Encounters with AI
Decision notice
The judgement
As of 12 September 2026, the AI Act does not generally require every organisation to announce that non-interactive AI helped decide a loan, job, benefit or similar application. The direct-interaction rule does not cover ordinary back-office software, and the relevant high-risk decision notice has been postponed.1
The diagram shows the difference between present GDPR routes and the future AI Act notice.
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 590 390" width="590" height="390" role="img" aria-labelledby="decision-title" style="font-family: system-ui, sans-serif">
<title id="decision-title">Notice and information routes for a software-assisted decision</title>
<defs>
<marker id="arrow" markerWidth="8" markerHeight="8" refX="7" refY="4" orient="auto">
<path d="M0 0 L8 4 L0 8 Z" fill="currentColor"/>
</marker>
</defs>
<rect x="170" y="20" width="250" height="58" rx="8" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="295" y="44" text-anchor="middle" fill="currentColor" font-size="16">
<tspan x="295" dy="0">Software makes or assists</tspan>
<tspan x="295" dy="21">a decision about a person</tspan>
</text>
<line x1="295" y1="78" x2="295" y2="118" stroke="currentColor" stroke-width="2" marker-end="url(#arrow)"/>
<rect x="40" y="120" width="510" height="70" rx="8" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="295" y="144" text-anchor="middle" fill="currentColor" font-size="15">
<tspan x="295" dy="0">Current position on 12 September 2026</tspan>
<tspan x="295" dy="21">No general AI Act notice for hidden decision software</tspan>
</text>
<line x1="165" y1="190" x2="165" y2="235" stroke="currentColor" stroke-width="2" marker-end="url(#arrow)"/>
<line x1="425" y1="190" x2="425" y2="235" stroke="currentColor" stroke-width="2" marker-end="url(#arrow)"/>
<rect x="20" y="238" width="285" height="120" rx="8" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="162" y="263" text-anchor="middle" fill="currentColor" font-size="14">
<tspan x="162" dy="0">GDPR route already available</tspan>
<tspan x="162" dy="20">Where its conditions apply, seek</tspan>
<tspan x="162" dy="20">information, access and safeguards</tspan>
<tspan x="162" dy="20">from the data controller</tspan>
</text>
<rect x="325" y="238" width="245" height="120" rx="8" fill="none" stroke="currentColor" stroke-width="2"/>
<text x="447" y="253" text-anchor="middle" fill="currentColor" font-size="14">
<tspan x="447" dy="0">From 2 December 2027</tspan>
<tspan x="447" dy="15">Ordinary Annex III decisions:</tspan>
<tspan x="447" dy="15">deployer tells person AI is used</tspan>
<tspan x="447" dy="15">This is not a full explanation</tspan>
<tspan x="447" dy="15">Law-enforcement decisions:</tspan>
<tspan x="447" dy="15">Directive (EU) 2016/680 Art. 13</tspan>
<tspan x="447" dy="15">competent law-enforcement DPA</tspan>
</text>
</svg>
Figure: Present GDPR information routes sit beside the deferred notice for Annex III high-risk AI decisions.
When a controller collects personal data from the person, GDPR Article 13 has required the controller to provide information about relevant automated decision-making, including meaningful information about logic, significance and expected consequences, since 25 May 2018. When personal data comes from elsewhere, Article 14 has ordinarily required the controller to provide similar information and identify the data's source since that date, subject to Article 14's exceptions. Data-protection authorities and courts enforce both duties.2
Under GDPR Articles 15 and 12, a person can ask the controller for access to meaningful information about relevant automated-decision logic. The controller normally must respond within one month, with data-protection authorities and courts enforcing the duty since May 2018. The Court of Justice says the account should intelligibly explain the procedure and principles actually applied, rather than merely supplying a complex formula.23
GDPR Article 22 also provides qualified protection against solely automated decisions producing legal or similarly significant effects. When contractual necessity or explicit consent permits such a decision, the controller must provide human intervention, an opportunity to state a view and a way to contest it. Data-protection authorities and courts have enforced those safeguards since May 2018.2
From 2 December 2027, Article 26(11) will ordinarily require deployers using Annex III high-risk systems to make or assist decisions about people to tell those people that the system is being used. National market-surveillance authorities will enforce the deployer duty. For high-risk systems used for law enforcement, Article 26(11) instead directs decision-notice questions to Article 13 of Directive (EU) 2016/680; the competent law-enforcement data-protection authority enforces that regime for the deferred AI Act duty from 2 December 2027. The ordinary notice concerns AI use, not a full explanation, and no prescribed wording has been established.1
Boundary. Whether a particular decision is solely automated under the GDPR depends on the facts. The future AI Act notice does not itself create an explanation, human review or appeal procedure.
Quellen
Quizze
Software may have influenced an important decision, but no AI notice arrived. What is the most useful present route for information about personal-data use?
- Send a GDPR access request to the data controller
- Demand an immediate AI Act appeal from the provider
- Wait until every high-risk duty becomes applicable
The GDPR already supports access to relevant automated-decision information, while the general Annex III AI-use notice remains deferred.
Under the ordinary future Annex III decision-notice regime, the notice tells an affected person that ____.
- a high-risk AI system is being used
- a complete technical audit has been finished
- a human appeal has already been accepted
The deployer’s ordinary future notice concerns the use of high-risk AI. It is not automatically a full explanation or completed appeal.
Where the GDPR’s conditions for a significant solely automated decision are met, safeguards can include human intervention and an opportunity to contest.
- True
- False
The GDPR provides qualified safeguards for covered solely automated decisions, including human intervention, stating a view and contesting the result.
Kommentare
Noch keine Kommentare. Fang das Gespräch an.