DEFINITION
Automated Decision-Making (ADM)
Using algorithms or AI systems to make or substantially influence decisions about individuals — regulated under GDPR Article 22, Colorado SB 24-205, and a growing number of state and sector laws.
In depth
Automated decision-making (ADM) refers to decisions made about individuals where the outcome is produced by algorithmic or AI processing with little or no human review. GDPR Article 22 grants EU residents the right not to be subject to solely automated decisions that produce legal or similarly significant effects, and requires meaningful human review, explanations, and the ability to contest decisions when ADM is permitted. In the United States, state consumer privacy laws increasingly include ADM provisions: Colorado, Virginia, Connecticut, Texas, and Montana require opt-out rights for ADM profiling that produces legal or similarly significant effects; Colorado SB 24-205 (effective February 2026) requires human review for adverse consequential decisions in employment, credit, housing, healthcare, and education. The New York City Local Law 144 (2023) requires independent bias audits of automated employment decision tools. 'Automated' in most regulatory contexts means the AI output has a significant influence on the decision, not that no human ever touches the result — so using ChatGPT or a fine-tuned LLM to score job applications, assess creditworthiness, or triage healthcare access likely qualifies as ADM even if a human reviews the output.
Examples
- An ATS that uses an AI model to score résumés and automatically reject candidates below a threshold — ADM in employment, regulated by NYC LL144, EEOC guidance, and state privacy laws.
- A lender using an LLM to generate credit risk assessments that are passed to an underwriter who rarely overrides them — functional ADM even with nominal human review.
- A healthcare insurer using AI to pre-authorise or deny claims — high-risk ADM under Colorado SB 24-205 and the EU AI Act.
How Locke handles automated decision-making (adm)
Locke protects the data flowing into ADM systems at the prompt level — ensuring that personal data fed into AI scoring or decision models is not unnecessarily expanded beyond what the model needs to produce a useful output. For organisations subject to ADM regulations, keeping prompts to minimum-necessary data also reduces the risk of discriminatory proxy variables entering the model.
See the productRelated terms
- GDPR
The EU General Data Protection Regulation — the world's most comprehensive data-protection law, governing how organisations handle personal data of EU residents.
- CCPA
The California Consumer Privacy Act and its 2023 successor, the CPRA — the United States' most influential state-level privacy law.
- EU AI Act
The European Union's comprehensive AI regulation, which classifies AI systems by risk level and imposes conformity assessments, transparency obligations, and prohibitions on certain high-risk uses.