Products Demo Docs Blog About Contact Sign in Sign up
Blog · · Philippe Laporte

Which Model Decided: What LATAM Supervisors Can Already Ask For

In Latin America, the right to demand review of an automated decision is already law. The hard part is explaining the decision without opening the model.

A consumer taps twelve interest-free installments at checkout and an approval is scored in real time. A monitoring model flags an account and somebody has to decide whether it goes to the regulator. A claims model sorts which files a human ever sees. A diagnostic support tool puts a suggestion in front of a physician who is short on time. None of that is a pilot any more across Latin America; it is the production path, and every one of those decisions lands on a person who can contest it.

The obligation did not wait for an AI law

The common assumption is that the reckoning arrives when an AI act passes. It does not.

Brazil's LGPD has carried Article 20 since 2020: a person may request review of a decision taken solely on automated processing that affects their interests, and the text names credit profiling explicitly. The controller must supply clear and adequate information on the criteria and procedures used. Brazil's data protection authority is empowered under Article 20 to regulate automated decision-making, has published a technical note on it, and carries it on its 2025-26 regulatory agenda, with penalties running to two percent of Brazilian revenue capped at fifty million reais per violation.

CMN Resolution 4557 has governed operational risk since 2017, and a model that fails inside a regulated process is an operational failure before it is anything more novel. In Argentina the central bank supervises AI largely through the frameworks it already has — prudential, operational, cybersecurity and outsourcing — while generative AI is already the most common approach reported by surveyed institutions.

The AI-specific law is arriving anyway, with Brazil's Bill 2338 through the Senate in December 2024 and now with the Chamber of Deputies, carrying duties to document, assess and monitor high-impact uses and to explain system behaviour to regulators and affected people, and Chile's bill in committee with supervision tied to its forthcoming data protection authority.

Nobody has to wait for any of it to be asked the question.

The clause that makes this genuinely hard

Read Article 20 to the end and it asks for something more demanding than it first appears: clear and adequate information regarding the criteria and procedures used for the automated decision, in compliance with commercial and industrial secrets.

Two obligations pulling opposite ways in a single sentence. Explain the decision, and do not open the model. Most available answers fail one side or the other. Hand over weights and architecture and you have surrendered the commercial secret. Hand over a summary and you have supplied an assurance, not an explanation.

Self-attested evidence fails exactly when it is needed

Ask a team today what they would put in front of a supervisor and the answer is some combination of application logs, a screenshot of the decision screen, a model card, and a letter from the vendor. Each is useful and each has the same defect: it is the institution vouching for its own record.

That is perfectly adequate until the party asking is a supervisor, an external auditor, a court, or the customer's lawyer, which is precisely the moment your own word is the thing in question.

A log proves what you wrote down. It does not prove what the model did.

What independent verification has to mean

It is worth being concrete about who does the verifying, because verifiable on its own has been worn smooth by marketing and now reads to most people as a synonym for encrypted.

It means a specific outside party — the supervisor examining a credit file, the external auditor sampling AML alerts, a counterparty, the counsel for the person who was declined — can check the claim themselves. Not by trusting the operator's assurance, and not by being shown the model. The same input verifiably produces the same output, and a record that has been altered fails the check instead of passing quietly.

What is actually live, named honestly

Cyberian Systems builds cryptographic receipts with probabilistic replay: a cryptographic receipt per mathematically verified inference, which makes an inference output independently verifiable, reproducible and tamper-evident without exposing model internals. Separation between the party that executes and the party that proves is a property of the design.

Today that capability applies to embedding workloads, with BGE embeddings as the flagship, and to ONNX-exportable models through a bring-your-own-ONNX upload. It does not cover generative or mixed workloads, and there are no live-verification claims for those today. If your exposure is a large language model writing credit memos, this does not solve your problem yet, and that is worth saying plainly rather than letting a diagram imply otherwise.

A question for your own team

Pick one automated decision that reached a customer last week: a declined limit increase, a flagged transaction, a triaged claim. Ask what you would put in front of a supervisor who wants to know which model produced it. Then ask the harder half, which is who, other than you, can confirm that answer is true.

If the only answer to the second question is us, that is the gap, and it is worth knowing the size of it before somebody else measures it for you.


PL
Philippe Laporte
Founder and CEO of Cyberian Systems, building verified AI inference infrastructure for regulated industries.

Try the live demo · Follow on LinkedIn · RSS