Week 41 · 7 min read

EU AI Act Regulatory Brief — Week of 5 October 2026

The Dutch data protection authority's €825 million fine on Uber, now under appeal, shows what Article 22 GDPR demands when automated systems cut people off. A leaked Council text would add an AI legitimate-interest clause to the GDPR without four Commission safeguards; it is not law. The AI Board met on 17 September and set no new deadlines.

Relay Labs Ltd ·

Uber Fined €825 Million for Fully Automated Driver Deactivations

On 21 August 2026 the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) announced a fine of €824,990,000 on Uber B.V. and Uber Technologies Inc. It acted in cooperation with the French CNIL, which received the original complaint from the Ligue des droits de l'Homme on behalf of more than 170 drivers. It is the second-highest GDPR fine to date. Uber disputes the findings and has appealed.

Between 2018 and 2022, Uber's systems deactivated driver accounts, temporarily or permanently, when they flagged suspected fraud or a rating judged too low. The authority found that no human assessed these cases before drivers lost access to the platform, in breach of the prohibition on solely automated decisions in Article 22 GDPR. It also found that Uber did not adequately inform drivers about how those decisions were taken.

Article 22(1) gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Where an exception applies because the decision is necessary for a contract or rests on explicit consent (Article 22(2)(a) and (c)), Article 22(3) requires safeguards: at least the right to obtain human intervention, to express a point of view and to contest the decision.

What it means for you

Article 22 covers decisions taken solely by automated means that have legal or similarly significant effects — in employment, credit, access to services or platform work. Such a decision is allowed only under one of the Article 22(2) exceptions (a contract, Union or Member State law, or explicit consent), and under the contract and consent exceptions people must be able to obtain human intervention, express their view and contest the decision.

If you instead rely on a person in the loop so that the decision is not solely automated, that person must genuinely assess the case and be able to decide differently; a rubber stamp does not take a decision outside Article 22. In our view, the best evidence of real review is operational: logs showing that reviews took place and that some automated outcomes were overturned. A written procedure that production systems do not follow is not evidence.

The AI Act adds its own duties for high-risk systems, applying to Annex III systems from 2 December 2027: providers must design them for effective human oversight (Article 14), and deployers must assign that oversight to competent people (Article 26(2)). Article 22 GDPR already applies today, to whoever is the controller of the decision.

The ceilings: under the GDPR, up to €20 million or 4% of worldwide annual turnover, whichever is higher (Article 83(5)). Under the AI Act, up to €15 million or 3% for most operator obligations, including the high-risk requirements, and €35 million or 7% for prohibited practices (Article 99), whichever is higher, or whichever is lower for SMEs and start-ups. Both regimes can apply to the same conduct, though AI Act authorities must take into account fines already imposed for the same activity (Article 99(7)).

Sources

  1. Automated decisions: UBER fined nearly EUR 825 million — CNIL
  2. Uber hit with a nearly $1 billion fine for automatically deactivating drivers in Europe — Engadget
  3. €825 million fine: Uber sanctioned for automated decision-making — Dastra
  4. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex
  5. Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex

Leaked Council Text Would Add an AI Legitimate-Interest Clause to the GDPR — Not Law

On 21 September 2026 the privacy organisation noyb published Council Presidency document 12535/26, a compromise text dated 3 September 2026 and prepared under the Irish Presidency for the Antici Group meeting of 11 September. It proposes a new GDPR Article 88bis, renumbered from Article 88c in the Commission's Digital Omnibus proposal of 19 November 2025. Under it, processing personal data "in the context of the development and operation of an AI system or of an AI model" could rest on a legitimate interest under Article 6(1)(f).

Compared with the Commission's text, the Presidency draft strikes the four example safeguards: data minimisation in source selection and training, protection against disclosure of data residually retained in the model, enhanced transparency, and an unconditional right to object. The Article 6(1)(f) balancing test remains in every version.

This is an unadopted Presidency draft in the GDPR strand of the Digital Omnibus, which is still in the Council. The EDPB and EDPS (Joint Opinion 2/2026) called for stronger safeguards around the clause, and civil-society groups including noyb have criticised it.

Existing GDPR obligations — the legal basis under Article 6, special categories under Article 9, automated decisions under Article 22 and transparency under Articles 13–14 — are unchanged.

What it means for you

The direction of travel in the Council is towards a broader legitimate-interest route for AI. Even if Article 88bis were adopted as drafted, the balancing test would remain: before processing personal data for AI development or operation, you would still have to document that your interest is not overridden by the rights and interests of the people concerned.

Do not treat this draft as law. Keep conducting and documenting legitimate-interest assessments under the existing Article 6(1)(f).

Sources

  1. noyb: leaked EU draft makes AI data use lawful by default — ResultSense (21.09.2026)
  2. GDPR AI clause leak: why Article 88bis is no free pass — Technspire (21.09.2026)
  3. Digital Omnibus: What the Leaked Council Documents Say About AI and Personal Data — GDPR Local
  4. EDPB-EDPS publish opinion on Digital Omnibus proposal — Matheson

AI Act Enforcement: What Applies Now, and What Waits Until December 2027

The European AI Board held its ninth meeting on 17 September 2026 and discussed AI Act implementation and enforcement. It set no new deadlines; the Board advises, and does not set deadlines or bring cases.

Since 2 August 2026 the Commission can enforce the obligations of providers of general-purpose AI models, and the transparency requirements of Article 50 apply. The Commission has sent a first round of requests for information to general-purpose AI providers. The prohibited practices (Article 5) and the AI literacy duty (Article 4) have applied since 2 February 2025.

National market surveillance authorities have had their powers since 2 August 2026, but the high-risk requirements in Articles 9–17 do not apply to stand-alone Annex III systems until 2 December 2027, so they cannot be enforced against them before then. Reports of a coordinated September "inspection wave" against hiring, credit and healthcare AI could not be traced to any Commission or national-authority source.

What it means for you

The prohibitions, AI literacy and the Article 50 transparency duties are enforceable today: check that you meet them.

For Annex III systems — recruitment and candidate screening (point 4(a)), creditworthiness of natural persons (point 5(b)) and emergency patient triage (point 5(d)) — use the time until 2 December 2027 to build the risk management, documentation, oversight and quality-management evidence. The requirements are not enforceable yet, but they take more than a year to put in place.

Confirm your role. A provider (Article 3(3)) places a system on the market or puts it into service under its own name; a deployer (Article 3(4)) uses one under its own authority in a professional capacity. The obligations differ.

Sources

  1. Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commission (02.08.2026)
  2. European Artificial Intelligence Board — European Commission
  3. CDT Europe's AI Bulletin: September 2026 — Center for Democracy and Technology
  4. EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes — Gibson Dunn (27.05.2026)

What to do this week

  • For each system that takes significant decisions about people automatically, record which Article 22(2) exception it relies on and how people obtain human intervention and contest a decision. Where you rely instead on human review, check that the review is real and that your logs can show it.
  • Make sure your privacy notices explain solely automated decisions under Article 22, their logic, significance and envisaged consequences (Articles 13(2)(f) and 14(2)(g) GDPR).
  • Make sure your process for subject access requests can give the same information about an individual's automated decisions on request (Article 15(1)(h) GDPR).
  • Confirm that you meet the AI Act obligations already enforceable: prohibited practices (Article 5), AI literacy (Article 4) and transparency (Article 50).
  • Map your AI systems against Annex III and set a plan to meet Articles 9–17 by 2 December 2027.
  • Do not base legal-basis documentation on the proposed Article 88bis. Keep documenting legitimate-interest assessments under the existing Article 6(1)(f).
  • If you are commissioning ISO/IEC 42001 certification, ask whether the certification body applies ISO/IEC 42006:2025, the requirements standard for bodies that certify AI management systems.

Quick reference

TopicChangeAction
GDPR — automated decisionsDutch DPA fined Uber €824.99m (announced 21 Aug 2026; under appeal) for fully automated driver deactivationsRecord the Art. 22(2) exception for each automated decision; where a human reviews, make the review real and logged
GDPR — draft Art. 88bisLeaked Council text 12535/26 (3 Sep 2026) adds an AI legitimate-interest clause without four Commission safeguards; not lawKeep documenting Art. 6(1)(f) assessments
AI Act — enforceable nowArts 4, 5 and 50 and GPAI provider obligations; Annex III high-risk requirements from 2 Dec 2027Check current duties; plan Annex III readiness
AI Act — AI BoardNinth meeting 17 Sep 2026; no new deadlinesNone
ISO/IEC 42001 — certificationISO/IEC 42006:2025 sets requirements for bodies certifying AI management systemsAsk your certifier how it applies them

Every source in this issue

  1. Automated decisions: UBER fined nearly EUR 825 million — CNIL
  2. Uber hit with a nearly $1 billion fine for automatically deactivating drivers in Europe — Engadget
  3. €825 million fine: Uber sanctioned for automated decision-making — Dastra
  4. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex
  5. Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex
  6. noyb: leaked EU draft makes AI data use lawful by default — ResultSense (21.09.2026)
  7. GDPR AI clause leak: why Article 88bis is no free pass — Technspire (21.09.2026)
  8. Digital Omnibus: What the Leaked Council Documents Say About AI and Personal Data — GDPR Local
  9. EDPB-EDPS publish opinion on Digital Omnibus proposal — Matheson
  10. Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commission (02.08.2026)
  11. European Artificial Intelligence Board — European Commission
  12. CDT Europe's AI Bulletin: September 2026 — Center for Democracy and Technology
  13. EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes — Gibson Dunn (27.05.2026)
  14. ISO/IEC 42006:2025 — ISO (08.07.2025)

Compiled by Relay Labs Ltd from the sources above, which remain the authoritative text. General information about EU law, not legal advice.

Subscribe

The EU AI governance brief

One email a week. Sourced and dated. Unsubscribe in one click, from any of them.

Relay Labs Ltd is the controller. Your address is used to send you this brief and nothing else. Privacy notice.

More issues
28.09.2026 · Week 40

EU AI Act Regulatory Brief — Week of 28 September 2026

EN 18286:2026, the first European standard written for the AI Act, is published but not yet cited in the Official Journal. The EDPB's draft fining guidelines decide who can be fined, not only how much. Council talks on the GDPR part of the Digital Omnibus continue, with an AI legitimate-interest clause back in the text. No ISO/IEC 42001 change.

Read →
21.09.2026 · Week 39

EU AI Act Regulatory Brief — Week of 21 September 2026

The EDPB adopted draft fining-methodology guidelines and finalised DSA-GDPR interplay guidance at its 21 September plenary. No new EU AI Act enforcement instruments or ISO 42001 revisions were confirmed during the 15-21 September window.

Read →
14.09.2026 · Week 38

EU AI Act Regulatory Brief — Week of 14 September 2026

No new EU AI Act guidance or GDPR enforcement decisions were published this week. The material story is the AI Office's ongoing formal information request campaign against 30-plus GPAI model providers — the Act's first enforcement instruments. Germany and Austria completed ISO 42001 national transpositions in August; the underlying standard is unchanged.

Read →