Trusq

factual analysis · traceable to primary sources

Explainer

Right to explanation of an AI decision: what Article 86 of the AI Act gives you

Adopted 2026-06-23 · ≈ 3 min read · Dirk Baaijen

If you are affected by a decision based (in part) on a high-risk AI system, Article 86 of the AI Act gives you the right to a clear explanation of the AI system's role and the main elements of the decision — from the deployer, on top of your GDPR rights.

Short answer: If an organisation takes a decision about you based (in part) on the output of a high-risk AI system listed in Annex III, and that decision has legal effects or similarly significantly affects you, Article 86 of the AI Act gives you the right to a clear and meaningful explanation: what role did the AI system play, and what were the main elements of the decision? You direct that right to the deployer, and it comes on top of your GDPR rights.

Who and when

The right applies to an affected person — the individual the decision is about. Three conditions together:

  • the decision is taken by the deployer on the basis of the output of a high-risk AI system listed in Annex III (except the systems under point 2 of Annex III, critical infrastructure);
  • the decision produces legal effects or affects the person in a similarly significant way;
  • the person considers that this adversely affects their health, safety or fundamental rights.

Think of a rejected credit application, a refused insurance policy, a selection decision in recruitment, or the allocation of an essential service — in so far as a high-risk system was used.

What the explanation must contain

Not the full source code or model weights, but understandable information: the role of the AI system in the decision-making procedure and the main elements of the decision taken. The benchmark is intelligibility for a layperson, not technical completeness. "The computer said no" does not suffice; the organisation must be able to explain how the output shaped the decision.

Relationship to the GDPR

Article 86 applies "only to the extent that this right is not otherwise provided for under Union law" — it complements, it does not replace. GDPR Article 22 in principle prohibits a solely automated decision with significant effect and grants the right to human intervention and to make your view known. Article 86 of the AI Act is narrower in trigger (specifically high-risk Annex III), but explicit about the explanation itself. In practice they stack: a high-risk decision often engages both regimes at once — see also algorithmic decision-making in government.

Exceptions

The right is not absolute. Paragraph 2 provides that it does not apply where exceptions or restrictions follow from Union or national law (in compliance with Union law) — think of situations involving fraud detection, law enforcement or national security. And paragraph 3 makes it subsidiary: where an equivalent right to explanation already exists under other Union law, that applies. It is a floor, not an addition on top of existing rights.

What it requires of provider and deployer alike

The deployer can only explain what it understands. That depends on two other obligations: the provider must make clear, via the instructions for use (Art. 13), how the system works and is to be interpreted, and the system must keep logs (Art. 12) so that decisions are reconstructable. Without that basis, a meaningful explanation after the fact is impossible. So build the explanation process in before deployment, not when the first complaint arrives.

From when

Article 86 enters into application on 2 August 2026 (the general application date of the AI Act). Its practical effect runs in step with the high-risk obligations of Annex III — see the AI Act timeline of obligations for the exact phased dates.

What to do

  • Map which decisions you base (in part) on high-risk Annex III systems, and who the affected persons are.
  • Set up an explanation process: who provides the explanation on request, within what time, in plain language?
  • Secure the basis from the provider: instructions for use (Art. 13) and logging (Art. 12) that make after-the-fact explanation possible.
  • Align with your GDPR process: combine the Art. 86 request with the rights under GDPR Art. 22 and the information duties.
  • Document the main elements of every relevant decision, so the explanation is reproducible and holds up under a complaint or review.

Article 86 makes explanation a right of the citizen, not a favour from the organisation. Whoever has their logging and instructions for use in order can comply; whoever defers it until the first request is left empty-handed.

Sources

  1. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
    Regulation (EU) 2024/1689 (AI Act): Article 86 on the right to explanation of individual decision-making.
  2. https://eur-lex.europa.eu/eli/reg/2016/679/oj
    Regulation (EU) 2016/679 (GDPR): Article 22 on automated individual decision-making.

Share on LinkedIn

Read next

W

Instructions for use and transparency to the deployer: Article 13

Article 13 requires high-risk AI to be transparent enough and to come with instructions that let the deployer understand and use the system correctly. Those instructions must cover purpose, performance, limits and oversight measures. This guide explains what belongs in them.

W

Registering high-risk systems in the EU database (Article 49)

Article 49 of the AI Act requires providers and certain deployers to register high-risk systems in a public EU database before deployment. The registration makes visible which systems are on the market and is a condition for lawful use.

A

AI for strategic workforce planning: usually not high-risk, as long as it does not become individual

AI for strategic workforce planning and skills forecasting at organisation level is usually not high-risk under the AI Act. But once it steers individual decisions, it can tip over. Data quality, governance and transparency remain crucial.

Dirk Baaijen

About this knowledge base

Compiled and maintained by YRproject — programme and project direction at the intersection of digital transformation, AI and regulation. Every factual claim is traceable to its primary source. YRproject is led by Dirk Baaijen About & method →

A project or programme? Work with YRproject →

The monthly briefing

AI regulation in five minutes: what changed, what is coming and what it means. No spam, unsubscribe anytime.

Your address is used for this only and stored on our own servers.