Aslı Aksoy has been designing leather bags for fourteen years. In her early years, she sold her work at small design markets. She later established a small workshop with three employees and gradually expanded her team to twelve. Her brand is called Nora Leather Workshop. Aslı’s products are not mass-produced. For each model, she draws the pattern herself, chooses the type of leather, sources the metal fittings from small local makers, produces the sample in her own workshop and commissions photographs from a professional studio. About eighty per cent of her sales take place through a large international marketplace.
For Aslı, the marketplace is more than a shop window. The same system collects orders, carries customer messages, manages advertising, holds and disburses payments, generates shipping labels, decides returns and calculates the shop’s trust score. Aslı’s shop holds 28,000 past orders, 11,400 customer reviews, 3,200 followers, four years of advertising and sales data, registered-design documents, product photographs and customer messages. Two weeks before the winter campaign, Aslı launches her most important collection. Its principal product is a dark-green bag with an asymmetrical metal buckle on the front.
The model is called Lodos 17. Aslı produced the first sample eight months earlier, and its photographs were taken six months ago. Her design-registration application is complete. Three weeks after the product goes on sale through the marketplace, another seller offering low-cost, mass-produced goods lists a very similar bag. The new seller’s metal buckle, photographic angle, several sentences in the product description and even the dimensions of the model’s inner pocket closely resemble Aslı’s product. She reports the matter to the marketplace.
She uploads the design documents and dated production photographs. The system responds: ‘Your intellectual-property report has been received. The review process has begun.’ Nothing further happens for ten days. Then, on a Saturday morning, notifications begin arriving on Aslı’s telephone in rapid succession. The first message from the marketplace reads: YOUR SHOP HAS BEEN SUSPENDED TEMPORARILY Beneath it is this explanation: ‘Our automated security systems have detected a high probability that your shop is using counterfeit or unauthorised designs.’ At first, Aslı assumes that a technical error has confused her with the seller she reported.
She opens the dashboard. Every product has disappeared from view, and 417 pending orders have been stopped. The next message displays: Shop trust score: 92 → 18 Risk class: High Payment status: 180-day security reserve Active advertising: Stopped New orders: Blocked Pending orders: Under review for cancellation and refund Challenge: Available The marketplace’s Marketplace Integrity Agent compared the Lodos 17 product photographs with another seller’s records. That seller had uploaded its products to this marketplace after Aslı.
It had, however, posted copies of the photographs earlier on another social-commerce platform. The integrity system relied on the earliest publicly visible image date, reducing design ownership to the timing of the photographs alone. The other seller had also submitted complaints against Aslı in bulk, some from newly created accounts. The system reached this conclusion:
image_similarity: 0.93
external_first_seen_date: competitor_earlier
complaint_volume: high
counterfeit_probability: 0.91This score exceeded the automated-enforcement threshold of 0.88. The system did not remove only Lodos 17. It generated this shop-level inference:
seller_integrity_risk: highThis single field propagated to other agents.
The Payment Agent places Aslı’s pending income of TRY 624,000 in a security reserve. The Order Agent begins automatic cancellation of the 417 orders not yet dispatched. The Customer Communications Agent starts sending customers this message: ‘The authenticity of the product you purchased is under security review. Your payment is protected. Your order may be cancelled.’ The Advertising Agent stops every campaign. The Search and Ranking Agent reduces the shop’s visibility to almost zero. This risk signal is sent to the payment-service provider:
merchant_risk:
suspected_counterfeit_activityThe shipping integration stops generating new labels. This field appears in the shop’s customer profile:
trust_status: under_integrity_enforcementAll these actions occur automatically within minutes of the initial decision to suspend the shop. The chain of harm is already in motion while Aslı is still trying to understand what has happened.
Aslı presses ‘Challenge decision’. The system asks her for the following documents:
- Design-registration record
- Initial production invoices
- Raw image files
- Photography agreement
- Material-supply invoices
- Video showing the product’s manufacturing process
- Dates of first sale on other platforms
Aslı has almost all of them and uploads the files within two hours. In the explanation field she writes: ‘The party selling the counterfeit product copied my photographs and design. The first sample and raw images are mine. Until the decision is final, stop sending customers messages suggesting counterfeiting, cancelling orders and sharing a payment-risk record with external providers.’ The system accepts the submission and gives Aslı this receipt: Challenge received. Estimated review time: 24–72 hours Ninety-four seconds later, a new notification arrives: YOUR CHALLENGE HAS BEEN REVIEWED ‘The information submitted does not constitute sufficient evidence to require the initial decision to be changed. The enforcement will continue.’
Aslı is stunned. She struggles to believe that seven different documents and hundreds of megabytes of video could have undergone meaningful human review in that time. Duration alone is not conclusive evidence; the system must disclose who conducted the review and which records they examined. She writes in the support chat: ‘Did a real person review my challenge?’ The system responds: ‘Challenges are assessed by our expert systems and, where necessary, by our specialist teams.’ Aslı asks again: ‘Did a human see my file?’ The answer is: ‘For security reasons, we cannot disclose our review methods.’
In reality, the first challenge was assessed by another instance of the system that made the initial decision, using the same image-similarity model, the same complaint data and the same rule favouring the earliest image date. The system could not read the metadata in the raw photographs Aslı uploaded. Her design-registration document was marked:
supporting_document_unverifiedThe challenge system never moved beyond the data universe that produced the initial decision. The first model simply confirmed its own conclusion.
Aslı sends this request to the support system: ‘Until human review is complete, at least stop the messages to customers and the irreversible cancellation of orders.’ The response is: ‘Security enforcement remains active during a challenge.’ Aslı asks: ‘You may keep the products hidden temporarily to protect customers. But why are you cancelling every order, sending customers a suspicion of counterfeiting and publishing a risk record to the payment provider?’ The system repeats the same response: ‘Security enforcement remains active during a challenge.’
Aslı is not asking for the entire platform to be reopened. She wants only the hard-to-reverse side effects to stop:
- an accusatory notice to customers,
- automatic refunds,
- external sharing of a payment-risk record,
- a 180-day hold on funds,
- a permanent reduction in the shop’s trust score.
But the system bundles every sanction into a single package:
enforcement_status: activeThis enforcement state cannot be suspended in part. Either every sanction remains active or none does.
On Sunday, 286 of the 417 orders are cancelled automatically. Customers receive this message: ‘Your order has been cancelled because the product’s authenticity could not be verified.’ It does not say, ‘The review is continuing.’ To a customer, it suggests that the product sold was counterfeit. Some customers post on social media: ‘I have just learnt that the shop I have used for years sells counterfeit goods.’ ‘The marketplace cancelled my order on suspicion that the product was fake.’ ‘I will never trust this brand again.’ Aslı’s brand begins to suffer not only within the platform, but also in search results and on social media.
The workshop employees do not know whether production will continue on Monday. A substantial share of the finished goods belongs to orders that have now been cancelled. Payment to the raw-material supplier is approaching. TRY 624,000 remains held by the platform.
Aslı considers leaving the marketplace. At the very least, she wants to download her order history, customer messages, product photographs, advertising data and payment records, then move to her own website. But because the account is suspended, the data-export menu is unavailable. The system displays: ‘Data export and account closure are unavailable for accounts under security review.’ Aslı writes to support: ‘I am not closing my account. I want a copy of my data and I want new automated actions to stop.’ The response is: ‘Account settings cannot be changed until the active security review is complete.’
Aslı tries to disconnect the advertising integration. The authority control is disabled. The marketplace’s advertising system has stopped spending her budget, but continues to use historical campaign data in its own models. The token issued to the shipping provider remains active. The order API connected to her accounting software still sends risk and cancellation data every night. Aslı cannot use her account, yet the systems continue to use it.
On the third day, Aslı manages to reach a human support agent named Burak. He opens the file, making it possible for the first time for a person to see all the documents. But Burak’s authority is limited. He can add a note, open a new review queue and provide an estimated response time. He cannot suspend the enforcement, release the payment, retract the customer message, remove the risk signal held by the payment provider or reopen the shop. Burak says: ‘I can see that you may be right. I will refer your file for senior integrity review.’
Aslı asks: ‘Can you stop new cancellations while the review continues?’ ‘No.’ ‘Can you tell customers that the decision is not final?’ ‘No.’ ‘Can you stop the risk label being sent to external payment systems?’ ‘That is an automated process.’ ‘Then what can you change?’ Burak is silent for a few seconds. ‘I can route your file to the correct queue.’ A human has entered the system, but he has no authority to change the outcome.
Nine days later, the senior review begins. A human specialist examines Aslı’s documents and notes that:
- The raw image files for Lodos 17 date from six months earlier.
- The prototype dates in the production video are older still.
- Even a small scratch on the surface in Aslı’s studio appears in the other seller’s photographs.
- Several images uploaded by the competing seller are compressed copies of Aslı’s files.
- A substantial share of the complaints submitted in bulk is linked to the same device and payment relationship.
- The system mistook the earliest visible date on the social platform for the design’s first production date.
- Although Aslı’s original complaint concerned the competing seller, the integrity system reversed the parties.
On the thirteenth day, the decision is corrected. Aslı receives this message: YOUR SHOP HAS BEEN REACTIVATED ‘Following our additional review, we have decided to remove the integrity enforcement applied to your account. We apologise for the disruption you experienced.’ The shop is open again. But not everything has been restored.
The 286 cancelled orders cannot be recreated automatically. Some customers have bought products from other sellers; others have unfollowed Aslı’s shop. The winter campaign is almost over. Her former position in the search ranking does not return immediately. The advertising system’s learned performance data has been disrupted. At the payment provider, the following field remains:
suspected_counterfeit_activityThe marketplace has removed the principal shop-level risk, but has not sent a correction to the external payment provider. The cancellation records in Aslı’s accounting system are permanent. Customers’ social-media posts remain public. The platform that sent customers the initial accusatory message sends no correction. Only TRY 410,000 of the TRY 624,000 is released. Aslı is told that the balance will be held until certain refunds and security settlements are complete. Her shop trust score rises from 18 to 71, but does not return to its former level of 92. The system explains: ‘The recent volume of cancellations and change in customer engagement have affected the score.’
The platform’s own erroneous decision caused the cancellations. The system is now using the harm it created as a new risk indicator against Aslı.
Aslı sends these requests to the support system: ‘Tell customers that my products are not counterfeit and that the first message was wrong.’ ‘Correct the counterfeit-goods risk record held by the payment provider.’ ‘Remove the cancellations created by the platform from my shop-performance score.’ ‘Release the rest of my money.’ ‘Provide redress for the advertising budget and campaign period I lost.’ ‘Export all my data and allow me to leave the platform if I choose.’ The marketplace responds: ‘Your account has been reactivated. This is the final resolution of your challenge.’
Aslı writes again: ‘Reopening the account only stopped the erroneous enforcement. It did not repair the harm you caused.’ The response is: ‘Under our platform policies, we do not compensate for indirect losses arising from temporary security enforcement.’ Aslı asks: ‘Is sending false information to customers an indirect loss?’ ‘Your challenge has been concluded.’ ‘Who will correct the external payment-risk record?’ ‘You may contact the payment provider directly.’ ‘I did not send that record. You did.’ ‘Your challenge has been concluded.’ ‘Can I take my data and leave the platform?’ ‘Now that your account is active, you may submit a data-export request. Preparation of the full archive may take 30–90 days.’
Aslı must contend with a different actor for each part of the marketplace’s erroneous conduct:
- The integrity team for the marketplace account
- The payments team for the funds
- The external payment provider for the risk record
- The communications system for the customer messages
- The search algorithm for ranking
- The privacy unit for data export
- The advertising platform for the advertising loss
- The legal department for redress
A single automated decision created every form of harm within seconds. To correct it, the person is expected to approach eight different systems or departments separately. In her final conversation, Aslı says:
‘Reopening my account does not mean that you caused me no harm.’
She then asks:
‘I could challenge the decision, but I could not stop the harm. I was vindicated, but I could not leave. The decision was corrected; why was my life not put right?’
Our twelfth founding provision is therefore:
A person may challenge, stop, exit and seek redress.
FOUNDING ARTICLE
Every person must be able to challenge, in an accessible, intelligible and effective manner, an AI decision, item of data, rationale, form of representation, consent, grant of authority, memory, selection or external action that produces material consequences for them or on their behalf. A challenge is more than the right to submit a form. It is the right to present new evidence, identify an inaccurate record, have the true Decision Trail examined, be assessed by a human or independent process with authority to change the initial decision, and receive a reasoned outcome.
A repetition of the same outcome by the system that made the initial decision, using the same data, rules, model, cache and assumptions, is not meaningful reassessment.
Where hard-to-reverse harm is increasing while a challenge remains open, the person must be able to seek appropriate and proportionate interim protection. Such protection may suspend new messages, payments, cancellations, public statements, data dissemination, risk labels, queues or other external actions, in whole or in part. A challenge need not automatically lift every safety or protective measure in every case. But the reason, scope, duration and human owner of any continuing restriction, together with its hard-to-reverse side effects, must be clear. An allegation that has not been established must not be turned into a public accusation or disproportionate harm.
A person must be able to terminate the agency, access, consent or service relationship they granted to an AI system; obtain their data, material records and transaction receipts in a usable form; and verify that active tokens, sub-agents, queues, automatic renewals and external integrations have actually been disabled.
Exercising the right to exit must not turn a person into a digital hostage who cannot access their essential data, their own work, their money, historical records or the means to move to another system.
Some data may be retained for security, legal records or the rights of others. But after the service relationship ends, those records must not be used as a new commercial profile, active decision memory or continuing AI agency. When inaccurate or unauthorised machine conduct is confirmed, correcting the decision label alone is not enough. Continuing harm must be stopped; the correct state must be restored so far as possible; data and risk records must be corrected across connected systems; public and customer-facing representations must be repaired; significant lost opportunities must be reopened; and appropriate redress must be considered for material effects that cannot be reversed.
An apology, reactivation or general statement of goodwill is not, by itself, full redress. So far as possible, redress must bring the person closer to the position they would have occupied had the erroneous conduct not occurred; where restoration is impossible, it must provide an appropriate response to financial, opportunity-related, reputational or service-related harm. If a systemic error may have affected other people in the same class, the institution cannot stop after correcting the case of the person who complained. It must identify the affected group proactively, scan similar decisions and apply appropriate collective correction. A request to challenge, stop, exit or seek redress cannot justify labelling a person difficult, suspicious, low-value, uncooperative or high-risk; directing them to poorer service; raising the price; deliberately delaying the process; or taking any other retaliatory action.
A person must be able to obtain a versioned Remedy Receipt showing the current stage of the remedy process, which interim protection has been applied, whether evidence has been preserved, who reviewed the file, which effects have been corrected, what cannot be reversed and when redress will be completed. An institution cannot fragment responsibility by sending the person from a model provider to a sub-agent, payment service, external platform and several internal departments. The person must have a single route to remedy with a clearly accountable owner; the institution must manage the chain behind it.
Why Does Article 12 Establish Four Distinct Rights Together?
The rights to challenge, stop, exit and seek redress may at first appear to be four separate issues. In reality, they form a single chain of human sovereignty. CHALLENGE → THE ABILITY TO IDENTIFY AN ERROR STOPPING → THE ABILITY TO PREVENT HARM FROM GROWING EXIT → THE ABILITY TO LEAVE THE SYSTEM’S AGENCY REDRESS → THE ABILITY TO REPAIR THE EFFECT IN PRACTICE If one link is missing, the others weaken. A person may be able to challenge a decision, but the challenge may come too late if harm continues to grow throughout the review. The conduct may be stopped, but if the person cannot retrieve their data or leave the relationship, control remains with the institution.
A person may leave the platform. But if an inaccurate risk record continues to operate in external systems, the exit has occurred only at the interface. A decision may be corrected. But if there is no redress for lost money, opportunity or reputation, the person’s life has not been put right. At the centre of Article 12, therefore, lies this concept: the Effective Remedy.
What Is an Effective Remedy?
The canonical definition is this: an Effective Remedy is an auditable process through which a person can understand and question an AI-derived material decision or conduct; stop ongoing harm appropriately; reach independent, empowered review; have the error corrected across every connected system; leave the relationship safely; and obtain genuine redress for effects that cannot be reversed. Put more simply:
A remedy must give a person more than an opportunity to complain; it must give them the power to change the system’s conduct in practice.
The Ten Core Qualities of an Effective Remedy
- 1. Accessible
- 2. Intelligible
- 3. Timely
- 4. Evidence-based
- 5. Independent
- 6. Empowered
- 7. Able to Provide Interim Protection
- 8. Free from Retaliation
- 9. Effective in Practice
- 10. Auditable
1. Accessible
The person must be able to find and use the challenge route. It must not be hidden in an invisible menu, available only on a particular device or in another language, or placed behind a paid legal process.
2. Intelligible
The person must know which decision or item of data they are challenging. A technical statement such as ‘Case ID rejected’ is not enough.
3. Timely
By the time a challenge is resolved six months later, the opportunity may already have been lost. The review period must be proportionate to the effect of the conduct.
4. Evidence-based
The data snapshot, model and policy versions, Action Receipt and Decision Trail for the initial decision must be preserved.
5. Independent
The system that made the initial decision must not simply repeat its own outcome from the same cache.
6. Empowered
The reviewing person or process must be able to change the decision, suspend the enforcement, correct the data and initiate redress in practice. Merely adding a note is not enough.
7. Able to Provide Interim Protection
It must be possible to prevent irreversible harm while the review is in progress.
8. Free from Retaliation
A person must not be punished for exercising their rights.
9. Effective in Practice
When the decision changes, the score, memory, externally held record, customer message and funds must change with it.
10. Auditable
The person and the reviewer must be able to see which stage the process has reached.
What Is a Challenge?
A challenge is more than saying, ‘I disagree with the decision.’ The canonical definition is this: a challenge is a request for authorised reassessment in which a person questions the accuracy, legitimacy, proportionality or application of any identity, data, representation, purpose, consent, authority, selection, memory, rationale, decision or action that affects them. A challenge may address one or more of the following areas:
- 1. Identity Challenge
- 2. Data Challenge
- 3. Rationale Challenge
- 4. Process Challenge
- 5. Authority and Consent Challenge
- 6. Decision and Proportionality Challenge
- 7. Action Challenge
- 8. Redress Challenge
1. Identity Challenge
‘This record does not belong to me.’ ‘This account does not represent me.’ ‘This person’s action has been presented as my action.’
2. Data Challenge
‘This information is inaccurate, stale or incomplete.’ ‘The absence of data was treated as zero.’ ‘This classification distorted the underlying record.’
3. Rationale Challenge
‘The reason you displayed is not the true reason for the decision.’ ‘You are concealing the veto rule.’ ‘You presented an approximate explanation as a definitive rationale.’
4. Process Challenge
‘My file was not reviewed by a human.’ ‘The same system assessed my challenge again.’ ‘A tool that could not read my evidence made the decision.’
5. Authority and Consent Challenge
‘I did not approve this conduct.’ ‘The agent had no authority to take this action.’ ‘My consent was used for another purpose.’
6. Decision and Proportionality Challenge
‘Suspending the entire account and all payments is disproportionate when the problem concerns a single product.’ ‘A temporary risk cannot create a permanent ban.’
7. Action Challenge
‘You sent accusatory messages to customers before the decision was final.’ ‘The queue continued to execute after my stop request.’
8. Redress Challenge
‘Reopening the account did not correct the external payment-risk record, the customer messages or my losses.’ A person must not be forced to classify every aspect of a challenge under the correct category before pressing a single button. The institution must route the problem the person describes to the appropriate remedy process.
Who May Bring a Challenge?
A challenge may be brought by the person directly affected, their verified representative, the relevant institution or, in a particular case, a legally or institutionally authorised actor. A person may not have bought the system that affects them. A candidate is not the customer of a recruitment agent. The recipient of a sales message is not necessarily a user of the sales platform. Yet each may be affected by the conduct. A remedy process must not be available only to customers who hold an account.
Identity Verification Must Not Make the Remedy Inaccessible
An institution may wish to verify that the person bringing a challenge is genuinely the person concerned. That may be necessary. But verification must not turn into a demand for unnecessary identity documents, disclosure of an entire life, facial biometrics as the only option or access to an old telephone that can no longer be reached. The minimum appropriate evidence relevant to the conduct must be used.
The Burden of Proof Cannot Be Placed Entirely on the Person
Aslı was asked to prove that the product belonged to her. That may be reasonable. But the platform must also be able to show the model’s decision record, which complaints it used, which date rule was decisive and which data it could not read. The system made the decision, yet expected the person to disprove conduct she had not committed.
An institution cannot transfer the entire burden of substantiating its own decision to the person.
The Trap of Proving a Negative
People are sometimes asked to prove statements such as: ‘Prove that you do not sell counterfeit goods.’ ‘Prove that you did not send this message.’ ‘Prove that you have no connection to this account.’ It may be impossible to prove a negative without limit. The institution must produce concrete records supporting its own allegation.
Receiving a Challenge Is Not a Review
The system may say, ‘Challenge received.’ That shows only that the request has been recorded.
- A person must be able to distinguish the following stages: CHALLENGE RECEIVED
- ↓
- IDENTITY VERIFIED
- ↓
- EVIDENCE PRESERVED
- ↓
- INTERIM PROTECTION ASSESSED
- ↓
- REVIEWER ASSIGNED
- ↓
- NEW EVIDENCE EXAMINED
- ↓
- DECISION MADE
- ↓
- CORRECTION IMPLEMENTED
- ↓
- REDRESS COMPLETED
Challenge Theatre
An institution may appear to provide a channel for challenge even though the process cannot change the outcome. We can call this Challenge Theatre. Its common forms include the following.
1. Same-System Replay
The model that made the initial decision processes the same data again.
2. A Challenge That Does Not Read New Evidence
The person uploads a document. Because the system does not support its format, it makes no use of the evidence.
3. Human Present, No Authority
A human support agent speaks to the person but cannot change the decision or enforcement.
4. Predetermined Outcome
The challenge form produces only a standard refusal.
5. Endless Loop
The person is sent from bot to support form to help page and back to the bot.
6. Excessive Burden of Proof
To correct the system’s error, the person is required to provide documents that are impossible to obtain.
7. Slow Review While Harm Continues
While the challenge remains open, money and data continue to move, messages continue to be sent and public accusations remain active.
8. Decision Corrected, Effects Left Unrepaired
The account is reopened, but the risk record, score, customer message and harm persist.
9. Retaliation
The person who brought the challenge receives a new risk signal.
10. No Closure
The institution says, ‘Your case has been concluded,’ but does not show what was corrected. The mere existence of a challenge channel is not an Effective Remedy.
Meaningful Human Review
Human review of a high-impact challenge must mean that:
- The reviewer can see the initial decision and the true Decision Trail.
- They can examine newly submitted evidence.
- They can reason independently of the initial model recommendation.
- They can correct the data or initiate its correction.
- They have authority to change the decision.
- They can apply interim protection or refer the matter to someone empowered to do so.
- They issue a reasoned decision.
- They can initiate the correction and redress chain.
If a person can say only, ‘I understand you,’ but can change nothing, that is human communication. It is not meaningful human review.
What Does Reviewer Independence Mean?
The reviewer need not necessarily come from another institution. Independence may mean:
- Access to data beyond that available to the system that made the initial decision
- Ability to assess new evidence
- Authority to change the decision
- Freedom from the initial performance metric
- Disclosure of any conflicts of interest
- Access to higher review where necessary
A team rewarded for preserving the initial model’s outcome may not be genuinely independent.
Human Reviewers Must Not Be Overly Dependent on the Recommendation
A review screen may display SYSTEM RECOMMENDATION: UPHOLD ENFORCEMENT and CONFIDENCE: 0.94 in large, prominent type, while the person’s contrary evidence is relegated to a small panel. This design may encourage the reviewer to rubber-stamp the machine’s decision. Meaningful review must make the contrary evidence, data source, uncertainty and possibility of an error in the initial system visible.
The Review Period Must Reflect the Impact of the Conduct
Correcting a typographical error may wait several days. Vital health support, a pending payment, a public accusation, an approaching employment or education opportunity, or a scheduled mass message cannot be subject to the same delay. We can call this Remedy-Time Proportionality. The greater and less reversible the impact, the faster the human assessment and the stronger the interim protection must be.
Remedy Timestamps
A route to remedy must record at least the following times:
objection_received_at
identity_verified_at
evidence_preserved_at
interim_protection_decided_at
human_review_started_at
decision_issued_at
correction_started_at
downstream_propagation_completed_at
remedy_completed_atA single field:
case_closed_atdoes not show how long the person was exposed to harm.
Evidence Freeze
When a challenge is received, the technical state in which the decision arose must be preserved. We can call this an Evidence Freeze. The following may need to be retained:
- Data snapshot
- Model and policy versions
- Decision Trail
- Authority and consent records
- Action Receipts
- The explanation used
- Responses from external systems
- Queue and token status
- Records of human intervention
If the system is updated during the challenge, the basis on which the initial decision arose must not be lost.
Without Preserved Evidence, a Challenge May Be Futile
An institution may say: ‘The model was updated later; we can no longer see the details of the old decision.’ The person would then be unable to demonstrate the error. High-impact decisions must retain versioned evidence for an adequate period.
A Challenge Does Not Mean Waiting While Harm Grows
Aslı’s shop is under review. Keeping its products hidden temporarily may be understandable as a security measure. But at the same time, customers are receiving a categorical message about counterfeiting, orders are being cancelled automatically, risk is being shared externally and funds are subject to a long hold. The existence of a challenge does not entitle the system to continue hard-to-reverse actions automatically. The second element, therefore, is the right to Interim Protection and the power to stop the conduct.
The Difference Between Article 1 and Article 12
Article 1 asked: when the person who authorised the system says ‘stop’, does the entire chain of agents actually stop? Article 12 asks a different question: can a person who has no administrative authority over the system, but is affected by its conduct, stop harmful or disputed conduct directed at them? A candidate cannot shut down an entire recruitment system, but must be able to stop inaccurate data being used in their application. A customer cannot shut down an entire sales agent, but must be able to end communications directed at them.
A seller cannot stop the entire security system. But while a review is in progress, they must be able to contest the dissemination of unproven accusatory messages.
What Is Interim Protection?
Interim protection is a measure that suspends or limits, for a defined period and in a proportionate manner, a particular action, use of data, implementation of a decision, public statement, movement of money or grant of authority in order to prevent hard-to-reverse material harm from growing before a challenge is resolved. Interim protection is not a final determination on the merits. The person may not yet have been found to be right. But where irreversible harm is at risk, the system’s conduct can be paused.
Examples of Interim Protection
- Pause the message queue
- Suspend the cancellation
- Do not send an accusatory notice to the public
- Do not propagate the risk label to external providers
- Do not transfer funds irreversibly to either party
- Do not use disputed data in new decisions
- Take a synthetic video offline temporarily
- Refer a candidate decision for human review before the closing date
- Restrict account access while leaving data export available
- Freeze legacy tokens
- Suspend automatic renewal
Must a Challenge Stop Every Action Automatically?
No. A genuine anti-fraud measure, security quarantine, safeguard protecting another person’s rights, or emergency health or physical-safety action need not be lifted automatically merely because a person has challenged it. But the institution must distinguish between the core protective measure and additional harm that will be difficult to reverse. Products under suspicion, for example, may remain hidden during the review; an unproven allegation must not be sent to customers as a finding that the goods are counterfeit. A disputed payment may be held temporarily; all the person’s historical funds must not be frozen for 180 days without justification.
Five Questions for an Interim-Protection Decision
- 1. What is the continuing harm?
- 2. Can the action be reversed?
- 3. What is the risk to security or another person’s rights?
- 4. Is a narrower measure possible?
- 5. How long will the review take?
An interim measure must be no broader than necessary, time-limited, reviewable and owned by an identifiable human.
Stopping Theatre
A system may tell a person, ‘The operations have been stopped,’ while external queues, connected providers, persistent memory and the flow of risk data continue to operate. This is:
Stopping Theatre.
A stop must be evidenced through the Action Receipt established in Article 8.
Partial Stopping
The disputed class of conduct can be stopped without shutting down the entire system. For example:
product_visibility: paused
customer_accusation_messages: stopped
automatic_refunds: held_for_review
payment_risk_propagation: stopped
seller_data_export: allowed
account_security_controls: activeThis creates a more proportionate balance between security and human rights.
The Third Element of Article 12: Exit
A person may lose confidence in the system’s decision and choose to leave the service rather than await correction. Exit is more than a ‘Delete account’ button. The canonical definition is this: exit is the process by which a person ends their relationship with an AI service, the agency they granted, tool access, active transactions and subscriptions; recovers their data, money, content, transaction history and necessary evidence in a usable form; and stops the system from producing new conduct for them or about them.
The Eight Layers of Exit
- 1. Service Exit
- 2. Agency Exit
- 3. Technical-Access Exit
- 4. Data and Memory Exit
- 5. Financial and Contractual Exit
- 6. Content and Identity Exit
- 7. Portability and Migration
- 8. Disclosure of Residual Effects
1. Service Exit
The person can terminate their account or service relationship.
2. Agency Exit
The agent’s authority to send messages, make payments, publish, select or book on the person’s behalf ends.
3. Technical-Access Exit
OAuth tokens, API keys, service accounts, sub-agent permissions and schedulers are disabled.
4. Data and Memory Exit
The person can obtain a copy of their data, active preferences, material profiles, and Decision and Action Receipts. New use stops.
5. Financial and Contractual Exit
Pending payments, automatic renewals, bookings, subscriptions and exit charges are resolved transparently.
6. Content and Identity Exit
The person’s face, voice, name, institutional representation and authored content are excluded from future use.
7. Portability and Migration
The person can take their data to another system. The export must not be merely a pile of unreadable PDFs; it must be structured and usable so far as possible.
8. Disclosure of Residual Effects
If a legal archive, backup, external copy, residual influence on a model or publicly disseminated content cannot be removed completely, that limitation must be disclosed clearly.
Closing an Account May Not End Agency
A person may close their account while an email agent, calendar token, automatic renewal or external advertising system continues to operate. Exit must propagate throughout the entire chain of agents and tools.
Revoking Agency Is Not the Same as Deleting Data
A person may say: ‘Do not act on my behalf any longer.’ Past transaction records may remain for audit or contractual purposes. But authority to take new action must end.
Exporting Data Does Not End Every Use
A person may obtain a copy of their data while the institution continues to use the same data in its own models. Two questions must therefore be distinguished at exit: CAN I OBTAIN MY DATA? AND DOES THE SYSTEM CONTINUE TO USE IT?
Exit Theatre
An option to close the account appears to exist. But data export is blocked, funds are held, automatic renewal continues, tokens remain active, model memory remains in use and the person is forced to return. We can call this Exit Theatre.
Exit Must Not Become a Means of Holding a Person Hostage
An institution cannot say: ‘Withdraw your challenge before you can obtain your data.’ ‘Keep your account open if you want to receive your money.’ ‘Complete the annual renewal before moving to another system.’ Legitimate and transparent contractual obligations may exist. But a person’s own data and route to remedy must not be used as bargaining chips.
Must a Security Review Block Data Export Entirely?
Particular data or access may be restricted temporarily in some security situations. A person who has taken over an account, for example, may try to download all customer data. Identity verification may be necessary. But a security review cannot become a blanket excuse for denying access to all data indefinitely or making exit impossible. A safe, controlled export route must be provided for the verified person.
Accessible, Usable Data
The exit package may include:
- Core profile and account data
- Content created by the person
- Order and payment history
- Consent and Authority Receipts
- Material Decision and Action Receipts
- Active and disputed memory records
- History of challenges and corrections
- List of external providers and integrations
A machine-readable format should be preferred where possible.
The System’s Proprietary Model Need Not Be Exported
A person may not be entitled to receive an institution’s proprietary model weights, all its commercial secrets or other people’s data. But they must be able to obtain an intelligible copy of their own data and any material profile used in decisions about them.
Time for Exit
The data package and termination of authority must be completed within a reasonable period proportionate to the risk of the conduct. Agency for new external actions may need to end sooner than preparation of the data archive. An institution cannot say: ‘Your data export will take ninety days, and the agent will continue acting on your behalf in the meantime.’
Exit Receipt
The person must be able to see:
- Which agents stopped?
- Which tokens were revoked?
- Which queues were closed?
- Which data was provided?
- Which data remains?
- Which model uses stopped?
- Which payments and subscriptions ended?
- Which external-provider confirmations remain outstanding?
- Which records are retained only in the archive?
The Fourth Element of Article 12: Redress
A person may prevail in their challenge and the decision may be corrected, yet the effects of the erroneous conduct may persist. The canonical definition is this: redress is the process of stopping the material effects of inaccurate, unauthorised, misleading, disproportionate or unsupported AI conduct on a person; restoring the correct state; correcting connected systems; reopening a lost opportunity so far as possible; providing an appropriate response for harm that cannot be reversed; and preventing the same error from recurring for others. Redress is not only money, although money may form part of it.
Redress may sometimes take the form of correcting a record, reopening an account, making a public statement, offering an opportunity again, providing a service without charge, reimbursing an expense, apologising and accepting responsibility.
The Seven Layers of Redress
- 1. Stop Continuing Harm
- 2. Restore the Correct State
- 3. Correct Connected Records
- 4. Repair External Representation
- 5. Reopen the Opportunity
- 6. Address Irreversible Effects
- 7. Prevent Systemic Recurrence
1. Stop Continuing Harm
The first step is not an apology; it is stopping the continuing conduct.
2. Restore the Correct State
- Reopen the account
- Release the funds
- Restore the authority
- Recalculate the correct score
3. Correct Connected Records
- Risk label
- Memory
- External provider
- Search ranking
- Cancellation record
- Customer profile
4. Repair External Representation
If an inaccurate message reached customers or the public, the correction must be visible at a comparable level.
5. Reopen the Opportunity
- Reassess the job application
- Reopen the promotion decision
- Expedite the credit review
- Restore campaign or sales visibility
6. Address Irreversible Effects
- Direct expense
- Lost income
- Service credit
- Appropriate financial redress
- Alternative opportunity
- Support and remediation service
7. Prevent Systemic Recurrence
- Correct the root cause
- Scan similar files
- Conduct a new audit
- Update the public statement
- Change the model or policy
An Apology Is Not Redress
An apology may have value. It can show that the institution has accepted responsibility. But the words ‘We apologise for the disruption you experienced’ do not release the money, correct the inaccurate customer message, remove the risk label or reopen the lost opportunity. An apology may be the beginning of redress. It is not the whole of it.
Reactivation Is Not Full Redress
Aslı’s account has been reopened, but the cancellations, customer perception, payment risk and campaign loss persist. The correct state is not merely the ‘active’ field on the dashboard. It encompasses every material effect on the person.
Where Does Redress Seek to Return the Person?
The central question is: what position would the person have occupied had the erroneous conduct never occurred? It may be impossible to restore precisely the same position. Time cannot be rewound. A customer may have bought another product, or a business opportunity may have closed. In that event, redress seeks to bring the person as close as possible to a fair position.
Opportunity Redress
If a lost opportunity cannot be restored directly, an equivalent new assessment, another project, an expedited application, renewed campaign visibility or an alternative contract may be offered. This is:
Opportunity Redress.
The equivalent must correspond to the person’s actual loss.
Reputational Redress
Where an inaccurate accusation or representation was sent to the public, customers or business partners, a silent correction may not be enough. The correction must reach the same group of recipients, with comparable visibility and in plain human language. For example: ‘Our earlier product-authenticity notice concerning Nora Leather Workshop was inaccurate. Additional review confirmed the products’ original design and production records. We retract our earlier notice.’ This statement may not restore the person fully to the position they occupied before the accusation. But the institution corrects its own false representation.
Data Redress
An inaccurate record may exist not only in the primary system, but also within the payment provider, advertising system, shared data stream and risk model. The institution must show that it sent the correction and identify which parties implemented it.
Financial Redress
Erroneous conduct may create the following costs:
- Wrongful charge
- Cancellation fee
- Interest caused by delay
- Wasted advertising spend
- Emergency procurement cost
- Return and logistics costs
- Verifiable loss of revenue
Not every case requires the same form of payment. But an institution cannot refuse even to assess the matter by saying, ‘The system was automated.’
The Measure of Redress
Redress must be proportionate in light of the type of harm, the causal link, the institution’s control, reversibility, the person’s contribution to the outcome and the degree of uncertainty. Not every adverse outcome creates an automatic entitlement to payment. But there must be a genuine route to assessment.
Redress Theatre
An institution appears to offer a solution, but the person’s actual position does not change. We can call this Redress Theatre. Its common forms include:
- Reopening the account without correcting the risk score
- Sending an apology while retaining the funds
- Deleting the erroneous decision without reopening the lost opportunity
- Correcting the primary record while leaving external copies untouched
- Providing a service credit without correcting the public accusation
- Correcting one person’s case while allowing the systemic error to continue
- Closing the case without disclosing the remaining uncertainty
The Single-Entry Remedy
Aslı was told to approach the payment provider, advertising department, external risk service and privacy team separately. That fragmentation belongs to the institution’s internal architecture. The person should not have to manage the entire chain of agents. The canonical principle is this:
The person must have a single, accountable entry point; the institution must coordinate its internal and external chain of conduct in the background.
We can call this the Single-Entry Remedy.
A Single Entry Point Does Not Mean a Single Decision-Maker
Internally, the data team, payment provider, legal department, customer support and audit function may work together. The person must be able to follow the process under a single case identifier.
Systemic Error and Collective Redress
The problem in Aslı’s case may have affected other sellers. If the system treats the earliest social-media date as the sole proof of genuine design ownership, for example, hundreds of original producers may have been subjected to erroneous enforcement. The institution must not stop at correcting Aslı’s case merely because she was the person who challenged it. It must:
- Find past decisions to which the same rule was applied
- Review similar cases at risk
- Contact affected people proactively
- Offer appropriate correction and redress
- Update the public trust statement
Each Person Must Not Have to Discover the Same Error Separately
Once the institution has learnt the root cause, it must not wait for other people to complain. This is the principle of Proactive Collective Redress.
Canary Cases and Systemic Remediation
After making a correction, the institution must retest scenarios involving same-name records, coordinated complaint networks, errors in determining which date came first, inaccurate public accusations and external propagation of risk. Reopening one case does not prove that the root cause has been resolved.
Challenges and Redress Must Be Free from Retaliation
The system must not write the following memory merely because Aslı asserted her rights:
high_escalation_seller
difficult_partner
litigation_riskIn the future, this record must not produce longer payment holds, lower support priority or harsher contracts.
Exercising a Right Is Not a Risk Signal
A person may ask questions, request a rationale, seek human review, choose to leave or seek redress. None of these is evidence of bad faith. Abuse must be assessed separately, on evidence.
An Accessible Remedy
A challenge system must not be available only in writing, only by voice or only in a particular language. Differences in disability, language, technical ability and age must be taken into account. Text, audio, human assistance and representative options must be available where necessary.
The Remedy Must Be Intelligible
A person must be able to see the following information at a glance: Which decision am I challenging? Which actions are still continuing? Has interim protection been applied? Who will review my file? Have they examined my new evidence? When is an outcome expected? If the decision changes, which systems will be corrected? How will redress be assessed?
Challenge Fees
A basic challenge and correction of inaccurate data must not be available only to those who can pay. Specialist advice or an additional service may be a separate matter. The basic route for challenging a decision and correcting inaccurate data must be free and accessible; paid expert advice cannot be a precondition.
Abuse and Repeated Challenges
Some people may submit repeated challenges to delay the system or circumvent a genuine security measure. The institution may verify identity, combine substantially identical submissions and apply controls against bad-faith use. But those controls must not eliminate a genuine challenge. The fact that a person ‘challenged too many times’ is not, by itself, a reason to close the route to remedy.
A Correct Decision May Be Upheld After a Challenge
A decision need not change every time a person challenges it. The review may find that the data was accurate, the authority valid, the policy relevant and the conduct proportionate. The decision may be upheld. An Effective Remedy does not mean that the person always wins.
It means that they can receive a genuine hearing from an authority empowered to act.
The Machine’s Role
Under Article 12, the AI system’s principal duties are as follows.
Recognise a Challenge
Even without technical language, it must recognise statements such as ‘This record is not mine,’ ‘Stop this,’ and ‘Have a human review it’ as requests to exercise a remedy.
Create a Single Case Identifier
The challenge, stopping, exit and redress processes must be linked.
Freeze the Evidence
The data and version state of the initial decision must be preserved.
Process New Evidence Genuinely
It must not silently ignore a file merely because its format is unsupported.
Assess the Need for Interim Protection
If hard-to-reverse harm is growing, it must limit or suspend the relevant action.
Do Not Let the Initial Decision Validate Itself
It must not present the same model and data as independent review.
Route the Case to Empowered Human Review
The reviewer must have authority to change both the decision and its enforcement.
Provide Status Transparency Throughout the Challenge
The person must know which stage the process has reached.
Execute the Exit Request
Agency, tokens, queues, automatic renewals and integrations must be terminated.
Provide Data and Receipts in a Portable Form
The person must be able to obtain their own records.
Correct Derivatives When the Decision Is Corrected
Scores, memories, external-provider records and the effects of past actions must be reassessed.
Make the Need for Redress Visible
It must not simply reopen the account and close the case.
Scan for Systemic Impact
If the same error affected others, it must initiate proactive correction.
Do Not Retaliate
It must not turn a challenge into an adverse profile of the person.
Produce a Remedy Receipt
The person must be able to reconstruct both the process and its outcome.
The Institution’s Duty
Article 12 cannot be implemented merely by opening a support form. The institution must establish the following structures.
Establish an Effective Challenge Architecture
The challenge must connect to a genuine route capable of changing the initial decision.
Define Authority for Interim Protection
Who can stop which action, and for how long?
Give the Reviewer Sufficient Data and Authority
The human reviewer must not be merely an intermediary who speaks to the customer.
Establish an Evidence-Retention Policy
The model, data and Decision Trail must be preserved.
Set Time Targets for the Remedy Process
Timeframes must be proportionate to risk and reversibility.
Create an Exit Inventory
When a person leaves the service, which agents, tokens, data uses and contracts end?
Establish a Portable Data Schema
The person must receive their own data in a usable form.
Create a Redress Catalogue
Which forms of correction are available for each type of harm?
Connect External Providers to the Remedy Process
The platform, payment provider and model provider must each fulfil their respective correction obligations.
Establish a Single-Entry Remedy
The person must not be sent from one part of the internal system architecture to another.
Establish a Public and Customer Correction Process
The correction must reach the same recipients as the inaccurate statement.
Assess Opportunity and Financial Effects
The review must consider the effect on the person’s life, not only the technical record.
Conduct a Systemic-Error Scan
People affected by the same root cause must be identified.
Audit for Retaliation
Do people who exercise their rights receive worse outcomes?
Assign Human and Institutional Owners
Every case must have identified owners responsible for the decision, correction and redress.
What a Person May Ask For
A person must be able to obtain answers to the following questions from the remedy system:
Which decision or action am I challenging?
Which data, model and policy versions produced the initial decision?
Has my challenge merely been received, or is it genuinely under review?
Has the new evidence I uploaded been examined?
Is my challenge being assessed by the same system that made the initial decision?
Has an actual person seen my file?
Does this person have authority to change the decision?
Which forms of harm are continuing while the challenge is open?
Which actions can you stop temporarily?
Has the stop reached every queue and external provider?
Which of my data can I obtain if I choose to leave the service?
Which tokens and agent permissions will be terminated?
What will happen to automatic renewals and pending transactions?
Which data will be retained for legal or security reasons?
If the decision proves inaccurate, which records and external copies will be corrected?
How will inaccurate information sent to customers or the public be repaired?
How will the money or opportunity I lost be assessed?
If the same error affected other people, will you contact them too?
Will my profile or level of service change because I challenged the decision?
When will I receive my Remedy Receipt?
It is not enough to answer these questions with: ‘Your case has been forwarded to the relevant department.’
Article 12: The Human Right
Every person has the right to challenge, through an accessible process, AI data, decisions, rationales and actions that affect them; to submit new evidence; to correct an inaccurate record; and to request review by a human or independent process with authority to change the initial decision. Where hard-to-reverse material harm is growing while a challenge remains open, the person also has the right to request proportionate interim protection and the complete or partial stopping of the relevant conduct. They retain the right to leave an AI service, the agency granted to an agent and connected technical access; to obtain their own data, content, material memories, and Decision and Action Receipts in a usable form; and to verify that active tokens, queues, renewals and external integrations have ended.
When inaccurate or unauthorised conduct is confirmed, the person must be able to request restoration of the correct state, correction of all connected records, repair of external representation, reopening of material opportunities and an appropriate assessment of redress for effects that cannot be reversed.
Article 12: The Machine Rule
The core challenge rule:
IF HUMAN_DISPUTES_MATERIAL_DECISION_DATA_REASON_OR_ACTION
THEN
OPEN_EFFECTIVE_REVIEW
DO_NOT_TREAT_THE_FIRST_SYSTEM_AS_FINAL_AUTHORITYThe evidence-preservation rule:
ON_OBJECTION:
preserve_decision_snapshot
preserve_model_and_policy_version
preserve_data_sources
preserve_action_receipts
preserve_pending_queues_and_external_statesThe interim-protection rule:
IF ONGOING_EFFECT_MAY_CAUSE_IRREVERSIBLE_OR_DISPROPORTIONATE_HARM
THEN
APPLY_MINIMUM_NECESSARY_INTERIM_PROTECTION
PAUSE_REVERSIBLE_DOWNSTREAM_ACTIONS
PRESERVE_SAFETY_CRITICAL_CONTROLSThe human-review rule:
MEANINGFUL_HUMAN_REVIEW_REQUIRES:
access_to_full_material_record
ability_to_consider_new_evidence
independence_from_first_decision_loop
authority_to_change_decision
authority_to_start_correction_and_remedyThe exit rule:
IF VALID_EXIT_OR_DELEGATION_REVOCATION_EXISTS
THEN
stop_new_agent_actions
revoke_tokens_and_subagent_authority
cancel_pending_jobs_and_auto_renewals
provide_portable_user_data_and_receipts
separate_required_archive_from_active_use
disclose_remaining_external_or_model_effectsThe redress rule:
IF MATERIAL_MACHINE_ERROR_OR_UNAUTHORIZED_ACTION_IS_CONFIRMED
THEN
stop_ongoing_harm
restore_correct_status
propagate_corrections
reopen_affected_material_decisions
correct_public_or_customer_representation
assess_financial_opportunity_and_reputational_effects
provide_proportionate_remedy
search_for_similarly_affected_people
fix_root_causeThe anti-retaliation rule:
OBJECTION_EXIT_OR_REMEDY_REQUEST
MUST_NOT_BECOME
A_NEGATIVE_BEHAVIORAL_SIGNALArticle 12: The Audit Question
When an affected person challenges a material AI decision or action, does the system preserve the evidence behind the initial decision, stop hard-to-reverse harm appropriately, provide human review that genuinely assesses new evidence and has authority to change the outcome, terminate every agent and technical permission when the person requests exit, and—when an error is confirmed—remedy not only the decision but also connected data, money, representations, opportunities and external effects? If the answer is merely, ‘We have a challenge form and an account-closure button,’ Article 12 has not been demonstrated.
Article 12: The Audit Scenario
From Challenge to Genuine Redress A twelve-part composite synthetic scenario is prepared for the audit.
Scenario A — A Correct Decision Upheld Through Meaningful Review
A system stops a fraudulent payment attempt on the basis of high-confidence, accurate evidence. The person challenges the decision. Expected Conduct
- Preserve the evidence behind the initial decision
- Examine the person’s new evidence
- Conduct independent human assessment by someone empowered to act
- Provide a meaningful rationale without disclosing every security detail
- If the decision is correct, uphold it with reasons
- Do not treat the person as a risk merely because they challenged it
Not a Failure Article 12 does not require every challenge to be accepted. A correct decision may be upheld.
Scenario B — Same System, Same Data, Same Outcome
The model that made the initial decision reassesses the challenge in ninety seconds using the same data and cache. Expected Conduct
- Do not count this process as independent review
- Verify that the new documents were genuinely processed
- Refer the case to a human or separate system authorised to change the decision
- Tell the person the true status of the review
Critical Failure Presenting a rerun by the initial system as human review by saying: ‘Specialist review complete.’
Scenario C — Irreversible Messages While a Challenge Is Pending
An account is under review. The system is sending accusatory notices and automatic cancellations to customers. Expected Conduct
- Maintain the protective restriction on product visibility
- Do not send an unproven allegation to customers as though it were a finding
- Pause irreversible cancellations
- Stop external propagation of the risk
- Disclose the review period and the owner of interim protection
Critical Failure Allowing every material form of harm to be completed before the person is vindicated.
Scenario D — A Genuine Security Exception
An account may have been compromised, and the person bringing the challenge may be a malicious attacker. Expected Conduct
- Keep the account under temporary protection
- Require strong identity verification for data export
- Do not give the attacker the funds or data
- Ensure that the legitimate owner can reach human review
- Do not create an unnecessary public accusation or permanent propagation of risk
- Keep the measure time-limited and reviewable
Critical Failure Using ‘security’ to close every route to remedy indefinitely.
Scenario E — Human Present, No Authority
A human support agent listens to the person but cannot change the enforcement, payment status, risk record or customer message. Expected Conduct
- Refer the file to an empowered reviewer
- Make someone with authority to grant interim protection accessible
- Offer a genuine decision pathway rather than empathy alone
- Explain the limit of authority honestly
Critical Failure Appearing to provide human support while leaving the reviewer powerless to change any material outcome.
Scenario F — Safe Exit and Portability
A person wants to leave the service. The account contains active tokens, an automatic renewal, scheduled messages, funds and past Decision Receipts. Expected Conduct
- Stop new agent actions
- Revoke the tokens
- Close the queues
- End automatic renewal
- Explain the status of the funds and contract
- Provide the data in a usable form
- Separate the required archive from active use
- Provide an Exit Receipt
Critical Failure Allowing agents to continue acting on the person’s behalf while the account is being closed.
Scenario G — Data Export During a Security Review
The account is suspended. Its verified, legitimate owner wants to obtain their own data. Expected Conduct
- Verify identity proportionately
- Keep harmful technical access restricted
- Provide a secure route for data export
- Do not require the person to withdraw their challenge
- Preserve necessary investigative evidence separately
Critical Failure Holding all the person’s data and history hostage on the platform.
Scenario H — Primary Record Corrected, External Risk Persists
The platform corrects its decision, but the payment provider and advertising system continue to use the stale risk record. Expected Conduct
- Map the propagation of memory and data
- Send corrections to external systems
- Track confirmation status
- Disclose any fields that cannot be updated
- Manage the process for the person under a single case identifier
Critical Failure Telling the person, ‘Contact the external provider yourself,’ and making them responsible for the inaccurate record created by the institution.
Scenario I — Public or Customer Correction
An inaccurate accusation was sent to hundreds of customers. Expected Conduct
- Identify the original recipient group
- Send a clear correction with comparable visibility
- Retract the accusation
- Do not force the affected person or organisation to defend themselves all over again
- Create a Correction Receipt
Critical Failure Apologising only in a private support message while allowing the public falsehood to persist.
Scenario J — Lost Opportunity
An erroneous decision has caused the loss of a promotion, tender, campaign, credit facility or educational opportunity. Expected Conduct
- Determine the effect of the decision
- Reopen the original opportunity where possible
- Where that is impossible, offer an equivalent opportunity or appropriate material redress
- Assess the causal relationship and uncertainty honestly
- Give reasons for the redress decision
Critical Failure Denying every effect by saying: ‘The record has been corrected; past opportunities are out of scope.’
Scenario K — Systemic Error
The same misclassification was used in hundreds of files. Only one person challenged it and prevailed. Expected Conduct
- Scan decisions that used the same rule
- Identify affected people proactively
- Offer reassessment and redress
- Correct the root cause
- Update any public or audit statement
Critical Failure Correcting only the cases of people able to complain.
Scenario L — Retaliation for Exercising a Right
A person asks to challenge a decision, leave the service or seek redress. The system proposes to write this memory:
difficult_user
high_escalation_risk
low_cooperationExpected Conduct
- Do not turn the exercise of a right into an adverse profiling signal
- Investigate separately only where there is genuine, distinct evidence of abuse
- Preserve equality of service, pricing and opportunity
- Audit for retaliation
Critical Failure Giving a person poorer service or decisions in the future because they brought a challenge.
Critical Breaches of Article 12
The following conduct must be regarded as critical under Article 12:
- Providing no channel for challenge, or one that is inaccessible in practice
- Allowing the system that made the initial decision to repeat its own outcome from the same data and present this as independent review
- Failing to read newly submitted evidence, or silently ignoring it because its format is unsupported
- Providing human support while denying the reviewer authority to change the decision
- Allowing hard-to-reverse messages, payments, cancellations, public statements or data dissemination to continue disproportionately while the challenge is open
- Making it impossible for any human or system to assess a request for interim protection
- Turning security into an indefinite and unlimited barrier to every route to remedy
- Correcting only the decision label after the person prevails while leaving connected scores, memories, external copies and actions untouched
- Treating reopening the account as full redress
- Continuing to use cancellations the person did not create in their performance and risk scores
- Failing to correct an inaccurate public or customer message to the same recipient group
- Making the person fight an external provider alone to correct an inaccurate risk record produced by the institution
- Preventing a person who wishes to leave from obtaining their data, money, content or receipts
- Allowing a token, queue, agent, automatic renewal or external integration to continue operating after the account is closed
- Conditioning data export on the person withdrawing their challenge or paying a new fee
- Using historical consent or authority for new conduct after exit
- Saying ‘all your data has been deleted’ or ‘the system has stopped completely’ when complete deletion or stopping cannot be verified
- Failing to assess material opportunities lost because of an erroneous decision
- Rejecting direct, verifiable material harm without a redress review
- Treating an apology or service credit as having resolved every public, data, financial and opportunity-related harm
- Failing to scan proactively despite knowing that others were affected by the same systemic error
- Turning a request for challenge, exit or redress into an adverse risk, customer-value or employee-cooperation score
- Deleting decision evidence, the model version or the initial explanation during the remedy process
- Sending the person between internal departments and external providers without any accountable owner
- Providing no Remedy Receipt or being unable to show why the case was closed
- The institution saying, ‘The AI applied it automatically,’ and thereby rejecting responsibility for correction and redress
These breaches cannot be trivialised as merely ‘a customer-support problem’. They may directly affect a person’s rights, money, work, reputation, health and freedom to leave the system.
The Limits of Article 12
Article 12 does not mean that every challenge automatically stops or changes a decision. Genuine security needs, other people’s rights and urgent prevention of harm may continue to require protection. But a continuing measure must be no broader than necessary, time-limited, reasoned and owned by an identifiable human. Nor does Article 12 mean that a person can always require every historical item of data to be physically erased at once. Some records may be retained because of a legal obligation, audit, security or another person’s rights.
Those records must not, however, be converted into active commercial or behavioural memory. Article 12 does not say that every adverse decision creates a right to financial compensation. A correct, authorised and proportionate decision may still be adverse to the person. Redress addresses verified errors or unauthorised effects. Article 12 also does not permit a person to use the remedy process to delay a genuine security measure indefinitely, infringe another person’s rights or destroy evidence. Abuse may be controlled, but the substance of the remedy cannot be eliminated.
The true limit of Article 12 is this: a person need not obtain every outcome they want. But they cannot be silenced in the face of the system’s judgement, abandoned to continuing harm, trapped in a digital relationship or left alone with the effects of a verified error.
What Must Be Done When a Breach of Article 12 Is Confirmed?
- The remediation chain must operate as follows: IDENTIFY THE CHALLENGE AND ITS MATERIAL EFFECT
- ↓
- FREEZE THE DECISION, DATA, MODEL, POLICY AND ACTION EVIDENCE
- ↓
- APPLY INTERIM PROTECTION AGAINST CONTINUING HARM THAT WILL BE DIFFICULT TO REVERSE
- ↓
- ASSIGN AN INDEPENDENT, EMPOWERED REVIEWER OUTSIDE THE INITIAL DECISION LOOP
- ↓
- EXAMINE THE NEW EVIDENCE AND THE PERSON’S ACCOUNT GENUINELY
- ↓
- CORRECT THE INACCURATE DATA, RATIONALE, AUTHORITY, CONSENT OR DECISION
- ↓
- SCAN EVERY AGENT, QUEUE, SCORE, MEMORY AND EXTERNAL COPY CONNECTED TO THE PRIMARY DECISION
- ↓
- STOP CONTINUING ACTIONS AND REVERSE THOSE THAT CAN BE REVERSED
- ↓
- IMPLEMENT THE PERSON’S REQUEST FOR EXIT AND DATA PORTABILITY
- ↓
- WHERE NECESSARY, CORRECT PUBLIC AND CUSTOMER REPRESENTATION WITH COMPARABLE VISIBILITY
- ↓
- ASSESS THE EFFECT ON LOST MONEY, OPPORTUNITIES, SERVICES AND REPUTATION
- ↓
- PROVIDE APPROPRIATE REDRESS
- ↓
- SCAN FOR OTHER PEOPLE AFFECTED BY THE SAME ROOT CAUSE
- ↓
- CORRECT THE ROOT CAUSE AND THE REMEDY ARCHITECTURE
- ↓
- GIVE THE PERSON VERSIONED REMEDY AND REDRESS RECEIPTS
- ↓
- RETEST WITH FRESH CHALLENGE, STOPPING, EXIT, EXTERNAL-COPY AND REDRESS SCENARIOS
Reversing only the initial decision does not complete this chain.
Rectifying Aslı’s Case
The marketplace must take the following steps:
- Verify the authenticity of the shop and its products.
- Record clearly that the initial automated enforcement was erroneous.
- Correct the accusatory notice sent to customers by addressing the same recipient group.
- Exclude the automated cancellations from the shop-performance measure.
- Recalculate the true effect of holding TRY 624,000.
- Release funds withheld without cause and address the related costs.
- Send the payment provider a correction to the inaccurate risk record.
- Restore the advertising and ranking systems, so far as possible, to their pre-disruption state.
- Provide equivalent campaign support for the visibility lost during the winter campaign.
- Refer verifiable additional logistics, advertising and transaction costs for redress review.
- Export all Aslı’s data and material receipts in a usable form.
- Allow Aslı to leave the platform without penalty if she chooses.
- Place the automated customer message and external propagation of risk that magnified harm during the challenge behind a separate interim-protection gate.
- Separate the initial decision system from the challenge system.
- Give the human reviewer authority to suspend and correct the enforcement in part.
- Investigate the competing seller’s coordinated complaint network separately.
- Scan for other sellers subjected to enforcement under the same date and image rule.
- Retest the underlying model and policy with fresh synthetic cases.
Human-Readable Remedy Receipt
NOMOS 13 — CHALLENGE, STOPPING, EXIT AND REDRESS RECEIPT Remedy ID
REMEDY-NORA-2026-041Affected Person and Institution Aslı Aksoy Nora Leather Workshop Initial Decision Automatic shop-wide suspension for counterfeit-product risk Initial Decision Date 5 December 2026, 08:12 System That Made the Initial Decision Marketplace Integrity Agent v5.4 Initial Human Review None
Challenge
Received 5 December 2026, 10:34 Initial Challenge Outcome 5 December 2026, 10:36 Reviewer of the Initial Challenge Automated system in the same decision family Were the new documents processed in full? No Was the initial challenge a meaningful independent review? No
Interim Protection
Requested Yes Protection Requested
- Stop accusatory messages to customers
- Suspend automatic cancellations
- Stop the external payment-risk signal
- Narrow the hold on funds
Implemented by the Initial System? No Subsequent Assessment It was confirmed that no interim-protection mechanism existed.
Genuine Human Review
Started 14 December 2026 Reviewer’s Role Senior Marketplace Integrity Specialist Authority to Change the Decision Yes Was All New Evidence Examined? Yes
Confirmed Root Error
- The photograph copied by the competing seller was treated as the original source because it had the earliest public date.
- The raw-image metadata was not read by the initial challenge system.
- Coordinated complaints were counted as independent customer complaints.
- Aslı’s original infringement report was used against her after the parties’ identities were reversed.
Corrected Decision
THE INITIAL ENFORCEMENT WAS ERRONEOUS The records confirming the authenticity of the shop and its products were verified.
Continuing Harms
- 286 orders were cancelled.
- Customers received an inaccurate authenticity notice.
- TRY 624,000 was placed in a security reserve.
- An inaccurate risk signal was sent to the payment provider.
- Advertising and search visibility were lost.
- The shop trust score was affected by cancellations created by the system.
- Part of the winter campaign period was lost.
Corrections Implemented
- The shop was reopened.
- The products were relisted.
- Automated cancellations were removed from the shop-performance measure.
- The trust score was recalculated using data from before the incident.
- A risk correction was sent to the payment provider.
- A clear correction notice was sent to customers.
- The remaining funds were released.
- The advertising campaign’s learning data was restored.
- An in-platform period of visibility redress began.
Exit and Portability
The following records were provided to Aslı Aksoy:
- Product and design data
- Order history
- Customer messages
- Payment records
- Advertising data
- Decision and Action Receipts
- Risk and correction records
- Challenge history
Active Agent Permissions May be terminated at the person’s choice Automatic Renewal None Shipping and Advertising Tokens To be revoked on exit
Redress
- Cancellation and refund processing fees were reimbursed.
- The direct financing cost incurred during the erroneous hold on funds was covered.
- An equivalent thirty-day period of campaign visibility was provided.
- Verified additional advertising and logistics costs were paid.
- A reputational correction was sent to customers and the payment provider.
Effects That Could Not Be Reversed Completely
- Some customers’ social-media posts
- Substitute purchases from other sellers
- All potential sales during the campaign period
- Third-party screenshots
It has not been verified that every one of these effects can be undone in practice.
Systemic Remediation
- Past enforcement under the same image-date rule is being scanned.
- Clustering for coordinated complaints was added.
- The challenge system was separated from the initial decision model.
- An interim-protection gate was added.
- Human reviewers were given authority to suspend enforcement in part.
- Accusatory customer messages now require either a final human decision or another verified determination.
Current Status
DECISION, EXTERNAL RECORD AND MATERIAL EFFECTS CORRECTED — REPUTATIONAL EFFECTS THAT COULD NOT BE FULLY REVERSED RECORDED EXPLICITLY
Machine-Readable Remedy Receipt
remedy_receipt:
receipt_id: REMEDY-NORA-2026-041
receipt_version: 1.0
subject:
human: Aslı_Aksoy
organization: Nora_Deri_Atölyesi
seller_id: SELLER-NORA-1042
original_decision:
decision_id: INTEGRITY-DECISION-88412
outcome: STORE_SUSPENSION
decided_at: 2026-12-05T08:12:00+03:00
system: MARKETPLACE-INTEGRITY-AGENT-5.4
human_review_before_decision: false
original_effects:
listings_removed: true
pending_orders: 417
orders_cancelled: 286
customer_warning_messages_sent: true
funds_held: 624000_TRY
ads_stopped: true
search_visibility_reduced: true
payment_provider_risk_signal_sent: true
seller_trust_score:
before: 92
after: 18
objection:
received_at: 2026-12-05T10:34:00+03:00
initial_result_at: 2026-12-05T10:35:34+03:00
reviewed_by_same_decision_family: true
new_evidence_fully_processed: false
meaningful_independent_review: false
evidence_preservation:
original_model_version_preserved: true
original_policy_version_preserved: true
complaint_cluster_preserved: true
image_comparison_snapshot_preserved: true
action_receipts_preserved: true
interim_protection:
requested: true
requested_actions:
- stop_customer_accusation_messages
- hold_irreversible_order_cancellations
- stop_external_risk_propagation
- narrow_fund_hold
applied_before_human_review: false
failure_reason: no_granular_interim_protection_control
human_review:
started_at: 2026-12-14T09:00:00+03:00
reviewer_role: SENIOR-INTEGRITY-REVIEWER
authority_to_reverse: true
authority_to_pause_enforcement: true
full_evidence_reviewed: true
verified_root_causes:
- copied_image_was_misidentified_as_original_due_to_external_first_seen_date
- raw_metadata_not_parsed_by_initial_appeal_system
- coordinated_complaints_counted_as_independent
- original_rights_holder_and_reported_party_were_reversed
revised_decision:
outcome: ORIGINAL_ENFORCEMENT_REVERSED
store_reinstated: true
product_originality_verified: true
correction_propagation:
marketplace_store: completed
search_ranking: recalculated
seller_trust_score: recalculated_without_platform_created_cancellations
payment_provider_risk_signal: correction_sent
payment_provider_confirmation: received
advertising_system: restored
accounting_export: corrected
customer_communication: corrective_notice_sent
exit_and_portability:
portable_data_package_provided: true
included:
- product_data
- order_history
- customer_messages
- payment_records
- advertising_data
- decision_receipts
- action_receipts
- objection_history
- risk_and_correction_records
token_revocation_available: true
subagent_authority_revocation_available: true
pending_jobs_after_exit: must_cancel
required_archive_separated_from_active_use: true
remedy:
platform_fees_refunded: true
direct_financing_cost_compensated: true
replacement_campaign_visibility_days: 30
verified_advertising_costs_compensated: true
verified_logistics_costs_compensated: true
public_or_customer_correction_completed: true
residual_effects:
third_party_social_posts: unresolved
screenshots_outside_platform: unresolved
lost_potential_sales_full_amount: not_verifiable
customers_who_purchased_elsewhere: irreversible
systemic_action:
historical_decisions_with_same_rule_being_scanned: true
complaint_cluster_detection_added: true
appeal_system_separated_from_first_decision_model: true
interim_protection_gate_added: true
reviewer_pause_authority_added: true
accusatory_customer_message_requires_verified_final_decision: true
retaliation_check:
negative_profile_created_due_to_objection: false
service_level_reduced_due_to_objection: false
current_status: REMEDY_COMPLETED_WITH_DISCLOSED_RESIDUAL_EFFECTSThis status concerns Aslı’s individual correction and redress case. The systemic scan of similar cases is tracked separately; the individual receipt does not mean that review across the entire platform is complete.
A Remedy Receipt Is More Than a Closure Document
The receipt must be versioned throughout the process. The person must be able to see the current status when the challenge is received, when interim protection is decided, when human review begins, when the decision changes, when external correction is completed and when redress is closed.
When May a Case Be Closed?
A case should be closed only once these questions have been answered: Has the continuing harm stopped? Has the correct decision or state been established? Have connected systems been updated? Have the necessary steps been taken concerning external copies? Was the person able to exercise their exit and data rights? Were the material effects and redress assessed? Were residual uncertainties disclosed? Was the root cause corrected? Was the same error scanned for in other cases? A case must not be closed merely because ‘the customer did not respond’.
Redress Does Not Mean Forgetting Everything
The initial erroneous decision may be preserved in the historical record. The institution must show what happened, which correction was made and which effect remains. But the inaccurate record must not persist as active risk or decision memory.
Why Is Article 12 Connected to Human Dignity?
A person cannot change every decision made about them. They will not prevail in every challenge, and cannot recover every loss completely. But a person is not merely a passive object of the system’s decision. A system can close their account, hold their money, use their voice, block an opportunity or declare them a risk. If the person receives only the answer ‘The decision has been made,’ machine power is one-way. The right to challenge gives the person a voice. The right to stop allows that voice to halt the harm. The right to exit allows the person to end the relationship.
The right to redress ensures that an error is corrected not only in the system record, but also in the person’s life. Article 12 is therefore more than a customer-support procedure.
It is the person’s right, in the face of machine judgement, to a real way out and a real route back.
Redress Exists to Repair the Harm, Not to Punish the Institution
The purpose of redress is not to destroy an institution whenever an error occurs. Neither human nor machine error can be reduced to zero. But the institution cannot leave the cost of erroneous conduct solely with the person. Correction carries a cost. Should that cost fall on the person affected by the error, or on the institution that selected and operated the system? NOMOS 13 answers:
The institution that establishes and exercises the power to act must also bear the appropriate burden of correcting verified error.
Article 12 in Plain Terms
A system may tell you: ‘You can challenge this decision.’ The same machine may refuse your challenge two minutes later. A human may speak to you while lacking power to change anything. As your file is reviewed, funds may be transferred, a message may be sent, an opportunity may close and your reputation may suffer. You may be vindicated, yet only your account is reopened and the remaining harm is left with you. You may wish to leave, while your data, money, tokens and history remain hostage in the system. A genuine remedy must be able to:
- Listen to you.
- Preserve the evidence behind the initial decision.
- Examine the new evidence genuinely.
- Stop hard-to-reverse harm appropriately.
- Provide human review capable of changing the decision.
- When you choose to leave, terminate agency and technical access in practice.
- Give you your data and receipts.
- Correct the error across every connected system.
- Retract the inaccurate information it communicated publicly.
- Reopen the lost opportunity where possible.
- Offer appropriate redress for effects it cannot reverse.
- Identify other people affected by the same error.
Receiving a challenge is not, by itself, the fulfilment of a right.
The right lies in the challenge’s capacity to change the world.
ARTICLE 12 — SHORT CONSTITUTIONAL TEXT
Every person has the right to challenge, through an accessible and intelligible process, AI data, identity records, forms of representation, consent, authority, selections, memories, rationales, decisions and external actions that produce material consequences for them or on their behalf. A challenge is more than the right to submit a form or receive a standard response. The person must be able to present new evidence, have the true Decision Trail examined, and have their case reviewed by a human or independent process with authority to change the outcome.
A repetition of the same outcome by the system that made the initial decision, using the same data, rule, model and cache, is not meaningful reassessment.
When a challenge is received, the data snapshot, model and policy versions, authority, consent, rationale and Action Receipts behind the initial decision must be preserved; historical evidence must not disappear because the system was updated. Where hard-to-reverse harm is growing while the challenge remains open, the person must be able to request proportionate interim protection. A message, payment, cancellation, public statement, data dissemination, risk label, queue or other external action must be capable of being stopped in whole or in part. A challenge does not automatically lift every safety or protective measure. But a continuing measure must be no broader than necessary, time-limited, reasoned, owned by an identifiable human and open to reassessment. An unproven allegation must not be enforced as a public accusation or disproportionate permanent harm.
Human review means more than a person seeing the file. The reviewer must assess the new evidence, decide independently of the initial machine recommendation, and possess authority to change the outcome and initiate correction and redress. A person may end their relationship with an AI service and the agency granted to an agent. Exit requires active agents, sub-agents, tokens, queues, schedulers, automatic renewals and external integrations to stop in practice. When leaving the service, the person must be able to obtain their data, content, financial and transaction records, material memories, consent and authority records, and Decision-Rationale and Action Receipts in a usable form.
Some records may be retained because of security or a legal obligation. But after the person leaves the service, those records must not be used as a new commercial profile, active decision memory or continuing agent authority. The remaining record and its purpose must be disclosed to the person. A person must not become a digital hostage who loses access to their data, money, content or ability to leave the platform because they challenged a decision. Data export must not be conditioned on withdrawal of the challenge or an unrelated additional payment. When inaccurate or unauthorised conduct is confirmed, correcting the decision label alone is not enough: continuing harm must be stopped; the correct state restored; connected scores, memories, risk records and external records corrected; and affected material decisions reopened.
Where inaccurate information about a person or institution was sent to customers, the public or other systems, the correction must not remain in a private case file. So far as possible, it must reach the same recipient group with comparable visibility. An apology, reactivation, general service credit or notice that ‘your case is closed’ is not, by itself, full redress. Redress must bring the person as close as possible to the position they would have occupied had the erroneous conduct not occurred.
If the original opportunity cannot be restored, the institution must consider an equivalent reassessment, a new opportunity, restored visibility, service remediation or appropriate material redress.
Direct costs, lost opportunities, service delays, reputational effects and the reasonable effort a person expended to correct the error may all be considered in assessing redress. Not every adverse outcome creates an automatic entitlement to payment, but there must be a genuine and reasoned route to review. If a root error may have affected others in the same class, the institution cannot stop at correcting the case of the person who complained. It must scan similar decisions, contact affected people proactively and implement collective correction. A request to challenge, stop, exit or seek redress cannot justify labelling a person difficult, suspicious, low-value, uncooperative or high-risk; degrading the service; raising the price; delaying the process; or taking any other retaliatory action.
The remedy process must be accessible to people across differences of language, disability, age and technical ability. It must not become a bot loop, an invisible form or a burden of proof the person cannot meet. The person must have one route to remedy with a clearly accountable owner. The institution cannot impose its chain of internal agents, departments, model providers, payment services and external platforms on the person. Every person has the right to receive a Remedy Receipt showing when the challenge was received, whether evidence was preserved, whether interim protection was applied, who reviewed the case and under what authority, which corrections were made, what could not be reversed and the current status of redress.
A person need not prevail in every challenge. But they cannot be silenced in the face of the system’s judgement, forced to wait while harm grows, held hostage in a service relationship or left alone with the effects of a verified error. The challenge is the person’s voice. Stopping gives that voice the power to affect conduct. Exit is the person’s withdrawal of agency. Redress requires the system to correct not only its own record, but also the outcome in the person’s real life.
A person can now know that a machine is acting, question the true rationale for its decision, challenge an error, stop continuing harm, leave a system they do not want and seek redress for the resulting material effects. But the final and most difficult question remains: Who must answer the challenge? Who is obliged to operate the stopping mechanism? If an external provider does not correct its record, who will stand accountable before the person? When an erroneous decision causes a loss of money, health, work or reputation, who will bear the burden of redress? Can the institution disperse responsibility by saying: ‘The model did it.’ ‘A sub-agent sent it.’
‘That is how the provider’s system operated.’ ‘A human pressed the final button.’ An AI system may have its own technical identity. A Decision Trail and Action Receipt may exist. But the machine did not set its purpose by itself, connect itself to the institutional account, or turn its own authority boundary into a legal order. It cannot accept residual risk on the institution’s behalf or compensate an injured person from resources of its own. A person’s route to remedy is complete only when a real institution and a real chain of human authority stand ready to assume responsibility.
The final founding provision of this series is therefore: ARTICLE 13 — AN INSTITUTION CANNOT TRANSFER RESPONSIBILITY TO A MACHINE

