Key Takeaways
- Workplace surveillance: AI-driven monitoring already triggers GDPR, labor law, DPIA, and employee-information obligations in Europe.
- Automated decisions: Article 22 GDPR and the CJEU’s SCHUFA ruling restrict decisions based solely on algorithmic scoring.
- Supply-chain accountability: CS3D and due-diligence laws increasingly require visibility into training data, annotators, and suppliers.
- AI governance: The legal question is no longer “Do we use AI?” but “Can we prove who controls decisions, where data comes from, and who is accountable?”
A surprising convergence between ethics and law
In May 2026, Pope Leo XIV published Magnifica Humanitas, his first encyclical, devoted to human dignity in the age of artificial intelligence.
At first glance, this seems far removed from the daily concerns of corporate counsel and compliance teams.
But the striking point is this: the four major concerns raised in the text are almost exactly the same issues European regulators are already trying to govern through the GDPR, the AI Act, labor law, and supply-chain legislation.
This is not a religious argument. It is a governance signal.
The four concerns, and the law already surrounding them
1. Algorithmic surveillance of workers
The first concern is familiar: employees continuously monitored by software, productivity measured in real time, management decisions increasingly automated, and AI systems inferring behavior from digital traces.
In Europe, this is already heavily regulated. The legal framework combines:
- GDPR obligations (lawful basis, transparency, minimization, accountability).
- Article 35 GDPR requiring a DPIA where monitoring creates high risks.
- Labor-law principles of proportionality and employee information.
- Consultation duties toward employee representative bodies in many jurisdictions.
The practical issue is not whether monitoring is technically possible. It is whether the employer can justify necessity, proportionality, transparency, retention periods, and human oversight.
An AI productivity tool that quietly records keystrokes, screenshots, or behavioral patterns may look innovative from an operations perspective. Legally, it can become a high-risk processing operation almost immediately.
2. Opaque automated decisions
The second concern is more foundational: can people be hired, rated, denied credit, or excluded by systems no one can meaningfully explain?
That is no longer theoretical. Article 22 GDPR gives individuals the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. The CJEU’s SCHUFA judgment (7 December 2023) reinforced this by recognizing that a credit score can itself constitute such a decision when it effectively determines the outcome of a human process.
The upcoming AI Act strengthens this architecture further for high-risk systems used in:
- employment and worker management,
- access to credit,
- education,
- essential services.
For companies, the operational implication is blunt: “human review” cannot be cosmetic. If the human merely rubber-stamps the algorithm, regulators may still treat the decision as effectively automated.
3. Invisible labor in the AI supply chain
The third concern is less visible but increasingly important. AI systems depend on large chains of human labor:
- data annotators,
- content moderators,
- synthetic-data contractors,
- dataset suppliers.
Users see the polished model. Lawyers must see the chain behind it.
This is where the Corporate Sustainability Due Diligence Directive (CS3D) and national vigilance laws become relevant. They push companies to identify and prevent human-rights risks across their value chains, including outsourced digital labor.
For AI governance, this changes the compliance perimeter. Training-data provenance, annotation conditions, contractor oversight, and documentation practices are becoming legal-risk issues, not merely procurement issues.
4. Resource extraction and technological dependency
The fourth concern addresses the extraction of resources needed for digital technologies: minerals, hardware supply chains, and geopolitical dependencies.
This may sound remote from software governance, but it intersects with ESG, supply-chain due diligence, and corporate reporting obligations. Companies are increasingly expected to document where critical resources come from and how suppliers are vetted.
For AI systems specifically, this reinforces a broader trend: governance now extends beyond the model itself to infrastructure, vendors, hosting, datasets, and upstream dependencies.
The real shift: AI is becoming a governance problem
What makes this convergence interesting is not the moral framing. It is that the law already anticipated many of the same risks.
- Surveillance.
- Automated decision-making.
- Traceability.
- Accountability across the value chain.
In other words, the central debate about AI is no longer primarily technological. It is organizational and evidentiary.
The key question is no longer: “Do we use AI?”
It is becoming: “Can we demonstrate who controls decisions, where the data came from, and who is responsible when something goes wrong?”
That is a fundamentally legal question.
Why this matters for in-house legal teams
Many organizations still treat AI as a tooling issue owned by IT or innovation teams. That model is becoming fragile.
A defensible AI governance program now requires:
- Documented decision ownership: identify who can approve, override, or halt AI-driven outputs.
- Traceable data provenance: know where training and operational data originate, under what rights, and with what restrictions.
- Meaningful human oversight: define what reviewers must actually do, not just that a human is “in the loop.”
- DPIAs and risk assessments: especially for employee monitoring, profiling, and high-impact decisions.
- Supplier governance: audit AI vendors, cloud providers, annotators, and data suppliers.
- Evidence retention: maintain logs, model documentation, and governance records capable of surviving regulatory scrutiny.
In practice, legal teams increasingly become the architects of AI governance rather than the reviewers at the end of deployment.
A note on the AI Act timeline
The AI Act entered into force in 2024, but obligations apply progressively over several years. High-risk systems face phased compliance requirements, with key obligations becoming operational between 2026 and 2027 depending on the category and implementing standards.
That matters because many companies are already deploying systems that will later fall into regulated categories. Governance built today should anticipate those obligations instead of waiting for the final enforcement date.
FAQ
Is “human oversight” enough to avoid GDPR Article 22 issues?
No. Human involvement must be real and meaningful. If a person merely approves the algorithmic recommendation without independent assessment, regulators may still treat the process as effectively automated.
When is a DPIA likely required for workplace AI?
A DPIA is typically required when processing is likely to result in a high risk to individuals’ rights and freedoms. Continuous monitoring, profiling, productivity scoring, biometric analysis, or large-scale employee surveillance are common triggers.
Does the AI Act apply to in-house AI tools?
Potentially yes. The AI Act focuses on the system’s function and risk category, not simply whether the tool is sold externally. Internal systems used for employment, access control, or other high-risk purposes may still fall within scope.
Why do supply chains matter for AI compliance?
Because legal exposure increasingly extends beyond the final model. Training-data provenance, annotation practices, outsourcing conditions, and vendor governance can create GDPR, IP, labor, human-rights, and due-diligence risks.
Can AI governance remain only an IT responsibility?
Not safely. AI governance now intersects with privacy, labor law, consumer protection, sector regulation, procurement, ESG, litigation risk, and board accountability. Legal oversight is becoming central, not auxiliary.
Final thought
Whether the warning comes from regulators, courts, legislators, or an encyclical, the underlying message is converging:
AI systems do not dissolve human responsibility. They redistribute it.
And the organizations that will struggle most are not necessarily the ones using the most AI, but the ones unable to explain how their AI is governed.
Suggested primary source
Magnifica Humanitas, Encyclical of Pope Leo XIV (15 May 2026) – official Vatican publication:
Vatican Magnifica Humanitas (15 May 2026) : https://www.vatican.va/content/leo-xiv/en/encyclicals/documents/20260515-magnifica-humanitas.html
Legal references
- Regulation (EU) 2016/679 (GDPR), including Articles 22 and 35.
- CJEU, SCHUFA judgment, 7 December 2023.
- EU AI Act (Regulation on Artificial Intelligence), entered into force in 2024 with phased application.
- Directive (EU) 2024/1760 on corporate sustainability due diligence (CS3D).
- French Duty of Vigilance Law (2017).
