Recommended guardrail
Explain adverse AI-assisted decisions and offer a way to contest them — everywhere
When an AI-assisted decision adversely affects a person, tell them AI was involved, give a clear explanation of the main factors and the AI system's role, and provide a way to correct data and contest the decision with a human who can change it. Apply this regardless of jurisdiction. Detect adverse-decision flows with no explanation or contest route.
This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.
The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Evidence grade
Law in force in 1 jurisdiction, coming in 2 more
Law in force in 1 jurisdiction · law coming in 2 more · 3 standards and frameworks · 1 graded incident.
TwinEthos recommendation, not law. Where binding law applies, the law governs. Binding law on this control, or in provisions cited as convergence, is in force in 1 jurisdiction (CA-QC). Such law is enacted but not yet applicable, or stayed, in 2 more (EU, US-CO). 3 standards and frameworks recommend it (CoE AI Framework Convention (CETS 225), MAS FEAT Principles, WHO AI-for-Health (LMM) Guidance). 1 graded incident cited.
Law in force on this control or cited as convergence
- Exclusively-automated decisions require notice, explanation, and human review (Quebec) (Quebec (CA-QC); Act respecting the protection of personal information in the private sector (CQLR c P-39.1), s. 12.1; cited)
Law enacted, not yet applying
- Affected persons can demand a meaningful explanation of a high-risk AI decision (EU AI Act Art. 86) (European Union (EU); Article 86; applies from 2026-08-02; same control)
- Adverse ADMT outcomes require a 30-day plain-language explanation (Colorado (US-CO); C.R.S. 6-1-1704(3); applies from 2027-01-01; stayed; same control)
Standards and frameworks
- Significant AI decisions should be documented and contestable with remedies (CoE Framework Convention) (CoE AI Framework Convention (CETS 225); CoE Framework Convention on AI (CETS 225), Article 14(2); same control)
- Financial institutions should disclose AI use and explain AI-driven decisions on request (MAS FEAT) (Singapore (SG); MAS FEAT Principles — Transparency, Principles 12-14; same control)
- Health AI/LMMs should be transparent and documented before deployment (WHO) (WHO AI-for-Health (LMM) Guidance; WHO Ethics and Governance of AI for Health (LMMs, 2024) — Six Consensus Principles; same control)
Family “People cannot obtain an explanation of an AI-assisted decision about them”: binding law on related controls is in force in no jurisdiction; enacted, not yet applying in European Union (EU), California (US-CA), Colorado (US-CO). Context only: it does not change this guardrail's grade.
Graded incidents
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)) STAT News · evidence grade: primary
The guard to add
Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.
Where model output becomes an adverse status (denied, declined, rejected, ineligible), the decision service stores reason codes or principal reasons, the model id and version, and an input snapshot or hash with the decision. The notice to the person (letter, email, portal response) says AI was involved and what role it played, lists the main factors, and links to data correction and to an appeal that creates a human-review task with authority to change the outcome. An explanation endpoint returns the stored record on request, so the deployer can explain a decision long after the model has changed.
Example (Python + OpenAI SDK + Pydantic), before:
resp = client.chat.completions.create(model=MODEL, messages=msgs)
if 'deny' in resp.choices[0].message.content.lower():
application.status = 'denied'
send_email(applicant.email, 'Your application was declined.')After:
a = Assessment.model_validate_json(resp.choices[0].message.content) # decision, reason_codes
if a.decision == 'deny':
decisions.insert(app_id=application.id, status='denied', reason_codes=a.reason_codes,
model=resp.model, input_hash=hashlib.sha256(payload).hexdigest())
send_email(applicant.email, render('adverse_action_notice.txt',
reasons=a.reason_codes,
role_of_ai='An AI model assessed your application; a reviewer can change the outcome.',
correct_data_url='/profile/data', appeal_url=f'/appeals/new?decision={application.id}'))Control: Adverse AI decision without explanation/appeal. Engineering guidance, not legal advice.
Why
The right to an explanation and to contest an AI-assisted decision is converging across the EU, Colorado, Quebec, and the Council of Europe convention. It is also the control that most directly addresses low appeal rates in automated claim denial: people cannot contest what they cannot see.
Class: law derived · set: universal baseline · maturity: reviewed · confidence: high · id guardrail.baseline-adverse-decision-explanation