An employee asks why her role cluster leads to one target role and another does not. The question is not rhetorical. It is a claim. Since 2 August 2026 it sits in the AI Act, it runs against the company using the system, and the usual way out does not work on it.
The wording
Article 86 (1) of Regulation (EU) 2024/1689 reads, in the German text:
„Personen, die von einer Entscheidung betroffen sind, die der Betreiber auf der Grundlage der Ausgaben eines in Anhang III aufgeführten Hochrisiko-KI-Systems [...] getroffen hat und die rechtliche Auswirkungen hat oder sie in ähnlicher Art erheblich [...] beeinträchtigt, [...] haben das Recht, vom Betreiber eine klare und aussagekräftige Erläuterung zur Rolle des KI-Systems im Entscheidungsprozess und zu den wichtigsten Elementen der getroffenen Entscheidung zu erhalten."
In English: any affected person subject to a decision taken by the deployer on the basis of the output of a high-risk AI system listed in Annex III, other than the systems in point 2 of that Annex, which produces legal effects or similarly significantly affects them in a way they consider to adversely impact their health, safety or fundamental rights, has the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken.
Whether a given system falls under Annex III at all is a separate question, handled elsewhere on this site. This piece is about the two questions that come after it: who owes the explanation, and from when.
Who owes it
The word deployer appears twice, and the word provider appears nowhere. The claim runs against whoever puts the system to use, meaning the company, not the maker of the software.
That is the line with the most practical consequence. A procurement contract in which the vendor promises explainability does not move the duty. It helps you perform it, which is a different thing. If the answer does not come, it is the deployer who is in the dispute, and „our supplier cannot give us that" describes a contract problem, not a defence against the claim.
From that follows a question that belongs in selection rather than in operation: can I explain, out of this system, what it contributed to a decision, without asking the vendor? If the answer is no, you have outsourced a duty that cannot be outsourced.
Why Article 22 GDPR does not carry this
The obvious place to look for a right to an explanation about machine assisted decisions is Article 22 GDPR. It does not carry this situation, and it fails on a single word.
Article 22 (1) GDPR gives the data subject the right
„nicht einer ausschließlich auf einer automatisierten Verarbeitung [...] beruhenden Entscheidung unterworfen zu werden, die ihr gegenüber rechtliche Wirkung entfaltet oder sie in ähnlicher Weise erheblich beeinträchtigt."
That is: not to be subject to a decision based solely on automated processing which produces legal effects concerning them or similarly significantly affects them.
Solely. As soon as a person reviews the recommendation and takes the decision, it is no longer based solely on automated processing, and Article 22 does not apply. In a qualification initiative that is the normal case: the system proposes, the department decides. Building in human involvement as a safeguard switches Article 22 off by design.
Article 86 is built the other way round. It presupposes the human decision: the decision is one the deployer „has taken", and taken „on the basis of the output" of the system. The person in the procedure is not a ground for exclusion here, it is part of the trigger. So the relief that works against Article 22 GDPR does not work against Article 86.
The two sit side by side without overlapping. Article 86 (3) says the article applies only in so far as the right in paragraph 1 is not otherwise provided for under Union law. Where Article 22 GDPR genuinely applies, meaning the narrow solely automated case, Article 86 steps back. Where it does not apply, because a human decided, Article 86 remains.
Since when
Article 86 sits in Chapter IX Section 4 of the Regulation, headed „Remedies". That is the decisive fact for its application date.
Article 113 sets the general date of 2 August 2026 and makes exceptions from it. Point (a) covers Chapters I and II, point (b) covers Chapter III Section 4, Chapter V, Chapter VII and Chapter XII plus Article 78, point (c) covers Sections 1, 2 and 3 of Chapter III, and the point (d) added by Regulation (EU) 2026/1744 covers Articles 102 to 110.
Chapter IX appears in none of those exceptions. The general rule therefore applies to Article 86, meaning 2 August 2026. And the amending Regulation 2026/1744, which reworked Article 4, Article 99 and Article 113, does not mention Article 86 anywhere. The claim has been neither postponed nor amended.
The tension this piece is actually about
Two dates now sit next to each other that do not fit together.
The right to an explanation has been running since 2 August 2026. The obligations from which an explanation is produced in the first place apply, for Annex III systems and after the amendment by Regulation (EU) 2026/1744, only from 2 December 2027. Chapter III Sections 1 to 3 carry exactly the material an explanation feeds on: risk management, data and data governance, technical documentation, record keeping, transparency and provision of information to deployers, human oversight.
So for roughly fifteen months there is a right to an explanation of a system that is not yet required to be documented in the way that would yield one. That is not a quibble. It follows from the postponement having been applied to the obligations and not to the remedies.
What follows in practice can be said without forecasting: anyone waiting for the vendor to supply the Chapter III material may be waiting past the point at which they have to answer. Whether and how the right is enforced in this window is open, and we assert nothing about it. The question a business can answer today is a different one: could we explain it, if somebody asked?
What an explanation has to carry
The text names two subjects, and both concern the decision rather than the model:
- the role of the AI system in the decision-making procedure, meaning what the system contributed and what it did not
- the main elements of the decision taken, meaning what it actually turned on
That is answerable without exposing the internals of a model. What is required is not an account of the architecture but information about an event: what the system output, what else fed in, and who decided.
One detail worth knowing, because summaries tend to lose it: recital 171 speaks of a decision based „predominantly" on the output. That „predominantly" does not appear in the enacting text, which says simply „on the basis of the output". A recital does not narrow the enacting text. Anyone resting their position on the system having been only one element among several is resting it on a threshold the article does not contain.
The limits written into the article itself
Paragraph 2 excludes uses for which exceptions or restrictions follow from Union or national law. Paragraph 3 is the subsidiarity to other Union law noted above. And the trigger itself excludes the systems listed in Annex III point 2, meaning critical infrastructure; employment sits in point 4 and is not affected by that carve out.
What a business can take from this
The duty falls on you and not on your vendor, it does not depend on whether a human took part in the decision, and it is already running. What can be derived from that is unspectacular and therefore doable: record, per case, what the system output and what a person added. Whoever keeps that can answer, regardless of how far the vendor's documentation has progressed.
One temptation is worth naming. The observation that your own analysis works at role level is not an answer to Article 86. A statement about a role cluster can still feed into a decision about an individual, and it is then that decision which has to be explained. QualiShift discloses the weighting of its criteria in the Company Workspace and makes every assignment traceable to its source. That is material for an explanation. It is not the explanation, and it is not an exemption from it.
What this piece does not do
This piece is not legal advice. It sets out the wording and places the application dates. Whether a specific system falls under Annex III, who is the deployer in a given case, and what an explanation has to look like in a dispute, belongs with the people who own those questions in house.
Sources
- Regulation (EU) 2024/1689 (AI Act), Article 86, Article 113 and recital 171.
- Regulation (EU) 2026/1744 of 8 July 2026, Official Journal of the European Union, L series 2026/1744 of 24 July 2026.
- Article 22 of Regulation (EU) 2016/679 (General Data Protection Regulation).
