The difference is not whether a model was used but whether a person could see the reasoning and decide otherwise.
Why it matters when the plan changes
The same output can be either, depending entirely on what happens after it appears. If a leader reads a recommendation, weighs the evidence and chooses, the system supported a decision. If the recommendation is applied without anyone in a position to disagree, the system made one. Recital 71 of the GDPR draws this line, reserving to a person the right not to be subject to a decision with legal or similarly significant effects based solely on automated processing. Procurement questions about which is being bought are questions about process design as much as software.
The tension is that decision support only works as such when the person is equipped to disagree. A confident recommendation with no visible reasoning invites deference, and deference at scale is automated decision-making by another name. Research on human-AI combinations found the pairing can perform worse than either alone, showing presence alone is not a safeguard. The design obligation is to make disagreement practical, which costs certainty in the room.
In practice
A platform presents a ranked list of internal candidates for a role with a score beside each name. A hiring manager takes the top name because nothing on the screen gives them a reason not to. On paper a human decided. In substance the list did. The same list with evidence, counter-evidence and a confidence beside each entry produces a different conversation and sometimes a different appointment.
Evidence
A person should not be subject to a decision evaluating personal aspects based solely on automated processing with legal or similarly significant effects.
Recital 71, General Data Protection Regulation (2016)Pairing people with a model is not automatically better than either alone; it depends on how the combination is designed.
Vaccaro, Almaatouq and Malone, When Combinations of Humans and AI Are Useful (2024)
What it cannot tell you
The distinction describes where accountability sits, not whether the underlying model is accurate or fair. A system can meet every condition for decision support, visible reasoning, a person free to disagree, and still recommend badly. The label says who is answerable for the outcome; it says nothing about whether the outcome deserved to be trusted.
Questions
Ask what the person can see and do. If they can inspect the evidence, the confidence and what argues against the recommendation, and can choose differently without friction, it is decision support. If the output is applied by default and disagreeing means fighting the system, it is automated in substance.
No. Recital 71 of the GDPR, 2016, prohibits solely automated decisions with legal or similarly significant effects, but decision support falls outside that specific rule while a lawful basis, transparency duties and, for high-risk uses under the AI Act, documentation and oversight obligations still apply regardless of who takes the final decision.
Easily. Deference grows as a system earns trust, and a recommendation that is always followed has become a decision. Guarding against it means keeping the reasoning visible, recording overrides and their reasons, and treating a fall in override rates as something to examine rather than celebrate.
The person who owns the consequence of the decision. Placing the review with someone who does not carry the consequence produces the form of oversight without the substance, because they have no particular reason to spend the effort that genuine disagreement takes.
Not automatically. Vaccaro, Almaatouq and Malone's 2024 study on human-AI combinations found the pairing can perform significantly worse than either humans or the model alone. It works when the person contributes context the model cannot see and the process for combining the two is disciplined.