Uber Just Paid €825 Million for Automated Decisions Nobody Explained
Uber just got hit with an €825 million fine from the Dutch privacy regulator, the second largest penalty in GDPR history. The reason should concern every founder who runs software at scale: automated decisions. Uber’s systems suspended driver accounts by algorithm, and drivers never learned why, or how to appeal, or whether a human ever looked at their case.
There was no breach. No leaked database, no hacker, no ransom note. The fine punishes a design choice. Uber let software make serious decisions about people, then treated explanation as optional.
Most companies deploying AI right now are making the same choice. The numbers are smaller. The shape is identical.
What Uber Actually Got Fined For
GDPR Article 22 gives people the right not to be subject to purely automated decisions that carry legal or similarly significant effects. If software decides something that matters, the person affected must be able to get human review, an explanation, and a path to contest the outcome. Losing your income because a model flagged your account clears the “significant” bar easily.
Note that the automation itself was never the crime. Regulators did not fine Uber for using fraud models. They fined Uber for the silence around them. Drivers got deactivated through automated systems without being informed, the Dutch Data Protection Authority found. No notice, no reason, no human to call.
That distinction matters, because it means the fix was never technical. It was organizational, and it was cheap. A notification, a review queue, an appeals process. Uber saved pennies on process and paid €825 million for the savings.
Automated Decisions Are Now a Balance Sheet Item
For a decade the automation math ran one way. Every decision you removed from a human saved money, so the goal was to remove as many as possible. Headcount down, throughput up, margins better. Nobody priced the other side of the trade, because the other side had no enforcement behind it.
That era ended this week. A regulator has now attached a nine figure number to automated decisions made without explanation. Insurance underwriters will read that ruling. So will plaintiff lawyers, procurement teams, and every enterprise buyer who reviews vendor risk before signing.
Meanwhile, the industry is sprinting in the opposite direction. We are wiring up AI agents that act on cases instead of merely scoring them: closing accounts, denying claims, canceling orders, suspending access. Each of those actions is an automated decision with real effects on a real person. Every one of them now carries a question a regulator might someday ask: could the affected person get an explanation and reach a human?
If your honest answer is no, you are accumulating liability at machine speed.
The Support Version of This Problem
I run a support software company, so I watch the small version of this play out weekly. Support is where automated decisions touch customers first, and it is where silence does the most damage.
An AI agent closes a ticket it decided was resolved. A fraud rule freezes an account mid purchase. A warranty bot rejects a claim because the photo looked wrong. In each case the company saved four minutes of human time and spent something harder to measure: the customer’s belief that anyone is accountable on the other end. I wrote about this failure mode in When Your AI Agent Decides to Close the Ticket Anyway, and the Uber ruling is the same disease at regulatory scale.
The pattern repeats because the incentive repeats. Automation gets measured on deflection and cost per contact. Nobody gets a bonus for building the appeal path.
Three Questions Before You Let Software Decide
You do not need a compliance department to avoid Uber’s mistake. You need three questions asked before any automated decision ships.
First, can the affected person reach a human? Not a chatbot loop that eventually surrenders, but an actual review by someone with authority to reverse the outcome.
Second, can you explain the decision? If your own team cannot reconstruct why the system acted, you cannot inform the customer, and you cannot defend the action later.
Third, is there a record and an appeal path? Logs, notice, and a defined way to contest the result. This is boring work. It is also, as of this week, work with a documented price for skipping it.
Teams that answer all three honestly tend to discover something useful. The scariest automated decisions are usually the least reviewed ones, because they sit in fraud, billing, and account systems that no product manager owns.
This Pattern Will Not Stay in Europe
It is tempting for US operators to file this under European regulatory theater. That would be a mistake. GDPR requirements have a history of becoming global product standards, because building two versions of your decision pipeline costs more than building one compliant version.
The bigger force is not regulation anyway. It is customers. Enterprise buyers already ask vendors how AI decisions get reviewed, and they walk when the answer is a shrug. The market is pricing explanation into trust faster than the law is pricing it into fines.
So the winners of the agentic era will not be the companies that automate the most decisions. They will be the companies whose automated decisions survive an audit, an angry customer, and a journalist’s records request. Uber just paid €825 million to establish the benchmark. The least you can do is take the lesson at that price.
