Voice AI and Article 22D: How UK ADM Rules Could Change
In short
Article 22D of the UK GDPR lets the Secretary of State refine the automated decision-making rules by regulation, without new primary legislation. Dilr Voice explains what the power permits, the affirmative parliamentary procedure any change must clear, and how enterprises can build voice AI governance that survives a tightening of the regime.
DE
Dilr.ai EngineeringEngineering team
Published Aug 22, 2026Read 12 min
Roughly 88% of enterprises now use AI somewhere, yet only about 6% capture material EBIT impact, according to McKinsey's State of AI (November 2025). Voice is where a large share of that automation now touches a member of the public directly, deciding who gets routed to a human, whose claim is fast-tracked, which caller is offered a payment plan. In the United Kingdom, those decisions sit under a data-protection regime that was rewritten in 2026, and the rewrite left a lever behind that most compliance teams have not yet noticed.
That lever is Article 22D of the UK GDPR. It does not tell you what to do today. It tells the Secretary of State what they can change tomorrow, by regulation, without passing a new Act. For a governance owner that is a subtle but important fact: the automated decision-making rules you are building against right now are a floor set by the current text, and Article 22D is the mechanism by which that floor can be raised.
This guide is the horizon-scanning companion to the current-regime explainer. It does not re-teach the Article 22A definition or the four Article 22C safeguards in full; those are covered in our guide to UK GDPR Articles 22A to 22D for voice AI. Instead it answers the forward-looking question a serious voice AI programme has to answer: what does Article 22D permit, what process would any change have to clear, and how do you build a governance model that survives a tightening of the regime rather than being caught flat by it.
This guide is shipped by the team behind Dilr Voice, enterprise voice AI built for regulated deployments. Or see DATS, our five-stage AI consulting system.
What is Article 22D of the UK GDPR?
Article 22D is the regulation-making power inside the UK GDPR's automated decision-making chapter. When the Data (Use and Access) Act 2025 replaced the old Article 22 with Articles 22A to 22D on 5 February 2026, it added Article 22D so the Secretary of State can refine, by regulation, what counts as meaningful human involvement, a similarly significant effect, and the required safeguards. It sets no duty of its own; it is a dial on the other three.
The distinction matters because it changes what "keeping up with the law" means for a voice AI owner. Articles 22A, 22B and 22C are the visible rules, and our Article 22A to 22C explainer walks through each. Article 22D is the quiet article that determines how those visible rules can move without a Bill going through Parliament from scratch. If you monitor only the primary text, you will miss the pipeline through which the regime actually changes. That pipeline is the subject of this post, and it is why a serious UK voice AI compliance posture needs a horizon-scanning habit, not just a point-in-time sign-off.
What power does Article 22D give the Secretary of State?
Article 22D hands the Secretary of State three regulation-making heads. First, they may define, for cases described in regulations, whether there is or is not meaningful human involvement in a decision. Second, they may define whether a description of decision has a similarly significant effect on a person. Third, they may make provision about the safeguards required under Article 22C, including measures beyond the four already listed. Each head reshapes the reach of the rules without touching the primary text.
The first head is the one a voice AI team should watch most closely, because "meaningful human involvement" is the switch that decides whether your call flow is even in scope. The statute puts the power plainly:
"The Secretary of State may by regulations provide that, for the purposes of Article 22A(1)(a), there is, or is not, to be taken to be meaningful human involvement in the taking of a decision in cases described in the regulations."
That is Article 22D(1) of the UK GDPR, as inserted by the Data (Use and Access) Act 2025. Read it carefully: a future regulation could say that a particular pattern of human review does, or does not, count as meaningful. A design your legal team signs off as compliant today, a supervisor glancing at a dashboard, say, could be named in regulations as insufficient. The power runs in both directions, which is exactly why a voice AI programme cannot treat the current line as fixed. The pipeline from power to enforceable rule runs through several gates, shown below.
How an Article 22D regulation becomes an enforceable ruleThe path a change to the UK automated decision-making rules must travel under Article 22D.
Can the automated decision-making rules change without a new Act of Parliament?
Yes, and that is the whole point of Article 22D. A change to what counts as meaningful human involvement, a similarly significant effect, or the required safeguards can be made by regulation rather than by a fresh Act. That is faster and lighter than primary legislation. It is not, however, unchecked: Article 22D(5) states that "Regulations under this Article are subject to the affirmative resolution procedure", which is a meaningful constitutional brake.
The affirmative procedure means a draft of the regulations must be laid before Parliament and approved by a resolution of each House before it can become law, unlike the negative procedure where an instrument takes effect unless Parliament objects. In practice the Joint Committee on Statutory Instruments scrutinises the draft to confirm it stays within the powers the parent Act granted, and both the Commons and the Lords must vote it through. So the regime can tighten, but not silently and not overnight. There is one further limit worth knowing: Article 22D(4) provides that regulations made about safeguards "may not amend Article 22C", so the Secretary of State can supplement the safeguard baseline but cannot rewrite the article itself. For a compliance owner mapping this against the right to object and the wider UK voice AI compliance picture, the takeaway is that change is procedural and visible, which is precisely what makes it trackable.
Have any Article 22D regulations been made yet?
Not as of this writing. As at 22 August 2026, no regulations had been made under Article 22D; the legislation.gov.uk text of the article records only the Data (Use and Access) Act substitution that created it, and no substantive Article 22D instrument was in force. The power exists and is live, but the horizon is currently open. That is a reason to build ahead of it, not a reason to ignore it.
Regulatory intent, though, is already visible through the Information Commissioner's Office. The ICO ran a consultation on draft guidance for automated decision-making and profiling under the reformed regime, which closed on 29 May 2026, and it is finalising that guidance now. Guidance is not the same as an Article 22D regulation: the ICO interprets and enforces the law, it does not make the secondary legislation. But the consultation is the clearest current signal of where the regulator wants the meaningful-involvement and safeguard lines to sit, and it is the document a voice AI governance owner should read alongside the ICO's automated decision-making guidance and the related controls in our guide to consent withdrawal mid-call. When we run an AI placement diagnostic, this is exactly the kind of live regulatory signal we map against a client's call flows.
Why should enterprises treat the current ADM regime as a floor, not a ceiling?
Because Article 22D makes the current regime the least it will ever ask of you, not the most. The Article 22C safeguards are a baseline the Secretary of State can supplement but, under Article 22D(3), cannot reduce below what the primary article sets. A programme built to sit exactly on today's line is designed to fail the first tightening. A programme built with headroom absorbs a change as a configuration update, not a crisis.
This is not abstract. Consider a voice AI collections agent that offers a repayment plan based on a solely automated affordability score. Under the current text, a genuine human review before the offer is finalised may take the decision out of the solely-automated category. If a future Article 22D regulation specified that a reviewer must have the authority and information to change the outcome, and must actually consider it, a rubber-stamp step would no longer qualify. The firm that already designed real human authority into the loop changes nothing. The firm that designed the minimum viable review has to rebuild under time pressure. Our guidance to clients, reflected in the DATS methodology and our approach to placing AI in regulated workflows, is consistent: engineer to the plausible ceiling of the safeguards, keep the delta between your build and the statutory floor documented, and hold it under a named accountable owner such as your data protection officer, so you can prove headroom on demand.
How should you build voice AI governance that survives an Article 22D change?
Build for the power, not just the present text. Four practices carry it. First, keep a horizon-scanning register for the Article 22D power, ICO guidance, and any laid or made regulations, with a named owner. Second, make human-review thresholds and consent logic configurable, so a definitional change becomes a settings change. Third, document the delta between your current build and a plausible tightening. Fourth, confirm your voice AI vendor can reconfigure the decision boundary when the rules move.
That last practice is where platform choice becomes a governance question rather than a features question. A voice AI stack that treats "route to a human" and "meaningful human involvement" as the same thing will not survive a regulation that pulls them apart. When you evaluate voice AI agents from vendors such as Vapi, Retell AI or PolyAI, and telephony layers such as Twilio underneath them, the question to ask is not only "can it detect intent" but "can we redraw where the automated decision ends and human authority begins, and evidence it, without a rebuild". The governance-readiness ladder below is the sequence we take clients through in an AI execution office engagement.
The Article 22D governance-readiness ladderEach rung is a control a voice AI programme can put in place before any regulation is made.
What is the best way to prepare for a moving ADM regime in 2026?
The best way to prepare in 2026 is to treat automated decision-making governance as a living control tied to a named owner, not a one-off legal opinion filed after go-live. The strongest approach combines three things: a monitored horizon-scan of the Article 22D power and ICO guidance, a voice AI architecture where the human-involvement boundary is configurable and evidenced, and a documented delta between your build and the statutory floor. No single tool delivers all three.
To be clear about where the market sits, no voice AI platform "solves" Article 22D, because most of the work is organisational rather than technical: the register, the ownership, the decision-point mapping and the rehearsal are yours to run whatever platform you buy. A capable general-purpose builder such as Vapi or Retell AI can be the right choice when your team owns the governance layer and wants maximum flexibility. A managed, regulation-aware deployment, which is where Dilr Voice and the DATS methodology focus, tends to win when you would rather buy the governance scaffolding than build it. The right answer depends on whether you have the in-house compliance engineering to maintain the scaffolding yourself.
Does Article 22D let the government weaken the safeguards?
Not the core safeguards. Article 22D(3) lets the Secretary of State add measures beyond the four in Article 22C and specify steps that will not count as satisfying them, which raises rather than lowers the bar. Article 22D(4) states that safeguard regulations "may not amend Article 22C", and every such regulation must clear the affirmative procedure. The government can tighten the safeguards; it cannot quietly delete the baseline rights a person holds over a solely automated decision.
How is Article 22D different from the EU AI Act approach?
Both regimes reserve detail to secondary rules, through different machinery. The UK uses regulations under Article 22D, made by the Secretary of State and subject to Parliament's affirmative procedure, to refine its automated decision-making rules. The EU AI Act relies on delegated and implementing acts at Commission level for its high-risk obligations. For a voice AI operator in both markets, that means two change-tracking feeds: Article 22D and ICO guidance for the UK, the Commission's acts for the EU.
Build voice AI that survives the next rule change.
30-min scoping call · No deck · Confidential. We will tell you where your automated decision boundary is exposed, and how to make it configurable before Article 22D moves.
Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.
voice AI Article 22DUK GDPR automated decision-making regulationsSecretary of State ADM powersDUAA automated decision rulesvoice ai compliance redditbest voice ai governance 2026Dilr Voice
Questions this article answers
What is Article 22D of the UK GDPR?
Article 22D is the regulation-making power inside the UK GDPR's automated decision-making chapter. When the Data (Use and Access) Act 2025 replaced the old Article 22 with Articles 22A to 22D on 5 February 2026, it added Article 22D so the Secretary of State can refine, by regulation, what counts as meaningful human involvement, a similarly significant effect, and the required safeguards. It sets no duty of its own; it is a dial on the other three.
What power does Article 22D give the Secretary of State?
Article 22D hands the Secretary of State three regulation-making heads. First, they may define, for cases described in regulations, whether there is or is not meaningful human involvement in a decision. Second, they may define whether a description of decision has a similarly significant effect on a person. Third, they may make provision about the safeguards required under Article 22C, including measures beyond the four already listed. Each head reshapes the reach of the rules without touching the primary text.
Can the automated decision-making rules change without a new Act of Parliament?
Yes, and that is the whole point of Article 22D. A change to what counts as meaningful human involvement, a similarly significant effect, or the required safeguards can be made by regulation rather than by a fresh Act. That is faster and lighter than primary legislation. It is not, however, unchecked: Article 22D(5) states that "Regulations under this Article are subject to the affirmative resolution procedure", which is a meaningful constitutional brake.
Have any Article 22D regulations been made yet?
Not as of this writing. As at 22 August 2026, no regulations had been made under Article 22D; the legislation.gov.uk text of the article records only the Data (Use and Access) Act substitution that created it, and no substantive Article 22D instrument was in force. The power exists and is live, but the horizon is currently open. That is a reason to build ahead of it, not a reason to ignore it.
Why should enterprises treat the current ADM regime as a floor, not a ceiling?
Because Article 22D makes the current regime the least it will ever ask of you, not the most. The Article 22C safeguards are a baseline the Secretary of State can supplement but, under Article 22D(3), cannot reduce below what the primary article sets. A programme built to sit exactly on today's line is designed to fail the first tightening. A programme built with headroom absorbs a change as a configuration update, not a crisis.
How should you build voice AI governance that survives an Article 22D change?
Build for the power, not just the present text. Four practices carry it. First, keep a horizon-scanning register for the Article 22D power, ICO guidance, and any laid or made regulations, with a named owner. Second, make human-review thresholds and consent logic configurable, so a definitional change becomes a settings change. Third, document the delta between your current build and a plausible tightening. Fourth, confirm your voice AI vendor can reconfigure the decision boundary when the rules move.
What is the best way to prepare for a moving ADM regime in 2026?
The best way to prepare in 2026 is to treat automated decision-making governance as a living control tied to a named owner, not a one-off legal opinion filed after go-live. The strongest approach combines three things: a monitored horizon-scan of the Article 22D power and ICO guidance, a voice AI architecture where the human-involvement boundary is configurable and evidenced, and a documented delta between your build and the statutory floor. No single tool delivers all three.
Does Article 22D let the government weaken the safeguards?
Not the core safeguards. Article 22D(3) lets the Secretary of State add measures beyond the four in Article 22C and specify steps that will not count as satisfying them, which raises rather than lowers the bar. Article 22D(4) states that safeguard regulations "may not amend Article 22C", and every such regulation must clear the affirmative procedure. The government can tighten the safeguards; it cannot quietly delete the baseline rights a person holds over a solely automated decision.
DE
Dilr.ai Engineering
Engineering team
Compliance
Deploy voice AI without failing an audit
Dilr Voice ships per-country TCPA and GDPR rules, and the UK AI compliance changelog tracks ICO, FCA, and EU AI Act changes as they land.