The word that carries the article is solely: a decision with a real human in it falls outside the prohibition.
Why it matters when the plan changes
Any system that scores people and feeds a consequential decision about them has to be designed with this article in view. The line it draws is not about whether a model was involved but about whether a person with authority and understanding actually made the decision. A signature on an output the signatory could not inspect does not count as one, and the difference between a recommendation and a decision only holds if the person retains the power to depart from what the system suggests.
The tension is that the exceptions are narrow and frequently misread. Explicit consent is one of them, and consent in an employment relationship is treated as unlikely to be freely given. Contractual necessity is another, and it is hard to argue for a promotion decision. In practice the defensible route is meaningful human involvement rather than an exception, with the reasoning visible enough for that person to engage with it, not merely sign it.
In practice
A hiring process adds an automated screen that rejects applicants below a threshold before any person sees the file. A candidate asks how the decision was made and whether a person was involved. Nobody was, and no exception applies. The process is redesigned so that a recruiter reviews every rejection with the reasoning visible, which is what the article had required from the start.
Evidence
A person should not be subject to a decision evaluating personal aspects that is based solely on automated processing and produces legal or similarly significant effects.
Recital 71, General Data Protection Regulation (2016)High-risk systems must be built so people can effectively oversee them while in use, which is the design condition that keeps a decision from being solely automated.
Article 14, European Union Artificial Intelligence Act (2024)
What it cannot tell you
Article 22 addresses the automation of a decision, not the quality or fairness of the model behind it. A process can involve a human at every step and still produce a biased or poorly reasoned outcome; the article is silent on that. It also does not define how substantive human involvement must be, which leaves 'solely' open to interpretation in practice.
Questions
That no person with authority and understanding actually made the decision. Recital 71 of the General Data Protection Regulation (2016) frames this as a right not to be subject to a decision based solely on automated processing. A signature on an unreviewed output does not satisfy that standard.
No. It restricts decisions with legal or similarly significant effects that rest solely on automated processing. A score that informs a human decision, where the human can see the reasoning and depart from it, sits outside the prohibition. The design of that human step is what matters.
Explicit consent, necessity for a contract, and authorisation by law, each with safeguards attached. Article 14 of the European Union Artificial Intelligence Act (2024) reinforces this by requiring human oversight of high-risk systems, which narrows how far any exception can substitute for a genuine human decision.
At minimum the right to obtain human intervention, to express a point of view and to contest the decision. In practice that means the reasoning has to be recorded and available, because a person cannot contest a decision whose basis nobody can show them.
Both are decisions with significant effects on a person, so any automated element in them has to be examined against the article. The usual answer is not to remove models from the process but to make sure a person genuinely decides, with the model's reasoning visible and the ability to disagree.