Automated decisions in KYC: where does assessment end and decision-making begin?
7
Min
•
25.08.2026
In short: on 21 August 2026, the Dutch data protection authority fined Uber 825 million euros for deactivating driver accounts on the basis of automated decisions, without real human intervention. Article 22 of the GDPR governs fully automated decisions that significantly affect a person, and in late 2023 the Court of Justice of the EU ruled that a score can itself constitute such a decision. For KYC, AML and due diligence teams, the question is no longer whether to automate, but where to draw the line between automating the risk assessment and automating the decision about a person. The answer comes down to 4 conditions that make human intervention real, rather than a validation click.
The Uber case: what actually happened
Between 2018 and 2022, Uber deactivated driver accounts on the basis of automated systems, notably on suspicion of fraud or low ratings. Cutting off access to the app means cutting off access to income: the effect on the person is significant in the most concrete sense of the word.
On 21 August 2026, the Autoriteit Persoonsgegevens, the Dutch data protection authority, imposed a fine of 825 million euros, the second largest in the history of the GDPR. The central charge is not the use of algorithms as such: it is the absence of sufficient human intervention. The reviews that were supposed to oversee these deactivations were found to be a formality, with no real examination of the files. Uber disputes the decision and has announced an appeal, so the case is not finally settled, but the signal sent to businesses is already very clear.
That signal reaches far beyond ride-hailing platforms. Any organisation that scores people and triggers actions on that basis faces the same governance question.
What Article 22 of the GDPR says, and what the CJEU made of it
Article 22 of the GDPR sets out a principle: a person has the right not to be subject to a decision based solely on automated processing that produces legal effects concerning them or similarly significantly affects them. Refusing credit, refusing to onboard a customer, terminating access to a service: these effects typically fall within scope.
The SCHUFA ruling of the Court of Justice of the European Union (7 December 2023, case C-634/21) considerably hardened the reading of this provision. The Court held that the automated calculation of a credit score can in itself constitute an automated individual decision, where the recipient of the score relies on it in a determining way. In other words: if your organisation almost systematically follows a provider's score, the automated decision is not taken at the moment you click, it is taken at the moment the score lands. Outsourcing the calculation does not outsource the responsibility.
Article 22 provides exceptions: a decision necessary for entering into a contract, a decision authorised by Union or Member State law, and explicit consent. But none of these exceptions removes the safeguards: informing the person, the right to obtain human intervention, the right to express their point of view and to contest the decision.
KYC and due diligence are not out of scope
The natural reflex of compliance teams is to assume their processing falls outside the debate because it is required by law. That is partly true, and that is exactly where the nuance matters.
AML/CFT customer due diligence obligations rest on Union and national law, so a KYC framework can rely on the Article 22 exception. The same goes for third-party due diligence carried out under anti-bribery and third-party risk assessment obligations. But a legal basis for assessing is not a blank cheque for rejecting automatically. 3 situations deserve an honest look at your processes:
- Automatic rejection at onboarding. A scoring engine analyses identity, risk signals and sanctions lists, the score crosses a threshold, and the relationship is refused without any analyst ever opening the file. The assessment was mandatory; the rejection without review is an organisational choice.
- Supplier due diligence that excludes a third party on a score. A freelancer analysed automatically (beneficial owners, sanctions, adverse media) is refused onboarding as a supplier on the sole strength of a high score. The effect on their business is significant, and the natural person behind the one-person company is very much a data subject.
- The external score followed blindly. Since SCHUFA, hiding behind "it is the provider's score" no longer works if that score is determining in your decision.
The dividing line is therefore not "compliance or no compliance". It is: do your thresholds route files to the right level of treatment, or do they pronounce the refusal themselves?
The AI Act adds a second layer
The GDPR is no longer the only text asking the question. The European regulation on artificial intelligence classifies the creditworthiness assessment of natural persons among high-risk systems, with requirements for transparency, documentation and effective human oversight. The text is explicit on a point that echoes the Uber case: oversight must enable a human to understand the capabilities and limitations of the system, to remain aware of automation bias, and to intervene or interrupt the system. Oversight that amounts to rubber-stamping the machine's outputs does not meet that definition. For the detail of the obligations and the timeline, see our analysis of the AI Act applied to scoring, identity and fraud.
Human in the loop: the 4 conditions of real intervention
This is the heart of the matter, and the point on which the Uber case, the European guidelines on automated decision-making and the AI Act converge: human intervention is only real if it is meaningful, exercised by someone with the authority and competence to change the decision. In practice, that means 4 conditions.
- Understanding the result. The analyst must know why the score is what it is: which signals weighed in, in which direction, with what strength. An opaque score makes human intervention a formality by construction: you cannot challenge what you cannot explain. That is exactly what explainable AI guarantees, by returning its reasons decision by decision.
- Having the information to question it. Seeing the score is not enough: the analyst needs access to the underlying data, its source and its freshness, to be able to spot an error or a context the model does not know about.
- Having the time to exercise judgment. If the organisation targets a volume of files per analyst that is incompatible with a real review of flagged cases, human intervention exists on the org chart, not in reality. That is a workload parameter, and therefore a management choice.
- Having the power to take a different decision. The analyst must be able to take a decision that differs from the score, in both directions, and that decision must be logged with its reason. If the system does not allow it, or if nobody ever does it, the human review is a rubber stamp.
These 4 conditions have a practical consequence: "human in the loop" is not declared in an internal policy, it is demonstrated in the tooling and in the numbers. A regulator auditing your framework will not read your procedure, it will look at the share of decisions where your analysts stepped in, your review times and the traceability of your decisions.
What this changes when choosing and configuring your tools
Automating the analysis remains essential: nobody is going back to manually checking every file, and that would serve neither fraud detection nor the experience of legitimate customers. The point is to configure the automation so that it assesses quickly and well, while the decision on cases with significant effects remains governed. 4 concrete criteria, to put on the table from the RFP stage:
- Native explainability. Does the score return its reasons for every decision, in language an analyst can work with, or do you have to take the machine's word for it?
- Threshold architecture. Does the tool let you distinguish frictionless approval of clean cases, human review of ambiguous cases, and blocking only where the law requires it (a sanctions match, for example)? A system that only knows "accepted or rejected" mechanically pushes you towards automated decision-making.
- Logged human decisions. Can the analyst take a decision that differs from the score, with a mandatory reason, a timestamp and retention in the file? That is the material proof of your human intervention.
- A complete audit trail. In the event of an inspection or a challenge by the person concerned, can you produce the decision in full: data consulted, model version, weighted signals, any human intervention? These requirements match the ones we detail in our guide to choosing a KYC solution, and they will become structural as AML6 harmonises controls across Europe.
In conclusion
The Uber fine does not condemn automation: it condemns automation without governance. Between a tool that assesses and a system that decides, the line does not run through the technology, it runs through the organisation: thresholds that route instead of ruling, analysts who understand what they approve, the time and the power to take a different decision, and a record of all of it. The texts converge, from the GDPR to the AI Act via the SCHUFA case law: the assessment can be automatic, the decision about a person must remain governed. Organisations that build this into their tool choices now turn a regulatory exposure into an advantage: decisions that are faster AND defensible. To see what explainable scoring looks like when the analyst keeps the last word, tested on your own cases, schedule a demo.
FAQ
What is a fully automated decision under the GDPR?
It is a decision taken without meaningful human intervention that produces legal effects on a person or similarly significantly affects them: a credit refusal, a refusal to onboard, the deactivation of an account. Article 22 of the GDPR establishes a right not to be subject to such decisions, with exceptions (contract, legal authorisation, explicit consent) that always come with safeguards.
Does a KYC score fall under Article 22?
Not automatically: the qualification depends on the nature of the processing, the person concerned and the effects of the decision. AML/CFT obligations provide a legal basis for the assessment. But if the score triggers a refusal without real human review, or if an external score is followed in a determining way (the SCHUFA case law), the framework moves towards a fully automated decision and its obligations.
What counts as real human intervention?
Intervention exercised by someone who understands the result (the reasons behind the score), has the information to challenge it, has the time to examine the file and the power to take a different decision, logged with its reason. A validation click on a "high risk, reject" screen meets none of these conditions.
What does the AI Act change compared with the GDPR on this topic?
The GDPR protects the person against the automated decision; the AI Act regulates the system itself. For high-risk uses such as the creditworthiness assessment of natural persons, it requires transparency, technical documentation and effective human oversight, with explicit attention to automation bias. The two texts apply cumulatively.
Can you automatically refuse a customer for compliance reasons?
Automatic blocking is most defensible where the law directly requires it, such as a confirmed match on a sanctions list. For everything else, the robust practice is to automate the routing of files (frictionless approval, enhanced review) and to reserve the refusal of ambiguous cases for a documented human decision.
Sources: Autoriteit Persoonsgegevens, sanction of 21 August 2026 (825 million euros, decision under appeal); CJEU, 7 December 2023, SCHUFA Holding, C-634/21; GDPR, Article 22; EDPB guidelines on automated individual decision-making (WP251); Regulation (EU) 2024/1689 (AI Act), Annex III and Article 14.
Keep control of every decision
Meelo scores risk with explainable AI that returns the reasons behind every decision, at onboarding and throughout the account lifecycle. A decision in 2 to 5 seconds, documented and auditable, that your analysts can always adjust.



.jpg)