AI Control Brief, September 2026: can your enterprise explain and reverse an automated decision?

EUR 825 million for switching off drivers with nobody looking first, the AI Office's first requests to model providers, and a deletion case that reaches your recruitment AI. What changed, where it touches your AI, what to do next.

Share
The Beagle cover: the words Control Brief on a plum field, September 2026. The Beagle AI Control Brief, a monthly briefing on European AI supervision for enterprises.
The Beagle AI Control Brief
September 2026
Reporting period: 16 August to 14 September 2026
This month: AI rules and supervision · Automated decisions · Related control lessons

The month in 60 seconds

The Dutch data protection authority, the AP, fined Uber close to EUR 825 million for switching off drivers' accounts by software, with nobody looking first. This is not the AI Act but a 2018 GDPR rule for any software deciding about a person. If a system of yours suspends, rejects or restricts someone, the review before the decision is the control I would expect a regulator to look for.

The European Commission's AI Office sent its first requests for information to more than 30 providers of general-purpose AI models. Your model supplier's safety, security and copyright file has become something a supervisor can ask to see. So can you.

The CNIL fined an engineering consultancy EUR 300,000 for candidates' erasure requests it did not handle properly. Any AI that reads candidate data inherits that duty: a deletion has to reach every store the model reads.

The development that matters most

What happened. The AP's decision, announced on 21 August 2026, fines Uber EUR 824,990,000. Between 2018 and 2022, Uber's software deactivated drivers' accounts for suspected fraud or low customer ratings, sometimes permanently. The AP found no human assessment in the process, and that drivers were not properly told a machine was deciding. It calls this a breach of the GDPR's prohibition of fully automated decisions (Article 22). Uber has appealed, so read it as what the regulator expects, not a final court ruling.

Where it touches enterprise AI. Article 22 gives a person the right not to be subject to a decision made only by a machine when it affects them in a legal or similarly significant way. Exceptions exist (a contract that needs it, a law that allows it, explicit consent), and even then the person keeps the right to human intervention, to put their case and to contest. The AP's summary does not say which exception Uber claimed. A fraud model freezes a customer account, a claims engine rejects a file, a recruitment tool closes an application. None is an AI Act case today, and each can fall under Article 22 when the effect is significant and nobody decides before the action lands.

What it changes. The AP's finding covers 2018 to 2022, when it found no assessment before the decision. Uber told Reuters its current policies include human reviews and a way to dispute. Inside the exceptions, the legal minimum is human intervention on request, and I would not stop there. A person before the decision is the design that keeps you out of that dispute. That person needs the authority to change the outcome, the time to look, and the information the system used. The record to keep follows from it: inputs, rule or model version, reviewer, reason, final decision.

What to ask for. One recent decision that restricted a customer or an employee, traced from the signal to the outcome, with the name of the person who could have stopped it, this week.

Where the person sits in an automated decision
A person before the decision appliesAn automated signal such as a fraud flag or a low rating runs through a versioned rule or model to a proposed outcome; a person with authority, time and the information used reviews it before it applies, the decision is then applied and explained, and the person affected can contest it and a named role can reverse it. The fully automated route that skips the review is what the Dutch regulator found unlawful for decisions with major consequences, with few exceptions. The record to keep: inputs, rule or model version, reviewer, reason, final outcome. Signal a fraud flag, a low rating Rule or model version recorded Proposed outcome suspend the account A person reviews it before it applies with authority, time, the information used, and the power to change it Decision applied and explained the person is told what happened and why Contest and reverse a named role can change the outcome Fully automated: no person before it applies unlawful for major decisions, with few exceptions THE RECORD TO KEEP inputs · version · reviewer · reason · final outcome A person before the decision appliesAn automated signal such as a fraud flag or a low rating runs through a versioned rule or model to a proposed outcome; a person with authority, time and the information used reviews it before it applies, the decision is then applied and explained, and the person affected can contest it and a named role can reverse it. The fully automated route that skips the review is what the Dutch regulator found unlawful for decisions with major consequences, with few exceptions. The record to keep: inputs, rule or model version, reviewer, reason, final outcome. Signal a fraud flag, a low rating Rule or model version recorded Proposed outcome suspend the account A person reviews it before it applies with authority, time, the information used and the power to change it Decision applied and explained the person is told what happened and why Contest and reverse a named role can change the outcome Fully automated: no person before it applies. Unlawful for major decisions, with few exceptions THE RECORD TO KEEP inputs · version · reviewer · reason · outcome
The Dutch regulator did not object to software flagging a driver. It objected to the account being switched off with nobody looking first: "These decisions should have been looked at first by a human being," said its deputy chair. The AP did not say the next part, but it follows: a complaint channel after the fact does not replace that review. What to ask for: one decision, traced through every box.

Two more signals worth your attention

The AI Office starts asking model providers for evidence

What happened. On 1 September the Commission confirmed that its AI Office had sent its first requests for information to more than 30 general-purpose AI providers. Its spokesperson named two topics: the safety and security of the most advanced models, and copyright and transparency. These are requests, not findings, and I found no recipient list or fine published by 14 September.

Where it touches enterprise AI. The customer-service assistant built on a vendor's model, the document summariser your claims team uses: anything with a vendor's general-purpose model underneath, by API, through a cloud provider's contract, or on your own servers.

What it changes. The provider carries the AI Act duties for the model, and your own duties stay where they were. They sit under the GDPR for the data, under the supplier rules of DORA (the EU's operational-resilience law for financial firms) where it applies, and from December 2027 under the AI Act's high-risk rules. When someone asks how you checked the model underneath, the question now rests on those rules, and the vendor's file becomes part of your file.

What to ask for. Ask the model supplier, or the contract owner when it comes through a cloud provider, for four things: the training-content summary (public), the technical documentation (contractual, Article 53), a summary of its latest external evaluation, and how incidents and model changes reach you.

The CNIL fines a consultancy for deletions that never happened

What happened. On 9 September the CNIL published its 21 July decision fining EXTIA, an IT and engineering consultancy, EUR 300,000. Of 265 erasure requests received in 2024, mostly from candidates, more than three quarters were not handled or badly handled, and 166 people were never told the outcome. No appeal has been reported.

Where it touches enterprise AI. The CNIL said nothing about AI. I would put this decision next to a recruitment assistant that ranks candidates, a talent-pool search, and an evaluation set built from past applications.

What it changes. "Delete" has to travel through the applicant tracking system, the talent pool, the vector index behind the search, the evaluation dataset and the processors that handle data for you. The trained model itself is the open question, and a deletion that stops at the front office is the EXTIA case with an AI attached.

What to ask for. One candidate's deletion, traced through every system that holds a copy, with the confirmation sent to the person.

What to do in the next 30 days

Suggested management actions, not legal requirements. If you are the CEO, ask each business-unit head for the one decision their systems take against a person with nobody reviewing it first, on one page, by 15 October. Ask the DPO to confirm the Article 22 analysis for that decision and what the person was told.

Three actions for the next 30 days
ReaderActionConcrete result to request
CIO, with the decision ownerTrace one automated decision (rule or model) with real consequences for a person, from input to outcome.A record showing the system version, the information used, the reviewer and the final decision.
COOWalk through how staff challenge and reverse an automated outcome.A demonstrated process on one real case, including who has the authority to intervene.
Transformation leaderReview where AI moves from advising someone to taking action.An inventory of the decisions where AI acts on a customer or employee with no one deciding first, each with a named owner and the conditions for approving it.

The CIO's trace shortens the next legal review, because a decision that can be shown can be approved. The COO's walkthrough saves the rework that starts when the first complaint arrives, and the transformation leader's inventory lets a use case grow from advising to acting without a new committee each time.

One control to test

Take one decision your systems make about a person: a blocked payment, a rejected claim, a candidate not shortlisted. Ask its owner for the last case. What did the system see? Which version of the rule or model ran? Who looked at it before it applied, and could that person have said no? What was the person affected told? Answers from records mean you have a control. Answers from memory mean you have a story, and the AP has just shown what it thinks a story is worth.

The standing question, every month: pick one AI-supported decision that affects a customer or employee. Can the responsible manager explain what happened, identify who could intervene, and show how an error would be corrected?

What we are watching next

Uber's appeal against the AP decision: filed, no hearing date public.

The AI Office requests: whether any becomes a formal investigation, and whether the Commission publishes its questions.

The AI Act dates after the Digital Omnibus (Regulation (EU) 2026/1744): stand-alone high-risk systems in employment, credit, life and health insurance and essential services from 2 December 2027. AI in regulated products from 2 August 2028. General-purpose AI obligations have applied since August 2025, with Commission enforcement since 2 August 2026.

The Platform Work Directive (2024/2831), due in national law by 2 December 2026: human oversight and review of automated decisions such as account restrictions.

Sources and scope

Autoriteit Persoonsgegevens, 21 August 2026, EUR 824,990,000: announced, under appeal. AP announcement. CNIL note, 24 August. Uber's statement: Reuters, via Insurance Journal.

European Commission AI Office, requests to more than 30 general-purpose AI providers, confirmed on 1 September 2026: preliminary requests, no finding, no recipient list. Spokesperson statement reported by Agence Europe, 3 September; I found no Commission web page by 14 September. Powers: AI Act Service Desk.

CNIL, EXTIA, decision of 21 July 2026 published 9 September, EUR 300,000: published, no appeal reported. CNIL decision note.

Digital Omnibus on AI, Regulation (EU) 2026/1744, Official Journal 24 July 2026: EUR-Lex. Platform Work Directive (EU) 2024/2831: EUR-Lex.

Also verified but not covered: Garante, BBVA Italia, more than EUR 5.5 million, 3 September, promotional messages sent for seven months after a customer's objection; the bank blamed two systems that did not line up. Garante newsletter.

Reporting period: 16 August to 14 September 2026. Excluded: a paper-records case, two hospital data-access cases, a nuisance-calls fine, national penalty tables, and the research's predictions. Related control lessons are my analysis.

Outside the EU. The UK ICO said on 11 September it is investigating Police Scotland's handling of subject-access requests: an investigation, not a finding. Relevant if an AI-supported service must answer "what do you hold on me" within a month.

Common questions

Is the Uber fine an AI Act case?

No. It is a GDPR case under Article 22, the right not to be subject to a decision made only by a machine when it has a significant effect on you. The AI Act's high-risk rules for employment and platform-work systems apply from 2 December 2027. Article 22 applies today, to any automated system, whether or not anyone calls it AI.

What counts as meaningful human review?

A person who looks before the decision applies, with the authority to change it, the time to look, and the information the system used. A reviewer who can only click "confirm" is not a review. Inside the GDPR's exceptions, human intervention on request is the legal floor. After the Uber decision, a review before the decision is the safer design.

Should we wait for the AI Act high-risk rules before fixing this?

No. Fixing the review and the record now also produces most of the evidence the AI Act will ask for in 2027, so the work is not done twice.