Can You Opt Out of Automated Decisions?
Synthocracy Institute · Explainer · by Martin Novak · July 2026
Short answer: Sometimes — and it depends heavily on where you live and what the decision is. In the EU, GDPR Article 22 gives you a right not to be subject to a purely automated decision that significantly affects you. In California, new rules let you opt out of automated decision-making for significant decisions. But these rights carry large exceptions, can be sidestepped by adding a token human, and often cost you something to use.
Key takeaways
- The EU’s GDPR Article 22 and California’s ADMT rules both give you rights around automated decisions — but with important limits.
- A landmark EU ruling (SCHUFA, 2023) closed one loophole: a credit score can count as an automated decision, even if a human formally signs off.
- Another loophole remains open: adding a token human reviewer can remove you from the strongest protections — the ceremonial-human problem.
- The US has no federal law; protection is a state-by-state patchwork, and California’s rules narrowed in the final version.
- The deepest catch is practical: opting out is often slower, costlier, or worse-served. A right you’re punished for using is barely a right.
Can you opt out of automated decisions?
Increasingly, yes — but conditionally, and the fine print matters more than the headline. Two systems lead the world here: the EU’s GDPR and California’s privacy rules. Both give you a foothold. Neither gives you a clean exit.
The honest summary: you often have a right to contest or demand a human review of an automated decision, and sometimes a right to opt out of one. What you rarely have is a frictionless way to make a decision-maker set the machine aside and treat you as a person — for free.
What does GDPR Article 22 actually give you?
In the EU, GDPR Article 22 says you have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal effects or similarly significant effects on you. Where the right applies, you’re entitled to safeguards: human intervention, the chance to express your view, and the right to contest the decision.
There are three big exceptions. The automated decision is allowed if it is necessary for a contract, authorised by law, or made with your explicit consent. In practice, “necessary for a contract” and “consent” (often bundled into terms you must accept to proceed) cover a great deal of everyday automation.
A 2023 ruling strengthened the right. In SCHUFA (Court of Justice of the EU, C-634/21), a credit agency argued it merely produced a score and that banks made the actual lending decisions. The court disagreed: because an insufficient score effectively always led to refusal, generating the score was itself an automated decision under Article 22. The effect was to pull upstream scoring — not just the final “yes/no” — into the protection.
The loophole: how a token human can cancel your rights
Here is the catch that connects everything. Article 22 applies to decisions made solely by automation. Add a human, and the strongest protections may fall away — even if that human changes nothing.
Legal analysts noted a perverse implication of SCHUFA: a company might be in a marginally better legal position by inserting a human reviewer only when it rejects you, because that can move the decision out of the “solely automated” category. In other words, the law can be satisfied by exactly the figure we have described elsewhere — the ceremonial human: a person present to sign, not to decide.
The law can give you the right to a human. It cannot, by itself, make that human free to disagree.
This is why “there was a human in the loop” is not proof your rights were honoured. The question is whether that human had the authority, information, and independence to reach a different answer.
What rights do you have in the US?
There is no federal equivalent of Article 22. Protection is a patchwork of state laws, and California is furthest along.
Under rules finalised by the California Privacy Protection Agency in 2025, businesses using automated decision-making technology (ADMT) for significant decisions — those with important consequences for someone’s life, opportunities, or access to essential services — must give consumers an opt-out right, a plain-language pre-use notice, and the ability to request information about the system and human review. Most obligations phase in by January 1, 2027. California uses an opt-out model, and its “significant decision” scope is broader than GDPR’s “legal effects.”
But the final rules narrowed: ADMT is generally implicated only when the system directly determines whether a service is provided or denied — leaving systems that heavily shape a decision without formally making it in a greyer zone. Colorado has a separate, narrower automated-decision regime arriving in 2027. Elsewhere in the US, rights are thinner or absent.
Why “human review” often isn’t real review
Both systems lean on a “right to human intervention” or “human review.” On paper, that’s your safeguard. In practice, it is only as strong as the human behind it.
If the reviewer simply re-reads the machine’s output — under time pressure, trusting a system that is usually right, with no access to the underlying facts — then “human review” restates the automated decision rather than checking it. This is automation bias meeting the ceremonial human. A right to review that returns you to the same answer is a right in name.
The real catch: the cost of refusal
Suppose your rights apply and the human is genuine. There is still a final barrier, and it is the one most people actually hit: opting out costs you something.
Refuse the automated path and you may wait longer, pay more, receive worse service, lose access, or be treated as an anomaly to be scrutinised. The analogue queue is slower; the human line is shorter-staffed; the “manual review” takes weeks. Over time, opting out drifts toward a premium — a comfort the well-resourced can buy and others cannot.
A right to refuse that punishes you for using it is not a right. It’s a toll.
This is the quiet way synthocracy secures itself. It does not need to remove your right to say no. It only needs to make saying no expensive enough that almost no one does. Refusal survives as a minimal channel of agency — real, but rationed by cost.
How to actually exercise your rights
You have more leverage than it feels like. Concretely:
- Ask if a decision was automated, and request the logic, significance, and likely consequences of the processing.
- Request human review — and ask whether the reviewer can access the underlying facts and depart from the system’s recommendation.
- Contest the outcome in writing, citing the relevant right (GDPR Article 22 in the EU; your state’s ADMT/opt-out rules in the US).
- Document the friction. If opting out is penalised, that penalty is itself part of the story regulators need.
→ To test whether a decision is genuinely accountable, use The Ten Questions. For why the “human” often isn’t a safeguard, see The Ceremonial Human. For the deeper fix, see Admissibility.
General information, not legal advice. Your rights depend on your jurisdiction and the specific circumstances; consult a qualified professional for your situation.
FAQ
Can you opt out of automated decisions? Sometimes. The EU’s GDPR Article 22 lets you avoid or contest purely automated decisions with significant effects; California’s ADMT rules give an opt-out for significant automated decisions. Both have major exceptions and vary by jurisdiction.
What is GDPR Article 22? It is the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — with exceptions for contract, law, or explicit consent, and safeguards including human review and the right to contest.
Does adding a human reviewer remove my rights? It can. The strongest GDPR protections apply to decisions made “solely” by automation, so a token human reviewer can move a decision out of scope — even if that human changes nothing. Whether the human is meaningful is the real question.
Do Americans have a right to opt out of automated decisions? There is no federal right. California’s finalised ADMT rules provide an opt-out for significant automated decisions (phasing in by 2027), and some other states have narrower rules; many have none.
Why is opting out often difficult? Because it usually carries a cost — slower service, higher prices, or reduced access. A right that penalises you for using it functions as a toll, not a true choice.
Martin Novak is the founder of the Synthocracy Institute, an independent research institute studying how decision-making power shifts through AI systems. Warsaw, operating internationally. Sources include GDPR Article 22, the CJEU’s SCHUFA ruling (C-634/21), and the California Privacy Protection Agency’s ADMT regulations.
