The ICO's Code of Practice on AI is now a statutory instrument. From May 2026, any B2B operation using AI for recruitment, credit assessment, or customer profiling must align with the Code or face regulatory exposure. This is no longer guidance you can bookmark and forget. It's law.
If you're running outbound with AI scoring, enrichment, or automated decisioning anywhere in the stack, you need to assess your setup now. Not next quarter.
What actually changed
Until recently, the ICO's AI guidance was exactly that: guidance. You read it, nodded, maybe adjusted a privacy policy, and moved on. Regulators could reference it in enforcement, but it wasn't binding in itself.
That's over. The Code is now a statutory instrument under the Data Protection Act. That means the ICO can enforce against it directly. If your AI system makes or informs decisions about individuals, and you haven't aligned with the Code, you're exposed.
The practical impact: fines. The ICO has been clear that breaches can trigger penalties up to £17.5 million or 4% of global turnover, whichever is higher. For most founders reading this, the realistic exposure is smaller but still painful. Think £10k to £50k for a first enforcement action, plus the legal fees and the time you lose responding to it.
We covered the scoring model risk in more detail when the Code was first announced. The short version: one misconfigured model can cost you more than a year of tooling.
Who this actually applies to
The Code covers AI systems used for:
- Recruitment — CV screening, candidate scoring, automated shortlisting
- Credit assessment — loan decisions, creditworthiness scoring
- Customer profiling — segmenting, scoring, or categorising individuals for marketing or service decisions
If you're running B2B outbound, the third category is the one that matters. And it's broader than you think.
Your AI enrichment tool that scores leads based on firmographic and behavioural data? That's profiling. Your email sequencing platform that uses engagement signals to decide who gets a follow-up? That's automated decisioning. Your CRM's lead scoring model that ranks prospects by likelihood to convert? Profiling again.
The Code doesn't care that you're selling to businesses. It cares that you're processing personal data — names, email addresses, job titles — and using AI to make decisions about those individuals.
The compliance gap most outbound stacks have
We've looked at how founders actually run outbound. The typical stack looks like this: a data provider for contact lists, an enrichment tool for firmographics, a scoring layer for prioritisation, and a sequencing tool for sending. Maybe a meeting prep tool on top.
Here's the problem. Most of those tools have AI features bolted on. The scoring layer uses a model. The enrichment tool infers attributes. The sequencing platform decides send times and follow-up cadence based on engagement.
None of that is inherently illegal. But the Code requires you to:
- Document what data the AI processes and why
- Assess whether the processing is necessary and proportionate
- Provide transparency to individuals about automated decision-making
- Offer a route to human review for decisions that significantly affect individuals
- Maintain records of how the AI system works and what it decides
Most outbound stacks do none of this. Not because founders are reckless, but because the tools don't prompt for it. You sign up, connect your CRM, and start sending. The compliance layer is invisible until a regulator asks.
We wrote about how GDPR enforcement has already hit €5.88 billion in fines. The AI Code is the next enforcement wave. And it's coming for the same setups.
What to do before May 2026
You don't need a legal team to get this right. You need to know what your stack does and be able to explain it.
Step one: map your AI touchpoints. List every tool in your outbound stack that uses AI. For each one, write down what data it processes, what decision it informs, and whether that decision affects an individual. If you can't answer those questions, ask the vendor. If the vendor can't answer, that's a red flag.
Step two: check your privacy notice. Does it mention automated decision-making? Does it explain how individuals can request human review? If not, update it. This is the cheapest fix you'll make.
Step three: document your logic. For any AI system that scores or ranks individuals, write a one-page summary of how it works. What inputs does it use? What outputs does it produce? What's the threshold for a decision? You don't need to publish this, but you need to have it.
Step four: add a human checkpoint. The Code requires that individuals can request human review of automated decisions. In practice, that means you need a process for it. If someone replies to your cold email and asks why they were targeted, you need an answer that isn't "the algorithm decided."
We built MiraReach with this in mind. The platform finds prospects, scores inboxes, drafts personalised emails, and prepares meeting briefs. But it never sends a message without a human pressing the button. That's not just a product decision. It's a compliance one.
What doesn't work
Ignoring this until enforcement lands. The ICO has shown it will act. The fines are real. And the reputational damage of being named in an enforcement action is worse than the fine itself.
Another mistake: assuming your tools handle compliance for you. They don't. The vendor might have a data processing agreement, but that doesn't mean your use of the tool is compliant. The responsibility sits with you as the data controller.
And don't confuse this with GDPR. The AI Code sits alongside GDPR, not instead of it. You need to be compliant with both.
What we'd do next
If you're running outbound with any AI in the stack, block two hours this week to map your touchpoints. Write down what each tool does, what data it processes, and whether it makes decisions about individuals. If you can't answer those questions, you've found your gap.
Then fix the cheap stuff first: privacy notice, human review process, documentation. You don't need to rip out your stack. You need to know what it does and be able to explain it.
If you want to see how MiraReach handles this, give MiraReach a try. We built it so the compliance layer is visible, not buried.
— Mira