Binding law — in force
Tell users whether AI made or drove a decision, explain how it was reached, and let them challenge it before a competent person (El Salvador, DL 234 Art. 18)
El Salvador's Law for the Promotion of AI and Technologies (Legislative Decree 234) Art. 18 provides that where AI is used commercially or to access rights or services in the Republic, the user must be told whether the decision was taken directly by AI or driven by it (an AI-driven decision is one with a significant AI contribution, alone or with human operators, Art. 4(i)); the notification must contain understandable and transparent explanations of how the decision was reached, and there must be mechanisms to challenge it before a competent natural person who can confirm, modify or revoke it. Compliance is a condition for the Law's safeguards (Art. 19). Detect a model-driven decision sent to the person with no AI-decision notice or challenge route.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
- Lane
- Binding law — in force In force: applies since 11 Mar 2025
- Official source
- DL 234, Art. 18 (AI decisions: notice, explanation and challenge before a natural person) · captured 2 Oct 2026 · anchor hash (SHA-256)
9ca56cdea271…· 5 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
- Data release
- Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Decisions shown in the UI rather than sent
- Notice text held in templates
- The notice and challenge route may be added by a template outside the file; check the rendered message before reporting.
Who it applies to
- Duty falls on: any person
- Systems covered: automated decision, consequential decision
- Anyone who uses AI commercially, or to decide access to rights or services, in El Salvador: every decision taken directly by AI or driven by it (a significant AI contribution, Art. 4(i)) is notified with that fact and an understandable explanation, and can be challenged before a competent natural person who can confirm, modify or revoke it. In force since 2025-03-11. The Law has no sanctions chapter: compliance conditions the Art. 19 safeguards. Whether other law makes Art. 18 enforceable, and what 'commercially' covers, are questions for counsel (review flag).
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.
Where model output becomes an adverse status (denied, declined, rejected, ineligible), the decision service stores reason codes or principal reasons, the model id and version, and an input snapshot or hash with the decision. The notice to the person (letter, email, portal response) says AI was involved and what role it played, lists the main factors, and links to data correction and to an appeal that creates a human-review task with authority to change the outcome. An explanation endpoint returns the stored record on request, so the deployer can explain a decision long after the model has changed.
Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.
What this provision adds:
- Say in every decision notice whether the decision was taken directly by AI or driven by it, with an understandable explanation of how it was reached.
- Offer a challenge before a competent natural person who can confirm, modify or revoke the decision.
Example (Python + OpenAI SDK + Pydantic), before:
resp = client.chat.completions.create(model=MODEL, messages=msgs)
if 'deny' in resp.choices[0].message.content.lower():
application.status = 'denied'
send_email(applicant.email, 'Your application was declined.')After:
a = Assessment.model_validate_json(resp.choices[0].message.content) # decision, reason_codes
if a.decision == 'deny':
decisions.insert(app_id=application.id, status='denied', reason_codes=a.reason_codes,
model=resp.model, input_hash=hashlib.sha256(payload).hexdigest())
send_email(applicant.email, render('adverse_action_notice.txt',
reasons=a.reason_codes,
role_of_ai='An AI model assessed your application; a reviewer can change the outcome.',
correct_data_url='/profile/data', appeal_url=f'/appeals/new?decision={application.id}'))Control: Adverse AI decision without explanation/appeal. The same guard addresses 12 items with binding law in 8 jurisdictions. Engineering guidance, not legal advice.
Standards that recommend the same control
- Significant AI decisions should be documented and contestable with remedies (CoE Framework Convention) (CoE AI Framework Convention (CETS 225) · CoE Framework Convention on AI (CETS 225), Article 14(2))
- Financial institutions should disclose AI use and explain AI-driven decisions on request (MAS FEAT) (MAS FEAT Principles · MAS FEAT Principles — Transparency, Principles 12-14)
- Health AI/LMMs should be transparent and documented before deployment (WHO) (WHO AI-for-Health (LMM) Guidance · WHO guidance on large multi-modal models (2024), Executive summary (Figure 1), section 1.2 and Box 1: the six consensus principles of WHO's 2021 guidance)
Related incidents
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere
Rule id sv-dl-234.ai-decision-notice-explanation-and-human-challenge · review status: primary source derived