<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Data-AI Continuum: What the Machine Owes You.]]></title><description><![CDATA[Robodebt. A convenience store that took 1.6 million faceprints. A risk score that sent a man to prison. A Dutch algorithm that took sixteen hundred children from their parents and brought down a government. In every case, the harm was enormous, the system did exactly what it was built to do, and nobody was at fault — because nobody had been made responsible before the machine was switched on. Eight essays on what a responsible organisation owes the people it decides about, and why almost none of them build it.]]></description><link>https://dataaicontinuum.substack.com/s/what-the-machine-owes-you</link><image><url>https://substackcdn.com/image/fetch/$s_!E46p!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F179dedb3-3d70-448b-89eb-77826f571c60_1024x1024.png</url><title>The Data-AI Continuum: What the Machine Owes You.</title><link>https://dataaicontinuum.substack.com/s/what-the-machine-owes-you</link></image><generator>Substack</generator><lastBuildDate>Fri, 14 Aug 2026 19:41:52 GMT</lastBuildDate><atom:link href="https://dataaicontinuum.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[M Maruf Hossain, PhD]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[dataaicontinuum@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[dataaicontinuum@substack.com]]></itunes:email><itunes:name><![CDATA[M Maruf Hossain, PhD, GAICD]]></itunes:name></itunes:owner><itunes:author><![CDATA[M Maruf Hossain, PhD, GAICD]]></itunes:author><googleplay:owner><![CDATA[dataaicontinuum@substack.com]]></googleplay:owner><googleplay:email><![CDATA[dataaicontinuum@substack.com]]></googleplay:email><googleplay:author><![CDATA[M Maruf Hossain, PhD, GAICD]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Everybody Agreed. Nobody Started.]]></title><description><![CDATA[Why the AI governance framework you adopted is still not running?]]></description><link>https://dataaicontinuum.substack.com/p/everybody-agreed-nobody-started</link><guid isPermaLink="false">https://dataaicontinuum.substack.com/p/everybody-agreed-nobody-started</guid><dc:creator><![CDATA[M Maruf Hossain, PhD, GAICD]]></dc:creator><pubDate>Mon, 27 Jul 2026 21:01:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6E6M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>87% of organisations say they have a clear AI governance framework. Fewer than a quarter have implemented the controls described in the framework.</p><p>That gap is the subject of this essay, and it is not a gap of conviction. Nobody in those organisations is against fairness. Nobody argued for opacity or against giving people a way to challenge a decision that ruined their week. The framework was written by capable people, reviewed by capable people, and approved by a committee that agreed with every word of it.</p><p>And then, for the most part, nothing happened.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6E6M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6E6M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!6E6M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!6E6M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!6E6M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6E6M!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png" width="1200" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:2690352,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dataaicontinuum.substack.com/i/206659766?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6E6M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!6E6M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!6E6M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!6E6M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91d66a85-f26f-4650-b094-874bc3160b1b_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="callout-block" data-callout="true"><h1 style="text-align: center;"><strong><span>87% vs 25%</span></strong></h1><p style="text-align: center;">The share of organisations claiming a clear AI governance framework, against the share that has actually implemented the controls to manage bias, transparency, and security risk.</p><p style="text-align: center;"><em><span>IBM, cited in AI governance benchmarking, 2026</span></em></p></div><h1><strong><span>The Finding That Explains the Gap</span></strong></h1><p>A study of 3,000 companies, published by UNESCO and the Thomson Reuters Foundation, sought to uncover the mechanics behind the adoption statistics. Two of its findings sit together in a way that should stop anyone who has ever signed off on a governance framework.</p><p>Only about one in six or seven companies could identify the person within their organisation responsible for the ethical risks arising across the AI lifecycle.</p><p>And for roughly three-quarters of companies, there was no evidence of a policy on the quality of the training data used by their AI.</p><p>Put those together. Most organisations cannot name who is accountable, and most have not addressed the thing the previous essay in this series called the ground on which other controls stand. These are not separate failures. The second is a consequence of the first. Data provenance did not get done because it was nobody&#8217;s &#8212; and a task that belongs to everybody, in an organisation of any size, belongs to no one at all.</p><blockquote><p><em>A responsibility distributed across four functions is not shared. It is lost. Everyone assumes it sits slightly to their left.</em></p></blockquote><h1><strong><span>The Shape of the Thing That Doesn&#8217;t Get Done</span></strong></h1><p>Watch how a governance framework typically arrives, because the failure is built into the delivery.</p><p>It is a single document, or a suite of them, covering the whole territory: principles, risk, data, fairness, explainability, human oversight, incident response, procurement, monitoring, board reporting. It is comprehensive. Comprehensiveness is the thing it is most proud of, and the thing that will kill it.</p><p>Because when it lands, every function reads the section that concerns it and correctly concludes that it cannot act alone. Data governance needs engineering. Engineering needs the model standard. The model standard needs the risk appetite. The risk appetite needs the board. The board needs a paper from the executive who is awaiting the operationalisation of the framework. Everybody is waiting for a prerequisite that belongs to someone else, and every one of them is being reasonable.</p><p>So the framework is adopted in the specific sense that a committee has agreed on it and it now exists. And nothing about how any decision gets made on Tuesday has changed.</p><p>This is what I mean by a monolith. Not that it is long &#8212; length is fine &#8212; but that it has no entry point. It cannot be started, only completed, and so it is never started.</p><h1><strong><span>Divide by Owner, Not by Topic</span></strong></h1><p>The instinctive fix is to break the framework into pieces, and organisations do this constantly. They almost always break it the wrong way.</p><p>The wrong way is by topic. A fairness workstream, an explainability workstream, a data workstream, a monitoring workstream. It looks like decomposition, and it changes nothing because a topic is not something anybody owns. Fairness is not a department. It has no budget, no head, no seat at the executive table, no line in anyone&#8217;s objectives. A fairness workstream is a coordination problem with a name &#8212; it needs the data people, the modelling people, the risk people, the legal people, and the business owner, none of whom report to it. You have not divided the work. You have divided the document and left the work exactly where it was.</p><p>The right way is by an accountable owner. Cut the framework along the seams that already exist in the organisation &#8212; the places where authority, budget, and a named executive already sit. Not fairness and explainability, but the thing the board must decide and cannot delegate. The thing the risk function enforces before deployment. The thing the technology function builds into the pipeline. The thing the general counsel owes to a regulator. The thing procurement must extract from a vendor before signing. The thing that the operating business runs every day.</p><p>Each of those already has a name associated with it. Each has a budget. Each can begin on Monday without waiting for the others, since the owner has the authority to start.</p><blockquote><p><em>Divide governance by topic, and you get a coordination problem nobody owns. Divide it by owner, and you get a set of programmes that can each begin on Monday.</em></p></blockquote><h1><strong><span>Why the Seams Matter More Than the Content</span></strong></h1><p>This is not an argument about how to organise a filing cabinet. The seams determine whether anything moves, and they do so for three reasons unrelated to the quality of the governance content.</p><p>Different owners move at different speeds. A board sets risk appetite annually. A technology function ships fortnightly. A procurement cycle turns over when a contract renews. A framework that requires all three to move in lockstep moves at the pace of the slowest, which in practice means it does not move. Cut along the ownership seam, and each part runs at its natural clock. The board can ratify a prohibition list while engineering is still building the logging standard, and neither is blocked by the other.</p><p>Different owners respond to different pressures. The general counsel is under pressure due to regulatory exposure. The technology executive is driven by delivery. The chief risk officer is pushed by the board. These pressures are real, and a framework that ignores them fails; a framework that follows the ownership seams can attach each obligation to the pressure that will actually cause it to be honoured.</p><p>And an owner can be held to it. This is the decisive one. The whole series has argued that governance without a named accountable human is theatre &#8212; the royal commission that had to excavate who was responsible; the vendor&#8217;s data scientist who chose the fairness metric; the reviewer with no authority to overturn. A framework divided by topic reproduces exactly that failure at the level of the framework itself. It creates obligations with no owner and then expresses surprise when they are not met.</p><h1><strong><span>Separable, Not Fragmented</span></strong></h1><p>There is an obvious objection here, and it is the right one: this sounds like a recipe for fragmentation. Six separate programmes, six owners, six interpretations, six sets of thresholds, and an organisation whose AI governance is a patchwork that agrees with itself nowhere.</p><p>That objection is correct about the risk, and it identifies precisely what has to be got right. Separability without a spine is fragmentation. What prevents it is that the division occurs in only one layer.</p><p>Divide the doctrine. Unify the enforcement.</p><p>The constitutional layer &#8212; what the organisation will not do, what its risk appetite is, who is ultimately accountable &#8212; is single, board-owned, and a prerequisite to everything else. It is not one of the divisible pieces. It is the root from which the divisible pieces derive their authority, and no workstream may contradict it or reinterpret it locally.</p><p>And at the other end, the enforcement point is single too. One gate that a system must pass before it goes into production. One register of what is deployed and under whose authority. One escalation path when something breaks. One board line where it is all reported. The workstreams feed that gate; they do not each build their own.</p><p>What is divisible is the middle &#8212; the standards, the processes, the tooling, the day-to-day machinery of each domain. That can proceed at six different speeds, under six different owners, with six different budgets, and still compose, because everything at the top is common and everything at the bottom converges.</p><blockquote><p><em>Divide the doctrine, unify the gate. Anything that divides the enforcement point does not decompose the framework. It has abandoned it.</em></p></blockquote><h1><strong><span>What This Buys You</span></strong></h1><p>Consider what becomes possible once the division follows ownership.</p><p>An organisation can start where its pain is. A general counsel exposed to regulatory explainability can build that, alone, now, without waiting for the fairness programme to be scoped. A technology executive who knows the deployment gate is the real problem can build the gate. A board that has looked at the last three essays in this series and gone slightly pale can ratify a prohibition list and a set of accountability assignments in a single meeting, and that ratification is immediately load-bearing for everything built afterwards.</p><p>And they can run in parallel, because none of them is a prerequisite for the others except the constitutional layer, which is a prerequisite for all of them and takes a board meeting rather than a programme.</p><p>This is the difference between a framework that yields value on a horizon of weeks and one that yields nothing until the day it is finished &#8212; which, since it is never finished, is never. The evidence bears this out plainly: the organisations with the highest governance maturity are consistently those with clear, assigned ownership. Not the ones with the best documents. The ones where somebody&#8217;s name is against the thing.</p><h1><strong><span>The Honest Cost</span></strong></h1><p>This approach has a price, and a framework author who claims otherwise is selling something.</p><p>Six owners mean six interpretations to reconcile, and reconciliation is work that a monolith does not require. There will be duplication at the boundaries &#8212; two workstreams both touching model documentation, two both touching vendor obligations &#8212; and someone senior has to arbitrate when they collide. The common layer at the top and the common gate at the bottom have to be maintained against six programmes that will, under delivery pressure, each be tempted to build a local variant that suits them better. That temptation has to be refused every single time, because the first exception is the end of the architecture.</p><p>That is real overhead, and it is the price of adoptability. The monolith has none of it &#8212; no boundary disputes, no reconciliation, perfect internal consistency &#8212; and it achieves this by never being implemented. An internally consistent framework that nobody has started is not a superior artefact. It is a document.</p><h1><strong><span>Everybody Agreed</span></strong></h1><p>Return to the number this essay opened with, because it is not really a statistic about frameworks. It is a statistic about how organisations fail to act on things they sincerely believe.</p><p>Eighty-seven per cent have the framework. Fewer than a quarter run it. Nobody in that gap is a villain &#8212; and by now that sentence should sound familiar, because it has been true of every case in this series. Nobody at 7-Eleven decided to conduct biometric surveillance on 1.6 million customers. Nobody at Northpointe set out to double the false-positive rate for Black defendants. Nobody in the Dutch tax authority intended to take 1,600 children from their parents. Nobody downloaded child abuse material on purpose.</p><p>In every case, the harm occurred through a gap where a named human being should have been standing, and in every case, the organisation had documents stating otherwise.</p><p>The framework is not the governance. The framework is a description of governance that someone still has to build &#8212; and they will only build it if the thing they were handed can be started by someone with the authority to do so on a Monday, without permission from four other people who are all waiting for each other.</p><p>Everybody agreed. That was never the hard part. The hard part is that agreement, distributed evenly across an organisation and attached to nobody in particular, is indistinguishable from nothing at all.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1><strong><span>References</span></strong></h1><p><em>This piece draws on published survey research into AI governance adoption and implementation.</em></p><ol><li><p>UNESCO and Thomson Reuters Foundation. Responsible AI in Practice: 2025 Global Insights from the AI Company Data Initiative. Based on public data from 3,000 companies, collected July&#8211;November 2025.</p></li><li><p>McKinsey &amp; Company. State of AI Trust in 2026: Shifting to the Agentic Era. AI Trust Maturity Survey, approximately 500 organisations, December 2025 &#8211; January 2026.</p></li><li><p>PwC. 2025 US Responsible AI Survey. Survey of 310 US business leaders, September&#8211;October 2025.</p></li><li><p>AuditBoard. From Blueprint to Reality: Execute Effective AI Governance in a Volatile Landscape. Survey of over 400 GRC and audit professionals, 2025.</p></li><li><p>Stanford Institute for Human-Centered AI. AI Index Report 2026, Responsible AI chapter.</p></li></ol>]]></content:encoded></item><item><title><![CDATA[Nobody Knows Where It Came From]]></title><description><![CDATA[And every control you built is standing on it.]]></description><link>https://dataaicontinuum.substack.com/p/nobody-knows-where-it-came-from</link><guid isPermaLink="false">https://dataaicontinuum.substack.com/p/nobody-knows-where-it-came-from</guid><dc:creator><![CDATA[M Maruf Hossain, PhD, GAICD]]></dc:creator><pubDate>Sat, 25 Jul 2026 21:00:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!OSTV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>LAION-5B is a dataset of more than five billion images, scraped from the open web without human supervision. It was used to train Stable Diffusion, which in turn became a foundational component of thousands of image-generation tools embedded in apps, websites, and products worldwide.</p><p>In December 2023, a researcher at the Stanford Internet Observatory ran perceptual and cryptographic hash matching across it. He found 3,226 suspected instances of child sexual abuse material. More than a thousand were externally validated as known CSAMs.</p><p>LAION took the dataset down. The Stanford report recommended that models trained on it be deprecated and their distribution ceased where feasible.</p><p>And here is the sentence that ought to change how every organisation thinks about the data under its AI. The lead author put it plainly: if you downloaded that dataset for any purpose, you have CSAM unless you took extraordinary measures to prevent it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OSTV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OSTV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!OSTV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!OSTV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!OSTV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OSTV!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png" width="1200" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:2713193,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dataaicontinuum.substack.com/i/206659405?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OSTV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!OSTV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!OSTV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!OSTV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b7f903-ce91-4265-935a-d97df6f6be94_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Nobody had known. Not LAION, which built it. Not the companies that trained on it. Not the thousands of businesses that shipped products built on top of models trained on it. Every one of them would have told you, in complete good faith, that their training data was fine &#8212; because not one of them could see.</p><div class="callout-block" data-callout="true"><h1 style="text-align: center;"><strong><span>3,226</span></strong></h1><p style="text-align: center;">Suspected instances of child sexual abuse material were found in a dataset of five billion scraped images used to train widely deployed AI models. Over a thousand were externally validated. It took a specialist research team with hash-matching tools to find them.</p><p style="text-align: center;"><em><span>Stanford Internet Observatory, Identifying and Eliminating CSAM in Generative ML Training Data and Models, December 2023</span></em></p></div><h1><strong><span>The Question Nobody Can Answer</span></strong></h1><p>Pick any AI system in your organisation that makes decisions about people. Now ask the question that sounds trivially simple and turns out not to be.</p><p>Where did its training data come from?</p><p>Not roughly. Specifically. Which datasets, obtained from whom, collected under what basis, transformed how, by whom, and when. If some of it is personal information, on what lawful footing was it collected &#8212; and does that footing extend to training a model, or merely to the purpose for which it was originally gathered? If any of it was bought, what did the vendor actually warrant, and can they evidence it? If the system is built on a foundation model, what was that model trained on?</p><p>In most organisations, this question produces silence, followed by a series of partial answers that trail off. The data science team knows what it pulled. The data engineering team knows what it ingested. Nobody has the whole chain, because nobody was ever asked to keep one &#8212; and the model works, so the question never became urgent.</p><p>Then the system goes into production and starts deciding things about people, and every claim the organisation makes about it quietly rests on a fact nobody has established.</p><h1><strong><span>What You Are Actually Claiming</span></strong></h1><p>Consider what an organisation asserts when it says its AI is well governed. Then notice what each of those assertions silently assumes about the data.</p><p>It says the system is fair &#8212; that it has measured disparities across groups and they fall inside an acceptable threshold. But a fairness measurement is a statement about a population. It says: within the people this system affects, outcomes do not differ unacceptably by protected characteristic. If the organisation cannot characterise the population its training data actually represents &#8212; who is in it, who is missing, what proportion of each group &#8212; then the fairness metric is a number computed over an unknown. It is precise, reproducible, green on the dashboard, and unanchored to anything.</p><p>It says the system is explainable &#8212; that it can name the principal factors that drove any given decision. But an explanation is a claim about what the model learned. If nobody can say what it learned from, the explanation is a description of the model&#8217;s behaviour dressed as an account of its reasoning. It may be perfectly accurate about what the model did. It cannot be vouched for as an account of why.</p><p>It says a person can contest the decision &#8212; that a reviewer can look again at the specific basis on which it was made. But a review reconstructs a decision from its inputs. If the provenance of those inputs is unknown, the reviewer is examining a record whose reliability the organisation cannot attest to itself.</p><blockquote><p><em>Unknown data does not simply fail the data test. It silently voids the fairness test, the explanation, and the review &#8212; each of which will still run, still pass, and still report green.</em></p></blockquote><h1><strong><span>The Failure That Leaves No Trace</span></strong></h1><p>This is what makes the provenance gap more dangerous than the failures in the earlier essays in this series, and it is worth being precise about why.</p><p>A prohibited use announces itself eventually &#8212; someone finds out you were scanning faces. A fairness breach shows up as a measurable disparity. An absent explanation produces a complaint. A rubber-stamp review can be exposed by calculating an override rate.</p><p>A provenance gap does none of this. It produces no symptoms. The model trains. The metrics compute. The dashboards go green. The audit passes because the audit checks whether the controls were run, not whether the ground beneath them was ever verified. An organisation can operate for years in full compliance with its own framework on data whose origin nobody can state &#8212; and nothing will ever surface it.</p><p>Until something does. And when it does, it does not arrive as a data-quality issue. It arrives as a regulator asking whether you had consent, or a court asking what the model learned, or a research team publishing a paper about what was in the dataset all along.</p><p>LAION did not degrade. It was always what it was. What changed in December 2023 was that somebody finally looked.</p><h1><strong><span>The Part You Cannot Fix With Diligence</span></strong></h1><p>There is a version of this problem that careful work solves. Document your sources. Keep a lineage. Check your consent basis. Assess your data quality. All of this is achievable, and an organisation that does it is in a far better position than one that does not.</p><p>And then there is the version that careful work does not solve, and it is now the version most organisations are in.</p><p>If your system is built on a foundation model &#8212; and increasingly, everything is &#8212; then a material part of its behaviour was determined by a training corpus that the provider will not fully disclose and that you cannot inspect. This is not a failure of your diligence. It is not something a better vendor questionnaire will fix. The information is structurally unavailable to you, and no amount of contractual language creates knowledge that nobody has.</p><p>So the honest position for most enterprises today is this: there is a layer beneath your AI whose provenance you cannot establish, and you are accountable for its behaviour anyway.</p><blockquote><p><em>The vendor&#8217;s opacity does not transfer the obligation. It simply means you have built on ground you are not permitted to inspect, and you remain answerable for what is buried in it.</em></p></blockquote><p>This does not eliminate the obligation, nor is it an excuse. It means the unknown has to be named, assessed for its specific use, and signed off by someone with the authority to accept it &#8212; rather than silently absorbed into a system that is then described as governed.</p><h1><strong><span>What Knowing Your Data Actually Means</span></strong></h1><p>The requirement is not a folder of documentation. It is the ability to answer four questions about every material dataset under a consequential system, on demand, without a project.</p><ol><li><p><strong>Where it came from.</strong> The origin, the collection method, and the chain of custody and transformation from source to the form the model was trained on. Not a vague sense of the source. A lineage you could put in front of a regulator.</p></li><li><p><strong><span>On what basis?</span></strong> If it contains personal information, there must be a specific lawful basis for using it to train this model. Consent to collect data for one purpose is not consent to train a model on it for another, and the fact that everybody does it does not make it so.</p></li><li><p><strong>Whether it fits.</strong> Whether the data actually represents the population the system will decide about &#8212; completeness, currency, and representativeness &#8212; depends on the model, because a model trained on a population that excludes the people it will judge is not a slightly worse model. It is a model whose errors are systematic, invisible, and concentrated on the people least able to complain.</p></li><li><p><strong>Whether it still holds.</strong> Provenance is not a certificate you obtain once. A consent basis can lapse. A data-sharing right can terminate. A dataset can go stale as the world it describes moves on. The question is not whether you knew your data at the time of deployment. It is whether you know it now.</p></li></ol><h1><strong><span>The Uncomfortable Audit</span></strong></h1><p>Here is an exercise that costs nothing and tends to be clarifying, in the way a diagnosis is.</p><p>Take your three most consequential AI systems. For each, ask the team to produce, within a week, the documented provenance of every material dataset it was trained on &#8212; origin, custody, consent basis, and quality assessment.</p><p>Watch what comes back.</p><p>In most organisations, some of it will arrive promptly and in good order. Some will arrive after a scramble, reconstructed from memory and commit logs. And some will not arrive at all, because the person who built that pipeline has left, or the vendor cannot say, or the dataset was assembled in 2019 by someone who did not think anyone would ever ask.</p><p>That last category is the finding. Not the volume of it &#8212; the existence of it. Because those are the systems that are currently deciding things about people, on a basis the organisation cannot state, while every control built on top of them reports that everything is fine.</p><h1><strong><span>The Ground Under Everything</span></strong></h1><p>This series has worked through the things a responsible organisation owes the people its systems judge. A prohibition on the uses it will not make. A fairness threshold someone chose and owns. An explanation the affected person can actually use. A right to challenge that a human with real authority can honour.</p><p>Every one of them assumes you know what the system was built on.</p><p>Data provenance is not the fourth or fifth item on a responsible-AI checklist, to be addressed only after the visible controls are in place. It is the ground the other controls stand on, and it is the only one whose absence produces no symptoms at all &#8212; no complaint, no discrepancy, no failed audit. Just a set of green ticks over a foundation nobody checked.</p><p>Somebody, somewhere, assembled the data your model learned from. They made choices about what to include and what to leave out, and those choices are now inside the decisions your organisation makes about people&#8217;s money, their housing, their employment, their liberty.</p><p>If you cannot say who they were or what they chose, then you are not governing that system. You are operating it and hoping.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1><strong><span>References</span></strong></h1><p><em>This piece draws on the Stanford Internet Observatory investigation into LAION-5B and reporting on its consequences.</em></p><ol><li><p>Thiel, D. Identifying and Eliminating CSAM in Generative ML Training Data and Models. Stanford Internet Observatory, Stanford University, December 2023.</p></li><li><p>Schuhmann, C., et al. LAION-5B: An Open Large-Scale Dataset for Training Next Generation Image-Text Models. Advances in Neural Information Processing Systems (NeurIPS), 2022.</p></li><li><p>Reporting on the removal of LAION-5B, 404 Media and TechCrunch, December 2023 and August 2024.</p></li><li><p>Office of the Australian Information Commissioner. Determination on Clearview AI, Inc. Canberra, 14 October 2021.</p></li></ol>]]></content:encoded></item><item><title><![CDATA[Somebody Looked at It. Nobody Changed It.]]></title><description><![CDATA[Why &#8220;human review&#8221; is the easiest control to fake]]></description><link>https://dataaicontinuum.substack.com/p/somebody-looked-at-it-nobody-changed</link><guid isPermaLink="false">https://dataaicontinuum.substack.com/p/somebody-looked-at-it-nobody-changed</guid><dc:creator><![CDATA[M Maruf Hossain, PhD, GAICD]]></dc:creator><pubDate>Wed, 22 Jul 2026 21:00:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!u0Vz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>From 2013, the Dutch tax authority ran a self-learning risk model over childcare benefit claims. It scored parents on the likelihood that their claim was fraudulent. Among the variables it learned to weigh were having a second nationality and having a low income.</p><p>When the model flagged a family, their benefits were suspended, and the tax authority demanded repayment of everything they had received, sometimes going back years. The sums ranged from 20,000 euros to 60,000 euros, payable in full, with no instalment plan. The trigger was often a missing signature or an unticked box.</p><p>Around 26,000 families were wrongly accused. Some estimates put it above 35,000. Parents were bankrupted, lost their homes, and lost their jobs. More than sixteen hundred children were taken into foster care. Some parents took their own lives.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!u0Vz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!u0Vz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!u0Vz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!u0Vz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!u0Vz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!u0Vz!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png" width="1200" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:2571761,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dataaicontinuum.substack.com/i/206658916?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!u0Vz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!u0Vz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!u0Vz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!u0Vz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80fbff1b-7b33-4d57-be8e-dde4eebad0d7_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The parliamentary inquiry that finally examined all this gave its report a title that does not require translation: Ongekend Onrecht. Unprecedented Injustice. It found that the tax authority had violated fundamental principles of the rule of law, and that fraud investigations had been triggered by something as simple as an administrative error, with no malicious intent on anyone&#8217;s part.</p><p>On 15 January 2021, the entire Dutch cabinet resigned.</p><div class="callout-block" data-callout="true"><h1 style="text-align: center;"><strong><span>26,000</span></strong></h1><p style="text-align: center;">Families were wrongly accused of childcare benefit fraud by an algorithm that treated dual nationality as a risk factor. More than 1,600 children were removed to foster care. The government fell.</p><p style="text-align: center;"><em><span>Ongekend Onrecht (Unprecedented Injustice), Dutch parliamentary inquiry, December 2020</span></em></p></div><h1><strong><span>The Sentence That Explains Everything</span></strong></h1><p>Buried in the analysis of how this happened is a sentence that ought to be printed and pinned above every desk where an AI system is being designed.</p><p>The risk score was not a tool to support a caseworker&#8217;s judgment. It was treated as a judgment.</p><p>The Dutch tax authority was not short of humans. There were caseworkers. There were supervisors. There were managers, directors, a state secretary, a minister, and a cabinet. The system did not operate in a vacuum, and at no point did anyone claim that a machine had autonomously ruined 30,000 families while the civil service watched, powerless.</p><p>Humans were in the loop at every stage. Humans read the flags. Humans sent the letters. Humans received the phone calls from parents who could not understand what they had done wrong, and humans told them to pay.</p><p>Somebody looked at it. Nobody changed it.</p><h1><strong><span>The Control That Is Not a Control</span></strong></h1><p>Every organisation deploying consequential AI offers the same reassurance, and it is offered so reflexively that it has stopped being examined: there is a human in the loop.</p><p>It is the most comforting sentence in AI governance and the least informative. It describes a position on an org chart. It says nothing whatsoever about whether that person can, in practice, do anything.</p><p>Consider what being in the loop actually meant for a Dutch caseworker. They saw what the system surfaced &#8212; a risk score, a flag, a case marked for recovery. They did not see the model, could not interrogate its reasoning, and had no way to know that dual nationality was among the variables driving the score in front of them. They had a queue. They had targets. The institutional culture around them, as the inquiry found, was fraud-first: the presumption ran against the citizen.</p><p>Now ask what it would have taken for that person to overturn the machine. They would have had to form an independent view against a system the organisation trusted, justify it to a supervisor, absorb the delay in their own throughput, and accept the professional risk of being the person who let a suspected fraudster through. Agreeing with the system cost nothing and took seconds. Disagreeing costs time, standing, and nerve.</p><p>Put a competent, decent person in that position, and they will agree with the machine. Not because they are lazy or cruel, but because every force acting on them points that way. The review is real. The authority is not.</p><blockquote><p><em>Human presence is not human authority. A person who reviews what the machine surfaced under a clock, with no power to see inside it and no protection from being overruled, is not oversight. They are a signature.</em></p></blockquote><h1><strong><span>Why This Control Is the Easiest to Fake</span></strong></h1><p>Every other control in AI governance leaves evidence. A fairness threshold is a number. An audit trail has records. A prohibited-use screen has a decision logged under a name. If those do not exist, their absence is visible.</p><p>Human review leaves evidence of exactly the same kind, whether it is real or theatrical. A case was reviewed. A person&#8217;s name is against it. A timestamp exists. The box is ticked. And a review in which the human agreed with the machine because agreeing was the path of least resistance looks, in every record the organisation keeps, identical to a review in which the human independently reached the same conclusion.</p><p>This is why it is the easiest control to fake &#8212; and, more troubling, the easiest to fake unintentionally. Nobody has to decide to build a rubber stamp. You get one for free, by default, simply by placing a human in a process without giving them the time, the information, the standing, or the protection they would need to disagree.</p><p>The organisation then reports, in complete good faith, that its automated decisions are subject to human review. The auditor confirms it. The regulator accepts it. And the override rate, if anyone ever calculated it, would be indistinguishable from zero.</p><blockquote><p><em>An organisation that cannot tell you how often its human reviewers overturn the machine does not have human oversight. It has a person and a hope.</em></p></blockquote><h1><strong><span>The Number Nobody Calculates</span></strong></h1><p>So here is a question worth asking inside your own organisation, and it takes about a day to answer.</p><p>For every AI system that makes or shapes decisions about people and that has a human review step, how often does that human change the outcome?</p><p>Not how many cases were reviewed. How many were reversed?</p><p>If the answer is that nobody has ever calculated it, that is itself the finding, and it should be treated as one. It means the control has been claimed, relied upon, reported to a board, and never once tested. It means the organisation has been assuring itself for years that a mechanism&#8217;s effectiveness has never been measured.</p><p>And if the number comes back at 1-2%, resist the comfortable interpretation. The comfortable interpretation is that the model is simply very good. The uncomfortable one is that the reviewers cannot see enough to disagree, do not have time to disagree, or have learned that disagreeing is not rewarded. Both interpretations produce the same statistic. Only one of them is oversight.</p><p>The distinguishing test is not the rate. It is what happens when a reviewer overturns the machine. Is that treated as the control working &#8212; as evidence that the system caught an error before it reached a person? Or does it generate a query, a variance report, a quiet conversation about why this officer&#8217;s numbers look different from everyone else&#8217;s?</p><p>Organisations tend to know the answer to that question immediately, and to be uncomfortable saying it out loud.</p><h1><strong><span>What a Real Review Needs</span></strong></h1><p>A contestation review that can actually overturn a machine requires four things, and it fails if it lacks any one of them.</p><ul><li><p><strong>Independence.</strong> The review cannot be conducted by the process that produced the decision, nor can it consist of re-running the model. A second look at the same output by the same system is not a second look; it is the first decision defending itself.</p></li><li><p><strong>The actual record.</strong> The reviewer must see the specific facts of this decision &#8212; the factors that drove it, the inputs it used, the thresholds it applied &#8212; not a general account of how the system behaves. A reviewer working from the machine&#8217;s own summary is reasoning inside the machine&#8217;s frame and will almost always confirm it.</p></li><li><p><strong>Real authority, exercised.</strong> The power to uphold, modify, or overturn &#8212; with the time to use it, the standing to survive using it, and no penalty attached. This is the one that quietly fails, not by being removed but by being made expensive.</p></li><li><p><strong>A route in.</strong> None of the above matters if the <span>affected person cannot access</span> the process at all. The Dutch families were, according to the inquiry&#8217;s findings, frequently given no explanation, no appeal pathway, and no evidence beyond the score &#8212; and were then required to prove their innocence of a fraud they had not been told they were suspected of, using documents the tax service had often lost.</p></li></ul><p>That is the inverted burden of proof, and it is the signature of a system that has stopped treating its output as a proposal and started treating it as a finding of fact.</p><h1><strong><span>The Objection</span></strong></h1><p>A fair objection: real review at scale is impossible. A bank makes millions of automated decisions. A tax authority processes tens of thousands of benefit claims. You cannot have a human independently re-adjudicate each one &#8212; that would defeat the purpose of automating anything and would cost more than the system&#8217;s entire benefit.</p><p>This is correct, and it is not the argument.</p><p>Nobody is proposing that every automated decision receive a substantive human review. The proposal is narrower and entirely affordable: that any decision a person challenges receives one. The machine decides by default. A human decides on a challenge. That is the whole design, and the volume it generates is a small fraction of the volume the system handles, because most people do not contest most decisions.</p><p>What makes the volume manageable is precisely what makes the right meaningful &#8212; it is exercised by the people who believe the machine got it wrong about them. Those are the cases where a second look has the highest value, and where the second look is currently most likely to be a formality.</p><p>The Dutch tax authority did not fail because it could not review 26,000 cases. It failed because when parents rang up to say the machine was wrong about them, nobody who answered the phone had the authority to agree.</p><h1><strong><span>The Last Thing Standing</span></strong></h1><p>Contestation is the final control and the one that matters most, because it is the only one that operates after everything else has failed.</p><p>The prohibited-use screen can miss a use. The fairness threshold can be set incorrectly. The explanation can be inadequate. The data can be flawed in ways nobody detected. Every upstream control is fallible, and in any system of sufficient scale, some of them will fail some of the time.</p><p>The right to contest is what stands between that failure and the person it is about to harm. It is the moment at which a human being can look at what the machine has decided and say: not this one, not this person, not today.</p><p>Which is why an organisation that has built every other control and left this one hollow has built nothing at all. The machine will be wrong. It is wrong for somebody right now. The only question that matters is whether, when that person picks up the phone, anyone on the other end can actually help them.</p><p>In the Netherlands, for eight years, there was not. Somebody looked at each of those cases. Nobody changed them. And by the time anybody with authority did look &#8212; properly, with the power to act &#8212; 26,000 families had already been destroyed, sixteen hundred children were in foster care, and a government fell.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1><strong><span>References</span></strong></h1><p><em>This piece draws on the Dutch parliamentary inquiry, findings of the Dutch Data Protection Authority, and reporting on the toeslagenaffaire.</em></p><ol><li><p>Tweede Kamer der Staten-Generaal. Ongekend Onrecht: Verslag Parlementaire Ondervragingscommissie Kinderopvangtoeslag. The Hague, 17 December 2020.</p></li><li><p>Autoriteit Persoonsgegevens. Findings on the processing of nationality data by the Belastingdienst. The Hague, 17 July 2020.</p></li><li><p>Nationale Ombudsman. Geen powerplay maar fair play. The Hague, 2017.</p></li><li><p>Reporting on the toeslagenaffaire by Trouw and RTL Nieuws, 2018&#8211;2021.</p></li><li><p>Henley, J. Dutch government faces collapse over child benefits scandal. The Guardian, 14 January 2021.</p></li></ol>]]></content:encoded></item><item><title><![CDATA[We Can Explain It. Just Not to You.]]></title><description><![CDATA[Three audiences need three explanations. The one owed to the person judged is the one that goes missing.]]></description><link>https://dataaicontinuum.substack.com/p/we-can-explain-it-just-not-to-you</link><guid isPermaLink="false">https://dataaicontinuum.substack.com/p/we-can-explain-it-just-not-to-you</guid><dc:creator><![CDATA[M Maruf Hossain, PhD, GAICD]]></dc:creator><pubDate>Mon, 20 Jul 2026 21:00:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!odQc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In November 2019, a software developer named David Heinemeier Hansson applied for an Apple Card and was granted a credit limit twenty times higher than his wife&#8217;s. They filed joint tax returns. She had the higher credit score.</p><p>He called Goldman Sachs, which underwrote the card, and asked why. The representatives could not tell him. They told him, repeatedly, that it was the algorithm. He posted about it. Steve Wozniak replied that the same thing had happened to him and his wife. The New York Department of Financial Services opened an investigation.</p><p>Then Goldman raised his wife&#8217;s credit limit. It did so without requesting a single additional document and without addressing why the limit had been low in the first place.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!odQc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!odQc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!odQc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!odQc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!odQc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!odQc!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png" width="1200" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:2407166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dataaicontinuum.substack.com/i/206657669?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!odQc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!odQc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!odQc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!odQc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83f7fe52-0fe1-4aa8-bf52-9f3aaf1d668d_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The regulator reviewed underwriting data for approximately 400,000 New York applicants. It found no unlawful discrimination. Applications from women and men with similar credit characteristics generally received similar outcomes. And it described the bank&#8217;s credit decisions in three words that are worth reading slowly.</p><p>Explainable. Lawful. Consistent with the bank&#8217;s credit policy.</p><div class="callout-block" data-callout="true"><h1 style="text-align: center;"><strong><span>400,000</span></strong></h1><p style="text-align: center;">New York applications reviewed by the regulator, which found the bank&#8217;s credit decisions to be &#8220;explainable, lawful, and consistent&#8221; &#8212; while the customers who called to ask why were told it was the algorithm.</p><p style="text-align: center;"><em><span>New York State Department of Financial Services, Report on the Apple Card Investigation, March 2021</span></em></p></div><h1><strong><span>Explainable to Whom?</span></strong></h1><p>Hold both of those facts in your head at once, because they are both true and they are the whole argument.</p><p>The system was explainable. A regulator with subpoena powers, full access to the model, the underwriting data, thousands of pages of records, and months of investigation could reconstruct exactly why any given credit limit was what it was. The bank could show its work. The decisions held up.</p><p>And the woman who called to ask why she had been given a twentieth of her husband&#8217;s limit, on a better credit score, was told that it was the algorithm.</p><p>Both of those describe the same system. The system was, in the regulator&#8217;s words, explainable &#8212; and the person it had judged could not obtain an explanation. Nothing here is a contradiction. It is simply that the word explainable was doing entirely different work in the two sentences, and almost nobody noticed.</p><blockquote><p><em>A system can be fully explainable to a regulator and completely opaque to the person it just refused. Those are not degrees of the same thing. They are different obligations to different people, and meeting one says nothing about the other.</em></p></blockquote><h1><strong><span>Three People Are Asking, and They Want Different Things</span></strong></h1><p>When a consequential AI decision is made about a person, three parties have a legitimate claim to an explanation, and what each of them needs bears almost no resemblance to what the others need.</p><p>The regulator needs a complete, tamper-evident record from which the decision can be reconstructed and defended, months or years later, under adversarial examination. It wants the model version, the inputs, the policy applied, the thresholds, and the audit trail. It is exhaustive, technical, and no ordinary person will ever read it &#8212; which is fine, because no ordinary person is its audience.</p><p>The operator &#8212; the officer, the underwriter, the case manager who sits between the machine and the customer &#8212; needs something different. They need a concise, real-time account of what the system found and how confident it is, sufficient to agree with it, question it, or override it. They have context, a queue, and about ninety seconds. An audit log is useless to them. So it is a policy document.</p><p>And the person who was refused needs something different again: what actually drove this decision about me, in language I can understand, and what would I have to change for the answer to be different? They have no technical knowledge, no access to the model, and the highest stakes of anyone in the chain. It is their credit, their housing, their job, their liberty.</p><p>Three audiences. Three explanations. Three separate obligations. And the artefact that discharges one discharges none of the others.</p><h1><strong><span>The One That Always Gets Built</span></strong></h1><p>Of the three, one is reliably built, and it is not an accident which one.</p><p>The audit trail gets built because the organisation needs it. Logging is a familiar engineering discipline. Regulators ask for it directly, and they ask with the power to fine. Internal audit wants it. Legal wants it. Its audience has standing, resources, and teeth.</p><p>So the audit trail exists, and it tends to be genuinely good. And then something quietly follows: the organisation, having built the artefact that protects itself, says that its AI is explainable &#8212; and it is telling the truth.</p><p>The operator&#8217;s explanation, meanwhile, is usually approximated. A confidence score. A list of contributing features. Something that looks like a reason without being usable as one.</p><p>And the individual&#8217;s explanation is the one that goes missing. Not because anyone decided to withhold it. Because its audience &#8212; the applicant, the customer, the citizen &#8212; has the least power to demand it, the least standing to know what they are owed, and no seat at the table where the system was scoped. The obligation is real, and the pressure to meet it is nil.</p><blockquote><p><em>The tier that protects the organisation is the tier that gets funded. The tier that protects the person is the tier that gets deferred. This is not a coincidence; it is the shape of every incentive in the building.</em></p></blockquote><h1><strong><span>It&#8217;s Just the Algorithm</span></strong></h1><p>Which brings us back to the phone call, because that sentence deserves proper examination.</p><p>When a Goldman representative told a customer that it was the algorithm, they were not being evasive. They were being accurate. They genuinely could not explain the decision, because nothing in the system had been built to tell them &#8212; and nothing had been built to tell the customer, because the customer&#8217;s explanation was not an artefact anyone had been required to produce.</p><p>The information existed. Somewhere in the underwriting data that the regulator would later review across 400,000 applicants, the factors that drove that specific credit limit were sitting there, recoverable. The bank was not hiding them. It simply had no mechanism that turned them into a sentence a human being could hear.</p><p>So the customer got the truest thing the representative could say: nothing at all.</p><p>And notice how the story ends. Goldman raised the wife&#8217;s credit limit without additional documentation. That is what an organisation does when it cannot explain a decision and needs the complaint to go away: it changes the outcome, rather than the process, for the person who complained loudly enough to be heard. Everybody else keeps the limit they were given and never finds out why.</p><h1><strong><span>What the Person Is Actually Owed</span></strong></h1><p>An explanation owed to an individual is not a shorter version of the audit trail. It has specific content, and its failure lies in vagueness, even when attempted.</p><ul><li><p><strong>The principal factors.</strong> Not the model, not a feature list &#8212; the handful of things that actually drove this decision, in order, stated so a person recognises them. Your existing debt relative to your income<span> and the length of your credit history</span> were the main factors. Not: a range of factors was considered. That sentence explains nothing, and everyone who writes it knows so.</p></li><li><p><strong>The counterfactual.</strong> For an adverse decision, the smallest change that would have produced a different outcome. Had your reported income been higher by roughly this much, or had this account not been in arrears, the decision would have changed. This is what makes the explanation usable rather than merely informative. It is the difference between being told why the door is shut and being told where the handle is.</p></li><li><p><strong>Delivery on time matters.</strong> In language, a person without a statistics degree can act on. An explanation that comes after escalation, on request, three weeks later, has not been delivered. It has been extracted.</p></li></ul><h1><strong><span>Why You Cannot Bolt This On</span></strong></h1><p>Here is the part that makes this a design problem rather than a communications problem, and it is the reason so many organisations discover it too late.</p><p>The principal factors and the counterfactual cannot be reverse-engineered from a model that was not built to produce them. The attribution has to be computed at the moment of decision and captured. The counterfactual requires the system to answer a question about a decision it did not make. If the model was chosen or bought without that capability, no amount of goodwill afterwards will conjure it &#8212; the information was either recorded when the decision was made, or it is gone.</p><p>This means explainability to the individual is not a reporting feature to be added in a later release. It is a constraint on which models you are permitted to use at all, decided before anything is built or procured. A vendor&#8217;s system that cannot explain why it made a decision is not a system with a documentation gap. It is a system that cannot be deployed against people, and the right time to discover that is in procurement, not in a phone call with a customer you cannot answer.</p><blockquote><p><em>A black box you bought is still a black box you own. The vendor&#8217;s opacity does not transfer the obligation; it just means you have acquired a system you cannot use responsibly.</em></p></blockquote><h1><strong><span>The Question to Ask Your Own Organisation</span></strong></h1><p>Somewhere in your organisation, there is a claim that the AI is explainable. It is probably true. The question is what it is true of.</p><p>Ask to see the explanation a person actually received after an adverse automated decision. Not the audit log. Not the model card. Not the policy. The letter, the screen, the sentence that went to the human being on the other end.</p><p>Then ask whether it names the factors that drove their outcome, and whether it tells them what would have changed it. If it says that a range of factors was considered, or that the decision was based on our credit criteria, or nothing at all, then the organisation has built the tier that protects itself and skipped the one that protects them.</p><p>And it will have done so while truthfully saying, in a regulatory filing and under oath, that its systems are explainable.</p><h1><strong><span>Both Things Were True</span></strong></h1><p>The regulator was right. The decisions were explainable, lawful, and consistent. 400,000 applications were reviewed, and no discrimination was found; the model is doing what the credit policy says it should.</p><p>The customer was also right. She could not find out why. Nobody could tell her. It was the algorithm.</p><p>There is no contradiction between those two sentences, and that is precisely the problem. An organisation can satisfy every explainability obligation it has been asked about, pass every audit, survive every investigation, and still leave the people it judges with nothing they can understand or use &#8212; and it will not even notice, because the word explainable will keep coming back green.</p><p>Explainable is not a property. It is a relationship, and it has to be true of somebody. Ask who.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1><strong><span>References</span></strong></h1><p><em>This piece draws on the New York State Department of Financial Services&#8217; investigation report and contemporaneous reporting on the Apple Card.</em></p><ol><li><p>New York State Department of Financial Services. Report on Apple Card Investigation. Albany, March 2021.</p></li><li><p>New York State Department of Financial Services. DFS Issues Findings on the Apple Card and Its Underwriter Goldman Sachs Bank. Press release, 23 March 2021.</p></li><li><p>Reporting on the Apple Card credit limit allegations, CNBC and CNN Business, November 2019.</p></li><li><p>Banking Dive. Goldman cleared of bias claims in NYDFS&#8217;s Apple Card probe. 24 March 2021.</p></li></ol>]]></content:encoded></item><item><title><![CDATA[Somebody Chose This Number]]></title><description><![CDATA[Fairness is not a property your model has. It is a threshold someone picked, and you should know who.]]></description><link>https://dataaicontinuum.substack.com/p/somebody-chose-this-number</link><guid isPermaLink="false">https://dataaicontinuum.substack.com/p/somebody-chose-this-number</guid><dc:creator><![CDATA[M Maruf Hossain, PhD, GAICD]]></dc:creator><pubDate>Sat, 18 Jul 2026 23:00:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HIZm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In August 2013, a judge in La Crosse County, Wisconsin, sentenced Eric Loomis to eight years and six months in prison. In doing so, he noted that Loomis had been identified, through a COMPAS assessment, as an individual at high risk to the community.</p><p>COMPAS is a risk-assessment tool sold by a private company. It takes a defendant&#8217;s history and answers to a questionnaire, then returns a score from 1 to 10 predicting the likelihood of reoffending. Judges across the United States have used those scores in decisions about bail, sentencing, and parole.</p><p>Three years later, ProPublica examined more than 10,000 COMPAS assessments in Broward County, Florida, and published a finding that became one of the most-cited results in the history of algorithmic accountability. Among defendants who did not go on to reoffend, Black defendants were nearly twice as likely as white defendants to have been labelled high risk. Among those who did reoffend, white defendants were far more likely to have been labelled low risk. The headline read: Machine Bias.</p><p>Northpointe, the company that built COMPAS, responded with a rebuttal. It said the tool was fair, and it produced numbers to prove it. Among defendants who scored a seven, roughly 60% of white defendants and 61% of Black defendants went on to reoffend. A seven meant the same thing regardless of race. The score was doing exactly what it claimed.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HIZm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HIZm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!HIZm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!HIZm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!HIZm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HIZm!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png" width="1200" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:2336572,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dataaicontinuum.substack.com/i/206656480?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HIZm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!HIZm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!HIZm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!HIZm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3456a9d4-73b3-4009-a13f-fd3d4c094f9d_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Here is the part that should unsettle you. Both of them were telling the truth.</p><div class="callout-block" data-callout="true"><h1 style="text-align: center;"><strong><span>60% and 61%</span></strong></h1><p style="text-align: center;">The share of white and Black defendants who scored 7 on COMPAS and went on to reoffend was nearly identical and formed the basis of Northpointe&#8217;s claim that the tool was fair. Both that claim and ProPublica&#8217;s opposite finding are true of the same data.</p><p style="text-align: center;"><em><span>ProPublica, Machine Bias, May 2016; Northpointe response, 2016</span></em></p></div><h1><strong><span>Two True Answers to the Same Question</span></strong></h1><p>ProPublica and Northpointe were not arguing about the data. They agreed on the data. They were arguing about what the word fair means, and neither of them said so out loud, because neither of them fully realised it.</p><p>ProPublica used a definition that most people, asked on the spot, would endorse: when the system is wrong, it should be wrong equally often for everyone. If you did not reoffend, your chance of being wrongly branded high-risk should not depend on your race. By that standard, COMPAS failed, and failed badly.</p><p>Northpointe used a different definition, which most people would also endorse if you asked them separately: a score should mean the same thing for everyone. A seven should carry the same probability of reoffending whether the defendant is Black or white, or the score is lying to the judge. By that standard, COMPAS passed.</p><p>Both definitions are reasonable. Both are defensible in a courtroom. And they cannot both be satisfied.</p><h1><strong><span>The Mathematics That Ends the Argument</span></strong></h1><p>This is not a matter of opinion, or of engineering effort, or of a better model trained on cleaner data. It is a theorem.</p><p>In 2016, Kleinberg, Mullainathan and Raghavan formalised three fairness conditions at the heart of these debates and proved that, except in highly constrained special cases, no method can satisfy them simultaneously. Chouldechova proved a parallel result independently. The constrained special cases are these: either the system predicts perfectly, or the two groups have identical base rates &#8212; the same proportion of each group genuinely belongs to the class being predicted.</p><p>Perfect prediction does not exist. Equal base rates, in the domains where these systems are deployed &#8212; criminal justice, credit, employment, welfare &#8212; do not exist either, because the world the data records is not equal. Black defendants in Broward County were rearrested at a higher rate than white defendants, for reasons that have everything to do with policing and history and nothing to do with the algorithm.</p><p>And that is enough. Once the base rates differ, the mathematics closes the door. A system calibrated so that a score means the same thing across groups will produce unequal error rates. A system equalised for error rates will produce scores that mean different things across groups. You may have either. You may not have both. There is no third option, and no amount of retraining will find one.</p><blockquote><p><em>Fairness is not one thing a system has or lacks. It is several incompatible things, and choosing among them is not a technical decision. It is a decision about who bears the cost of being wrong.</em></p></blockquote><h1><strong><span>The Choice Nobody Admits Making</span></strong></h1><p>So somebody chose. Northpointe chose calibration. It chose to guarantee that a score means the same thing for everyone, and the price of that guarantee, paid entirely by Black defendants who would never have reoffended, was a doubled rate of being wrongly labelled dangerous to the community.</p><p>That was a moral decision of the first order. It determined who would be harmed by the system&#8217;s inevitable errors. And it was taken inside a private company, embedded in a model, and delivered to judges as a number between one and ten.</p><p>No judge chose it. No legislature chose it. No defendant was told a choice had been made at all. Eric Loomis was sentenced with reference to a score whose entire meaning depended on a fairness definition selected by a vendor, and the selection was never disclosed, debated, or defended because it was never presented as a selection. It was presented as a measurement.</p><p>This is the pattern, and it is everywhere. The choice does get made. It gets made by whichever metric the library computed by default, or by whichever definition the model happened to satisfy, or by the data scientist who picked one at 6 pm because the report was due. It gets made, and then it disappears into the number.</p><blockquote><p><em>The question is never whether a definition of fairness was chosen. One always was. The question is whether anyone in your organisation knows which, and whether the person who chose it had the standing to make that choice on your behalf.</em></p></blockquote><h1><strong><span>What This Means for Your Dashboard</span></strong></h1><p>Somewhere in most large organisations deploying AI, there is a slide with a fairness metric on it, and the metric is green.</p><p>Ask three questions about that slide.</p><ol><li><p><strong>Which definition of fairness is that number measuring?</strong> If nobody in the room can answer, the number means nothing &#8212; not because it is wrong, but because it is unanchored. It is the answer to a question no one has stated.</p></li><li><p><strong>What does it look like </strong><span>i</span><strong>n the other definitions?</strong> A model that passes on calibration but fails on error-rate balance is not a fair model, even by technical standards. It is a model that has made a specific choice about who bears responsibility for its mistakes, and the metric of failure is the receipt.</p></li><li><p><strong>Who chose the threshold?</strong> Not the metric &#8212; the threshold. Someone decided that a disparity of five per cent was acceptable and eight per cent was not, and that decision determined how many people would be harmed before anyone was required to act. That number did not come from the data. It came from a person, or, more often, from nobody at all &#8212; inherited from a template, a vendor default, or a figure that seemed reasonable in a meeting.</p></li></ol><p>If the answer to all three is a shrug, the organisation has not measured its fairness. It has adopted somebody else&#8217;s answer to a question it never realised it was asking.</p><h1><strong><span>The Objection Worth Taking Seriously</span></strong></h1><p>There is a serious reply to all of this, and it goes something like: if fairness is genuinely impossible to achieve on all definitions at once, then any choice is arbitrary, and this whole discourse is a counsel of despair. The engineers are stuck with an unsolvable problem, and the critics have nothing to offer but the observation that it is unsolvable.</p><p>That reply mistakes the argument. The impossibility is not an excuse; it is a reallocation of responsibility. The mathematics tells you that a trade-off must be made. It does not tell you who should make it, and that is precisely the point &#8212; because the answer, currently, is a vendor&#8217;s data scientist or nobody.</p><p>A trade-off that must be made can still be made well or badly. Made well, it is made in the open, by someone with the authority and the standing to decide who bears the cost of error in this particular domain, with the reasons written down and the losing metric reported alongside the winning one. Made badly, it is made silently, by default, and reported to the board as a fact about the world.</p><p>The impossibility theorem does not absolve anyone. It identifies the decision that has to be owned.</p><h1><strong><span>What Owning It Looks Like</span></strong></h1><p>For any consequential system, three things should be written down before it is deployed and available afterwards to anyone who asks.</p><ul><li><p><strong>The primary fairness definition, named in advance.</strong> Not chosen after the results are in &#8212; because a metric chosen after the results are in is a metric chosen to pass. Named beforehand, on the basis of the decision the system makes and the errors that matter most in that domain. In criminal justice, a false positive costs a person their liberty; in medical screening, a false negative costs a person their life. These are not the same, and the definition should follow the harm.</p></li><li><p><strong>The threshold, and the name of whoever set it.</strong> The maximum disparity the organisation will accept<span> is</span> tighter where the stakes are higher, set deliberately rather than inherited. And attached to a human being who can be asked why that number and not a different one.</p></li><li><p><strong>The trade-off, stated.</strong> Where the system satisfies its primary definition and breaches another &#8212; which it will, because the mathematics guarantees it &#8212; the breach is documented, not buried. Who is bearing the cost of this system&#8217;s errors, and by how much, and why did we decide that was the right allocation? That is the sentence most fairness reports do not contain, and it is the only one that matters.</p></li></ul><blockquote><p><em>A fairness metric with no named definition, no owner, and no disclosed trade-off is not a measurement. It is a green tick over a decision nobody admits making.</em></p></blockquote><h1><strong><span>Back to the Courtroom</span></strong></h1><p>Eric Loomis appealed, arguing, among other things, that he could not challenge a score whose workings were a trade secret. The Wisconsin Supreme Court upheld the sentence, with cautions about how such scores should be used. The tool remained in service.</p><p>Nothing in that story turns on anybody behaving badly. Northpointe built a calibrated instrument and said so. The judge used a number he had been given. ProPublica did the analysis nobody else had done. The mathematics did what mathematics does.</p><p>What failed was the assumption underlying all of it &#8212; that fairness is a property a system can be tested for and certified to have, rather than a choice about who gets hurt when the system is wrong. That assumption allows a vendor to make an enormous value judgment, encode it in a product, and pass it to a judge as a fact.</p><p>Your model has made the same choice. It made it the moment it was trained, whether or not anybody in your organisation was paying attention. The only open question is whether you can say which choice it was, who made it, and why.</p><p>Somebody chose this number. If it wasn&#8217;t you, find out who.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1><strong><span>References</span></strong></h1><p><em>This piece draws on the ProPublica investigation, the Northpointe response, and the formal literature on fairness impossibility.</em></p><ol><li><p>Angwin, J., Larson, J., Mattu, S., and Kirchner, L. Machine Bias. ProPublica, 23 May 2016.</p></li><li><p>Larson, J., Mattu, S., Kirchner, L., and Angwin, J. How We Analyzed the COMPAS Recidivism Algorithm. ProPublica, 23 May 2016.</p></li><li><p>Dieterich, W., Mendoza, C., and Brennan, T. COMPAS Risk Scales: Demonstrating Accuracy Equity and Predictive Parity. Northpointe Inc., July 2016.</p></li><li><p>Kleinberg, J., Mullainathan, S., and Raghavan, M. Inherent Trade-Offs in the Fair Determination of Risk Scores. Proceedings of the 8th Innovations in Theoretical Computer Science Conference (ITCS), 2017.</p></li><li><p>Chouldechova, A. Fair Prediction with Disparate Impact: A Study of Bias in Recidivism Prediction Instruments. Big Data, vol. 5, no. 2, 2017.</p></li><li><p>State v. Loomis, 881 N.W.2d 749 (Wis. 2016).</p></li></ol>]]></content:encoded></item><item><title><![CDATA[Nobody Asked If We Should]]></title><description><![CDATA[Some uses of AI are not risks to be managed. They are things a decent organisation refuses to do.]]></description><link>https://dataaicontinuum.substack.com/p/nobody-asked-if-we-should</link><guid isPermaLink="false">https://dataaicontinuum.substack.com/p/nobody-asked-if-we-should</guid><dc:creator><![CDATA[M Maruf Hossain, PhD, GAICD]]></dc:creator><pubDate>Wed, 15 Jul 2026 21:00:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pca-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Between June 2020 and August 2021, 7-Eleven installed tablets with built-in cameras in 700 stores across Australia. Customers were invited to fill in a short survey about their in-store experience. While they tapped through the questions, the tablet photographed their face.</p><p>Each image was uploaded to a server and converted into a faceprint &#8212; an algorithmic representation of that person&#8217;s face, unique to them, used for biometric identification. The faceprints were compared against one another. They were also analysed to infer the customer&#8217;s age and gender.</p><p>Over the first ten months, 1.6 million surveys were completed.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pca-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pca-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!pca-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!pca-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!pca-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pca-!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png" width="1200" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:2277935,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dataaicontinuum.substack.com/i/206655899?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pca-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!pca-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!pca-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!pca-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb44ec475-d3fb-4d83-97b0-20c4d347252c_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The purpose of all this was to prevent staff from gaming their own customer satisfaction scores by completing the survey more than once.</p><div class="callout-block" data-callout="true"><h1 style="text-align: center;"><strong><span>1.6 million</span></strong></h1><p style="text-align: center;">Customer surveys are completed on camera-equipped tablets across 700 stores, each one capturing a facial image and generating a biometric faceprint &#8212; to protect the integrity of the feedback form.</p><p style="text-align: center;"><em><span>Office of the Australian Information Commissioner, determination on 7-Eleven, October 2021</span></em></p></div><h1><strong><span>The Detail That Should Stop You</span></strong></h1><p>When the Privacy Commissioner examined this, she made two findings that are worth holding still and looking at.</p><p>The first was that the benefit to the business was not proportionate to the impact on people&#8217;s privacy. Biometric information, as she put it, is unique to an individual and cannot normally be changed. You can reissue a password. You cannot reissue a face.</p><p>The second was quieter and, I think, more damning. If 7-Eleven wanted to know the age and gender of its survey respondents, it could have asked them. There was a survey. The questions were right there.</p><p>There is a third detail that did not make the headlines. When the regulator asked 7-Eleven how many fraudulent survey responses the facial recognition system had actually caught, the company could not say.</p><blockquote><p><em>Biometric surveillance of 1.6 million people was deployed to protect the integrity of a customer feedback form, with no evidence that it was even working. This is not villainy. It is the absence of a question.</em></p></blockquote><h1><strong><span>Nobody in That Building Was a Villain</span></strong></h1><p>It is important to be precise about what went wrong here, because the comfortable reading &#8212; that a company decided to spy on its customers &#8212; is almost certainly false, and the true version is far more alarming.</p><p>Picture how this actually happened. A vendor offered a customer-feedback platform. The platform had a feature that could detect duplicate responses using the tablet&#8217;s built-in camera. The feature solved a real and irritating problem: store staff were inflating their own scores. Somebody in operations thought that was clever. Somebody in procurement bought it. Somebody in IT deployed it to 700 stores. Signs went up at the door. Everyone involved was doing their job competently.</p><p>At no point in that chain was there a step that required anyone to ask: should we be taking biometric readings of every customer who touches this screen?</p><p>Not can we &#8212; that was answered by the vendor&#8217;s feature list. Not only is it legal &#8212; nobody seems to have asked that either &#8212; but the signage suggests someone thought they had covered it. The question that was never asked was whether this is a thing the organisation is prepared to do to the people who walk into its shops.</p><p>There was no villain. There was a gap in the process where a question should have been.</p><h1><strong><span>The Question That Never Gets Asked</span></strong></h1><p>Every organisation deploying AI has a mechanism for asking whether a system works. Most have one for asking whether it is safe, accurate, compliant, or profitable. Almost none have a mechanism for asking whether the use is one they are willing to make at all.</p><p>This is not an oversight. It is a structural consequence of how these decisions arrive. A capability shows up &#8212; in a vendor&#8217;s product, in a model&#8217;s release notes, in an engineer&#8217;s proof of concept &#8212; and it arrives already answering the question of feasibility. The demonstration is the answer. What follows is a conversation about implementation, risk, cost, and timeline, all of which take for granted that the thing will be done.</p><p>The prior question, the one about permission rather than possibility, has no natural moment in that sequence. Nobody&#8217;s job is to ask it. No gate requires it. No document captures it. And so it is asked, if at all, by whoever in the room has the standing and the nerve to say something that sounds naive: should we be doing this?</p><blockquote><p><em>Feasibility arrives with its own answer. Permission has to be asked for, and if no step in the process demands it, no one will.</em></p></blockquote><p>Which is why it goes unasked in rooms full of thoughtful, decent people. The silence is not a moral failure. It is process design.</p><h1><strong><span>Why Risk Management Cannot Catch It</span></strong></h1><p>The standard reply is that this is what risk assessment is for. Run the facial recognition system through a privacy impact assessment, and the problem surfaces.</p><p>Sometimes it does. But there is a category error hiding in that reply, and it is the heart of this essay.</p><p>Risk management asks how likely a harm is, how severe it would be, and what controls would bring it to an acceptable level. It is a machine for converting a hazard into a manageable quantity. Feed it a facial recognition system, and it will do exactly that: it will identify privacy risk, propose signage, propose encryption, propose a retention limit of seven days, propose a third-party processing agreement &#8212; and it will produce, at the end, a residual risk rating that somebody with sufficient seniority can accept.</p><p>Every one of those controls is sensible. 7-Eleven had most of them. The images were encrypted. They were held briefly. There was signage at the door. A privacy assessment, competently done, would have produced precisely this list, and the system would have gone live with a moderate residual risk, accepted by someone with the authority to accept it.</p><p>Because that is what risk machinery does. It does not have an output that says, &#8220;This is not a thing we do&#8221;. Its outputs are accept, mitigate, transfer, and avoid &#8212; and, in practice, avoid is the option nobody selects once a project has a budget and a launch date.</p><blockquote><p><em>Put a prohibition through a risk process, and it comes out the other side as a risk. And a risk, however severe, is something a sufficiently senior person can accept.</em></p></blockquote><h1><strong><span>What a Prohibition Actually Is</span></strong></h1><p>A prohibition is not a very high risk. It is a different kind of object entirely, and confusing the two is how organisations end up doing things they would never have defended if anyone had said them out loud.</p><p>A risk is something you weigh. You put the benefit on one side and the harm on the other; you consider the controls, and you make a judgment. This is the correct way to handle most things. It is how we decide whether to launch a product, extend a credit line, or run a model in production.</p><p>A prohibition is something you do not weigh, because weighing it is already a mistake. It is a use the organisation has decided it will not make, and the decision was taken in advance precisely so that it could not be relitigated in a room where someone has a deadline and a business case. The whole function of deciding beforehand is to remove the decision from the pressure that would distort it.</p><p>Consider what it would mean for a bank to treat this properly. Not: we will assess the risks of using AI to infer customers&#8217; health conditions from their transaction data and apply appropriate controls. But we do not do that. There is no control environment that makes it acceptable, no benefit that offsets it, no seniority sufficient to approve it. The question does not reach the risk committee because the answer was settled before the question could be asked.</p><p>That is a prohibition. And an organisation that has none has not made a considered decision to permit everything. It has simply never noticed that some things are not risks.</p><h1><strong><span>The Screen Before the Gate</span></strong></h1><p>In practice, this means a prohibited-use screen must sit before the risk assessment, not inside it &#8212; and it has to be binary.</p><p>Before anyone assesses how a proposed use might be controlled, someone has to answer a prior question with a yes or a no: is this a use we are prepared to make? If the answer is no, the assessment stops. There is no residual risk to accept because there is no risk conversation to have. The system is not built. Nothing about the strength of the business case reopens it.</p><p>This is unfashionable because it sounds inflexible, and inflexibility is not how modern organisations like to describe themselves. But inflexibility is the entire point. A prohibition that bends under sufficient commercial pressure is not a prohibition; it is a preference that has not yet met its price. The value of the line is precisely that it does not move when moving it would be convenient &#8212; which is the only moment at which anyone ever wants to move it.</p><p>And the list has to be written down in advance, by people with the authority to bind the organisation, in a document that cannot be amended by the executive who finds it inconvenient on a Tuesday. Otherwise, the prohibition exists at the discretion of whoever is under the most pressure, which is to say it does not exist.</p><h1><strong><span>What It Would Have Cost</span></strong></h1><p>Return to the tablets for a moment, because the arithmetic here is instructive.</p><p>If somebody at 7-Eleven had asked the question &#8212; should we take a biometric reading of every customer who fills in this survey? The answer would have been no, and it would have taken about four seconds to reach that conclusion. Nobody would have argued. The purpose was to survey hygiene. The alternative was a checkbox.</p><p>The cost of asking would have been nothing. The cost of not asking was 1.6 million people&#8217;s faces, a regulatory determination, a destruction order, and a permanent entry in the case law of what Australian companies may not do.</p><p>That is the shape of this failure almost every time. The prohibition, when finally examined, is obvious. The harm is real. The benefit was trivial. And the reason it happened, anyway, is that the organisation had no place in its process for the obvious question to be asked out loud by someone whose job it was to ask it.</p><blockquote><p><em>The uses you would be ashamed to defend are rarely the ones anyone argued for. They are the ones nobody was required to question.</em></p></blockquote><h1><strong><span>The Line, and Who Draws It</span></strong></h1><p>Nothing external is going to draw this line. That was the argument of the last essay, and it applies here with full force: there is no Australian regulator who will inspect your use case before you deploy it, and the guardrail that would have required you to assess it was withdrawn.</p><p>So the line is yours to draw, and the only question is whether you draw it before the capability arrives or after the harm does. 7-Eleven drew it after. The determination did it for them, at a cost, and the line it drew is now permanent and public.</p><p>An organisation serious about this decides, in advance and in writing, what it will not do with AI &#8212; surveillance of people who have not meaningfully consented, inference of characteristics people have not disclosed, automated decisions that deny someone something essential with no human being who can be reached, systems designed to exploit the fact that a person is desperate or confused or a child. Then it puts that list somewhere a project cannot route around, and it gives someone the authority to stop anything that crosses it, with the standing to survive doing so.</p><p>None of this is difficult. It requires no technology, no new regulation, and no great moral courage. It requires only that somewhere in the process between a vendor&#8217;s feature list and 700 stores, there is a step where someone has to ask the question out loud.</p><p>Nobody at 7-Eleven asked. That is the whole story. It is also, right now, the story in most organisations deploying AI &#8212; where the capability is arriving faster than anyone&#8217;s willingness to say that some of it is simply not for us.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1><strong><span>References</span></strong></h1><p><em>This piece draws on determinations of the Office of the Australian Information Commissioner and the published record of Australian AI policy.</em></p><ol><li><p>Office of the Australian Information Commissioner. Commissioner initiated investigation into 7-Eleven Stores Pty Ltd (Privacy) [2021] AICmr 50. Determination of Commissioner Angelene Falk, 29 September 2021.</p></li><li><p>Office of the Australian Information Commissioner. Commissioner initiated investigation into Clearview AI, Inc. (Privacy) [2021] AICmr 54. Determination, 14 October 2021.</p></li><li><p>Office of the Australian Information Commissioner. Statement on Clearview AI. Canberra, 21 August 2024.</p></li><li><p>Department of Industry, Science and Resources. National AI Plan. Canberra, December 2025.</p></li></ol>]]></content:encoded></item><item><title><![CDATA[Nobody Is Coming to Save You]]></title><description><![CDATA[Australia&#8217;s AI rules are voluntary. Whatever protects the person on the other side of the machine, you build yourself.]]></description><link>https://dataaicontinuum.substack.com/p/nobody-is-coming-to-save-you</link><guid isPermaLink="false">https://dataaicontinuum.substack.com/p/nobody-is-coming-to-save-you</guid><dc:creator><![CDATA[M Maruf Hossain, PhD, GAICD]]></dc:creator><pubDate>Mon, 13 Jul 2026 21:02:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ArT0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In September 2024, the Australian government proposed ten mandatory guardrails for high-risk AI. They had teeth. Organisations deploying AI in healthcare, employment, credit, education, or law enforcement would have been required to establish accountability for their systems, test them before deployment, keep records that an outsider could audit, maintain meaningful human oversight, disclose to people that a machine was deciding, and provide a process by which a person could challenge the outcome. Independent conformity assessment would have applied. The guardrails would have covered both general-purpose models and high-risk deployments, and they would have been enforceable.</p><p>Fifteen months later, the government abandoned them.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ArT0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ArT0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!ArT0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!ArT0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!ArT0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ArT0!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png" width="1200" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:2173201,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dataaicontinuum.substack.com/i/206651806?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ArT0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!ArT0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!ArT0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!ArT0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a3c3253-e333-4b43-bacf-ec07f3aab224_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The National AI Plan, released on 2 December 2025, dropped the mandatory guardrails and the idea of an AI Act. In their place: existing technology-neutral laws, on the theory that privacy, consumer protection, and anti-discrimination statutes already cover whatever AI does; and voluntary guidance, in the form of six essential practices published two months earlier, which organisations are encouraged to adopt. An AI Safety Institute was funded to monitor, test, and advise.</p><p>It has no enforcement powers.</p><div class="callout-block" data-callout="true"><h1 style="text-align: center;"><strong><span>$29.9 million</span></strong></h1><p style="text-align: center;">The initial funding of Australia&#8217;s AI Safety Institute &#8212; a body with advisory and monitoring functions and no power to compel anyone to do anything. Regional data centre investment over the same period runs to roughly $100 billion.</p><p style="text-align: center;"><em><span>National AI Plan, Department of Industry, Science and Resources, December 2025</span></em></p></div><h1><strong><span>What Was on the List</span></strong></h1><p>Read the abandoned guardrails closely, because the specifics matter more than the fact of the retreat.</p><p>One of the ten was contestability: a requirement that people affected by a high-risk automated decision be able to challenge it. Another was human oversight: a requirement that a person be able to intervene in, and override, what the system did. Another was accountability: a requirement that someone be identifiable and answerable for the system&#8217;s outcomes. Another was transparency: that people be told a machine was involved at all.</p><p>Those four, had they been law, would have described with some precision the protections that Robodebt&#8217;s victims did not have. They could not contest because the burden had been inverted, and the tribunal decisions were never allowed to become precedent. There was a human presence but no human authority. Nobody could be identified as accountable until a royal commission was convened to find out. And the scheme&#8217;s logic was opaque to the people it judged.</p><p>So the guardrails were, in a real sense, drafted from the wreckage. They were the state&#8217;s own account of what had gone wrong, converted into obligations.</p><p>And then they were withdrawn.</p><blockquote><p><em>The protections Australia decided not to mandate are the very protections whose absence led to its worst automated-decision failure. That is not an accident of drafting. It is a decision about who bears the risk.</em></p></blockquote><h1><strong><span>The Argument for Voluntary</span></strong></h1><p>The case for the retreat is not stupid, and it deserves to be stated properly rather than caricatured.</p><p>Australian law is technology-neutral, and that is a genuine strength. The Privacy Act does not distinguish between a human and a model mishandling your data. Consumer law does not care whether a person or an algorithm misled you. Anti-discrimination statutes apply to a discriminatory outcome regardless of what produced it. Directors&#8217; duties do not contain an exception for decisions taken by software. On this reading, AI-specific legislation risks building a parallel regime that duplicates what already exists, freezes today&#8217;s technology into tomorrow&#8217;s statute, and imposes compliance costs on a country that is already a net importer of AI rather than a builder of it.</p><p>The Productivity Commission made this case explicitly, calling for a pause on economy-wide AI regulation. Industry made it forcefully. And there is a version of it that is simply true: an organisation that breaks the Privacy Act with a model is still breaking the Privacy Act.</p><p>But notice what that argument quietly concedes. It says that existing law will catch up to you afterwards. It says nothing about whether anything will stop you first.</p><h1><strong><span>Enforcement After the Fact Is Not Protection</span></strong></h1><p>Robodebt was unlawful under existing law. It was unlawful from the first debt notice in 2015, and the legal advice saying so existed in 2014. Technology-neutral law applied to it perfectly, and technology-neutral law did not stop it. The Federal Court eventually found the method unlawful &#8212; in 2019, four years and hundreds of thousands of victims later.</p><p>That is what existing law enforcement looks like when a machine is running at scale. It is retrospective. It requires someone harmed to litigate, or a regulator to investigate, or a commission to be convened. It arrives after the money has been taken and, in some cases, after the person is dead. The law was not absent. It was slow and downstream, and the machine was fast and upstream.</p><blockquote><p><em>A statute that catches you in four years is not a guardrail. It is a post-mortem with a fine attached.</em></p></blockquote><p>This is the gap the mandatory guardrails were designed to close, and it is precisely the gap the National AI Plan reopened. Conformity assessment before deployment, testing before release, a contestation route that exists on day one rather than being litigated into existence on day 1,400 &#8212; these are ex ante controls. They act before the harm. Existing law, however elegant and technology-neutral, acts after it.</p><p>Australia has decided that ex ante protection for high-risk AI is optional. Not absent. Optional. There is a difference, and the difference is where this essay is going.</p><h1><strong><span>The Word That Does the Work</span></strong></h1><p>The six essential practices published in October 2025 are, on their merits, good. They cover governance and accountability, risk management, data governance, testing and monitoring, privacy, and continuous improvement. An organisation that implemented them properly would be in a far better position than most. Nothing here is an argument against their content.</p><p>The argument is about the adjective. They are voluntary.</p><p>Voluntary means an organisation adopts them when it wants to and does not when it does not. It means the practices bind only as far as the enthusiasm of the person implementing them goes, and no further. It means that when a delivery deadline collides with a testing requirement, nothing external decides the conflict. It means the framework is a description of what a responsible organisation would do, offered to organisations that may or may not be responsible.</p><p>And it means the guidance has the same enforcement architecture as Enron&#8217;s code of ethics, which its board formally voted to waive so that its chief financial officer could run the partnerships that destroyed the company. A rule you can switch off is not a rule. It is a preference with good branding.</p><div class="callout-block" data-callout="true"><h1 style="text-align: center;"><strong><span>10 &#8594; 0</span></strong></h1><p style="text-align: center;">Mandatory guardrails proposed for high-risk AI in September 2024, and the number that survived into the National AI Plan of December 2025. The guidance that replaced them is voluntary.</p><p style="text-align: center;"><em><span>Proposals Paper: Safe and Responsible AI in Australia &#8212; Mandatory Guardrails, September 2024; National AI Plan, December 2025</span></em></p></div><h1><strong><span>What This Actually Means for You</span></strong></h1><p>Strip away the policy language, and the position is stark, and it is worth stating without euphemism.</p><p>If your organisation deploys a system that decides something consequential about a person &#8212; whether they get the loan, the job, the insurance, the tenancy, the benefit &#8212; there is no Australian regulator that will inspect that system before it goes live. Nobody will require you to test it for bias. Nobody will require you to explain your decision to the person it affected. Nobody will require you to give that person a route to challenge it. Nobody will require you to name a human being who is accountable for what it does.</p><p>You may do all of those things. You are encouraged to. There is excellent guidance available, and it is free.</p><p>But if you do not, the machine still runs. It runs until someone who was harmed finds a lawyer, or a journalist, or the resources and stamina to litigate against an institution with vastly more of both. It runs until the harm is large enough and documented enough to summon the retrospective machinery of existing law &#8212; which, on the Robodebt evidence, takes years and requires the dead to pile up first.</p><p>The person on the other side of your model has no external protection. Whatever protects them is whatever you built.</p><h1><strong><span>The Burden Nobody Asked For</span></strong></h1><p>This is not a call for regulation, nor a complaint that the government failed to do its job. Reasonable people can hold that a standalone AI Act would have been clumsy, premature, and economically costly for a country in Australia&#8217;s position. That argument may even be right.</p><p>But the argument has a consequence, and the consequence is not evenly distributed. When the state declines to mandate ex ante protections, it does not eliminate the need for them. It relocates the decision. The question of whether a person can contest an automated decision that ruined their week does not disappear because the guardrail was withdrawn. It simply moves from parliament to a product meeting, where it will be decided by people who balance it against the launch date.</p><blockquote><p><em>Deregulation does not remove a control. It moves the decision about that control from a legislature to a delivery team, and hopes.</em></p></blockquote><p>So the burden has landed on the enterprise, and it has landed without ceremony. Every protection the guardrails would have compelled is now a thing your organisation must choose to build, fund, and &#8212; this is the hard part &#8212; enforce against itself, under commercial pressure, with nobody watching and no penalty for quietly deciding not to.</p><p>Most organisations will not build it. They will adopt the principles, publish them, and treat the publication as the work. This is not cynicism; it is the observable pattern of every voluntary code in the history of corporate governance. The organisations that build real controls will be the ones that decide the protection matters independently of whether anyone is going to make them.</p><h1><strong><span>Which Leaves the Question</span></strong></h1><p>Australia has run an experiment, and the terms are now clear. It has been that existing law, plus good guidance, plus the good faith of the people deploying these systems, is enough. The AI Safety Institute will watch and advise. Nobody will be compelled.</p><p>Which means the question for anyone deploying AI that touches human beings is no longer what the regulator will require. There is no answer to that question. The question is what you would build if nobody were going to check &#8212; because that is precisely the situation you are in.</p><p>It is an uncomfortable question, and it is uncomfortable in a specific way: it is the question a person&#8217;s character answers, not their compliance function. There is no filing to submit and no auditor to satisfy. There is only the gap between what you know you should build and what you can be made to build, and the discovery that in this country, for now, those are very different sizes.</p><p>The guardrails were withdrawn. The institute has no teeth. And the person your model is about to judge is relying entirely on what you decided to build when you thought no one was looking.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1><strong><span>References</span></strong></h1><p><em>This piece draws on the Australian Government&#8217;s published AI policy record and reporting on the National AI Plan.</em></p><ol><li><p>Department of Industry, Science and Resources. National AI Plan. Canberra, December 2025.</p></li><li><p>Department of Industry, Science and Resources. Proposals Paper: Introducing Mandatory Guardrails for Safe and Responsible AI in Australia. Canberra, September 2024.</p></li><li><p>National Artificial Intelligence Centre. Guidance for AI Adoption: Foundations and Implementation Practices. Canberra, 21 October 2025.</p></li><li><p>Department of Industry, Science and Resources. Voluntary AI Safety Standard. Canberra, September 2024.</p></li><li><p>Productivity Commission. Interim report on harnessing data and digital technology, August 2025.</p></li><li><p>Royal Commission into the Robodebt Scheme. Report of the Royal Commission into the Robodebt Scheme. Canberra, 7 July 2023.</p></li></ol>]]></content:encoded></item><item><title><![CDATA[Cruel, Unlawful, and Nobody’s Fault]]></title><description><![CDATA[The accountability gap at the heart of automated decisions]]></description><link>https://dataaicontinuum.substack.com/p/cruel-unlawful-and-nobodys-fault</link><guid isPermaLink="false">https://dataaicontinuum.substack.com/p/cruel-unlawful-and-nobodys-fault</guid><dc:creator><![CDATA[M Maruf Hossain, PhD, GAICD]]></dc:creator><pubDate>Sun, 12 Jul 2026 02:46:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dJUR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In November 2014, the Department of Social Services took legal advice on a proposed new method for calculating welfare debts. The method was to take a person&#8217;s annual income from tax records, average it evenly across the year, and treat the resulting fortnightly figure as what they had actually earned in each fortnight. The advice came back: this did not accord with the social security legislation. There is no evidence that the advice was ever passed on to the department building the system.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dJUR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dJUR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!dJUR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!dJUR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!dJUR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dJUR!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png" width="1200" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:2401318,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://dataaicontinuum.substack.com/i/206544880?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dJUR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!dJUR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!dJUR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!dJUR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67f8275-5c32-46c7-a5a2-a4f02fa9d43e_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The system was built. It ran from 2015 to 2019. It issued debt notices to hundreds of thousands of people on welfare payments, and it inverted the burden of proof: the machine asserted the debt, and the person had to disprove it, often by producing payslips from years earlier that they had no means of obtaining. When the Federal Court finally examined the method in 2019, it was unlawful. By then, the Commonwealth had taken at least $751 million from people on the basis of debts it had no legal power to raise.</p><p>The Royal Commission that eventually examined the scheme described it as a crude and cruel mechanism, neither fair nor legal, and said that it made many people feel like criminals. Mothers gave evidence about sons who had taken their own lives after receiving debts they could not disprove.</p><div class="callout-block" data-callout="true"><h1 style="text-align: center;"><strong><span>$751 million</span></strong></h1><p style="text-align: center;">taken from welfare recipients under a debt-raising method the Federal Court found unlawful &#8212; after legal advice in 2014 had already found it did not accord with the legislation.</p><p style="text-align: center;"><em><span>Royal Commission into the Robodebt Scheme, Final Report, 7 July 2023</span></em></p></div><h1><strong><span>The Knowledge Was Never Missing</span></strong></h1><p>The temptation is to file Robodebt under cruelty or incompetence and move on. Both readings are comfortable, and both are wrong, because they suggest the problem was that nobody knew.</p><p>Everybody knew. The legal advice existed in 2014, before a single debt was raised. The Commonwealth Ombudsman investigated in 2017. The Senate inquired twice. The Administrative Appeals Tribunal struck down income averaging in decision after decision at the first tier, and the department did not appeal any of them, because an appeal would have produced a binding precedent it did not want. Each adverse ruling was absorbed in silence, and the machine kept running. Welfare recipients wrote, called, and pleaded. Community lawyers documented it. Journalists reported it.</p><p>Four years of knowing, and the scheme did not stop until a court ordered it to.</p><blockquote><p><em>The information was never the missing ingredient. What was missing was any mechanism by which knowing became stopping.</em></p></blockquote><h1><strong><span>Everyone Was Responsible, So Nobody Was</span></strong></h1><p>Ask who was accountable for Robodebt, and the answers arrive in a circle.</p><p>The ministers acted on departmental advice. The department acted with ministerial authority. The public servants who had doubts raised them through channels, and the channels absorbed them. The officers who sent the letters were executing a process they had not designed and could not override. And the system itself &#8212; the actual calculation that averaged the income and generated the debt &#8212; had no author in any meaningful sense. It was a policy expressed as arithmetic, and arithmetic cannot be culpable.</p><p>The Royal Commission found that a departmental secretary had been made aware of the scheme&#8217;s illegality and failed to act. It found a minister had allowed the cabinet to be misled. But those findings had to be constructed, painstakingly, across three volumes and hundreds of pages, by a body with royal powers of compulsion, four years after the scheme had ended and eight years after the first unlawful debt was raised.</p><p>That is what it took to answer a question that should have been answerable on the first day: who is responsible for what this machine does to people?</p><blockquote><p><em>An accountability that must be excavated after the harm, by an inquiry with the power to compel testimony, is not accountability. It is archaeology.</em></p></blockquote><h1><strong><span>The Tool That Isn&#8217;t</span></strong></h1><p>Underneath the circle of deferrals sits a single comfortable idea, and almost every organisation deploying AI today lives inside it: the system is a tool; tools have users; and users are accountable.</p><p>This is how we think about hammers, and it is unimpeachable right up to the moment the tool stops executing a decision and starts making one. Then a gap opens in the middle of the chain that runs from human intention to human consequence, and nobody has been assigned to close it.</p><p>Consider what user accountability actually meant inside Robodebt. The user was a Centrelink officer who did not design the averaging method, could not inspect it, had a queue and a handling-time target, and whose entire practical discretion consisted of forwarding what the system had produced. To call that person accountable is not a governance position. It is a place to put the blame when it eventually arrives.</p><p>And notice where responsibility goes when the fiction collapses. It does not transfer to the machine, which cannot be sanctioned, struck off, or compensate anyone. It does not settle on the executive, who never saw an individual decision. It does not rest with the engineer, who built to specification. It does not attach to the policy officer, who wrote a rule, not a system.</p><p>It simply becomes unlocated. That is the accountability gap: not an absence of responsible people, but the absence of any answer, settled in advance and in writing, to the question of which one.</p><blockquote><p><em>Delegating a decision is not delegating responsibility for it. Most organisations have done the first and quietly assumed the second came along.</em></p></blockquote><h1><strong><span>A Human Was in the Loop the Whole Time</span></strong></h1><p>The standard reassurance is that a human remains in the loop. The phrase has done more damage than almost any other in this field, because it describes a position and implies an authority, and those are not the same thing.</p><p>A human in the loop, in most real deployments, is a person who reviews what the system surfaced, under time pressure, with a queue behind them, in an environment where agreeing with the machine is fast and costless and disagreeing is slow and demands justification. Every incentive arranged around that person produces assent. They are present. They are not, in any operative sense, deciding.</p><p>Robodebt had humans throughout &#8212; officers, managers, secretaries, ministers, an ombudsman, a tribunal, two Senate committees. What it did not have was a single point at which a named human with real authority was required to examine the method and say yes or no, in writing, before the machine reached a citizen. Presence was everywhere. Authority was nowhere.</p><div class="callout-block" data-callout="true"><h1 style="text-align: center;"><strong><span>57</span></strong></h1><p style="text-align: center;">recommendations from the Royal Commission &#8212; including that the Commonwealth consider establishing a body with power to monitor and audit automated decision-making for fairness, bias, and usability. No such capability existed while the scheme ran.</p><p style="text-align: center;"><em><span>Royal Commission into the Robodebt Scheme, Final Report, 7 July 2023</span></em></p></div><h1><strong><span>The Objection, and Why It Fails</span></strong></h1><p>There is an objection to all of this, and it deserves to be met at its strongest rather than its weakest.</p><p>It runs like this. Robodebt was not an AI failure. Its algorithm was arithmetic &#8212; a division, performed at scale. No machine learning, no neural network, nothing that could not be done in a spreadsheet. What went wrong was political culture, ministerial ambition, and a public service that had learned not to say no; the Commission itself named venality, incompetence and cowardice. To recast that as an algorithmic accountability problem is to let humans off the hook by blaming the technology&#8217;s shape. Large organisations have always diffused responsibility. Committees have always been where accountability goes to die. There is nothing new here.</p><p>Every part of that is true, and it strengthens the case rather than weakening it. If a division sum could open an accountability vacuum that took a royal commission four years to excavate, then nobody should want to argue that systems which are more capable, more opaque, and more autonomous will be easier to hold to account. Robodebt is not the exception that proves AI will be fine. It is the floor.</p><p>The technology changes one thing, and it changes it decisively. Robodebt ran for four years and reached hundreds of thousands of people before the courts caught it, and it was slow enough and paper-based enough to leave a trail. That trail is the only reason the scheme has a name. A modern system does the same amount of harm before a quarterly report prints, and it leaves a log that nobody reads, instead of a letter that somebody keeps.</p><h1><strong><span>What Closing It Requires</span></strong></h1><p>If the gap is the absence of a pre-assigned answer, it cannot be closed by better values, stronger ethics training, or a more sincere statement of principles. It is closed by deciding three things before the system is permitted to act, and writing them down where they can be produced later.</p><p>Who is accountable for this system&#8217;s outcomes by name? Not a committee, not a function, not the business. A person who can be asked afterwards why they permitted this, and who knew in advance that they would be asked.</p><p>What that person had to see before the machine was allowed to decide. The population it will touch, the errors it will make, the harm those errors will cause, and the route by which a person on the receiving end can push back. A signature on a document nobody read is the same fiction with a name attached to it.</p><p>What happens when it goes wrong, mechanically rather than aspirationally? Not that concerns will be escalated, which is precisely what Robodebt had, in abundance, for four years. But that&#8217;s the thing that stops. That there is a point at which the machine&#8217;s authority ends and it cannot proceed, and that point is enforced by architecture rather than by somebody&#8217;s willingness to make a career-limiting phone call.</p><p>None of this is exotic, and none of it is new. It is what every other domain of consequential machinery worked out long ago. An aircraft does not fly because its designers had good intentions; a named person certifies it, and that person is prosecuted if the certification was a lie. A drug does not reach the market because the chemistry is elegant. The pattern is old and well understood. It has simply not yet been applied to the systems now deciding people&#8217;s money, housing, employment, and liberty.</p><h1><strong><span>The Question Underneath All the Others</span></strong></h1><p>Fairness, explainability, contestability, the provenance of the data &#8212; every other question in responsible AI sits downstream of this one, because each is finally an answer to the question of who has to answer for it. Where the answer is nobody, fairness becomes a metric someone tunes until it passes, an explanation becomes a document nobody reads, and a right to contest becomes a form nobody processes.</p><p>That is the argument this series will make, and it will take each of those in turn. Why nothing external will stop the next Robodebt, and what that leaves you holding. The uses no organisation should make, and the question that never gets asked before they are made. The fairness threshold somebody chose without telling you. The explanation that satisfies a regulator and tells the person you refused nothing at all. The human review that changes no outcome. The training data, whose origin nobody can state, quietly voids everything built on top of it. And finally, why organisations that agree with every word of this still never build any of it.</p><p>Each is a control that fails on its own terms. All of them fail together, and for the same reason, when there is no one whose job it is to stop.</p><p>Robodebt had policies. It had oversight bodies, an ombudsman, a tribunal, two Senate inquiries, and a department full of people who knew. What it did not have was a single person who would be held to it, named before the first letter went out, who could not get out of the way.</p><p>So the accountability was manufactured afterwards, at enormous public cost, by a commission with the power to compel sworn testimony &#8212; which is the most expensive and least effective method of governance ever devised, and the one we currently rely on.</p><p>$751 million was taken from people who owed nothing. Some of them did not survive it. And for four years, while everybody knew, there was nobody whose job it was to stop.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://dataaicontinuum.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Data-AI Continuum! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1><strong><span>References</span></strong></h1><p><em>This piece draws on the public record of the Royal Commission into the Robodebt Scheme, Federal Court judgments, and reports of the Commonwealth Ombudsman and Senate committees.</em></p><ol><li><p>Royal Commission into the Robodebt Scheme. Report of the Royal Commission into the Robodebt Scheme. Commissioner Catherine Holmes AC SC. Canberra, 7 July 2023.</p></li><li><p>Federal Court of Australia. Amato v Commonwealth. Consent judgment finding the income-averaging method unlawful, November 2019.</p></li><li><p>Commonwealth Ombudsman. Centrelink&#8217;s Automated Debt Raising and Recovery System. Report No. 02/2017, April 2017.</p></li><li><p>Senate Community Affairs References Committee. Inquiries into the Better Management of the Social Welfare System initiative. Canberra, 2017 and 2022.</p></li><li><p>Federal Court of Australia. Prygodicz v Commonwealth of Australia (No 2) [2021] FCA 634. Settlement approval judgment, June 2021.</p></li></ol>]]></content:encoded></item></channel></rss>