European organisations preparing for the AI Act frequently overlook the fact that a binding restriction on automated decision-making has been in force since May 2018 — and that it applies today, without a transition period, to systems already in production.

GDPR Article 22 is short. Its consequences are not.

What the article says

An individual has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

Three exceptions permit such decisions: where necessary for entering into or performing a contract; where authorised by EU or member state law with suitable safeguards; or with the individual’s explicit consent. Where the contractual or consent route is used, the controller must implement safeguards including — at minimum — the right to obtain human intervention, to express a point of view, and to contest the decision.

Article 22 also prohibits basing such decisions on special category data (health, biometrics, ethnicity, political opinion, trade union membership, sexual orientation) unless explicit consent or substantial public interest applies, with safeguards.

The EDPB’s long-standing position, unchanged after SCHUFA, is that Article 22 operates as a prohibition in principle — not as a right that the individual must first assert. That reading matters: it means the compliance burden sits with you before anyone complains.

The two phrases that decide everything

“Solely”

The intuitive reading is that inserting any human step defeats the article. That reading is wrong, and expensively so.

The CJEU in SCHUFA confirmed what the EDPB had already said: a human who formally approves while in practice deferring to the algorithm does not make the decision non-automated. What breaks the chain is meaningful human involvement — a person with the authority, competence, information and time to reach a different answer.

This is the single most consequential point on this page, because it means the compliance question is not is there a human? but could that human realistically have said no? A reviewer approving 400 cases a day, with no access to the reasoning behind a score and no incentive to disagree, is providing the appearance of oversight. This is the failure mode examined in designing human-in-the-loop systems that actually work, and it is now a legal exposure as well as a design flaw.

“Similarly significantly affects”

Legal effects are the easy case: contract termination, benefit refusal, entry denial. The harder category is the “similarly significant” one, which regulators have read to include refusal of credit, e-recruitment decisions without human intervention, differential pricing that effectively excludes, and decisions affecting access to essential services.

Marketing personalisation generally falls outside. Personalisation that materially determines whether someone can access a service generally falls inside.

What SCHUFA changed

Case C-634/21, decided 7 December 2023, concerned a German credit reference agency that produced probability scores and supplied them to lenders. SCHUFA’s position was that it merely generated a score; the decision was made by the bank.

The Court disagreed. Where a third party draws strongly on the score in deciding whether to establish, perform or terminate a contract, the generation of that score is itself an automated decision within Article 22.

The structural consequence is significant and under-appreciated. Article 22 obligations do not attach only to the organisation making the final call — they can attach to the organisation producing the model output that the decision rests on. In a market where scoring, screening and risk models are supplied as services, that pulls upstream vendors directly into scope, and makes the allocation of responsibility across that boundary a matter of legal exposure rather than commercial preference.

If you supply a model whose output your customers rely on heavily for consequential decisions, “we don’t make the decision” is no longer a complete answer.

How this interacts with the EU AI Act

They are separate instruments with different logics, and both apply.

GDPR Article 22 EU AI Act
Trigger Effect on an individual System classification
Applies from May 2018 Staged; high-risk deferred to Dec 2027
Focus The decision The system
Rights Individual, directly enforceable Largely regulator-enforced
Remedy Complaint to a DPA; compensation Market surveillance; penalties

The practical point: Article 22 is enforceable now, by individuals, against systems you already operate. The AI Act’s heaviest obligations are still ahead. An organisation that plans only against AI Act deadlines is defending the wrong timeline.

The overlap is also substantial — human oversight, transparency, contestability and documentation appear in both. Controls built for one largely serve the other.

What compliance requires operationally

Inventory the decisions, not just the systems. The unit of analysis under Article 22 is the decision and its effect on a person. A single model may feed several decisions with different risk profiles.

Test whether your human involvement is real. Measure override rates. A rate near zero is not evidence that the model is excellent; it is evidence that the reviewer is not reviewing. Give reviewers the reasoning behind the output, the authority to disagree, and a workload that permits it.

Be able to explain the logic. Articles 13–15 require meaningful information about the logic involved, and the significance and envisaged consequences. This does not demand disclosure of model weights. It demands that an individual can understand what factors drove the outcome for them.

Build the contest route before you need it. Human intervention, statement of view, and challenge must be practically available — not theoretically available behind a support queue.

Complete a DPIA. Systematic evaluation based on automated processing with significant effects is expressly listed as requiring a Data Protection Impact Assessment. Where the system is also high-risk under the AI Act, the two assessments should be run as one exercise with a single evidence base.

The through-line

Article 22, the AI Act, and the AI Human Proof standard converge on one requirement from three directions: a person must be genuinely in a position to say no, and you must be able to show it.

European law reached that conclusion first. It has been enforceable for years.