THINK Digital Partners this week carried an argument from Snowflake’s Field CTO, Fawad Qureshi, that accountability rather than raw capability will decide whether public-sector AI earns citizen trust. He is right, and the piece is worth reading. But it frames accountability as something government must now build — a capability to be acquired alongside the models. That is not the position UK departments are actually in. Accountability for administrative decisions is already a legal obligation, it already attaches to named humans, and there are already at least four separate regimes bearing on an automated recommendation inside a department. The gap is not absence. It is that each regime answers a different question, none of them answers who signs this particular decision, and the design pattern departments have adopted for safety reasons is the one that disapplies the strongest protections citizens have.
Strategic Reality: The question “who is accountable for this AI decision?” has four different legal answers in the UK depending on which regime you ask, and they do not resolve to the same person. That is a harder problem than having no answer at all, because it produces the appearance of governance without a single point of ownership.
Four regimes, four questions, one missing answer
The regimes below all apply to a UK central government department deploying AI in a citizen-facing process. None of them is optional, and none of them is new enough to be described as an emerging framework.
| Instrument | Status | Question it answers | Who it names |
|---|---|---|---|
| UK GDPR Articles 22A–22C, inserted by Data (Use and Access) Act 2025 s.80 | In force 5 February 2026 | What can a citizen demand after an automated decision? | The controller — an organisation, not an individual |
| Algorithmic Transparency Recording Standard | Mandatory for departments and public-facing arm’s-length bodies; scope and exemptions policy published December 2024 | Which algorithmic tools are in use? | The publishing organisation |
| Common-law presumption that computer evidence is reliable | Long-standing; Ministry of Justice call for evidence ran 21 January to 15 April 2025 | Is the system’s output reliable in court? | Nobody — reliability is presumed until rebutted |
| Carltona doctrine, the duty to give reasons, the rule against fettering discretion | Long-standing | Was the decision lawful? | The Secretary of State, through an official acting in their name |
Read across that table and the shape of the problem appears. Data protection law tells the citizen what they can ask for. Transparency policy tells them what software exists. Evidence law tells a court what to assume. Administrative law is the only one that names a human — and it is also the only one that was built entirely for humans.
The safeguard that switches off when a human joins in
The Data (Use and Access) Act 2025 substituted a new set of provisions for the old automated decision-making article in the UK GDPR, and the substantive data protection changes commenced on 5 February 2026 — which Resultsense covered when the ICO confirmed the provisions were in force. The reform relaxed the old general prohibition on solely automated significant decisions and put a safeguards regime in its place. Where a significant decision is taken solely by automated means, Article 22C(2) obliges the controller to give the citizen information about the decision, let them make representations, let them obtain human intervention, and let them contest it.
That is a strong set of rights. It is also a set of rights with a precise trigger. Article 22A(1)(a) defines the threshold: “a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision”.
Now consider how every responsible public-sector AI deployment is currently specified. The model does not decide. The model produces a recommendation, a risk score, a triage priority, a shortlist. A caseworker, clinician or officer reviews it and makes the decision. This is the pattern departments have converged on precisely because it looks safer, and in engineering terms it usually is.
It is also the pattern that takes the deployment outside Articles 22B and 22C entirely.
Critical Context: Human-in-the-loop is simultaneously the recommended safety architecture and the mechanism that removes the citizen’s statutory right to information, representations and contestation. Departments are not exploiting a loophole. They are following good engineering practice into a legal position nobody chose deliberately.
The consequence is uncomfortable. The deployments where citizens have the strongest codified rights are the fully automated ones that departments are least likely to build. The deployments departments are actually building — advisory models feeding human caseworkers at scale — sit outside the safeguards, and the citizen’s route back to an explanation reverts to the general administrative law position and a subject access request.
What “meaningful” has to mean, from two directions
Public law arrives at the same requirement from the opposite end, and this is where the two regimes become mutually reinforcing in a way that most governance documentation misses.
Under the Carltona doctrine, a decision taken by a departmental official is in law the minister’s decision — the official acts as the minister’s alter ego, which is what makes the accountability chain in Whitehall work at all. There is no equivalent doctrine for a model. A statistical system is not an officer of the department, cannot hold delegated authority, and cannot be the subject of a duty to give reasons.
Separately, a decision-maker holding a statutory discretion must not fetter it. An officer who adopts a model’s output as a matter of course, without bringing independent judgement to the individual case, is at risk of having unlawfully fettered that discretion — regardless of whether the model was right.
Put the two together with Article 22A and the same test appears twice. Data protection law asks whether the human involvement was meaningful, in order to decide whether safeguards apply. Administrative law asks whether the human exercised genuine judgement, in order to decide whether the decision was lawful. A department that cannot evidence the second has almost certainly failed the first, and vice versa. Yet in most deployments neither is measured. The record shows that a human account approved the case; it does not show what that human saw, what they changed, or how long they spent.
Reality Check: If your only evidence of meaningful human involvement is that a named user clicked approve, you have documentation, not evidence. An override rate near zero across thousands of cases is not proof that the model is good. It is the signature of a rubber stamp, and it reads that way in a tribunal.
The evidential problem nobody has closed
Qureshi invokes Horizon, and correctly separates the technology failure from the governance failure. “It wasn’t an AI failure,” he said. “It was an accountability failure. It was a governance problem.” Volume 1 of Sir Wyn Williams’ final report, published in July 2025, dealt with redress and the human toll rather than with the software.
But Horizon left a legal residue that bears directly on AI-assisted decisions, and it has not been cleared. In England and Wales there is a rebuttable common-law presumption that a computer producing evidential records was working correctly. The Ministry of Justice ran a call for evidence on whether that presumption remains fit for purpose, which closed on 15 April 2025; the government has not published an outcome on the call for evidence page.
So the presumption stands. Which means the burden of showing that an automated output was wrong falls on the person affected by it — the same person who, in an advisory-model deployment, has no statutory right to information about the logic under Article 22C because a human was in the loop.
Hidden Cost: The citizen must rebut a system they cannot inspect, whilst the provisions that would give them inspection rights are disapplied by the very design choice made to protect them. That is not a hypothetical. It is the default configuration of most UK public-sector AI now entering service.
What a working answer looks like
The useful unit of accountability is not the system. It is the decision type. Resultsense has argued before that UK public-sector AI stalls on procurement, governance and delivery rather than on trust in the abstract; this is the governance leg made concrete.
For organisations at the pilot stage. Name the accountable officer per decision type before the model is procured, and write that name into the service specification rather than the risk register. Decide at the same point whether the deployment is intended to be solely automated. If it is, build to Article 22C from the start — retrofitting contestation rights into a live caseworking system is an order of magnitude more expensive than designing them in. If it is not, document why the human involvement is meaningful in operational terms, not aspirational ones.
For organisations already in production. Instrument the human step. Capture what the reviewer was shown, what they altered, the time taken, and the override rate broken down by cohort. Those four fields do more for defensibility than any volume of policy documentation, because they are the only things that answer the question a tribunal will actually ask. Then check the disparity: if override rates differ materially across protected characteristics, the Public Sector Equality Duty is engaged whether or not the model was designed with those characteristics as inputs.
For organisations at scale, or running multiple models in sequence. Move from per-tool disclosure to per-decision lineage. The transparency standard records that a tool exists and what it broadly does. It does not record which model version, which input data and which human judgement produced the outcome in a specific case eighteen months ago. Qureshi’s point about tracing every stage of a recommendation is the right one; the gap is that the mandatory standard operates at a coarser granularity than the accountability question requires.
Implementation Note: An algorithmic transparency record is a floor, not an audit trail. Publishing one satisfies a policy obligation. Reconstructing an individual decision two years later satisfies a legal one, and needs versioned models, retained inputs and a durable record of the human step.
For suppliers to government. Contract for evidentiary disclosure now. If a department must reconstruct a decision your model contributed to, and your training data, model version or scoring logic is commercially confidential, the department cannot discharge its duty to give reasons. That conflict is far cheaper to resolve at procurement than at judicial review.
Four problems a compliance review will not surface
The standard can move under you. Article 22D empowers the Secretary of State to make regulations specifying which cases do and do not count as meaningful human involvement, subject to an affirmative vote in both Houses. A deployment that sits comfortably outside the safeguards today can be brought inside them by secondary legislation without any change to the system. Mitigation: build the Article 22C capabilities even where you assess them as not currently required, and treat the assessment as reviewable rather than settled.
Multi-agent chains have no Carltona equivalent. Where several models exchange information across departmental boundaries before a recommendation emerges, the doctrine that makes an official’s decision the minister’s decision has nothing to attach to. Mitigation: define a single accountable department per decision type in the data-sharing agreement, before the pipeline is built, and resist architectures where no single body can reconstruct the whole chain.
Transparency records drift out of date. A record describes the tool as it was when published. Retraining, prompt changes and model upgrades all move the system away from its published description without triggering a republication in most departmental processes. Mitigation: tie record review to the model release process rather than to an annual governance cycle.
Explanations that satisfy lawyers can fail citizens. A decision can be fully traceable, fully documented and still incomprehensible to the person it affects — which is what happened with the 2020 exam grading algorithm, where public confidence collapsed over a process that was in principle documented. Mitigation: test the explanation with people who receive it, and treat comprehension as the acceptance criterion rather than completeness.
⚠️ Warning: An accountability posture built solely on data protection compliance will pass an internal audit and fail in the tribunal, because the strongest data protection provisions do not apply to the advisory deployments most departments are running. Public law, not the UK GDPR, is where these decisions will be tested.
The takeaway
Qureshi’s conclusion is the right one: “The most trusted governments will not necessarily be the ones building the smartest AI. The trusted governments will be the ones who build the most accountable AI.” The refinement British organisations need is that accountability here is not a capability to acquire. It is an existing legal obligation with a specific shape, and the shape has a hole in it exactly where current deployment practice sits.
Three things follow for anyone deploying AI into a decision that affects a member of the public — inside government or in a regulated sector that will inherit the same expectations.
- Name a person, not a system. Every decision type needs one accountable human whose name predates the incident, because every regime that actually bites eventually asks for one.
- Evidence the human step, do not assert it. What was shown, what changed, how long it took, how often the recommendation was overridden. Assertion is worthless in both the data protection and the public law analysis.
- Assume the burden of proof falls on you, not the citizen. The evidential presumption may currently run in your favour. Building as though it does not is the only posture that survives it changing.
The organisations that get this right will not be the ones with the most governance documentation. They will be the ones that can answer, for a decision taken two years ago, what the system recommended, what the human did with that recommendation, and whose name is on the outcome.
Source and attribution
This analysis responds to “Government’s biggest AI challenge isn’t intelligence – it’s accountability”, published by THINK Digital Partners on 10 August 2026, reporting comments by Fawad Qureshi, Field CTO at Snowflake. Quotations attributed to Qureshi are taken from that article.
Statutory provisions are cited from the Data (Use and Access) Act 2025 as published on legislation.gov.uk, the Algorithmic Transparency Recording Standard Hub, and the Ministry of Justice call for evidence on software-generated evidence in criminal proceedings.
Related Resultsense analysis: why UK government AI projects keep stalling, what the school attendance system failure revealed about governance discipline, and the State of the State 2026 findings on public-sector AI scaling.
This article is general analysis, not legal advice. Organisations should take their own advice on the application of these provisions to specific deployments.