Are the four tests actually the same test?
| Jurisdiction | Statutory phrase | What it determines | From |
|---|---|---|---|
| United Kingdom | "Meaningful human involvement" (UK GDPR Art. 22A) | Whether the decision is solely automated at all | 5 Feb 2026 |
| Colorado | "Meaningful human review" (SB 26-189) | A deployer duty, with notice and correction | 1 Jan 2027 |
| California | Technology that "replaces or substantially replaces human decision-making" | Whether the tool is ADMT and the rights attach | Duties 1 Jan 2027 |
| Switzerland | "Review by a natural person" (DSG Art. 21 Abs. 2) | A remedy after an exclusively automated decision | In force |
The UK's placement matters most: meaningfulness sits at the entrance, not inside. If involvement is meaningful, the decision is not solely automated and the regime does not engage at all. Switzerland sits at the other end, as an information and review right rather than a prohibition. Kenya's Data Protection Act 2019 s.35 takes the European shape: a right not to be subject to a solely automated decision with legal or significant effects, and a right to request reconsideration or a fresh decision.
Where does an agent sit on the autonomy spectrum?
The binary — autonomous or supervised — is why so many teams believe they sit outside these regimes. Real deployments occupy one of five points.
| Mode | What the person does | Regulatory position |
|---|---|---|
| Fully autonomous | Nothing; the agent acts and the outcome stands | Solely automated on every test; UK Arts. 22A–22D, Swiss Art. 21 and ADMT rights all engage |
| Notify-after | Told once the outcome has issued; may reverse it | Still solely automated; a reversal right is not involvement |
| Approve-exceptions | Reviews only the cases routed out | Meaningful for those cases; everything else stays solely automated |
| Approve-all | Reviews every output before it takes effect | Capable of being meaningful; where the failure patterns bite |
| Human decides, AI advises | The person decides; the model supplies input | Outside these regimes if the authority is real |
Most systems described internally as human-in-the-loop are approve-exceptions or approve-all. Both can qualify; neither does automatically.
How does involvement stop being meaningful?
Three patterns, in ascending order of damage.
What happens when a reviewer approves in batches?
A reviewer confirming two hundred outcomes in a sitting is performing an action, not a judgement, and the throughput is the evidence. It is usually a symptom: the queue was built without a middle tier, so everything routes to review and gets cleared the only way it can be — the design problem treated in approving AI agent actions before execution.
Can a reviewer disagree with what they cannot see?
The second is quieter. The reviewer is conscientious, the volume manageable, and the screen shows a score and a recommendation but not the factors behind them: formal authority to disagree, no practical basis for doing so. The approval rate converges on one hundred per cent, not through negligence but because nothing displayed supports a different answer. Article 22C requires that the data subject be given information about the decision — hard to satisfy when your own reviewer was not.
What if the review was genuine but nothing recorded it?
This one converts a defensible position into an indefensible one. The reviewer read the factors, weighed the circumstances and agreed — and eighteen months later, when the complaint arrives, none of it can be established. The system logged a timestamp and a user ID, not what was shown or considered.
That is a records problem, not a legal one, which is why it goes unowned: it looks like an engineering detail until the day it is the whole case. You were compliant in fact and cannot show it, which before a regulator is the same thing. See building an audit trail for AI agents.
What changed in the UK on 5 February 2026, and in Colorado next?
Section 80 of the Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A–22D, commenced by SI 2026/82. It is prospective only: decisions taken before that date remain under the old Article 22(3), saved by reg. 5.
For non-special-category data the old general prohibition is relaxed: any lawful basis will do, including legitimate interests, subject to the Article 22C safeguards — information about the decision, the ability to make representations, human intervention, a right to contest. Article 22B keeps tighter conditions for special category data: explicit consent, or contract necessity or legal authorisation within the exemptions. That is relocation, not deregulation; the burden moves from establishing a lawful basis to demonstrating the safeguards worked. The ground is still moving — the ICO's 2023 AI guidance is under review, its draft ADM and profiling guidance (consulted 31 March to 29 May 2026) is not final, and SI 2026/425, in force 12 May 2026, requires the Commissioner to prepare a statutory code of practice on AI and automated decision-making. Detail in the DUAA analysis.
And what does Colorado add from 2027?
SB 26-189, signed 14 May 2026, repealed and replaced SB 24-205, which never took effect. Alongside meaningful human review it requires pre-use notice, adverse-outcome disclosure within 30 days, and data correction.
Why is the Swiss contract exception narrower than it looks?
DSG Article 21 covers an automatisierte Einzelentscheidung: a decision based exclusively on automated processing with a legal consequence or significant effect. On request the controller must let the data subject state their position, and the data subject may demand review by a natural person.
Article 21 Abs. 3 lit. a is read too generously. The exception applies where the decision relates to the conclusion or performance of a contract and the data subject's request is granted. Both limbs. An automated approval falls outside it; an automated refusal does not, because the request was not granted. Every case where the automation says no — the declined application, the rejected claim, the withheld limit — stays fully in scope. Those are also the decisions people complain about. See the Swiss analysis.
What does a functioning loop look like?
Three parts, all checkable from outside the organisation.
- Authority. The reviewer can issue a different outcome without escalation, and doing so is not treated as an exception needing justification.
- Information. They see the factors, not only the score and the recommendation.
- Record. Disagreement and its basis are captured; so is what the reviewer was shown when they agree.
One diagnostic follows: if the review never produces a different outcome, that is evidence it is not functioning. A zero override rate across ten thousand cases means the reviewer either has nothing to add or cannot act on what they have, and neither reading survives a regulator putting it to you. Track override rate as a control metric, not as model quality.
FINRA's 2026 Annual Regulatory Oversight Report recommends human-in-the-loop protocols, tracking mechanisms and behavioural guardrails for AI agents, and names autonomy without human validation as a risk. The pairing is deliberate: a protocol you cannot evidence is not a control.
Can the model decide when a human is needed?
No — and this is the failure most often built deliberately. If the model producing the recommendation also decides whether the case is routed for review, the involvement is not independent: the system chooses when it will be supervised, and anything shaping its context shapes whether a person is ever consulted. Routing must be enforced in a layer the agent passes through and cannot reconfigure. The same reasoning runs through the AI agent governance guide and the Californian ADMT obligations, where pre-use notice, opt-out, access to the logic and appeal presuppose that something other than the model knows which decisions are in scope — significant decisions covering financial and lending services, housing, education, employment and independent contracting, and healthcare.
Frequently asked questions
What makes involvement meaningful rather than decorative?
Authority to reach a different conclusion, the information needed to reach it, and a record when it happens.
Does a person approving the output make the decision non-automated?
Not by itself. Article 22A asks whether the involvement is meaningful, not whether a person was present.
Which regimes test the quality of the review?
The UK from 5 February 2026, Colorado from 1 January 2027, California through the ADMT definition, Switzerland through review by a natural person.
Does the Swiss contract exception cover refusals?
No. Art. 21 Abs. 3 lit. a requires that the request be granted, so automated refusals stay in scope.
Can the agent route its own cases for review?
No. That places the supervision decision inside the model's context and removes its independence.
Related
- AI agent governance — the complete guide
- Approving AI agent actions before execution
- How to build an audit trail for AI agents
- Automated decision-making under the DUAA
- Automatisierte Einzelentscheidung nach DSG Art. 21
- CPPA ADMT compliance
BarzelVault records what the reviewer was shown alongside the outcome and the policy version in force, and reports override rates by reviewer and decision type — so whether the review is functioning has an answer before anyone asks.
In practice
Permission before the action. Evidence after it.
The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.
430 days leftEU AI Act high-risk obligations (Annex III) apply from 2 December 2027
BarzelVault
The AI action firewall: decide what an agent may do before it does it.
- Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
- Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
- Credential isolation, spend and action limits, and an emergency kill switch.
Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize
Barzel Central Gateway
The AI governance control plane: one inventory and one policy layer across every MCP server and agent.
- Registers and synchronises every tool; enforces identity, policy, region, cost and health per tool.
- Identity mapping through OIDC, Entra ID, Okta, SAML and SPIFFE, with credential brokerage.
- Trace and SIEM export (W3C trace context, OTLP) for the security team and the regulator.
Free tier: 1,000 calls a monthPaid plans from $10 a monthLive on MCPize
Enterprise: written quote by email within two business days. No sales call.
Sources
- Data (Use and Access) Act 2025, s.80; UK GDPR Articles 22A–22D; SI 2026/82; SI 2026/425.
- ICO, draft guidance on automated decision-making and profiling (consultation 31 March – 29 May 2026).
- Bundesgesetz über den Datenschutz (DSG), Art. 21.
- Colorado SB 26-189; CPPA automated decision-making technology regulations.
- Kenya Data Protection Act 2019, s.35.
- FINRA, 2026 Annual Regulatory Oversight Report.
This article is for information and does not constitute legal advice.