AI Decisions Need Expiration Dates, Not Just Approval Stamps
As governments test frontier models, a Georgetown researcher argues the bigger risk is automated rulings that stay active long after their underlying facts go stale.

Regulators are finally building capacity to test advanced AI systems before deployment. OpenAI this week called on Congress to mandate safety testing, independent assessment, and incident reporting. The EU's cybersecurity agency began evaluating frontier models. But according to Georgetown researcher Burak Oktenli, these efforts address only the first moment of risk.
The second arrives after an AI output becomes an operational decision—a credit denial, a border flag, a sanctions designation—and sits in institutional databases governing real people and transactions. The model may not change, but the facts behind the decision can. A ruling that made sense on Monday may be indefensible by Friday, yet every system still treats it as valid.
Why it matters
Automated decisions in credit, migration, sanctions screening, and aid eligibility often persist far longer than the evidence that justified them. When those decisions cross borders or get copied into other agencies' systems, a correction at the source may never reach downstream users. The result: stale judgments with institutional authority but no current factual basis—a governance gap that existing AI regulations don't yet close.
Two clocks, one mismatch
Oktenli frames the problem as a clash between two timelines. One measures how long a decision remains in force. The other measures how long its supporting facts can reasonably be expected to stay true. When the first outlasts the second, yesterday's evidence continues to exercise today's authority.
He calls the second timeline the "decision-validity horizon"—the window in which the premises behind a ruling can still support its continuing effect. A credit decision may rest on income and interest rates. A travel-risk assessment may depend on an identity match or threat picture. Each premise changes at a different speed, yet the resulting decision is often stored as if it were permanent.
A 2021 example: Zillow wound down its home-buying business after concluding that house-price volatility far exceeded its models' assumptions, recording a $304 million inventory write-down. Prices moved faster than the commitments built on them could be unwound. Public decisions can have longer tails and higher stakes, Oktenli notes, especially when automation separates the moment of judgment from months of execution.
How stale decisions cross borders
The geopolitical risk intensifies when institutions exchange conclusions without exchanging shelf lives. A bank, airline, border service, or allied agency may receive a category—"flagged," "ineligible," "high-risk"—but not the assumptions that created it. The originating institution may correct its record, but a downstream system preserves a local copy or derived flag. A match cleared at the source can continue to block access elsewhere.
Replication gives a decision durability its evidence never earned, Oktenli argues. Without a common way to transmit expiry and correction, a provisional national ruling hardens into a de facto cross-border rule.
What current rules miss
The EU AI Act requires logging, documentation, human oversight, and post-market monitoring for high-risk uses. The Council of Europe Framework Convention mandates documentation sufficient for challenge and iterative risk assessment. The NIST AI Risk Management Framework treats risk management as ongoing, not one-time.
These frameworks follow the system across its lifecycle, Oktenli writes. What they don't yet supply is an expiry discipline for each consequential decision that persists or travels. Logging shows what happened. Explainability shows why. Human oversight identifies who was responsible. None answers the temporal question: until when may this decision remain authoritative?
A validity horizon for public decisions
Oktenli proposes four interoperable rules. First, record the material premises—the limited facts that, if changed, could alter the decision. Second, assign a validity horizon expressed in time, conditions, or both, reflecting how quickly evidence can change and how serious the consequence of error would be. Third, trigger lapse or genuine revalidation when the horizon is reached—not merely rerunning the same model on stale inputs, but checking whether decisive premises remain current. Fourth, propagate expiry: any decision exchanged between institutions should carry machine-readable validity metadata, including originating authority, issuance time, material premises, review date, and revocation status.
The priority is the smaller class of decisions with long tails or cross-border effects: standing risk scores, access restrictions, watch-list derivatives, supplier exclusions, benefit suspensions. The more durable the consequence, the stronger the case for an explicit horizon, Oktenli argues.
Appeal rights remain essential but are not a substitute. People cannot reliably challenge decisions they don't know exist, and a successful correction in one institution is incomplete if others retain the result. A validity horizon makes review proactive; propagation makes correction effective.
The details were first reported by Burak Oktenli, who holds an MBA and a Master of Professional Studies in Applied Intelligence from Georgetown University, in an analysis published at Eurasia Review.
This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.
Want systems like this working for your business?
Book a Call
