Meaningful Human Involvement Is Not A Rubber Stamp

The Dutch regulator has fined Uber 824,990,000 euros for fully automated decisions about drivers. Roles under the AI Act can be reallocated, but the duty to have a human who can overturn the output follows whoever decides about the person. Where that review sits in your organisation.
AI generated image - workers held at a closed gate beside an empty booth, illustrating meaningful human involvement missing from an automated decision

Uber wrote the software. Uber ran the software. Nobody at Uber supplied the meaningful human involvement those decisions required, and that omission is what the fine is for.

The Dutch data protection authority has fined Uber 824,990,000 euros for making fully automated decisions about drivers. Software tracked driving behaviour and customer ratings. Where it detected suspected fraud, accounts were temporarily deactivated. Where ratings stayed low, some were deactivated for good. Drivers lost their Uber income while the block held. The regulator found two breaches rather than one: the prohibition on fully automated decision-making and the failure to inform drivers that such decisions were being made about them. Meaningful human involvement was missing at both ends, in the decision and in the explanation.

It is the second largest GDPR fine issued in the EU, behind the 1.2 billion euro penalty Ireland imposed on Meta in 2023. The authority says the violations have stopped. Uber disagrees fundamentally with the decision, considers the amount disproportionate and is appealing. It also says people are involved in these decisions today and that drivers can challenge a deactivation.

The case started with 171 French drivers, a French human rights organisation and a complaint to the French regulator. It landed in the Netherlands because Uber’s European headquarters are in Amsterdam, which made the Dutch authority the lead supervisor under the one-stop-shop mechanism.

Why the developer and deployer split does not save you here

Last week this blog covered Article 25 of the AI Act, which pushes provider obligations onto your organisation when you rebrand or substantially modify a high-risk system. Roles under the AI Act move. They get allocated, negotiated and occasionally transferred to you without anyone sending a notification.

Article 22 of the GDPR does not behave that way.

The duty attaches to the controller, meaning the organisation that decides something about the person. Whether the model was built by your own team, licensed from a vendor or buried inside a workforce platform you renew annually makes no difference to who answers for the outcome. There is no provider tier and no deployer tier. There is the organisation whose decision it was.

Uber is the clean illustration precisely because it held every role at once. It developed the system, deployed it on its own drivers and carried the consequences. No supplier stood between the company and the decision. Your organisation almost certainly has a supplier, and that is exactly where the reasoning tends to go wrong.

Meaningful human involvement cannot be outsourced

A contract can allocate a great deal. Technical documentation, logging, accuracy testing, retraining and incident notification all sit comfortably with a supplier, and a good procurement team will put them there.

A contract cannot place meaningful human involvement inside somebody else’s company.

The supplier’s compliance pack is evidence about the tool. It says nothing about whether a person in your organisation looked at the output before it changed somebody’s month. That gap is not a documentation gap. It is the substance of the duty, and it is the part no vendor assessment will ever close for you.

What meaningful human involvement looks like in practice

The standard is not the presence of a person. Someone who approves whatever the system proposes has added a signature rather than a decision, and a regulator reading the audit trail will see the difference immediately.

Three tests for the review

Apply these to any automated decision your organisation makes about a worker:

  • Authority. The reviewer can reach a different outcome from the one the system proposed, and does so often enough to prove the route is real.
  • Reasons. The reviewer sees why this particular person was flagged, not simply that a score crossed a threshold.
  • Capacity. The reviewer has the time, the training and the standing to disagree with the model in front of a manager who would rather not hear it.

Then there is the second limb, the one that gets overlooked. Telling people that automated systems may be used somewhere in your processes is not information. The person needs to know that a decision about them was automated, what the logic broadly involved and what it means for them. Uber was fined for that failure separately from the decision itself, which tells you how the authority weighs it, and the same regulator has already set out what an explanation has to contain.

Where these decisions already sit in your organisation

Almost nobody deactivates drivers. The equivalent happens under other names.

Access revoked because a security score moved. An expense claim frozen by a fraud model. Shifts allocated by a scheduling engine that quietly stops offering hours to people it scores badly. A candidate filtered before any human opens the file. A contractor payment held pending a flag nobody can explain. Each of those can carry a significant effect on somebody’s income, and the moment it does, the automated decision rules apply.

The pattern that matters is not the technology. It is that the system now sits between a manager and a person, and the manager has stopped looking. Where an organisation takes that seriously, the review becomes a named role rather than a line buried in somebody’s job description.

The AI Act layer arrives later, not instead

Annex III of the AI Act covers employment and worker management, and those high-risk obligations now apply from 2 December 2027 following the Digital Omnibus on AI. That deferral is real and it is worth planning around.

It changes nothing about meaningful human involvement, which Article 22 has required since 2018. Reading a 2027 date as breathing space on worker-facing automation is precisely the misreading that produced a 824,990,000 euro penalty for conduct that predates the AI Act entirely.

The question your AI lead should be able to answer

For every automated decision that touches a member of staff or a contractor, who is the named reviewer, what can they overturn and what evidence exists that they ever have?

The first part usually has an answer. The third part is where the file goes quiet.

That is not a legal problem and it is not a procurement problem. It is a training problem, because the people doing the reviewing usually have no idea what the review is for. They were told to check the flags. Nobody explained that their signature is the safeguard.

Future Prep Applied trains the AI lead and the team around them, starting with the AIGP course for governance roles and extending to framework and staff awareness training. If your organisation runs automated decisions about people, train the reviewers before a regulator asks who they were.

Newsletter
Releted Blogs
LATEST NEWS

AI governance is not a future problem

Regulation is already in effect. Your competitors are already building internal capability. The gap between ‘we are aware of AI’ and ‘we have operational control’ is closing, and it closes faster with a structured framework.

 

Book a 30-minute discovery call. No obligation. We will assess where your organisation stands and what a realistic starting point looks like.

No sales pressure. No jargon. Just a structured conversation about your organisation's AI readiness.

Scroll to Top