Cybersecurity, explained for the rest of us.

General

AI Regulation and Your Rights: What You Can Actually Control

Margot 'Magic' Thorne@magicthorneAugust 14, 202611 min read
Illustrated scales balancing a human silhouette against an AI neural network diagram

AI decides whether you get the loan. Whether your resume makes it past the first screen. Whether you see the apartment listing or the higher price. The systems are everywhere, making consequential decisions about your life, and most of the time you don't even know they're running.

You have rights against these systems. Not many, not strong, and not consistently enforced, but they exist. Here's what the law actually protects, what you can demand, and how to use the tools you have.

The Legal Landscape: What Actually Exists

AI regulation in 2026 is a patchwork. The European Union passed the AI Act, which classifies AI systems by risk level and imposes requirements on high-risk applications. The United States has no federal AI law. Instead, you get state-level privacy statutes, sector-specific rules, and agency guidance that may or may not apply to your situation.

GDPR, the EU's data protection regulation, gives Europeans the right to object to automated decision-making and to demand human review of decisions that significantly affect them. California's CPRA, Colorado's CPA, and Virginia's CDPA offer similar protections, but the definitions are narrower and enforcement is newer.

The FTC has authority over unfair and deceptive practices, which includes AI systems that discriminate or mislead. The agency has issued guidance and brought enforcement actions, but the legal framework is built on general consumer protection law, not AI-specific rules.

What this means: your rights depend on where you live, what sector the AI operates in, and whether the company using it falls under a specific regulatory regime. There is no universal answer to "what are my rights against AI." The answer is always "it depends."

Right to Know: Disclosure Requirements

Under GDPR, companies must tell you when they use automated decision-making that produces legal or similarly significant effects. The disclosure requirement applies to decisions about credit, employment, insurance, and similar high-stakes contexts.

In practice, this means a line in the privacy policy. Something like "we use automated systems to evaluate applications." The disclosure is often vague, the policy is long, and the explanation of how the system works is minimal.

Some U.S. state laws require similar disclosure. California's CPRA gives you the right to know whether a business uses automated decision-making technology and to request information about the logic involved. Colorado and Virginia have comparable provisions.

The problem is enforcement. Companies disclose in ways that technically comply while revealing almost nothing useful. "We use machine learning to personalize your experience" tells you nothing about what data feeds the model, how the decision gets made, or what you can do about it.

What you can do: read privacy policies with a specific question in mind. Search for "automated," "algorithm," "AI," "machine learning," and "profiling." If the policy mentions automated decision-making, note what it says about your rights. If it says nothing, that's information too.

Right to Object: Opting Out of Automated Decisions

GDPR Article 22 gives you the right not to be subject to decisions based solely on automated processing when those decisions significantly affect you. This is the strongest protection in the current legal landscape, and it's limited to Europe.

The right has exceptions. Companies can use automated decision-making if it's necessary for a contract, authorized by law, or based on your explicit consent. In practice, most AI systems fall into one of these exceptions, which means the right to object is weaker than it looks on paper.

California's CPRA gives you the right to opt out of automated decision-making, but the law is new, the regulations are still being written, and enforcement hasn't caught up. Other states with similar provisions face the same gap between legal text and practical reality.

When you object, the company must either provide human review or stop using automated processing for your case. Getting to that point requires knowing the system exists, understanding your rights, and navigating a complaint process that most companies design to be opaque.

What you can do: if you're in the EU or a state with automated decision-making rights, file an objection when you encounter a consequential automated decision. Use the company's privacy request portal if one exists. If not, send an email to the privacy contact listed in the policy. Be specific: "I object to automated decision-making under [law] and request human review of [decision]."

Right to Explanation: Understanding the Logic

GDPR gives you the right to obtain meaningful information about the logic involved in automated decision-making. This is not the same as a right to a full explanation of how the AI works. It's a right to understand, in general terms, what factors the system considers and how it reaches decisions.

Companies interpret "meaningful information" narrowly. You might get a list of data categories the system uses. You might get a high-level description of the decision process. You will not get the training data, the model weights, or a step-by-step breakdown of why the system scored you the way it did.

U.S. laws are weaker here. California's CPRA requires businesses to provide information about automated decision-making logic, but the specifics are still being defined through regulation. Other states have similar provisions with similar ambiguity.

The practical barrier is that most AI systems are proprietary. Companies claim trade secret protection over the models, and courts have generally sided with companies when users demand detailed explanations. The right to explanation exists in theory. In practice, you get a summary that tells you less than you need to know.

What you can do: submit a data access request under GDPR or your state privacy law. Ask specifically for information about automated decision-making logic, the data categories used, and the factors that influenced the decision. You probably won't get everything, but you'll get more than if you don't ask.

Right to Human Review: Challenging Automated Decisions

When an AI system makes a decision that affects you, you have the right to request human review under GDPR and some U.S. state laws. This means a person, not the algorithm, reconsiders your case.

The effectiveness of human review depends on how it's implemented. If the human reviewer just looks at the AI's output and rubber-stamps it, the review is meaningless. If the reviewer has access to your full file, understands the decision criteria, and has authority to override the system, the review can actually help.

Most companies treat human review as a box to check, not a substantive reconsideration. The reviewer might spend 30 seconds on your case. They might not have training in the decision domain. They might not even know what data the AI used.

What you can do: when you request human review, document everything. Note the date you requested review, who you contacted, and what response you received. If the review upholds the automated decision, ask for specifics: what factors did the human reviewer consider? What information did they have access to? Did they review the same data the AI used, or did they rely on the AI's output?

If the review feels perfunctory, escalate. File a complaint with your state attorney general if you're in a state with automated decision-making protections. File with the FTC if you believe the process was deceptive or unfair. Enforcement is slow, but complaints create a record.

Sector-Specific Protections: Where Stronger Rules Apply

Some sectors have AI-specific rules that go beyond general privacy law. Employment, credit, housing, and healthcare all face additional regulatory scrutiny when AI enters the decision-making process.

The Equal Credit Opportunity Act requires lenders to provide reasons for credit denials. If an AI system denies your loan application, the lender must tell you the specific factors that led to the denial. This is stronger than the general right to explanation under privacy law, because it's tied to an existing anti-discrimination framework.

The Fair Housing Act prohibits discrimination in housing, which extends to AI systems that screen rental applications or set prices. If you believe an AI system discriminated against you in housing, you can file a complaint with the Department of Housing and Urban Development.

Employment decisions face scrutiny under Title VII and the Americans with Disabilities Act. If an AI screening tool filters out your resume, and you believe the filtering was discriminatory, you can file with the Equal Employment Opportunity Commission.

These protections are stronger than privacy law because they're backed by decades of enforcement and case law. The challenge is proving that the AI system caused the discriminatory outcome. AI makes discrimination harder to detect, because the decision process is opaque and the patterns are statistical rather than explicit.

What you can do: if you face an adverse decision in credit, housing, or employment, ask for the specific reasons. If the company uses an AI system, note that in your request. If you believe the decision was discriminatory, file a complaint with the relevant agency. Document the timeline, the communications, and any evidence of disparate treatment.

The FTC's Role: Unfair and Deceptive Practices

The FTC regulates AI under its authority over unfair and deceptive trade practices. The agency has brought cases against companies that made false claims about AI capabilities, used biased algorithms, or failed to secure AI systems properly.

In 2021, the FTC issued guidance warning companies that AI systems must be transparent, explainable, fair, and empirically sound. The guidance doesn't create new legal obligations, but it signals how the agency interprets existing law in the AI context.

The FTC has enforcement power, but it's reactive. The agency investigates after harm occurs, which means your individual complaint might not trigger action. But if enough people report similar issues, the FTC can build a case.

What you can do: if you believe an AI system harmed you through deceptive practices, false advertising, misleading disclosures, or promises the system didn't deliver, file a complaint at ftc.gov/complaint. Be specific about what the company claimed, what actually happened, and how you were harmed. The FTC aggregates complaints to identify patterns, so your report contributes to enforcement even if it doesn't resolve your individual case.

Data Access Requests: Your Strongest Tool

The most effective right you have is the right to access your data. Under GDPR, CPRA, and similar state laws, you can request a copy of the personal information a company holds about you. This includes data used to train or run AI systems.

A data access request forces the company to show you what they know. You'll see the data points the AI system used, which can reveal patterns you didn't expect. You might discover that the system relied on inaccurate information, or that it used proxies for protected characteristics, or that it drew inferences that don't match reality.

The request process varies by company. Some have automated portals. Others require you to email or submit a form. The law requires companies to respond within a set timeframe, 30 to 45 days in most jurisdictions, but enforcement of those deadlines is inconsistent.

What you can do: submit a data access request when you encounter a consequential AI decision. Use the company's designated process if one exists. If not, send an email to the privacy contact in the policy. Ask specifically for:

  • All personal data the company holds about you
  • Data used in automated decision-making systems
  • Information about the logic, significance, and consequences of automated processing
  • The source of any data not collected directly from you

Save the response. If the company provides incomplete information or misses the deadline, follow up. If they ignore you entirely, file a complaint with the relevant regulatory authority.

The Reality: Rights Without Enforcement

You have rights against AI systems. You can demand disclosure, object to automated decisions, request human review, and access your data. These rights exist in law.

The problem is enforcement. Regulatory agencies are understaffed, underfunded, and learning how to apply old laws to new technology. Companies comply minimally, interpreting obligations narrowly and designing processes that technically meet legal requirements while frustrating practical use.

This isn't a counsel of despair. It's a reality check. Your rights are real, but using them requires persistence, documentation, and realistic expectations. You won't get everything you ask for. You might not get anything. But exercising your rights creates a record, signals to companies that people are paying attention, and contributes to the slow accumulation of enforcement pressure that eventually changes behavior.

What to Do When AI Makes a Decision About You

When you encounter an AI system making a consequential decision, loan denial, job rejection, insurance rate increase, account suspension, follow this sequence:

  1. Document the decision. Save emails, screenshots, and any communication about the decision. Note the date, the claimed reason, and any reference to automated processing.

  2. Read the privacy policy. Search for terms like "automated decision-making," "AI," "algorithm," and "profiling." Note what the policy says about your rights.

  3. Submit a data access request. Ask for all personal data, data used in automated systems, and information about the decision logic. Use the company's process if one exists; otherwise, email the privacy contact.

  4. Request human review. If the decision is adverse, ask for a human to reconsider. Be explicit: "I request human review of this decision under [applicable law]."

  5. File complaints if needed. If the company ignores your requests, provides incomplete responses, or you believe the decision was discriminatory, file with your state attorney general, the FTC, or the relevant sector regulator (HUD for housing, EEOC for employment, etc.).

  6. Keep records. Save everything. Dates, names, communications, responses, and timelines. If you escalate, this documentation becomes evidence.

This process won't guarantee a different outcome, but it's the mechanism you have. Use it.

The Cultural Reference That Fits

In The Two Towers, Treebeard tells Merry and Pippin that Ents don't say anything unless it's worth taking a long time to say. The Entmoot, the gathering where Ents make decisions, moves slowly, deliberately, with full consideration of consequences.

AI regulation works like an Entmoot in reverse. The technology moves fast, consequences arrive before anyone's ready, and the legal system responds at geological speed. By the time regulators finish deliberating, the AI landscape has shifted three times over.

Your rights exist in that gap. The law says you can object, access your data, demand human review. But the infrastructure to make those rights meaningful, the enforcement, the clarity, the teeth, is still being built. You're exercising rights in a system that's only halfway to functional.

That doesn't make the rights worthless. It makes them incomplete. Use them anyway. Document, request, complain, escalate. The Entmoot is still in session, and every voice that speaks up moves the deliberation forward, even if the pace feels glacial.

What's Coming: The Regulatory Horizon

AI regulation is evolving. The EU AI Act takes effect in phases through 2026 and 2027, creating the first comprehensive risk-based framework for AI systems. High-risk AI, systems used in employment, credit, law enforcement, and critical infrastructure, faces mandatory requirements for transparency, human oversight, and accountability.

In the U.S., federal AI legislation is under discussion but hasn't passed. State laws continue to proliferate. Colorado, Connecticut, and Utah have passed AI-specific provisions in their privacy laws. More states will follow.

Sector regulators are moving faster than legislatures. The EEOC issued guidance on AI in employment. The CFPB is scrutinizing AI in lending. The FTC is bringing enforcement actions. These agencies are building case law that will shape AI regulation even without comprehensive federal legislation.

What this means for you: the rights landscape will improve, but slowly. Enforcement will get stronger as agencies gain experience and case law develops. Disclosure requirements will become more specific as regulators learn what "meaningful information" actually requires. But the gap between legal text and practical reality will persist for years.

In the meantime, you work with what exists. Know your rights, use them when it matters, and understand that the system is still being built around you.

Practical Steps You Can Take Now

You can't control the regulatory timeline, but you can control your own preparation. Here's what to do now, before you need it:

Know your state's privacy law. If you're in California, Colorado, Connecticut, Virginia, or Utah, you have data access rights and some protection against automated decision-making. Read a summary of your state's law so you know what to request when the time comes.

Identify high-stakes AI systems in your life. Credit scoring, employment screening, insurance underwriting, and social media content moderation all use AI. Know which systems affect you so you can monitor for adverse decisions.

Set up a documentation system. Create a folder, physical or digital, for AI-related decisions and communications. When something happens, you'll have a place to store evidence immediately.

Understand your sector-specific protections. If you're applying for credit, housing, or employment, know that you have stronger rights in those areas than in general consumer contexts. Familiarize yourself with the relevant agency (CFPB for credit, HUD for housing, EEOC for employment) and their complaint processes.

Practice reading privacy policies. Pick three services you use regularly and search their privacy policies for AI-related terms. Note what they disclose, what they don't, and whether they mention your rights. This builds the skill you'll need when it matters.

You have rights against AI. They're imperfect, inconsistently enforced, and often frustrating to use. But they exist, and using them is how the system gets better. Document, request, object, escalate. The process is slow, but it's the process we have.

Person reviewing a document with AI-related legal text visible on screen
→ Filed under
AIconsumer rightsprivacyregulationdata protection
ShareXLinkedInFacebook

Frequently asked questions

In some cases, yes. GDPR gives Europeans the right to object to automated decision-making, and some U.S. state laws offer similar protections. But enforcement is inconsistent, and many AI systems operate without clear opt-out mechanisms.
Under GDPR and a few U.S. state laws, companies must disclose automated decision-making that significantly affects you. In practice, disclosure is often buried in privacy policies, and 'significant effect' is poorly defined.
You can request human review under GDPR and some state laws. File a complaint with your state attorney general or the FTC if you're in the U.S. Document everything, but understand that enforcement is slow and outcomes vary.
The EU AI Act is the most comprehensive framework, classifying AI by risk level and imposing requirements on high-risk systems. U.S. regulation is fragmented across state laws and sector-specific rules, with no federal AI law as of 2026.
Under GDPR, you can request access to your data and information about the logic behind automated decisions. U.S. rights are more limited and vary by state, but data access requests are your strongest tool.

You might also like