Glossary

DEFINITION

Automated Decision-Making (ADM)

Using algorithms or AI systems to make or substantially influence decisions about individuals — regulated under GDPR Article 22, Colorado SB 24-205, and a growing number of state and sector laws.

In depth

Automated decision-making (ADM) refers to decisions made about individuals where the outcome is produced by algorithmic or AI processing with little or no human review. GDPR Article 22 grants EU residents the right not to be subject to solely automated decisions that produce legal or similarly significant effects, and requires meaningful human review, explanations, and the ability to contest decisions when ADM is permitted. In the United States, state consumer privacy laws increasingly include ADM provisions: Colorado, Virginia, Connecticut, Texas, and Montana require opt-out rights for ADM profiling that produces legal or similarly significant effects; Colorado SB 24-205 (effective February 2026) requires human review for adverse consequential decisions in employment, credit, housing, healthcare, and education. The New York City Local Law 144 (2023) requires independent bias audits of automated employment decision tools. 'Automated' in most regulatory contexts means the AI output has a significant influence on the decision, not that no human ever touches the result — so using ChatGPT or a fine-tuned LLM to score job applications, assess creditworthiness, or triage healthcare access likely qualifies as ADM even if a human reviews the output.

Examples

  • An ATS that uses an AI model to score résumés and automatically reject candidates below a threshold — ADM in employment, regulated by NYC LL144, EEOC guidance, and state privacy laws.
  • A lender using an LLM to generate credit risk assessments that are passed to an underwriter who rarely overrides them — functional ADM even with nominal human review.
  • A healthcare insurer using AI to pre-authorise or deny claims — high-risk ADM under Colorado SB 24-205 and the EU AI Act.

How Locke handles automated decision-making (adm)

Locke protects the data flowing into ADM systems at the prompt level — ensuring that personal data fed into AI scoring or decision models is not unnecessarily expanded beyond what the model needs to produce a useful output. For organisations subject to ADM regulations, keeping prompts to minimum-necessary data also reduces the risk of discriminatory proxy variables entering the model.

See the product