AI for brokers

Automated decisions in a broker inbox: what changed for UK brokerages in February 2026

On 5 February 2026 the UK replaced Article 22 with Articles 22A to 22D. What a brokerage running AI replies, risk scores and lifecycle triggers must now show.

Published on 8 min readFCB.ai
Contents
  1. What changed on 5 February 2026
  2. Sorting your own automations into the right box
  3. Health data keeps the old answer
  4. The safeguards you must be able to show
  5. If your book crosses the Channel
  6. Frequently asked questions

An assistant that drafts a reply for an adviser to read is one thing. An automation that decides something about a client on its own — declines the request, excludes them from renewal terms, closes their notification — is another, and UK data protection law changed its mind about the second category this year. On 5 February 2026, section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with four new Articles, 22A to 22D. If your brokerage has been treating "no solely automated decisions" as a settled rule in its AI policy, that policy is out of date.

What changed on 5 February 2026

The old Article 22 started from prohibition: a decision based solely on automated processing with legal or similarly significant effects was banned unless you could fit into one of three exceptions — contract necessity, authorisation by law, or explicit consent. The new framework, commenced by the Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026, starts from permission with conditions. For ordinary personal data, a controller may take a significant automated decision on any lawful basis, including legitimate interests, provided the safeguards in Article 22C are in place. The ICO's own summary is that the Act opens up the full range of lawful bases you can rely on when using people's personal information to make significant automated decisions about them, so long as the safeguards continue to apply.

Three definitions in Article 22A do the heavy lifting. A decision is based solely on automated processing if there is no meaningful human involvement in taking it. A decision is significant if it produces a legal effect for the data subject or has a similarly significant effect. And when you assess meaningful human involvement, Article 22A(2) requires you to consider, among other things, the extent to which the decision is reached by means of profiling — which is the statutory way of saying that an adviser clicking "approve" on a score they do not understand is not a human in the loop.

Sorting your own automations into the right box

Most of what a brokerage runs on WhatsApp never gets near Article 22C. The value of the exercise is being able to say why, in writing, before someone asks. Work through each automation with three questions: is a decision being taken, is it significant for the client, and is there meaningful human involvement before it takes effect?

AutomationSignificant decision?Solely automated?Where it lands
AI drafts a reply, adviser reads it, edits and sendsUsually notNo — the adviser decidesOutside 22A–22C, but the review must be real, not a rubber stamp
Rule-based auto-reply confirming a renewal date or office hoursNo legal or similar effectYesOutside the regime; transparency and accuracy still apply
Attrition risk score used to build an adviser call listNo decision yetProfiling under Article 4; accuracy and information duties
Client excluded from a campaign segment by scoreNormally notYesDocument the logic; revisit if the exclusion denies a benefit
Automated refusal to quote, or automated referral that ends the enquiryLikely yesDepends on the human stepArticle 22C safeguards; Article 22B if health data is involved
AI classification that closes a claim notification with no adviser reviewYesYesArticle 22C safeguards and, realistically, a DPIA

Two traps sit in this table. The first is the attrition risk score: computing it is profiling, which is governed by the accuracy and transparency rules but is not a decision. It becomes a decision the moment nobody looks at the output before something happens to the client. The second is Article 22B(4), which is easy to skip: a significant decision may not be taken solely by automated means where the processing relies on Article 6(1)(ea), the recognised legitimate interests basis. Choosing the convenient lawful basis can therefore close the automation door you were trying to open.

Health data keeps the old answer

Article 22B preserves the stricter regime where special category data is in play — and for a brokerage writing private medical, group risk, income protection or travel with medical declarations, that is a live question, not a theoretical one. A significant decision based entirely or partly on Article 9(1) processing cannot be taken solely by automated means unless either the data subject gave explicit consent to the processing the decision is based on, or the decision is necessary for entering into or performing a contract with the controller, or is required or authorised by law, and an Article 9(2)(g) substantial public interest condition applies.

In plain brokerage terms: an automation that sorts a client into a "refer to underwriter" track on the strength of a disclosed condition, with no adviser in the loop, needs a condition you can name. Most firms will find it faster to keep a human decision point than to build the consent architecture around it.

The safeguards you must be able to show

Where a significant, solely automated decision is taken, Article 22C requires safeguards for the data subject's rights, freedoms and legitimate interests, consisting of or including measures that provide the data subject with information about the decisions taken in relation to them, enable them to make representations about those decisions, enable them to obtain human intervention on the part of the controller, and enable them to contest the decision. Article 22D lets the Secretary of State add to those safeguards by regulations, and define — positively or negatively — what counts as meaningful human involvement; those regulations cannot amend Article 22C itself.

For a small brokerage, evidencing this is mostly paperwork you should already have. Four practical steps:

  1. Update the privacy notice. The Act also amended Articles 13, 14 and 15, so people must be told about significant automated decisions subject to Article 22C safeguards. A notice that still says "we do not carry out automated decision-making" while an automation quietly declines enquiries is the easiest complaint a client will ever make.
  2. Name the human. Write down who reviews, what they see, what they are empowered to overturn, and how often they actually do. Reviews that never change an outcome are evidence against you.
  3. Give the client a route. One reply in the thread asking for a person should reach a person. That is what "obtain human intervention" means on a messaging channel.
  4. Keep the record. Which automation ran, on what inputs, what it decided, who reviewed it and when — retrievable later, at brokerage level rather than on an adviser's handset.

Guidance is still settling. The ICO consulted on draft guidance on automated decision-making, including profiling in spring 2026, and a separate 2026 statutory instrument requires the regulator to produce a code of practice on artificial intelligence and automated decision-making. Expect the detail on meaningful human involvement to firm up; expect the four safeguards not to move. If your firm has not yet mapped whether this processing needs a data protection impact assessment, start with our guide on when an AI-assisted broker inbox needs a DPIA.

If your book crosses the Channel

The UK moved; the EU did not. A broker in Dublin, Amsterdam or Frankfurt is still under Article 22 of the EU GDPR, where the default remains prohibition and you need contract necessity, member state law or explicit consent before a significant solely automated decision, with the Article 22(3) safeguards on top. Layer on the obligations covered in our guide to the EU AI Act for brokers using AI-drafted replies, and a firm serving clients on both sides ends up running two regimes through one inbox. The pragmatic answer for most brokerages is to build to the stricter standard — keep a human decision point, document it, and let the UK flexibility be headroom you do not need to use. The rest of our AI topic covers the governance side.

Frequently asked questions

Does an AI-drafted message my adviser sends count as an automated decision?

No, provided the adviser genuinely takes the decision. The test in Article 22A(1)(a) is whether there is meaningful human involvement in taking the decision, and Article 22A(2) makes you weigh how far the outcome was reached by profiling. An adviser who reads the draft, has the client history in front of them and can rewrite or discard it is deciding. An adviser told to approve a queue of a hundred drafts a day is not.

Is our churn or risk score caught by the new rules?

Computing a score is profiling, not a decision. It becomes a significant automated decision only when the score alone triggers an outcome with legal or similarly significant effects for the client and no human reviews it. A score that produces a call list for an adviser stays on the right side of that line — but the accuracy, transparency and lawful basis obligations still apply to the score itself.

We advise on private medical cover. What changes for us?

Article 22B keeps the stricter position wherever special category data is part of the picture. A solely automated significant decision based on health data needs explicit consent to the underlying processing, or contract necessity or legal authorisation coupled with an Article 9(2)(g) condition. In most brokerages the realistic answer is to keep an adviser in the decision.

Do we still need a DPIA?

The DPIA obligation did not change. Systematic and extensive evaluation of individuals through automated processing on which significant decisions are based remains a high-risk trigger, and large-scale processing of health data is another. The commencement of Articles 22A to 22D makes the assessment more useful, not less, because it is where you record which automations you decided were significant and why.

What should our privacy notice say now?

It should describe the significant automated decisions the firm takes that are subject to Article 22C safeguards, the logic involved in general terms, the consequences for the client, and how to ask for human intervention or contest a decision. Say it in the notice, and make sure the route you describe actually works when a client uses it on WhatsApp.

See ORIS in action

Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.

Book a demo
Book a demo