The Individual Rights Response Obligation: Why the Right to Contestation in Enterprise AI Governance Requires Human Authority, Not Human Presence
Enterprise AI governance frameworks impose transparency obligations on AI systems affecting individuals: the right to know that a decision was made, the right to an explanation of how it was made, and the right to contest it. The right to contestation is recognised in the EU AI Act, the Australian Privacy Act, and sector-specific regulatory guidance. What the literature and regulatory frameworks do not resolve is what contestation requires at the level of the governance architecture. A survey of existing frameworks reveals that they impose the obligation to provide a contestation pathway without specifying two critical governance design questions: what authority the human reviewer must hold relative to the AI system’s output, and what independence that reviewer must maintain from the system whose decision is being contested. This paper identifies the unresolved design questions as the Contestation Authority Gap and the Reviewer Independence Problem, and argues that both are governance design problems that current frameworks leave structurally unresolved. The paper introduces the Individual Rights Response Obligation, a governance framework that operationalises the right to contestation as a substantive accountability mechanism rather than a procedural compliance obligation. The framework rests on three governance design principles. First, the Human Authority Principle: the human reviewer in a contestation process must hold full authority to uphold, modify, or overturn the AI system’s decision, without constraint from the system’s output, the system owner’s commercial interest, or the organisation’s operational preference. Second, the Independence Requirement: the human reviewer must be structurally independent from the team that designed, deployed, and operates the AI system being contested. Independence is not a matter of seniority or good faith. It is a structural property of the reviewer’s position relative to the system whose decision is under review. Third, the Burden Allocation Principle: the burden of demonstrating that an AI system did not make, or materially contribute to, a decision affecting an individual rests with the organisation, not the individual. An individual who asserts AI involvement in a decision affecting them has submitted a valid contestation request regardless of whether they can technically identify the system involved. The paper analyses six major governance frameworks and regulatory regimes, demonstrating that none fully specifies the authority level, independence structure, or burden allocation that the right to contestation requires as a matter of governance design. The paper introduces the Contestation Completeness Standard, a set of four criteria against which the adequacy of a contestation architecture may be assessed, and applies it to existing frameworks.
Paper
The full text of this publication is not hosted on 44B due to licensing.
Read it at OpenAlex