An at-a-glance map of where a preserved, contestable decision record is moving from good practice to law.
This is a plain-language map of where a preserved, contestable record of an automated decision is moving from good practice toward requirement. It is a snapshot as of mid-2026, not legal advice. Regimes that share no common drafter are converging on the same artifact — the ability to reconstruct, after the fact, how a consequential decision was reached, on what inputs, under whose oversight, and with what chance to contest it. The map groups that landscape by sector and by cross-cutting regime. Each entry names an instrument, states in one line what it asks for, flags its status, and points to the underlying Summit research brief, which carries the primary citations.
By Brian C. Long · Founder, Summit Cognitive · Snapshot dated mid-2026
In force live and enforceable today ·
Phasing in enacted, obligations not yet fully effective ·
Proposed drafted or under consultation, not yet binding ·
Shifting in flux — recently deferred, repealed, softened, or contested
Filters are a convenience; the full map reads in order with filtering off.
Finance
Sector
Credit, underwriting, pricing, and fraud detection. The federal posture turned deregulatory across 2025–2026, but the underlying statutes were never amended — so the duty to reconstruct a decision shifted toward state regulators, private plaintiffs, and the EU rather than disappearing.
ECOA / Regulation B — adverse-action notices
In force
A creditor that denies credit must give the specific, accurate principal reasons — which presupposes the decision can be reconstructed. The CFPB's 2022 circular saying "no exemption for complex algorithms" was withdrawn in May 2025, but the statute and regulation are unchanged.
Details: Accountable AI in Financial Services
Model risk management — OCC Bulletin 2026-13 (formerly SR 11-7)
Shifting
Validation, monitoring, documentation, and an auditable model inventory for models in the decision path. In April 2026 the agencies replaced the 2011 SR 11-7 guidance with a lighter, explicitly non-binding successor and placed generative and agentic AI out of scope, pending a future request for information.
Details: Accountable AI in Financial Services
Fair-lending / disparate-impact law (Fair Housing Act, ECOA)
Shifting
Liability for lending outcomes that fall unequally on protected classes — itself a reconstruction exercise. Executive Order 14281 (April 2025) directed agencies to stop using disparate-impact liability; the law is unchanged, and exposure migrated to state attorneys general and private plaintiffs.
Details: Accountable AI in Financial Services
EU AI Act — credit scoring as high-risk (Annex III, 5(b))
Shifting
Creditworthiness systems are classified high-risk, triggering logging, technical documentation, human oversight, and an explanation right. The classification stands; the compliance deadline was deferred to 2 December 2027 under the Digital Omnibus (fraud detection is excluded).
Details: Accountable AI in Financial Services
Healthcare
Sector
Clinical decision support and AI-enabled medical devices, where a model's output lands on a patient through a licensed clinician and becomes the subject of inspection, payer audit, and litigation. Every instrument here presupposes a versioned, case-level record of what the AI recommended and what the clinician did with it.
FDA Predetermined Change Control Plans (PCCPs)
In force
Lets a manufacturer pre-specify how an AI-enabled device may change, and the methods to validate and monitor those changes, so updates ship without a new submission. Finalized December 2024 — and only enforceable against a versioned, case-level record of which model produced which output.
Details: Accountable AI in Healthcare
FDA Clinical Decision Support carve-out (§ 520(o)(1)(E))
In force
Software escapes device regulation only if a clinician can independently review the basis of its recommendation — an accountability requirement disguised as a regulatory carve-out. A tool that cannot expose its basis falls back inside device jurisdiction. (2022 final guidance.)
Details: Accountable AI in Healthcare
ONC/ASTP HTI-1 — predictive DSI source attributes
Shifting
Certified health IT had to surface 31 "source attributes" about a predictive decision-support tool — a de facto model card. The December 2025 HTI-5 proposed rule would unwind those transparency requirements; the outcome is unresolved.
Details: Accountable AI in Healthcare
FDA total-product-life-cycle lifecycle guidance
Proposed
Folds transparency, bias analysis, data quality, and post-market monitoring into a lifecycle framework for AI-enabled devices. Issued as a January 2025 draft (comment closed April 2025); signals direction rather than binding obligation.
Details: Accountable AI in Healthcare
Insurance
Sector
The most developed state-level documentation regimes in the United States. Each, in its own vocabulary, requires insurers to show their work retrospectively, on demand, for individual decisions and for models in aggregate.
NAIC Model Bulletin on the Use of AI Systems by Insurers
Phasing in
Expects insurers to adopt a documented, board-overseen AI systems (AIS) program and contemplates regulators requesting model inventories, governance records, and testing results. Adopted by roughly 25 jurisdictions by 2026; enforcement edge varies by state.
Details: Accountable AI in Insurance
Colorado SB 21-169 / Regulation 10-1-1
Phasing in
Requires insurers to quantitatively test external-data and model use for unfair discrimination, with documented governance. Extended to auto and health insurers effective October 2025; compliance evidence due to the Division on request from July 2026. The life-insurance quantitative-testing methodology (BIFSG-based) remains a pending draft.
Details: Accountable AI in Insurance
New York DFS Circular Letter No. 7 (2024)
In force
A multi-step fairness assessment with a documentation duty woven through, plus an AIS inventory and adverse-action specificity. Notably, an insurer may not hide behind a vendor's trade-secret claim to avoid naming the data behind a decision.
Details: Accountable AI in Insurance
EU AI Act — life/health insurance pricing as high-risk (Annex III, 5(c))
Shifting
Risk assessment and pricing for life and health insurance are classified high-risk, with logging, documentation, oversight, and an Article 86 explanation right. Classification stands; the deadline moved to December 2027. Property and casualty is not named in 5(c).
Details: Accountable AI in Insurance
Hiring & employment
Sector
Automated employment decision tools governed by regimes that diverge substantively but converge on one prerequisite: a preserved, candidate-level record of what the tool did and why — without which an audit cannot run, an appeal contests nothing, and a collective action cannot trace a pattern.
NYC Local Law 144 — bias audit
In force
Employers using an automated employment decision tool must commission an independent annual bias audit, publish a summary, and notify candidates. A December 2025 State Comptroller audit found enforcement "ineffective" precisely where records and disclosures were absent.
Details: Accountable AI in Hiring
Illinois HB 3773 (amended Human Rights Act)
In force
Makes it a civil-rights violation to use AI that has a discriminatory effect in employment decisions or to use ZIP codes as a proxy for protected classes, and requires notice that AI is in use. Effective January 2026; implementing rules pending.
Details: Accountable AI in Hiring
California FEHA automated-decision rules + CPPA ADMT
Phasing in
FEHA imposes a four-year recordkeeping duty over ADS inputs, outputs, and testing (effective October 2025). The CPPA's ADMT rules add pre-use notice, opt-out, access to the logic, and an appeal right for significant decisions including hiring — phasing in from 1 April 2027.
Details: Accountable AI in Hiring
EU AI Act — recruitment AI as high-risk (Annex III, Area 4)
Shifting
Recruitment and candidate-evaluation AI is high-risk, with automatic logging an enumerated obligation. Classification is settled; the deadline was deferred to 2 December 2027 under the Digital Omnibus.
Details: Accountable AI in Hiring
Federal: EEOC guidance rescinded; Title VII / ADEA / ADA intact
Shifting
The EEOC removed its AI hiring guidance in January 2025, but removing guidance does not repeal law — the underlying anti-discrimination statutes still apply to AI-driven selection, shifting the locus of accountability to private litigation and the states.
Details: Accountable AI in Hiring
Litigation — Mobley v. Workday
Shifting
An AI hiring vendor faces direct liability on an "agent" theory, with an ADEA disparate-impact claim conditionally certified as a collective (May 2025). Certification depends on a common, traceable pattern of decisions attributable to the tool. Ongoing — verify against the docket.
Details: Accountable AI in Hiring; AI on Trial
Education
Sector
Schools run AI through the most consequential moments of a student's life — admission, grading, exam integrity, risk flagging. Every governance instrument presupposes someone can reconstruct what the system did to a particular student; that prerequisite is frequently unmet, because the underlying signal is often held by a vendor, not the school.
FERPA — access and amendment of education records
In force
Students may inspect and seek amendment of their education records — which can include AI outputs about them, such as a risk score or integrity flag. A statutory right to a contestable record, but only if the record exists and the school, not just the vendor, can produce it.
Details: Accountable AI in Education
Title VI / Title IX / Section 504; Ogletree room-scan ruling
In force
Civil-rights and disability statutes reach biased proctoring, grading, and detection tools; a 2022 federal ruling held a pre-exam room scan an unreasonable search under the Fourth Amendment for a public institution. Each remedy depends on a preserved, student-level record. (ED's OCR AI nondiscrimination resource was rescinded in 2025; the statutes remain.)
Details: Accountable AI in Education
EU AI Act — educational decision AI as high-risk; emotion-recognition ban
Shifting
Admissions, learning-outcome evaluation, placement, and exam-monitoring AI are high-risk, with logging, oversight, and redress duties. The prohibition on emotion recognition in education is already in force (since February 2025); the broader high-risk obligations were deferred to 2 December 2027.
Details: Accountable AI in Education
Public safety
Sector
Face recognition, predictive tools, license-plate readers, and gunshot detection. Where liberty is at stake, what matters is not aggregate accuracy but whether a specific automated output was recorded, disclosed to the affected person and the court, and testable for reliability after the fact.
Virginia facial-recognition framework (§ 15.2-1723.2)
Phasing in
Requires agencies to keep records "sufficient to facilitate discovery in criminal proceedings," including a complete query history, and bars real-time tracking. Revised provisions scheduled to take effect 1 July 2026.
Details: Accountable AI in Public Safety
Williams v. City of Detroit settlement — face-recognition policy
In force
Bars arrests based solely on a face-recognition result, bars lineups built on such a lead absent independent evidence, and mandates an audit of every case since 2017 where the tool obtained a warrant. Court-enforced for four years (settled June 2024).
Details: Accountable AI in Public Safety
Brady disclosure & Confrontation Clause for algorithmic leads
Shifting
Defense advocates argue the use of a face-recognition search is itself disclosable — the probe photo, database, algorithm, error rates, and candidate lists. Courts have not settled clear rules; trade-secrecy claims create a "missing algorithm" problem. Unsettled and contested.
In May 2025 the court endorsed judicial inquiry into gunshot-detection reliability, indicating a Daubert-Lanigan hearing should be available when the forensic use is challenged. Whether other state courts follow is unsettled.
Details: Accountable AI in Public Safety
Elections & synthetic media
Sector
Two distinct responses to AI-generated political content. Content-based bans are proving constitutionally fragile; disclosure and provenance obligations are surviving better, and both increasingly lean on machine-readable provenance as connective tissue.
US state election-deepfake laws (~30 states)
Shifting
Most follow a disclosure model — political media with AI-generated content must carry a disclaimer. A minority reach for prohibition, and those are breaking: California's two flagship 2024 statutes both fell in 2025 (First Amendment; Section 230). Litigation ongoing.
Details: Synthetic Media and Democratic Integrity
EU AI Act — Article 50 transparency
Phasing in
Providers must mark generative outputs in a machine-readable format, and deployers must disclose deepfakes — a duty that applies even absent intent to deceive. Largely held its 2 August 2026 application date, with a short grace period and a June 2026 Code of Practice.
Details: Synthetic Media and Democratic Integrity
EU Disinformation Code folded into the DSA
In force
The formerly voluntary code became an auditable benchmark for very large platforms' risk-mitigation duties under DSA Article 35, effective as a Code of Conduct from July 2025, with the first reporting cycle covering the second half of 2025.
A machine-readable, signed provenance standard now adopted across cameras, phones, and generative providers, with a Conformance Program launched in 2025. Not a legal mandate but the connective tissue regulators and platforms increasingly lean on; fragile where pipelines strip metadata.
Details: Synthetic Media and Democratic Integrity
National security & government
Sector
The governing documents for US defense, intelligence, and federal civilian AI converge on one under-stated requirement: when an AI system informs a consequential decision, the basis must remain traceable, auditable, and reconstructable. The deregulatory turn of 2025 retained this core machinery.
DoD AI Ethical Principles — "Traceable"; Directive 3000.09
In force
Makes traceable a named pillar — "transparent and auditable methodologies, data sources, and design procedures and documentation" — and requires "appropriate levels of human judgment over the use of force." Verifying that judgment was exercised requires a record of what the human saw and decided.
Details: Accountable AI in National Security and Government
OMB M-25-21 / M-25-22 — "high-impact AI"
Shifting
The 2025 deregulatory successor memoranda retained the accountability core — pre-deployment testing, impact assessments, ongoing monitoring, human oversight, documentation — and require contracts to let the government monitor and evaluate AI performance over time.
Details: Accountable AI in National Security and Government
NIST AI RMF & GAO Accountability Framework
In force
The RMF's MEASURE and MANAGE functions and the GAO framework — written explicitly for auditors, specifying the evidence to collect — both presuppose retained, reconstructable evidence of system behavior over time. Non-binding, but the reference vocabulary federal practice cites.
Details: Accountable AI in National Security and Government
Political Declaration on Responsible Military Use of AI
Phasing in
A non-binding declaration endorsed by more than 50 states, calling for auditable methodologies, documentation, and human accountability for military AI. Internationalizes the "traceable" commitment; aspirational rather than enforceable.
Details: Accountable AI in National Security and Government
EU AI Act
Cross-cutting
The clearest example of a record-centric regime — it does not merely require systems to behave well; it requires them to be able to prove what they did. The high-risk record-keeping obligations were deferred, not deleted; the transparency obligations largely held their near-term clock.
Articles 12 & 19 — record-keeping and log retention
Shifting
High-risk systems must automatically log events over their lifetime, with a retention floor of at least six months. The high-risk regime for stand-alone Annex III systems was deferred from August 2026 to 2 December 2027 (embedded product-AI to August 2028) under the Digital Omnibus — a postponement, not a dismantling.
Details: The Accountability Stack; The Global Map of AI Accountability
Articles 13 & 14 — transparency and human oversight
Shifting
High-risk systems must be interpretable by deployers and designed so a person can effectively oversee and intervene. The CJEU's SCHUFA ruling sharpened this: a rubber-stamp click by someone without authority to override does not de-automate a decision. Deadline deferred to December 2027.
Details: The Global Map of AI Accountability
Article 86 — right to explanation of an individual decision
Shifting
Any affected person may obtain a clear explanation of the role of the AI and the main elements of a decision — a reactive, on-demand right that presupposes the deployer can retrieve historical logs and reconstruct the decision. Tied to the high-risk timeline.
Details: The Global Map of AI Accountability
US federal posture & state ADMT
Cross-cutting
In the absence of a federal statute, the states are the laboratory. The 2025 federal turn was deregulatory, but the binding rules on private deployers are emerging at the state level — converging on notice, explanation, access, and appeal.
California CPPA — automated decisionmaking technology (ADMT) rules
Phasing in
For "significant decisions," businesses must give pre-use notice, an opt-out, access to the logic of the tool, and an appeal right. Effective 1 January 2026, with core ADMT duties phasing in from 1 April 2027. A right of access to decision logic is, in practice, a requirement that an explainable record exist.
Details: The Accountability Stack; The Global Map of AI Accountability
Colorado SB 26-189 (repealed and replaced the 2024 AI Act)
Shifting
The 2024 Colorado AI Act never took effect; it was repealed and replaced by a narrower statute centered on pre-use notice, 30-day adverse-outcome explanations, human review, and developer documentation. Signed May 2026, effective 1 January 2027; final contours still settling.
Details: The Accountability Stack; The Global Map of AI Accountability
Federal acquisition — OMB M-25-22
In force
Even under a deregulatory framing, agencies must ensure contracts let the government regularly monitor and evaluate AI performance, risk, and effectiveness over time — unworkable without a durable record. Applies to solicitations issued on or after 30 September 2025.
Details: The Accountability Stack
Federal effort to constrain state AI rules
Shifting
A proposed moratorium on state AI laws was stripped from federal legislation by a near-unanimous Senate vote in 2025, and a later executive order directed agencies to evaluate and potentially challenge state AI laws. Unresolved tension; the documentation logic is grounded in pre-existing law that the effort does not reach.
Details: Accountable AI in Insurance; The Global Map of AI Accountability
Standards & conformity
Cross-cutting
Where regulation sets the obligation, voluntary standards supply the operational template — and procurement is making them de facto mandatory. Each converges on the same controls: logging, traceability, documentation, monitoring, human oversight.
ISO/IEC 42001 — AI management system (with 42005, 42006)
In force
The first certifiable AI management-system standard, governance-by-documentation, now anchoring a live certification market. Voluntary, but increasingly an AI-vendor-selection benchmark spreading the record-keeping discipline through procurement. (Published 2023; 42005 impact assessment and 42006 certifier requirements added in 2025.)
Details: The Standards Layer
NIST AI Risk Management Framework & GenAI Profile
Shifting
The dominant US non-regulatory vocabulary; its MEASURE and MANAGE functions presuppose retained, reconstructable evidence of system behavior. Under administration-directed revision (removing certain references, folding AI into cyber incident-response), with a draft Cyber AI Profile (IR 8596) and agentic work in progress.
Details: The Standards Layer
EU harmonized standards (CEN-CENELEC JTC 21)
Proposed
Harmonized standards confer a presumption of conformity with the AI Act once cited in the Official Journal. The work has slipped repeatedly; publication targets are around Q4 2026, and the EU explicitly tied its high-risk timeline to standards availability — publication is not the same as OJEU citation.
Details: The Standards Layer
Litigation & evidence
Cross-cutting
The sharpest emerging edge, where the question moves from "is the output true?" to "is the record of this decision admissible, and on what foundation?" The litigated question about an automated decision is almost never abstract; it is forensic.
Proposed Federal Rule of Evidence 707
Proposed
Would require machine-generated evidence offered without a sponsoring expert to meet Daubert-style reliability criteria. Published for comment in 2025 (comment closed February 2026); not adopted, and any adopted version would not take effect before December 2027.
Details: AI on Trial
Draft Rule 901(c) — AI-fabricated evidence
Proposed
A burden-shifting approach to authenticating evidence alleged to be AI-fabricated. Described by the committee as a "just in case" rule; not yet formally transmitted as of late 2025.
Details: AI on Trial
The New York Times Co. v. OpenAI — preservation & production
In force
A court ordered preservation and ultimately production of a 20-million-log sample of ChatGPT conversations, affirmed January 2026 — establishing AI interaction data as discoverable business data subject to preservation orders. A specific ruling, not a general rule.
Details: AI on Trial
EU AI Liability Directive — withdrawn
Shifting
The dedicated AI civil-liability regime many anticipated did not materialize — withdrawn, with notice in the Official Journal in October 2025. AI civil liability in the EU now runs through the AI Act, the revised Product Liability Directive, and national tort law, throwing more weight onto the contemporaneous record.
Details: AI on Trial
No entries match this filter.
How to read this map. This is a summary of Summit Cognitive's research briefs, not a survey of primary law. It is informational and analytical — not legal advice. Dates, statuses, and the very existence of these instruments change quickly: the EU deferred its high-risk obligations, the US federal posture turned deregulatory, Colorado repealed and replaced its own AI Act, and several court matters remain open. Where a brief flagged something as proposed, deferred, contested, or unsettled, that flag is carried here. Status labels are a simplification of more nuanced positions. Before relying on any entry, verify it against primary sources — each underlying brief carries its own citations and access dates. Status is as of mid-2026.