Control
Significant-decision ADMT without consumer access explanation
Consumers must be able to obtain a plain-language explanation of the purpose, logic, and outcome of significant-decision automated decisionmaking technology used about them.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
enacted, not yet applying in California (US-CA); next date 2027-01-01.
The guard to add
Store each ADMT decision's purpose, logic, output, and use at decision time, and return them in plain language from a consumer access-request path.
At decision time, write a decision-log row with the purpose, the key factors or reason codes, the model output, how the output was used, the human's role, and the model version. Provide an access-request path (privacy portal endpoint or DSAR export job) that verifies the requester and assembles a plain-language response from those rows using a template that explains the purpose, the logic, the outcome, and the person's other rights. Without decision-time records the access response cannot be reconstructed later, so the logging belongs in the decision service, not in the privacy team's tooling.
Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.
What reviewers look for: decision rows carrying purpose, key factors, output, how it was used, and human role for every significant decision; an access-request handler or export job that reads those rows and returns a plain-language explanation plus rights information to the verified consumer.
Example (Python + scikit-learn), before:
score = model.predict_proba([features])[0][1]
applications.update(app_id, status='approved' if score >= 0.6 else 'denied')After:
score = model.predict_proba([features])[0][1]
status = 'approved' if score >= 0.6 else 'denied'
decision_log.insert({'consumer_id': cid, 'purpose': 'credit line eligibility',
'key_factors': reason_codes(features), 'model_output': score,
'how_used': 'scores of 0.6 or more approve; lower scores deny',
'human_role': 'underwriter reviews appeals', 'model_version': MODEL_VERSION})
applications.update(app_id, status=status)Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Upcoming dates
- : Consumers requesting access to ADMT must receive a plain-language explanation (California (US-CA); first application)
Every rule this guard addresses
Binding law — not yet in force or stayed (1)
- California (US-CA)
- Consumers requesting access to ADMT must receive a plain-language explanation 11 CCR 7200(a)-(b) · applies from 2027-01-01
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere