← Insights / Compliance

The Data (Use and Access) Act 2025: What Professional Services Need to Know About Automated Decision-Making

The UK's AI compliance landscape has shifted considerably in a short space of time. For professional services businesses — accountants, solicitors, HR consultancies, marketing agencies — the changes introduced by the Data (Use and Access) Act 2025 (DUAA) are not abstract regulatory developments. The

Compliance 26 July 2026 6 min read

The Data (Use and Access) Act 2025: What Professional Services Need to Know About Automated Decision-Making

The UK's AI compliance landscape has shifted considerably in a short space of time. For professional services businesses — accountants, solicitors, HR consultancies, marketing agencies — the changes introduced by the Data (Use and Access) Act 2025 (DUAA) are not abstract regulatory developments. They carry direct operational consequences for how you assess clients, screen candidates, make lending or credit decisions, and deploy AI-assisted tools across your practice.

If you have not yet reviewed your automated decision-making processes against the new framework, the window for comfortable preparation is narrowing.

What the DUAA Changes — and Why It Matters

The DUAA received Royal Assent on 19 June 2025. Its most significant effect on day-to-day AI use in professional services is the replacement of Article 22 of the UK GDPR with new Articles 22A to 22D, which came into force on 5 February 2026.

Article 22 was the original safeguard against purely automated decisions with significant effects on individuals. The DUAA does not dismantle those protections — it restructures them. The new framework is designed to be more permissive for ordinary personal data, allowing controllers greater latitude to use automated decision-making, provided a defined set of safeguards is properly implemented.

Those safeguards are not optional add-ons. Controllers must:

  • Inform data subjects that a solely automated significant decision has been, or will be, made about them
  • Offer meaningful human intervention — not a rubber-stamp review, but genuine reconsideration by a competent individual
  • Allow representations from the data subject before or after the decision
  • Provide a clear right to contest the outcome

For special category data — health information, biometric data, data revealing racial or ethnic origin, and similar — the bar is higher still. Explicit consent or a specific legal basis is typically required. This will be directly relevant to HR consultancies handling occupational health assessments, solicitors managing disclosure processes, or any firm using AI tools that process sensitive client information.

Where Professional Services Businesses Are Exposed

Consider the scenarios that are already common across professional services:

  • An accountancy firm uses AI to flag clients for enhanced due diligence based on transaction patterns
  • A recruitment consultancy applies an automated scoring tool to shortlist candidates
  • A law firm uses AI-assisted contract analysis to make recommendations that inform significant client decisions
  • A marketing agency uses profiling algorithms to segment and target audiences on behalf of clients

Each of these may constitute a solely automated significant decision — or may come close enough that the distinction matters legally. The obligation to identify which of your processes fall within scope is yours, not the regulator's.

The Information Commissioner's Office (ICO) is preparing a statutory Code of Practice on AI and Automated Decision-Making under SI 2026/425, which came into force on 12 May 2026. A public consultation on draft guidance closed in May 2026, with the finalised code expected in Summer 2026. Once published, that code will carry evidential weight in enforcement proceedings. Businesses that have not aligned their practices with its requirements before enforcement action begins will find it difficult to demonstrate compliance retrospectively.

The EU AI Act: Still Relevant If You Operate Across Borders

UK businesses with European clients or EU market exposure cannot treat these obligations as solely a domestic matter. The EU AI Act applies extraterritorially. If your firm sells or deploys AI systems in the EU, provides AI services to EU-based clients, or uses AI tools whose outputs affect individuals in the EU, you are within scope — regardless of where your business is incorporated.

The practical timeline is pressing. Prohibitions on unacceptable-risk AI systems have been in effect since February 2025. Obligations for general-purpose AI model providers applied from August 2025. High-risk AI system requirements apply from 2 August 2026, with some obligations extending to December 2027. The financial exposure is substantial: fines of up to €35 million or 7% of global annual turnover.

For firms operating across the UK, EU, North America, the Middle East, or Asia-Pacific, a patchwork approach to AI compliance is increasingly untenable. The regulatory frameworks are converging on shared principles — transparency, human oversight, contestability, and accountability — even where the specific legislative mechanisms differ. Building compliance architecture around those principles, rather than jurisdiction-by-jurisdiction checklists, is both more efficient and more durable.

The DUAA also mandates an economic impact assessment and a report on the use of copyrighted works in AI development, both due by March 2026. A progress statement was published in December 2025, with expert working groups examining transparency, technical standards, licensing, and creator remuneration.

For marketing agencies and legal practices in particular, this is worth watching. Questions about whether AI-generated content infringes third-party copyright — and who bears liability when it does — are already reaching the courts. The regulatory framework to address this is still forming, but the judicial scrutiny is not waiting for it. Businesses using generative AI tools to produce client-facing content, legal documents, or marketing materials should document their processes and review the provenance of AI-generated outputs as a matter of current practice, not future preparation.

What a Compliant Automated Decision-Making Process Looks Like

The new Articles 22A to 22D do not prescribe a single model of compliance, but a well-structured approach should include:

  1. Mapping all automated and semi-automated decision-making processes across your business to determine which fall within scope
  2. Documenting the logic, inputs, and outputs of those systems in a way that supports transparency obligations
  3. Designing or retrofitting meaningful human review mechanisms — not procedural theatre, but substantive oversight
  4. Establishing a clear process for receiving and responding to representations and contests from data subjects
  5. Updating privacy notices and data subject communications to reflect new disclosure requirements
  6. Assessing special category data separately, with appropriate legal bases in place before processing begins

This work sits within a broader compliance programme that should account for the forthcoming ICO Code of Practice, the EU AI Act where applicable, and sector-specific guidance relevant to your practice area.

The Regulatory Direction of Travel Is Clear

The UK government has signalled intentions to introduce legislation targeting developers of the most powerful AI models. A standalone UK AI Act has not yet been presented, but the direction of travel is evident: greater accountability, more formal oversight, and increasing enforcement activity from the ICO, which updated its AI and Biometrics Strategy in March 2026 and has made AI a central regulatory priority for 2025/26.

Proactive compliance now is measurably less costly than reactive compliance after an investigation or enforcement notice.


Ops Intel helps professional services businesses assess their AI compliance obligations, map automated decision-making processes, and build practical frameworks that hold up to regulatory scrutiny — in the UK, EU, and beyond.

If you are unsure whether your current practices meet the requirements of the DUAA or the EU AI Act, contact our team for a structured compliance review. We work directly with accountancy firms, law practices, HR consultancies, and marketing agencies to turn regulatory complexity into clear, actionable steps.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit