AI Guide

Automated Decision-Making (ADM): Solely automated decisions under GDPR and the EU AI Act

Automated decision-making (ADM) means a decision about a person, such as a credit approval, a job rejection, or an insurance premium, is reached solely by automated means with no meaningful human involvement in that individual case. GDPR Article 22 restricts ADM with legal or similarly significant effects, and the EU AI Act classifies many ADM use cases as high-risk. Learn below what qualifies as ADM, how it differs from human-reviewed automation, and what German Mittelstand companies must do before deploying it.

Key Facts
  • GDPR Article 22 gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects
  • The EU AI Act Annex III classifies ADM systems for credit scoring, employment decisions, and insurance risk assessment as high-risk AI systems
  • Gartner projects that AI agents will soon augment or automate roughly half of everyday business decisions that currently require human judgment
  • Bitkom's 2025 KI-Studie found 36 percent of German companies with 20 or more employees already use AI, nearly double the 20 percent share a year earlier
  • A decision only counts as ADM under Article 22 when it is solely automated; adding a human who can genuinely review and overturn the outcome takes it outside that definition

Definition: Automated Decision-Making (ADM)

Automated decision-making (ADM) is reaching a decision about a person, such as a loan approval or a recruiting rejection, using only automated processing, with no human judgment applied before the outcome takes effect.

Core characteristics of automated decision-making

An ADM system ingests applicant data, applies a scoring model or rule set, and enforces the outcome unreviewed. Under GDPR Article 22, this only counts as ADM when solely automated and legally significant.

  • Nobody could overturn the outcome before it takes effect
  • The result carries legal weight, such as a denied loan
  • Common in credit scoring, recruiting, and underwriting
  • Distinct from AI-assisted decisions with real human discretion

Automated decision-making vs. human-in-the-loop review

ADM and human-in-the-loop review sit on opposite ends of one workflow: in ADM the system’s output is final; in human-in-the-loop, it drafts a recommendation a person can still change. The difference is who controls the outcome, not model sophistication.

Importance of automated decision-making in enterprise AI

ADM sits at the center of current AI regulation because it removes the human safeguard most consumer protection law assumes exists. Gartner projects AI agents will soon automate roughly half of everyday business decisions. Bitkom’s 2025 KI-Studie found 36 percent of German firms with 20+ staff already use AI, up from 20 percent a year earlier.

Methods and procedures for automated decision-making

Three implementation patterns cover most enterprise ADM deployments.

Rule-based decision engines

A rule-based engine applies fixed thresholds to structured data, producing a deterministic, explainable outcome for every matching case.

  • Data intake and validation
  • Rule evaluation against documented criteria
  • Audit log entry for every rule fired

Statistical and machine learning scoring models

Scoring models replace fixed rules with a trained model, such as a gradient-boosted classifier, outputting a probability. These handle more nuance but are harder to explain, so both the EU AI Act and GDPR require documented model logic for solely automated decisions.

Hybrid decision workflows with human sign-off

Many companies keep a human checkpoint in workflows that would otherwise qualify as ADM. The model drafts a recommendation, and an employee reviews flagged cases first, keeping the process out of Article 22 scope while keeping most of the efficiency gain.

Important KPIs for automated decision-making

Enterprises tracking ADM performance monitor three categories of indicators.

Operational throughput KPIs

  • Decision cycle time: target under 2 minutes for standard cases
  • Straight-through processing rate: target 60-80 percent of eligible volume
  • Manual escalation rate: target under 15 percent of total cases
  • Data completeness rate at intake: target above 95 percent

Strategic KPIs

Straight-through processing signals ADM’s business case: McKinsey’s 2025 State of AI report found 88 percent of organizations report regular AI use in at least one function. The real question for Mittelstand leaders is which decisions can be automated without crossing into unsupervised ADM.

Quality KPIs

Fairness monitoring compares outcome rates across demographic segments to catch disparate impact early. Appeal resolution time, how fast a contested outcome reaches a human, is itself a GDPR Article 22 obligation, not just a service metric.

Risk factors and controls for automated decision-making

Three risk categories dominate ADM deployments in regulated, people-facing processes.

Discrimination and bias risk

Bias enters ADM systems through training data or variables that correlate with protected characteristics even when excluded outright.

  • Proxy variables, such as postal code, correlating with protected attributes
  • Historical data encoding past discriminatory decisions
  • Disparate outcome rates by age, gender, or origin going undetected

Regulatory noncompliance risk

GDPR Article 22 and, often, the EU AI Act Annex III high-risk classification for credit scoring, employment, and insurance both apply. A DPIA is required before deployment, and high-risk systems need a FRIA too, neither of which is the ADM system itself, they are the safeguard used to evaluate it.

Contestability and human intervention risk

Article 22 grants individuals the right to human intervention, to state their view, and to contest an outcome. Companies unable to route a contested decision to someone with real authority to change it face enforcement exposure regardless of accuracy.

Practical example

A 140-employee regional insurance underwriter in North Rhine-Westphalia used to route every household policy application through a senior underwriter, creating a two-week backlog each renewal season. It introduced an ADM system that automatically approves standard-tier applications against documented guidelines, while borderline or high-value cases still go to a senior underwriter. The rollout followed a combined DPIA and FRIA.

  • Automatic approval for standard-tier applications within documented guidelines
  • Structured escalation to a senior underwriter for high-value cases
  • Audit trail attached to every decision, referencing the DPIA and FRIA on file
  • Explanation letter generated automatically for every automated rejection

Current developments and effects

Three developments are reshaping how enterprises govern automated decision-making.

Regulatory tightening under the EU AI Act

The EU AI Act adds a second, overlapping layer of obligations on top of existing GDPR duties.

  • Annex III classifies credit scoring, employment, and insurance as high-risk
  • Deployers must maintain instructions for use and human oversight
  • The Digital Omnibus postponed some deadlines to 2027, but Article 22 already applies

Agentic AI blurring the line between assistance and automation

Multi-step AI agents that plan and act across systems blur where assistance ends and ADM begins. A workflow that looks like a recommendation on paper becomes de facto ADM if nobody reviews the output.

Growing demand for decision transparency tooling

Vendors are building explanation layers for automated outcomes, related to but distinct from explainable AI (XAI), which asks whether a model can be interpreted at all.

Conclusion

Automated decision-making will keep expanding as scoring models and AI agents take on more routine judgment calls. GDPR Article 22 and the EU AI Act’s high-risk classification are not going away, and enforcement scrutiny is only likely to grow. Companies that treat the human checkpoint as a deliberate design choice keep both the efficiency gain and the legal safety margin. The question for every Mittelstand leader is where a person still needs to look before an outcome becomes real.

Frequently Asked Questions

Is automated decision-making the same thing as using AI?

No. A company can use AI for analysis without triggering ADM, as long as a person reviews the outcome first. ADM means significant decisions reached without that review step.

Does automated decision-making violate GDPR?

Not automatically. Article 22 restricts, rather than bans, solely automated decisions with significant effects, permitting them under conditions like contractual necessity, and always requiring human intervention on request.

Is automated decision-making relevant for a company with fewer than 100 employees?

Yes, if it decides about customers or employees at real volume. A 40-person lender carries the same Article 22 obligations as a large bank; the difference is resources, not the legal threshold.

What has to happen before deploying an ADM system under the EU AI Act?

For high-risk uses such as credit scoring or employment, deployers need a DPIA, typically a FRIA, documented instructions for use, and a working human oversight mechanism before go-live.

How is automated decision-making different from rule-based systems companies have used for years?

Legally, it is not: a rules engine denying a loan without human review is ADM, same as a machine learning model doing it. What changed is scale and explainability, not the legal category.

Does Superkind build automated decision-making systems?

Superkind’s AI employees prepare recommendations and route flagged cases for a person to sign off on, not unsupervised decisions that trigger Article 22 on their own. A workflow that genuinely needs to qualify as ADM still needs its own DPIA, FRIA, and human-intervention design.

Further Resources

DPIA for AI Agents: How the German Mittelstand Implements GDPR Article 35 for Agent Rollouts in 2026
AI Compliance

DPIA for AI Agents: How the German Mittelstand Implements GDPR Article 35 for Agent Rollouts in 2026

Practical guide for German SMEs on running a DPIA for AI agents. WP248 nine-criteria test, DSK Orientierungshilfen, DPIA vs. FRIA (EU AI Act Art. 27), 7-step process, RAG-specific risks, costs and timelines.

AI in Recruiting: How the Mittelstand Sources, Screens, and Schedules Against a 391,000-Worker Shortage
AI in HR

AI in Recruiting: How the Mittelstand Sources, Screens, and Schedules Against a 391,000-Worker Shortage

A practical guide for German HR leaders on deploying an AI recruiting agent across the whole funnel - active sourcing, application screening, candidate ranking, interview scheduling and candidate comms - against the 391,000-worker shortage. Covers AGG, the EU AI Act high-risk classification (Annex III), DSGVO and Betriebsrat, a build-vs-buy view against Personio, SmartRecruiters, HeyJobs and Paradox, and a 90-day pilot.

EU AI Act: The Omnibus Reprieve - What the Postponed High-Risk Deadline Really Changes for the Mittelstand
AI Compliance

EU AI Act: The Omnibus Reprieve - What the Postponed High-Risk Deadline Really Changes for the Mittelstand

The Digital Omnibus pushed Annex III high-risk obligations to December 2027, but Article 50 transparency, deployer duties, and AI literacy still apply now. What the Mittelstand must keep doing despite the reprieve, and why a deferred deadline is a trap if you stop preparing.

The AI Employee for Credit Management: Running Customer Credit Checks and Limits Without a Credit Analyst Keying It
AI in Finance

The AI Employee for Credit Management: Running Customer Credit Checks and Limits Without a Credit Analyst Keying It

Credit management is routine, knowledge-heavy work that hangs on one analyst. See how an AI employee pulls bureau data, applies your credit policy, and drafts limit recommendations for human approval - while the Company Brain keeps the policy alive when the analyst leaves.

Building better software Contact us together