{"id":"b959d6fb-b3ff-4b12-8cc1-67fb85900238","arxiv_id":"2608.02699","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A systematic review of 57 post-2024 papers shows only 19 integrate EU law and XAI, most misidentify the GDPR basis, and the authors propose an addressee/purpose framework and a four-phase operationalization blueprint.","lead":"A systematic review finds that only 19 of 57 papers on explainable AI genuinely engage with EU law on the right to explanation, and most cite the wrong legal basis. The paper proposes an addressee/purpose framework to separate how explanations must be presented from what they must contain, plus a four-phase roadmap for compliance.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Screening/search completeness is the load-bearing risk: the Appendix A search string omits 'EU'/'European Union'/'data protection' terms, and ASReview stopped at ~8% with one reviewer; any missed eligible papers would shift the 19/57 corpus and the pattern prevalence.","rationale":"I agree with the reader's weakest assumption: the completeness of the 19-paper corpus is the linchpin of the systematic-review findings. The paper is transparent about its search strings, stopping criterion, and validation procedure, and its inclusion of a dual full-text review is commendable. However, the search string's legal vocabulary is narrow enough to exclude papers that refer to the EU legal framework by other common names, and the ASReview stopping rule combined with a single title/abstract screener leaves a real residual risk. The validation sample of 60 records cannot rule out missing a few percent of eligible papers, and the absence of the excluded-study list prevents external verification. If a broadened search surfaced additional eligible papers—especially ones that correctly ground the right in Art. 15(1)(h) or engage with Dun & Bradstreet—the reported prevalence of the three patterns could change. That would not necessarily invalidate the overall translation-gap thesis, but it would weaken its quantitative basis. The proposed test is inexpensive and direct: expand the search and re-screen. If the counts remain stable, the conditional acceptance is justified; if they shift materially, the paper's empirical claims need revision. I do not see a more load-bearing concern than this, and for that reason I do not recommend changing the reader's conditional verdict.","tokens_in":23157,"tokens_out":7833,"duration_ms":74170,"concrete_test":"Re-run the WoS/Scopus search with an expanded EU-law clause that adds 'European Union', 'EU law', 'data protection', and 'right to explanation' to the original terms, and have two independent reviewers (one legal, one technical) screen all newly retrieved records against Table 1 criteria; if any additional papers qualify for full-text review, recompute the 19/57 counts and the three-pattern rates to see whether the conclusions hold.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's central empirical claim—that only 19 of 57 post-2024 papers substantively integrate EU law and XAI, and that the corpus exhibits three systematic problems—depends on the completeness of the search and screening. Appendix A's search string requires at least one of 'European Legislation', 'GDPR', 'General Data Protection Regulation', 'Artificial Intelligence Act', 'AI Act', or 'European Law' in title/abstract/keywords. This omits papers that use 'EU', 'European Union', 'EU law', 'data protection law', or 'right to explanation' without naming a specific instrument. The paper itself acknowledges that a known paper (Sovrano et al. 2025) was excluded because it was not indexed in WoS/Scopus, and that title/abstract screening was performed by a single technical reviewer with an ASReview stopping rule of 40 consecutive irrelevant records after 219 records (~8%). The validation sample of 60 random records is too small to substantiate completeness: at a ~2.3% full-text retrieval rate (60/2643), the expected number of eligible records in 60 draws is ~1.4, so finding zero provides weak evidence (the 95% upper bound on the residual eligible rate is about 5%). Moreover, the excluded-study list and coding data are not released, so the 19/57 classification cannot be independently audited. If even a few eligible papers were missed or misclassified, the prevalence of 'misgrounding' (Art. 22 vs. Art. 15(1)(h)) and the 'form/content conflation' patterns could change, undermining the conclusion that the Right to Explanation has no technically realizable path to compliance.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper reports a PRISMA-based systematic literature review of post-2024 research at the intersection of Explainable AI (XAI) and the EU Right to Explanation. From 2643 records identified in Web of Science and Scopus, 57 full texts were screened and 19 papers were judged to substantively integrate legal and technical perspectives. The authors find three recurring problems in this corpus: most papers ground the GDPR right in Art. 22 and Recital 71 rather than Art. 15(1)(h); few engage with the CJEU's Dun & Bradstreet judgment; and many conflate the form of an explanation (governed by its addressee) with its content (governed by its legal purpose). Based on this, the paper proposes an Addressee/Purpose Framework, a four-phase blueprint for operationalizing explanation requirements, and six open research questions.","tokens_in":23423,"tokens_out":7605,"duration_ms":65297,"significance":"The topic is timely and the review is useful if its empirical claims hold. The paper's strengths are its explicit search strings and inclusion criteria, a PRISMA flow diagram, dual full-text review by a legal and a technical researcher, and a candid limitations section that acknowledges single-reviewer title/abstract screening and database coverage limits. The Addressee/Purpose Framework is a concrete analytical contribution that connects Art. 12(1) GDPR to explanation form and the substantive provisions to explanation content. The paper also makes falsifiable claims (e.g., the low count of dual-domain papers, the prevalence of misgrounding) that can be checked by replicating the search. However, the central quantification depends on screening completeness and coding transparency, which are currently only weakly supported.","major_comments":[{"comment":"The search strings reported in Appendix A (WOS: TS=(...); Scopus: TITLE-ABS-KEY=(...)) require at least one of 'European Legislation', 'GDPR', 'General Data Protection Regulation', 'Artificial Intelligence Act', 'AI Act', or 'European Law' in the title, abstract, or keywords. They do not include 'EU', 'European Union', 'EU law', 'data protection law', or 'right to explanation'. Since inclusion requires engagement with Art. 15(1)(h) GDPR and/or Art. 86 AIA, a paper whose abstract mentions 'EU law' and 'explainability' without naming those exact instruments would be missed. Expanding the search with these terms could change the 2643→57→19 counts and the prevalence of the three patterns; the authors should rerun the search and report the number of additional records and whether any would meet the inclusion criteria.","section":"Appendix A / Section 3"},{"comment":"The validation exercise described in Appendix A draws 60 records from the unscreened portion of the corpus. With a 19/2643 eligible rate (about 0.72%), the expected number of eligible records in 60 draws is less than one, and observing zero yields a 95% upper bound on the residual eligible rate of about 5%. This sample is therefore too small to substantiate the claim that the ASReview stopping criterion (40 consecutive irrelevant records, reached after screening roughly 8% of records) did not miss a material number of eligible papers. I would ask the authors to screen a larger random sample (e.g., several hundred records) or to perform a second full screening pass, and to report the results.","section":"Appendix A, 'Validation'"},{"comment":"The paper's central findings are the three patterns in the 19-paper corpus, but the coding along the four dimensions (XAI classification, legal basis, form, content/purpose) is not reported per paper, and the excluded-study list is not released. This makes the prevalence claims impossible to audit independently. The authors should provide a supplementary table listing all 57 assessed papers with their inclusion/exclusion decisions and, for included papers, the coding of the four dimensions; this is especially important given that the authors' own prior work is part of the corpus.","section":"Section 8 / Appendix A"}],"minor_comments":[{"comment":"The statement that the literature on the GDPR legal basis presents 'a heterogeneous and overall rather blurred picture' would be more informative with a per-paper breakdown of the legal-basis coding; the current text names only a subset of the 19 papers.","section":"Section 4.3"},{"comment":"The PRISMA flow diagram is internally consistent, but the split between 'manually' (279) and 'automatically' (2364) screened records is explained only in Appendix A; a one-sentence clarification in Section 3 would help.","section":"Figure 1"},{"comment":"The arrows and the '⇓' row make the form/content consequence hard to parse; consider separating the form and content outcomes into distinct columns.","section":"Table 2"},{"comment":"The statement that the CJEU in Dun & Bradstreet 'did not lay down detailed requirements regarding the substance of explanations' would benefit from a pinpoint citation to the judgment's paragraphs.","section":"Section 2"},{"comment":"The exclusion of Sovrano et al. 2025 is described as due to non-indexing and because 'it did not yield a substantial additional contribution'; the second clause is an evaluative judgment that could be clarified as a relevance decision under the inclusion criteria.","section":"Section 8"}],"recommendation":"major_revision","confidential_remarks":"The manuscript is within scope for a journal at the AI-law interface and has a transparent method, but the empirical claim that only 19 papers substantively integrate law and XAI is the key result and the screening evidence for it is thin. I recommend a major revision that expands the search, strengthens the validation, and releases the coding data. The authors' inclusion of their own prior work is transparent, but the absence of per-paper coding data is the main obstacle to independent verification. If the empirical claim is later shown to be robust to the expanded search, the paper could be a valuable contribution."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Bottom line: this is a serious, useful systematic review, and the central claim—that only 19 of 57 post-2024 papers truly integrate EU law and XAI—is credible. The Addressee/Purpose framework is the real contribution: form follows addressee (Art. 12(1) GDPR), content follows legal purpose (Art. 15(1)(h), Art. 86 AIA, Art. 18(8)(a) CCD). It is anchored in the actual provisions, not a vague metaphor, and it gives practitioners something to design against. I would send this to review.\n\nWhat is new: the post-2024 corpus, the explicit mapping of the three problematic patterns (Art. 22 vs Art. 15(1)(h) grounding, slow Dun & Bradstreet uptake, form/content conflation), and the four-phase blueprint. The PRISMA documentation is transparent: search strings, inclusion/exclusion criteria, dual full-text screening by a legal and a technical reviewer, coding dimensions, and an unusually candid limitations section.\n\nThe soft spots are real but not fatal. The search string requires an explicit EU instrument name in title/abstract/keywords, so a paper that says 'EU law' or 'data protection law' without naming GDPR/AI Act drops out. Single-reviewer ASReview screening stopped at ~8% (219 records, 40 consecutive irrelevant), and the 60-record validation sample is too small to establish completeness—at the observed ~2.3% eligibility rate you'd expect about 1.4 eligible records in a random sample of 60, so zero hits is weak evidence. The paper acknowledges the single-reviewer risk, but the excluded list and coding data are not released, so the 19/57 classification can't be independently audited. Also, the decision to exclude Sovrano et al. 2025—a known overlapping systematic review—because it wasn't indexed in WoS/Scopus is disclosed but still a gap. None of this undermines the qualitative patterns; those would likely survive a few missed papers. But it does mean the 'only 19 papers' number should be read as 'at least 19, after our pipeline', not as an exact census.\n\nI'd accept for peer review and ask for the missing audit trail in revision. The paper is aimed at XAI researchers, legal scholars working on digital rights, and standardization bodies (CEN-CENELEC, ISO). It deserves a serious referee.","headline":"A genuinely useful law-XAI systematic review with a solid conceptual core; the 19/57 count is credible but rests on a screening pipeline that is thinner than the conclusions imply.","tokens_in":24059,"tokens_out":3812,"would_cite":true,"duration_ms":34506,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"EU law grants a real Right to Explanation, but a systematic review of the post-2024 literature finds only 19 papers that substantively integrate law and XAI, and the field misstates the legal basis, ignores the key court ruling, and…","keywords":["Right to Explanation","GDPR Article 15(1)(h)","AI Act Article 86","Explainable AI","systematic literature review","Addressee/Purpose Framework","counterfactual explanations","Dun & Bradstreet judgment"],"falsifier":"Conduct a full dual-reviewer screen of all 2,643 records (or a much larger validation sample than the 60 used) and count how many additional papers meet every inclusion criterion; finding more than a handful would overturn the claim that only 19 papers substantively integrate EU law and XAI.","tokens_in":22890,"feed_emoji":"⚖️","tokens_out":8480,"duration_ms":82147,"temperature":0.7,"pith_summary":"The paper tries to establish that the EU Right to Explanation is a real, enforceable legal entitlement that current explainable-AI research cannot yet satisfy. Reviewing 2,643 records and reading 57 full texts, it finds only 19 papers that substantively engage both EU law and XAI, and it documents three systematic failures across that literature: most papers ground the GDPR right in Art. 22 and Recital 71 rather than Art. 15(1)(h), almost none engage the Court of Justice's Dun & Bradstreet judgment, and most mix up the form an explanation must take with the content it must carry. The paper's answer is the Addressee/Purpose Framework: the addressee fixes the form, the legal purpose fixes the content, and both dimensions are independently required. If that is right, the practical consequence is stark: no current XAI method reliably produces a legally compliant explanation, so the Right to Explanation remains a formal obligation without a technically realizable path to compliance unless standard-setting and user research close the gap.","feed_headline":"Only 19 papers truly bridge EU law and explainable AI","feed_subtitle":"A systematic review finds most papers misread the GDPR basis, ignore a key CJEU ruling, and conflate form with content.","key_machinery":"The load-bearing object is the Addressee/Purpose Framework, defined as the claim that the addressee of an explanation determines its required form while the legal purpose of the triggering provision determines its required content. The framework maps directly onto the law: Art. 12(1) GDPR governs form, and the substantive provisions (Art. 15(1)(h) GDPR, Art. 86 AIA, Art. 18(8)(a) CCD) govern content, with the CJEU's Dun & Bradstreet judgment requiring both dimensions simultaneously and independently. It does the work of showing why a pure SHAP visualization fails both dimensions and why a plain-language narrative can still fail if it omits contrastive or counterfactual information. The companion machinery is a four-phase operationalization blueprint: identify applicable requirements, break them into quantifiable sub-requirements, evaluate XAI methods against those sub-requirements, and argue tradeoffs with explicit documentation of non-fulfillment.","core_discovery":"On the paper's own terms, the discovery is that the post-2024 literature on explainable AI and EU law is not merely incomplete but structurally misaligned with the law it claims to implement. The paper shows that the GDPR right to explanation is anchored in Art. 15(1)(h) GDPR, that the Court of Justice of the European Union settled its existence and its 'meaningful' quality standard in Dun & Bradstreet in February 2025, and that Art. 86 AIA and Art. 18(8)(a) CCD add separate, partly subsidiary rights. Against that legal baseline, most surveyed papers cite the wrong provision (Art. 22 or Recital 71), few cite the court ruling, and almost none separate the addressee-driven form requirement (Art. 12(1) GDPR: concise, transparent, intelligible, plain language) from the purpose-driven content requirement (what the explanation must contain so the person can contest the decision). The paper proposes the Addressee/Purpose Framework to make that separation explicit, plus a four-phase blueprint from identifying applicable requirements to documenting tradeoffs and non-fulfillment.","pith_inferences":["Extension: the Addressee/Purpose Framework can be turned into a concrete test: generate explanations for a fixed credit decision and measure whether a non-expert can identify grounds for contestation; the pass rate would operationalize 'meaningful' in a way courts could use.","Extension: the paper's own position implies that black-box foundation models may be legally impermissible in high-risk Art. 86 AIA domains even when they outperform interpretable alternatives, so an audit of deployed high-risk systems' actual explanation capacity would show how much of the market is currently non-compliant.","Extension: the single-reviewer screening and the search requirement that EU legislation be named in title, abstract, or keywords likely undercounts work that discusses the right under other terms such as 'automated decision-making' or 'contestability'; a broader-concept search would quantify that undercount.","Extension: the framework's distinction between form and content could be extended beyond the three instruments examined here to other transparency duties, such as Art. 13 and Art. 14 AIA, where the same conflation likely occurs."],"forward_implications":["A legally compliant explanation must satisfy form and content independently; if a system cannot produce an honest, intelligible explanation for the specific decision, the paper's Phase 4 conclusion is that the system must not be deployed in that context.","Standards bodies need to define conformance criteria for Art. 86 AIA explanations; current standardization work does not cover that provision, so verifiable thresholds for 'meaningful' and 'intelligible' do not exist.","Research and practice should stop grounding the GDPR right in Art. 22 and Recital 71; the correct anchor is Art. 15(1)(h) GDPR as interpreted by Dun & Bradstreet.","Explanation form cannot be verified by technical properties alone; user studies with the relevant non-expert population are required, and the disagreement problem must be treated as a potential violation of Art. 12(1) GDPR accuracy.","The CCD right under Art. 18(8)(a) becomes applicable in November 2026, which puts a near-term deadline on resolving the open questions."],"supporting_citations":[{"why":"Settles that Art. 15(1)(h) GDPR grants a meaningful right to explanation and that both form and content requirements apply; the paper uses it as the legal anchor for its critique.","marker":"(Court of Justice of the European Union 2025)"},{"why":"Introduces counterfactual explanations as the candidate method for the GDPR right; the paper connects it to Dun & Bradstreet's 'different result' language and treats it as the origin of the implementation debate.","marker":"(Wachter, Mittelstadt, and Russell 2018)"},{"why":"Supplies the systematic-review reporting method that structures the screening pipeline and the 2643-to-57-to-19 record counts.","marker":"(Page et al. 2021)"},{"why":"Provides the machine-assisted screening tool and stopping criterion that the paper's corpus completeness relies on.","marker":"(van de Schoot et al. 2021)"},{"why":"Gives the Co-12 explanation-property list that the paper maps onto the form/content distinction.","marker":"(Nauta et al. 2022)"},{"why":"Documents the disagreement problem, which the paper argues is a legal problem under Art. 12(1) GDPR when explanations conflict.","marker":"(Krishna et al. 2022)"},{"why":"User study showing lawyers as technical laypeople fail to understand SHAP visualizations; the paper uses it as evidence for the form dimension.","marker":"(State et al. 2025)"},{"why":"Proposes the 'principal reason fallacy' and argues explanations must include normative justification; the paper cites it as doubt that any XAI method can satisfy both dimensions.","marker":"(Engelfriet 2025)"}],"fun_headline_variants":["EU law meets AI: only 19 papers truly connect","Most XAI papers misidentify EU explanation law","CJEU's Dun & Bradstreet ruling absent from most XAI work","Form vs content: EU AI explanations often conflated","New framework clears up EU right to explanation"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The picture rests on the screening pipeline: the search required explicit EU legislation in title, abstract, or keywords, and a single technical reviewer judged relevance with a stopping rule reached after screening about 8 percent of the 2,643 records.","fun_headline_variants_meta":{"raw":{"variants":["EU law meets AI: only 19 papers truly connect","Most XAI papers misidentify EU explanation law","CJEU's Dun & Bradstreet ruling absent from most XAI work","Form vs content: EU AI explanations often conflated","New framework clears up EU right to explanation"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000803,"raw_usage":{"total_tokens":3595,"prompt_tokens":1075,"completion_tokens":2520,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":691,"completion_tokens_details":{"reasoning_tokens":2440}},"tokens_in":691,"tokens_out":2520,"duration_ms":17777,"temperature":1.0,"reasoning_tokens":2440,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-07T00:08:55.724388+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Conduct a full dual-reviewer screen of all 2,643 records (or a much larger validation sample than the 60 used) and count how many additional papers meet every inclusion criterion; finding more than a handful would overturn the claim that only 19 papers substantively integrate EU law and XAI.","supporting_citations":[{"cited_title":"and McKenzie, Joanne E","cited_arxiv_id":null,"evidence_quote":"Supplies the systematic-review reporting method that structures the screening pipeline and the 2643-to-57-to-19 record counts."},{"cited_title":"International Review of Law, Computers & Technology , pages =","cited_arxiv_id":null,"evidence_quote":"User study showing lawyers as technical laypeople fail to understand SHAP visualizations; the paper uses it as evidence for the form dimension."},{"cited_title":"An Uninterpretable Right:","cited_arxiv_id":null,"evidence_quote":"Proposes the 'principal reason fallacy' and argues explanations must include normative justification; the paper cites it as doubt that any XAI method can satisfy both dimensions."}],"review_version":1}