Binding law — in force AI-adjacent law
Fully automated algorithmic decisions: notice that an algorithm was used, its key factors and review by a specialist (Kazakhstan Digital Code Art. 43)
Kazakhstan's Digital Code (No. 255-VIII, in force 2026-07-11) treats as an algorithmic system any digital system that takes or influences decisions by automated data processing, including AI systems (Art. 43(1)); decisions made with them must not discriminate (Art. 43(2)). A fully automated decision is one taken without a human assessing the circumstances or approving the result, in cases provided by law or agreement (Art. 43(3)). The person concerned may, in the cases and manner set by legislation, be told that an algorithmic system was used, receive an explanation of the key factors and criteria behind the decision without disclosure of the algorithm, source code or protected secrets, and demand review of the decision with an authorised specialist where it has legal consequences or may affect their rights (Art. 43(4)). Detect a model output that becomes a decision about a person with no notice, key factors and specialist review route, and no human decision.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
- Lane
- Binding law — in force In force: applies since 11 Jul 2026
- Official source
- Art. 43(4) (rights of the person subject to a fully automated algorithmic system) · captured 3 Oct 2026 · anchor hash (SHA-256)
90a63df709bc…· 8 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
- Data release
- Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Notice, factors and review handled in a separate service
- The rights apply only in cases set by legislation; the decision may not be fully automated if a person approves the result elsewhere.
Who it applies to
- Duty falls on: any person
- Systems covered: automated decision, consequential decision
- Whoever uses an algorithmic system, including an AI system, for a fully automated decision about a person in Kazakhstan's digital environment (Art. 1(1)); foreign persons acting there bear the same duties (Art. 1(3)). In force from 2026-07-11 (Art. 106(1): six months after first official publication on 10.01.2026). The rights arise 'in the cases and manner established by legislation', and the review right needs legal consequences or an effect on rights; whether Art. 43(4) is directly enforceable before implementing legislation exists is a counsel question.
- Not covered:
- A decision in which a human assesses the circumstances or approves the result is not fully automated (Art. 43(3))
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Route significant automated decisions through meaningful human review, or wire in an automated-decision notice, reasons, human intervention, a way to give a view, and contest.
At the point where model output becomes a significant decision about a person (approve, deny, underwrite, set_status), either queue the case for a reviewer who weighs the evidence and can change the outcome before it takes effect (review_queue.enqueue, requires_human_review), or, where the decision stays solely automated, record the permitted basis for that decision type and wire the safeguards in. Those safeguards are a notice in the decision message that it was made by automated processing, reasons the person can read, and request_human_review or contest routes where the person can give their view and have a human reconsider. A reviewer who approves every case without examining it does not make the decision non-automated, so the review records reviewer identity, the evidence viewed, and the outcome.
Where it goes: 1 application source code, 9 AI output handling, 15 agent action surface, 14 user-facing text.
What this provision adds:
- Tell the person that an algorithmic system was used, explain the key factors and criteria of the decision without disclosing the algorithm, code or protected secrets, and let them demand review with an authorised specialist.
Example (Python + OpenAI SDK), before:
verdict = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
if verdict.strip() == 'deny':
deny(applicant)
send_decision_email(applicant, 'Your application was not approved.')After:
out = client.chat.completions.create(model=MODEL, messages=msgs,
response_format={'type': 'json_object'})
result = json.loads(out.choices[0].message.content)
if result['decision'] == 'deny':
if requires_human_review('credit'): # a person decides
review_queue.enqueue(applicant.id, proposal=result)
else: # solely automated, recorded basis
deny(applicant, basis=DECISION_BASIS['credit'], reasons=result['reasons'])
send_decision_email(applicant, render('adm_denial.txt', notice=ADM_NOTICE,
reasons=result['reasons'], contest_url=f'{BASE}/decisions/{applicant.id}/contest'))Control: Solely-automated significant decision without human-intervention safeguards. The same guard addresses 15 items with binding law in 15 jurisdictions. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Monitor how often adverse AI decisions are reversed, and suspend models that are usually wrong
- Cigna PXDX batch claim denials (reported) (2022; alleged (not proven)). ProPublica, citing internal Cigna records, reported that Cigna's PXDX system was used to reject more than 300,000 claims over two months in 2022, with physicians spending an average of 1.2 seconds on each. Cigna disputes the reporting; related lawsuits are ongoing. Source: ProPublica / The Capitol Forum · evidence grade: press of record · cited by Make human review of adverse AI decisions substantive, not nominal
Rule id kz-digital-code.fully-automated-decision-rights · review status: primary source derived