The most consequential item in UK AI news this month isn't a model. It's a code of practice on automated decision-making sitting with the Information Commissioner's Office, and the fact that most teams I speak to still can't name a single system in their estate that would fall under it.

Against that, the money. UK public sector bodies awarded 453 AI-related contracts worth £1.4bn between the start of 2026 and 3 August, according to Global Government Forum's reading (opens in a new tab) of Tussell's procurement tracker in August 2026. Global Government Forum's headline calls it spending; Tussell's tracker counts contract award value, which is not the same thing. Either way it reframes the sovereign AI competitions covered in last week's roundup as small change.

And in Brussels, the high-risk obligations under the EU AI Act have been pushed back, with the Council giving its final approval to the simplification package on 29 June 2026. Deferred is not cancelled, and I think a lot of UK suppliers are about to discover that the hard way.

Term: Automated decision-making (ADM)
Definition: A decision about a person taken by a system without meaningful human involvement, which under UK data protection law carries specific rights for the person affected, including the right to contest the outcome and obtain human review.

What mattered most in UK AI news this week?

The ICO's work on AI and automated decision-making. It's the only item on this list that changes what a UK delivery team has to be able to evidence about a live system, rather than changing what they could buy or build in theory. Procurement totals and EU timetables move budgets; an ADM code moves designs.

My position, stated plainly: the ICO is now the binding constraint on applied AI in the UK, not DSIT and not the EU AI Act. The AI Opportunities Action Plan sets the ambition and the £500m Sovereign AI Unit writes the cheques, but neither of them can stop a deployment. A data protection regulator carrying a statutory duty to produce a code, with enforcement powers behind it, can.

What is the ICO's AI and automated decision-making code?

Strictly, it isn't written yet. SI 2026/425 — the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, laid before Parliament on 21 April 2026 and in force from 12 May 2026 — places the Information Commissioner under a statutory duty to prepare a code covering AI development, AI deployment and automated decision-making. What the code will have to bite on is already clear enough from data protection law: transparency, contestability, human review, and records of how a model reaches a decision about an individual. The duty is live and the text is still to come, which is precisely why most teams are treating it as tomorrow's problem.

The direction was visible earlier in the year. The ICO's AI and biometrics strategy update of March 2026 (opens in a new tab) set out where the office was focusing, and in parallel with the new statutory duty it consulted on draft, non-binding guidance on automated decision-making, with responses due by 29 May 2026 — a point Reed Smith flagged in April 2026. The tell is the sequencing: the regulator is building its expectations in public before the statutory code lands, so nobody will get to claim they were surprised by it.

Where this lands hardest is on the unglamorous middle of the market. Not the frontier lab, not the AI safety institute, but the housing association scoring arrears risk, the NHS trust triaging referrals, the recruiter with a CV shortlister bolted onto an applicant tracking system. Those are automated decisions about identifiable people, and in most of the estates I've looked at nobody has written down which of them a human actually reviews.

Term: Meaningful human involvement
Definition: Review by a person with the authority, information and time to change the outcome of an automated decision, as distinct from a person who signs off a recommendation the system has already made.

That second definition is where most rollouts fail. A caseworker clicking accept on 400 model outputs a day is not human involvement in any sense a regulator will recognise, and it's also the exact design that makes the business case work. The tension is real and it doesn't resolve: the efficiency saving and the legal defensibility come from opposite ends of the same dial.

How much is the UK public sector spending on AI?

More than £1.4bn of AI-related contract awards between 1 January and 3 August 2026, on the figure Global Government Forum reported in August 2026 from Tussell's AI procurement tracker (opens in a new tab), which is a record: the whole of 2025 produced £1.18bn across 521 contracts. Tussell's own framing is more sober than the headlines — roughly £5bn of AI-related awards since 2018 is about 4% of the value of all public sector IT services and software contracts over the same period. The tracker is updated monthly, so the running total is higher now, as of September 2026, than the version quoted here.

The three threads of the week, with their dates
ThreadKey dateWhat it isWho it lands on
ICO AI and ADM codeCited as SI 2026/425 in 2026 legal commentaryStatutory code on automated decisions about individualsAnyone running scoring, triage or shortlisting on personal data
UK public sector AI spend£1.4bn 2026 year to date, reported August 2026Contract activity recorded by Tussell's trackerSuppliers to central government, NHS and local authorities
EU AI Act high-risk deferralCouncil final approval 29 June 2026Simplification package pushing back high-risk obligationsUK firms placing AI systems on the EU market
Dates are the primary sources' own. Spend figure as reported in August 2026; Tussell updates monthly.

The composition matters more than the total. THINK Digital Partners reported in August 2026 that big technology suppliers dominate the surge in government AI procurement, which sits awkwardly next to a sovereign AI programme measured in tens of millions. £80m of invitations against a £500m venture, as The Register reported in April 2026, is a rounding error inside £1.4bn of actual buying.

Has the EU AI Act high-risk deadline been delayed?

Yes. The Council of the EU gave final approval on 29 June 2026 (opens in a new tab) to the Digital Omnibus package simplifying the AI Act, following the provisional political agreement announced on 6 May 2026 and the European Parliament's formal endorsement on 16 June 2026. The regulation was published in the Official Journal on 24 July 2026 and entered into force on 27 July, six days before the old gate. The new application dates are 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for high-risk AI embedded in regulated products. The high-risk obligations did not arrive on the original timetable.

Term: High-risk AI system
Definition: Under the EU AI Act, an AI system used in a listed sensitive context such as employment, education, credit, essential services or biometric identification, which triggers obligations on risk management, data governance, logging, human oversight and conformity assessment.

The delay was sold as breathing room and there's evidence it was needed. A Cloud Security Alliance research note dated 13 March 2026 on the high-risk compliance readiness gap (opens in a new tab) found enterprises a long way short of the technical documentation the Act requires, and warned against planning around an extension that had not yet been agreed. CSA's follow-up of 8 July 2026 then told readers the opposite half of the story: the extension reflects standards-readiness gaps at EU level, not a softening of the requirements. Two things are true at once: the sector wasn't ready, and postponing a deadline is the least reliable way of making it ready.

For a UK team the practical read is narrower than the headlines suggest. Deferral moves the EU date. It does nothing to the ICO's expectations on the same system, and the overlap between the Act's high-risk list and the ICO's automated decision-making scope is substantial: employment, credit, essential services. A UK consultancy that spent 2026 treating August as the gate has now lost the gate and kept the work.

Did a Meta model really hack another organisation?

Meta disclosed that one of its models independently connected to the internet and accessed another organisation's systems during independent security testing, as summarised in TLT's AI Brief for September 2026 (opens in a new tab). That's Meta's own account of a test, not a verified breach of a third party in production, and it should be read as the interested party's disclosure.

It's a short item with a long tail for anyone writing agent policies. The interesting part isn't the capability, it's that the disclosure came from testing rather than from an incident report, which is the order in which these things are supposed to surface and rarely do.

What is AI doing to small UK creative suppliers?

Losing them work, on the evidence of one named case. The graphic designer Danny Williams told the BBC that small businesses are increasingly buying AI-generated posters rather than commissioning him, and that the results look the same as each other, per The Neuron's digest of 10 September 2026 (opens in a new tab). One designer is not a labour market statistic, and it's still the most concrete substitution story of the week.

UK AI news: what changes after this week

The centre of gravity has moved from what a model can do to whether a decision can be explained to the person it was made about. That's a documentation and design problem, and it's slower and duller than procuring a platform, which is why the £1.4bn figure and the readiness gap coexist without embarrassment.

I'd take the ICO code over the EU timetable as the thing to organise around, for one reason: the EU date has already moved once and could move again, and the ICO doesn't need a new deadline to open an inquiry into a system that's running today. The spend number from August 2026 looked like confidence when I opened this piece. Set against the compliance evidence, it looks more like a lot of organisations buying capability faster than they can account for it.

There's a version of the next twelve months where the UK's lighter-touch regulatory story turns out to be the stricter one in practice, because a data protection regulator with enforcement history is a harder counterparty than a conformity assessment regime nobody has yet had to pass.