The Brief
Issue 13 · 1 September 2026
No one reviewed the decision. Now it's an €825 million problem.
€825 million for a decision no one reviewed. France's bar bodies write the playbook, its courts start testing it. A hidden prompt reaches further when a lawyer's licence is on the line.
On 21 August the Dutch data protection authority fined Uber €824,990,000. The finding: automatic deactivation of driver accounts, for suspected fraud and for low customer ratings, with no human review at any stage. Under GDPR Article 22, that makes it an automated individual decision, and the total absence of human intervention is what triggered the fine.
It's the third sanction in this matter, after €10 million in 2023 and €290 million in 2024, running back to a 2020 complaint from more than 170 drivers. The Dutch authority led the investigation, since Uber's main EU establishment sits in the Netherlands, with the CNIL cooperating throughout. Uber has called the fine disproportionate and says it will appeal.
The mechanism is the point, not the number. Any automated process that produces an outcome with real effect on a person needs a genuine reviewer, not a rubber stamp, and the person has to be told automation is involved. That's not a rideshare problem. It's what any firm putting AI near a client-facing decision has to get right first.
France's bar wrote the rules. Its courts are already testing them.
In March the Conseil National des Barreaux adopted a national deontology guide for AI, built around eight existing duties: professional secrecy, GDPR, competence, diligence and prudence, independence, conflicts of interest, client information, and fair fee-setting. In July the Paris Bar went further, publishing a model charter of roughly fifteen articles that firms can adopt directly. It distinguishes agentic AI from generative AI and sets out three tiers of access a firm can choose between: pre-audited tools only, supervised online tools, or case-by-case authorisation. Neither document mentions the other. Between them, they're the closest thing the profession has to an actual operating manual right now.
The courts are catching up on their own. In December the Tribunal Administratif de Grenoble rejected a filing it called totally unsuited to the purpose, citing fanciful case references. Weeks later, Périgueux's civil court flagged a citation that didn't hold up under the reference given, and pointedly invited counsel to verify anything found by AI before filing it again. Orléans's administrative court went further, laying out sixteen citations in a lawyer's brief, fifteen that didn't exist under the numbers given and one real citation that had nothing to do with the case. None of the three produced a sanction, and in two of them the claimant's side won anyway, on unrelated grounds. What changed in June: Grenoble fined a litigant €200 for an abusive 300-page AI-drafted brief. Small number, real escalation, the first time this specific failure has cost money in a French court.
A hidden instruction, caught. An unverified brief, still under review.
In July, a self-represented litigant in Connecticut hid white-on-white text in a court filing, instructing any AI reviewing it to side with him regardless of what else the document said. In August the judge caught it. His e-filing privileges were revoked; he now has to file on paper.
Still open: Delaware's Richards, Layton & Finger has already submitted affidavits explaining a separate hallucinated brief filed under one of its own directors' name. The court has not yet ruled on whether to sanction the firm.
Same hidden instruction. A very different bill.
Nearly three months before the Connecticut case above made headlines as a first, two licensed lawyers in a Brazilian labour court tried the identical trick. In May, hidden text turned up in a client's filing instructing the court's own AI review tool to wave the case through no matter what. The judge fined both lawyers 10% of the claim's value, jointly, and referred them to the bar, which suspended both within days as a precaution.
The precaution didn't hold for both. A technical audit later found no record that one of the two lawyers had touched the case file at all, and the bar lifted her suspension. The other's suspension stands while the bar's ethics tribunal decides the underlying case. Even so, professional accountability moved faster and reached further here than it did in Connecticut, where the person behind the identical trick wasn't a lawyer at all, and lost nothing but the ability to file electronically.
Three regulators, one shared question: who's actually watching the algorithm?
In Singapore, the Ministry of Law and the Intellectual Property Office opened a joint public consultation on 26 August, running to 22 October, on how the IP regime should treat AI. On copyright: how clearly the existing text-and-data-mining exception covers AI training in practice, how infringement liability should split between developers, deployers and end users, and how to evidence a human's actual creative contribution to AI-assisted work. On patents: inventorship when AI helps formulate the problem or select the output, and how AI-generated technical disclosures affect what counts as prior art.
In Australia, the prudential and securities regulators went further than a consultation. APRA and ASIC published a joint call to action on 27 August telling banks, insurers, super trustees and market participants that frontier-AI risk awareness has to become concrete governance now: patching and access controls, board-level decisions on risk appetite before a crisis hits, tested incident response. ASIC Commissioner Simone Constant: "Threat actors are exploiting frontier AI models to identify and exploit vulnerabilities that previously may have taken a team of professionals months to find." It followed nine roundtables across June and July, more than 600 attendees, hosted by APRA and ASIC with support from the Australian Signals Directorate and participation from the Reserve Bank, Treasury and the ACCC.
And Australia's privacy regulator published the number that undercuts a lot of AI-governance talk generally. Reviewing 23 government agencies authorised to use automated decision-making, the Information Commissioner's office found only 4, 17%, had actually disclosed that use where the law requires it. The gap between having a policy on AI and telling anyone you're using it is, apparently, most of the policy.
Our read
Nobody built a smarter model this cycle. What moved is where the accounting happens. Uber's fine is what a regulator does when there's no human between an algorithm and someone's income. France's new documents are what that accountability is supposed to look like before the fact, not after. Its courts are what happens when nobody read the filing first. Brazil shows what changes once professional responsibility actually attaches to the failure. And Australia's own transparency count, four agencies out of twenty-three actually disclosing their use of AI where the law requires it, is a reminder that most of this accountability still runs on the honour system. None of it required the AI to get worse. It required the systems around it to start paying attention, and once one part of a profession starts, the rest of it tends to follow.
Get the next issue in your inbox