News / public record

Checking
  1. Update / Component / Readiness · CheckingOpenLegalCore Word Connector public launch is completeThe Apache-2.0 v0.1.0-beta.1 source-only release now has a complete public component record, homepage feature, Roadmap outcome and discovery path.
  2. Update / Component / Release · CheckingOpenLegalCore Word Connector v0.1.0-beta.1 is publicThe Apache-2.0 source-only beta brings verified Slovenian legal-source research into Word for the web through OLC Engine, directly or through Open WebUI.
  3. Article · CheckingLegal RAG Can Fail Before the Model AnswersA genuine provision can still support the wrong answer. This article shows how collection scope, document splitting, filters and ranking determine which sources a legal AI model ever sees.
  4. Article · CheckingWhen a Correct Citation Leads to the Wrong LawA genuine provision and an official link do not prove that the right law was applied. This article explains why legal AI must preserve temporal versions, transitional rules and the source-selection path.
  5. Update / Project · CheckingPublic project foundation gate is completeOpenLegalCore has completed its public project foundation gate: core public routes, bounded participation channels and publication controls are operating.
  6. Article · CheckingAn Audit Trail Is Not a Log: What a Digital Legal Process Must PreserveAn audit trail is useful when it permits a reasonable reconstruction of the particular process while remaining purpose-bound, appropriately protected and subject to retention rules.
  7. Article · CheckingArticle 86 of the AI Act: Does the right to explanation already apply to Annex III systems?The legal question remains open. The technical capacity to provide an intelligible explanation should not.
  8. Update / Project · CheckingPrivate security reporting is now availableOpenLegalCore now provides a monitored project-wide private channel and a canonical security-reporting policy.
  9. Update / Component / Release · CheckingSlovenian Case Law Pipeline v0.1.7 is publicOpenLegalCore has published the production-verified Slovenian case-law ingestion component as a source-available BUSL-1.1 release.
  10. Article · CheckingA Result Is Not a Method: Why Visible Methods Matter in Legal AIWhy legal AI needs inspectable sources, provenance and human review: a legal and technical analysis of the EU Artificial Intelligence Act and GDPR.
  11. Update / Component / Release · CheckingSlovenian Legislation Pipeline v0.1.0 is publicOpenLegalCore has published the production-verified PISRS legislation-ingest component as a source-available BUSL-1.1 release.
  12. Update / Component / Release · CheckingLegal OCR Pipeline v0.1.2 is publicThe first public OpenLegalCore component is available with code, tests, offline review tooling and a bounded acceptance record.
Explore the code
Menu

THE RIGHT TO EXPLANATION BETWEEN TWO DATES

Article 86 of the AI Act:Does the right toexplanation already applyto Annex III systems?

Under the AI Act’s general timetable, Article 86 became applicable on 2 August 2026. Regulation (EU) 2026/1744 neither amended Article 86 nor expressly deferred it.

Summary

Under the AI Act’s general timetable, Article 86 became applicable on 2 August 2026. Regulation (EU) 2026/1744 neither amended Article 86 nor expressly deferred it. At the same time, however, that Regulation postponed the application of Article 6(2) and most of the rules by which Annex III systems are legally classified as high-risk until 2 December 2027. This creates a serious interpretative problem. May Article 6(2) be applied before that date to the limited extent necessary to determine the scope of Article 86? Or, without an applicable classification rule, does the right to explanation still lack an operative subject matter?

The text supports arguments in both directions. The first interpretation relies on the express timetable, the practical effectiveness of Article 86 and the protection of fundamental rights. The second stresses the systemic connection between classification, technical obligations and remedies, together with the requirement of legal certainty. As at 26 August 2026, neither final Commission guidelines nor a ruling on the merits from the Court of Justice of the European Union has settled that relationship. It would therefore be professionally misleading to claim either that the right unquestionably applies already or that it has unquestionably been deferred.

The practical conclusion is less ambiguous. Organisations using AI in recruitment, creditworthiness assessment, access to services, the administration of justice or other Annex III fields should already be able to reconstruct the path from input data and system output to the human decision. The legal question remains open. The technical capacity to provide an intelligible explanation should not.

One decision, two dates

Consider a familiar but entirely hypothetical case. A candidate does not get a job. The employer’s message is brief: after careful consideration, the candidate was not selected. The candidate then learns that the human resources team used a system to rank applications, flag supposed risks and recommend a shortlist. They ask what role the system played and which reasons were decisive.

The employer might answer in one of two ways. The first is: Article 86 of the AI Act has applied since 2 August 2026, so you are entitled to a clear and meaningful explanation. The second is: the rules for high-risk Annex III systems have been deferred until 2 December 2027, so that right does not yet apply.

Both answers sound confident. Neither is safe without further legal analysis.

The difficulty is not that every part of Article 86 is obscure. It arises because the right and the classification mechanism on which that right depends sit in different parts of the Regulation. Following the July 2026 amendment, they are also caught between different dates of application.

This is more than a puzzle about a legislative calendar. The answer may determine whether an affected person has a direct legal basis for a request, whether an organisation must provide an explanation now, and which records must exist if any explanation is to be possible. As we explained in A Result Is Not a Method: Why Visible Methods Matter in Legal AI, a final result does not reveal how a system reached it or how a person used it. Article 86 brings that distinction into a concrete legal relationship.

What Article 86 actually provides

The official heading of Article 86 is Right to explanation of individual decision-making. This article uses the shorter expression right to explanation, but always as shorthand for that specific provision, not for a general right to have every AI system explained.

Article 86 does not give everyone a universal right to an explanation of every AI system. Its first paragraph requires several conditions to be met at the same time:

  1. there must be an affected person;
  2. the decision must be taken by the deployer of an AI system;
  3. the decision must be based on the output from a high-risk AI system listed in Annex III;
  4. the critical-infrastructure systems listed in point 2 of Annex III are expressly excluded;
  5. the decision must produce legal effects or similarly significantly affect the person; and
  6. the person must consider that the decision has an adverse impact on their health, safety or fundamental rights.

Where those conditions are met, the person may obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken. The provision appears in the consolidated text of Regulation (EU) 2024/1689 and is also reproduced separately in the European Commission’s official AI Act Service Desk.

The identity of the duty bearer matters. Article 86 directs the request to the deployer—generally the organisation or public authority using the system under its authority—not directly to the provider that developed or placed the system on the market. The deployer is the actor that takes the decision concerning the individual. In practice, however, the deployer may be unable to give a useful explanation without information and technical support from the provider. The legal duty and the technical capacity to discharge it may therefore sit with different actors.

The required explanation also has limits. Article 86 does not automatically require disclosure of source code, the entire technical file or a generative model’s internal chain of thought. It requires an explanation of the system’s role in the particular procedure and the main elements of the particular decision. The subject is not the model in the abstract. It is the path to a decision that affected an identifiable person.

Recital 171 adds that the relevant decision should be based mainly on the output from the system and that the explanation should enable the person to exercise their rights. This is an important interpretative aid, but a recital cannot replace or rewrite the operative provision. Article 86(1) uses the broader expression “on the basis of the output”. The precise degree of influence that the system must have had on the decision therefore remains another issue for practice to clarify. Recital 171

Paragraphs 2 and 3 narrow the right further. Exceptions or restrictions may follow from Union or national law, provided that national rules comply with Union law. Article 86 also applies only to the extent that the same right is not otherwise provided for under Union law. Its relationship with the General Data Protection Regulation and other sector-specific rules cannot therefore be reduced to a simple accumulation of rights.

Why Annex III is not enough on its own

Annex III lists fields in which AI may have a profound effect on a person’s life. They include biometrics, education, employment, access to essential private and public services, law enforcement, migration, the administration of justice and democratic processes. Yet the fact that a system’s intended purpose appears on that list is not always the final step in its legal classification.

The essential link is Article 6 of the AI Act. Article 6(2) establishes the classification route for Annex III systems. Article 6(3), however, creates a limited derogation where a system does not pose a significant risk of harm to health, safety or fundamental rights, including where it does not materially influence the outcome of decision-making. That derogation is unavailable where the system performs profiling of natural persons.

A sound legal analysis cannot therefore proceed on the basis that “the use case appears in Annex III, so the system is high-risk”. At a minimum, it must examine the intended purpose, the system’s actual function, the relevant point of Annex III and the conditions in Article 6(3). The same is true when interpreting Article 86. If the classification rules were applied before 2 December 2027 solely to establish the scope of the right to explanation, the complete relevant test would have to be applied—not Annex III in isolation and not Article 6(2) alone.

This is the heart of the temporal problem. Article 86 does not refer merely to “a system resembling those in Annex III”. It refers to a high-risk AI system listed in Annex III. That legal status arises through the classification scheme in Article 6, whose application to this group of systems has been deferred.

What Regulation (EU) 2026/1744 changed

Regulation (EU) 2026/1744 was adopted on 8 July 2026, published on 24 July and entered into force on 27 July 2026. Among other changes, it amended Article 113 of the AI Act, which governs the Regulation’s entry into force and application.

Under the amended Article 113:

  • the AI Act generally applies from 2 August 2026;
  • Chapter III, Sections 1, 2 and 3 apply to systems classified as high-risk under Article 6(2) and Annex III from 2 December 2027;
  • the same sections apply to systems falling under Article 6(1) and Annex I from 2 August 2028; and
  • Article 6(5), concerning Commission guidelines, is excluded from that postponement.

Apart from Article 6(5), the deferred group covers the classification rules in Articles 6 and 7, the requirements for high-risk systems in Articles 8 to 15, and the main obligations of providers and deployers in Articles 16 to 27. It includes technical documentation, record-keeping, information to deployers, human oversight and other requirements that also matter when a decision later needs to be reconstructed.

Article 86 is not part of that group. It appears in Chapter IX, Section 4, which concerns remedies. That point deserves to be made expressly because Chapter III also has a Section 4, but there the subject is notifying authorities and notified bodies. A bare reference to “Section 4” without naming the chapter can therefore lead quickly to the wrong conclusion.

Regulation (EU) 2026/1744 did not amend Article 86. Nor did it add the provision to the express postponements. On an ordinary reading of Article 113, Article 86 therefore became applicable as a provision on 2 August 2026.

It does not necessarily follow, however, that every substantive condition in Article 86 can already be satisfied. The timetable tells us when the Article applies. It does not expressly say whether a classification provision with a deferred date may be used earlier as an incidental test for that Article.

The recitals to Regulation (EU) 2026/1744 explain that delays in harmonised standards and supporting instruments, together with the incomplete readiness of parts of the institutional framework, prompted the postponement of the high-risk regime. That supports the view that the legislature intended to move a connected regulatory package. The explanation for the amendment does not, however, answer the Article 86 question directly.

The first interpretation: the right already applies

The strongest argument for immediate application begins with the wording of Article 113. In July 2026 the legislature revised the timetable in detail. It identified the deferred chapters, sections, classification routes and dates, but did not mention Article 86. Where a regulation specifies departures from a general date so precisely, adding another without an express textual basis is difficult.

This interpretation rests on four principal grounds.

1. The express timetable

Article 86 is among the provisions for which Article 113 sets no special later date. Regulation (EU) 2026/1744 was adopted shortly before the general date of application. Had the legislature intended to postpone the right, it could have said so expressly.

2. The practical effectiveness of the right

If no system can be treated as high-risk under Article 6(2) and Annex III before 2 December 2027, Article 86 has almost no operative field during that period. An interpretation that deprives an applicable provision of practical effect requires a strong justification. Recital 171 describes the purpose of the right as enabling the affected person to exercise their rights effectively.

3. Classification as an incidental test

It may be possible to distinguish between two uses of Article 6. The first is the full application of the high-risk regulatory regime, imposing the requirements of Chapter III on providers and deployers. The second is a limited, incidental use of the classification criteria solely to establish whether a condition in another, already applicable provision is satisfied. On that reading, postponing the Chapter III obligations would not necessarily erase the taxonomy on which Article 86 relies.

4. Protection of fundamental rights

Article 86 is a remedy for circumstances involving a possible adverse impact on health, safety or fundamental rights. If two interpretations are genuinely available, the objective of effective protection favours the one that enables the affected person to understand and challenge the decision.

This is a serious legal interpretation, but it has a weakness. Nowhere does the Regulation state that Article 6(2) and (3) apply before 2 December 2027 “for the purposes of Article 86 only”. That distinction must be constructed through interpretation; it cannot be read from an express sentence in the legislation.

The second interpretation: the right is effectively deferred for Annex III systems

The opposing interpretation need not claim that Article 86 itself is inapplicable. Instead, it argues that its decisive substantive condition cannot be met before 2 December 2027: the system has not yet acquired the legal classification of high-risk under the deferred Article 6(2).

This interpretation, too, has strong foundations.

The phrase “high-risk AI system listed in Annex III” has a specific legal meaning within the Regulation. Annex III describes use cases; Article 6(2), subject to the Regulation’s conditions, gives those systems high-risk status. If the classification rule does not yet apply, it may follow that its legal consequence does not yet arise either.

2. Article 113 moves classification and the regime together

The amended Article 113 does not postpone only individual technical requirements. It expressly covers Chapter III, Sections 1, 2 and 3, and refers to systems classified as high-risk pursuant to Article 6(2) and Annex III. This points to a legislative decision that classification, requirements and obligations should begin to apply as a connected package.

3. The right depends technically on deferred obligations

A meaningful individual explanation is much easier to provide where technical documentation, logs, information for the deployer and genuine human oversight exist. Those are precisely the supporting obligations whose application to Annex III systems has been deferred. An interpretation under which the deployer must already provide a legally sufficient explanation, while the supporting duties of the provider and deployer do not yet apply, creates an evident systemic tension.

An obligation must be sufficiently foreseeable, particularly where breach may lead to regulatory scrutiny and sanctions. If a deferred classification test nevertheless creates an immediate individual right, regulated actors must infer that result from the relationship between provisions located far apart in the Regulation. The principle of legal certainty therefore favours a common start for the regime.

This interpretation has its own weakness. The legislature left Article 86 outside the express postponement even though, when revising the timetable, it could be expected to know that the provision refers to Annex III. An interpretation that leaves the right practically empty for sixteen months must explain why its date was not moved directly.

The most accurate answer at the cut-off date

As at 26 August 2026, four findings can be stated with confidence. One central question cannot.

Established Still unresolved
Article 86 was neither amended nor expressly deferred. Whether Article 6(2) and (3) may be applied incidentally before 2 December 2027 solely to determine the scope of Article 86.
Article 86 falls within the general date of application, 2 August 2026. Whether the phrase “high-risk AI system listed in Annex III” presupposes a classification already applicable under Article 6(2).
For systems falling under Article 6(2) and Annex III, the application of Chapter III, Sections 1, 2 and 3 is postponed until 2 December 2027. How the effectiveness of the right and the deployer’s legal certainty should be reconciled during the transitional period.
No ruling on the merits from the Court of Justice or final Commission guidance had resolved this relationship by the cut-off date. Which interpretation will prevail before authorities and courts.

The most precise answer is therefore:

On the wording of Article 113, Article 86 falls within the general date of application of 2 August 2026. It remains unresolved, however, whether its condition that the system be a high-risk Annex III system can be satisfied before 2 December 2027, when the application of Article 6(2) has been expressly deferred.

An affected person can reasonably invoke Article 86 now, particularly where a decision relied heavily on a system used in an Annex III field. The deployer, in turn, may argue that the classification condition is not yet operative. The outcome of such a request is therefore uncertain. A bare assertion that “all high-risk provisions have been postponed” is too broad. So is the assertion that Article 86 unquestionably already creates a right in every Annex III case.

The Commission has not yet given a final answer

On 19 May 2026, the European Commission published draft guidelines on the classification of high-risk AI systems. The accompanying targeted consultation closed on 23 July 2026, and the Commission stated that the final guidelines would be adopted by the end of 2026.

The draft explains how Article 6 should operate and distinguishes between systems under Annex I and Annex III. It does not, however, directly address the temporal relationship between Articles 86 and 113 following Regulation (EU) 2026/1744. It is also a draft, not a binding interpretation of the law.

The final guidelines may have significant practical value, especially if the Commission explains whether the classification criteria apply during the transitional period for the purposes of other provisions in the Regulation. They cannot amend the Regulation or bind the Court of Justice. They will therefore be a reason to update this analysis, but not necessarily the final answer.

The EDPB–EDPS Joint Opinion 1/2026, issued during the legislative process, likewise warned that administrative simplification should not weaken the protection of fundamental rights. It is an important institutional signal, but it is advisory and does not analyse Article 86 specifically.

Two cases before the Court of Justice, but no definitive answer

Article 86 has already reached the Court of Justice of the European Union, but not yet in a form that resolves the issue examined here.

C-806/24, YETTEL BULGARIA

In Case C-806/24, YETTEL BULGARIA, a Bulgarian court asked, among other things, how Article 86 should be interpreted in a consumer dispute. On 3 June 2026 the Court issued an order, ECLI:EU:C:2026:466, but did not answer the questions on their merits. After the claim was withdrawn, the main proceedings had become devoid of purpose, and the Court held that there was no longer any need to rule. Order in Case C-806/24

The case is therefore not authority on the meaning or temporal application of Article 86. It shows only that the provision reached the Court and that the substantive questions remained unanswered.

C-245/25, DZI – OBSHTO ZASTRAHOVANE

The pending Case C-245/25, DZI – OBSHTO ZASTRAHOVANE concerns software that assisted a court-appointed expert in preparing an expert report. The referring court asks whether such a system may fall within point 8 of Annex III; what weight should be given to human verification, traceability and explainability; and whether the right to explanation is satisfied merely because the expert checks the result against their own scientific and technical knowledge and professional experience.

Questions 9 and 10 are particularly relevant to temporal application. They concern the admissibility of a request for a preliminary ruling on a regulation that is already in force although the provisions in question are not yet applicable, and the application of a new rule to legal relationships created earlier that continue to produce effects. The complete list of questions appears in the Official Journal of the European Union, C/2026/276.

No ruling on the merits had been published by 26 August 2026. Moreover, the request was made before Regulation (EU) 2026/1744 was adopted. A future judgment may clarify general principles, but it may not address the new tension between the dates in Articles 86 and 113 directly.

The Court’s broader case-law starts from the proposition that a new rule generally applies to the future effects of situations arising under the old rule, but not to situations that had become final before the new rule entered into force. The Court discussed that principle, among other decisions, in its judgment of 2 December 2021, Case C-484/20, Vodafone Kabel Deutschland, ECLI:EU:C:2021:975, paragraphs 30–31, and its judgment of 14 May 2020, Case C-15/19, Azienda Municipale Ambiente, ECLI:EU:C:2020:371, paragraphs 56–57. That general principle does not by itself answer the present question, because Article 113 contains a specific temporal arrangement for the very provisions at issue.

Uncertainty under Article 86 does not mean that an individual has no other rights until 2 December 2027. Where a system processes personal data, the General Data Protection Regulation must be examined separately.

The two regimes overlap, but they are not the same:

Article 86 of the AI Act GDPR
Concerns a deployer’s decision based on the output of a specified high-risk Annex III system. Article 22 concerns a decision based solely on automated processing, producing legal effects or similarly significantly affecting a person, and involving personal data.
Does not necessarily require full automation, but it does require a particular system classification and the other conditions in Article 86. Articles 13, 14 and 15 require meaningful information about the logic involved, as well as the significance and envisaged consequences of the processing, in the relevant circumstances.
The duty to explain rests with the deployer taking the decision. The duty rests with the controller of the personal data, which may or may not be the same actor in the particular data flow.
Paragraph 3 limits the provision’s application where the right is otherwise provided for under Union law. The GDPR applies independently wherever its own conditions are met.

In Case C-634/21, SCHUFA Holding (Scoring), ECLI:EU:C:2023:957, the Court held that the automated establishment of a probability value may itself amount to automated individual decision-making within the meaning of Article 22 GDPR where a third party draws strongly on that value when making a contractual decision. The judgment is an important warning against a purely formal argument that a human took the decision where the human was, in substance, only the last link in a predetermined automated path. Judgment in Case C-634/21

In Case C-203/22, Dun & Bradstreet Austria, ECLI:EU:C:2025:117, the Court interpreted Article 15(1)(h) GDPR as requiring the controller to provide relevant information, in a concise, transparent, intelligible and easily accessible form, explaining the procedure and principles actually applied to the personal data in order to obtain the specific result, such as a credit profile. The complexity of the system does not relieve the controller of that duty. Trade secrets are not a general ground for complete refusal either: where necessary, protected information should be placed before the competent authority or court so that the competing rights and interests can be balanced. Judgment in Case C-203/22, especially paragraphs 58, 61, 66 and 76

Those judgments interpret the GDPR, not Article 86 of the AI Act. Their findings cannot simply be transplanted into a different legal regime. They nevertheless offer a valuable indication of what an individualised and effective explanation means in EU law: not a generic account of the model, but an intelligible connection between the data used, the procedure actually applied and the specific result.

Article 86(3) also prevents the easy conclusion that an individual may always accumulate two identical rights. In each case, it will be necessary to determine whether other Union law already provides a substantively comparable right and, if so, to what extent Article 86 still fills a gap. Beyond the GDPR, a duty to give reasons or an entitlement to an explanation may also arise under administrative, consumer, employment or other sector-specific law.

An explanation must be technically possible

A legal right is useful only if it is supported by technical and organisational records. An organisation that waits until a request arrives before asking which version of a system was used, what data it received and what the human decision-maker did is unlikely to reconstruct a reliable decision path.

Article 86 is decision-centred. The record should therefore connect at least four layers:

  1. source — which data or documents entered the procedure, where they came from and which version was available;
  2. system — which system, model or rules were used, in which version and with which settings material to the decision;
  3. output — what the system actually returned in the individual case; and
  4. human decision — what the responsible person saw, what they accepted, changed or rejected, and which reasons became the reasons for the final decision.

At OpenLegalCore, we call this structured provenance and audit record a verifiability wrapper. The expression is not a term used in the AI Act. It is not a safe harbour, and its existence does not by itself prove compliance. It describes a practical way to preserve, as one coherent record, the material needed to inspect the path from source to decision.

What a verifiability wrapper should be able to answer

Reviewer’s question Record required
Which system was involved? System name, provider, model or rules version, date of execution and relevant configuration.
What did the system receive? Data, documents or references used; their provenance and time-specific version; and material missing values.
What did the system return? The particular result, class, score, recommendation or text output; where appropriate, the threshold and confidence level.
What influenced the result? Variables, rules, thresholds, retrieved sources or other factors material to that decision, presented intelligibly.
What did the human do? Who reviewed the result, what information they had, whether they accepted, corrected or rejected it, and why.
Why was the final decision taken? The actual main reasons for the decision, not merely a copy of the system output.
How can an error be corrected? A route for correcting data, obtaining a fresh human review, challenging the decision or using another available remedy.

For a conventional scoring or rules-based system, the relevant material will include the input variables, their treatment, the thresholds applied, the result and the decisive rules. For a system combining source retrieval with a generative model—for example, a retrieval-augmented generation (RAG) architecture—the record should preserve the model version, the set and versions of the retrieved sources, material settings, the generated output and the human action that followed.

This does not make a generative model’s raw internal chain of thought a legal explanation. Such material may be unstable, misleading, security-sensitive or unavailable. A meaningful explanation should instead rest on verifiable inputs, retrieved sources, applied rules, observed outputs and the genuine reasons for the human decision.

Three common shortcuts are therefore insufficient:

  • a log is not automatically an explanation — a technical event record may be unintelligible to the affected person and may not show the reasons for the final decision;
  • the system output is not the final reason — a recommendation becomes part of a decision only through the deployer’s actual procedure; and
  • a human signature is not proof of substantive review — the record must show what the person checked and whether they had a genuine opportunity to change the result.

Article 12, Article 13, Article 14 and Article 26 of the AI Act will later provide an important part of the infrastructure for record-keeping, information to deployers and human oversight for Annex III systems. Their deferred application supports the second legal interpretation of Article 86, but it is also a practical reason to prepare early. Evidence that was not captured when a decision was made cannot be recreated reliably after the event.

Evidence capture must remain proportionate. “Keep everything” is not a safe architecture. Data minimisation, defined retention periods, access control, information security, third-party rights and trade secrets all remain relevant. Good explainability and data protection are not opposing objectives, but reconciling them requires deliberate design.

What to do before a definitive answer arrives

An organisation can manage an unresolved legal question without pretending that it has been settled.

For providers and deployers

  1. Carry out an interim classification analysis. For each system, examine its intended purpose, the relevant point of Annex III and Article 6(2) and (3). Mark the result as a current legal assessment, not a definitive official classification.

  2. Distinguish the provider from the deployer. Establish who places the system on the market, who uses it and who takes the decision about the individual. Article 86 addresses the deployer, but the deployer should contractually secure sufficient information and support from the provider.

  3. Build a verifiability wrapper. Preserve versions, sources, material settings, outputs, human interventions and the principal reasons for the decision. The record should be structured well enough for review by someone who did not run the original procedure.

  4. Define a process for requests. A request for an explanation should not become stranded between legal, customer support, human resources and the technology provider. Assign an owner, a response period, an escalation path and a method for verifying the requester’s identity.

  5. Prepare an individual, not generic, explanation. Saying that “the system uses machine learning” does not explain its role in the particular case. A template should lead the reviewer to the actual inputs, the system’s influence, the human assessment and the main reasons for the decision.

  6. Check other legal bases as well. Where personal data are involved, examine Articles 13 to 15 and 22 GDPR separately. In employment, administrative decision-making, credit, insurance or judicial proceedings, assess the relevant sector-specific law too.

  7. Do not use the postponement as a reason to erase the evidential trail. Even if the interpretation ultimately prevails that Article 86 takes full effect for Annex III systems only on 2 December 2027, the same records will be needed for internal control, error correction, data protection and future obligations.

  8. Monitor defined triggers for review. These include the Commission’s final guidelines on Article 6, developments in Case C-245/25, new requests for preliminary rulings, practice from national authorities and any further amendment to the Regulation.

For affected persons

A person who suspects that an AI system influenced an important decision can frame the request in concrete terms. Useful questions include:

  • Was an AI system used in making the decision, and who used it?
  • What role did its output play in the final decision?
  • Which principal data and factors influenced the result?
  • Did a person substantively review the decision, and what were they able to change?
  • What were the main reasons for the final decision?
  • How can inaccurate data be corrected or a fresh review requested?

The request may invoke Article 86 conditionally and, where personal data and the relevant conditions are present, rely in parallel on the applicable rights under the GDPR. That approach does not guarantee success. It does, however, avoid making the request depend entirely on an unresolved question of timing.

Limits of this analysis

This article analyses general European Union law as at the cut-off date of 26 August 2026. It does not examine the specific rules of any Member State or individual fields such as employment, administrative, banking, insurance, health or procedural law. Those rules may provide an additional entitlement to reasons or an explanation in a particular case, or establish a relevant exception or restriction.

The unresolved issue is not hidden in a footnote. On the current text, it cannot be determined with sufficient certainty whether Article 6(2) and (3) may be applied incidentally before 2 December 2027 to define the scope of Article 86. Until final guidance, a judicial ruling or further legislative clarification arrives, categorical claims in either direction should be treated with caution.

This analysis should be reviewed in particular:

  • when the Commission publishes its final guidelines on Article 6;
  • when a ruling on the merits is delivered in Case C-245/25 or another relevant case;
  • if Article 86, Article 113 or Annex III is amended again; and
  • in any event before 2 December 2027.

Conclusion

The AI Act placed the right to explanation in one part of the Regulation and, after the amended timetable, moved the classification key on which it depends to a later date. Article 86 was not expressly deferred and, on the wording of Article 113, falls within the general date of application of 2 August 2026. Whether it can already operate for systems whose high-risk status depends on the deferred Article 6(2) remains an open legal question.

That is not a reason to manufacture certainty, and it is not a reason to wait. An affected person has a reasonable argument for requesting an explanation. A deployer has a reasonable counterargument based on the deferred classification. An organisation seeking to act responsibly does not need a judgment before it preserves the origin of the data, the version of the system used, its output, the human review and the real reasons for the decision.

When the legal answer comes, it may tell us when Article 86 required an explanation to be given. It will not be able to recreate evidence that the system failed to preserve when the decision was made.

Key primary and official sources

The consolidated text on EUR-Lex is a documentation tool. The changes to the timetable were therefore also checked against the original text of Regulation (EU) 2026/1744 as published in the Official Journal of the European Union.

Date of last legal, technical and source review: 26 August 2026.

Publication record

Research verified 26 August 2026Legal cut-off 26 August 2026