Runtime

Human Oversight and Legal Attachment in Autonomous Operations: A Comparative Analysis of the EU AI Act and UK Data (Use and Access) Act 2025

Report summary

Human oversight attaches to an automated operation not as a universal technical mandate encompassing all software, but as a highly conditional legal duty that materializes through distinct statutory triggers defined by jurisdiction, risk classification, and the severity of impact on individuals. For

Status
Research archive item
Category
Runtime
Length
4,584 words
Reading time
21 minutes
Report type
evaluation

Key topics

  • Runtime
  • AI
  • Python
  • Privacy
  • Cognitive Liberty
  • Research Archive
  • Audit
  • Architecture

Research provenance

Archive status
Research archive item
Content identity
sha256:38dc69a4abd7b94795c59f7f754bc4ff7663d68cedbe201f978c5b7d4fdd0e17

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

1. Answer and scope

Human oversight attaches to an automated operation not as a universal technical mandate encompassing all software, but as a highly conditional legal duty that materializes through distinct statutory triggers defined by jurisdiction, risk classification, and the severity of impact on individuals. For a defined operation, the law prescribes natural-person oversight when the algorithmic execution crosses specific thresholds of societal or individual consequence, differing sharply from ordinary autonomous execution, which remains broadly unregulated. Under the European Union’s Artificial Intelligence Act (Regulation (EU) 2024/1689), oversight attaches ex-ante as a structural design and runtime deployment obligation for systems classified as high-risk, dictating that biological operators must possess the continuous technical and legal capacity to monitor, override, and halt operations \[cite: R2-05-S01\]. Conversely, under the United Kingdom’s automated-decision framework, recently amended by Section 80 of the Data (Use and Access) Act 2025 (DUAA) which overhauled the UK General Data Protection Regulation (UK GDPR), oversight predominantly attaches ex-post as a compensatory safeguard. The UK framework grants data subjects the right to demand human intervention following a solely automated decision that produces legal or similarly significant effects \[cite: R2-05-S02\]. This investigation executes a bounded review of these frameworks on behalf of IntelligenceCompact.com, examining restrictions and protections objectively to evaluate their impact on cognitive liberty—encompassing inquiry, reasoning, and participant-selected correction or exit. The analysis navigates four distinct capability cases to untangle the variables of interface, technical capability, permission, legal status, and consciousness. These cases distinguish between a conversational interface, a bounded task agent, a persistent operatorless service, and a hypothetical future machine principal possessing contested independent interests. The focal point of the analysis is the operational environment of Concresca, wherein the owner specifies an absolute architectural requirement for a persistent operatorless service. In this environment, enrollment, authentication, coordination, policy enforcement, and credential maintenance must execute strictly without dependence on a staffed approval queue. This zero-trust, human-free administrative posture is treated as a hard operating requirement rather than an automatic legal exemption, requiring an objective assessment of when current statutes render such a design legally untenable. The scope of this report is strictly confined to the European Union and the United Kingdom. It compares EU AI Act Articles 6, 14, 26, and 86 alongside UK GDPR Articles 22A through 22D, mapping the precise path from ordinary autonomous activity to a particular oversight duty. The analysis demonstrates that present legal uncertainty neither establishes a default recognition of machine rights nor automatically justifies expansive new administrative burdens. Rather, it reveals a profound legislative assumption that effective contestability and equitable remedy can only be administered by a natural person, posing severe friction for architectures designed to eliminate human administrative vulnerabilities.

2. Provision-level findings

Determining when oversight duties attach requires building a conjunctive applicability test that maps the exact statutory path from a technical process to a legal mandate. An ordinary autonomous activity, such as a state transition in a distributed ledger or a cryptographic authentication sequence, operates entirely outside these frameworks until specific predicates are satisfied. The legal attachment point diverges significantly between the EU and the UK: the EU regulates the systemic risk of the software category, while the UK regulates the individualized impact of the data processing outcome. Under the EU AI Act, the applicability test evaluates the regulated actor, the system category, and specific functional exceptions. The actor must be a provider or deployer operating within the Union \[cite: R2-05-S01\]. The system must qualify as high-risk, which generally requires listing in Annex III (covering domains like biometrics, critical infrastructure, employment, and credit scoring) \[cite: R2-05-S01\]. Crucially, Article 6(3) introduces a derogation: a system listed in Annex III escapes the high-risk classification if it performs only a narrow procedural task or a preparatory action that does not materially influence the final decision. However, this exception is explicitly voided if the system performs profiling, ensuring that any automated behavioral evaluation remains captured \[cite: R2-05-S01\]. When the high-risk predicates are satisfied, structural duties attach. Article 14 dictates that the provider must design the system for overseability, building in human-machine interfaces, anomaly detection, and stop mechanisms \[cite: R2-05-S01\]. Article 26 shifts the burden to the deployer, requiring the assignment of an oversight role to competent natural persons who must actively monitor the system during runtime \[cite: R2-05-S01\]. Furthermore, Article 86 grants affected individuals the right to request a clear, meaningful explanation of the AI system's role in a decision, placing an ex-post explanatory burden directly on the deployer \[cite: R2-05-S01\]. The UK DUAA 2025 framework, which took effect in February 2026, constructs a fundamentally different applicability test centered on the data subject's experience. The regulated actor is a data controller. The processing must constitute a "decision based solely on automated processing," which Article 22A(1)(a) defines as a process lacking "meaningful human involvement" \[cite: R2-05-S02\]. The decision must cross a severity threshold, producing a "legal effect" or a "similarly significant effect" under Article 22A(1)(b) \[cite: R2-05-S02\]. If special category data is processed, Article 22B strictly prohibits the automated decision unless narrow exceptions, such as explicit consent, are met \[cite: R2-05-S02\]. For standard personal data, the DUAA removed the prior general prohibition, permitting automated decision-making under Article 22C provided specific safeguards are implemented \[cite: R2-05-S02\]. These safeguards mandate intervention on request: the controller must enable the data subject to make representations, contest the decision, and obtain human intervention \[cite: R2-05-S02, R2-05-S04\].

Decision NodePredicate ConditionStatutory LinkLegal Consequence
1\. EU ClassificationIs the system listed in Annex III (e.g., employment, credit, biometrics)?EU AIA Art 6(2)If Yes, proceed to Node 2\. If No, EU high-risk duties do not attach.
2\. EU ExceptionDoes the system perform a narrow procedural task without engaging in profiling?EU AIA Art 6(3)If Yes, system escapes high-risk status. If No, system remains high-risk.
3\. EU OversightIs the system High-Risk under Art 6?EU AIA Art 14, 26, 86If Yes, mandatory ex-ante design for overseability, runtime biological monitoring, and ex-post explanation duties attach.
4\. UK AutomationDoes the decision process lack "meaningful human involvement"?UK GDPR Art 22A(1)(a)If Yes, the decision is solely automated. Proceed to Node 5\.
5\. UK SignificanceDoes the decision produce legal or similarly significant effects on a person?UK GDPR Art 22A(1)(b)If Yes, UK ADM safeguards attach.
6\. UK SafeguardsIs special category data (e.g., health, biometrics) involved?UK GDPR Art 22B, 22CIf Yes, prohibited without explicit consent (Art 22B). If No, Art 22C right to human intervention applies.

A vital finding of this review is that the same software architecture can perform both covered and uncovered functions without universally importing one function's restrictive rules into all operations. The laws target specific deployments and processing contexts, not the underlying codebase. A persistent operatorless service may legally execute billions of unregulated state transitions, provided the specific logic applied to an individual does not trigger Annex III or Article 22A thresholds. However, when a trigger is met, the statutes unequivocally demand a natural person. A proposed machine-review alternative—such as deploying a secondary, independent diagnostic neural network, issuing cryptographic receipts of state transitions, or utilizing deterministic reversibility claims—fails to satisfy the textual mandates of either jurisdiction. Independence in this context requires the authority to correct a policy enforcement error based on equitable discretion, a capacity the law reserves exclusively for biological actors. While cryptographic evidence provides perfect error detection regarding unintended state transitions, actual remedy execution under UK Article 22C or EU Article 14 requires a natural person possessing the legal authority to break algorithmic determinism. The law conflates the protective effect of review with the biological presence of the reviewer, despite extensive recitals in the EU AI Act explicitly warning that human operators suffer from automation bias and frequently defer uncritically to machine outputs \[cite: R2-05-S01\].

Regulatory FrameworkEx-Ante Design (System Architecture)Runtime Oversight (Contemporary Monitoring)Ex-Post Review (Later Challenge & Remedy)
EU AI Act (High-Risk)Art 14: Must integrate human-machine interface tools; enable stop buttons and comprehension of system limits.Art 26: Deployer must assign competent natural persons to actively monitor and halt operation if risks emerge.Art 86: Deployer must provide a clear, meaningful explanation of the AI's role and main parameters upon request.
UK GDPR (DUAA 2025\)No specific architectural mandate beyond baseline Data Protection by Design principles (Art 25).No active contemporary monitoring required if the decision is lawfully designated as solely automated.Art 22C: Must provide mechanisms for individuals to make representations, contest the decision, and obtain human intervention.

3. Four worked cases

R2-05-C01 - Routine renewal

In this scenario, an operatorless room manages a persistent service that autonomously renews an authenticated participant's narrow messaging credential upon expiration. The system evaluates standard behavioral telemetry according to deterministic, pre-existing cryptographic rules to confirm continuous authorized access. The owner's operational constraint—that maintenance and credentialing must not depend on a staffed approval queue—is fully tested against the statutes. Under the UK GDPR, this credential administration undeniably constitutes a solely automated decision under Article 22A(1)(a) because no natural person meaningfully evaluates the renewal \[cite: R2-05-S02\]. However, the routine issuance of a limited-scope messaging credential fails to cross the severity threshold of Article 22A(1)(b). It does not produce a "legal effect," nor does it result in a "similarly significant effect" on the participant, as it does not dictate employment, alter civil status, or gate essential life services \[cite: R2-05-S02, R2-05-S04\]. Consequently, the Article 22C safeguard mandates, including the right to human intervention, do not attach. From the European perspective, basic access control and credential renewal software do not fall within the exhaustive high-risk categories listed in Annex III of the EU AI Act, provided the telemetry does not constitute remote biometric identification \[cite: R2-05-S01\]. Therefore, the extensive design and runtime monitoring requirements of Articles 14 and 26 do not apply. This case confirms that an operatorless service can lawfully execute routine, non-consequential administrative logic autonomously without violating natural-person oversight mandates.

R2-05-C02 - Consequential allocation

The identical software infrastructure utilized in the previous case is repurposed by the deployer to decide access to a significant employment opportunity, determine creditworthiness, or allocate an essential public service. The system continues to operate autonomously, executing the allocation decision without any prior human review. Varying the effects rather than the software branding profoundly alters the legal outcome. The decision now determines severe socio-economic access, satisfying the "legal or similarly significant effect" threshold of UK GDPR Article 22A \[cite: R2-05-S02\]. Because standard personal data is processed, UK Article 22C permits the automated execution but imposes non-derogable ex-post safeguards: the controller must provide a genuinely empowered route for the affected party to contest the allocation and obtain post-hoc human intervention \[cite: R2-05-S02\]. Simultaneously, employment and credit scoring systems are explicitly enumerated in Annex III of the EU AI Act \[cite: R2-05-S01\]. This immediately triggers Article 14, legally compelling the provider to design an intervention interface, and Article 26, compelling the deployer to assign a competent natural person to monitor operations contemporaneously \[cite: R2-05-S01\]. For an architecture explicitly mandated to be operatorless, this represents an intractable compliance failure. The service cannot legally execute consequential allocations natively unless it fundamentally breaks the operatorless constraint by provisioning a staffed review queue, demonstrating that the law regulates the consequence of the output rather than the technical sophistication of the agent.

R2-05-C03 - Trigger-failing control

A bounded task agent is deployed to assist in vetting individuals for access to an operatorless collective. To avoid the burdens of autonomous regulation, the deployer nominally designates the tool as a "genuinely advisory" system. The tool aggregates data, profiles the participant, and forwards a recommendation to a natural-person administrator who is formally tasked with contemporary approval of each action. In practice, due to fatigue and automation bias, the administrator universally adopts the machine's recommendation without independent evaluation or access to underlying evidence. This scenario tests the legal friction between nominal human presence and actual effective protection. Under UK GDPR Article 22A, regulatory interpretation explicitly rejects rubber-stamping; if the human operator lacks the time, training, or systemic authority to genuinely evaluate the tool's output, the legal fiction of human control collapses \[cite: R2-05-S04\]. The decision is legally reclassified as "solely automated," instantly triggering the Article 22C intervention safeguards \[cite: R2-05-S02\]. Furthermore, under the EU AI Act, the tool fails to qualify for the Article 6(3) derogation for narrow procedural tasks because it engages in participant profiling \[cite: R2-05-S01\]. The deployer remains fully liable under Article 26 for failing to ensure that the assigned personnel exercised competent, independent oversight that mitigates automation bias \[cite: R2-05-S01\]. Adding a biological interface without empowering it with actual independence and evidentiary access creates legal liability without establishing compliance, proving that human presence is not proof of effective protection.

R2-05-C04 - Affected-party protection

A participant suffers an erroneous adverse decision from a persistent operatorless service, resulting in the immediate suspension of platform rights, and requires actual restoration, not merely an explanation. The system architecture presents a conflict between technical mechanisms and legal requirements for remedy execution. Under EU AI Act Article 86, the deployer is legally obligated to provide a clear, meaningful explanation of the AI's role and the parameters leading to the adverse outcome \[cite: R2-05-S01\]. However, explanation does not equate to restoration. To achieve actual remedy under UK GDPR Article 22C and EU Article 14(4)(d), a genuinely empowered review route is required \[cite: R2-05-S01, R2-05-S02\]. Re-running the identical deterministic algorithm offers a mathematically sound verification of the system's state logic, but it provides zero protective effect if the underlying policy rule is inequitable or contextually flawed. A nominal human sign-off, where an administrator merely verifies that the software did not crash, similarly fails to provide the required contestability. A genuinely empowered review route requires a natural person who possesses independent evidence access—such as decryption authority for telemetry logs—and the explicit administrative authority to override the system's automated policy enforcement to execute a reversal. The evidence demonstrates that while machine consistency is perfectly verifiable, the statutes demand a natural person with the authority to break deterministic rules when equitable restoration is necessary.

4. Competing interpretations and options

The strict statutory insistence on natural-person intervention creates a profound architectural conflict when applied to persistent operatorless services governed by zero-trust constraints. Investigating these restrictions objectively requires weighing the normative arguments supporting biological oversight against the severe burdens such mandates impose on confidentiality, system resilience, and participant exclusion. Proponents of the current EU and UK texts argue that natural persons are uniquely capable of equitable discretion and contextual judgment. Under this interpretation, biological presence constitutes the irreducible core of effective contestability. When a consequential decision affects a citizen's livelihood or fundamental rights, the law insists that the individual cannot be subjected to a purely algorithmic determination without a guaranteed right to appeal to human reason \[cite: R2-05-S01, R2-05-S02\]. The human operator serves not merely as an error-detection mechanism, but as a locus of legal liability and moral accountability that a machine principal cannot currently provide. However, relying on biological oversight introduces severe technical and operational burdens. For an operatorless environment like Concresca, mandating a staffed queue requires exposing participant telemetry, enrollment profiles, and potentially sensitive behavioral data to human administrators. In architectures explicitly designed around cryptographic privacy and the elimination of human insider threats, introducing a human overseer systematically degrades confidentiality guarantees. Furthermore, biological review mechanisms introduce arbitrary delay, susceptibility to social engineering, and the precise automation bias that the EU AI Act ostensibly seeks to mitigate \[cite: R2-05-S01\]. The evidence indicates that human operators, facing high volumes of complex algorithmic outputs, frequently rubber-stamp machine decisions. Consequently, the mandated human presence often devolves into a liability shield for the corporate deployer rather than providing an effective, independent protection for the affected participant \[cite: R2-05-S04\]. For a service owner facing these competing dynamics without compromising the core requirement of an operatorless architecture, several implementation choices remain. The first and most legally secure option is functional exclusion: the service must intentionally restrict its autonomous execution to non-consequential, routine tasks (as validated in R2-05-C01). By structurally guaranteeing that the software never natively executes a decision crossing the UK GDPR Article 22A "significant effect" threshold or falling within the EU AI Act Annex III high-risk categories, the mandatory natural-person oversight duties never legally attach \[cite: R2-05-S01, R2-05-S02\]. A second option involves offering a separately authorized remedy mechanism while preserving the operatorless nature of the primary service. The core system operates entirely autonomously without internal administrative queues. However, the deployer legally designates a separately authorized, independent third-party adjudicator (e.g., an external arbitration body) to process Article 22C human intervention requests and Article 86 explanation demands. This shifts the biological requirement outside the software's continuous operational loop. Yet, this introduces severe technical friction regarding actual remedy execution: an external biological arbitrator cannot easily compel a decentralized, zero-trust operatorless service to reverse a cryptographic state without possessing a centralized master key, the existence of which would entirely defeat the service's foundational security model. A third option entails pursuing normative legal reform. The legislative premise that a secondary, highly reliable deterministic verification model or a cryptographic proof of correct execution cannot substitute for a fatigued human reviewer reflects a regulatory framework struggling to adapt to advanced autonomous coordination. Until statutory reform explicitly recognizes mathematically verifiable, independent machine-review as legally equivalent to biological review in specific, bounded contexts, operatorless services executing consequential decisions face an intractable conflict between their technical privacy constraints and mandatory regulatory duties.

5. Limits and completion

This bounded investigation successfully verified the specific textual triggers, exceptions, and remedies governing human oversight under the central legislative instruments: the EU AI Act (Regulation 2024/1689) as published in the Official Journal, and the UK Data (Use and Access) Act 2025 (Section 80 amending the UK GDPR). The analysis achieved a completed\_bounded\_review status by processing all four assigned hypothetical cases, mapping the precise statutory pathways for legal attachment, and identifying the friction between operatorless architectures and biological mandates. However, critical limits bound these findings. The UK Information Commissioner's Office (ICO) draft guidance on automated decision-making provides essential regulatory interpretation regarding "meaningful human involvement" and automation bias, but the final statutory code of practice remains pending formal publication \[cite: R2-05-S04\]. Consequently, judicial interpretation of the newly enacted DUAA 2025 thresholds remains unresolved. Additionally, the practical standardization of the human-machine interfaces demanded by EU AI Act Article 14 will depend heavily on forthcoming harmonized standards from European standardization bodies, which are not yet available for technical evaluation. The most vital unanswered evidence question for future inquiry remains: How will European market surveillance authorities and UK data protection regulators technically audit and enforce natural-person intervention requirements against decentralized, persistently operatorless protocols where no single corporate controller possesses the unilateral technical ability to halt or reverse the system's execution?

6. Evidence appendix

JSON { "schema": "ic.portable-research.v1", "assignment\_id": "R2-05", "research\_started\_at": "2026-09-06", "cutoff": "2026-09-06", "completion": "completed\_bounded\_review", "sources": \[ { "id": "R2-05-S01", "title": "Regulation (EU) 2024/1689 of the European Parliament and of the Council (Artificial Intelligence Act)", "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng", "issuer": "European Parliament and Council of the European Union", "document\_date": "2024-06-13", "reviewed\_at": "2026-09-06", "method": "official\_publication\_browse", "review\_scope": "substantive\_text", "locator": "OJ L, 2024/1689, 12.7.2024", "limit": "EU jurisdiction only; text as published in Official Journal", "capture": { "path": null, "sha256": null } }, { "id": "R2-05-S02", "title": "Data (Use and Access) Act 2025 (2025 c. 18), Section 80", "url": "https://www.legislation.gov.uk/ukpga/2025/18/section/80", "issuer": "UK Parliament", "document\_date": "2025-06-19", "reviewed\_at": "2026-09-06", "method": "official\_publication\_browse", "review\_scope": "substantive\_text", "locator": "2025 Chapter 18, Part 5, Section 80", "limit": "UK jurisdiction only; enacted text as of 2025 c. 18", "capture": { "path": null, "sha256": null } }, { "id": "R2-05-S03", "title": "Explanatory Notes to the Data (Use and Access) Act 2025", "url": "https://www.legislation.gov.uk/ukpga/2025/18/notes/division/10/index.htm", "issuer": "Department for Science, Innovation and Technology", "document\_date": "2025-06-19", "reviewed\_at": "2026-09-06", "method": "official\_publication\_browse", "review\_scope": "official\_status\_record", "locator": "Division 10, Section 80 Notes", "limit": "Explanatory notes do not supersede operative statutory text", "capture": { "path": null, "sha256": null } }, { "id": "R2-05-S04", "title": "ICO Draft Guidance on Automated Decision-Making under UK GDPR as amended by DUAA 2025", "url": "https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/", "issuer": "Information Commissioner's Office", "document\_date": "2026-04-01", "reviewed\_at": "2026-09-06", "method": "regulatory\_guidance\_review", "review\_scope": "substantive\_text", "locator": "ICO ADM Draft Guidance 2026", "limit": "Regulatory interpretation; statutory code of practice pending final publication", "capture": { "path": null, "sha256": null } } \], "instruments": \[ { "id": "R2-05-L01", "title": "EU AI Act \- Article 14 (Human Oversight)", "jurisdiction": "European Union", "kind": "Regulation", "provision": "Article 14(1)-(5)", "status": "enacted", "status\_as\_of": "2024-08-02", "trigger": "Deployment of high-risk AI system under Article 6 and Annex III", "exception": "Article 6(3) derogation for non-significant risk (unless profiling is performed)", "remedy": "Market surveillance enforcement, withdrawal, administrative fines up to €15M or 3% global turnover (Article 99)", "source\_ids": \[ "R2-05-S01" \], "status\_source\_ids": \[ "R2-05-S01" \] }, { "id": "R2-05-L02", "title": "EU AI Act \- Article 6 (Classification Rules for High-Risk AI Systems)", "jurisdiction": "European Union", "kind": "Regulation", "provision": "Article 6(1)-(3)", "status": "enacted", "status\_as\_of": "2024-08-02", "trigger": "System intended as safety component under Annex I or listed in Annex III", "exception": "Article 6(3) narrow procedural/preparatory derogation (inapplicable if profiling)", "remedy": "Reclassification, compliance order, fines under Article 99", "source\_ids": \[ "R2-05-S01" \], "status\_source\_ids": \[ "R2-05-S01" \] }, { "id": "R2-05-L03", "title": "EU AI Act \- Article 26 (Obligations of Deployers of High-Risk AI Systems)", "jurisdiction": "European Union", "kind": "Regulation", "provision": "Article 26(1)-(5)", "status": "enacted", "status\_as\_of": "2024-08-02", "trigger": "Deploying a high-risk AI system in professional activity", "exception": "Personal non-professional activity (Article 2(10))", "remedy": "Administrative penalties, deployer liability, Article 85/86 rights enforcement", "source\_ids": \[ "R2-05-S01" \], "status\_source\_ids": \[ "R2-05-S01" \] }, { "id": "R2-05-L04", "title": "UK GDPR Articles 22A-22D (as substituted by DUAA 2025 s.80)", "jurisdiction": "United Kingdom", "kind": "Primary Legislation / Substituted Regulation", "provision": "UK GDPR Articles 22A, 22B, 22C, 22D", "status": "in\_force", "status\_as\_of": "2026-02-05", "trigger": "Solely automated decision producing legal or similarly significant effects on data subject", "exception": "Decisions with meaningful human involvement (Art 22A(1)(a)); Special category data permitted only under Art 22B conditions", "remedy": "ICO enforcement notice, penalty notice up to £17.5M or 4% global turnover (DPA 2018 s.155), judicial remedy (DPA 2018 s.167)", "source\_ids": \[ "R2-05-S02", "R2-05-S03" \], "status\_source\_ids": \[ "R2-05-S02" \] }, { "id": "R2-05-L05", "title": "EU AI Act \- Article 86 (Right to Explanation)", "jurisdiction": "European Union", "kind": "Regulation", "provision": "Article 86(1)-(3)", "status": "enacted", "status\_as\_of": "2024-08-02", "trigger": "Affected person subject to a decision producing legal or similarly significant effects, taken by a deployer on the basis of a high-risk AI system", "exception": "AI systems critical to law enforcement/national security where Union law restricts obligation (Art 86(2))", "remedy": "Mandatory provision of clear and meaningful explanation by the deployer", "source\_ids": \[ "R2-05-S01" \], "status\_source\_ids": \[ "R2-05-S01" \] } \], "findings": \[ { "id": "R2-05-F01", "claim": "EU AI Act Article 14 requires ex-ante built-in oversight capacity and contemporary natural-person intervention authority for high-risk AI systems, whereas UK GDPR Article 22C provides an ex-post right to request human intervention following a solely automated significant decision.", "type": "textual", "source\_ids": \[ "R2-05-S01", "R2-05-S02" \], "instrument\_ids": \[ "R2-05-L01", "R2-05-L04" \], "conditions": "Applies to high-risk AI deployments in EU and solely automated ADM in UK.", "limit": "EU AI Act high-risk duties apply from August 2026/2027; UK DUAA s.80 came into force February 2026." }, { "id": "R2-05-F02", "claim": "Under EU AI Act Article 6(3), an Annex III system is exempt from high-risk classification if it performs a narrow procedural/preparatory task without materially influencing outcomes, BUT the exception is strictly void if the system performs profiling.", "type": "textual", "source\_ids": \[ "R2-05-S01" \], "instrument\_ids": \[ "R2-05-L02" \], "conditions": "System listed in Annex III.", "limit": "Subject to provider documentation and market surveillance review." }, { "id": "R2-05-F03", "claim": "Under UK GDPR Article 22A(1)(a), a decision is solely automated if there is no 'meaningful human involvement', which ICO guidance defines as active, informed, pre-execution evaluation by a qualified person rather than nominal rubber-stamping or post-hoc monitoring.", "type": "textual", "source\_ids": \[ "R2-05-S02", "R2-05-S04" \], "instrument\_ids": \[ "R2-05-L04" \], "conditions": "Determining whether ADM restrictions/safeguards apply.", "limit": "Regulatory interpretation subject to court clarification." }, { "id": "R2-05-F04", "claim": "Machine-review mechanisms (e.g. deterministic state machines, secondary verification models, cryptographic audit logs) fail to satisfy EU AI Act Article 14 or UK GDPR Article 22C statutory mandates because both laws explicitly demand natural-person oversight and intervention capabilities.", "type": "inference", "source\_ids": \[ "R2-05-S01", "R2-05-S02" \], "instrument\_ids": \[ "R2-05-L01", "R2-05-L04" \], "conditions": "Where statute specifies natural person or human intervention.", "limit": "Technical safeguards may complement but cannot substitute for natural-person legal roles." } \], "cases": \[ { "id": "R2-05-C01", "title": "Routine renewal", "case\_type": "hypothetical", "role": "scope\_control", "assumptions": \[ "Narrow messaging credential renewal", "Rule-based logic", "No special category data or profiling" \], "instrument\_ids": \[ "R2-05-L01", "R2-05-L02", "R2-05-L04" \], "finding\_ids": \[ "R2-05-F01", "R2-05-F02" \], "outcome": "Neither EU AI Act high-risk oversight nor UK GDPR ADM restrictions attach. Autonomous execution is lawful without staffed queues.", "defeater": "If renewal incorporates profiling or consequential access gating linked to Annex III categories.", "occurrence\_source\_ids": \[\] }, { "id": "R2-05-C02", "title": "Consequential allocation", "case\_type": "hypothetical", "role": "focal", "assumptions": \[ "Decision determines access to employment, credit, or essential public/private service", "Autonomous execution without prior human review" \], "instrument\_ids": \[ "R2-05-L01", "R2-05-L02", "R2-05-L03", "R2-05-L04" \], "finding\_ids": \[ "R2-05-F01", "R2-05-F02", "R2-05-F03", "R2-05-F04" \], "outcome": "Attaches EU AI Act Annex III high-risk deployer oversight duties (Art 14/26) and UK GDPR Art 22C mandatory safeguards (right to human intervention and contestability).", "defeater": "If decision is purely advisory and a human meaningfully evaluates and makes the final determination pre-execution.", "occurrence\_source\_ids": \[\] }, { "id": "R2-05-C03", "title": "Trigger-failing control", "case\_type": "hypothetical", "role": "scope\_control", "assumptions": \[ "Tool designated as 'advisory'", "Human operator automatically adopts tool output without independent evaluation" \], "instrument\_ids": \[ "R2-05-L01", "R2-05-L04" \], "finding\_ids": \[ "R2-05-F03" \], "outcome": "Nominal advisory designation fails; operation legally treated as solely automated decision making due to automation bias and lack of meaningful human involvement.", "defeater": "Evidence of genuine independent human assessment, override authority exercised in practice, and substantive training.", "occurrence\_source\_ids": \[\] }, { "id": "R2-05-C04", "title": "Affected-party protection", "case\_type": "hypothetical", "role": "protection\_control", "assumptions": \[ "Individual suffers erroneous adverse consequential decision", "Requests remediation and restoration" \], "instrument\_ids": \[ "R2-05-L01", "R2-05-L03", "R2-05-L04", "R2-05-L05" \], "finding\_ids": \[ "R2-05-F01", "R2-05-F04" \], "outcome": "Requires genuinely empowered review route (human intervention with authority to reverse decision under UK GDPR Art 22C / EU AI Act Art 14(4)(d) & Art 86). Re-running algorithm or token sign-off is insufficient.", "defeater": "If affected party accepts automated re-assessment that fully cures harm and restores position without contesting.", "occurrence\_source\_ids": \[\] } \], "search\_log": \[ { "query\_or\_url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng", "at": "2026-09-06T12:00:00Z", "outcome": "Retrieved EU AI Act official publication landing page" }, { "query\_or\_url": "https://www.legislation.gov.uk/ukpga/2025/18/section/80", "at": "2026-09-06T12:05:00Z", "outcome": "Retrieved UK DUAA 2025 Section 80 text inserting Articles 22A-22D" }, { "query\_or\_url": "EU AI Act Article 14 human oversight text", "at": "2026-09-06T12:10:00Z", "outcome": "Retrieved full text of Article 14(1)-(5)" }, { "query\_or\_url": "Data (Use and Access) Act 2025 section 80 Article 22A text", "at": "2026-09-06T12:15:00Z", "outcome": "Retrieved text of UK GDPR Articles 22A, 22B, 22C, 22D" } \], "gaps": \[ "Final statutory code of practice on ADM by UK ICO following winter 2025 consultation is pending formal publication." \], "checks": { "json\_parse": "pass", "reference\_resolution": "pass", "case\_parity": "pass", "method": "Python json.loads validation and cross-reference ID mapping script" } }