Legal concerns

  • draft from playbook

This information complements and updates the AI Playbook for the UK Government . It reflects the latest guidance and best practice. This will be updated as needed.

Legal considerations

Different types of AI and use cases will likely create different types of legal issues. To mitigate these, you should seek advice from government legal advisers who can help you navigate the design and use of AI in government.

Many of the legal issues that surround AI are not new. For example, the ethical principles discussed in this playbook, such as fairness, discrimination, transparency and bias, have sound foundations in public and other law. Any ethical issues that your team identifies are also likely to be legal issues that your lawyers will be able to help guide you through.

The lawfulness and purpose limitation section explains how to ensure that personal data is processed lawfully, securely and fairly at all times. Your lawyers can advise you on that.

You may face procurement and commercial issues when buying AI products. Alongside commercial colleagues, your lawyers can also help you navigate to those challenges.

When you contact your legal team, you should explain your aims for the AI solution, what it will be capable of doing, and any potential risks you’re aware of. This will help you to understand, for example, if you need legislation to achieve what you want to do.

It will also help to minimise the risk of your work:

  • being challenged in court

  • having unintended or unethical consequences

  • having a negative impact on the people you want it to benefit

Example legal issues

The following types of issues are designed to help you understand when you might want to consider getting legal advice. They should not be read as real legal advice and their application to any given scenario will depend on the specific facts. You should always consult your organisation’s lawyer.

Data protection

Data protection is a legal issue with potentially serious consequences if the government gets it wrong.

Although your organisation will likely have a data protection officer, and there may also already be data protection experts in your team, your legal team can help you unpick some of the difficult data protection issues that are created by AI.

Refer to the data protection and privacy section for more information.

Contractual issues

Your lawyers will help you draw up the contracts and other agreements for the procurement or licensing of AI tools. There may be special considerations for these contracts, including how to:

  • deal with intellectual property

  • ensure the level of transparency needed to help buyers understand their systems

  • transfer a project to new or successor suppliers

  • assist with the defence against any legal challenge

Contracts for technology services may need to incorporate procedures for system errors and outages that recognise the potential consequences of performance failures.

It’s important that you consider appropriate contractual terms early on because this may, in part, drive decisions on the appropriate route to market. Refer to the buying AI section for more information.

Intellectual property, including copyright

Potential intellectual property issues with AI can be navigated with the help of your lawyers.

You should consider at the outset:

  • which parties will own which parts of any intellectual property generated during the project

  • which parties will have ongoing rights to use any intellectual property that is generated, and on what basis

  • how the balance of risk and liability should be determined between the parties, as this will be relevant to any claims for infringement of third-party intellectual property

Equality issues

Lawyers can help you navigate the equality issues raised by the use of AI in government, such as obligations arising under the Equality Act 2010 and the Public Sector Equality Duty. Conducting an assessment of the equality impacts of your use of AI can also be one way to guard against bias, which is particularly important in the context of AI.

If approached as early as before signing contracts, your legal advisers can help you to ensure the government is fulfilling its responsibilities to the public by assessing the impacts of the technology it’s using.

Public law principles

Public law principles explain how public bodies should act rationally, fairly, lawfully and in compatibility with human rights. They are guidelines for public bodies on how to act within the law.

Many of these public law principles overlap with the ethics set out in this guidance. As a result, your lawyers will likely be able to guide you on how to apply ethical principles based on their knowledge of public law, the court cases that have occurred, and the detail of the judgments.

For example, public law involves a principle of procedural fairness. This is not so much about the decision that is eventually reached but about how a decision is arrived at. The transparency and explainability of the AI tool may well be key in being able to demonstrate that the procedure was fair. Similarly, an inability to determine how AI tools have arrived at their decisions or outputs may introduce risk into the decision-making process.

Public law also considers rationality. Rationality may be relevant in testing the choice of an AI system, considering the features used in a system, and considering the outcomes of the system and the metrics used to test those outcomes.

If you’re considering using AI in decision-making, here public law can also guide you. It can help you determine whether a particular decision should be delegated to a decision maker, rather than letting an AI tool make an automated decision. When operating in a regulated environment, such as a procurement process, automated decision-making or assessments could be subject to legal challenge if procedural fairness, lack of bias and rationality cannot be evidenced.

Human rights

Public authorities must act in a way that is compatible with human rights. It’s possible that AI systems, especially those involving the use of personal data, may in some way affect at least one of an individual’s rights as set out in the European Convention on Human Rights (ECHR). The rights most likely to be impacted are Article 8 (right to a private and family life) and Article 10 (freedom of expression).

Legislation

Sometimes, in order to do something, a public authority needs a legislative framework. Your lawyers will be able to advise you whether your use of AI is within the current legal framework or needs new legislation.

For example, the legislative framework might not allow the process you’re automating to be delegated to a machine, or it might provide for a decision to be made by a particular person.

Practical recommendations

  • Ensure you engage legal professionals at the outset of your AI project. They can help you navigate legal complexities and identify potential legal risks associated with data protection, contractual agreements, intellectual property, equality issues, and compliance with public law principles.

  • Given the potential consequences of mishandling personal data, you should collaborate with legal experts to ensure you comply with data protection regulations and understand how to mitigate risks associated with data privacy and security.

  • Work with legal experts to develop robust contracts and agreements for procuring or licensing AI tools, considering issues such as intellectual property rights, transparency levels, liability distribution, and procedures for addressing system errors or failures.

  • Seek legal advice to determine whether your AI project aligns with existing legislative frameworks or requires new legislation. Understanding legislative constraints helps mitigate the risk of legal challenges and ensures you comply with legislative requirements.

Data protection and privacy

AI-driven technologies offer significant benefits but they also pose the potential risk of harm to individuals and groups if they’re not implemented with specific focus on protecting individuals’ personal data and right to privacy.

Be aware that organisations developing and deploying AI systems must consider the principles of data protection outlined in the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 to minimise the risk of privacy intrusion from the outset.

The UK data protection law applies irrespective of the type of technology used, so its basic principles of compliance will also apply to any AI system. The data protection principles most relevant to the use of AI are:

  • accountability, where that your organisation has clear ownership of risk and responsibility for mitigations and compliance

  • lawfulness, where you have an applicable lawful basis for processing personal data and ensure the processing is lawful under data protection or any other regulation

  • purpose limitation, to define why you’re processing personal data and only process data for that purpose

  • transparency and individual rights, where you’re open about what it uses personal data for, and your users can exercise their information rights

  • fairness, to avoid processing personal data in ways that are detrimental, unexpected or misleading

  • data minimisation, to develop systems that process only the data that is needed for the task at hand

  • storage limitation, so that you don’t accumulate large amounts of personal data for unjustifiably long periods

  • human oversight, to build in human oversight to automated decision-making

  • automated decision-making (ADM), where you consider whether using an automated decision system is appropriate

  • accuracy, where you have steps in place to ensure the accuracy of AI-generated responses and data related to individuals

  • security, to implement appropriate technical and organisational mitigations to protect sensitive and personal data

Data protection and privacy considerations require specialist expertise, so it’s crucial to involve relevant data protection, legal and other information governance professionals in AI projects from the outset to follow data protection by design principles.

Accountability

Accountability is a key principle that establishes ownership of risk, responsibility for mitigations, compliance with legislation, the ability to demonstrate compliance, and high standards for privacy.

When planning AI solutions, you should:

  • make strategic decisions on how any use of AI technology fits with your existing risk tolerance

  • review your risk governance model to establish clear ownership of AI risks at a senior level

  • implement measures to mitigate these risks and test their effectiveness

  • make sure you identify residual risks and align them with your organisation’s risk threshold

  • be collaborative, work transparently and demonstrate how you mitigate risks

  • due to the evolving nature of AI technologies and new regulations, ensure you conduct regular reviews, with a view to making further iterations

  • engage with internal data protection, privacy and legal experts from the outset

Data protection by design is an important component of the UK GDPR risk-based approach. It requires you to integrate data protection safeguards into personal data processing activities throughout the AI product life cycle.

This will ensure that you implement appropriate technical and organisational measures to protect data subject rights, and comply with the data protection principles defined in the UK GDPR and Data Protection Act 2018.

Practical recommendations

Lawfulness and purpose limitation

Before implementing AI solutions, you need to undertake a data protection impact assessment (DPIA). This involves an assessment of data protection and privacy risks, and the implementation of appropriate technical and organisational measures to sufficiently mitigate them.

Article 35(3)(a) of the UK GDPR requires you to undertake a DPIA if your use of AI involves any:

  • systematic or extensive evaluation of personal data aspects based on automated processing, including profiling, on which decisions are made that produce legal or similarly significant effects

  • large-scale processing of special categories of personal data

  • systematic monitoring of publicly accessible areas on a large scale

The Information Commissioner’s Office (ICO) also requires a DPIA if your processing of personal data involves the use of innovative technologies. In your DPIA, you must:

  1. describe the purpose of personal data processing activities
  2. assess the necessity and proportionality of personal data processing
  3. identify all personal data, including special category data, that is being processed, including sources and flows of data
  4. identify the valid lawful basis under Article 6, and any additional special conditions under Article 9 for special category data of the UK GDPR
  5. identify your organisation’s role and obligations as a data controller and whether any data processors are involved
  6. identify the stages when AI processes and automated decisions may have an impact on individuals
  7. seek and document the views of individuals whose personal data is being processed. This includes finding out whether data subjects are aware that this processing is taking place
  8. identify the stages when any human is involved in the decision-making process
  9. consider any potential detriment to individuals due to bias or inaccuracy
  10. document measures and safeguards put in place, and any residual levels of risk posed by the processing

The purpose for which data is collected and used has a significant effect on whether individuals perceive it as being invasive to privacy. A clear and well-defined articulation of this purpose from the outset will guide your deliberations about an applicable, lawful basis and the minimum personal data that is absolutely necessary to deploy the AI service.

AI systems often reuse personal data for new purposes that are different from those for which it was originally collected. This may cause tension with the purpose limitation of the UK GDPR. Repurposing of personal data is only legitimate if a new purpose is compatible with the purpose for which the data was originally collected.

When repurposing personal data, you should consider:

  • whether the new purpose aligns with the data subjects’ expectations

  • what type of personal data is involved

  • what potential impact it will have on data subjects’ interests

  • whether the data controller will need to adopt additional safeguards to ensure fairness and transparency

The DPIA process should identify personal data processing at each stage of the AI life cycle, from design to data acquisition and preparation, training, testing, deployment and monitoring. Although it’s common to characterise AI with large volumes of data, AI systems are able to directly perceive and evaluate their environment, and adapt to the data received. You should not underestimate AI’s interactive qualities, such as its ability to collect new data in real time from touchscreens and audiovisual inputs and adapt its responses and subsequent functions based on these inputs.

When mapping personal data flows, you should identify the geographic location of each distinct processing activity because the processing of data outside the United Kingdom will increase the risk of losing the protection of UK data protection laws. Data controllers may need to bring in additional safeguards, such as international data transfer agreements, if personal data is being processed in jurisdictions where the data protection regime is not deemed to be adequate and transfers of personal data are restricted under Article 46 of the UK GDPR.

If your assessment indicates that there’s a high risk to the data protection rights of individuals, and that you’re unable to sufficiently reduce these risks despite mitigating actions, you must consult the ICO before you can start processing personal data.

Practical recommendations

  • When building your team, seek support from data compliance professionals, including data protection, legal and privacy experts.

  • Identify data processing operations and their purpose, and map personal data sources and flows.

  • Determine whether personal data is necessary for each activity, and whether you’re processing special category data or children’s data.

  • Identify the applicable lawful basis of your data processing and assess data protection and privacy risk through DPIAs and legitimate interest assessments.

  • If data protection and privacy risks remain high even after mitigations, consult with the ICO.

  • Identify any processing outside the UK to take additional safeguards to protect personal data in jurisdictions where the data protection regime may not be adequate.

  • Assess any changes in the purpose of your AI system and make sure your AI system remains compliant and lawful.

Transparency and individual rights

In addition to the ethical reasons for seeking transparency, organisations need to be transparent about how they process personal data in an AI system so that individuals can effectively exercise the rights granted to them by the UK GDPR.

The UK GDPR requires data controllers to:

  • provide information to users in a concise, transparent, intelligible and easily accessible form using clear and plain language

  • be transparent about the purpose for processing personal data, retention periods and third parties involved in the processing activity

  • be transparent about the existence of automated decision-making, providing meaningful information about the logic involved, and about the significance and envisaged consequences for the data subject of processing in this way

  • provide a clear explanation of the results these systems produce

  • uphold individuals’ rights, including the right of access to the personal data that you hold on them, and have a simple and clear process to exercise their right to correction and to object to the processing of their personal data at any time

The transparency principle applies to personal data collected from all sources, including the interactive qualities of AI systems that have the ability to collect new data, which may include text and audiovisual inputs. For example, if you’re using facial recognition technology for public area monitoring, you need to be transparent by clearly informing data subjects. You can do this with clear signage and information about relevant data controllers, what information is collected, the purpose and legal basis of processing, and for how long the data is kept.

Practical recommendations

  • Explain your system in plain English.

  • Be transparent about the purpose for processing personal data, retention periods and third parties involved in the processing activity.

  • Be transparent about the existence and nature of automated decision-making, using the Algorithmic Transparency Recording Standard Hub where required or on a voluntary basis as best practice.

  • Provide a clear explanation of the results these systems produce, following guidance such as the ICO’s explaining decisions made with AI.

Fairness

Fairness in processing is another principle under the UK GDPR which applies to AI systems that process personal data. In the context of data protection legislation, fairness means that ‘you should only process personal data in ways that people would reasonably expect and not use it in any way that could have unjustified adverse effects on them’.

DPIAs are the main tool to help you consider the risks to the rights and freedoms of individuals, including the potential for any significant social or economic disadvantage. DPIAs also help demonstrate whether your processing is necessary to achieve your purpose, and if they are proportionate and fair.

The Responsible Technology Adoption Unit (RTA) in DSIT published the results of its public attitudes to data and AI survey in December 2023. This report found that people’s comfort with the use of AI greatly depends on the specific context. Perceptions of the need for AI governance also vary considerably by sector, with a substantial proportion of the public prioritising careful management of AI used in healthcare, the military, or in banking and finance.

You must make sure that AI systems do not process personal data in ways that are unduly detrimental, unexpected or misleading to the individuals concerned. If AI systems infer data about people, you need to ensure that the system is accurate and not discriminatory. You need to uphold the right to be informed for individuals whose personal data is used at any stage of the development and deployment of AI systems. This is part of fulfilling the transparency and fairness principles.

Data protection aims to protect individuals’ rights and freedoms with regard to the processing of their personal data, not just their information rights. This includes the right to privacy but also the right to non-discrimination. For example, computer vision technologies such as facial recognition have raised concerns due to the risk of errors in matching faces. This technology has proven to be less accurate when used on women and people of colour, producing biased results. Ultimately, this can create discrimination, raising fundamental rights concerns because of the disadvantage to some individuals whose facial images are captured and processed.

People’s facial images constitute biometric data. This is personal data because it’s the result of specific technical processing related to physical, physiological or behavioural characteristics of a natural person, which can confirm the unique identification of the person. Facial images may fall into the special categories of personal data because they’re likely to reveal sensitive characteristics such as racial or ethnic origin, and so require enhanced protection and additional safeguards.

Biometric data is also considered special category data when processed for the purposes of identification. You must ensure that the technologies used to capture and process this data are overt, accurate, proportionate, fair and deploy a narrow ‘zone of recognition’. For example, if someone walks past a camera and their image does not meet the threshold for a potential match, their data needs to be promptly deleted.

Practical recommendations

  • Identify the risks to the rights and freedoms of individuals through DPIAs and assess whether your processing is necessary, proportionate and fair to achieve your purpose.

  • Use the ICO’s AI and data protection risk toolkit to reduce the risks to individuals’ rights and freedoms.

  • Mitigate risks using the ICO’s guidance on fairness, bias and discrimination in AI systems.

  • Provide users with clear reassurance that you’re upholding their right to privacy, including simple processes to exercise their rights in clear privacy notices.

  • Address any objections from users, including those related to solely automated decisions, or where there’s a significant legal impact, by implementing safeguards such as meaningful human intervention, or an effective process to obtain and consider individuals’ views and corrections of factual errors.

Data minimisation

The data minimisation principle requires you to identify the minimum amount of personal data you need to fulfil your purpose, and to only process that information and no more. This does not mean that AI tools should not process personal data, but if you can achieve the same outcome by processing a smaller amount of personal data then the data minimisation principle requires you to do so.

Retaining data that is not strictly necessary is a risk to the individuals from whom the data is derived. Excluding irrelevant data prevents algorithms from identifying correlations that lack significance or are coincidental. There are a number of techniques that you can adopt to develop AI systems that process only the data you need while still remaining functional.

For example, you can consider using privacy-enhancing technologies (PETs) to offer stronger protections and preserve data privacy while enabling the effective use of data. Some PETs provide new tools for anonymisation, and some enable collaborative analysis on privately-held data sets, allowing data to be used without disclosing copies of the data.

PETs are multipurpose, so you can use them to reinforce data governance choices, or as tools for data collaboration and greater accountability through audits. A data-focused example solution is to create ‘synthetic data’. This is an artificial data set that does not include any actual data on ‘real’ individuals but mirrors in characteristics and proportional relationships all statistical aspects of the original data set.

You must be aware that advanced AI models can sometimes re-identify individuals by correlating multiple pseudonymized data points. The DPIA process must explicitly assess this re-identification risk.

Practical recommendations

  • Justify your use of personal data, using your DPIA to think about the problem you’re solving so that you settle with the minimum personal data that’s required. Less personal data means less risk.

  • Reduce the risk of individuals being identified through the processing of their personal data by using appropriate de-identification techniques, such as redaction, pseudonymisation and encryption.

  • Refer to the ICO guidance on privacy-enhancing technologies (PETs).

Storage limitation

The UK GDPR states that you should only hold personal data as long as you can reasonably justify it for the purpose of your processing, and that you should not retain personal data longer than you need it. You must consider:

  • what personal data the technology will hold

  • why you have it and what it’s used for

  • whether you can justify keeping it for that period of time

You should map all personal data flows through every stage of development, testing and deployment, and utilise data minimisation, anonymisation techniques and eventual deletion to irreversibly transform or remove personal data.

Practical recommendations

  • Use data minimisation and anonymisation techniques as needed to remove or irreversibly transform personal data where possible.

  • Be transparent about the length of personal data retention in privacy notices.

Human oversight

It is possible to use AI systems for automated decision-making, which is where the system makes a decision automatically without any human involvement. However, this may infringe on the UK GDPR. Article 22 currently prohibits decisions based solely on automated processing that have legal or similarly significant consequences for individuals. Services using AI that affect a person’s legal status or their legal rights must only use AI to support decisions that must be made by a human decision maker.

AI systems need to introduce deliberation processes into all stages of the life cycle so that the abilities of humans and machines are combined to reach the best results when performing tasks. The human input must still be meaningful. Several factors determine how much human involvement there should be in AI systems, such as the complexity of the output, its potential impact, and the amount of specialist human knowledge required for specialist areas such as legal and medical.

Practical recommendations

  • Design, document and assess the stages when meaningful human review processes are incorporated and what additional information will be taken into consideration when making the final decision.

  • Use the ICO guidance on automated decision-making under UK GDPR for more clarity on types of decisions that have a legal or similarly significant effect.

Accuracy

Accuracy in the context of data protection requires that personal data is not factually incorrect or misleading, and, where necessary, is corrected, deleted and kept up to date without delay.

You should not treat AI outputs as factual information about the individual, but instead consider these as a statistically-informed guess. You also need to factor in the possibility of outputs being incorrect and the impact this may have on any decisions.

You need to make it explicit that the outputs of your AI systems are statistically informed guesses rather than facts, including information about the source of the data and how the inference has been generated.

Automated decision-making (ADM)

Definition and examples

Automated decision-making (ADM) is the process of making a decision by automated means using algorithms or computer systems. Its use is increasing quickly to process and make decisions on a large scale. ADM can be used to make decisions based on pre-defined rules, or can be powered by AI and machine learning.

Decisions made by automated means do not always affect individuals, as in the example of traffic signal optimisation systems that automatically adjust the timing of traffic lights at intersections. Here, the system makes decisions about traffic patterns and not about people.

Some automated decisions may affect individuals without using their personal data, such as dynamic transport pricing systems which adjust ticket prices based on demand, timing and popularity. Both of these examples have lower risks to individuals.

Higher risk applications of automated decision-making are when these decisions may have legal or similar significant effects on individuals. An example of this is when automated decisions are used to assess eligibility for state benefits, as approval or denial of financial support can directly affect a person. These decisions can have legal consequences, such as appeals or investigations. Such automated decisions use personal data and have significant impact on individuals.

Higher risk applications of ADM that process personal data and make decisions with legal or similarly significant impact on individuals are subject to the provisions of the UK data protection legislation.

Solely automated systems are typically used for routine, repetitive tasks while automated decisions with human oversight are applied in more complex situations that may have significant consequences for data subjects. Profiling, which is a form of automated processing of personal data that makes predictions based on characteristics and patterns of behaviours with a margin of error, may be used to inform human decisions. Fairness, transparency and accountability need to be key considerations for profiling to be lawful and ethical.

Automated decision-making can be useful for service providers and users by speeding up processes and reducing backlogs, but there are potential risks that need to be taken into consideration.

The use of automated decision-making, how it works and how it affects people is not always obvious. The decisions made by automated means may lead to significant adverse effects for some individuals.

It is very important to consider whether using an automated decision system is appropriate in your context. A process won’t be considered fully automated if someone interrogates the decision-making, weighs up and interprets the result with the discretion to alter it before applying it to the individual. If further automated processing such as profiling was used at any stage, that could reduce the range of decisions to the extent that human involvement could never be meaningful.

The extent to which human engagement is required for your context depends on factors such as the complexity of the system’s output, the potential impact on the individual, and whether specialist expertise, such as legal or medical knowledge, is required. Simply applying the decision taken by the automated system, without meaningful human involvement, interrogation and consideration, is a token gesture and does not constitute meaningful human involvement.

Individuals have the right to transparency and fairness in how decisions that affect them are made, especially when those decisions have legal or similarly significant effects. Additionally, automated decision-making carries significant risks to accuracy, particularly when decisions are based on incomplete, outdated, or biased data. In such cases, it is essential that a human is meaningfully involved before a final decision is made.

Data (Use and Access) Act 2025 and the UK GDPR

Section 80 of the Data (Use and Access) Act 2025 has introduced changes to the Article 22 provisions of the UK GDPR.

According to the Data Act, a solely automated decision is defined as a decision made entirely through automated processing without any meaningful human involvement. This decision will also have either a legal effect, such as the approval or denial of a benefit, contract, or service, or a similarly significant impact, such as affecting someone’s financial situation, access to healthcare, or employment opportunities. The Data Act permits these automated decisions as long as safeguards are provided for the individuals affected where they:

  • are informed by the data controller about the existence of automated decision-making

  • receive meaningful information from the data controller about the logic involved, the significance, and the envisaged consequences for the data subject

  • request human intervention

  • express their point of view where the decision is necessary for a contract or based on explicit consent

  • contest the decision and obtain an explanation where the decision is necessary for a contract or based on explicit consent

The Act restricts solely automated decision-making using special categories of personal data as described in Article 9(1) of the UK GDPR. This includes personal data that relates to health, employment, political belief, race, religion and gender, unless:

  • the individual has explicitly agreed to the automated decision (given explicit consent)

  • there are reasons of substantial public interest

  • the automated decision is required or allowed by law, and the processing meets specific legal safeguards listed above

The ethics, transparency and accountability framework for automated decision-making published by DSIT provides guidance to help you with the safe, sustainable and ethical use of automated or algorithmic decision-making. It provides definitions, examples, risks and a framework for responsible and fair use. The Information Commissioner’s Office has also published useful guidance in relation to compliance with the data protection legislation, which can be found at what is ADM?

Automation Bias

Automation bias describes the potential for individuals involved in augmented assisted decision-making to rely too heavily on the decisions recommended by the automated system, and a reluctance to challenge decisions that they believe may be inaccurate.

This bias can have a negative impact on accuracy and safety for augmented assisted decision systems. It can erode the value of having a human in the loop and the human operator’s ability to have meaningful control over a system.

As augmented assisted decision-making is used in areas which may have more significant consequences, it is necessary to ensure that human interactions are meaningful, and that the risk of automation bias is understood and mitigated. Over-reliance by a human decision-maker on an AI-generated recommendation or prediction may render the decision susceptible to legal challenge, particularly if it can be established that the human has failed to exercise any real judgment of their own or has not understood how the AI-generated recommendation or prediction was arrived at.

There are multiple human, contextual and design factors that may increase the risk of automation bias. These include:

  • human factors such as knowledge gaps in human reviewers, or a lack of real-world experience

  • contextual factors such as time pressure and task complexity

  • design factors such as the omission of confidence scores

The risk of automation bias may be mitigated in some instances through design and process changes, such as by displaying the confidence of automated decisions and recommendations, or prompts to ensure ongoing engagement with tasks. Additional confirmations and notifications of human accountability in the process can also help.

Adequate mitigations will depend on the specific application of ADM in your process. Your teams should assess to ensure mitigations are effective. If they are not, you will need to decide whether ADM of any kind is appropriate for your project.

Practical recommendations

  • Consider whether using an automated decision system is appropriate in your context.

  • Provide clear information explaining whether  personal data is used and whether automated decisions are made, especially if the automated decision might impact outcomes relating to an individual. The Algorithmic Transparency Recording Standard Hub is a mandatory tool for government organisations that helps with being open about automated decisions.

  • Provide simple means for individuals to submit feedback, raise objections and request human intervention on automated decision making processes to engage with decisions that may affect them.

  • Implement meaningful human intervention or an effective process to obtain and consider individuals’ views and the correction of factual errors. The human should weigh up and interpret the result of an automated recommendation with the discretion to alter it.

  • Be mindful of potential biases and inaccuracies in data and algorithms. Involve diverse teams in development and take appropriate steps to assess and analyse any impact on those with protected characteristics.

  • Where necessary to satisfy obligations under the Equalities Act 2010 (or equivalent legislation in Northern Ireland) and undertake ethical risk assessments

  • Consider regular audits and reviews of automated systems to identify potential biases or errors within the automated decision-making systems.

  • Refer to the ethics, transparency and accountability framework for automated decision-making, which provides a framework for the ethical and safe use of ADM in the public sector. The framework emphasises testing, fairness, responsibility, data protection, transparency, legal compliance, and future-proofing.

  • Refer to the Information Commissioner’s Office guidance, with specific focus on the legal requirements of the UK GDPR, Data (Use and Access) Act 2025 regarding ADM and profiling. Be mindful of recent changes in the legislation and look out for upcoming guidance from the Information Commissioner’s Office.