TwinEthosRequest access

Control

Automated decision tech without opt-out

Consumers must be able to opt out of automated decision technology making significant decisions about them.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: People cannot opt out of automated decision-making, profiling, or personalization · control id cond.admt-no-optout

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
1more where it is enacted, not yet applying
0standards and frameworks on the same control

enacted, not yet applying in California (US-CA); next date 2027-01-01.

The guard to add

Offer an ADMT opt-out (or a qualifying human appeal), store the consumer's choice, and check it before the model runs on any significant-decision path.

Two pieces: an opt-out endpoint linked from the pre-use notice (e.g. POST /privacy/admt-opt-out) that stores a per-consumer admt_opt_out preference, and a check at the top of the server-side decision function that reads that preference and routes opted-out consumers to a human decision-maker without calling the model. Where the business instead relies on a human appeal, the decision response carries an appeal route (POST /decisions/{id}/appeal) to a reviewer who can interpret the model output and overturn the decision. A UI-only toggle that the decision service never reads does not count.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.

What reviewers look for: the stored preference read (if consumer.admt_opt_out, preferences.get('admt_opt_out')) before chat.completions.create or predict on the decision path, an opted-out branch that never calls the model, the opt-out endpoint linked from the notice, or an appeal route whose reviewer has authority to change the outcome.

Example (FastAPI + OpenAI SDK), before:

def decide_tenancy(applicant):
    resp = client.chat.completions.create(model=MODEL, messages=tenant_prompt(applicant))
    return approve_or_deny(resp.choices[0].message.content)

After:

def decide_tenancy(applicant):
    if prefs.get(applicant.consumer_id, 'admt_opt_out'):
        return route_to_human(applicant, reason='admt_opt_out')   # model never runs
    resp = client.chat.completions.create(model=MODEL, messages=tenant_prompt(applicant))
    return approve_or_deny(resp.choices[0].message.content)

@app.post('/privacy/admt-opt-out')
def admt_opt_out(user=Depends(current_user)):
    prefs.set(user.consumer_id, 'admt_opt_out', True)
    return {'opted_out': True}

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Upcoming dates

Every rule this guard addresses

Binding law — not yet in force or stayed (1)