Monthly Archives: August 2026

No Human in the Loop: Uber’s Record GDPR Fine

On August 21, 2026, the Dutch data protection authority has sanctioned the company Uber for breach of article 22 of the GDPR on automated decisions. An appeal by Uber against the fine, equal to no less than €824,990,000 (yes, all those zeros!), is pending.

Rules on automated decisions.  Section 22 of the GDPR sets forth that the data subject is entitled not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. Certain exceptions to this rule apply, namely if the decision is necessary to enter into or perform a contract with the data controller, if it is provided by law, or if it is based on express consent of the data subject. Changes to the provision may be brought by the Digital Omnibus proposal, but are not yet in force.

An entirely automated decision.  The data protection authority found that between 2018 and 2022 Uber used software to track drivers’ conduct and customers reviews, which would automatically deactivate the driver’s account in case of suspicion of fraud or if customer reviews were bad. The account’s deactivation implied no human assessment and was found to be entirely automatic.

The previous SCHUFA case.  The European Court of Justice tackled a similar issue in the Schufa case of December 7, 2023. In that case, the decision process was more articulated, with an automated first step and a second step involving a human decision heavily relying on the first step. The Court ruled that a credit information agency setting forth “a probability value based on personal data relating to a person and concerning his or her ability to meet payment commitments in the future constitutes ‘automated individual decision-making’ within the meaning of that provision, where a third party, to which that probability value is transmitted, draws strongly on that probability value to establish, implement or terminate a contractual relationship with that person”. The Court justified this broad interpretation by pointing to the risk, where three parties are involved, of circumventing Article 22 and creating a gap in legal protection if the calculation of the probability value were classified merely as a preparatory act.

Are AI decisions better than human decisions?  An optimistic view argues that AI-based hiring of employees may result in a less biased human resources function. On the other hand, a more commonly shared opinion is concerned that AI decisions, which can be as biased as human decisions, are becoming fully independent from instructions received by humans (e.g., Ukrainians have started to be killed by drones entirely guided by AI).

Conclusions. The GDPR bans fully automated decisions and requires “human-in-the-loop” processes whenever such decision produces legal effects or significantly affects a person. Section 22 of the GDPR can be seen, and is being interpreted, as a safeguard for EU citizens against fully automated decisions.

HAL Can Compute, But Can HAL Copyright? Italy’s Answer for the AI Era

Think of HAL 9000, the ominously calm on-board computer from 2001: A Space Odyssey. HAL runs the ship, plays chess, holds a conversation, even claims to feel emotions – but the one thing HAL never does is sign anything. But could HAL place his name as author on anything – a painting, a poem? Or think of Ai-Da, the Oxford-built robot that paints portraits through cameras built into its eyes and a robotic arm guided by machine-learning algorithms, whose most famous work has been described as “the first self-portrait with no self.” HAL and Ai-Da raise, one in fiction and one in a gallery, the same question Italian lawmakers just answered in statutory form: can a machine be an author? The answer, for Italian copyright law, is now written into the text itself – and it matters for any business generating content with AI tools.

Italy’s Law No. 132/2025 (in force since October 10, 2025) is the first comprehensive national framework on artificial intelligence in Europe, designed to work alongside the EU AI Act. Its Article 25 amends Article 1 of the Italian Copyright Law (Law No. 633/1941), the core provision that defines which works qualify for copyright protection in Italy.

Before the reform, Article 1, first paragraph, of the Copyright Law simply read: works of intellectual endeavour of a creative character belonging to literature, music, figurative arts, architecture, theatre and cinematography are protected under this law, whatever the mode or form of their expression. The provision said nothing about who, or what, had to create the work – it only required intellectual endeavour and creative character, a gap that left the treatment of AI-generated output to interpretation.

The amendment inserts two changes into that same sentence. First, the word “human” is added immediately after “works of intellectual endeavour”, so the provision now protects works of human intellectual endeavour, not just intellectual endeavour in the abstract. Second, a new clause is added at the end: even where created with the aid of artificial intelligence tools, provided they constitute the result of the author’s intellectual work.

What actually changed, in practice:

  • The threshold question is now explicit in the text, not just in case law. Before the reform, Italian courts and commentators already generally assumed that copyright required a human creative act, drawing on the general theory of authorship. The reform writes that assumption directly into the statute, removing any doubt that a work generated entirely autonomously by a machine – with no human creative contribution, like HAL’s compositions with no composer behind them, or Ai-Da’s brushstrokes without a “self” behind them – falls outside protection.
  • AI-assisted works are not excluded, but they are conditioned. The law does not ban the use of AI tools in the creative process. A text generated with ChatGPT can still be protected — but only if the applicant can show that a genuine human creative intervention shaped the result, rather than the output being a pure automatism.
  • The burden of proof shifts to the author. Because the law now links protection to demonstrating that the result stems from the author’s intellectual work, businesses and creators using AI tools should keep records of their creative process-— prompts, iterations, selection choices, edits – as evidence they may need to produce if authorship or protectability is ever challenged.

Practical takeaway for businesses: document the human creative input behind AI-assisted content (prompts, edits, selection criteria) before relying on it as a protectable asset. Where multiple people or vendors are involved in an AI-assisted content pipeline, contracts should specify who is responsible for demonstrating that creative contribution and who owns the resulting rights. HAL, notably, had no human “director” feeding it prompts and making editorial choices – which is the missing ingredient the statute now requires. Your brand’s AI-generated content can have that missing ingredient, and with it a legal “self” behind the work – but remember to prove it!

AI Act Transparency Obligations Are Now in Force

Dear Readers,

I hope you had a great summer! While you were travelling, hiking, swimming or simply resting, article 50 of the AI Act has entered into force, which means that a number of transparency obligations are applicable.

1. YOUR ROLE. First things first: are you an AI provider or an AI deployer?

  • A provider of AI systems is a natural or legal person that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark; while
  • A deployer is a natural or legal person using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity.

Providers and deployers have different obligations, which are summarized below.

2. PROVIDER’S OBLIGATIONS.

  • Providers must ensure that AI systems intended to interact directly with natural persons are designed so that those persons are informed they are interacting with an AI system, unless this is obvious from the point of view of a reasonably well-informed, observant and circumspect person.
  • Providers of AI systems that generate synthetic audio, image, video or text content must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Technical solutions must be effective, interoperable, robust and reliable, as far as technically feasible.

Providers have started to comply and use different technical solutions. Anthropic, for example, is using a watermarking technique, while Open AI and Google are using different strategies. No single marking technique meets Article 50(2) requirements of effectiveness, interoperability, robustness and reliability, and only an appropriate combination of techniques and detection mechanisms can satisfy them. Some point to a clear “Brussels effect” where the AI Act ends up applying beyond its scope.

3. DEPLOYER’S OBLIGATIONS.

  • Deployers of emotion recognition or biometric categorization systems must inform the natural persons exposed to the system of its operation and must process personal data in accordance with the GDPR and any other applicable data protection laws.
  • Deployers of AI systems that generate or manipulate image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated. For evidently artistic, creative, satirical, fictional or analogous works, the obligation is limited to appropriate disclosure that does not hamper the display or enjoyment of the work.
  • Deployers of AI systems that generate or manipulate text published to inform the public on matters of public interest must disclose the artificial nature of the content, unless the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility.

All information must be provided in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure.

The AI Office is tasked with encouraging codes of practice at Union level to facilitate the effective implementation of obligations regarding the detection and labelling of artificially generated or manipulated content. In fact, the voluntary Code of Practice on Transparency of AI-generated Content has already been signed by 190+ organizations and has been found by the EU Commission and the AI Office as an effective tool to aid compliance with article 50 of the AI Act.

In a world where AI systems have started to go rogue, perhaps the AI Act – with all its constraints to AI technology – can offer reassurance that the EU continues to pursue a human-centric, trustworthy AI.