From the journal

EDPS Publishes Human Intervention Checklist for Automated Decision-Making, 18 May 2026

On 18 May 2026, the European Data Protection Supervisor (EDPS) published a self-assessment checklist on human intervention in automated decision-making (ADM) for EU institutions, bodies, offices, and agencies. The checklist operationalises Article 24 of Regulation (EU) 2018/1725 and Article 22 GDPR and sets out requirements across governance, reviewer competence, process design, appeal mechanisms, and performance monitoring. A human sign-off that does not include access to model inputs, logic, or genuine authority to override fails the EDPS standard.

3 min read

On 18 May 2026, the European Data Protection Supervisor (EDPS) published a Checklist on Human Intervention in Automated Decision-Making as a self-assessment tool for EU institutions, bodies, offices, and agencies (EUI) that operate automated decision-making systems capable of producing decisions with a significant effect on individuals. The checklist is addressed to EUI data controllers and processors and does not bind private entities directly, but its criteria draw on Article 22 GDPR and Article 24 of Regulation (EU) 2018/1725, and the EDPS will use the checklist when assessing EUI ADM practices in supervisory inquiries and audits.

The checklist groups requirements into five domains. Governance and accountability: a documented mandate and a named responsible officer for each ADM system. Reviewer competence and training: reviewers must understand the system's purpose, inputs, known biases, and failure modes. Process design: reviewers must have sufficient time, access to all relevant input data used by the system, and the ability to query the system's reasoning before confirming or overriding its output. Appeal and escalation: a mechanism for individuals to challenge ADM outcomes and for reviewers to escalate uncertain cases to a senior decision-maker. Performance monitoring: the entity must track override rates, error-detection rates, and audit outcomes to assess whether human intervention is functioning in practice and not merely on paper.

Data protection authorities in EU member states routinely cite EDPS guidance when interpreting Article 22 GDPR obligations applicable to private entities. Credit institutions, insurance firms, consumer lenders, employers, and online platforms using automated scoring, risk assessment, eligibility determination, or credit decisioning systems should treat the checklist as the current EU supervisory benchmark for meaningful human review. AI Act deployers of high-risk systems in Annex III categories, including AI used in employment decisions, creditworthiness assessment, education, and law enforcement, have parallel human oversight obligations under Article 14 of the EU AI Act. The EDPS checklist provides implementation detail for those Article 14 requirements where national data protection authorities are likely to look for practical compliance evidence.

The EDPS issued a TechDispatch on human oversight of ADM in September 2025 and is expected to publish further guidance addressing the interaction between GDPR Article 22 and EU AI Act Article 14 as the AI Act's high-risk provisions begin applying from August 2026. Financial institutions subject to EBA Guidelines on Internal Governance and EBA model risk management guidelines should map EDPS checklist requirements against the model validation and human review controls already required under those guidelines to identify gaps specific to ADM-intensive AI systems.

Licentium advises financial entities and AI deployers on human oversight programme design for the EU AI Act, GDPR, and sector-specific obligations. Work we undertake includes AI Act Annex III high-risk system assessments, Article 22 GDPR compliance reviews, ADM governance documentation, fundamental rights impact assessments, and DORA-aligned ICT risk documentation for AI systems.

Source: European Data Protection Supervisor, Checklist on Human Intervention on Automated Decision-Making, 18 May 2026

AI Regulatory

More from the journal

See all

Finland Gambling Act Ends State Monopoly, Opens Licensed iGaming Market from July 2027

Finland's Gambling Act, approved by the President on 16 January 2026, ends the state monopoly held by Veikkaus Oy and introduces competitive licensing for private iGaming operators in online sports betting and casino verticals. The Finnish Gambling Authority accepts licence applications from 1 March 2026; licensed market operations begin 1 July 2027. Licensed operators pay a flat gross-gaming-revenue tax of 22%.

SEC Adds Regulation Crypto to Rulemaking Agenda with Token Safe Harbor, July 2026

On 7 July 2026, the U.S. Securities and Exchange Commission placed Regulation Crypto on its regulatory priority agenda, the first crypto-specific rulemaking in the agency's history under Chair Paul Atkins. The proposal would create a time-limited registration exemption for early-stage token projects, permit capital raises up to $75 million in a 12-month period, and establish a decentralisation safe harbor for tokens whose issuers have ceased all essential managerial efforts.

Delaware Enacts Stablecoin Modernization Package Aligning State Licensing with Federal GENIUS Act

Delaware Governor Matt Meyer signed the Banking, Money Transmission, and Stablecoin Modernization Package on 6 July 2026, creating a state licensing regime for payment stablecoin issuers under the Delaware Payment Stablecoin Act. Senate Bill 19 establishes reserve requirements, redemption standards, and capital obligations aligned with the federal GENIUS Act and directs the Commissioner of Banks to seek nationwide operating authority through a substantial-similarity certification.