Somewhere in a broking firm there is a folder, and in that folder there is a note about artificial intelligence. It was written by someone conscientious. They did not copy it from a webinar. They went to the regulator, found the FCA's AI Update, read it properly, followed it out to the data protection law it points at, and wrote down what they found.
That person did everything right. Their note is out of date.
What the FCA told firms to read
The AI Update, published in April 2024, does not create AI rules. It tells you which existing rules AI walks into, and that structure is the point of it. At paragraph 3.31 it turns to data protection.
"Where firms use AI systems that process personal data, they will also need to consider obligations under data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018."
The same paragraph sends firms on to the Information Commissioner's Office, which "has produced helpful Guidance on AI and Data Protection". Then paragraph 3.32 gets specific:
"This includes reference to the safeguards on automated decision making under Article 22 UK GDPR, which provides data subjects with the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects."
Article 22 comes back at paragraph 3.47, where the Update sets out the right not to be subject to automated decisions and the safeguards that apply where exceptions are relied on.
This is the trail a careful firm follows. Regulator, to the rule, to the guidance.
The footnote nobody reads
Hanging off paragraph 3.32 is footnote 3, and it deserves more attention than a footnote usually gets.
"We note the Data Protection and Digital Information Bill (currently at committee stage in the House of Lords) proposes changes to the data protection regime, including Article 22."
So the FCA saw it coming. In April 2024 it wrote down, in the document itself, that the rule it was citing was in flux. That matters for how the rest of this is read. The Update was not wrong then and it is not careless now. It was a correct statement of the law with a flag on it.
The interesting part is what happened next. There is no Data Protection and Digital Information Act. Search the statute book for that title and it returns nothing. The bill the footnote named never became law.
The change still happened. It simply arrived by a different road.
What actually replaced it
Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 with four new articles, 22A to 22D. It took effect in stages, and came fully into force on 5 February 2026.
The centre of gravity moved, and it moved somewhere quite specific. Old Article 22 gave a right not to be subject to a decision based solely on automated processing. The obvious question it left hanging was what "solely" meant, and the honest answer for years was that a human somewhere in the process probably took you out of scope. Article 22A(1) closes that door by defining the term:
"a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision"
Meaningful. Not present, not nominally responsible, not named on the file. And in case the point could be softened, Article 22A(2):
"When considering whether there is meaningful human involvement in the taking of a decision, a person must consider, among other things, the extent to which the decision is reached by means of profiling"
Read those two together and the test has changed character. It used to be a question about the architecture of a system, whether a human was in it. It is now a question about the quality of what that human actually did. The more the output was shaped by profiling, the more the involvement has to carry.
That is a harder question, and it is much closer to the one a regulator asks after something has gone wrong.
Where it got harder, not easier
Reform is usually read as loosening. Here is the part that did not loosen. Article 22B:
"A significant decision based entirely or partly on processing described in Article 9(1) ... may not be taken based solely on automated processing, unless one of the following conditions is met"
Article 9(1) is special category data, and for a broking firm the word in that list is health. Note the reach of "entirely or partly". A decision does not have to be about health data to engage this. It has to have been based partly on it.
For everything outside that, Article 22C sets the floor: where a significant decision is taken solely by automated means, the controller must ensure safeguards are in place, and those must include information, the ability to make representations, human intervention, and the ability to contest the decision.
So the shape of the regime is intact. Solely automated decisions, significant effects, tighter rules where health data is involved, safeguards where exceptions are relied on. Anyone who understood the old position understands the new one. What has changed is the sharpest question in it, and that question is now about the human rather than the system.
The guidance chain has not caught up
Here is the position as it stands.
The AI Update still says Article 22, which is what a document published in April 2024 says. The FCA's own page on its approach to AI carries a last-updated date of 13 February 2026, eight days after the replacement came into force, and says:
"We do not plan to introduce extra regulations for AI. Instead, we'll rely on existing frameworks, which mitigate many of the risks associated with AI."
Which is true, and is the whole philosophy in one sentence. Existing frameworks apply. The corollary is the thing worth sitting with: if the framework is what governs you, then when the framework moves, your position moves with it, and nobody sends a letter.
No rule changed at the FCA. Everything changed underneath it.
What this actually costs a firm
Not a breach, and this piece is not going to tell you that you have one. The provisions replacing Article 22 keep the same architecture, so a firm that genuinely had meaningful human involvement before still has it now.
The cost is narrower and more awkward than that. It is that the document in the folder cites a provision that is no longer there. The thinking may be entirely sound. The reference is to a rule that was replaced in February, and it is the firms that did the reading, wrote it down and dated it that have this problem at all. A firm that never documented anything has nothing to go stale.
That is the uncomfortable shape of it. Diligence is what creates the exposure, because diligence is what produces a dated record of your understanding of the law.
Which is the argument for the thing nobody schedules. Governance is not a document you write, it is a document you re-read. The rules that apply to AI are not AI rules, they sit in data protection law, in the Consumer Duty, in the conduct rules, and they move on their own timetable without reference to whatever you happen to be building.
The firm that wrote its AI note in 2024 and has not looked at it since is not careless. It is simply working from a photograph of a moving thing.