From the journal

EDPS Publishes Human Intervention Checklist for Automated Decision-Making, 18 May 2026

On 18 May 2026, the European Data Protection Supervisor (EDPS) published a self-assessment checklist on human intervention in automated decision-making (ADM) for EU institutions, bodies, offices, and agencies. The checklist operationalises Article 24 of Regulation (EU) 2018/1725 and Article 22 GDPR and sets out requirements across governance, reviewer competence, process design, appeal mechanisms, and performance monitoring. A human sign-off that does not include access to model inputs, logic, or genuine authority to override fails the EDPS standard.

3 min read

On 18 May 2026, the European Data Protection Supervisor (EDPS) published a Checklist on Human Intervention in Automated Decision-Making as a self-assessment tool for EU institutions, bodies, offices, and agencies (EUI) that operate automated decision-making systems capable of producing decisions with a significant effect on individuals. The checklist is addressed to EUI data controllers and processors and does not bind private entities directly, but its criteria draw on Article 22 GDPR and Article 24 of Regulation (EU) 2018/1725, and the EDPS will use the checklist when assessing EUI ADM practices in supervisory inquiries and audits.

The checklist groups requirements into five domains. Governance and accountability: a documented mandate and a named responsible officer for each ADM system. Reviewer competence and training: reviewers must understand the system's purpose, inputs, known biases, and failure modes. Process design: reviewers must have sufficient time, access to all relevant input data used by the system, and the ability to query the system's reasoning before confirming or overriding its output. Appeal and escalation: a mechanism for individuals to challenge ADM outcomes and for reviewers to escalate uncertain cases to a senior decision-maker. Performance monitoring: the entity must track override rates, error-detection rates, and audit outcomes to assess whether human intervention is functioning in practice and not merely on paper.

Data protection authorities in EU member states routinely cite EDPS guidance when interpreting Article 22 GDPR obligations applicable to private entities. Credit institutions, insurance firms, consumer lenders, employers, and online platforms using automated scoring, risk assessment, eligibility determination, or credit decisioning systems should treat the checklist as the current EU supervisory benchmark for meaningful human review. AI Act deployers of high-risk systems in Annex III categories, including AI used in employment decisions, creditworthiness assessment, education, and law enforcement, have parallel human oversight obligations under Article 14 of the EU AI Act. The EDPS checklist provides implementation detail for those Article 14 requirements where national data protection authorities are likely to look for practical compliance evidence.

The EDPS issued a TechDispatch on human oversight of ADM in September 2025 and is expected to publish further guidance addressing the interaction between GDPR Article 22 and EU AI Act Article 14 as the AI Act's high-risk provisions begin applying from August 2026. Financial institutions subject to EBA Guidelines on Internal Governance and EBA model risk management guidelines should map EDPS checklist requirements against the model validation and human review controls already required under those guidelines to identify gaps specific to ADM-intensive AI systems.

Licentium advises financial entities and AI deployers on human oversight programme design for the EU AI Act, GDPR, and sector-specific obligations. Work we undertake includes AI Act Annex III high-risk system assessments, Article 22 GDPR compliance reviews, ADM governance documentation, fundamental rights impact assessments, and DORA-aligned ICT risk documentation for AI systems.

Source: European Data Protection Supervisor, Checklist on Human Intervention on Automated Decision-Making, 18 May 2026

AI Regulatory

More from the journal

See all

Hong Kong SFC and FSTB Conclude Consultation on Virtual Asset Advisory and Management Regimes, 26 May 2026

On 26 May 2026, Hong Kong's Securities and Futures Commission and Financial Services and the Treasury Bureau published consultation conclusions on proposed licensing regimes for virtual asset advisory and management service providers. The regimes apply the same business, same risks, same rules principle and align SFC licensing requirements with those for securities advisory and management businesses. A bill implementing the regimes is planned for introduction into the Legislative Council in 2026.

OCC Grants Circle Final Charter for First National Digital Currency Bank N.A., 9 July 2026

The Office of the Comptroller of the Currency granted final approval on 9 July 2026 for Circle Internet Group to establish First National Digital Currency Bank, N.A., operating as Circle National Trust. The bank opened 24 July 2026 under direct OCC oversight and will manage USDC reserves on a directed basis, act as collateral trustee for USDC holders, and provide digital asset custody services to Circle affiliates.

Manitoba Enacts Public Sector AI and Cybersecurity Governance Act June 2026

On 1 June 2026, Bill 51, The Public Sector Artificial Intelligence and Cybersecurity Governance Act (S.M. 2026, c. 43), received Royal Assent in Manitoba, Canada. The Act mandates transparency, accountability structures, and cybersecurity incident reporting for public sector entities using AI systems. Substantive obligations take effect only through regulations yet to be made.