More and more decisions about us — small and large ones, routine and life-shaping — are being taken by machines. We are entering an age in which algorithms decide, or co-decide, on jobs, education, loans, social benefits, insurance, and the content we are shown. The EU GDPR and the EU AI Act address automated decision-making (ADM) directly and, in central cases, require a human “in the loop”. Some national laws, notably the new Italian AI statute, address these issues in specific sectors. But what does this actually mean in practice? When is a human click enough, and when is it not? This talk sets out where the EU GDPR and the EU AI Act draw the line, where national rules may add further obligations, and, in particular, which concrete design choices in ADM projects may decide whether human oversight is what it claims to be: a last sovereign act of human decision.
