ADMISSIBLE·REALITY

An excerpt · Editorial galley · Executive circulation · 2026

An excerpt

The End of Assumed Truth

From the editorial galley of Admissible Reality by Brian C. Long — a book about legitimacy under machine-mediated decisions, and the procedural standard that has to follow.

In this excerpt

Ch 2 · The Age of Assumed Truth  ·  Ch 3 · The Three Breaks  ·  Ch 4 · Why the Old Fixes Fail  ·  Ch 5 · What Is a Real Decision?  ·  Ch 6 · The Reviewer  ·  Ch 7 · The Decision Record  ·  Ch 8 · The Affected Party  ·  Ch 9 · The Legal Threshold  ·  Ch 10 · The Adversarial Problem  ·  Ch 11 · The Procurement Revolution  ·  Ch 12 · The New Public Order


Executive thesis

For most of modern institutional history, decisions were treated as legitimate because they came from authorized sources. That arrangement breaks once consequential decisions are produced by systems whose reasoning cannot be reconstructed.

Credit. Employment. Benefits. Insurance. Healthcare. Security. Administrative governance. The list is no longer hypothetical. Institutions already rely on machine-mediated determinations in each of those domains. Most cannot replay those determinations after the fact. The records of the outputs exist. The procedural ground does not.

This is not a technology problem. It is a procedural and constitutional one, sitting one institutional layer beneath the vocabulary currently used to describe it.

The manuscript proposes a replacement standard. Decision admissibility.

A consequential automated decision must become admissible in the same sense evidence becomes admissible inside a court.

The admissibility criteria

Reconstructable — on the inputs that produced it.

Reviewable — by an examiner outside the institution that issued it.

Replayable — on the model state, parameters, and pipeline that produced it.

Contestable — on procedural grounds, by the party it affects, after the fact.

The criteria are not separate questions. They are facets of the same question, which is whether the decision survives adversarial reconstruction. The current governance vocabulary — alignment and explainability and audit and transparency and safety — performs partial work while leaving that question untouched.

A decision is not real because it is authorized.
A decision is real because it can be reconstructed.

Why this matters now

Institutions have automated the production of consequential decisions faster than they have built the machinery required to contest them.

The mismatch sits inside ordinary public life. A person denied credit by a model that has since been retired. A claimant denied benefits by a risk-scoring system whose vendor relationship the agency has since terminated. A worker screened out by an automated hiring pipeline whose feature weights nobody can produce. A patient whose prior authorization was denied by a determination the insurer attributes to "the system." A small-business owner flagged by fraud detection that the bank says it cannot explain.

The legitimacy cost is already visible. Litigation against opaque automated systems is rising in every jurisdiction that has tried to apply existing administrative-procedure law to machine-mediated determinations. Regulatory inquiry is widening across financial regulators, employment regulators, healthcare regulators, and the state attorneys general. Trust collapses first among the affected populations, then among the regulators, then, slowly, inside the institutions themselves.

The historical analogy is not speculative. The rules of evidence were built because adjudication conducted on unexaminable evidence eventually collapses into a contest of institutional trust rather than an examination of fact. Financial auditability was built after 1929. Scientific reproducibility was built after a series of clinical-research disasters. The Administrative Procedure Act was built after the New Deal forced the question of what process consequential state action owes the people it touches. Each was a procedural layer that institutions resisted, then absorbed, then made load-bearing.

The next layer is admissibility.

The question is no longer whether institutions automate decisions. The question is whether those decisions remain reviewable once they do.

The institutional claim the manuscript carries throughout is short. If a consequential decision cannot be replayed, institutions should not be allowed to rely on it. Everything else in the book is the architecture that follows from that sentence.

From Chapter Two

The Age of Assumed Truth

An excerpt from the opening of Chapter Two. The chapter — and the rest of the book — continues behind the wall.

§1.

In the spring of 1968, in a fourth-floor walk-up apartment on the Lower East Side of Manhattan, a twenty-year-old man named John Kelly received a letter from the New York City Department of Social Services. The letter informed him that his Home Relief benefits, the general-assistance program that paid his rent and bought his groceries, had been terminated. The reason given was administrative: he had moved from a city-assigned hotel into a friend's apartment without notifying his caseworker, and the move was treated as a violation of the program's residence requirements. Kelly went to the Mobilization for Youth Legal Services storefront on Avenue D, where attorneys had been representing welfare recipients in disputes with the city for several years. The attorney who took his case, Lee Albert, would spend the next two years arguing that the termination's specific mechanism, adverse action issued without prior notice or opportunity to be heard, violated the Fourteenth Amendment's Due Process Clause.

Two years later, on March 23, 1970, the Supreme Court of the United States decided Goldberg v. Kelly. The case involved Kelly and a group of fellow New York City residents whose public-assistance benefits had been terminated by state caseworkers without prior notice or opportunity to contest the termination. They had filed suit arguing that the terminations violated the Due Process Clause of the Fourteenth Amendment. The District Court had agreed. The state had appealed.

Justice Brennan, writing for the majority, affirmed. The opinion held that welfare benefits, while not property in the traditional sense, were a statutory entitlement, the product of specific legislative enactments that conferred specific benefits on specific classes of people meeting specific eligibility criteria. The entitlement, once conferred, could not be revoked by the state without the procedural protections the Due Process Clause required. Those protections, at a minimum, included timely notice of the proposed termination, opportunity to be heard before an impartial decision-maker, the right to present evidence and confront adverse witnesses, and a decision rendered on the record.

The opinion did not invent these requirements. Notice, hearing, impartial adjudication, and reasoned decision-making were, by 1970, substantively settled in American administrative law. What Goldberg did was extend them, explicitly, unambiguously, to the administration of welfare benefits, which had previously been treated as a matter of agency grace rather than legal entitlement.

Justice Brennan's opinion is a document of a particular moment in the American mind, the moment when the expansion of the administrative state had proceeded far enough that the Bill of Rights needed to be read as attaching to the new kinds of interests the state was now regulating. Welfare was not property in the common-law sense. It was property in the due-process sense, an expectation the government had created and on which recipients had organized their lives. The move Brennan made was not doctrinal invention. It was doctrinal recognition: the Constitution's procedural guarantees had to follow the state into the domains where the state was now acting. That move was made in 1970. It has to be made again, for the domain in which the state, and increasingly private actors standing in for the state, is now acting through automated decisions.

The opinion was celebrated as a landmark. In the decades since, it has been cited in thousands of subsequent decisions across the full range of administrative adjudications, benefits terminations, licensing revocations, public-employment dismissals, educational disciplinary proceedings, prison-discipline cases. Its core principles remain controlling law.

The plaintiffs in Goldberg were residents of New York City whose public-assistance benefits had been terminated by state and city agencies without prior notice. The lead plaintiff, John Kelly, was twenty years old, a recipient of New York's Home Relief general-assistance program whose benefits had been cut off after he left a city-assigned hotel for a friend's apartment. His caseworker had treated the move as a violation of the program's residence rules and terminated his benefits without a hearing. The class the District Court certified included recipients of Aid to Families with Dependent Children whose benefits had been similarly cut off, many for reasons of caseworker error or administrative convenience, all without the opportunity to contest the termination before it took effect.

The suit was brought by Mobilization for Youth Legal Services, a Manhattan-based legal-aid organization whose work on behalf of welfare recipients was part of the broader War on Poverty legal-services movement. The attorneys, David Diamond, Lee Albert, and others whose names appear in the case record, argued that the terminations violated the Due Process Clause because benefits, once granted, were the foundation of the recipients' subsistence and could not be revoked by administrative fiat without the procedural protections that had long been required in other deprivations of property and liberty.

The District Court, Judge Wilfred Feinberg writing for a three-judge panel, agreed. The state of New York appealed to the Supreme Court. The state's argument was simple: welfare benefits were not property in the constitutional sense; they were public largesse, conferred at the state's discretion, and revocable on the same terms. The Due Process Clause, on the state's reading, did not reach them.

The Court split five to three, Justice Marshall recused himself, with Brennan writing for the majority. The opinion was twenty-five pages long. It traced the history of the due-process doctrine. It acknowledged the state's interest in efficient administration of public-benefits programs. It held, after working through the interest-balancing calculus the Court had been developing in the preceding decade, that the procedural protections required in the termination of welfare benefits included notice, a meaningful pre-termination hearing, the right to present evidence and cross-examine adverse witnesses, and a decision based on the hearing record. Justice Hugo Black dissented, arguing that the majority had unduly extended judicial review over administrative process. Justice Harlan joined a separate dissent. Justice Stewart concurred in part. The five-justice majority held.

…

The chapter goes on from here — the holding in Kelly, the procedural order it built, and why the model of assumed truth it secured is the one machine-mediated decisions have quietly broken. It continues in the full manuscript.

Unlock the full book Back to the book

From Chapter Three

The Three Breaks

An excerpt from the opening of Chapter Three. The chapter — and the rest of the book — continues behind the wall.

§1.

Here is what is strange about the cases this chapter is about to describe. They were not, in any of the documented instances, produced by malicious actors. The people who designed Robodebt, MiDAS, the Dutch toeslagenaffaire algorithm, the British A-levels grading system, these people were not, on any examined record, attempting to produce harm. They were attempting to do their jobs under the operational pressures their institutions imposed. The harms that resulted were not the product of bad intent. They were the product of good-faith institutional choices made under specific structural conditions that the existing accountability infrastructure could not catch in time. This is what the three breaks describe. They are not a moral indictment. They are a structural diagnosis.

The structural diagnosis matters because it determines the remedy. If the harm were the product of bad intent, the remedy would be to identify and replace the bad actors. The harm is not the product of bad intent. The remedy is to change the structural conditions under which good-faith actors can produce harm without the accountability infrastructure catching it. The architecture this book proposes is the structural change. The cases that follow show, with documentary specificity, what the structural conditions look like in operation and why the existing infrastructure cannot catch them.

Between July 2016 and November 2019, the Australian Department of Human Services issued approximately 470,000 automated debt notices to current and former welfare recipients. The notices claimed, on average, $1,800 per recipient in overpayments the recipients had allegedly received and the government was now demanding back. The notices informed recipients that they had twenty-one days to respond with documentation disputing the debt. If no response was received, or if the response was deemed inadequate, the debt was formalized. Collection began. Interest accrued. Wages were garnished. Tax refunds were intercepted. Some recipients received letters from private debt collectors contracted by the government to pursue the debts on commission.

The scheme was called the Online Compliance Intervention. In public discourse it came to be called Robodebt.

The scheme's operating mechanism was straightforward. Welfare recipients' reported income, as they had declared it during the fortnightly reporting periods the benefits administration required, was compared to the annual income the Australian Taxation Office had on file for them. Where the two figures diverged, the government's system averaged the ATO's annual figure across the 26 fortnights of the year, compared the averaged figure to the fortnightly declarations, and if the averaged figure was higher in any fortnight than what the recipient had declared, the difference was treated as an overpayment.

The averaging was the mechanism's specific flaw. A worker who had earned $40,000 across a year, but had earned it entirely in the first six months and been unemployed for the second six, had received benefits lawfully during the second six months, because her fortnightly income during those months had been zero, and the eligibility threshold applied to fortnightly income, not annual. The averaging treated her as having earned $1,538 per fortnight every fortnight, including the months she had earned nothing. Under that calculation, she had been "overpaid" during the unemployment months by the full amount of her benefit.

The calculation was unlawful. It had always been unlawful, on the actual terms of the Social Security Act the scheme purported to enforce. The government's own general counsel had advised, before the scheme launched, that averaging of the kind the scheme employed would not satisfy the statutory requirements. The advice was not acted on. The scheme launched anyway.

Over its operating life, the scheme produced approximately $1.76 billion Australian in claimed debts. The actual overpayments the scheme was supposed to identify, had they been calculated lawfully, would have been a small fraction of that figure. The gap was not noise. The gap was, substantially, the scheme's pattern of illegitimate claims against its own beneficiaries.

The scheme was halted in November 2019 after a federal court ruling held the averaging method unlawful. A Royal Commission, convened in August 2022, delivered its report in July 2023. The report characterized the scheme as a "massive failure in public administration" that had caused "immense harm" to hundreds of thousands of Australians. Two recipients of debt notices were documented to have died by suicide shortly after receiving them; the Commission acknowledged the cases could not be directly attributed to the notices but observed that the timing was consistent with the contribution of acute financial shock to the outcomes. The settlement of the class action against the scheme totaled approximately $1.8 billion Australian in refunds, interest, and damages. The specific officials responsible for the scheme's launch and continued operation were referred for possible prosecution; some have since faced civil penalties.

…

The chapter goes on from here — what the three breaks were — and why, in every case, no villain was required. It continues in the full manuscript.

Unlock the full book


From Chapter Four

Why the Old Fixes Fail

An excerpt from the opening of Chapter Four. The chapter — and the rest of the book — continues behind the wall.

I. The Six Substitutes

By 2024 a vocabulary had congealed around the problem described in Chapter 3. Policymakers, academics, corporate counsel, standards bodies, and journalists spoke a shared dialect. Its six load-bearing words were alignment, explainability, audit, regulation, litigation, and, beneath them all, a political settlement that treated AI governance as an extension of existing administrative practice.

Each word named something real. Each had adherents who did honest work. None of them, taken alone or together, closes the gap opened by the three breaks.

This chapter is not a survey. It is a demolition. Each of the six is shown insufficient in compressed form, not because the people working on it are wrong, but because the concept itself cannot bear the weight being placed on it. The six together form a vocabulary. The vocabulary cannot carry the load. What comes after them, the positive standard developed in Chapter 5, is not an improvement on the vocabulary. It is a different kind of answer to a different kind of question.

Michael Oakeshott, in a 1947 essay that has become unfashionable to cite and difficult to replace, distinguished technical knowledge, the kind captured by rules, manuals, and procedures, from practical knowledge, the kind captured only by doing. The characteristic error of modernity, on Oakeshott's view, is the rationalist's confusion: treating the manual as if it were the craft. Each of the six substitutes this chapter addresses commits a version of Oakeshott's error. Each captures some technical feature of accountability, a training procedure, an explanation method, a compliance check, a statutory rule, a litigation pathway, an administrative process, and mistakes the capture for the practice. The practice of accountability, like the practice of any genuine craft, requires an artifact produced under discipline, reviewed by a qualified practitioner, against a standard that can survive adversarial examination. No manual produces the artifact. The substitutes are manuals. The Decision Record is the craft.

The question the vocabulary tries to answer is: how do we make AI systems good? The question admissibility asks is: how do we make decisions reviewable? These are not the same question, and conflating them is the reason the last five years of effort have produced so much documentation and so little accountability.

II. Alignment

Alignment began as a technical research program and has become a civilizational aspiration. The program, in its narrowest form, asks how to train a large model so that its outputs track the intentions of its designers rather than the literal reward signal it was trained on. The aspiration asks how to ensure that increasingly capable AI systems act in accordance with human values.

The program is real work. Reinforcement learning from human feedback, constitutional AI methods, debate protocols, scalable oversight, these have improved the behavior of deployed models on measurable benchmarks. Models in 2026 refuse categories of requests they would have complied with in 2022. They cite their sources more often. They hedge more calibratedly. These are not nothing.

But alignment, even if it worked perfectly, would not solve admissibility. A perfectly aligned model that denied a benefits claim would still leave the affected party with no reviewable record of why. A perfectly aligned model that recommended a sentence would still leave the judge with no way to show that the recommendation was arrived at rather than generated. A perfectly aligned model that approved a loan would still leave the regulator with no substrate to audit against.

Alignment is about the internal quality of a model's reasoning relative to its designers' intent. Admissibility is about the external quality of a decision's record relative to the rights of people affected by it. These are orthogonal concerns. A model can be aligned and its decisions inadmissible. A model can be misaligned and its decisions, if properly recorded, reproducible, and reviewable, admissible enough to be challenged, which is what matters when you are the person being denied.

…

The chapter goes on from here — why each of the six substitutes — transparency, explainability, audit, and the rest — does partial work and leaves the real question untouched. It continues in the full manuscript.

Unlock the full book


From Chapter Five

What Is a Real Decision?

An excerpt from the opening of Chapter Five. The chapter — and the rest of the book — continues behind the wall.

§1.

The Loomis sentencing hearing took place in a small wood-paneled courtroom on the second floor of the La Crosse County Courthouse, in the early afternoon of August 12, 2013. The judge, Judge Scott Horne, had been on the La Crosse County Circuit Court bench for nine years. The defendant, Eric Loomis, was thirty-one years old. The state's prosecutor was a senior assistant district attorney named Rian Radtke. The defense was represented by a public defender named Michael Rosenberg. The pre-sentence report on Judge Horne's bench, beneath the open Wisconsin Statutes, included a single page that summarized Loomis's COMPAS risk score. The number was a "high", both for violence and for general recidivism.

Judge Horne, in his subsequent sentencing remarks, acknowledged the score. He did not, he said, rely on it exclusively. He explained that he had considered the pre-sentence report as a whole, the nature of Loomis's offense, the defendant's prior record, the circumstances of his life, and the broader interests of public safety and rehabilitation that Wisconsin's sentencing framework asked him to weigh. He imposed a sentence of six years in prison.

What the judge did not have, on the bench that afternoon, was access to the algorithm that had produced the score. He had a number. He referenced the number. The number was opaque to him as it was opaque to Loomis, to the public defender, to the prosecutor, to the appellate courts that would later review the sentence, and ultimately to the Supreme Court of the United States, which would deny certiorari in June 2017. The opacity is what this chapter is about. The number on the bench was the product of a process whose specific operations on Loomis's specific case nobody in the courtroom could reconstruct.

In 2013, Eric Loomis was arrested in La Crosse, Wisconsin, for driving a car that had been used in a drive-by shooting. He pleaded guilty to two of the less serious charges. At his sentencing, the judge assigned him six years in prison. In the sentencing memorandum, the judge cited Loomis's score on a risk-assessment tool called COMPAS, Correctional Offender Management Profiling for Alternative Sanctions, which had rated him a high risk of violence and a high risk of recidivism. The judge did not rely on COMPAS alone. But the score was in the file, and the judge referenced it, and the six years were imposed.

Loomis appealed. He did not challenge the plea. He challenged the use of the score.

COMPAS was a proprietary product. Its algorithm was not disclosed to the court, to defense counsel, or to the defendant. The company that produced it, Northpointe (later Equivant), considered the methodology a trade secret. The questionnaire that produced Loomis's inputs was partially visible; the weights the algorithm applied to those inputs were not. The decisioning logic that had generated his specific score of high risk of violence was, in the judge's sentencing record, an opaque fact. The judge had the number. The judge did not have what the number was made of.

Loomis's argument was simple. He had been sentenced using a decisioning process he could not examine. He could not cross-examine the algorithm. He could not challenge the weights. He could not show that the score was inconsistent with his particular circumstances, because he did not know how the score had been calculated. The sentence had, in effect, been imposed partly by a tool whose reasoning no one in the courtroom could reconstruct.

The Wisconsin Supreme Court ruled against him in July 2016. The opinion, State v. Loomis, held that the use of the score had not violated his due-process rights because the judge had not relied on it exclusively. The court acknowledged that the algorithm was opaque. It acknowledged that the score's reasoning could not be examined. It imposed a prospective requirement, that future sentencing memoranda include a specific cautionary instruction about the score's limitations, and affirmed the sentence.

The United States Supreme Court denied certiorari in June 2017.

Loomis served his sentence. The tool remains in use, in various versions, across American courts.

…

The chapter goes on from here — what the Loomis court could not do, and what a decision worth the name would have required. It continues in the full manuscript.

Unlock the full book


From Chapter Six

The Reviewer

An excerpt from the opening of Chapter Six. The chapter — and the rest of the book — continues behind the wall.

§1.

In the autumn of 1936, in a small office on the seventh floor of the Equitable Building in lower Manhattan, a man named Carter Hawley was trying to figure out what he had been hired to do. Hawley was thirty-eight years old. He was a partner at a five-year-old accounting firm called Hawley, Bailey & Co. He had been retained by an industrial company whose stock was newly listed on the New York Stock Exchange, to audit the company's financial statements under the still-unclear requirements of the Securities Exchange Act of 1934. The Act had created the Securities and Exchange Commission. The Commission had begun issuing regulatory pronouncements. The accounting profession had begun developing what would become Generally Accepted Auditing Standards. None of these things was, in the autumn of 1936, settled. Hawley had on his desk three memos from the SEC, two articles from the Journal of Accountancy, and a letter from his client's general counsel inquiring about the scope and form of the audit Hawley was about to conduct. The professional infrastructure within which his work would, eventually, become routine was, at the moment Hawley sat at his desk in 1936, being built around him in real time.

What Hawley was doing was inventing the practical content of a profession the statute had created in name. The Act had specified that public companies' financial statements would be audited by an independent public accountant. The Act had not specified what audit meant in operational terms, what independent required of the auditor's relationship with the audited company, what scope the audit had to cover, what form the audit's opinion had to take, what the consequences of an inadequate audit would be. These specifications would be developed over the next thirty years, by people like Hawley working through specific engagements and producing, through their accumulated practice, the working content of the profession. The Securities Exchange Act of 1934 created one of the most consequential institutional roles of the twentieth century, and almost no one at the time understood what they were doing.

Section 13 of the Act required publicly traded corporations to file annual financial statements with the newly-created Securities and Exchange Commission. Section 10A, added later, required those statements to be audited by an independent public accountant. The Act did not specify what independent meant in operational terms. It did not specify the auditor's qualifications, the scope of the audit, the standards to be applied, the form of the audit opinion, or the consequences of audit failure. It specified a requirement. The institutional content of the requirement was left to be worked out.

Working out what it meant took thirty years.

The American Institute of Accountants (now the AICPA) spent the 1930s drafting what would become generally accepted auditing standards. The SEC spent the same decade issuing Accounting Series Releases that clarified what was expected of registrants and, indirectly, of their auditors. State boards of accountancy developed licensing procedures for Certified Public Accountants. Professional-liability insurance emerged to cover auditor negligence. Specialized training programs at universities began to produce graduates qualified for the role. Congressional hearings after the McKesson & Robbins fraud in 1938 produced the first real specification of auditor procedures. The post-war expansion of public markets produced demand for auditors at scales the profession had not previously seen.

By 1965, the independent financial auditor was a recognizable institutional figure. Every public company had one. Every audit followed procedures specified by professional standards. Every audit produced an opinion in standard form. Every state licensed auditors with uniform requirements. Every auditor could lose her license for failures of conduct that professional-ethics boards enforced. The role had acquired the specific shape that let it perform the function the 1934 Act had contemplated.

The history is worth pausing over because it establishes the institutional timeline that the admissibility Reviewer profession is about to compress. The 1896 New York law creating the CPA credential was modest in scope, it restricted the "CPA" title to individuals who had passed a written examination and met specified experience requirements. Similar state-level credentialing laws followed across the country through the early twentieth century, but the credential itself carried limited practical authority. Before 1933, most American corporations were not subject to any federal requirement to produce audited financial statements. Such audits as occurred were voluntary, conducted under bilateral arrangements between corporations and accounting firms, governed by inconsistent practices. The McKesson & Robbins fraud of 1938, a drug-distribution company that had been fabricating inventory for years while its auditors, Price Waterhouse, failed to detect the fabrication through the conventional audit procedures of the era, shocked the profession into its first serious standards-development effort. Statement on Auditing Procedure No. 1, published in 1939 by the American Institute of Accountants' Committee on Auditing Procedure, formalized procedures that would have caught McKesson & Robbins earlier. SAS No. 1 became, over subsequent decades, the foundation of what would eventually be Generally Accepted Auditing Standards.

…

The chapter goes on from here — who the reviewer is, what they need to do the work, and why the role has to sit outside the institution being reviewed. It continues in the full manuscript.

Unlock the full book


From Chapter Seven

The Decision Record

An excerpt from the opening of Chapter Seven. The chapter — and the rest of the book — continues behind the wall.

In 1958, the U.S. Civil Aeronautics Administration mandated flight data recorders on commercial aircraft after a decade in which high-profile accidents, the 1956 Grand Canyon mid-air collision had killed 128 passengers, and its causes had been partially unreconstructible, had made clear that the absence of a contemporaneous record of cockpit activity was limiting the industry's ability to learn from failures. The mandate was resisted. Pilot unions argued that the devices were surveillance technology whose presence would undermine cockpit collaboration. Airlines argued that installation costs were disproportionate. Manufacturers argued that the weight penalty cut into already-tight operating margins. The mandate was implemented anyway. The subsequent sixty-eight years have vindicated the decision: every major aviation accident since 1958 has been investigated, in substantial part, through the FDR and cockpit voice recorder substrate. The Air France 447 disaster was reconstructed from recorders recovered from the ocean floor two years after the crash. The Boeing 737 MAX investigations traced specific MCAS behavior across fatal crashes because the recorders preserved what the cockpit crews had seen and done. The commercial-aviation fatal-accident rate has dropped by roughly two orders of magnitude since the mandate; many factors contributed to the drop, but the FDR is the specific condition of possibility for the improvement, without the substrate for identifying what went wrong, the work of preventing its recurrence could not begin.

The Decision Record, in structure and purpose, is the automated-decisioning domain's flight data recorder. The parallels are precise: a high-stakes outcome produced under time pressure across distributed actors, whose reconstruction at the moment of investigation is what makes accountability possible. The initial resistance, from operators who find the preservation requirement costly, from vendors who find the transparency uncomfortable, from regulators who have not yet grasped how radically the substrate changes their enforcement capacity, tracks the resistance to FDR adoption in the 1950s. The eventual universality is what the aviation pattern predicts for admissibility too.

The earliest specification of such an artifact that still shapes contemporary practice was Luca Pacioli's 1494 treatise, which did not invent double-entry bookkeeping so much as crystallize the Venetian practice of the previous two centuries into a form that could be taught, reproduced, and audited. Pacioli's insight was that accountability required an artifact whose integrity properties were internal to its construction: if the books did not balance, the record itself told you so, and the error had to be found before any downstream claim could be trusted. The Decision Record stands in the same lineage. Its seven required fields are not a list of documentation recommendations. They are the internal integrity conditions of an artifact designed to reveal its own inadequacy before any downstream claim is made on it.

The history of double-entry bookkeeping is worth tracing briefly, because the parallel to admissibility is more precise than a passing invocation can show. The technique emerged in Italian commercial cities during the thirteenth and fourteenth centuries, Genoa, Venice, Florence, in response to specific operational problems that the merchants of those cities could not solve with older single-entry ledgers. A single-entry ledger records transactions as they occur; a double-entry ledger records each transaction as an equal and offsetting pair of entries in two separate accounts, such that the sum of all debits equals the sum of all credits at every point in time. The double-entry discipline does not prevent errors; it produces a property, the trial balance, that makes errors visible. If the trial balance does not balance, something is wrong, and the error must be found before any financial statement drawn from the ledgers can be trusted.

Pacioli's 1494 Summa de Arithmetica, Geometria, Proportioni et Proportionalità dedicated a section, Particularis de Computis et Scripturis, to double-entry. The treatise was not original research; it described practices Italian merchants had developed over the preceding two centuries. Its contribution was codification: Pacioli wrote the practices down in a form that could be taught in the emerging commercial schools, transmitted across languages and borders, and reproduced by practitioners who had not learned at the feet of a Venetian merchant. The printing revolution, then less than fifty years old, gave Pacioli's treatise reach the prior manuscript tradition could not have provided. By 1550, double-entry had spread to the merchant classes of Antwerp, Nuremberg, and London. By 1600, it was the default technique for commercial recordkeeping across Europe. By 1700, it had become the foundation of the joint-stock-company form whose subsequent evolution shaped modern capitalism.

…

The chapter goes on from here — what a record has to carry to be worth keeping — and what the flight recorder understood that most systems still do not. It continues in the full manuscript.

Unlock the full book


From Chapter Eight

The Affected Party

An excerpt from the opening of Chapter Eight. The chapter — and the rest of the book — continues behind the wall.

§1.

In 2013, a Dutch mother, a naturalized citizen, originally from Suriname, working as a clerk in Rotterdam, received a letter from the Belastingdienst, the Dutch tax and customs administration. The letter informed her that her childcare benefits, kinderopvangtoeslag, which she had been receiving for her two young children, had been terminated, and that she owed the state approximately €40,000. The letter said she had committed fraud.

She had not committed fraud. She had submitted the same paperwork she submitted every quarter. Her paperwork had been accurate. Her childcare arrangements had been legitimate. What had changed was that an algorithm within the Belastingdienst had flagged her case for review as high-risk, and the review had converted the flag into a fraud determination, and the fraud determination had been actioned without anyone who could explain the flag's basis ever examining her specific case.

The algorithm had been trained on features that included, among many others, dual citizenship and country of origin. Families with certain demographic markers were more likely to be flagged. The flag was not, on the Belastingdienst's internal description, a finding of fraud. It was a priority-sorting mechanism. But in practice, flagged cases were being terminated without substantive investigation, because the volume of flagged cases exceeded the investigative capacity, and the agency's internal procedures permitted termination on the flag alone when supporting documentation was not produced within a specified window.

She had not produced supporting documentation within the window because she had not known the window existed. The termination letter was the first notice she received that her case was under review.

She appealed. The appeal process required her to reproduce documentation that, in many cases, she did not have copies of, because she had submitted the originals to the Belastingdienst in the ordinary course of her benefits administration. The Belastingdienst did not return documents. The Belastingdienst also did not, on her repeated requests, provide her with the specific records that had produced her flag. The flag's basis was, on the agency's position, administrative and not subject to disclosure.

The appeal was denied. The €40,000 debt was formalized. Collection began.

Over the next six years, she was pressured into a payment plan that consumed approximately a quarter of her income. Her credit was impaired. Her bank, under Dutch banking regulations, flagged her as a financial-risk account. She could not open an investment account for her children's education. When her younger child's chronic condition required specialist care not fully covered by insurance, she could not afford the specialist fees. Her partner, under the strain of the debt, left. She stayed.

Her case was one of approximately 26,000 families, by the final count, possibly more, exact numbers disputed across subsequent investigations, that the Belastingdienst had processed through this pattern between 2010 and 2019. The pattern was eventually exposed by journalists at Trouw and RTL Nieuws, documented formally in the Dutch Ombudsman's 2019 report Geen Powerplay Maar Fair Play, and investigated by a parliamentary committee whose December 2020 report, Ongekend Onrecht, Unprecedented Injustice, became the catalyst for the resignation of the entire Dutch cabinet in January 2021.

Hannah Arendt's formulation, that the evil of mid-century bureaucracy was banal not because it was small but because the people conducting it were small, each performing a narrow function without a grasp of the cumulative effect, applies to the toeslagenaffaire with a painful exactness, scaled for the machine-assisted era. No single official decided to ruin twenty-six thousand families' financial lives. No single coder designed the fraud-detection algorithm to target the Dutch-Turkish and Dutch-Moroccan populations the system disproportionately flagged. The aggregate effect emerged from a cascade of small decisions, each defensible in isolation, none of which added up to accountability for the cumulative harm. Arendt identified this pattern in 1963. She did not foresee its automated form. The pattern carries across anyway. What has been lost is not the diagnosis; what has been lost is the capacity of the old accountability tools to reach the pattern now that the decisions travel faster than the tools.

The scandal is referred to, in Dutch public discourse, as the toeslagenaffaire, the benefits affair. The affected families are known, in the specific vocabulary the affair developed, as gedupeerde ouders, duped parents.

…

The chapter goes on from here — what the duped parents were owed — and what, for years, no one could give them. It continues in the full manuscript.

Unlock the full book


From Chapter Nine

The Legal Threshold

An excerpt from the opening of Chapter Nine. The chapter — and the rest of the book — continues behind the wall.

I. Daubert in a World of Models

In June 1993, the Supreme Court decided Daubert v. Merrell Dow Pharmaceuticals. The case was about Bendectin, an anti-nausea drug prescribed during pregnancy, and whether epidemiological testimony linking the drug to birth defects could reach a jury. The answer was a four-factor test for scientific evidence: testability, peer review, known error rate, and general acceptance. The test replaced the older Frye standard of "general acceptance in the scientific community" with a more demanding inquiry into methodological reliability.

The specific facts of the Daubert case are worth naming. Jason Daubert and Eric Schuller were children born with serious birth defects, limb reductions and other congenital malformations. Their parents, Joyce Daubert and her co-plaintiff, alleged that their mothers' use of Bendectin, an anti-nausea medication marketed by Merrell Dow for morning sickness, had caused the defects. Bendectin had been on the market since 1956 and had, by the time the Daubert family's case was filed in 1989, been the subject of extensive epidemiological research. The published research, reviewed by the FDA, had not found a statistically significant association between Bendectin and birth defects at the scale of the available studies. The plaintiffs' case rested on expert testimony from a group of scientists who, in their own re-analysis of the existing studies and through specific animal-toxicology research, argued that the published literature had underestimated the risk.

The district court excluded the plaintiffs' expert testimony under the Frye standard, the experts' conclusions were not generally accepted in the scientific community, so their testimony could not reach the jury. The Ninth Circuit affirmed. The Supreme Court granted certiorari to resolve the question of whether the Federal Rules of Evidence, passed in 1975, had displaced the older Frye standard. Justice Harry Blackmun wrote for the Court. The opinion held that the Federal Rules had displaced Frye, and that the new standard for admitting scientific expert testimony required the trial court to assess the reliability of the methodology rather than the consensus of the field. Blackmun's opinion listed four factors, testability, peer review, known error rate, general acceptance, as non-exhaustive considerations that trial courts could apply in the reliability inquiry. The case was remanded to the lower courts, which ultimately held that the plaintiffs' testimony failed the reliability inquiry even under the new standard. The Dauberts lost their case on the merits. The doctrine their case established became controlling for every subsequent scientific-evidence question in federal court.

The Frye standard the Court replaced had been established in 1923 in a case involving an early lie-detector technology. The United States Court of Appeals for the District of Columbia held that expert testimony based on novel scientific techniques was admissible only if the technique had gained "general acceptance" in the relevant scientific community. The standard was conservative by design, it protected the jury from novel scientific claims that had not been vetted through the peer-review process. It was also, by the 1980s, increasingly criticized as allowing admission of forensic methods that had gained community acceptance without having gained methodological rigor. The specific failures of forensic toolmark analysis, bitemark identification, and comparative bullet-lead analysis, each of which was admissible under Frye because each had gained community acceptance, and each of which was subsequently discredited through methodologically rigorous examination, illustrated the standard's weakness. Daubert shifted the inquiry from community acceptance to methodological reliability. The shift was partial, Daubert explicitly retained general acceptance as one of its four factors, but the direction was clear.

The Daubert doctrine has evolved through two subsequent Supreme Court cases. General Electric Co. v. Joiner (1997) clarified that trial courts' gatekeeping decisions under Daubert are reviewed for abuse of discretion rather than de novo. Kumho Tire Co. v. Carmichael (1999) extended the Daubert reliability inquiry to non-scientific expert testimony, engineering, clinical, and technical testimony, holding that the gatekeeping obligation applied to all expert evidence, not merely to scientific evidence in the narrow sense. The three cases, Daubert, Joiner, Kumho, together establish what courts now call the Daubert framework. Federal Rule of Evidence 702, amended in 2000 and substantially revised in 2023, codifies the framework.

…

The chapter goes on from here — how the law already decides what evidence is allowed to decide — and what that standard demands of a model. It continues in the full manuscript.

Unlock the full book

From Chapter Ten

The Adversarial Problem

An excerpt from the opening of Chapter Ten. The chapter — and the rest of the book — continues behind the wall.

I. The Threat Model That Breaks Most Proposals

Every accountability regime eventually meets an adversary. Financial audit met Enron. Forensic science met the Innocence Project. Clinical trials met industry-sponsored publication bias. Peer review met the replication crisis. The question for any proposal, including admissibility, is not whether it survives honest operators and good-faith contestation. The question is what happens when someone with real resources and strong incentives tries to break it.

The formal economic literature on this problem has a specific name: the principal-agent problem. Leonid Hurwicz, Eric Maskin, and Roger Myerson received the 2007 Nobel Prize in Economics for their work on mechanism design, the mathematical analysis of how institutional rules can be designed to produce specified social outcomes given that participants will pursue their own interests strategically. The principal-agent problem, a core concern in this literature since the 1970s, models the specific situation in which an agent (the operator) is hired by a principal (the affected parties, through the institutional arrangements the society has chosen) to act on the principal's behalf in conditions where the agent's actions are imperfectly observable and the agent's interests may diverge from the principal's. The theoretical question mechanism design asks is: what contract structure, monitoring arrangement, and incentive design minimizes the divergence? The answer the literature has developed, across half a century of refinement, has the shape the admissibility architecture takes: transparency of operator actions, third-party monitoring by agents with divergent interests, incentive alignment through external rewards and penalties, commitment mechanisms that make deviation costly. The book is not hoping operators will behave well. It is engineering the institutional conditions under which behaving well is each operator's best strategic response to its environment. Mechanism-design theory provides the formal vocabulary within which this engineering can be analyzed and refined.

This chapter develops the threat model for admissibility and shows how the architecture survives it. The adversary here is not hypothetical. The operators who will most strongly resist Decision Records are the ones whose current practices would be most exposed by them. The parties most likely to exploit weak records are the ones with the most to gain from contested decisions not being reviewable. The actors most positioned to corrupt the Reviewer function are the ones with the most interest in Reviewers who do not look too closely.

Admissibility is not an architecture for systems that want to be accountable. It is an architecture for systems that must be accountable under pressure they would rather not bear. The test of the design is how it holds when the adversary is real.

The pattern has been catalogued in domain after domain. The Italian double-entry ledger met its first systematic attack in the early modern period from merchants who maintained two sets of books, one for review, one for operation, which is why the modern audit regime requires third-party confirmations against external counterparties rather than trusting the books alone. The scientific peer-review system met its adversary in the 20th-century pharmaceutical-industry pattern of selective publication, which is why registration-of-trials before data collection has become the standard pre-submission requirement in much medical research. The credit-rating system met its adversary in the issuer-pays model that produced the 2008 financial crisis, which is why there are now serious proposals, unimplemented, but under ongoing policy discussion, to shift toward investor-pays or exchange-funded ratings. Each accountability regime's eventual adversary became the occasion for its architectural maturation. Admissibility will follow this pattern. It is already in motion.

The Enron case is worth pausing over, because it is the clearest twentieth-century instance of an accountability regime failing under adversarial pressure and the architectural reforms that eventually followed. Enron Corporation, an energy-trading company based in Houston, collapsed in December 2001 after its financial statements were revealed to contain years of systematic misrepresentation. The misrepresentation had been executed through "special-purpose entities", nominally independent companies that Enron controlled operationally but excluded from its consolidated financial statements, allowing it to book revenue from transactions with the entities while keeping the entities' associated debt and losses off its books. The misrepresentation had been known to Arthur Andersen, Enron's auditor; Andersen had signed Enron's financial statements for years while internal Andersen communications, later obtained through litigation and congressional investigation, showed that senior Andersen partners were aware of the aggressive accounting treatments. The scheme collapsed in late 2001 when SEC-registered disclosures forced restatement; Enron's stock price fell from $90 per share in mid-2001 to under $1 by the time it filed bankruptcy in December. Andersen, which at the time was one of the Big Five accounting firms, was indicted in 2002 for obstruction of justice related to the document destruction that had accompanied the scheme's unraveling. The firm did not survive the indictment. Its partners scattered to the other Big Four firms; its client base evaporated; it effectively dissolved within eighteen months of the indictment.

…

The chapter goes on from here — what happens when the standard meets a determined adversary, and which proposals survive the encounter. It continues in the full manuscript.

Unlock the full book


From Chapter Eleven

The Procurement Revolution

An excerpt from the opening of Chapter Eleven. The chapter — and the rest of the book — continues behind the wall.

I. How Standards Actually Propagate

Most accountability standards do not propagate through regulation. They propagate through procurement.

HIPAA did not change healthcare IT because the statute was powerful. It changed healthcare IT because every hospital system's vendor contracts began to require HIPAA-compliant data handling as a condition of sale, and vendors who could not demonstrate compliance lost their markets within three years of the rule taking effect. PCI-DSS was not legislated; it was a consortium standard that the major card brands imposed on merchants, who imposed it on acquirers, who imposed it on payment processors, who imposed it on the entire ecosystem within five years. SOC 2 was not a government mandate; it was a contract requirement that large enterprise buyers began inserting into their vendor agreements in 2013–2016, and the SaaS industry reorganized its operations around it in less than a decade. FIPS 140-2 certification became the default for federal cryptographic modules not because a regulator required it universally but because GSA schedules, FedRAMP authorizations, and DoD acquisition packages began requiring it as a line item that excluded non-compliant vendors from bidding.

Alfred Chandler, the historian of American managerial capitalism, identified the procurement function as one of the quiet engines of industrial standardization. When large-scale vertically integrated firms, railroads, steel, oil, automobiles, became the dominant organizational form in the late 19th and early 20th centuries, their purchasing departments became the mechanism by which engineering specifications propagated across supplier ecosystems. A locomotive manufacturer did not invent its wheel standards alone; it specified them in contracts with its steel suppliers, which forced the suppliers' upstream metallurgy practices to converge. This procurement-led standardization is how the interchangeable-parts tradition of Eli Whitney scaled from armaments into industrial production broadly, and how it propagated across national and eventually international supply chains. Admissibility is about to repeat the pattern. The specifications are engineering; the propagation mechanism is commercial. Chandler's observation is still operative.

The HIPAA case deserves development, because it is the clearest American example of a standard propagating through procurement rather than regulation alone. The Health Insurance Portability and Accountability Act was enacted in 1996. Its privacy and security rules were, however, not immediately operational; they required administrative rulemaking through the Department of Health and Human Services. The Privacy Rule was finalized in 2000, with compliance required by 2003. The Security Rule was finalized in 2003, with compliance required by 2005. Enforcement of both rules, through HHS's Office for Civil Rights, began modestly, the first significant civil monetary penalty under HIPAA was not assessed until 2008, twelve years after the Act was passed.

What moved the healthcare-IT industry into compliance was not, primarily, the enforcement risk. It was the procurement requirement that cascaded through the hospital and health-system purchasing departments. By 2004, every major hospital system's IT procurement function required HIPAA compliance as a condition of any new electronic-health-record contract. By 2006, the requirement had extended to adjacent systems, laboratory-information systems, billing platforms, patient-portal products, pharmacy-management tools. By 2008, the healthcare-IT industry's product roadmaps were substantially structured around HIPAA compliance as a baseline expectation. Vendors that could not certify compliance lost access to the market. Vendors that could certified built their marketing materials and sales presentations around the certification. The standard propagated from the largest buyers through the ecosystem within a five-year window, driven by procurement rather than by the direct operation of the statute.

PCI-DSS followed a parallel pattern with different actors. The Payment Card Industry Data Security Standard was launched in 2004 by the major card brands, Visa, Mastercard, American Express, Discover, JCB, as a consortium standard. The card brands imposed the standard on their acquiring banks; the acquiring banks imposed it on their merchant customers; the merchants imposed it on their payment processors and technology vendors. The cascade reached its saturation point within about six years. By 2010, PCI-DSS compliance was a baseline requirement for any vendor handling credit-card data in any capacity. The standard was never legislated; the card brands' commercial authority, amplified through the procurement cascade, produced more comprehensive compliance than most legislative frameworks achieve.

…

The chapter goes on from here — how a standard actually spreads — not through law, but through what the buyers require. It continues in the full manuscript.

Unlock the full book


From Chapter Twelve

The New Public Order

An excerpt from the opening of Chapter Twelve, the closing chapter. It continues behind the wall.

§1.

The book began with Dawn.

In 2014, in western Michigan, a commercial-bakery worker received an adverse determination from an automated system that could not explain itself. She lost her income, her credit, her housing stability, and for a period her custody arrangements. The state eventually acknowledged that the system had been wrong in her case and in approximately 40,000 others. The compensation, when it came, came years after the harm. The records that would have let her contest the original determination did not exist.

If Dawn's case arose today, in the jurisdictions that have begun to build the architecture the preceding chapters have described, it would unfold differently.

Her letter arrives on a Tuesday, three weeks after her claim is filed. It is, on its face, a routine administrative notice. The letterhead is the Michigan Unemployment Insurance Agency's. The tone is bureaucratic. The content is adverse: her claim has been referred for fraud review. But the letter, unlike the one that arrived in her actual 2014 case, contains additional text.

Below the categorical reasons for the referral, the letter specifies a Decision Record identifier, a twenty-character string that serves as a handle to the full record of the determination. The letter explains, in plain language, that the record contains the specific inputs the agency's system used, the specific rules in force at the time of the determination, and the specific components that produced the fraud referral. The letter provides three pathways to request the record: an online portal (accessible through the agency's website with identity verification), a request-by-mail template, and a referral to legal-aid organizations that can assist with record-based contestation at no cost.

She receives the letter. She reads it twice. She does not understand all of it, but she understands enough. She requests the record.

The record arrives three business days later. It arrives in two forms: a machine-readable file her attorney can use (if she hires one) and a human-readable summary she can read herself. The summary tells her, in specific terms, what the system concluded and why: the wage-matching rule flagged a discrepancy between her reported wages and the wages her employer had reported to the state tax authority; the discrepancy exceeded the fraud-referral threshold; the system generated the referral.

She reads the summary. She looks at her records. The discrepancy the system identified is the timing gap between her bi-weekly reporting and her employer's quarterly tax filing. She had reported her wages accurately; her employer had reported them accurately; the two reporting periods had simply not aligned, and the system's matching logic had treated the misalignment as evidence of fraud.

She, or her legal-aid attorney, contacts the agency through the channels the notice had specified. The attorney requests a replay of the determination under the affected-party-access protocol. The agency's Reviewer function, which in this jurisdiction is housed in an independent regulatory office, conducts the replay. The replay confirms that the determination was produced by the matching-rule misalignment. The Reviewer's finding, delivered in seven working days, confirms that the determination does not reflect actual fraud and should be vacated.

The fraud referral is rescinded. Dawn's benefits continue without interruption. The agency's governance office is notified of the matching-rule failure, which has been identified as a systemic issue across an entire category of similarly-situated claimants. A corrective patch is pushed to the matching rule within thirty days. Dawn's case is one of approximately 150 cases that surface the same pattern in a compressed timeframe; the pattern is caught at 150 cases rather than at 40,000.

The total elapsed time from determination to remedy: approximately eleven working days. The total out-of-pocket cost to Dawn: zero. The damage to her credit, her employment, her housing, her children's stability: none. The garnishment does not occur because the determination is vacated before the garnishment phase triggers. The hearing occurs, but it is a hearing on the specific facts of a correction that has already been performed, not a hearing in which she must prove her innocence against a system that has already damaged her.

…

The chapter closes the argument the book opened with Dawn — what the standard leads to, and what it would mean for the affected party to be owed a reconstruction rather than a fight. It continues in the full manuscript.

Unlock the full book


Lineage

The manuscript reads against a specific shelf, not against the contemporary technology-policy literature.

Lawrence Lessig's work on architecture as a regulatory modality is the closest single referent — the manuscript extends the argument that code precedes law into the procedural domain one layer further in: the architecture of review that determines whether the decisions produced inside an institution can be reconstructed at all. Laurence Tribe's work on constitutional reviewability, and the durability of procedural protection when state action becomes opaque, is the second. The constitutional pressure point the manuscript names — that automated state and institutional decisions become unstable when they cannot be examined adversarially — sits inside the tradition his work has carried.

The further references are partly historical, partly methodological: Hannah Arendt on the conditions under which public judgment is possible; Jürgen Habermas on procedural legitimacy as the load-bearing element of legitimate authority; Niklas Luhmann on second-order observation, and the discipline of asking how a system makes its own decisions visible to itself; Bernard Stiegler on what institutions inherit, store, and lose; Karl Polanyi on the social conditions under which institutional forms are forced to change; Carroll Quigley on the structural transitions between institutional periods. The lineage is named because the argument belongs inside that conversation.


A note on category

The closer shelf is constitutional theory, administrative-state realism, evidence theory, and institutional history. The reader who carries the most out of the manuscript is the one already operating inside that frame — a judge, a regulator, a senior administrative-law faculty member, an institutional operator who has seen procedural failure modes from the inside, a constitutional theorist asking what comes after the current administrative settlement.

The institutional claim the book carries throughout is short. If a consequential decision cannot be replayed, institutions should not be allowed to rely on it. Everything else is the architecture that follows from that sentence.


End of excerpt

This is an excerpt from the editorial galley of Admissible Reality. The full book is forthcoming. If you would like to be notified when it is available, you can join the list from the book home.

Join the list Back to the book