Res Agentica
Reading

No saved reading position.

Reading

No saved reading position.

Chapter 7

The Right to Run the Proof

The Means to Contest

29 min read
Aa
Text size

Do not consider a statement true because you find it in a book, for the prevaricator is as little restrained with his pen as with his tongue.

— Maimonides, Epistle to Yemen (1172)

The Score Behind the Door

In Houston, a number capable of ending a public-school career was produced by a company the school district had hired and could not itself audit.

The district had adopted a value-added system intended to measure how much a teacher contributed to the growth of student test scores. The aim was defensible. Schools need ways to identify excellent teaching, help teachers who are struggling, and act when performance remains poor. The difficulty lay in the object that the system produced. A private vendor, SAS, calculated each teacher's score through proprietary software and several layers of statistical transformation. The raw result became a Teacher Gain Index, and the index became one of five effectiveness ratings. Those ratings entered employment decisions carrying the authority of measurement, although neither the teachers nor the school district could reproduce the calculation that gave them force.

The district could tell a teacher which students had been linked to her and provide a general account of how value-added modeling worked. It could not show that her particular score had been calculated correctly. SAS treated the underlying code and methodology as trade secrets. The district did not audit the scores or retain anyone else to do so. Even an expert for the teachers, given more access than any individual teacher would receive, could not reproduce them. The number arrived finished.

That distinction became constitutional because the score was not merely advice. District policy tied low value-added ratings to nonrenewal and termination, and teachers with protected interests in their employment faced the prospect of losing those interests through a calculation no participant in the decision could independently test. In 2017 a federal court denied the district summary judgment on the teachers' procedural due-process claim. The record, the court concluded, supported the contention that teachers had no meaningful way to ensure that their scores were correct.

The court did not pretend that due process automatically dissolves trade secrecy. It made the harder point. A vendor's legitimate interest in protecting proprietary methods does not entitle a public institution to impose a consequential deprivation through a method that cannot be challenged. The remedy need not be publication of every line of code. It may instead be confidential independent testing, a different evidentiary method, or a refusal to make the secret score dispositive. What the institution cannot do is borrow the authority of a calculation while disclaiming responsibility for whether the calculation is right.

This is the right to run the proof in its most elementary form. The right does not mean that every person must become a statistician, cryptographer, or software engineer. It means that a consequential computational claim cannot become final merely because the institution making it possesses machinery the affected person does not. Somewhere outside the chain that produced the result, the claim must remain open to an adversarial test at the level on which the consequence depends.

The distinction is easy to blur because modern systems produce more transparency than older bureaucracies did. A dashboard may display the score, a technical paper may describe the model, and a notice may identify the category into which the person has fallen. None of those things establishes that the score was calculated from the correct records, under the operative version of the rule, with no silent error in the path from data to consequence. Visibility is not yet verifiability. A person can see the number and remain unable to answer it.

The Houston teachers stood before a score that was public enough to govern and private enough to resist examination. That position is becoming ordinary. Credit applicants receive adverse-action reasons without the model or data lineage that made those reasons decisive. Benefits recipients receive a budget without the rule by which their needs became dollars. Workers receive risk classifications generated by vendors their employers cannot fully inspect. The computational system speaks through the institution, while the institution points back to the system.

A constitutional order cannot allow that circle to close. Power may use experts, models, proprietary methods, and proofs too difficult for most people to understand. It may not use complexity to convert an assertion into an incontestable fact.


A Right in Name

Amartya Sen's capabilities approach begins from a distinction the law often prefers to postpone: the difference between possessing a right in form and possessing the practical freedom the right is supposed to secure. A polling place may be open while remaining unreachable. A school may admit everyone while existing nowhere nearby. The absence of a legal prohibition tells us little about what a person is actually able to do.

Verification has the same structure. Publishing code removes one barrier, but it does not give an ordinary person the time, data, tools, or expertise needed to test the decision that affected them. A system can be open source and practically unanswerable. The files exist, the instructions are online, and the person remains as unable to challenge the result as if the calculation were locked in a cabinet. Formal access becomes a recital performed over an inaccessible capability.

The right to counsel supplies the closest constitutional analogy, though the analogy should not be mistaken for existing doctrine about algorithms. The Sixth Amendment had long protected the accused person's ability to retain a lawyer. In Gideon v. Wainwright, the Supreme Court recognized that this formal permission was inadequate for an indigent defendant facing the machinery of criminal prosecution. Lawyers in criminal courts, the Court observed, are necessities rather than luxuries, and the adversary system cannot reliably produce justice when only one side can use the language, procedure, and investigatory resources through which the contest is conducted.

The constitutional insight was not that every defendant must learn the law. It was that a right whose exercise depends upon specialized capability may require society to make that capability available. The state already supplied prosecutors, rules of evidence, compulsory process, and a judge. Telling an indigent defendant that the courthouse was open did not place the defendant in a meaningful position to answer the case.

Strickland v. Washington later made clear that the right concerns effective assistance, not ceremonial presence, although the Court imposed a demanding test requiring both deficient performance and prejudice. The doctrine falls well short of guaranteeing perfect advocacy. It nonetheless rejects the idea that an empty chair filled by an unprepared body satisfies the constitutional need. The adversarial process must remain capable of testing the prosecution's claim.

That logic reaches computational governance by analogy rather than automatic extension. A person denied a loan is not thereby a criminal defendant, and a private scoring system is not a prosecutor. The relevant structure is narrower. Where an institution exercises consequential authority through a technical claim, the ability to contest that claim may depend on capabilities the affected person cannot reasonably be expected to possess alone. A formal appeal is then no more sufficient than a formal right to hire a lawyer one cannot afford.

State v. Loomis exposed the limit of access without inspectability. A Wisconsin sentencing court considered a proprietary COMPAS risk assessment among several factors. The state supreme court permitted that bounded use while requiring cautions: the tool could not determine whether a person should be incarcerated or the severity of sentence, and its proprietary character limited the defendant's ability to explain how the risk score was calculated. The court did not recognize a general right to source code. It placed legal limits around a consequential score whose methodology the defendant could not fully test.

That compromise is instructive and incomplete. Warning a judge that a score has limits may prevent one misuse while leaving the affected person unable to investigate error in the input, reference population, or application. A usable right must identify the material proposition, what evidence can test it, and which institution bears the cost when the issuer chooses a method the subject cannot inspect.

The litigation over Idaho's Medicaid budget tool made the point with unusual clarity. Adults with developmental disabilities received annual budgets determining the services available to support life in their homes and communities. The state calculated those budgets through a statistical tool built from administrative data. The notices did not adequately explain why a budget had been reduced, the standards governing review were difficult to identify, and the appeal required gathering medical records, understanding program rules, and presenting a case many participants could not prepare without substantial help.

The record was not a simple story of wicked automation. The state was administering a difficult program under resource constraints, and individualized budgeting necessarily required classification. Yet the underlying data contained extensive errors, the tool was expected to produce inadequate budgets for a significant minority of participants, and the state had not built a robust process for finding and correcting those errors. Before human reconsideration was curtailed, most reviewed budgets had been increased. The model did not fail by producing nonsense in every case. It failed constitutionally because predictable error was joined to an appeal process many of the people exposed to it could not use.

The court required more than another notice. It required the state to obtain a commitment from a suitable representative to assist a participant before proceeding with informal review and confirming a reduction generated by the tool. The representative mattered because the right belonged to the participant while the capability needed to exercise it could be supplied by someone else.

That is the institutional form the right to verify will often take. Some people will run the proof themselves. Others will choose a specialist. Some will need a publicly funded advocate or a protocol-supported service whose duty runs to the person affected rather than to the institution that issued the claim. What matters is not solitary technical mastery. It is the availability of competent, independent assistance with access to the evidence while a remedy can still change the outcome.

A right in name leaves the burden where power placed it. A real right changes who must supply the means of contest.


The Claim and the Proof

Every proof has a material cost. It must be computed, communicated, interpreted, and sometimes translated into a form a court or ordinary person can use. That fact matters politically because money, time, bandwidth, and expertise are distributed unequally. It does not yet tell us what anyone is entitled to verify.

The first task is to identify the claim.

A computational decision commonly contains several propositions folded into one authoritative result. The system claims that it used a particular rule or model. It claims that the inputs attributed to the person were the inputs actually used. It claims that the computation executed correctly. It may also claim that the input data were accurate, that the category applied to the person meant what the institution says it meant, that the rule was authorized, and that the resulting consequence fell within the institution's lawful bounds. These propositions require different kinds of evidence.

A cryptographic proof may establish that a declared program, run on committed inputs, produced a declared output. That is a major achievement. It does not establish that the inputs described the right person, that the institution was entitled to use them, that the program embodied a lawful rule, or that the consequence attached to the output was proportionate. A source-code repository may establish what one version of a model contains without establishing that the deployed system used that version when it acted. A technical explanation may describe the model class while leaving the individual calculation unreproducible.

The constitutional object is therefore not the algorithm in the abstract. It is the material claim the institution made about this person, under this authority, with this consequence.

In Houston, the decisive proposition was not that value-added modeling exists or that student growth can be analyzed statistically. It was that this teacher received this score through a valid calculation and could therefore be treated as ineffective. General documentation about the methodology left that proposition untouched. In Idaho, exact reproduction of the budget arithmetic would still have been incomplete if the assessment data were wrong, the standards for additional need remained unstated, or the participant lacked any practical means of presenting contrary evidence.

A usable evidentiary object must preserve the distinctions that an authoritative score tends to erase. It should identify the operative rule or model version, the material inputs or commitments from which the result was derived, the steps or proof needed to test execution, the institution that supplied each disputed fact, and the authority by which the result acquired consequences. It should distinguish observation from inference and inference from the final act. A model may observe a payment pattern, infer risk, and trigger a freeze. Those are three different propositions, and the person may contest one without contesting the others.

This is why a receipt is more than an explanation and less than a remedy. It binds the institution to an account of what occurred before later convenience can replace that account with another. It may carry a succinct proof, a reproducible computation, a content-addressed model, an input lineage, or a pointer to evidence held under lawful confidentiality. Its adequacy depends on whether the propositions that matter can be tested, not on whether every internal state has been exposed.

Trade secrecy and privacy complicate the design without defeating it. A vendor need not publish a proprietary model to every competitor in order to permit independent testing of a specific result. A confidential expert can receive access under protective rules. A proof can certify a bounded relation without revealing all underlying data. A regulator or public verifier can retain the model and provide reproducible findings to the parties. The affected person may receive the features, categories, and operative reasons relevant to the decision without receiving the personal information of everyone in the training set.

The burden lies with the issuer to choose an architecture compatible with contest. An institution that selects a method too secret, too unstable, or too costly to test cannot convert those design choices into a disability imposed upon the person it governs. It may simplify the method, fund independent verification, limit the role of the result, or refrain from using it for a consequence the method cannot constitutionally support.

The right to run the proof is thus a right to adversarial reproducibility at the level of the claim. It does not require omniscience about the system. It requires enough common ground for disagreement to become evidence rather than supplication.


Who Must Run It?

The phrase right to run the proof can suggest an impossible republic of universal cryptographers, each citizen maintaining a full copy of every system, auditing every model, and refusing to act until personal verification is complete. No political order has ever demanded that citizens individually reproduce all the expertise upon which public life depends. We drink water without operating the laboratory, cross bridges without recalculating the loads, and accept audited accounts without reconstructing every transaction.

The constitutional question is not whether expertise may be delegated. It is whether the delegation remains answerable to the person whose standing depends upon it.

Direct verification is the strongest form where it is genuinely cheap. A wallet may check a signature locally, a browser may confirm that a credential was issued by the expected key, and an ordinary device may verify a succinct proof attached to a consequential state transition. The person need not ask the issuer whether the issuer acted correctly because the check can be performed at the edge, through software the issuer does not control.

Assisted verification is necessary where the claim exceeds ordinary technical capacity. The affected person chooses or receives an expert who can inspect the evidence, run the relevant tests, and explain the result in terms the person can use. The expert's duty must run to the affected person or to an independent public office, not to the institution whose claim is under review. Access to the model, data, and logs must follow the dispute rather than remain contingent on the issuer's permission.

Institutional verification sits between individual and state. Universities, civil-society laboratories, professional auditors, unions, consumer organizations, and specialist firms can maintain tools no individual could justify owning. Their work becomes constitutionally valuable when methods are public enough to reproduce, incentives make error costly, conflicts are disclosed, and another verifier can challenge the result. Consensus among three services proves little if all three consume the same corrupted feed or depend on the same vendor. Plural names do not create plural evidence.

Certificate Transparency offers a bounded technical model. Its public logs use Merkle proofs so clients, monitors, and auditors can test whether a TLS certificate was logged and whether the log's history remains consistent. The protocol is intended to make suspect issuance and log misbehavior detectable; it does not itself decide whether a certificate should have been issued or supply the owner of an affected domain with a remedy. Verification capacity is distributed because the common evidence object can be checked by actors other than the certificate authority. Judgment and enforcement remain institutional work.

Public provision supplies the floor when neither market nor personal resources will. A public defender is not a state-owned substitute for private judgment. The office exists because the adversarial system would otherwise distribute access according to wealth. Verification assistance can be funded in the same spirit through public appropriations, protocol levies, filing fees assessed to issuers, or common funds insulated from the institution being reviewed. The funding mechanism should not allow the issuer to select the verifier or punish an unfavorable result.

None of these arrangements eliminates trust. They change its object and make it defeasible. The person may trust a verification advocate because the advocate has a professional duty, access to the evidence, exposure to liability, and work that another expert can reproduce. That is different from trusting the institution to review itself through a process the institution alone can see.

The right is satisfied when the person can cause the relevant proof to be run by an accountable party without first securing the consent of the power being challenged. Sometimes that party is the person. Sometimes it is counsel for the claim.


Proof at the Edge

The engineering problem is to make the evidentiary burden smaller than the system that produced it. A person contesting one payment reversal should not have to reconstruct the entire payment network. A worker challenging one score should not have to reproduce every score ever issued. Constitutional access depends on designing claims that carry compact, testable evidence to the place where their consequences arrive.

Blockchain systems illustrate both the possibility and the danger of imprecision. A full node validates a large body of protocol history and current state. A light client verifies a narrower set of claims under additional assumptions. Bitcoin's simplified-payment-verification design allows a client to check that a transaction was included in a block by using block headers and a Merkle path, while relying on the security of the chain rather than independently validating every transaction. The check is useful because it answers a bounded question. It is not a miniature full node, and it should not be described as one.

Ethereum's light-client architecture similarly uses rotating sync committees to authenticate recent consensus headers without requiring the client to maintain or execute the whole chain. The reduction is substantial, but the trust model remains explicit. A light consensus client is not necessarily verifying every execution-layer state transition or the availability of every piece of data. Some implementations still depend upon remote procedure-call providers for the information through which users interact with the chain. Lightness moves assumptions around. Good design names them.

Succinct proofs create a more powerful asymmetry. The party performing an expensive computation can attach a small proof that another device checks much more cheaply. Zero-knowledge techniques can sometimes hide private inputs while proving that a declared relation holds. These properties are well suited to civic verification because they place more of the expense on the issuer of the consequential claim and less on the person required to answer it.

The proof remains bounded by its statement. It may certify that the committed program produced the output from the committed inputs. It does not certify that the program was fair, that the inputs were lawfully obtained, that the data were available to anyone entitled to challenge them, or that the institutional rule should have attached this consequence. A short proof of the wrong proposition is a compact form of irrelevance.

The design task is therefore to make each consequential decision carry the smallest evidence sufficient to test its material claims. The receipt can identify the exact model and rule version, bind the relevant inputs without exposing unrelated information, include the proof of execution, preserve the issuer and authority, and state which questions remain outside the proof. If the dispute concerns whether the person's income was recorded correctly, the verifier should not need to rerun the model to establish the input error. If execution is disputed, the model and committed inputs should permit reproduction or proof checking. If authority is disputed, the relevant rule and delegation must be available in a form a court can interpret.

This modularity matters because verification cost is partly a design choice. A monolithic system that emits one opaque answer forces every challenge to reopen the whole apparatus. A system that separates data, inference, rule, and consequence lets the person contest the disputed joint. The cheapest proof is often the one the architecture made unnecessary by preserving a simpler fact.

A constitutional system should follow one principle throughout: never require the governed to reconstruct the whole machine in order to challenge one act of power.


Before the Remedy Expires

Verification access is measured in time as well as money. A proof completed after a payroll has been missed, an election has passed, a license has expired, or a market position has been liquidated may improve the historical record while leaving the constitutional injury intact. The right to run the proof belongs inside the appeal window.

The operational test can be stated in one question:

Can the affected person, directly or through accountable assistance, test the material claim before the remedy becomes useless and at a cost proportionate to the consequence?

Each term does work. The affected person keeps the inquiry tied to standing rather than abstract transparency. The right concerns the claim by which an institution acted upon someone, not an unlimited entitlement to inspect every system. Directly or through accountable assistance recognizes that constitutional capability can be shared. The material claim narrows the object to propositions capable of changing the result. Before the remedy becomes useless joins verification to procedure. Proportionate cost prevents a nominal right from being priced beyond the interest it protects.

Median access is a valuable design diagnostic and an inadequate constitutional floor. A system usable by a person of ordinary means may still fail those with the least time, money, literacy, or technical confidence, who are often most exposed to administrative power. For severe deprivations, inability to pay should not bar contest. A person does not lose the right to answer a benefits reduction because the proof costs more than the benefit remaining in the account.

Proportionality also limits the burden placed on routine administration. Not every automated approval, routing decision, or internal calculation requires an elaborate constitutional dossier. The obligation grows with the severity and irreversibility of the consequence, the unilateral character of the act, the opacity of the method, and the weakness of alternative routes. An arrest, account freeze, professional suspension, or termination of subsistence benefits requires a richer and faster evidentiary object than a routine scheduling decision. A denied permit may require the operative rule, deficiency, and cure without requiring disclosure of an entire administrative system.

The issuer should ordinarily bear the first cost of making the claim testable. It chose the model, controlled the records, and attached the consequence. Requiring each affected person to purchase access to the issuer's evidence creates a toll on the exercise of a right. Costs can be pooled through filing charges, protocol fees, insurance, public funding, or loser-pays rules designed carefully enough not to chill legitimate challenges. What matters is that poverty not convert an adverse claim into an unreviewable one.

Opacity has costs too, though they are usually hidden in another budget. Vague decisions generate broad appeals, discovery fights, public-records requests, repeated phone calls, emergency litigation, and long queues in which simple input errors remain mixed with substantive disagreement. A precise receipt and a compact proof add friction at the act and can remove far greater friction afterward. The comparison is not between costly accountability and costless administration. It is between costs paid where the evidence still exists and costs paid after uncertainty has spread through the system.

Where an institution cannot make its claim accessible without destroying a legitimate secret, the law need not force indiscriminate publication. It can require confidential independent review, a zero-knowledge proof of the relevant relation, or a nonproprietary alternative. If none is possible, the institution must narrow what the claim is allowed to do. The burden of an inaccessible method belongs to the party that chose it.


When Proof Becomes a Profession

Verification will become specialized. The history of complex societies offers no plausible alternative. Few people personally assay their medicine, inspect an aircraft, audit a bank, or trace the provenance of every credential they accept. Expertise is not the enemy of republican freedom. Unanswerable expertise is.

The danger appears when the institutions capable of checking power depend upon the same systems, vendors, and data they are expected to test. A verifier funded by the issuer, trained on the issuer's documentation, and denied access to the relevant artifacts may be independent in name and captive in function. A public endpoint that returns an answer without a proof simply relocates the command. Multiple services that share one upstream provider reproduce one dependency behind several logos.

A healthy verification profession requires plural routes and common objects. The claim should be portable among verifiers. The method should produce artifacts another expert can reproduce. Public test vectors, stable schemas, content-addressed model versions, and preserved input commitments keep the dispute from dissolving into incompatible accounts. Where secrecy is necessary, at least one independent institution must possess the authority and technical capacity to inspect what the public cannot, with procedures allowing the affected person to challenge its work.

The profession also needs a duty. Lawyers owe loyalty to clients, auditors owe defined obligations to those who rely on their reports, and laboratories can be held responsible for negligent testing. Verification providers should answer for careless or dishonest conclusions. A bond may support that responsibility in some systems, professional liability in others, and public discipline elsewhere. Reputation alone is insufficient when the person harmed cannot afford to wait for the market to learn which verifier was unreliable.

Public provision and market competition should coexist. Publicly supported verifiers can ensure that no consequential claim becomes final because the person lacks money. Competitive providers can improve tools, specialize by domain, and expose disagreements that a single official office might suppress. Private operation remains available to anyone who wants deeper or continuous assurance. Redundancy matters because every provider, including a public one, can become a chokepoint.

The design should also carry an explicit complexity budget. Each new feature, model layer, data source, exception, and translation increases the work required to test the result. Product teams usually count latency, storage, and deployment cost while treating citizen-side verification as an externality. A constitutional architecture counts that cost from the beginning. It asks whether a new capability makes consequential claims harder to reproduce and who will pay the difference.

There will still be experts and laypersons, institutions and individuals, people who inspect every proof and people who rarely inspect one. Equality does not require identical technical practice. It requires that expertise remain available as a means of standing rather than becoming a title to rule.

The relevant question is not whether a profession emerges. It is whom the profession owes.


The Benevolent Black Box

The strongest objection comes from systems that work well. If an AI system reliably advances human interests, if predeployment testing is rigorous, and if operators monitor it responsibly, why build an elaborate right of verification around every consequential act? Much of the proposed machinery may appear to solve a problem that better alignment could prevent.

The concession should be given in full. Alignment, testing, monitoring, and competent regulation can reduce harm substantially. A narrow system operating in a stable domain may need little more than ordinary quality assurance. A thermostat that maintains the chosen temperature does not owe its occupants a constitutional hearing after each heating cycle. The right attaches where computational output becomes a consequential claim about a person, not wherever software runs.

Alignment and verification answer different questions. Alignment asks how a system is disposed to behave across the situations it encounters. Verification asks what happened in this case, through which rule and evidence, and whether the institution was entitled to make the result consequential. A system may be reliably helpful in general and wrong in a particular instance. It may be aligned with its principal while acting against the interests of someone the principal governs. It may remain locally correct while composing with other systems into an outcome no participant intended.

Consider a bank optimizing lending risk, an employer optimizing hiring, and an insurer optimizing claims. Each can act rationally under its own mandate. A credit denial enters the employment screen, the employment result enters the insurance model, and the person encounters a closed field no single system designed. Better local alignment may improve each decision without supplying an author for the composition. The evidence of interaction is what allows the resulting exclusion to be reconstructed and challenged.

Drift creates a second gap. Models, policies, populations, and institutions change. A system tested under one distribution may later operate under another. A vendor may update a model while the surrounding organization continues to rely on an older description. The right to verify binds the actual act to the version, inputs, and authority in force when the act occurred. Certification describes a system at an examination point. A receipt describes the system as it entered a particular life.

Central oversight remains essential. Regulators can set prohibited uses, require testing, inspect systemic patterns, and impose duties no individual challenge could create. Independent researchers can uncover harms invisible in one case. Courts can interpret authority and supply remedies. Distributed verification does not replace these institutions. It prevents them from becoming the only places where the truth of a computational claim can be known.

Stuart Russell's assistance framework treats uncertainty about human preferences as a feature of beneficial AI rather than a defect, allowing correction and deference to remain part of intelligent behavior. If systems achieve that sensitivity reliably, the number of harmful acts should fall. The constitutional position of the affected person remains distinct. Good behavior lowers the expected need to contest. It does not justify designing contest out of the relation.

The benevolent black box is still a black box at the adverse moment. The right to run the proof exists for that moment, when the system's confidence, the operator's assurance, and the person's lived evidence no longer agree.


Consequence

The Houston case reached no general constitutional right to source code, and it did not need one. Its insight was more exact. A public institution cannot make a high-stakes employment decision through a score that neither the affected teacher nor the institution itself has any meaningful way to test. Proprietary secrecy may remain. The untestable policy may not.

The Idaho litigation supplied the complementary point. Information alone did not create access for people who could not navigate a complex appeal without help. The state had to preserve standards, reasons, and a suitable representative capable of using them. A right can be exercised through another person without becoming another person's right.

Together the cases suggest the constitutional rule this chapter has been seeking:

No consequential computational claim should become final against a person unless its material basis can be independently tested, directly or through accountable assistance, before the opportunity for remedy expires.

The rule does not promise that every claimant will win. A teacher may receive a low score that proves correct. A benefits recipient may receive a budget reduction supported by accurate data and a lawful standard. A borrower may be denied credit after every input and calculation has been checked. Contestability protects the standing to answer power, not a preferred outcome.

Nor does the rule require one universal technical architecture. Some claims can be verified on a phone. Some require a confidential expert. Some require a public laboratory, a court-appointed specialist, or a professional advocate. Some methods will prove too opaque for the consequences institutions wish to attach to them. The diversity of mechanisms is compatible with one invariant: the issuer cannot be the only party capable of establishing that the issuer was right.

The right to run the proof places verification cost inside constitutional design. It asks who controls the evidence, who can afford the tools, how much time remains, which assumptions the check inherits, and whether a successful challenge can alter anything that matters. Cheap computation helps. It does not distribute standing by itself.

A constitution that only its governors can verify remains a parchment barrier, even when written in code. The next task is to write the charter so that the proof travels with the act.

Search the book

Use ↑ ↓ to move through results; Escape to close.

Search every published chapter, section and reference.

    In this chapter