
Uber’s $964 Million GDPR Fine: The AI Governance Warning Every Business Should Understand
Data Privacy, AI Governance, GDPR, Risk Management
Uber’s $964 Million GDPR Fine: The AI Governance Warning Every Business Should Understand
Artificial intelligence and automation are rapidly moving from tools that assist employees to systems that can recommend—or even make—business decisions.
That distinction matters.
On August 24, 2026, SecurityWeek reported that Dutch data protection authorities imposed an €825 million fine—approximately $964 million—on Uber over the company's use of automated software to suspend driver accounts. According to the report, some suspensions were permanent and were made without human review to verify whether the automated decision was correct. The regulator said the practices violated the European Union’s General Data Protection Regulation, or GDPR. Uber disagrees with the decision and has said it will appeal.
The alleged violations themselves occurred between 2018 and 2022, which is an important distinction: this is not a newly discovered Uber system suddenly malfunctioning in 2026. What is new is the regulatory action—and the size of the penalty—which should get the attention of every organization deploying AI, machine learning, analytics, or automated decision-making.
For business leaders, the lesson is bigger than Uber.
Automation does not eliminate accountability.

What Happened With Uber?
According to the Dutch Data Protection Authority, Uber used automated systems to make decisions affecting drivers' accounts, including suspensions that could prevent a driver from earning income through the platform.
The regulator's central concern was not simply that software was being used.
It was that consequential decisions were allegedly being made without adequate human review, while drivers were also not properly informed about the automated decision-making process.
Uber disputes the regulator's conclusions. The company said the investigation examined historical policies that had already been discontinued and stated that its current processes include human reviews, safeguards, and opportunities for drivers to appeal decisions.
That distinction matters. Regulatory findings and a company's response should both be represented accurately, particularly while an appeal is pending.
But from an AI-governance perspective, the case raises a question every organization now needs to answer:
Where does automation stop and accountable human decision-making begin?
GDPR Already Places Limits on Fully Automated Decisions
This is not simply an emerging AI-policy concept.
European data protection law already establishes protections related to automated decision-making.
The European Commission explains that individuals generally have the right not to be subjected to decisions based solely on automated processing when those decisions produce legal effects or similarly significantly affect them. The Commission also explains that, when automated decision-making is permitted under applicable exceptions, organizations need appropriate safeguards that can include human intervention, the ability for an individual to express their position, and the ability to contest a decision.
Organizations are also expected to provide information about automated decision-making, including the logic involved and potential consequences where applicable.
That is where this case becomes highly relevant to today's AI deployments.
Businesses increasingly have systems that can:
Screen applicants;
Score leads or customers;
Detect fraud;
Evaluate employee behavior;
Prioritize customer support cases;
Approve or reject transactions;
Analyze worker performance;
Recommend disciplinary actions;
Terminate access to systems;
Identify suspicious activity; and
Make recommendations that employees may simply accept without independent review.
Not every one of these functions automatically violates GDPR or another regulation.
The governance problem begins when organizations no longer understand how much authority they have delegated to the technology.

Strong AI governance begins with documented policies, clear ownership, and regular review.
AI Governance Is More Than Having an AI Policy
Many businesses believe AI governance means writing an acceptable-use policy telling employees which AI tools they can use.
That is only one component.
As AI becomes integrated into business workflows, governance needs to address the entire decision lifecycle.
A mature organization should know:
What decision is the system making?
Is AI merely providing information to an employee, or can its output directly trigger an action?
What data is being used?
What personal, employment, financial, operational, customer, or sensitive information feeds the decision?
How significant is the outcome?
There is a major difference between AI recommending the order of marketing emails and AI determining whether a worker can continue earning income.
Who validates the decision?
A human technically being "in the loop" is meaningless if that person routinely clicks approve without reviewing the evidence.
Can the decision be challenged?
Organizations need defined procedures for reviewing errors, exceptions, disputes, and unexpected algorithmic outcomes.
Can the organization explain what happened?
If leadership, an auditor, a regulator, a customer, or an affected employee asks why a decision occurred, the company should not discover that nobody knows.
Human-in-the-Loop Cannot Be a Checkbox
One of the most important lessons for businesses deploying AI is that human oversight needs to be substantive.
Putting an employee at the end of an automated workflow does not automatically create meaningful governance.
If an AI system generates a recommendation and the employee is expected to rubber-stamp hundreds of recommendations per day, the practical decision-maker may still be the automated system.
Effective human oversight requires people to have the authority, information, training, and time necessary to challenge the machine.
That may include:
Clearly defining which decisions require mandatory human approval;
Presenting the underlying evidence used to make a recommendation;
Establishing escalation thresholds;
Logging who reviewed and approved an action;
Allowing reviewers to override automated recommendations;
Documenting why an override occurred;
Periodically testing false positives and false negatives; and
Providing a documented appeal or correction process where appropriate.
The European Commission specifically identifies human intervention and the ability to contest certain automated decisions among the safeguards associated with automated decision-making under GDPR.
This Is Also a Cybersecurity Issue
AI governance and cybersecurity are becoming inseparable.
An automated decision system is ultimately another component of the organization's technology environment. It has identities, permissions, data sources, APIs, integrations, logs, models, rules, and increasingly the ability to initiate actions.
That expands the attack surface.
Consider an automated fraud-detection system that can suspend accounts. If an attacker manipulates the data feeding that system, compromises an integration, abuses credentials, or changes a configuration, the attacker may not need direct administrative access to every downstream system.
They may only need to influence the automated decision.
The same principle applies to AI agents.
As organizations give agents permission to send messages, access documents, create accounts, modify records, interact with applications, execute workflows, or make recommendations, those agents should be treated as privileged digital identities, not merely productivity tools.
The security questions therefore become:
What is the agent authorized to access?
What actions can it execute?
What approvals are required?
Can its permissions be limited?
Are its actions logged?
Can anomalous behavior be detected?
Can the agent be rapidly disabled?
Can an attacker manipulate the information it receives?
What happens when the AI is wrong?
These are cybersecurity architecture questions as much as they are AI questions.
Shadow AI Makes the Governance Problem Harder
There is another layer businesses cannot ignore: Shadow AI.
Leadership may carefully govern the company's official AI platform while employees independently adopt other AI services, browser extensions, copilots, autonomous agents, or automation tools.
That creates two completely different environments.
The first contains approved AI with defined controls.
The second may contain tools the organization does not know exist.
If employees begin connecting unauthorized AI applications to company email, cloud storage, CRM systems, financial platforms, source code, customer databases, or internal documents, the business may have no reliable understanding of what information is being processed—or what automated actions are taking place.
Organizations therefore need both sides of AI governance:
Govern the AI you intentionally deploy, and discover the AI you did not authorize.
Five Controls Business Leaders Should Implement Now
The Uber situation provides a useful trigger for organizations to examine their own automation before a regulator, customer, employee, auditor, or incident forces the conversation.
1. Inventory Automated Decision Systems
Document systems using AI, algorithms, rules engines, automated scoring, or autonomous agents.
Identify what each system does, what data it consumes, and what decisions it can influence.
2. Classify Decisions by Business Impact
Not all automation requires the same controls.
A system recommending meeting times carries substantially different risk from one deciding employment, access, financial, healthcare, contractual, or customer eligibility outcomes.
Higher-impact decisions require stronger oversight.
3. Require Meaningful Human Review
Define situations in which a human must review and approve an action before it becomes effective.
Do not confuse a nominal approval button with meaningful oversight.
4. Create Logging and Auditability
Maintain records showing what the system recommended, what information influenced the decision where feasible, who approved the result, what action occurred, and when it occurred.
You cannot govern what you cannot reconstruct.
5. Establish an AI Governance Program
Assign ownership.
Define acceptable use.
Maintain an AI application inventory.
Review third-party AI vendors.
Establish cybersecurity controls.
Document approval authority.
Address privacy and data handling.
Build an incident-response process for AI-related events.
And periodically test whether the controls actually work.
The Bigger Lesson From Uber
The important takeaway from the Uber case is not that businesses should stop automating decisions.
Automation can create enormous operational value.
The lesson is that organizations cannot transfer accountability to an algorithm.
The European Commission's GDPR guidance reinforces the importance of transparency, safeguards, human intervention, and the ability to contest certain consequential automated decisions.
As AI agents become more capable and businesses automate more workflows, this issue will only become more important.
Executives need visibility into what automated systems are doing across their organizations. IT needs architectural and access controls. Cybersecurity teams need monitoring and incident-response capabilities. Compliance and legal teams need to understand how applicable requirements affect automated decisions. Employees need clear procedures for when human judgment must take control.
The companies that handle AI responsibly will not be the companies with the longest AI policy.
They will be the companies that can answer a much harder question:
When our technology makes or influences a consequential decision, can we prove that it was authorized, governed, reviewable, secure, and accountable?
If you would like to learn more about building secure AI governance and managing automated decision-making risk in your organization, schedule an appointment with Elliptic Systems here: https://ellipticsystems.com/discoverycall
