The Dutch data protection authority fined Uber €825M over automated driver deactivations
Regulators found drivers were cut off for suspected fraud or low ratings without human intervention. It is the largest penalty yet for an automated decision that removed someone's ability to earn.
The Dutch data protection authority has fined Uber €825 million over automated deactivation of drivers, finding that the company cut people off for suspected fraud or low ratings without meaningful human intervention.
The deactivations blocked drivers' ability to earn — which is the fact the penalty turns on. This is not a fine about data handling. It is a fine about an automated system making a decision with a serious effect on someone's livelihood, and no person meaningfully standing behind it.
The provision doing the work
Article 22 of the GDPR gives people a right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect them. It has been in force since 2018 and has been enforced rarely, partly because companies have generally been able to point to a human somewhere in the loop.
The Dutch regulator's finding is that Uber's human review was not meaningful — the humans confirmed the system rather than deciding. That distinction is the whole substance of Article 22, and this is the largest penalty yet attached to it.
For anyone deploying agentic systems, that is the sentence to underline. The compliance question is not whether a person is nominally involved. It is whether that person has the information, authority and time to reach a different conclusion from the machine.
Why this lands on AI deployments generally
Uber's deactivation system is old technology by current standards — risk scoring and rating thresholds, not a frontier model. The legal principle does not care.
Every enterprise agent now being sold into an operational workflow has the same structure: a system reaches a conclusion, a human nominally approves it, and the volume of decisions makes genuine review impractical. That is precisely the arrangement the Dutch authority has valued at €825 million.
The deployments most exposed are the ones being marketed hardest — automated claims handling, credit and fraud decisions, content moderation with account consequences, HR screening, and any agent that can suspend an account.
The pattern is already visible in adjacent sectors. Axon's Draft One tool was used by a Texas sheriff's office to convert body-camera audio into a police report in an abortion-related case, and NHS England's watchdog has documented AI clinical scribes producing wrong drug names and a fabricated diagnosis across 27 systems in use. Both are automated outputs entering consequential records with review that is nominal rather than substantive.
What Uber does next, and what everyone else should
Uber has consistently contested Dutch findings and can be expected to appeal; the company has not commented on whether it will. The amount is appealable and may be reduced.
The operational lesson survives any reduction. Organisations deploying decision-making agents need to be able to demonstrate that reviewers see the reasons, can overturn the output, and sometimes do — with records showing the rate at which they do. An override rate near zero is not evidence that the system is accurate. Under Article 22, it is evidence that no one is really deciding.
Runs the newsroom. Rename this profile in the studio to your own byline.
Related
Every weekday, the AI stories that moved money or shipped code.
No cross-posting, unsubscribe anytime. See all newsletters