
On the accountability rights that assume a decision record exists, and what organizations produce when asked for one they never kept.
Regulators have built rights that assume a decision record exists. Most organizations cannot produce one - so they produce a story instead, assembled after the outcome was already known.
What follows completes a practitioner hypothesis begun in Essay I: stated with enough precision to be falsified, and intended to be.
Essay I argued that no enterprise system holds a decision record natively.1 Essay II argued that records readable only through a vendor's runtime are rentals rather than assets.2 This essay examines what both failures cost at the point of accountability. GDPR Article 22 grants a right to contest an automated decision.3 The EU AI Act adds an explicit right to an explanation of decisions made using high-risk systems.4 Both presuppose that something exists to contest or explain. Where it does not, the obligation survives anyway: courts have held that data held by a third party remains the responding party's to produce.7 Reconstruction fills the gap, and reconstruction after a known outcome is a documented cognitive failure mode.9 The essay argues that missing decision provenance surfaces as confident, coherent, unfalsifiable narrative, and closes with falsifiable conditions.
Keywords: decision provenance, algorithmic accountability, GDPR Article 22, EU AI Act, right to explanation, e-discovery, hindsight bias, contestability
Return to the supplier switch from Essay I. A procurement team, mid-disruption, moves a primary supplier. Three alternatives evaluated. Risk scores available at the time. An executive who approved the deviation from preferred-vendor policy. A judgment that weighted speed of supply restoration over unit cost.
Now move forward three years. The disruption is long resolved. The platform that held the workflow has been replaced once. And a question arrives, from a regulator, a plaintiff's counsel, an internal auditor, or the supplier that was dropped: why was this decision made, and on what basis?
The organization can produce the transaction. Supplier changed, timestamp, user ID. It cannot produce the judgment, because the judgment was never a record. It was an interpreted object inside a runtime that no longer runs, or a schema that did not survive the migration, or a Slack thread in a workspace that was archived when the team reorganized.
Nobody stonewalls. The organization wants to answer and has nothing to answer with, which looks identical from the outside to an organization that will not.
GDPR Article 22
Article 22 of the GDPR establishes that a person subject to a decision based solely on automated processing, where that decision produces legal or similarly significant effects, has the right to obtain human intervention, to express their point of view, and to contest the decision.3
Whether Article 22 also creates a binding right to an explanation is disputed in the literature. Wachter, Mittelstadt and Floridi argue the operative articles support a narrower right to information about system logic rather than a right to explanation of a specific decision.5 Others read Articles 13 to 15 together with 22(3) as establishing something stronger.6 This essay does not need that dispute resolved, because the contestation right in 22(3) is not in dispute, and contestation is the harder requirement.
A person cannot meaningfully contest a decision whose basis cannot be stated. Neither can the organization meaningfully reconsider it. The right survives on paper and evaporates in practice, with nobody having denied anything.
The EU AI Act goes further
Article 86 of the EU AI Act creates an explicit and enforceable individual right: a person subject to a decision taken on the basis of a high-risk AI system, where that decision significantly affects their health, safety, or fundamental rights, may obtain from the deployer clear and meaningful explanations of the role the system played and the main elements of the decision taken.4
Two features of Article 86 matter here. The duty sits on the deployer, the organization that used the output to make the call, not on the provider that built the model. And it reaches decisions made on the basis of AI output even where a human remained in the loop, which is a wider net than Article 22's solely-automated threshold.4
The hard part of compliance is reconstruction: establishing after the fact which model version, which inputs, and which thresholds were actually in play at the moment of decision. An organization that cannot retrieve that state cannot produce a compliant explanation, however willing it is to try.
The date moved. Article 86 was set to apply from 2 August 2026 under the Act's original phased timeline. The Digital Omnibus on AI, endorsed by the European Parliament on 16 June 2026 and given final approval by the Council on 29 June 2026, defers the Annex III high-risk obligations to 2 December 2027.14 Sixteen additional months to build the capability, on a clock that started when the Act entered into force in 2024. Nothing about the deferral changes what the obligation will require. GDPR Article 22 applies now regardless.3
Both rights assume a record exists. Neither creates one.
The natural reply is that the record lives in the vendor's system, so the vendor should answer for it. Courts have already declined that argument in the adjacent context of civil discovery.
Under the US Federal Rules, a party must produce responsive material within its possession, custody, or control, and control has long been read to reach documents a party has the practical ability to obtain, including material physically held by someone else.7 The duty to preserve attaches when litigation is reasonably anticipated, not when a complaint is filed.
Courts have been unsympathetic to arguments that the location of data puts it beyond reach. In AccessData Corp. v. ALSTE Technologies GmbH, a Utah federal court compelled a German defendant to produce customer information over its objection that the German Federal Data Protection Act and the German Constitution forbade disclosure, and declined to route the request through the Hague Convention.8 A foreign blocking statute did not extinguish the obligation. It is a narrower holding than the argument this essay is making, and it points the same direction: the responding party owns the problem.
Apply that to a decision record legible only inside a vendor's runtime. The organization is still the responding party. It still owes an answer. The obligation survives intact and the capacity to meet it does not, which is a materially worse position than either refusing or complying.
That is Essay II's argument arriving in a courtroom. A rented corpus fails at the exact moment its absence is most expensive, and the cost lands on the tenant, not the landlord.
Ask an organization to explain a decision it cannot reconstruct and you will not get a blank page. You will get an explanation. Someone assembles one, in good faith, from what remains: the outcome, the surviving transaction, the recollections of whoever is still on the team.
That process has a name and a literature going back to 1975. Hindsight bias is the systematic distortion of what a person believes was known or knowable before an outcome, once the outcome is known.916 It is distinct from outcome bias, which is judging the quality of a decision by how it turned out rather than by the information available when it was made.10 Both are relevant here and they are not the same failure.
Safety-critical fields have already measured this. A study of clinicians reviewing a case vignette found that participants shown an adverse outcome retrospectively emphasized risk factors they had passed over when the same vignette was presented without an ending, and participants shown no adverse outcome judged the identical management plan far more favorably.15 Same facts, different endings, different accounts of what the reasoning had been. Incident-review practitioners name the mechanism plainly: post-incident reviews conducted late tend to become reconstructions rather than descriptions, with responders rationalizing decisions with the benefit of hindsight instead of capturing the uncertainty they were actually working with.11
Roese and Vohs, reviewing the field, find that hindsight bias operates partly through memory distortion, and that prompting people to consider alternative explanations for an outcome measurably reduces it.12 Both findings point the same way. The corrective has to reach the reasoning before the outcome does, which is the case Essay I made for structured decision capture, arrived at independently from the psychology side.
A lie would be easier. A lie has an author who knows better. This is coherent, offered honestly, consistent with every piece of evidence that survived, and unfalsifiable, because the record that could contradict it no longer exists.
Accountability does not fail as a blank page. It fails as a plausible story.
| Written before the outcome | Written after the outcome |
|---|---|
| Contemporaneous record | Reconstruction |
| Decision made | Outcome becomes known |
| Reasoning captured while still uncertain | Account demanded |
| Stops once written | Gains confidence as it is assembled |
Figure 1. A contemporaneous record is written once, before the outcome is known, and then stops. A reconstruction begins only after the outcome is known, and gains confidence as it is assembled. Both are offered in good faith. Only one was written before anyone knew how it turned out.
Compare that to the training cost in Essay II. A recency-skewed corpus produces a measurably worse model, and measurement will eventually catch it. A reconstructed decision narrative satisfies the questioner, closes the inquiry, and teaches the organization a lesson about its own judgment that nothing in the record can correct.
The abstraction has claimants already. In March 2025 the ACLU of Colorado filed complaints on behalf of a deaf, Indigenous applicant screened by an AI video interview system who, the complaint alleges, was denied the captioning accommodation she requested.13 Discrimination is the legal claim. Underneath it sits an evidentiary question that any such case has to answer: what did the system weigh, and who can produce it now?
That question arrives with a structural asymmetry. The affected person carries the burden of showing what the system did. The deploying organization frequently cannot show it either. The vendor holds the model, the deployer holds the obligation, and the record that would settle it was never written in a form either party can hand over.
Regulators have signalled they will not accept the black box as an answer, and the deployer remains the interlocutor of the affected person even when the model came from a third party.4 That is the same allocation of responsibility the discovery rules already make.
Three essays, one claim, at three different points of failure.
Essay I: enterprise systems record what happened and not why, so the reasoning behind consequential decisions is never captured as a structured record.1
Essay II: where something is captured, it is frequently legible only inside a vendor's runtime, which makes it a rental rather than an asset, and rentals decay from the past forward.2
Essay III: both failures come due at the moment an organization is asked to account for a decision, and the answer it produces then is assembled after the fact.
Carelessness is not the through-line. No one ever named the decision as the unit worth preserving, so nothing in the stack was built to hold one, and every downstream use that assumed otherwise inherits the same absence: training, audit, contestation, explanation.
[F1] Show an organization that satisfied a GDPR Article 22 contestation or an AI Act Article 86 explanation request using only records that required a vendor's runtime to interpret, without independent portable documentation, and the claim that rented provenance fails accountability weakens.
[F2] Show that decision narratives reconstructed after an outcome is known are empirically comparable in accuracy to contemporaneously captured decision records, and the reconstruction argument in Section 4 fails.
[F3] Show a case in which discovery or regulatory production obligations were excused specifically because the relevant records were locked inside a third-party runtime, and the custody argument in Section 3 fails.
[F4] Audit a sample of regulatory or litigation responses in which the responding organization lacked contemporaneous decision records, and show that the responses were predominantly declarations of inability rather than substantive accounts of reasoning, and the central claim of this essay fails.
If any of these can be demonstrated, this essay requires revision. That is not a hedge. It is the standard the series set.
Essay I closed by asking whether you could reconstruct the reasoning behind your last consequential decision. Essay III closes by asking a harder version.
If someone asked you to account for that decision tomorrow, in front of a regulator or a court, you would produce something. Organizations almost always do.
How would you know whether what you produced was the record, or the reconstruction?
If you cannot tell the difference, neither can anyone assessing you. An organization that cannot separate its retrieved reasoning from its reconstructed reasoning has stopped learning from its decisions and started learning from the story it tells about them afterward, which is worse for being indistinguishable from the real thing.
Jack Roche is a Strategic Partnerships leader and the founder of Roche on Strategy (rocheonstrategy.com), a journal on governance, systems, and the architecture of decisions. This essay is published under CC BY 4.0. Citation, adaptation, and distribution are permitted with attribution.
Roche on Strategy | rocheonstrategy.com | CC BY 4.0 | v1.0, August 2026 | Essay III of III