Research
Explainable AI for the EU Right to Explanation: A Systematic Review of the Law-XAI Translation Gap
Overview Research area: The intersection of EU law and Explainable AI (XAI) — specifically whether technical explanation methods can satisfy the legal Right to Explanation under the GDPR, the AI Act (
- arXiv
- 2608.02699
- Published
- 2026-08-03
- Authors
- Benjamin Fresz, Elena Dubovitskaya, Marco F. Huber
AI summary
Overview
Research area: The intersection of EU law and Explainable AI (XAI) — specifically whether technical explanation methods can satisfy the legal Right to Explanation under the GDPR, the AI Act (AIA), and the Consumer Credit Directive (CCD).
Technical level: Intermediate. The paper presumes no deep legal training, but it engages closely with normative legal doctrine (provisions, recitals, CJEU case law) alongside XAI method taxonomy, which will be dense for complete newcomers to either field.
Scope (one sentence): A PRISMA-based systematic literature review of papers published from 2024 onwards that examine the implementation of the EU Right to Explanation via XAI, covering 2,643 initially identified records and 19 fully included studies.
What This Paper Is About
EU law grants people a Right to Explanation when algorithms make or influence consequential decisions about matters such as loan eligibility, hiring, or healthcare, but it remains poorly understood whether and how XAI methods can actually deliver explanations that satisfy that right. The authors systematically review the post-AIA literature to see how well legal and technical perspectives are integrated, and find that most work misgrounds the legal basis, conflates distinct legal dimensions, and omits recent case law. The paper responds by proposing the Addressee/Purpose Framework, a four-phase blueprint for operationalization, and six concrete open research questions.
Key Contributions
- A norm-dogmatic derivation of the Right to Explanation in Art. 15(1)(h) GDPR, Art. 86 AIA, and Art. 18(8)(a) CCD, intended to resolve widespread and consequential confusion over the right's legal basis.
- Evidence of limited interdisciplinary integration: of 2,643 surveyed records, only 57 met the requirements for full-text screening, of which 19 papers demonstrate meaningful engagement with both the legal and technical domains.
- Documentation of problematic patterns in the literature, including imprecise grounding of the GDPR Right to Explanation, unrealistic expectations that laws provide technical detail, and the omission of recent case law — the latter likely an artifact of publication timing.
- The Addressee/Purpose Framework, a conceptualization that the addressee of an explanation determines its required form while the purpose determines its content, plus a four-phase blueprint for operationalization that marks where each of the six open research questions currently blocks progress.
Main Findings
- Misidentified legal basis is the norm: Most reviewed papers derive the GDPR Right to Explanation from Art. 22 GDPR, sometimes with Recital 71, rather than from Art. 15(1)(h) GDPR. Some refer exclusively to Recital 71 despite recitals not being binding provisions. Only a small number of works provide a correct norm-dogmatic grounding (Fresz et al. 2024; Juliussen 2025; Sapienza and Palmirani 2026; Häuselmann 2025; Škorjanc 2025).
- Slow uptake of the Dun & Bradstreet judgment: Among the 14 papers published in 2025 and 2026, only five take the CJEU's Dun & Bradstreet judgment into account, although it was delivered early in the year on February 27. Newer papers were more likely to include it, pointing to the slowness of scientific publishing as the main reason for the omission.
- Form and content are conflated: The literature tends to merge two legally distinct dimensions. Art. 12(1) GDPR governs the form of an explanation (concise, transparent, intelligible, easily accessible, clear and plain language), while Art. 15(1)(h) GDPR, Art. 86 AIA, and Art. 18(8)(a) CCD govern its content. The CJEU confirmed both dimensions must be fulfilled simultaneously and independently.
- The Consumer Credit Directive is largely ignored: The new CCD Right to Explanation is mentioned in only two of the surveyed papers (Engelfriet 2025; Škorjanc 2025), even in contributions that engage with consumer protection, cite credit denial as an example, or are based on a study explicitly concerned with credit decisions. Conversely, papers focused on GDPR and AIA commonly do not refer to the CCD.
- Art. 86 AIA is mentioned but not always used for the right: 13 papers mention Art. 86 AIA. Some authors do not engage with the Right to Explanation because they conceptualize explanations differently — as institutional accountability, as a device for liability attribution, or as a procedural precondition for judicial protection. Papers that do examine the right under the AIA correctly derive a decision-specific Right to Explanation from Art. 86(1).
- Exclusion breakdown: Of the 57 full texts assessed, 38 were excluded — 18 for limited coverage of AIA and/or GDPR, 5 for irrelevant or outdated laws, and 15 for insufficient XAI content — leaving 19 included.
- XAI methods are classified three ways in the corpus: broad categories (most commonly post-hoc versus ante-hoc/interpretable), explanation format (e.g., counterfactual or feature importance), and lists of desiderata (Fresz et al. 2024 using the Co-12 properties from Nauta et al. 2022 augmented by five process-properties; Colmenarejo et al. 2025 deriving five desiderata from three technical publications). The different underlying bases impede direct comparison, and properties such as Correctness or Fidelity/Faithfulness lack established quantification methods.
- Post-hoc explanations are widely judged insufficient: Reviewed papers agree that post-hoc XAI outputs may seem reliable and convincing but are not easily understood by end users and do not necessarily conform to the model or the decision. Engelfriet (2025) proposes the term "principal reason fallacy" — the belief that every algorithmic decision can be traced back to a single, stable, human-interpretable rationale.
- Risk of suboptimal explanations under legislative pressure: Chung et al. (2024) argue that legislative pressure will lead companies to use and trust suboptimal XAI explanations. Moreira et al. (2025) argue that regulatory requirements imply verification of XAI methods, and that a false explanation may cause more damage than no explanation at all.
- A study of lawyers as laypeople: State et al. (2025) presented SHAP visualizations as explanations for credit decisions to test subjects who were lawyers. They had difficulties understanding them and unanimously preferred textual over graphical explanations. The authors conclude commonly used XAI explanations are often ill-suited for exercising data subject rights — though the review notes the study misses that such explanations fail Art. 12(1) GDPR.
- The "justification" concept is used inconsistently: Colmenarejo et al. (2025), Górski and Ramakrishna (2025), and Engelfriet (2025) each use "justification" differently. The authors argue it is crucial to recognize that the three provisions concern explanations rather than the lawfulness of decisions as such; an explanation is not itself proof that a decision is lawful.
- Distinct information needs across legal contexts: Kästner et al. (2026) distinguish three liability questions — which inputs caused the harmful output (classical XAI), which functional components or circuits were causally decisive (mechanistic interpretability), and which training data or design decisions led to the harmful behavior (analysis of the system's overall history). Engelfriet (2025) proposes explanations with four parts: statistical transparency, distributive contextualization, normative linkage, and contrastive actionability.
- The state-of-the-art argument is rejected: Juliussen (2025) argues legal explanation requirements scale with the state of the art. The authors call this position untenable: where law requires intelligible explanations and a black-box model cannot provide them, the system must not be deployed.
- Legal details supplied by the review: Art. 86 AIA is subsidiary under Art. 86(3) and limited to certain high-risk AI systems under Art. 6(2) and Annex III. It was originally scheduled to apply from August 2, 2026, but the Digital Omnibus Act postponed this to December 2, 2027 (standalone systems) or August 2, 2028 (systems embedded in regulated products). Art. 18(8)(a) CCD 2023 (2023/2225/EU) becomes applicable on November 20, 2026 following Member State transposition, and covers cases where automated processing is only one component of the creditworthiness assessment — broader than the GDPR, which requires a decision based solely on automated processing.
Methodology in Plain English
The authors followed the PRISMA methodology for systematic literature reviews. They searched two bibliographic databases, Web of Science and Scopus, using a deliberately broad search string that combined explainability-related terms with the names of EU legal instruments. After deduplication and removal of patents, 2,643 records remained. Title and abstract screening was carried out with the ASReview tool, followed by a validation check that surfaced no additional records, leaving 60 articles for full-text retrieval. Of those, 57 were assessed for eligibility by two reviewers — one with a technical XAI background and one with a legal background — applying predefined inclusion and exclusion criteria.
The criteria included English or undefined language, publication in 2024 or later, and publication as a book or in a journal or conference. Papers had to discuss a group of applications rather than implement one specific AI application, explicitly mention XAI and discuss suitable methods, and engage with the legal bases on the Right to Explanation, especially Art. 15 GDPR and/or Art. 86 AIA and corresponding case law. Outdated legal bases, patents, and frameworks not aligned with the AIA or GDPR were excluded. Nineteen records matched all inclusion criteria. The paper states that search strings, screening procedure, stopping criterion, and validation sample are in Appendix A, with a PRISMA flow diagram in Figure 1, and a property overview in Appendix B. The content provided does not detail the individual phases of the four-phase blueprint or enumerate the six open research questions, as the text is truncated within Section 5.1.
Why This Matters
Impact on research. The review supplies a corrected legal baseline for future interdisciplinary work, arguing that the Right to Explanation has a firm basis in Art. 15(1)(h) GDPR, settled at the latest by the CJEU's Dun & Bradstreet judgment. It warns that the current blurring may create the false impression that the GDPR right is weak or exists only alongside the AIA right. It also names where the field is blocked: the Addressee/Purpose Framework is presented as a shared basis for discussion and concrete design guidance for practitioners developing legally compliant XAI systems.
Real-world applications. Art. 86 AIA covers certain high-risk AI systems in areas the paper names:
- Creditworthiness assessment and consumer credit decisions, where Art. 18(8)(a) CCD provides a specific Right to Explanation from November 20, 2026.
- Employment and hiring decisions, where affected individuals need information to contest outcomes.
- Healthcare, life and health insurance, and emergency services, where high-risk systems can significantly impact health, safety, or fundamental rights.
- Education and law enforcement, which are among the areas listed as covered by the high-risk classification under Art. 6(2) and Annex III.
Industry relevance. Deployers and providers of high-risk AI systems face deadlines of December 2, 2027 (standalone systems) and August 2, 2028 (systems embedded in regulated products) for Art. 86 AIA. The paper argues that technical standards, not legislation, are meant to provide the technical detail for compliance, and that while no explicit legal boundary is drawn between LLMs and other models, the General-Purpose AI provisions (Art. 51 AIA et seq.) are primarily aimed at LLMs and image-generation models. The claim that LIME and SHAP suffice for provider-deployer relationships is stated to be directly contradicted by the Addressee/Purpose Framework.
Future Directions
- Define what counts as the "main elements" of a decision. The paper states this remains unclear under Art. 86 AIA and expects the CJEU to interpret it in disputes similarly to the Dun & Bradstreet ruling.
- Close the operationalization gap. Even correctly identified legal requirements cannot currently be translated into verifiable XAI specifications; the six open research questions identified by the authors are described as blocking progress at specific points of the four-phase blueprint.
- Resolve how accuracy and intelligibility interact. Art. 12(1) GDPR gives rise to two potentially conflicting requirements, and one proposal cited in the review would grant the controller a margin of discretion in choosing the form of presentation, with a violation assumed only for manifestly inaccurate or unintelligible information.
- Settle the analytical status of "justification." The authors question whether the concept adds analytical value in the context of explanations or instead risks generating confusion, given that the three legal provisions concern explanations rather than the lawfulness of decisions.
- Develop and verify XAI quality standards. Multiple reviewed works call for regulations or standards that define and evaluate XAI methods; the authors observe that the two closest-to-operationalization frameworks frame requirements only as qualitative soft requirements that cannot be quantified.
Target Audience
This paper is most valuable to interdisciplinary researchers working at the law-XAI boundary — particularly those who write about the Right to Explanation and need an accurate statement of its legal basis across the GDPR, AIA, and CCD. It also serves legal scholars and policy analysts tracking the implementation of Art. 86 AIA and Art. 18(8)(a) CCD, XAI researchers who want to understand which properties actually matter for legal purposes, and practitioners, compliance officers, and standards developers seeking a structured design principle for legally compliant XAI deployments in high-risk domains such as credit, employment, and healthcare.
Authors’ abstract
When algorithms make or influence consequential decisions---about loan eligibility, hiring, or healthcare---EU law grants affected individuals a Right to Explanation. Yet whether (and how) Explainable AI (XAI) can satisfy this right in practice remains poorly understood, with direct implications for individuals' ability to contest automated decisions that affect their lives. This paper presents a systematic literature review of XAI in the context of the EU Right to Explanation, with particular focus on Art. 15(1)(h) GDPR, Art. 86 AI Act (AIA), and related instruments. We consider papers published from 2024 onwards, as the final version of the AIA was published in July 2024---with Art. 86 being added late. From 2643 initial records identified by a deliberately broad search, we review 57 full texts, of which only 19 papers demonstrate substantive integration of both legal and technical perspectives, showing gaps in the interdisciplinary synthesis of the current regulatory framework. We document three problematic patterns across the corpus: Most misidentify the GDPR legal basis; few engage with the CJEU's Dun & Bradstreet judgment (likely due to publication timing); and the distinction between explanation form (governed by addressee) and content (governed by legal purpose) is often conflated. We conceptualize this as the Addressee/Purpose Framework, propose a four-phase blueprint for operationalization, and identify six concrete open research questions. Without further progress, the Right to Explanation risks remaining a formal obligation without a technically realizable path to compliance.