DISPATCHES · Summit Cognitive

← All dispatches

The accountability map

Where the record is becoming the requirement.

An at-a-glance map of where a preserved, contestable decision record is moving from good practice to law.

This is a plain-language map of where a preserved, contestable record of an automated decision is moving from good practice toward requirement. It is a snapshot as of mid-2026, not legal advice. Regimes that share no common drafter are converging on the same artifact — the ability to reconstruct, after the fact, how a consequential decision was reached, on what inputs, under whose oversight, and with what chance to contest it. The map groups that landscape by sector and by cross-cutting regime. Each entry names an instrument, states in one line what it asks for, flags its status, and points to the underlying Summit research brief, which carries the primary citations.

In force live and enforceable today  ·  Phasing in enacted, obligations not yet fully effective  ·  Proposed drafted or under consultation, not yet binding  ·  Shifting in flux — recently deferred, repealed, softened, or contested

Filters are a convenience; the full map reads in order with filtering off.

Finance

Sector

Credit, underwriting, pricing, and fraud detection. The federal posture turned deregulatory across 2025–2026, but the underlying statutes were never amended — so the duty to reconstruct a decision shifted toward state regulators, private plaintiffs, and the EU rather than disappearing.

ECOA / Regulation B — adverse-action notices

In force

A creditor that denies credit must give the specific, accurate principal reasons — which presupposes the decision can be reconstructed. The CFPB's 2022 circular saying "no exemption for complex algorithms" was withdrawn in May 2025, but the statute and regulation are unchanged.

Details: Accountable AI in Financial Services

Model risk management — OCC Bulletin 2026-13 (formerly SR 11-7)

Shifting

Validation, monitoring, documentation, and an auditable model inventory for models in the decision path. In April 2026 the agencies replaced the 2011 SR 11-7 guidance with a lighter, explicitly non-binding successor and placed generative and agentic AI out of scope, pending a future request for information.

Details: Accountable AI in Financial Services

Fair-lending / disparate-impact law (Fair Housing Act, ECOA)

Shifting

Liability for lending outcomes that fall unequally on protected classes — itself a reconstruction exercise. Executive Order 14281 (April 2025) directed agencies to stop using disparate-impact liability; the law is unchanged, and exposure migrated to state attorneys general and private plaintiffs.

Details: Accountable AI in Financial Services

EU AI Act — credit scoring as high-risk (Annex III, 5(b))

Shifting

Creditworthiness systems are classified high-risk, triggering logging, technical documentation, human oversight, and an explanation right. The classification stands; the compliance deadline was deferred to 2 December 2027 under the Digital Omnibus (fraud detection is excluded).

Details: Accountable AI in Financial Services

Healthcare

Sector

Clinical decision support and AI-enabled medical devices, where a model's output lands on a patient through a licensed clinician and becomes the subject of inspection, payer audit, and litigation. Every instrument here presupposes a versioned, case-level record of what the AI recommended and what the clinician did with it.

FDA Predetermined Change Control Plans (PCCPs)

In force

Lets a manufacturer pre-specify how an AI-enabled device may change, and the methods to validate and monitor those changes, so updates ship without a new submission. Finalized December 2024 — and only enforceable against a versioned, case-level record of which model produced which output.

Details: Accountable AI in Healthcare

FDA Clinical Decision Support carve-out (§ 520(o)(1)(E))

In force

Software escapes device regulation only if a clinician can independently review the basis of its recommendation — an accountability requirement disguised as a regulatory carve-out. A tool that cannot expose its basis falls back inside device jurisdiction. (2022 final guidance.)

Details: Accountable AI in Healthcare

ONC/ASTP HTI-1 — predictive DSI source attributes

Shifting

Certified health IT had to surface 31 "source attributes" about a predictive decision-support tool — a de facto model card. The December 2025 HTI-5 proposed rule would unwind those transparency requirements; the outcome is unresolved.

Details: Accountable AI in Healthcare

FDA total-product-life-cycle lifecycle guidance

Proposed

Folds transparency, bias analysis, data quality, and post-market monitoring into a lifecycle framework for AI-enabled devices. Issued as a January 2025 draft (comment closed April 2025); signals direction rather than binding obligation.

Details: Accountable AI in Healthcare

Insurance

Sector

The most developed state-level documentation regimes in the United States. Each, in its own vocabulary, requires insurers to show their work retrospectively, on demand, for individual decisions and for models in aggregate.

NAIC Model Bulletin on the Use of AI Systems by Insurers

Phasing in

Expects insurers to adopt a documented, board-overseen AI systems (AIS) program and contemplates regulators requesting model inventories, governance records, and testing results. Adopted by roughly 25 jurisdictions by 2026; enforcement edge varies by state.

Details: Accountable AI in Insurance

Colorado SB 21-169 / Regulation 10-1-1

Phasing in

Requires insurers to quantitatively test external-data and model use for unfair discrimination, with documented governance. Extended to auto and health insurers effective October 2025; compliance evidence due to the Division on request from July 2026. The life-insurance quantitative-testing methodology (BIFSG-based) remains a pending draft.

Details: Accountable AI in Insurance

New York DFS Circular Letter No. 7 (2024)

In force

A multi-step fairness assessment with a documentation duty woven through, plus an AIS inventory and adverse-action specificity. Notably, an insurer may not hide behind a vendor's trade-secret claim to avoid naming the data behind a decision.

Details: Accountable AI in Insurance

EU AI Act — life/health insurance pricing as high-risk (Annex III, 5(c))

Shifting

Risk assessment and pricing for life and health insurance are classified high-risk, with logging, documentation, oversight, and an Article 86 explanation right. Classification stands; the deadline moved to December 2027. Property and casualty is not named in 5(c).

Details: Accountable AI in Insurance

Hiring & employment

Sector

Automated employment decision tools governed by regimes that diverge substantively but converge on one prerequisite: a preserved, candidate-level record of what the tool did and why — without which an audit cannot run, an appeal contests nothing, and a collective action cannot trace a pattern.

NYC Local Law 144 — bias audit

In force

Employers using an automated employment decision tool must commission an independent annual bias audit, publish a summary, and notify candidates. A December 2025 State Comptroller audit found enforcement "ineffective" precisely where records and disclosures were absent.

Details: Accountable AI in Hiring

Illinois HB 3773 (amended Human Rights Act)

In force

Makes it a civil-rights violation to use AI that has a discriminatory effect in employment decisions or to use ZIP codes as a proxy for protected classes, and requires notice that AI is in use. Effective January 2026; implementing rules pending.

Details: Accountable AI in Hiring

California FEHA automated-decision rules + CPPA ADMT

Phasing in

FEHA imposes a four-year recordkeeping duty over ADS inputs, outputs, and testing (effective October 2025). The CPPA's ADMT rules add pre-use notice, opt-out, access to the logic, and an appeal right for significant decisions including hiring — phasing in from 1 April 2027.

Details: Accountable AI in Hiring

EU AI Act — recruitment AI as high-risk (Annex III, Area 4)

Shifting

Recruitment and candidate-evaluation AI is high-risk, with automatic logging an enumerated obligation. Classification is settled; the deadline was deferred to 2 December 2027 under the Digital Omnibus.

Details: Accountable AI in Hiring

Federal: EEOC guidance rescinded; Title VII / ADEA / ADA intact

Shifting

The EEOC removed its AI hiring guidance in January 2025, but removing guidance does not repeal law — the underlying anti-discrimination statutes still apply to AI-driven selection, shifting the locus of accountability to private litigation and the states.

Details: Accountable AI in Hiring

Litigation — Mobley v. Workday

Shifting

An AI hiring vendor faces direct liability on an "agent" theory, with an ADEA disparate-impact claim conditionally certified as a collective (May 2025). Certification depends on a common, traceable pattern of decisions attributable to the tool. Ongoing — verify against the docket.

Details: Accountable AI in Hiring; AI on Trial

Education

Sector

Schools run AI through the most consequential moments of a student's life — admission, grading, exam integrity, risk flagging. Every governance instrument presupposes someone can reconstruct what the system did to a particular student; that prerequisite is frequently unmet, because the underlying signal is often held by a vendor, not the school.

FERPA — access and amendment of education records

In force

Students may inspect and seek amendment of their education records — which can include AI outputs about them, such as a risk score or integrity flag. A statutory right to a contestable record, but only if the record exists and the school, not just the vendor, can produce it.

Details: Accountable AI in Education

Title VI / Title IX / Section 504; Ogletree room-scan ruling

In force

Civil-rights and disability statutes reach biased proctoring, grading, and detection tools; a 2022 federal ruling held a pre-exam room scan an unreasonable search under the Fourth Amendment for a public institution. Each remedy depends on a preserved, student-level record. (ED's OCR AI nondiscrimination resource was rescinded in 2025; the statutes remain.)

Details: Accountable AI in Education

EU AI Act — educational decision AI as high-risk; emotion-recognition ban

Shifting

Admissions, learning-outcome evaluation, placement, and exam-monitoring AI are high-risk, with logging, oversight, and redress duties. The prohibition on emotion recognition in education is already in force (since February 2025); the broader high-risk obligations were deferred to 2 December 2027.

Details: Accountable AI in Education

Public safety

Sector

Face recognition, predictive tools, license-plate readers, and gunshot detection. Where liberty is at stake, what matters is not aggregate accuracy but whether a specific automated output was recorded, disclosed to the affected person and the court, and testable for reliability after the fact.

Virginia facial-recognition framework (§ 15.2-1723.2)

Phasing in

Requires agencies to keep records "sufficient to facilitate discovery in criminal proceedings," including a complete query history, and bars real-time tracking. Revised provisions scheduled to take effect 1 July 2026.

Details: Accountable AI in Public Safety

Williams v. City of Detroit settlement — face-recognition policy

In force

Bars arrests based solely on a face-recognition result, bars lineups built on such a lead absent independent evidence, and mandates an audit of every case since 2017 where the tool obtained a warrant. Court-enforced for four years (settled June 2024).

Details: Accountable AI in Public Safety

Brady disclosure & Confrontation Clause for algorithmic leads

Shifting

Defense advocates argue the use of a face-recognition search is itself disclosable — the probe photo, database, algorithm, error rates, and candidate lists. Courts have not settled clear rules; trade-secrecy claims create a "missing algorithm" problem. Unsettled and contested.

Details: Accountable AI in Public Safety

Massachusetts SJC — ShotSpotter reliability hearings

Shifting

In May 2025 the court endorsed judicial inquiry into gunshot-detection reliability, indicating a Daubert-Lanigan hearing should be available when the forensic use is challenged. Whether other state courts follow is unsettled.

Details: Accountable AI in Public Safety

Elections & synthetic media

Sector

Two distinct responses to AI-generated political content. Content-based bans are proving constitutionally fragile; disclosure and provenance obligations are surviving better, and both increasingly lean on machine-readable provenance as connective tissue.

US state election-deepfake laws (~30 states)

Shifting

Most follow a disclosure model — political media with AI-generated content must carry a disclaimer. A minority reach for prohibition, and those are breaking: California's two flagship 2024 statutes both fell in 2025 (First Amendment; Section 230). Litigation ongoing.

Details: Synthetic Media and Democratic Integrity

EU AI Act — Article 50 transparency

Phasing in

Providers must mark generative outputs in a machine-readable format, and deployers must disclose deepfakes — a duty that applies even absent intent to deceive. Largely held its 2 August 2026 application date, with a short grace period and a June 2026 Code of Practice.

Details: Synthetic Media and Democratic Integrity

EU Disinformation Code folded into the DSA

In force

The formerly voluntary code became an auditable benchmark for very large platforms' risk-mitigation duties under DSA Article 35, effective as a Code of Conduct from July 2025, with the first reporting cycle covering the second half of 2025.

Details: Synthetic Media and Democratic Integrity

C2PA Content Credentials (provenance infrastructure)

Phasing in

A machine-readable, signed provenance standard now adopted across cameras, phones, and generative providers, with a Conformance Program launched in 2025. Not a legal mandate but the connective tissue regulators and platforms increasingly lean on; fragile where pipelines strip metadata.

Details: Synthetic Media and Democratic Integrity

National security & government

Sector

The governing documents for US defense, intelligence, and federal civilian AI converge on one under-stated requirement: when an AI system informs a consequential decision, the basis must remain traceable, auditable, and reconstructable. The deregulatory turn of 2025 retained this core machinery.

DoD AI Ethical Principles — "Traceable"; Directive 3000.09

In force

Makes traceable a named pillar — "transparent and auditable methodologies, data sources, and design procedures and documentation" — and requires "appropriate levels of human judgment over the use of force." Verifying that judgment was exercised requires a record of what the human saw and decided.

Details: Accountable AI in National Security and Government

OMB M-25-21 / M-25-22 — "high-impact AI"

Shifting

The 2025 deregulatory successor memoranda retained the accountability core — pre-deployment testing, impact assessments, ongoing monitoring, human oversight, documentation — and require contracts to let the government monitor and evaluate AI performance over time.

Details: Accountable AI in National Security and Government

NIST AI RMF & GAO Accountability Framework

In force

The RMF's MEASURE and MANAGE functions and the GAO framework — written explicitly for auditors, specifying the evidence to collect — both presuppose retained, reconstructable evidence of system behavior over time. Non-binding, but the reference vocabulary federal practice cites.

Details: Accountable AI in National Security and Government

Political Declaration on Responsible Military Use of AI

Phasing in

A non-binding declaration endorsed by more than 50 states, calling for auditable methodologies, documentation, and human accountability for military AI. Internationalizes the "traceable" commitment; aspirational rather than enforceable.

Details: Accountable AI in National Security and Government

EU AI Act

Cross-cutting

The clearest example of a record-centric regime — it does not merely require systems to behave well; it requires them to be able to prove what they did. The high-risk record-keeping obligations were deferred, not deleted; the transparency obligations largely held their near-term clock.

Articles 12 & 19 — record-keeping and log retention

Shifting

High-risk systems must automatically log events over their lifetime, with a retention floor of at least six months. The high-risk regime for stand-alone Annex III systems was deferred from August 2026 to 2 December 2027 (embedded product-AI to August 2028) under the Digital Omnibus — a postponement, not a dismantling.

Details: The Accountability Stack; The Global Map of AI Accountability

Articles 13 & 14 — transparency and human oversight

Shifting

High-risk systems must be interpretable by deployers and designed so a person can effectively oversee and intervene. The CJEU's SCHUFA ruling sharpened this: a rubber-stamp click by someone without authority to override does not de-automate a decision. Deadline deferred to December 2027.

Details: The Global Map of AI Accountability

Article 86 — right to explanation of an individual decision

Shifting

Any affected person may obtain a clear explanation of the role of the AI and the main elements of a decision — a reactive, on-demand right that presupposes the deployer can retrieve historical logs and reconstruct the decision. Tied to the high-risk timeline.

Details: The Global Map of AI Accountability

US federal posture & state ADMT

Cross-cutting

In the absence of a federal statute, the states are the laboratory. The 2025 federal turn was deregulatory, but the binding rules on private deployers are emerging at the state level — converging on notice, explanation, access, and appeal.

California CPPA — automated decisionmaking technology (ADMT) rules

Phasing in

For "significant decisions," businesses must give pre-use notice, an opt-out, access to the logic of the tool, and an appeal right. Effective 1 January 2026, with core ADMT duties phasing in from 1 April 2027. A right of access to decision logic is, in practice, a requirement that an explainable record exist.

Details: The Accountability Stack; The Global Map of AI Accountability

Colorado SB 26-189 (repealed and replaced the 2024 AI Act)

Shifting

The 2024 Colorado AI Act never took effect; it was repealed and replaced by a narrower statute centered on pre-use notice, 30-day adverse-outcome explanations, human review, and developer documentation. Signed May 2026, effective 1 January 2027; final contours still settling.

Details: The Accountability Stack; The Global Map of AI Accountability

Federal acquisition — OMB M-25-22

In force

Even under a deregulatory framing, agencies must ensure contracts let the government regularly monitor and evaluate AI performance, risk, and effectiveness over time — unworkable without a durable record. Applies to solicitations issued on or after 30 September 2025.

Details: The Accountability Stack

Federal effort to constrain state AI rules

Shifting

A proposed moratorium on state AI laws was stripped from federal legislation by a near-unanimous Senate vote in 2025, and a later executive order directed agencies to evaluate and potentially challenge state AI laws. Unresolved tension; the documentation logic is grounded in pre-existing law that the effort does not reach.

Details: Accountable AI in Insurance; The Global Map of AI Accountability

Standards & conformity

Cross-cutting

Where regulation sets the obligation, voluntary standards supply the operational template — and procurement is making them de facto mandatory. Each converges on the same controls: logging, traceability, documentation, monitoring, human oversight.

ISO/IEC 42001 — AI management system (with 42005, 42006)

In force

The first certifiable AI management-system standard, governance-by-documentation, now anchoring a live certification market. Voluntary, but increasingly an AI-vendor-selection benchmark spreading the record-keeping discipline through procurement. (Published 2023; 42005 impact assessment and 42006 certifier requirements added in 2025.)

Details: The Standards Layer

NIST AI Risk Management Framework & GenAI Profile

Shifting

The dominant US non-regulatory vocabulary; its MEASURE and MANAGE functions presuppose retained, reconstructable evidence of system behavior. Under administration-directed revision (removing certain references, folding AI into cyber incident-response), with a draft Cyber AI Profile (IR 8596) and agentic work in progress.

Details: The Standards Layer

EU harmonized standards (CEN-CENELEC JTC 21)

Proposed

Harmonized standards confer a presumption of conformity with the AI Act once cited in the Official Journal. The work has slipped repeatedly; publication targets are around Q4 2026, and the EU explicitly tied its high-risk timeline to standards availability — publication is not the same as OJEU citation.

Details: The Standards Layer

Litigation & evidence

Cross-cutting

The sharpest emerging edge, where the question moves from "is the output true?" to "is the record of this decision admissible, and on what foundation?" The litigated question about an automated decision is almost never abstract; it is forensic.

Proposed Federal Rule of Evidence 707

Proposed

Would require machine-generated evidence offered without a sponsoring expert to meet Daubert-style reliability criteria. Published for comment in 2025 (comment closed February 2026); not adopted, and any adopted version would not take effect before December 2027.

Details: AI on Trial

Draft Rule 901(c) — AI-fabricated evidence

Proposed

A burden-shifting approach to authenticating evidence alleged to be AI-fabricated. Described by the committee as a "just in case" rule; not yet formally transmitted as of late 2025.

Details: AI on Trial

The New York Times Co. v. OpenAI — preservation & production

In force

A court ordered preservation and ultimately production of a 20-million-log sample of ChatGPT conversations, affirmed January 2026 — establishing AI interaction data as discoverable business data subject to preservation orders. A specific ruling, not a general rule.

Details: AI on Trial

EU AI Liability Directive — withdrawn

Shifting

The dedicated AI civil-liability regime many anticipated did not materialize — withdrawn, with notice in the Official Journal in October 2025. AI civil liability in the EU now runs through the AI Act, the revised Product Liability Directive, and national tort law, throwing more weight onto the contemporaneous record.

Details: AI on Trial

No entries match this filter.

How to read this map. This is a summary of Summit Cognitive's research briefs, not a survey of primary law. It is informational and analytical — not legal advice. Dates, statuses, and the very existence of these instruments change quickly: the EU deferred its high-risk obligations, the US federal posture turned deregulatory, Colorado repealed and replaced its own AI Act, and several court matters remain open. Where a brief flagged something as proposed, deferred, contested, or unsettled, that flag is carried here. Status labels are a simplification of more nuanced positions. Before relying on any entry, verify it against primary sources — each underlying brief carries its own citations and access dates. Status is as of mid-2026.

— Dispatches · Summit Cognitive