A human sign-off is not a compliance strategy
Multiverse, the £1.6bn apprenticeship company co-founded by Euan Blair, now has an AI model read transcripts of its instructors’ online lessons and give each instructor a “risk status” and a “percentage confidence score” for managers, according to the Guardian’s report of 28 September. Our news report covers what staff said and how the company answered. This analysis takes the question every UK employer weighing a similar tool should be asking: what does the law already require when software rates people’s work? More than the familiar human-in-the-loop defence implies. Most of the duties that apply to AI performance monitoring (an impact assessment, telling staff before it starts, accuracy, letting workers see and challenge the output, and managing work-related stress) apply whether or not a manager signs off the result.
Strategic Insight: Meaningful human involvement takes a decision outside the UK GDPR’s specific rules on solely automated decisions. It does not take it outside data protection law. The Information Commissioner’s Office (ICO) gives monitoring that may cause financial loss, such as performance management, as an example of high-risk processing, and high-risk processing needs an impact assessment before it begins.
Why is one training provider’s rubric a UK-wide question?
Multiverse is not the only employer using AI to track how staff work. The Guardian set Multiverse alongside two earlier cases: Burger King’s use of AI to track how restaurant staff deal with customers, and Meta pausing its tracking of employees’ keystrokes this summer after privacy concerns and pushback from staff. We covered both at the time (Burger King, Meta). The appeal is obvious: a model can read every session, where a manager could only sample one. The risk is that the model’s judgement becomes the organisation’s judgement before anyone has tested it.
What the Multiverse case actually shows
According to the Guardian, instructors used to be observed once a month by a human manager; the AI now reviews several hours of their teaching each day. Multiverse’s position is that the tool supports rather than replaces human judgement and that only managers write performance reviews; in a spokesperson’s words, “The most consequential performance management action it can take is to recommend that a human personally reviews a session.” Instructors described managers querying supposed “digressions” that were answers to learners’ questions. One, writing anonymously, said instructors were not told about the system while it was being developed, and that the dashboard is currently visible to managers alone. The company says staff were told about the rollout beforehand and that teachers will get access to the data.
Both accounts can be true at once, and that gap is exactly where the law sits. Announcing a system before launch is not the same as consulting staff while designing it. Promising access later is not the same as letting workers see and challenge their scores now.
| Metric | Value | Strategic Implication |
|---|---|---|
| Human observation before the AI | Monthly | The tool multiplies the volume of performance data held about each instructor |
| AI review now | Several hours a day | The ICO lists monitoring used for performance management among its high-risk examples, which need a DPIA first |
| Multiverse headcount | More than 800 | Far above the five-worker point at which the HSE requires a stress risk assessment to be written down |
| UK GDPR Articles 22A–22D in force | 5 February 2026 | The new automated-decision rules are live, while the ICO’s monitoring guidance is still under review |
Strategic Reality: Multiverse trains staff at NHS bodies, councils and universities, mostly paid for through the apprenticeship levy, according to the Guardian. That gives the public bodies paying for the training a stake in how the people delivering it are managed.
Where does UK law already draw the lines?
The automated-decision rules, and why a human sign-off matters
Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D, which came fully into force on 5 February 2026 under commencement regulations (SI 2026/82). The government describes the result as a more permissive framework for decisions based solely on automated processing. Under Article 22A, a decision is solely automated if there is “no meaningful human involvement” in taking it, and significant if it has a legal or similarly significant effect. Where both apply, Article 22C requires safeguards: telling the person about the decision, letting them make representations, letting them obtain human intervention, and letting them contest it.
On Multiverse’s description, the AI flags and a manager decides, so those specific safeguards may not formally apply. But the test is “meaningful” involvement, not any involvement, and Article 22A tells anyone assessing it to consider how far the decision rests on profiling. A manager who reads the model’s comments and acts on them without forming an independent view is a weaker safeguard than the org chart suggests. Whether that is happening anywhere is a question of fact about how managers use the dashboard, and it is the one employers should be able to answer with evidence.
Critical Context: The ICO’s guidance on monitoring workers now carries a notice that it is under review because of changes made by the Data (Use and Access) Act. Employers are designing AI monitoring against guidance the regulator itself says may change, so the safer course is to meet the guidance as it stands and watch for the revision.
The duties that apply regardless
The ICO’s guidance on monitoring workers sets out obligations that do not depend on whether a decision is solely automated:
- Impact assessment first: a data protection impact assessment (DPIA) is mandatory before processing likely to cause high risk, and the ICO’s examples include keystroke monitoring and monitoring that may cause financial loss, such as performance management. If a DPIA finds high risk that cannot be reduced, the employer must consult the ICO before proceeding.
- Tell workers before it starts: outside very exceptional cases of justified covert monitoring, workers must be informed, in a way that is accessible and easy to understand, and information must be provided before monitoring begins.
- Ask them during design: employers should seek and record the views of workers or their representatives, such as trade unions, as part of the DPIA, and document the reasons if they decide not to.
- Accuracy and challenge: the ICO warns that data analytic tools can make incorrect inferences about workers, and says workers should be able to see, explain or challenge monitoring results alongside performance reviews and appraisals.
- Access now, not later: whatever a dashboard rollout plan says, workers can make a subject access request, and the employer must hand over the personal information collected through monitoring unless an exemption applies.
The implementation reality
The rubric extracts published by the Guardian show how quickly style becomes a proxy for competence. The model is told to “judge the PATTERN across the whole transcript, not isolated instances”, which is a sensible guard against penalising a single slip. It is also told to mark an instructor down for confusion or self-correction while setting a task, “even if it was eventually straightened out”. A pervasive pattern of hedges, fillers and re-explanation is being read as a sign that the teacher has not mastered the material. That is an inference, and inferences are where the ICO’s accuracy warning bites.
The ICO’s own worked example makes the point. An employer that judges performance on time logged in a case management system, while ignoring the reasonable adjustments that mean some staff work outside it, is running monitoring the ICO calls “unfair and inadequate”. A speech-pattern rubric raises the same question: has anyone checked who it marks down for reasons unrelated to the quality of their teaching?
⚠️ Warning: Instructors told the Guardian that some staff were losing sleep and seeking therapy. The Health and Safety Executive says employers have a legal duty to protect workers from stress by assessing the risk and acting on it, and those with five or more workers must write the assessment down. A monitoring tool that staff report as a source of stress belongs in that assessment.
What does this mean for the people involved?
Beyond the technology: the human factor
The most telling line in the Guardian’s report is not about the AI at all. One instructor said the focus had shifted from the learner to whether they were saying the right thing for the model. When the measure changes what people do, the tool is managing the work, not observing it. The HSE’s Management Standards name control and change among the six areas of work design that affect stress levels, and a scoring system that staff say they could neither see nor shape touches both.
The company’s argument deserves a fair hearing. Multiverse says the tool “directs human time to where it’s needed most”, and that is a reasonable aim. On the instructors’ account, the problem is not the aim but the sequence. Design, consultation, transparency and access need to come before the switch-on, not after the complaints.
| Stakeholder Group | Primary Impacts | Support Needs | Success Metrics |
|---|---|---|---|
| Workers being rated | Continuous scrutiny, risk of misread sessions, stress | Sight of their own scores, a route to challenge, clarity on purpose | Challenges resolved; stress risk assessment reviewed |
| Line managers | New queue of AI flags to investigate | Training to form an independent view, not confirm the model | Share of flags overturned on review |
| DPO, HR and legal | Accountability for lawful basis, DPIA and access requests | Early involvement in procurement | DPIA completed and consulted on before launch |
| Clients and public funders | Quality assurance of training they pay for | Assurance the regime is lawful and evidence-based | Contract terms covering monitoring governance |
What actually drives success
A monitoring system succeeds when the people it measures accept that its judgements are mostly right and that they can fix the ones that are wrong. That depends less on the model than on what surrounds it: a published rubric, access to scores, a route to challenge, and managers who overrule the tool often enough to show their review is real.
The measure that proves this is not how many flags the model raises. It is how many it raises that a human, having looked properly, disagrees with, and what the organisation does next with that information.
🎯 Success Factor: Track the rate at which managers overturn AI flags. A rate near zero may mean the model is excellent, or that nobody is really reviewing. Either way, it is the number that tells you whether human involvement is meaningful.
How should employers deploy AI performance monitoring?
💡 Implementation Framework: Lawful by design, not by retrofit
Phase 1: Before procurement
- Define the specific purpose and why less intrusive methods will not do
- Identify the lawful basis and, if relying on legitimate interests, complete the balancing test
- Screen for high risk and start the DPIA
Phase 2: Before switch-on
- Consult workers or their representatives and record their views in the DPIA
- Test the rubric for inferences that penalise reasonable adjustments or other factors unrelated to performance
- Publish plain-language information on what is monitored, why, and how results are used
Phase 3: In operation
- Give workers access to their own scores and a way to challenge them
- Train managers to review sessions independently and log when they disagree
- Add the tool to the stress risk assessment and review both on a schedule
Priority actions for different contexts
For organisations just starting
- Write down the purpose first: the ICO expects employers to be clear on why they monitor, and a vague purpose makes every later test harder to pass.
- Treat the DPIA as a design document: use it to shape the tool, including the consultation step, rather than to justify a decision already made.
- Plan for access requests: choose systems that store monitoring data in a form you can retrieve and disclose.
For organisations already underway
- Check what staff were told, and when: if information arrived after monitoring started, fix that now and record it.
- Audit the human review: sample flagged sessions and check whether managers formed their own view.
- Open the dashboard to the people on it: workers can already request their monitoring data, so dashboard access formalises a right rather than creating one.
For advanced implementations
- Guard against function creep: the ICO says a new purpose must be compatible with the original, have consent, or rest on a clear legal obligation.
- Measure disparate outcomes: compare flag rates across groups of staff to catch rubrics that penalise how people speak rather than what they teach.
- Track the DUAA guidance revision: revisit the DPIA when the ICO publishes its updated monitoring guidance.
Resource Reality: None of this requires new technology. It requires HR, legal and management time before launch for the DPIA, consultation and stress assessment. That is a smaller bill than rebuilding trust after staff have learned about the monitoring from its results.
What are the challenges employers miss?
Challenge 1: Rubber-stamp drift
The risk is that human review, careful at first, thins out as the queue of flags grows. When that happens, a system designed to fall outside the automated-decision rules starts to behave like one that falls inside them, without anyone having decided so.
Mitigation Strategy: Set expectations for what a review involves, keep a record of disagreements with the model, and treat a falling overturn rate as a prompt to check, not a sign of success.
Challenge 2: Teaching to the rubric
One instructor told the Guardian their attention had moved from the learner to satisfying the model. The Guardian also cited a study suggesting AI monitoring can backfire by making workers rebellious. Either response degrades the quality the tool exists to protect.
Mitigation Strategy: Publish the rubric, explain the reasoning behind each standard, and invite instructors to propose changes. A standard that staff understand is one they can meet without performing for it.
Challenge 3: Purpose creep
The anonymous instructor feared that recordings of their sessions might one day train an AI to do the instructors’ job, and said they would never agree to that use. The ICO’s guidance says monitoring data should not be reused for a new purpose without a compatible purpose, consent or a legal obligation, and warns that function creep can happen gradually.
Mitigation Strategy: State in the privacy information what monitoring data will not be used for, including model training, and put any change of purpose through a fresh assessment and a fresh notice.
Challenge 4: Guidance in flux
The ICO’s monitoring guidance is under review following the Data (Use and Access) Act, while the new Articles 22A to 22D are already in force. Employers cannot wait for the revision, but anything designed now may need revisiting.
Mitigation Strategy: Build to the current guidance, which is demanding enough, and schedule a DPIA review for when the ICO publishes the updated version.
Reality Check: The Guardian’s report does not say whether Multiverse carried out a DPIA or a stress risk assessment, and we have not seen either. The point is not that one company has failed a test; it is that any employer running a tool like this should be able to show those documents on request.
The strategic takeaway: rating people is a regulated activity
AI can make quality review more consistent and less dependent on which manager happens to observe a session. But once software scores people, data protection law requires the monitoring to be fair, transparent and accurate, the ICO counts performance management among its examples of high-risk processing, and the HSE expects work-related stress to be assessed like any other risk. The Multiverse dispute shows what is at stake when staff feel those steps came second.
Three critical success factors
- Sequence: assessment, consultation and transparency before switch-on, not after complaints.
- Meaningful review: human involvement that can be shown to change outcomes, not a signature on the model’s verdict.
- Access and challenge: workers who can see their scores and get wrong ones corrected.
Reframing success
The usual measure for a monitoring tool is coverage: how many sessions reviewed, how many problems flagged. The better measure is trust: whether the people being rated believe the system is fair enough to learn from.
That shift also protects the employer. The work that builds trust, from the DPIA to the consultation record, is also the record the ICO’s accountability principle expects an employer to be able to show.
Strategic Insight: The ICO is clear that data protection law does not stop employers monitoring workers. The real question is whether you can show, on paper, that you assessed the risks, told and consulted staff, checked the tool’s accuracy and gave people a way to challenge it.
Your next steps
Immediate actions (this week):
- List every tool that scores, ranks or flags staff, including features inside existing software
- Check whether each has a DPIA and when staff were told about it
- Confirm you can answer a subject access request covering monitoring data
Strategic priorities (this quarter):
- Consult staff or their representatives on any tool that lacks recorded consultation
- Add AI monitoring to the stress risk assessment
- Introduce overturn-rate tracking for human review of AI flags
Long-term considerations (this year):
- Revisit DPIAs when the ICO publishes its revised monitoring guidance
- Put monitoring governance into contracts with training and outsourcing suppliers
- Test rubrics for outcomes that differ across groups of staff
Source: Teachers at Euan Blair firm report ‘horrendous stress’ after AI used to rate their work (The Guardian, 28 September 2026), reported by Robert Booth. Legal context from UK GDPR Article 22A and Article 22C as amended, the commencement regulations bringing them into force, GOV.UK’s summary of the Act’s data protection changes, the ICO’s guidance on monitoring workers and the HSE’s guidance on stress risk assessment (all read 30 September 2026).
This strategic analysis was written by Resultsense, a UK-focused AI news and analysis publication. We will be watching how the ICO’s revised monitoring guidance treats human review of AI flags once it is published. Read more analysis at Insights, or get in touch.