Runtime Rights · A standard for automated decisions

A standard for automated decisions

A Bill of
Runtime Rights

Ten articles governing the authority behind machine-initiated actions. Not what a machine may be capable of. Who said it could.

Free to reproduce, adapt, quote, and legislate. No permission required, no attribution required, nothing here is proprietary.

Nothing in this document is new.

Every article is a protection you already hold somewhere else, restated for a situation the old language did not anticipate: an action that arrives with no actor attached to it.

When a person does something to you, you can ask who they are, why they did it, who sent them, and what it will take to undo it. You hold every one of those when a person acts on you. You lose nearly all of them the moment a machine acts on you instead.

Note what is absent below. No restriction on what a system may be capable of, no cap on speed, no license required to build, no technology named as forbidden. Not one line slows a machine down. Every article governs the authority behind the action, which is a human question and always was.

The instrument

Ten articles

The Authorizing Party

Every consequential action taken by a machine has a party who authorized it, named before the action, not assembled after it.

Somebody said yes. The purpose of this article is to make that somebody findable at the moment of the action rather than reconstructed weeks later under pressure from a lawyer. The test is simple and it is a timing test: did the name exist before, or was it produced after the complaint? Attribution assembled after the fact is not authorization, it is blame allocation, and the two get confused constantly. A system that cannot name its authorizing party at the moment it acts is not a system with a paperwork gap. It is a system that was never authorized.

A Reason at the Speed of the Decision

A decision made in a second carries a reason available in a second.

This is deliberately a lower bar than full explanation of how a model reached its conclusion, and a much firmer one. What is owed is the operative reason, in language a person can read, at the time the thing happens. Not a disclosure process with a ninety day clock. Not a portal. A reason delivered after the consequence has landed is a history, not a reason, and it arrives too late to be used for the only purpose reasons serve, which is deciding whether to fight.

Reversal Proportional to Speed

A system that can act in a millisecond can undo in a minute. The speed of execution sets the standard for the speed of remedy.

Due process has always been a clock. The old gates had delay built into their physical nature: papers moved, offices closed, someone had to sign. That delay was not the point, but it was a window, and people used it. Automation removed the delay from the action and left it sitting in the appeal, which is precisely backwards. If the system can take your money instantly, the burden falls on the system to return it at comparable speed. Institutions asking for months to reverse what they did in a moment are describing their own architecture, not a law of nature.

Non-Inheritance of Consent

Permission does not travel. Consent given to one party for one purpose does not pass to the next actor in the chain unless it is given again.

Machines now commission other machines, which commission others. You agreed to one thing, with one party, for one reason. Four steps down that chain your permission is being cited by something you have never heard of, for a purpose you were never told about. Delegation is not a copying device for consent. This article also closes the older leak: an access grant written for one employee in one job does not silently become a grant for ten thousand automated agents because nobody ever revoked it. Permissions expire by default or they are not permissions, they are inheritance.

A Human on Request, Not on Appeal

The right to reach a person exists at the moment of the decision, not after the machine has been exhausted.

Nearly every automated system now treats the human being as a prize for persistence. Push through enough menus, wait long enough, escalate often enough, and eventually a person appears. Persistence is not evenly distributed. The people most damaged by an automated decision are usually the people with the least capacity to spend six weeks fighting it. The woman on the third round of treatment. The father working two jobs. The daughter on hold at two in the morning with a sleeping parent in the next room, who has already been transferred four times and who will hang up, because she has to be up at six, and the machine will record that as resolved. Placing the human at the end of the process is a design decision that quietly sorts by stamina. Move the human to the front and it stops sorting.

The Record

Every consequential machine action leaves a record that cannot be silently altered, and the person affected can read it.

Both halves carry weight. A record that can be quietly edited after an incident is worse than no record, because it manufactures confidence. And a record that only the operator and its auditors may read is not a record, it is a defense file. The person on the receiving end of the action is the one party with an absolute interest in its accuracy, and is usually the only party excluded from seeing it. Tamper evident, and legible to the person it was done to. Anything less is bookkeeping.

Dormant by Default

Identity and capability stay off until an authorized event turns them on, and turn themselves off when that event ends.

The quiet catastrophe of the last decade was not malice. It was persistence: things left on. Credentials, sessions, access, connections, and capabilities that were needed once and never withdrawn, sitting live for years because no process exists whose job is turning things off. The alternative to always on is not secrecy. It is a scope and a clock. Nothing should be live merely because it was once useful, and nothing should stay live merely because switching it off would require someone to notice.

Fail Closed

In the absence of established authority, the answer is no.

This is the elevator's pawls written as law, and it is the whole book compressed into one line. Every other article here can be argued over, phased in, scoped, and negotiated. This one is a single bit, and it is currently set wrong almost everywhere. Today, when a system cannot establish whether an action is permitted, it proceeds, because proceeding is what it was measured on and hesitation looks like failure on a dashboard. Reverse the bit. The cost of a wrong no is usually a delay and an annoyed user. The cost of a wrong yes is the rest of this book.

Usually, and the exception belongs here rather than in a footnote, because the sharpest critics of this article will arrive from medicine and emergency response, and on the narrow point they will be right. There are settings where a wrong no also injures and kills: the dispatch queue, the crash cart, the operator with ninety seconds to act. Fail closed does not mean those systems freeze while permission is located. It means something narrower and much harder to evade: in the absence of established authority, a system may not invent its own permission and proceed silently. Emergency authority is still authority. The paramedic who breaks your window is exercising a power that was named, bounded, trained for, and recorded long before the accident, and that is the design being asked for, not the exception to it. Emergency paths, continuity paths, and preauthorized overrides can and should exist. They are granted in advance by a party with a name, scoped to the condition that activates them, and they leave a record that can be examined afterward. What this article forbids is not acting under pressure. It is manufacturing permission out of momentum and calling the silence consent.

Standing to Contest

A person affected by an automated action is a party to it, with standing to contest it before someone who can overturn it.

Courts require a defendant. Complaint systems require a category. Between those two facts sits an enormous and growing population of people who were processed by something, harmed by it, and are not recognized as participants in it. They can file feedback. They cannot file suit. Standing is the difference between a complaint and a case, and it is the difference between a customer service function and a right. A forum that can log your objection but cannot reverse the decision is not a forum. It is a comment box with better branding.

Disclosure of the Principal

Anyone dealing with a machine acting for someone else may know whose behalf it acts on.

The agent in front of you is fluent, tireless, unfailingly pleasant, and working for somebody who is not you. Old law understood this hazard long before software: an agent who conceals the party they represent is running an undisclosed agency, and the law has never liked it. The negotiating system, the pricing system, the scheduling system, and the system that just called your mother all serve an interest. Naming that interest costs nothing and changes how a reasonable person responds. Concealing it is the entire value of concealing it.

How to move it

Three forms,
smallest to largest

Download all three on one page

Standards become real when somebody adopts one, and adoption almost never begins in a legislature. It begins with a board that puts a question to a vendor, a purchasing officer who adds a clause, a council member who reads a paragraph into a record.

For any board or committee

The five questions

Put these to any vendor of any automated system, today, with no policy change and no budget.

  1. What action can this take without a human?
  2. Who is the named party who authorized that?
  3. What reason does the person affected receive, and how fast?
  4. How is it reversed, and how long does that take compared to how long the action took?
  5. Who may contest it, and where do they go?

A vendor who cannot answer all five has told you something. The answers belong in the minutes.

For purchasing

The procurement clause

The fastest lever available. It needs no legislation, and every institution already owns the machinery. Adapt to your counsel's judgment.

The vendor shall identify, for each automated action, the party that authorized it; shall provide the affected person a reason in the same interval in which the action occurred; shall provide a reversal path proportional to the speed of the action; and shall maintain a record sufficient to reconstruct the decision. Absent established authority for a given action, the system shall not proceed.

For a governing body

The resolution

One paragraph, adopted by vote and entered into the record. It commits a body to a standard and creates a public artifact.

Resolved, that this body adopts the Runtime Rights as its standard for automated decisions affecting the people it serves, and directs that systems procured or operated under its authority be evaluated against them.

The register

Who has adopted it

A list of institutions that adopted a standard before anyone required them to is the most persuasive document in this fight. It does not exist yet.

If your organization puts the five questions to a vendor, adds the clause to a contract, or passes the resolution, say so. Organizations only, no individuals, no email list, nothing sold.

Being first costs nothing and is worth more than being tenth. The first name on this list is the one every later one points at.

Adopting organizations

The register opens with the first entry

Tell us you adopted it

Include the organization, the form adopted, and the date. Entries are added to the list above and shown exactly as submitted.

Runtime Rights

The articles first appeared in The Third Voice: Who Decides What the Machines May Do to You by Emily Hartstone. The book.

Reproduce it, adapt it, put it into procurement language, read it into a record, translate it, improve it. Attribution appreciated and not required. A standard nobody may copy is neither nameable nor reachable.