ISO Sets AI Explainability Standard | TLY

AI Regulation Tracker  /  Standards and safety

ISO Publishes the First Global Technical Spec for Explainable AI

Voluntary, not binding, but it is now the reference yardstick for explainability. In September 2025, ISO and IEC published TS 6254:2025, the first international technical specification that sets out the objectives and methods for explaining and interpreting machine learning models and AI systems across their whole life cycle. It creates no legal duty on its own, but it is the standard your regulators, auditors, and courts will reach for.

The Leveraged Years AI Regulation News

Explainability has been one of those AI topics where everyone agreed it mattered and almost nobody agreed on what the word meant. Developers called it interpretability, policy people called it transparency, product teams called it explainability, and the terms got used interchangeably until it was hard to tell whether two people arguing about it were even talking about the same thing. In September 2025, ISO and IEC published TS 6254:2025, and its whole purpose is to end that confusion with a shared framework. The specification writes it plainly in its introduction, acknowledging that the field "is suffering from a certain terminological inconsistency," and then it picks explainability as the umbrella term and builds a taxonomy under it.

The document is what ISO calls a Technical Specification. That label matters, so I want to be precise about it before anyone reads more into this than is there. A Technical Specification is a voluntary deliverable. It is not a regulation, it is not law, and it does not require any company to do anything. It sits a step below a full International Standard in ISO's own hierarchy, typically because the subject is still developing and the committee wants to publish agreed guidance without freezing it prematurely. So the honest headline is not that AI explainability is now mandated. It is that the world's main standards bodies have, for the first time, agreed on what explainability is and how to pursue it.

What the specification actually does

TS 6254 sets out, in its own words in the scope clause, "approaches and methods that can be used to achieve explainability objectives of stakeholders with regard to machine learning (ML) models and artificial intelligence (AI) systems' behaviours, outputs and results." It then does two useful things. First, it breaks explainability down by stakeholder, because a regulator, an end user affected by a decision, a developer debugging a model, and an auditor reviewing one all need different things from an explanation. Second, it walks explainability through the AI life cycle stage by stage, from inception and design and development, through verification and validation, into deployment, operation and monitoring, continuous validation, re-evaluation, and finally retirement. The message underneath the structure is that explainability is not a feature you bolt on at the end. It is a property you have to design for and maintain from the start.

It also builds a property taxonomy of explanation methods, sorting them by things like the expertise of the audience, the scope of the information, its completeness, and its depth. That is the part practitioners will actually use, because it gives you a way to reason about which explanation technique fits which obligation rather than reaching for whatever the vendor happens to offer.

Read the status precisely: this is voluntary, and it is from 2025

Two things get lost when a standard like this gets summarized, and I want to be exact about both. The first is that it is non-binding. Nothing in TS 6254 compels a company to adopt it. The second is timing. This was published in September 2025, so it is not breaking news, and I am not going to pretend it is. It is on the tracker because standards like this do their real work in the months and years after publication, as regulators cite them, auditors adopt them, and procurement teams start writing them into contracts. That adoption curve is what is happening now, and it is the reason a 2025 specification is a live issue for anyone deploying AI in a regulated US setting in 2026.

The specification itself is candid about why it exists, and it is worth quoting. It says it "aims to provide practical guidance for stakeholders regarding compliance with regulatory requirements labelled one way or another." In other words, the drafters knew that laws around the world are starting to demand explanations of automated decisions under a dozen different names, and they built a common toolkit so that a company can meet those obligations without reinventing the concept for each regime.

Why this matters for US lenders, insurers, and employers

Here is the part that makes a European-flavored ISO document relevant to a US operator. American businesses already owe explanations for automated decisions, and they have for years. Under the Equal Credit Opportunity Act and Regulation B, a lender that denies credit has to give specific reasons, and it does not get a pass because a model made the call. Adverse-action requirements in credit and, increasingly, in insurance and employment run on the same logic. On top of that, a growing set of state automated-decision rules, from California's work on automated decisionmaking technology to comparable moves in other states, are pushing explainability and transparency duties onto AI systems that make consequential decisions about people.

None of those US laws point to TS 6254 today. But the gap they leave is exactly the one this specification fills. When a regulator asks whether your explanation of an AI credit denial was adequate, or a plaintiff's expert argues your adverse-action notice was hollow, there is now a neutral international reference for what a real explanation is supposed to contain and how it should be produced across the life cycle. The specification even names this use directly, noting that "for service providers, explainability can be essential for demonstrating compliance with legal requirements." That is the practical value here. It gives you something citable to build your explanation methodology against, rather than defending an ad hoc approach you invented in-house.

What to do with it now

The move is not to rush out and get certified against a specification that has no certification regime attached. The move is to use it as a checklist. If you run AI in lending, insurance underwriting, or hiring, pull TS 6254 and compare its life-cycle stages and its stakeholder objectives against how you actually generate and document explanations today. Map your adverse-action and ECOA explanation process onto its framework and see where the holes are. Ask your model vendors whether their explainability tooling lines up with its taxonomy, because that is a fair procurement question and their answer tells you a lot. Doing this while the standard is voluntary is cheap. Doing it after a regulator or a court has started treating it as the baseline is not. The whole point of a reference standard is that it eventually stops being optional in practice even while it stays optional on paper.

Questions professionals are asking

Is ISO/IEC TS 6254 a law or a mandatory requirement?

No. It is a Technical Specification, which is a voluntary ISO/IEC deliverable. It is not legislation and it does not require any company to do anything on its own. It becomes consequential only when a law, regulator, contract, or auditor chooses to reference it.

When was it published?

It was published as a first edition in September 2025. It is not brand-new, but it is increasingly relevant now as regulators, auditors, and procurement teams begin to reference and adopt it.

What does the specification cover?

It defines the objectives and methods for explaining and interpreting machine learning models and AI systems, organized by stakeholder and mapped across the full AI life cycle, from inception and design through validation, deployment, monitoring, and retirement. It also provides a taxonomy of explanation methods sorted by audience, scope, completeness, and depth.

Why does it matter for US companies if it is not US law?

US businesses already owe explanations for automated decisions under laws like the Equal Credit Opportunity Act and Regulation B, adverse-action rules, and a growing set of state automated-decision rules. None of those point to TS 6254 yet, but it gives you a neutral international reference for what an adequate explanation contains, which is useful evidence that your process is sound.

What should we do with it now?

Use it as a checklist rather than a certification target. Compare its life-cycle stages and stakeholder objectives against how you actually generate and document explanations for AI-driven lending, insurance, or hiring decisions, find the gaps, and ask your model vendors whether their explainability tooling aligns with its taxonomy. It is cheaper to do while the standard is voluntary.

RELATED BRIEFINGS

Browse the full AI Regulation News tracker

Informational analysis for working professionals, not legal advice. Confirm how any standard or requirement applies to your situation with qualified counsel in the relevant jurisdiction.