Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over […]

Uber is facing an €825 million (approximately $964 million) fine from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) for its use of fully automated systems to suspend or deactivate driver accounts without human review. The AP ruled that Uber violated the General Data Protection Regulation (GDPR) by making significant decisions affecting individuals' livelihoods solely through algorithms, and by failing to adequately inform drivers about these automated processes.
The fine specifically addresses Uber's practices between 2018 and 2022. During this period, Uber's software monitored driver behavior and customer reviews. If the system detected suspected fraud or consistently low customer ratings, driver accounts were automatically deactivated, either temporarily or permanently, leading to a loss of income. The AP emphasized that these decisions were made without any human assessment or oversight.
Under GDPR, fully automated decisions that can significantly impact a person's life are restricted, particularly if they remove an individual's ability to earn a living without human intervention. The regulation also mandates that companies disclose when automated systems are used to make such decisions. The AP found Uber deficient on both counts.
Uber has stated its intention to appeal the decision and the size of the fine. The company claims that the regulator's examination focused on outdated policies and systems that have since been discontinued. Uber also asserts that it takes decisions affecting driver income seriously and has implemented human reviews, safeguards, and an appeals process for drivers. The appeal is expected to clarify whether these protections were in place during the period covered by the fine or were introduced later.
This is not the first time Uber has faced penalties from Dutch regulators. It marks the fourth fine imposed by the AP on Uber. A previous significant fine of €290 million in 2024 concerned the transfer of European drivers' personal data to the United States without adequate protections, a decision Uber also appealed.
The case highlights a broader issue within the gig economy, where many platforms rely on algorithms for managing workers, routes, and account statuses. The ruling underscores the potential costs for companies that depend on automated decisions without sufficient human oversight, signaling that simply attributing decisions to "the algorithm" is no longer acceptable under EU law when individuals' livelihoods are at stake.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs



Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as