How the scores are reached
This page explains what we measure, how we score it, what counts as evidence, and why each system in the first edition received the readings it did. It is written for readers, companies and researchers who want to check our work. It does not include our internal coding sheets, but everything needed to reproduce a score from the cited sources is here.
We take one decision a machine made about one person: a loan, a claim, a job application, a rental, a benefit, a surveillance alert. We follow that person through eight moments, from the data being collected to the moment they could walk away, and at each moment ask what they could actually do. We score each answer from 0 to 4 using public documents only. We score the company's own staff the same way. The gap between the two numbers is the finding. If a document is missing we say "not shown" rather than guessing, and the company gets to reply before we publish.
What the index is for
The index is not in itself the project's goal. The project exists to establish recourse standing as a term the law can use, to document the cases that show where standing is missing, to change three things in law through the Not Final campaign, and to give people a practical way to use the rights they already have. The index serves those aims: it is the evidence that rights on paper stop working at particular steps in particular deployments, and it is the thing a lawmaker, a regulator, a journalist, or a court can check. Because it serves as evidence, it is built to the strictest standard we can meet: a public codebook, several coders, a disagreement log, a right of reply, and a corrections log. That rigor is what lets a small research project speak in a rulemaking or a courtroom; scoring companies is not an end in itself. The index is also the step that makes collective action possible: a documented, comparable score for a deployment is what a group of affected people, a legal aid clinic, or a regulator can act on together, enabling collective action where a single, isolated complaint could not.
What is measured
We measure the position of one person in one decision made about them by or with an automated system. We call that position "recourse standing": the standing a person in fact holds to seek and obtain reconsideration of the decision, as distinct from the rights the law grants on paper. It is scored along seven powers, each asked at eight steps of the decision path.
The best objection to the term, and our answer
Standing, in American and English law, is the doctrine that decides who may bring a claim before a court. Using it for internal appeals, help-center routes and regulator complaints stretches the word. We use it anyway for two reasons. First, the ordinary legal phrase "standing to complain" has always reached beyond courts, and the question we ask is exactly that one: from what position can this person complain and be heard. Second, no other word carries both halves of what is measured: the position (standing) and the relief sought (recourse). "Contestability" describes the system; "due process" describes the law; neither names the person's position in a particular deployment. Readers who prefer "standing to contest" will find the definition identical.
The recourse standing test
Recourse standing is not a label. It is a test with three elements, each of which can be applied, cited and contested. A deployment passes the test only if all three hold for the affected person.
1. Symmetry
In plain words: we look at both sides. If the company's staff can change the decision and you cannot, that counts against the system.
Meaningful human involvement cannot be established by looking at one side of a decision. Both the operator and the affected person are scored on the same scale at the same steps, and the difference is published as the Human Option Gap. Where the operator holds full standing and the person holds almost none, the human in the loop belongs to the institution, not to the person, and, on our reading of the GDPR, of Colorado's law and of the UK Information Commissioner's draft guidance, the requirement of meaningful human involvement is not met. A large gap is treated as an indicator of nominal oversight; a small gap with both sides low is treated as the absence of any human option, which is worse.
2. Silence
In plain words: if we cannot find a document, we do not assume the worst. We mark it "not shown" and the company can send the document.
The absence of a public record of a mechanism is neither proof that it exists nor proof that it does not. It is recorded as not demonstrated, excluded from averages and reported as a count. The burden of showing that the mechanism exists lies with the party that deployed the system, which can discharge it with a single document through the right of reply. A mechanism that the record or the structure of the deployment shows cannot exist is scored 0. The rule separates what is unknown from what is absent, and it places the evidentiary burden where the information is.
3. Practical effect
In plain words: an appeal only counts if it can change the outcome. A button that leads nowhere scores low.
Recourse is scored by what it can change, not by whether it exists. A route to reconsideration counts to the extent that it is practical and effective rather than theoretical or illusory, the standard the European Court of Human Rights set for Convention rights in Airey v. Ireland (1979) and has since applied to the right to an effective remedy. Recourse depth runs from 0, no meaningful recourse, through automated reconsideration and human review without authority, to human review with authority to change the outcome and, at 4, independent or external contestability. An appeal button, a reviewer who cannot overturn, or a court that will not hear the case do not reach the higher rungs.
The three elements are borrowed from settled law and applied to a new object: symmetry from the requirement of meaningful human involvement, silence from the ordinary allocation of the burden of proof, practical effect from the Strasbourg principle that rights must be practical and effective. What is new is their combination into one measurement of a person's position in a documented automated decision, and the findings that only the combination produces: decisions in which nobody had a human option, recourse granted to the buyer of a system rather than to the person screened, a jurisdiction that leaves the affected person without a forum, a human in the loop who amplified the model's bias, and a city ordinance that measurably created standing where none had existed.
The seven powers
| Power | The question | What a 4 looks like | What a 0 looks like |
|---|---|---|---|
| Understand | Does the person know a machine took part and why it decided what it did? | Notice before the decision, specific reasons after it | No notice; the person cannot tell a machine was involved |
| Choose | Is there a non-automated path at comparable cost, speed and quality? | A human path offered on the same terms | No alternative, or one that is markedly worse |
| Influence | Can the person add context or evidence before the decision is final? | An invitation to supply information that is considered | The decision is made before any contact |
| Challenge | Is there an appeal that can actually change the outcome? | Appeal with deadlines, a substantive answer and real reversals | No appeal, or an appeal that cannot change anything |
| Control | Is there a person with authority to stop or override the system? | A named role with documented override authority | Nobody can override, or the human is nominal |
| Data | Can the person see, correct, limit and move the data used? | Access, correction and deletion rights that work | Data invisible and uncorrectable |
| Exit | Can the person refuse the automated path, and what does it cost? | Exit without losing the service, history or standing | Exit means losing the job, the benefit or the road |
The eight steps
- Data collection: what enters the system and whether the person can see it.
- Assessment: whether the person is told a machine took part.
- Decision: who holds final authority and whether they can override.
- Notification: whether the person learns a decision was made.
- Explanation: whether reasons are specific enough to act on.
- Correction: whether wrong data can be fixed before it counts.
- Review and appeal: how deep recourse goes.
- Exit: whether the person can refuse the automated path and at what cost.
The scale
What each score means at each step, with real-world examples, is set out in the codebook. The summary:
| Score | Meaning |
|---|---|
| 4 | The power exists in practice and is documented in a binding or operational source. |
| 3 | The power exists but is limited: partial, conditional, or documented only in general terms. |
| 2 | The power exists on paper with weak evidence that it works, or works only through an outside route. |
| 1 | A trace of the power: a route that is slow, indirect or rarely usable. |
| 0 | The power is shown to be absent, by the structure of the deployment or by a documented statement. |
| ND | Not demonstrated. Public sources are silent. ND is excluded from averages and reported as a count. |
Recourse depth uses its own five-point scale: 0 no meaningful recourse, 1 automated reconsideration, 2 human review without authority to change, 3 human review with authority, 4 independent or external contestability. Exit friction is scored on the same 0 to 4 logic: 4 means leaving costs nothing that matters, 0 means leaving means losing the thing the decision was about.
What counts as evidence
| Tier | Sources | What it can do |
|---|---|---|
| A | Terms and user agreements, privacy policies, securities filings, regulator decisions and fines, court records and settlements, device labels and clearance letters, public contracts, transparency portals, statutes and rules | Supports any score |
| B | Interfaces, help pages, appeal workflows, manuals, screenshots | Supports any score |
| C | Company blogs, press releases, marketing, executive statements | Context; cannot alone support a score above 2 |
| D | Academic studies, regulator investigations, complaint databases, reporting by established outlets, civil society investigations | Can lower a score or confirm absence; can support a positive score only when it quotes a Tier A document |
| E | Researcher inference | Never supports a positive score |
Missing evidence is not evidence of absence. If we cannot find a mechanism, we write ND. If a document or a structural fact shows it cannot exist, we write 0. The difference matters: a company can turn an ND into a score by pointing us to a document.
How the gap and the weakest step are computed
Each role in a deployment gets an average of its numeric step scores, ND excluded, expressed on a 0 to 100 scale. The Human Option Gap is the operator's average minus the affected person's average. A gap of 30 means the institution holds 30 points of power over that decision that the person does not.
The operator is scored under the same rules as the person. In most profiles the operator's authority is documented in a device label, a policy or a contract, and the score records documented authority, not observed practice; profiles carry the note "documented authority, practice not observed" where no independent source shows the authority being exercised. The record itself is asymmetric: in the first edition, ND appears on the person's side in 12 of 20 profiles and on the operator's side in none. That asymmetry is a finding about what companies publish, and it is reported as such rather than hidden in the averages.
An average can hide a fatal step. A person who is never told that a decision was made cannot use an appeal, however good the appeal is. Every profile therefore also reports the person's weakest step and its score. Where the weakest step is 0 at notification, explanation or reaching a person with authority, the profile is marked "standing blocked" regardless of the average. Live deployments and closed cases are reported in separate tables and are never averaged together.
The scale anchors for every step, with examples from the first edition, are in the codebook.
What the index is not
The index is not a position against automation. Many decisions score better when software makes them, and the index says nothing about accuracy, fairness or safety, which other measures cover. It measures one thing: whether the person a decision is about keeps a practical way to be told, to be heard, to correct the record and to reach someone who can change the outcome. A high score is available to any deployer, public or private, that provides those things. The project is nonpartisan, takes no position on immigration, policing, insurance or labor policy beyond the three asks of the Not Final campaign, and accepts no funding from companies it assesses or from political parties or campaigns.
One model, many deployments
The unit of the index is a deployment, not a model. The same underwriting model can run inside ten lenders, and each lender decides what the applicant is told, who can override, and how an appeal works; the model contributes to steps 1, 2 and 5 (what data enters, whether its role is disclosed, what reasons it can produce), while steps 3, 4, 6, 7 and 8 belong to the institution that deploys it. A vendor therefore never receives a score of its own. Where only vendor documents exist (Zest AI, Aidoc outside a named hospital), the profile is marked "not ranked" until a deployment can be documented, or the vendor's documentation is scored as the operator's upper bound with the note "documented, not observed". Where a deployer uses several models in one decision path, the path is scored once, because the person meets one decision, not several models. This is also why the index can score a system in Seattle and the same system elsewhere and get different numbers: the law changed the deployment, not the model.
What the first edition covers, and what it does not
The first edition scores deployments in the United States and Europe. This is a choice forced by the method: the scale measures rights in practice against rights in law, and where the law gives no right to notice, explanation or review, every step scores 0 by definition and the profile says nothing about the deployment that a reader could not already infer. Brazil (LGPD, Article 20), Australia (disclosure duties from December 2026), Quebec and other jurisdictions with a statutory right to review are planned for the second edition, one deployment each. Countries without such a right are covered by the request letter tool, which asks the six questions regardless, and by the stories library.
Right of reply, corrections, funding
How the first edition was coded: Data are collected and verified jointly by AI and several human coders; verification, and every addition to the dataset, is always checked by a human. The sequence for the first edition: an AI-assisted first reading of every case from the cited public documents; a line-by-line verification of that reading by human coder 1 against each document; an independent second pass by a separate AI system, whose disagreements with the first reading are recorded for publication; a review pass by human coder 2 under the codebook rules; a second human pass by coder 1 after the evidence archive is completed; and further independent human passes by additional coders, at least two per edition, added as the team grows. Where two passes differ by one point the lower rounding rule applies and the simple average is published alongside; larger differences go to a third coder; the disagreement log for the edition is published with the resolved scores in October. Until then, published scores carry the mark "first reading". This is the practice of established public-evidence ratings: the Human Rights Campaign's Corporate Equality Index publishes unverified ratings from public records alongside verified ones, Ranking Digital Rights and the Future of Life Institute's AI Safety Index publish versioned scores that change after review, and every such rating carries a right of reply and a corrections log. The Human Option follows the same rules.
From the second edition, the order changes. Case files are assembled jointly by a human coder and an AI research assistant, not by AI alone: the human selects the deployment, locates and saves the primary documents, and writes the claim for each step; the assistant searches for additional public records and drafts the evidence lines, which the human checks against the saved documents before anything enters the file. Scoring then runs in three passes: a human coder scores first; an AI system scores independently, without seeing the human scores, and records its reasoning for every score; the human coder then reviews the AI scores and the reasoning line by line, keeping, revising or rejecting each one with a note. Reconciliation, the third coder, the disagreement log, the right of reply and the corrections log apply as above. Every score published from the second edition onward has therefore been set by a human, checked against an independent machine reading, and checked again by a human.
Every profile is built from public records and needs nothing from the company. Every company or agency receives its full file and has ten business days to reply; the reply is published with the profile. A reply that supplies Tier A or B evidence changes the score; a reply that argues without documents is published and the score stands. For the first edition, files were sent on the day of publication. From the second edition, files go out ten business days before publication.
Corrections are logged publicly with the date and the change. Profiles carry version numbers.
The Human Option accepts no funding from companies it assesses. Paid assessment services, if offered, are provided by a separate team and cannot change a published score. This policy appears on every profile.
Why each system scored what it did
First readings, from public documents, before two-coder validation and right of reply. Sources are named in each note.
Upstart
Applicable law: Equal Credit Opportunity Act and Regulation B (specific reasons within 30 days); Fair Credit Reporting Act (dispute rights, adverse action based on a consumer report); CFPB Circulars 2022-03 and 2023-03 on adverse action reasons from complex models; from 1 January 2027, Colorado SB 26-189 for Colorado applicants, with the Attorney General's draft ADMT rules of 11 August 2026 setting the content of notices and review.
Why explanation is 3, not 4. Federal law requires specific reasons and Upstart publishes that it derives them from per-applicant feature contributions. That is strong. It falls short of 4 because the reasons are not counterfactual: they say what weighed against the applicant, not what would change the outcome, and we have not yet verified sample notices.
Why notification is 4. The adverse action notice is a legal requirement with a thirty-day clock; it is the most reliable step in consumer credit.
Why three steps are ND. We found no public document describing a human a borrower can reach before the decision, an appeal with authority, or a non-automated path. That may exist; it is not shown.
Why the lender is 4 on everything. Upstart's own compliance pages say lenders see approval and denial reasons per application, and partner banks hold credit policy authority. The gap is the point.
Lemonade
Applicable law: state unfair claims settlement practices acts and insurance codes (written reasons for denial); NAIC Model Bulletin on the use of AI by insurers as adopted by states; New York DFS Circular Letter 2024-7 on AI in insurance for New York business; Colorado SB 21-169 on insurers' use of external data and algorithms; GDPR for European policyholders.
Why assessment is 3. The annual report states the automation share plainly and the system is branded as AI. It is not 4 because the disclosure is corporate, not per claim.
Why control for the claimant is 2. Routing to a human is decided by the system, not requested by the claimant. The company's 2021 statement that AI never auto-declines is a company claim, so it caps at 2 until the terms confirm it.
Why appeal is 3. Every state insurance department takes complaints, an external route that exists in practice. The internal appeal is not documented, so we do not reach 4.
PayPal
Applicable law: the PayPal User Agreement, including its provisions on limitations and holds of up to 180 days; Electronic Fund Transfer Act and Regulation E for error resolution on transfers; state money transmission law; CFPB complaint jurisdiction; GDPR for European users.
Why influence before the decision is 0. The hold precedes contact by design. That is a structural fact, so 0 rather than ND.
Why exit is 1. The user agreement allows holds of up to 180 days after a limitation; leaving means leaving the money behind for that period.
Why explanation is 1. The notice uses general categories; public complaint narratives repeatedly report no specific reason. That is Tier D evidence lowering the score.
Workday
Applicable law: Title VII, the Age Discrimination in Employment Act and the Americans with Disabilities Act, applied to the vendor as the employer's agent by the court in Mobley; New York City Local Law 144 (notice and bias audit); Illinois HB 3773 (from 1 January 2026); California Civil Rights Council regulations on automated decision systems in employment (from 1 October 2025); Colorado SB 26-189 from 2027; EU AI Act Annex III employment obligations, currently scheduled for December 2027.
Why assessment is 1. Applicants are generally not told that software screened them; the court record and reporting say this is why litigation has been rare. Notice is required only in New York City.
Why explanation is 0. No reasons are given to rejected applicants, and in May 2026 the court shielded the company's bias-testing data from disclosure. Absence is documented.
Why the recruiter is 3, not 4. The tool ranks and recommends; a recruiter can override. But the court found the tool acts as a single policy across every applicant, which suggests the human rarely sees those it screens out.
Why appeal is 1. The only route is the EEOC and the courts. A collective action was certified, but it took years and a deadline to join has already passed.
Uber
Applicable law: GDPR Article 22 (decision found unlawful by the Dutch Data Protection Authority in August 2026) and Articles 13 to 15 on information; EU Platform Work Directive 2024/2831 on automated monitoring and decision-making, to be transposed by December 2026; Seattle's app-based worker deactivation ordinance and similar state and city rules for US drivers.
Why the operator scores 1, not 4. The regulator found that software acted on threshold breaches without routing the decision through a person. For that period there was no operator with a human option either, which is why the gap is near zero and the finding is worse, not better.
Why we score the documented period. The company now says a person reviews every deactivation and drivers can appeal. That is a company statement after enforcement. When we can confirm it in the driver terms or help pages, the current score will rise and both readings will be shown.
Why appeal is 2. The route that finally worked was a regulator, six years after the complaint. External contestability existed; it was not practical.
SafeRent
Applicable law: Fair Housing Act (disparate impact, as pleaded in Louis v. SafeRent with a Department of Justice statement of interest); Fair Credit Reporting Act, since tenant screening reports are consumer reports (right to a copy, dispute within 30 days); Massachusetts anti-discrimination law; the settlement's five-year injunctive terms.
Why the landlord scores 2 on control. The landlord formally makes the decision but cannot adjust the score and, in the case record, wrote that it could not override the outcome. Authority on paper, none in practice.
Why the applicant scores 0 on reaching a person. The management company's own words: it did not accept appeals.
Why explanation is 0. The screening company did not tell even landlords how the score was built.
Why exit is 0. The plaintiff found housing at higher cost in a worse area; the cost of exit is documented in dollars.
Aidoc
Applicable law: FDA clearance under 21 CFR 892.2080 as radiological computer-aided triage and notification software (Class II), whose labelling keeps the radiologist responsible; HIPAA right of access to records (45 CFR 164.524); state laws on AI disclosure in care as they apply to the hospital; Colorado SB 26-189 from 2027 for health care decisions.
Why the radiologist is 4. The regulator's clearance letters describe notification-only software whose previews are marked not for diagnostic use; the radiologist reads the original images and decides. Authority is in the label.
Why the patient is 0 on notification. The patient receives the radiologist's report; the software's flag is not part of it. That is the workflow as labelled.
Why four patient steps are ND. Whether a hospital tells patients that AI triage runs on their scans depends on the hospital's notices, which vary and which we are sampling. We will not guess.
Natural Cycles
Applicable law: FDA De Novo (2018) and subsequent 510(k) clearances as a Class II device; GDPR, applied by the company to all users; Washington's My Health My Data Act and similar state health-data laws for US users; app store data rules.
Why there is no gap. The person who uses the system is the person it decides about. We score one role.
Why data is 4. The privacy policy applies European data rights to every user, describes consent-based sharing of wearable data with permissions the user can change, and sets out retention and deletion. That is Tier A.
Why exit is 3, not 4. Deleting the account deletes the cycle history the algorithm learned from; the cost is real though modest.
Why explanation is ND. The general logic is explained; whether a user can see why a specific day is marked fertile is an in-app question we have not verified.
UnitedHealth nH Predict
Applicable law: Medicare Advantage rules at 42 CFR Part 422, Subpart M (appeals to an independent review entity and beyond); CMS Final Rule CMS-4201-F and its February 2024 guidance that coverage decisions must rest on individual circumstances and not on an algorithm alone; California SB 1120 on physician review of utilization decisions for California plans; pending litigation in Estate of Lokken v. UnitedHealth.
Why appeal is 4. Medicare Advantage appeals run through a multi-level process to an independent review entity and an administrative law judge. That is the deepest recourse in the edition and it is in federal regulation.
Why the gap is still 28. The member is not told a predictive tool was used, cannot reach anyone before the denial, and the litigation alleges very high reversal rates on appeal alongside very low appeal rates. Recourse exists; the friction is the finding.
Why the reviewer is 3. Federal rules since 2024 require individual assessment and forbid relying on an algorithm alone; clinicians sign the denials. Whether they can override in practice is what the court case will show.
Flock Safety
Applicable law: the Fourth Amendment, under challenge in litigation over plate-reader networks; state plate-reader statutes such as California's requirement of a public usage policy and Virginia's 2025 retention limits; public records law; the deploying agency's own policy as published on its transparency page. No federal or state law gives the driver notice or appeal.
Why the officer is 4. Agency transparency pages state that hotlist hits must be verified by a person before action and that every search needs a recorded reason. That is deployment policy, Tier A.
Why the driver is 0 on notification and influence. Alerts precede any contact and no channel to the driver exists at all. Structural, so 0.
Why data collection is 1, not 0. The portals disclose retention, sharing and prohibited uses to the public. That is a trace of Understand, at the population level rather than the individual.
Why appeal is 1. Courts are the only route, and a constitutional challenge is under way.
Palantir for ICE
Applicable law: the Privacy Act of 1974, whose access and correction rights largely exclude non-citizens; the E-Government Act's privacy impact assessment requirement; immigration due process in removal proceedings, which reviews the removal, not the targeting. No automated decision law applies to enforcement targeting.
Why this profile is analytical. The affected person's steps score 0 or 1 by the structure of enforcement targeting: no notice, no explanation, no correction, no appeal against the lead itself. We publish the profile but treat the number as a floor rather than a ranking, and we do not score military or targeting systems numerically.
What the documents show. Sole-source contracts describe prioritising people for removal and tracking them in near real time; reporting describes a tool that scores the confidence that a person lives at an address. The operator's authority is complete.
Michigan MiDAS
Applicable law: due process under the Michigan and United States constitutions (the basis of Bauserman v. Unemployment Insurance Agency); Michigan's unemployment insurance statute; the 2022 settlement, approved in January 2024, and the state's replacement of the system.
Why a closed case is in the edition. It is the best documented example of recourse that existed on paper and failed in practice: questionnaires to old addresses, silence treated as guilt, penalties before review. The state acknowledged that no person double-checked the system's conclusions; a 20 million dollar settlement was announced in October 2022 and approved by the Court of Claims in January 2024.
Why the operator is 0. For two years the determinations were fully automated. The state later restored human review; the profile scores the documented period.
Where this sits in the literature
The "affected person" is a legal category, well established in law and regulation, not ours: the EU AI Act uses the term and gives that person a right to explanation of individual decisions; the GDPR gives a right to contest solely automated decisions; the Council of Europe's Framework Convention on AI requires information sufficient for "affected persons" to contest decisions made through an AI system (Articles 14 and 15). The concept of contestability and its design was developed by Margot Kaminski and Jennifer Urban (The Right to Contest AI, Columbia Law Review, 2021), by Danielle Citron (Technological Due Process, Washington University Law Review, 2008), and by Susan Landau, James Dempsey and colleagues (Challenging the Machine: Contestability in Government AI Systems, 2024). The link between human agency and redress was made by Rosanna Fanni and colleagues (Enhancing human agency through redress in Artificial Intelligence Systems, AI and Society, vol. 38, 2023, online June 2022). Two recent works are the closest to our method and we build on both: the Contestability Assessment Scale (arXiv 2506.01662, 2025) proposes a composite metric of contestability mechanisms in system design, and Matthew Stewart's Beyond Explanation (arXiv 2603.22716, 2026) analyses 168 legal cases to show that contestation fails at an evidentiary gate before it reaches a doctrinal one.
What The Human Option adds is a change of object and a change of evidence. The object is not the system's design but the position of a named human role in a documented deployment, scored on both sides of the same decision so that the gap between institutional power and personal power is a published number. The evidence is the public record of that deployment, ranked by tier, with silence recorded as not demonstrated rather than as absence, and with a right of reply. The result is a measurement of rights in practice rather than a description of rights in law. Regulators are moving toward the same distinction: the Global Privacy Assembly's 2025 resolution on meaningful human oversight separates oversight during the process from human review after it, in which the impacted individual can substantiate their point of view, and the UK Information Commissioner's 2026 draft guidance, after a review of thirty employers, treats a reviewer who approves a score without the training, understanding and authority to change it as providing no meaningful involvement. The index measures whether that review exists in practice.
How the cases were chosen
Cases enter the index by three tests: the decision is one that Colorado's automated decision law, California's rules or the EU AI Act name as consequential; the decision can be reconstructed from public documents; and the case adds a relationship between machine and person that the index does not yet cover. Well-known court cases are included deliberately as anchors, so that readers who know them can check the method against a record they trust; the findings added in September 2026 are cases that, to our knowledge, no index has scored from the affected person's position. No case was taken from any teaching syllabus or course material; every case was located through court dockets, regulator decisions, government records and established reporting, all cited on this page.
Evolv in schools
Applicable law: FTC Act section 5 (the November 2024 complaint and settlement order on deceptive claims); state education and search law governing searches of students; no automated decision law reaches the student.
Why the student scores 0 on recourse. The FTC settlement gave certain K-12 customers a 60-day window to cancel contracts and banned unsupported detection claims; it created nothing for the person screened. Recourse existed for the buyer, not the affected person, which is the pattern the index is built to expose.
Why staff score 3, not 4. A person searches after an alarm, but the FTC record shows Evolv itself told schools more staffing and manual diversion would be needed, and reporting describes untrained staff running the machines.
Clearview AI, Vermont
Applicable law: Vermont Consumer Protection Act and data broker law (the state's three suits); Illinois BIPA (the federal class settlement); GDPR for European enforcement. The December 2025 dismissal rested on personal jurisdiction, not on the merits.
Why recourse is 0. The affected person's own state could not keep the company in court: the judge found Clearview has no presence, customers or operations in Vermont and that residents' images are a random connection. A forum that cannot be opened is the deepest possible absence of recourse.
Why correction is 1. Removal exists for residents of some states, and a 2020 ruling in the same litigation noted alleged deception about the ability to remove oneself.
DUO, Netherlands
Applicable law: GDPR and the Dutch General Data Protection Implementation Act; Dutch equal treatment law; administrative appeal under the Student Finance Act; the Dutch Data Protection Authority's November 2024 assessment.
Why the investigator scores 2, not 4. The PwC report found the human selection stage itself contributed to the discrimination. A human in the loop who amplifies the model's bias is not a human option for the person.
Why correction is 2. The Minister announced in November 2024 that decisions based on the system would be reversed and restitution paid. Correction came, years later and collectively, after journalists and Parliament rather than through the individual's own appeal.
Rotterdam welfare model
Applicable law: GDPR Article 22 and Dutch administrative law; the model was paused in 2021 after government-backed auditors' findings. Sources are Tier D by type but rest on the model file, training data and code disclosed by the city to Lighthouse Reports and WIRED.
Why this case sets a floor. Recipients had no knowledge that a score ranked them or how it was calculated; the top tenth were referred for investigation including home visits; hundreds lost benefits. The only explanation that ever reached the public came from journalists reconstructing the model.
CAF, France
Applicable law: GDPR and the French Data Protection Act; the Code des relations entre le public et l'administration on algorithmic decisions; equal treatment law (the Défenseur des droits found a presumption of indirect discrimination); pending before the Conseil d'État since October 2024, extended to the 2026 model.
Why data collection is 2. CNAF published the 2026 model's code and 17 variables, which is population-level transparency; it withheld the training data and gives no individual notice, so the score cannot reach 3.
Why the controller is capped at 3. CNAF states that a human decides whether to open a check and that the algorithm decides nothing alone. That is the agency's own statement, so it cannot support a 4.
Deliveroo Italy
Applicable law: Italian anti-discrimination law as applied by the Labor division of the Tribunale di Bologna (order of 31 December 2020, EUR 50,000 and publication of the ruling); the EU Platform Work Directive now addresses the same conduct prospectively.
Why the operator scores 0. The court's finding was that the platform did not know and did not want to know why a rider cancelled. There was no human on the company's side of the decision to reach.
Why recourse is 2, not 4. Riders won, but only collectively, through three unions and a first-instance court; no individual rider could have corrected a ranking.
Seattle deactivations
Applicable law: Seattle's App-Based Worker Deactivation Rights Ordinance, in force 1 January 2025; administrative rules from 24 June 2025; Office of Labor Standards enforcement of procedural rights until 31 May 2027 and of substantive reasons from 1 June 2027; Ninth Circuit decision of 4 March 2026 rejecting Uber's and Instacart's First Amendment challenge.
Why this case is in the index. It is the control. The same platforms that deactivate workers by algorithm elsewhere must, in Seattle, give fourteen days' notice, the records relied on, a human review and a challenge procedure. The city reported more than 30 reactivations and more than 20 forced reruns in the first fourteen months. The score shows what the law can do; the gap that remains is exit, which no ordinance changes.
Cigna PxDx
Applicable law: California Health and Safety Code section 1367.01 (physician review of medical necessity denials) and the Unfair Competition Law; ERISA full and fair review for employer plans; state unfair claims practices acts; Kisting-Leung v. Cigna, 2:23-cv-01477 (E.D. Cal.), partial ruling of 31 March 2025 allowing claims to proceed; House Energy and Commerce inquiry.
Why the medical director scores 1. A physician signs each denial, which is authority on paper. Internal records reported by ProPublica show batches signed at an average of 1.2 seconds per claim without opening files, and the court found that delegating the decision to the algorithm could be an abuse of discretion. Authority exercised in 1.2 seconds is not a human option for the member.
What we do not claim. The case is pending. No settlement has been reported; the index scores the documented process, not the outcome of the litigation.
Applying the method to AI agents
An agent acting for a person creates three positions to score: the principal (the person the agent acts for), the counterparty (the person on the other side of what the agent does), and the operator. The eight steps apply to each. For the principal we add a preliminary step, delegation: who authorised the agent, within what limits, with what record, and whether authority can be revoked and actions undone. The counterparty is scored exactly as an affected person is today, because that is what they are. Where an agent decides about another agent, we score both principals; a gap near zero with both sides low is reported as the absence of any human option, as in the Uber and Michigan cases.
The legal anchor is unchanged. Obligations that create a human option attach to the deployer of the system, not to the technology, and courts and regulators have treated deployed tools as the deployer's agent. An autonomous agent does not dilute the deployer's duty to notify, explain, allow correction and provide human review where the law requires them.
The fifth area: records
The second edition adds systems that keep and score the file on a person: background check providers, data brokers, court and eviction record aggregators and pretrial risk tools. The governing law is the Fair Credit Reporting Act where the file is a consumer report, state data broker laws including California's deletion mechanism, and criminal procedure rules for risk scores. The scoring question is the one people ask most: when the file is wrong, what can I do, and how long does it take.
Questions we are asked
Why score companies from documents instead of asking them?
Because a person facing the decision cannot ask either. The index measures what is knowable from the outside, which is the position the affected person is in. Companies can add to the record through the right of reply, and many will.
Isn't ND just a polite zero?
No. Zero means we can show the mechanism does not exist. ND means we could not find it. We publish the count of NDs on every profile so readers can see how much of a score rests on silence, and a company can convert an ND with one document.
Why does the operator score matter?
Because the gap is the finding. A company that gives its own staff full control and the affected person none is measurably different from one that gives neither, and from one that gives both. Uber and MiDAS show why: the gap was small because nobody had a human option.
Why did a legal requirement score 4 without proof it works?
Binding sources score the existence of the power; independent sources adjust for whether it works. Where complaint data, audits or court records show a mechanism failing in practice, the score comes down, as with explanation at PayPal and appeal at MiDAS.
Why is a company's own statement capped at 2?
Marketing is not evidence of a person's position. A statement like "a human always reviews" becomes a 3 or 4 when it appears in terms, a filing or a regulator's finding.
Why compare a hospital tool with a police camera?
We do not compare them as products. We compare the position of the person in each decision. A patient and a driver both want to know, to be heard and to be able to contest. The scale is the same because the question is the same.
Why "recourse standing" and not "contestability" or "due process"?
Contestability describes what a system allows; due process describes what the law requires. Recourse standing describes what a particular person can in fact do, at a particular step, in a particular deployment, as shown by the public record. Standing is the lawyer's word for the position that lets you be heard; recourse is the relief you seek. The term names the measurement, not the right, and it is defined on this page, with the three-part test above it, so that readers can hold us to it.
Is a high score an endorsement?
It is a statement that the public record shows a person keeps a human option at that step. It says nothing about accuracy, fairness or safety, which other indexes measure.
What if a company thinks a score is wrong?
Send the document. Every profile lists the steps, the sources and the score. If a source shows we are wrong, the score changes and the correction is logged.
Data
All step scores for every role in the first edition, coder 1, are in human-option-scores-first-edition.csv, released under Creative Commons Attribution 4.0. The second coding and the disagreement log will be added to the same file.
How to cite
Popova, Alena. The Human Option: an index of recourse standing in automated decisions. First edition, 2026. https://humanoption.org. Methodology version 1.0, September 2026. Scores and evidence files are released under a Creative Commons Attribution 4.0 license; cite the profile, the step and the edition date.