Right to explanation, defined: what an automated claims decision has to be able to say for itself
The right to explanation is the entitlement of a person subject to an automated decision to be told how that decision was reached, in language clear enough that they can contest it. In European law it is built from GDPR Articles 13 to 15 and Article 22, together with Article 86 of the AI Act.
For a counter-fraud team the practical version is narrower and more useful: if a model, a score, or a rules engine contributed to declining, delaying, or referring a claim, the claimant may be able to demand an account of that contribution.
What does the right to explanation actually require?
Article 15(1)(h) of the GDPR gives a data subject access to "meaningful information about the logic involved" in automated decision-making, plus its significance and envisaged consequences. Article 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects, and where such a decision is allowed, Article 22(3) requires safeguards including the ability to contest it.
Read together, those provisions demand something a person can act on. Not the source code, not the model weights. An account of the procedure, the inputs that mattered, and what would have had to be different.
- Logic, not algorithm: "logic involved" has consistently been read as the decision procedure in plain terms, not a mathematical disclosure.
- Enough to challenge: the test that matters is whether the person can identify what to dispute.
- Solely automated is the trigger: Article 22 bites when there is no meaningful human involvement. A rubber-stamp review does not count.
- Trade secrets do not end the conversation: they can shape how much is disclosed and to whom, but they are not a blanket exemption.
Why lawyers still argue about whether it exists
The phrase "right to explanation" does not appear in the binding text of the GDPR. It appears in Recital 71, which is guidance rather than law.
In 2017 Sandra Wachter, Brent Mittelstadt and Luciano Floridi published a paper in International Data Privacy Law titled "Why a Right to Explanation of Automated Decision-Making Does Not Exist in the General Data Protection Regulation". Their argument was that the GDPR creates a right to be informed about system logic in general, which is weaker and more forward-looking than a right to an explanation of one specific decision after it has been made.
Other scholars read the same articles the other way. That disagreement ran for years, and it is why confident statements about what the law obliges you to hand over are worth avoiding.
What the Court of Justice added in 2025
On 27 February 2025 the Court of Justice of the European Union ruled in Case C-203/22, Dun & Bradstreet Austria, on a credit assessment that had blocked a mobile phone contract. The Court held that "meaningful information about the logic involved" means explaining the procedure and principles actually applied, in a way that lets the data subject see which personal data were used and how, so they can effectively contest the decision under Article 22(3).
It also held that a mere reference to a complex algorithm does not satisfy the obligation, and that a claimed trade secret must be assessed by a supervisory authority or a court rather than decided unilaterally by the controller. The judgment narrowed the gap between the two readings without closing it.
Where the EU AI Act changes the picture
Article 86 of the EU AI Act, which applies from 2 August 2026, gives any affected person subject to a decision taken by a deployer on the basis of a high-risk AI system listed in Annex III the right to obtain clear and meaningful explanations of the role of the AI system in the decision procedure and the main elements of the decision taken. It applies where the decision produces legal effects or significantly affects health, safety or fundamental rights, and only to the extent the right is not already provided elsewhere in Union law.
Insurance pricing and risk assessment for life and health cover sit inside Annex III. Whether a particular fraud-triage model falls in scope is a question of classification, not a foregone conclusion, and it is worth settling with your own counsel rather than assuming either way.
Right to explanation in practice: a fraud referral
A motor claim is scored by a triage model, flagged, and routed to the counter-fraud team. Six weeks later the claimant's solicitor asks why the claim was singled out.
An answer that holds up names the factors: the claim was flagged because the reported incident date and the policy inception date fell within a defined window, and because supplied images showed indicators of prior editing. An answer that does not hold up is "our system identified elevated risk". The first tells the claimant what to dispute. The second tells them to complain to a regulator.
What this means for a counter-fraud file
- Record the reason at the moment of the referral: reconstructed rationales six weeks later are weaker and easier to attack.
- Keep a human genuinely in the loop: a reviewer with the authority and information to overturn the flag keeps you outside the hardest part of Article 22.
- Separate signal from verdict: an integrity signal on an image is a reason to look. It is not a finding of fraud, and describing it as one in a decision letter creates an avoidable problem.
- Keep the evidence checkable: an explanation is only as good as the material behind it. See evidence integrity and chain of custody.
The pressure here rises alongside automation. As more triage runs through models, more of what an SIU does becomes explainable in principle and awkward in practice, particularly where the flag came from a classifier reacting to synthetic media. The counter-fraud teams handling this well are the ones already writing referral reasons in sentences a claimant could read.