Key Takeaways
- The ICO's consultation on automated decision-making in employment closed 29 May 2026 and demands "meaningful human involvement" in hiring, performance and disciplinary decisions.
- The DRCF's 31 March 2026 paper on agentic AI warns that a single deployment can trigger obligations from the ICO, FCA, Ofcom and CMA simultaneously.
- A House of Commons Business and Trade Committee inquiry is examining AI in recruitment, performance monitoring and pay decisions across UK workplaces.
- Employers should immediately audit ATS scoring tools, AI interview platforms, performance-management analytics and any agent that takes consequential actions without human review.
- Two DRCF calls for input remain open until 2 September 2026, and a 10 June Commons Library briefing confirms no standalone UK AI bill is planned.
The UK's approach to AI regulation has been characterised, since the 2023 AI White Paper, by deliberate restraint. The government's position was that existing regulators should apply existing law to AI, rather than create new AI-specific legislation. The aim was to avoid the regulatory fragmentation that has complicated AI deployment in the EU. Critics noted it was also a way of postponing difficult decisions.
Those decisions are now arriving. In the spring of 2026, three regulatory developments landed at once: an ICO consultation on automated decision-making in employment, a House of Commons inquiry into AI in UK workplaces, and a cross-regulator foresight paper from the Digital Regulation Cooperation Forum on agentic AI. Together they have shifted the regulatory landscape from permissive to prescriptive. The direction of travel is clear: automated AI decisions that affect people are coming under closer scrutiny. Organisations that have not thought carefully about accountability and transparency will find themselves exposed.
Development 1: The ICO's Automated Decision-Making Consultation
The Information Commissioner's Office launched a consultation on 31 March 2026 on draft guidance covering automated decision-making, with recruitment uses at its centre. The consultation closed on 29 May 2026. It focused on a specific and contentious area: using AI to screen CVs, assess candidate suitability, schedule interviews, and in some cases make hiring recommendations, often without meaningful human involvement at each stage.
The ICO's working position is that automated decisions affecting employment — whether hiring, performance management, disciplinary outcomes, or promotion — require meaningful human involvement at decision points that have material consequences for the individual. Here, "meaningful" is doing real work. The ICO has been explicit that a human clicking "approve" on an AI recommendation, without genuinely reviewing the decision underneath it, does not constitute meaningful involvement.
The practical implications are considerable:
- CV screening tools that rank or filter candidates before a human reviewer sees them need to be audited for bias and explainability. The output must be reviewable by a human who can override it on the basis of their own judgment.
- AI interview assessment tools — software that analyses facial expressions, speech patterns, or responses to score candidates — face particular scrutiny. The ICO has flagged these as high-risk under existing data protection law, and the consultation suggests formal guidance is coming.
- Performance management systems that use AI to generate ratings, flag underperformance, or recommend disciplinary action must have human decision-makers who are genuinely engaged with the evidence, not simply ratifying an algorithmic output.
The consultation closed on 29 May, and final guidance is expected to follow. Organisations using AI in any of these ways should read the ICO's draft guidance now, rather than wait for the final version. The direction is already clear, and the guidance will have real teeth: the ICO has enforcement powers, and a track record of using them in high-profile cases.
Development 2: The House of Commons Business and Trade Committee Inquiry
In parallel with the ICO consultation, the House of Commons Business and Trade Committee launched an inquiry into the use of AI in UK workplaces. The inquiry is examining three primary areas: AI in recruitment and selection, AI in performance monitoring and management, and AI in decisions about pay, hours, and employment terms.
Parliamentary inquiries do not create law directly, but they shape it. The Committees' conclusions influence government policy, provide a platform for concerns from workers and trade unions, and create political pressure that tends to produce regulatory responses. The areas under scrutiny — recruitment, performance management, and terms of employment — cover the majority of consequential AI applications that UK employers are deploying or planning to deploy.
The inquiry is also examining the transparency obligations that employees should have when AI is used in decisions affecting them. Current UK law requires organisations to inform individuals when decisions about them are made solely by automated means. The inquiry is examining whether this obligation is being met in practice. It is also asking whether the threshold — solely automated — is set at the right level.
Development 3: The DRCF's Foresight Paper on Agentic AI
The Digital Regulation Cooperation Forum — the body that coordinates between the ICO, FCA, Ofcom, and CMA — published a foresight paper, The Future of Agentic AI, on 31 March 2026. It is the first UK cross-regulator publication addressed at the new generation of AI agents. These systems can take actions, make decisions, and operate over extended periods without direct human oversight.
The paper's central warning is that a single agentic AI deployment can engage all four regulators' remits at once. Its worked example is a retail assistant powered by agentic AI. It could simultaneously raise data protection questions for the ICO, financial-regulation questions for the FCA, online-safety duties overseen by Ofcom, and competition and consumer law concerns for the CMA. The practical message is to map each agent deployment against all four domains, not just the one that seems nearest.
For organisations that have been building or deploying AI agents — whether for internal automation or customer-facing services — the paper is the clearest signal yet of how UK regulators are thinking. It is a foresight exercise rather than binding guidance, but it sets out the questions that future supervision, and eventually enforcement, will ask.
Update, July 2026: the DRCF has followed the foresight paper with two live calls for input — one on consumer attitudes to generative and agentic AI, and one on the tools and frameworks organisations use to manage AI risks. Both are open until 2 September 2026. A House of Commons Library briefing of 10 June confirmed the frame: no AI bill is before Parliament, and the sector-based approach continues. The same period brought the AI Growth Labs, which put these regulators directly into product testing, starting with legal services — covered in our Growth Labs briefing and mapped alongside the rest of the estate in our UK AI policy landscape guide.
Which Systems Are in Scope
The combined effect of these three developments is to bring into scope a wide range of AI applications that many organisations have deployed without detailed regulatory analysis. The following systems deserve immediate audit:
- ATS (Applicant Tracking Systems) with AI scoring. Any system that ranks, filters, or scores candidates before human review.
- AI interview platforms. Tools that assess candidates via video analysis, psychometric profiling, or automated scoring of responses.
- Performance management software with AI analytics. Systems that generate performance scores, flag patterns, or recommend outcomes without separate human analysis.
- Workforce management tools. AI that schedules shifts, allocates tasks, or manages working hours based on algorithmic optimisation.
- Customer-facing AI agents. Any agent that makes or influences decisions about customers — credit, claims, service levels — without human review of individual cases.
- Internal agentic workflows. Automated processes that take consequential actions (sending communications, updating records, triggering payments) without a human checkpoint.
What to Do Now
The regulatory direction is clear: automated AI decisions affecting people are moving from permissive territory to regulated territory. Organisations that get ahead of this will be better positioned than those that wait for enforcement. Here is a practical starting point.
Audit your automated decision-making systems
Compile a complete inventory of AI systems that influence or make decisions about employees, job applicants, or customers. For each, document: what decision the AI is involved in, what data it uses, what a human reviewer sees and when, and what the process is if the decision is challenged.
Define what "meaningful human involvement" looks like in your processes
The ICO will be looking for evidence that human reviewers are genuinely engaged with AI outputs — not rubber-stamping them. This means designing review processes where the human has access to the underlying evidence, has time to form their own view, and has documented their reasoning. A reviewer who can only see the AI's recommendation, and not the data behind it, does not meet the standard.
Prepare your transparency documentation
Employees and job applicants have rights under existing data protection law to know when automated decision-making is being used. Audit whether your current privacy notices, job application processes, and employee communications accurately describe the AI systems you use. Update them where they do not.
Review your agentic AI deployments against all four regulatory remits
If you have deployed AI agents — even internally — map them against the four regulatory remits the DRCF paper spans: data protection (ICO), financial regulation (FCA), online safety (Ofcom), and competition and consumer law (CMA). For each agent, you should be able to name the accountable person, describe how affected parties could challenge the agent's actions, and demonstrate that you can pause or override the system if required.
UK AI regulation is not following the EU's prescriptive path, but it is moving in a clear direction: organisations that use AI in ways that affect people will be expected to demonstrate accountability, transparency, and genuine human involvement in consequential decisions. The organisations that are already building these disciplines into their AI deployments will face this transition as a confirmation of existing practice. Those that have not will face it as a compliance project — and compliance projects are always more expensive than getting it right the first time.
Frequently asked questions
What did the ICO's 2026 consultation on automated decision-making cover?
It covered the use of AI in recruitment — CV screening, candidate assessment, interview scheduling and hiring recommendations — and the ICO's position that employment decisions require meaningful human involvement. The consultation closed on 29 May 2026.
What does 'meaningful human involvement' mean under the ICO's position?
A human reviewer who is genuinely engaged with the evidence — able to see the underlying data and override the AI — not someone clicking approve on a recommendation. A reviewer who sees only the AI's output does not meet the standard.
What is the DRCF paper on agentic AI?
The Future of Agentic AI, a foresight paper published on 31 March 2026 by the Digital Regulation Cooperation Forum (the CMA, FCA, ICO and Ofcom). Its central warning: a single agentic AI deployment can engage all four regulators' remits at once. It is not legally binding, but it signals the questions future supervision will ask.
Which systems should UK employers audit first?
Applicant tracking systems with AI scoring, AI interview platforms, AI performance-management analytics, workforce-management tools, and any customer-facing or internal agent that takes consequential actions without human review.
To get future posts as they are published, leave your email address.
← All posts