Article 22, which was replaced on 5 February 2026 by Articles 22A–22D.

The ICO's published plan says an updated automated-decision-making and profiling guide is in drafting, with final publication due in Winter 2026. Until it appears:

  • use the existing guidance for risk-management structure and useful operational questions;
  • verify legal propositions against current UK GDPR;
  • replace old Article 22 references in your own documents; and
  • date your assessment so a reviewer can see which law and guidance you used.

The 2026 regulations also require the Information Commissioner to prepare a code of practice covering good practice in developing and using AI and automated decision-making, including children's data. That future code should not be confused with the current toolkit.

Using the risk toolkit well

Start with one real use case

Do not complete one spreadsheet for “AI” as a whole. Choose a specific system and intended use, such as screening job applicants, transcribing support calls, or drafting client reports. Use the AI Governance Checklist to find tools that would otherwise be missed.

Record:

  • the business purpose and owner;
  • whether you are controller, joint controller, or processor;
  • the people and categories of personal information involved;
  • where data comes from and where it goes;
  • the vendor, model, and significant subcontractors;
  • what the output changes or influences; and
  • whether a human can change a decision before it takes effect.

Separate legal duties from good practice

Some controls implement express UK GDPR duties: establishing a lawful basis, giving privacy information, entering Article 28 processor terms, responding to rights requests, maintaining security, or completing a required DPIA.

Other controls may be prudent without being mandated in that exact form: a model card, a particular testing cadence, or a central AI committee. Mark the difference. It prevents internal guidance from being presented as law and helps a small team prioritise.

Record residual risk and ownership

A control is not complete because a box says “human review.” Record who reviews, what information they see, whether they can override the output, how often exceptions occur, and how the organisation checks that the control works.

If a DPIA shows high residual risk that cannot be reduced, Article 36 requires consultation with the ICO before the processing begins. A recurring monthly AI usage review can then catch changes in vendor, purpose, or data between formal assessments.

Automated decisions under the new rules

Article 22A defines a solely automated decision by the absence of meaningful human involvement and defines a significant decision by its legal or similarly significant effect.

Article 22B places restrictions on significant solely automated decisions based wholly or partly on special-category personal information. Article 22C requires safeguards for significant solely automated decisions more generally, including:

  • information about the decision;
  • an opportunity to make representations;
  • human intervention by the controller; and
  • an opportunity to contest the decision.

Do not describe these simply as a universal “right to explanation.” The exact duties depend on the provision and facts. For an Article 22C decision, plan an individual communication and a working review route, not only a paragraph in the general privacy notice.

The ICO's explanation guidance remains useful for making information clear and meaningful, but its legal framework page is also marked as under review. Treat pre-February 2026 Article 22 analysis as stale.

When to complete a DPIA

UK GDPR Article 35 requires a DPIA before processing likely to result in high risk to people's rights and freedoms. Express cases include:

  • systematic and extensive evaluation of personal aspects based on automated processing, including profiling, where significant decisions are based on it;
  • large-scale processing of special-category or criminal-conviction data; and
  • large-scale systematic monitoring of a publicly accessible area.

Other combinations can also be high-risk. Employee monitoring, vulnerable people, novel technology, matching datasets, tracking, and preventing people from exercising a right or using a service are reasons for closer review.

Do not state that any AI use, any profiling, or any sensitive data automatically requires a DPIA. Complete and retain the screen, then do the full assessment where the facts cross the threshold.

A practical SME workflow

For each AI system:

  1. Add it to the inventory and identify the controller and processor roles.
  2. Record the purpose, Article 6 lawful basis, and any Article 9 condition.
  3. Map data sources, recipients, retention, security, and international transfers.
  4. Screen for a DPIA and complete one before use where required.
  5. Test fairness and accuracy for the affected people and intended context.
  6. Map how people receive information and exercise access, objection, erasure, or other applicable rights.
  7. For a significant decision, assess Articles 22A–22C using the real human workflow.
  8. Give every mitigation an owner, due date, test, and review date.
  9. Revisit the assessment when the vendor, model, data, purpose, or ICO guidance changes.

Where the UK Pro Pack fits

The UK AI Governance Pro Pack does not claim to certify a business against the ICO toolkit. Its UK Automated Decision-Making Assessment applies current Articles 22A–22D, while the UK GDPR AI Data Processing Register, UK DPIA Trigger Checklist, transparency notice, vendor checklist, and incident procedure support related controls.

For jurisdiction-neutral employee rules and governance basics, use the AI Governance Starter Pack. The free AI Risk Checklist is an operational screen, not an ICO or UK GDPR assessment.


This article summarises ICO guidance and UK data-protection provisions for SME owners. It is not legal advice, an ICO endorsement, or a guarantee of compliance. Guidance and law may change, and requirements depend on the processing, data, people, sector, and context. Check current ICO materials and obtain qualified advice where needed.

Put it into practice

Turn the guidance into a working rule.

The free tools on this site generate a tailored AI policy, risk assessment, or prompt safety check in under two minutes — no account required.

Operating under a specific regime? The EU Pro Pack and UK Pro Pack add 8 documents each, referenced to the articles that create the obligation.