Proposal № 027 of 250 · Released July 30, 2026
The Right to a Human Decision
No American should be denied a job, a loan, a home, or a medical claim by a machine alone. Explanation, human review, and appeal, in the seven places it actually matters.
The problem
Somewhere today an American applied for a job and was rejected in under a second by a system no human at the company has ever inspected. Somewhere else, a mother's insurance claim was denied by a model trained on prior denials. Somewhere else, a rental application was scored, a loan repriced, a benefit terminated. In none of these cases was the person told which factors decided it, and in most of them there was nobody to appeal to who could actually reverse it.
The wrong is not that a machine was involved. Machines are often more consistent than the humans they replace, and human decisions in these domains have their own long record of arbitrariness and bias. The wrong is the absence of a person on the other end: a decision that alters someone's life, issued by nothing, explicable by no one, appealable to no one.
Every previous generation of American consumer protection understood this. The Fair Credit Reporting Act has required adverse action notices since 1970 — if a credit report costs you something, you must be told, and you may dispute it. The Equal Credit Opportunity Act requires specific reasons for a credit denial, not a score. Due process in benefit terminations was constitutionalised in Goldberg v. Kelly in 1970. The principle is not novel and it is not European. It is that consequential adverse decisions come with reasons and a route back.
That principle simply never got extended to the systems that now make most of these calls at scale.
The states have started. Colorado enacted the Automated Decision-Making Technology Act on May 14, 2026, effective January 1, 2027, replacing its earlier and broader AI law with something narrower and more operable: advance notice that automated technology is being used, an explanation after an adverse outcome, a right to correct the data, and meaningful human review. It applies to "consequential decisions" in defined domains — employment, education, housing, lending, insurance, health care, and essential government services. Illinois has a disclosure law. California has employment regulations. The European Union's GDPR has carried a version of this in Article 22 for years.
So the model exists, has been drafted, argued over, and narrowed by a legislature. What America has is a patchwork in which a worker's rights depend on which state processed the application.
The proposal
A federal floor: in seven domains, no adverse decision may be final without notice, an explanation in plain language, human review on request, and a route to appeal.
The seven are the ones Colorado converged on because they are the ones that determine a life: employment, housing, lending, insurance, health care, education, and essential government benefits.
Outside those seven, nothing here applies. This is not a general regulation of artificial intelligence, and we would oppose extending it into one.
How it would work
- Notice, before. If automated technology will materially influence the decision, the applicant is told so at the point of application. One sentence.
- Explanation, after. An adverse decision comes with the principal factors that drove it, in plain language, in the same channel that delivered the rejection. Not the model weights, not the source code, and not a trade-secret disclosure — the same standard the Equal Credit Opportunity Act has imposed on lenders for fifty years without destroying the lending industry.
- Human review on request. The applicant may demand review by a person with the authority and the information to reverse the outcome. This is the load-bearing clause. Review by someone who can only re-run the model and read back its output is not review, and the statute must say so explicitly, because that is exactly what will be built otherwise.
- Correction. If the decision rested on inaccurate data about the person, they may correct it and have the decision re-made. This is the FCRA dispute right, moved to where the decisions now happen.
- A deadline. Human review completes within a fixed short period, and the burden of delay does not fall on the applicant. A right to review that takes ninety days is a denial with extra steps.
- Preserve the stricter state laws. A federal floor, explicitly not a ceiling. Colorado's law and any successor should survive intact.
The numbers
The cost of this proposal is the cost of the human review, and the honest way to estimate it is by the appeal rate, not the decision volume.
Where similar rights exist, appeal rates run low — typically a few percent of adverse outcomes, because most people who are rejected accept it. Take employment: if a large employer issues 100,000 automated rejections a year and 3 percent request review, that is 3,000 reviews. At 20 minutes each, that is about 1,000 hours, or roughly half of one full-time position — for a firm making a hundred thousand hiring decisions.
That is the entire compliance story for most covered firms, and it is why we think the industry objection is weaker than it sounds. The expensive part is not the reviewing. It is building the explanation pipeline once.
The counter-number, which matters more: in health insurance, where denial-and-appeal data is unusually good, a substantial share of denials that are appealed get overturned. Systems that face no appeals are not producing better decisions than systems that do. They are producing unexamined ones.
The honest objections
"Explanations from complex models are either trivial or misleading." The most technically serious objection. Post-hoc explanations of high-dimensional models genuinely can be unfaithful to what the model did, and a confident-sounding list of "principal factors" can be closer to a plausible story than a cause. Two answers. The standard is the ECOA standard, which has been workable for decades with statistical scoring models that were never fully interpretable either. And if a system genuinely cannot produce an honest account of why it rejected someone, that is a strong argument that it should not be making that decision alone — which is precisely the conclusion this proposal reaches.
"Human review will be a rubber stamp." Probably, in many places. This is why the text must require authority to reverse, access to the underlying record, and a reviewer who is not evaluated on throughput alone — and why overturn rates should be reported. A rubber stamp that must publish how often it stamps is a weaker rubber stamp. We do not claim it becomes a real one.
"This slows hiring and lending and raises costs for the people it claims to help." A real risk in thin-margin lending especially, where added friction can mean the marginal applicant simply is not served. The mitigations are the narrow domain list, the low expected appeal rate, and the deadline that keeps review from becoming a stall. We would rather have this argued on measured compliance costs than asserted on either side, and the statute should require an actual cost review at three years.
"Human decisions in these domains were biased and inconsistent. Machines are an improvement." Often true, and we are not proposing to return to the loan officer's intuition. Nothing here forbids automated decisions, requires human decisions, or mandates that a human make the first call. It requires that a person be reachable when the machine says no.
"A federal floor will preempt stronger state law in practice, whatever the text says." A fair reading of how preemption fights usually end. If the bill that emerges converts a floor into a ceiling, it should be opposed, including by us.
Sources
- Colorado Automated Decision-Making Technology Act, SB 26-189, signed May 14, 2026, effective January 1, 2027 — notice, post-adverse-outcome explanation, correction rights, meaningful human review across covered domains (leg.colorado.gov)
- Fair Credit Reporting Act, 15 U.S.C. § 1681m (adverse action notices); Equal Credit Opportunity Act, 15 U.S.C. § 1691(d) (statement of specific reasons)
- Goldberg v. Kelly, 397 U.S. 254 (1970)
- Regulation (EU) 2016/679 (GDPR) Article 22 and the EU AI Act human-oversight provisions
- Illinois AI disclosure legislation; California employment discrimination regulations on automated decision systems
- Proposal № 013 (The Portfolio Act), № 025 (The Automation Ledger)