An institutional governance chamber with a transparent decision apparatus and human reviewers

Dossier / 002 · Evidence dossier · public research edition

Who Governs the Machine?

Authority, accountability and institutional control when artificial intelligence begins to act.
Authority · evidence · intervention · recourseSeptember 2026 · Version 1.0
Publication stateReleased public dossier
Institutional authorNataraja Labs Research Foundation
GeographyIndia in comparative institutional context
Evidence cut-off2 September 2026
Claim boundaryComparative public-source analysis. The institutional anatomies are illustrative operating contexts, not representations of named deployments.

Executive reading

The machine does not govern alone. It governs through an institution that has chosen where to place it.

Artificial intelligence becomes an institutional question when its output enters a chain of authority: deciding what receives attention, what is classified as risk, which action is recommended, what is executed and how an affected person may challenge the result. This dossier reconstructs the governance architecture around that chain. It examines public rules and operating frameworks across India and selected international jurisdictions, then applies the evidence to three institutional anatomies: an industrial enterprise, a public administration and a regulated authority.

Governance begins before deployment: at the moment an institution defines what the system may perceive, recommend, communicate and do.

Chapter I / Finding register

What the institutional record establishes.

Each conclusion declares whether it is documented, inferred from documented mechanisms or unresolved in this edition.
F/01Strong inference

Authority may be delegated. Responsibility cannot be automated away.

Across the examined frameworks, responsibility remains attributable to people or legal entities even when an AI system supplies the recommendation, ranking, prediction or action pathway.

OECD accountability principle; UNESCO Recommendation; EU AI Act; Council of Europe Framework Convention; RBI FREE-AI report.
F/02Documented

A human in the loop is not, by itself, meaningful oversight.

Effective oversight requires competence, information, time and authority to disregard, reverse or stop the system. A nominal approver who cannot interrogate or interrupt the system is an accountability ornament.

EU AI Act Article 14; Canada Directive on Automated Decision-Making; UNESCO judicial guidance.
F/03Strong inference

The consequential object is the decision system, not the model alone.

Risk emerges from the relationship among mandate, data, model, interface, workflow, operator, affected population, vendor and remedy. Model accuracy cannot establish institutional legitimacy by itself.

NIST AI RMF; India AI Governance Guidelines; EU fundamental-rights impact assessment; Canadian Algorithmic Impact Assessment.
F/04Documented

Inventories and public records are becoming governance infrastructure.

Multiple governments now require or maintain AI use-case inventories, algorithmic transparency records or published impact assessments so that systems can be located before they can be scrutinised.

UK Algorithmic Transparency Recording Standard; Canada Directive; U.S. OMB M-25-21.
F/05Strong inference

Recourse is part of system design.

Notice, explanation, complaint, appeal and correction cannot be bolted on after deployment. They determine what records must exist, which human remains answerable and whether the institution can reverse an adverse outcome.

Canada Directive; Council of Europe Framework Convention; OECD transparency principle; EU AI Act.
F/06Documented

Procurement determines whether an institution can remain sovereign over its own system.

Current public procurement guidance treats portability, data rights, documentation, testing, subcontractor visibility, licensing and continuity as material AI controls rather than commercial afterthoughts.

U.S. OMB M-25-22; RBI FREE-AI third-party-risk analysis; NIST AI RMF.
F/07Strong inference

Autonomy changes the required containment architecture.

When a system can call tools, communicate, alter records or initiate transactions, governance must move from reviewing outputs to constraining permissions, sequencing approvals, preserving logs and containing incidents.

RBI FREE-AI discussion of autonomous agents and prompt injection; OECD override and decommissioning principle; NIST lifecycle governance.
F/08Strong inference

India’s emerging architecture is layered and institution-building.

The examined Indian record combines data-protection law, national governance guidelines, proposed coordination and safety institutions, voluntary risk mechanisms and sector-specific supervisory frameworks rather than a single horizontal AI statute.

DPDP Act and Rules; India AI Governance Guidelines 2025; PSA techno-legal white paper 2026; RBI FREE-AI report.

Confidence language

The dossier separates the rule, the inference and the unknown.

Documented

Directly supported by a cited law, treaty, official policy, standard, report or public administrative record.

Strong inference

Foundation analysis joining multiple documented mechanisms into an institutional conclusion.

Open question

Material to governance but not answerable from the public evidence examined for this edition.

A public algorithmic record hall with transparent archives, provenance maps and reading tables

Plate I / Public legibility

An institution cannot govern what it has not first made locatable.

Inventory · ownership · purpose · revision · evidence · public record
The visible machine

Inventories, impact assessments and transparency records turn invisible systems into objects of supervision.

Chapter II / Authority stack

Ten layers between purpose and termination.

The model is only one layer. Institutional control depends on the full route through which authority is granted, evidenced, challenged and withdrawn.
01

Mandate

What lawful or organisational purpose permits the system to exist?

Named institutional owner and bounded purpose.
02

Classification

What changes if the system is wrong, manipulated or unavailable?

Context-specific impact tier and prohibited uses.
03

Acquisition

What control is surrendered to providers, platforms and subcontractors?

Portability, data rights, testing access and exit terms.
04

Data

Which records shape the system and who may use them?

Provenance, lawful basis, quality, retention and access control.
05

Model & tools

What may the system infer, retrieve, communicate or execute?

Approved models, connected tools and permission boundaries.
06

Human authority

Who may accept, reject, suspend or reverse an output?

Competent officials with time, information and real authority.
07

Evidence

Can the institution reconstruct what happened?

Versioned prompts, inputs, outputs, actions, approvals and exceptions.
08

Monitoring

How will drift, bias, misuse and control failure become visible?

Operational metrics, testing, incident thresholds and review cadence.
09

Recourse

How can an affected person understand and challenge the result?

Notice, explanation, complaint, appeal and correction pathway.
10

Termination

Can the institution stop the system and continue its mission?

Kill switch, fall-back process, continuity record and vendor exit.

Comparative institutional record

Different jurisdictions regulate different points in the chain.

No single instrument resolves the problem. Together they reveal a recurring architecture: classify impact, assign ownership, preserve records, empower oversight and provide recourse.

R/01
India

AI Governance Guidelines

Guidelines / institution-building

Risk-based, light-touch governance; proposed AI Governance Group, AI Safety Institute, incident reporting, accountability and techno-legal mechanisms.
R/02
India · finance

RBI FREE-AI Committee Report

Sectoral recommendations

Board policy, lifecycle governance, product approval, audits, consumer disclosure, incident reporting and third-party controls.
R/03
European Union

AI Act

Binding regulation · phased application

Risk categories, provider and deployer duties, human oversight, logging, registration and fundamental-rights impact assessment.
R/04
Canada

Directive on Automated Decision-Making

Binding federal administrative policy

Published impact assessment, notice, explanation, peer review, testing, human intervention and recourse calibrated by impact level.
R/05
United Kingdom

Algorithmic Transparency Recording Standard

Mandatory across central government scope

Public records explaining how and why algorithmic tools support decisions, including responsible ownership and supplier information.
R/06
United States · federal

OMB M-25-21 and M-25-22

Binding executive-branch memoranda

Agency governance, use-case inventories, high-impact controls, acquisition testing, portability, data rights and protection against vendor lock-in.
R/07
International

Council of Europe Framework Convention

Treaty opened for signature

Human rights, democracy and rule-of-law duties; impact assessment, procedural safeguards, complaint and remedy.

Chapter III / Institutional anatomies

The same model changes meaning when it approaches a different kind of power.

These are bounded analytic scenarios built from the public frameworks—not claims about named clients, agencies or deployments.
An industrial operations room coordinating maintenance, procurement and inventory under human approval

A/01 · Industrial enterprise

The agent inside the operating core.

An AI agent coordinates procurement, maintenance and inventory across plants, suppliers and enterprise systems.

It may prioritise work, draft purchase actions, contact teams and recommend or execute bounded transactions.

  • Unsafe maintenance deferral
  • Inventory distortion
  • Unauthorised commitment
  • Supplier manipulation
  • Cascading operational outage
  • Segregated tool permissions
  • Financial and safety approval thresholds
  • Machine-readable operating policy
  • Action and override logs
  • Manual operating continuity
Can the enterprise reconstruct, interrupt and continue the process when the agent or its provider fails?
A public administration hall where applications enter triage, review and appeal pathways

A/02 · Public administration

The queue before the right.

An automated system triages applications for benefits or public services and directs cases toward approval, review or investigation.

Even where an official signs the final decision, ranking and triage can determine delay, scrutiny and practical access.

  • Invisible exclusion
  • Proxy discrimination
  • Unreviewed automation bias
  • Unintelligible denial
  • No effective path to correction
  • Published impact assessment
  • Notice of automated assistance
  • Meaningful case explanation
  • Human review with reversal authority
  • Accessible appeal and error correction
Can the affected person discover the system’s role and obtain a timely human reconsideration?
A regulated authority evidence chamber with provenance controls and paired human review

A/03 · Regulated authority

The machine near the coercive edge.

AI assists investigation, supervision, enforcement triage or risk prioritisation within an authority that can impose legal or economic consequences.

The system may not issue the order, yet it can determine who is seen, what appears suspicious and which evidence receives institutional attention.

  • Biased investigative attention
  • Opaque evidentiary chain
  • Automation-driven escalation
  • Vendor influence over public judgement
  • Inability to disclose or contest
  • Lawful-purpose boundary
  • Evidentiary provenance
  • Independent validation
  • Two-person or senior review for coercive action
  • Disclosure, complaint and external supervision
Can the authority defend the path from signal to state action before an independent forum?

Chapter IV / Operating constitution

Eight domains of institutional control.

The control system must survive model change, staff turnover, vendor exit and the first serious incident.
C/01

Purpose

Name the decision or action the system may influence—and those it may not.

C/02

Ownership

Assign a senior mission owner, technical owner, data owner and independent assurance function.

C/03

Permission

Treat tool access, communications and transaction rights as institutional authority.

C/04

Evidence

Preserve enough of the operating record to reconstruct consequential outputs and actions.

C/05

Intervention

Specify who can pause, override, reverse and decommission the system, and under what signal.

C/06

Recourse

Design notice, explanation, complaint and correction before the first affected decision.

C/07

Continuity

Maintain portable records, fall-back procedures and contractual rights to survive provider failure or exit.

C/08

Supervision

Create review beyond the delivery team: audit, legal review, regulator, court or public scrutiny as context requires.

A procurement and continuity archive displaying portable compute, records, interfaces and parallel replacement systems
Plate II / Institutional continuity

The right to understand, transfer and continue a system is part of the right to govern it.

The contract as control surface

Procurement writes the institution’s future room to manoeuvre.

These clauses are an analytical control register, not legal drafting for a specific transaction. Their exact form depends on governing law, sector, deployment and bargaining position.

  1. P/01

    System boundary

    Exact models, data sources, tools, environments, subprocessors and permitted changes.

  2. P/02

    Evaluation rights

    Access needed to test performance, security, bias, failure modes and context-specific limitations.

  3. P/03

    Operational evidence

    Logs, version records, incident information, known limitations and material-change notification.

  4. P/04

    Data and training

    Ownership, lawful use, retention, model-training restrictions, deletion and derivative-data treatment.

  5. P/05

    Portability

    Export formats, documentation, interfaces, knowledge transfer and transition assistance.

  6. P/06

    Continuity

    Service failure, provider exit, subcontractor change, escrow or replacement and manual fallback.

  7. P/07

    Liability

    Responsibility for unauthorised action, security failure, infringement, non-compliance and remediation.

  8. P/08

    Termination

    Institutional power to suspend unsafe use and terminate without losing mission records or operating control.

Chapter V / India

An architecture is emerging. Its operating proof must still be built.

The record below distinguishes notified law, published guidance, sectoral recommendations and evidence gaps.
I/01Documented

A national governance architecture is now explicit.

The 2025 India AI Governance Guidelines describe a risk-based, light-touch and techno-legal approach, including proposed coordination, safety, incident and accountability mechanisms.

I/02Strong inference

Data protection is necessary but not sufficient.

The DPDP framework governs digital personal data. It does not by itself answer who may delegate a public or corporate decision, what evidence must be preserved or how an AI-assisted outcome may be appealed.

I/03Documented

Sectoral institutions may move first.

RBI’s FREE-AI report translates general principles into board policy, product approval, lifecycle controls, audits, consumer communication, incident reporting and third-party governance for financial entities.

I/04Open question

Public-sector operating evidence remains thin.

The examined record does not establish a single mandatory public inventory of AI systems, a cross-government impact-assessment regime or a uniform recourse standard comparable to the Canadian and UK mechanisms.

An AI incident control centre where human supervisors isolate permissions and switch to a manual fallback

Plate III / The right to interrupt

The institution remains sovereign only if it can stop the machine and continue the mission.

Observe · isolate · override · reconstruct · correct · resume
Incident and continuity

A kill switch without a viable fall-back process stops the system—and may also stop the institution.

Research frontier

What the public record must answer next.

The next stage is not another general statement of principles. It is an empirical account of where systems are operating, what authority they possess and whether institutions can still explain, interrupt and correct them.

  1. Q/01

    Which Indian public institutions currently use AI to rank, triage, investigate, allocate or deny—and where is that use publicly recorded?

  2. Q/02

    What threshold should convert an ordinary automation project into a high-impact institutional system?

  3. Q/03

    Who is the legally and operationally accountable owner when a provider, integrator, model developer and deploying institution share the chain?

  4. Q/04

    What minimum operating record is necessary for audit, judicial review and affected-person recourse without exposing protected data or security controls?

  5. Q/05

    Which classes of autonomous action require dual control, prior approval or categorical prohibition?

  6. Q/06

    How should institutions test systems whose behaviour changes through model updates, retrieval sources, tools or agent-to-agent interaction?

  7. Q/07

    What continuity rights should be non-negotiable when an AI system becomes embedded in public or critical operations?

  8. Q/08

    Which supervisory institution can evaluate both technical performance and the legality of the institutional purpose?

Chapter VI / Method & limitations

A comparative reconstruction of institutional control.

This edition examines laws, treaties, official policy memoranda, regulatory reports, administrative directives, public transparency standards and technical risk-management frameworks current to the stated evidence cut-off.

It does not provide legal advice, determine compliance in a named jurisdiction or evaluate a deployed system. The three institutional anatomies are illustrative contexts used to test how authority, evidence, intervention and recourse change across domains.

Binding law, administrative policy, voluntary standards and Foundation analysis are not treated as equivalent. The source register states institutional provenance; the finding register distinguishes documented mechanisms from comparative inference.

Source register

The rule should remain reachable.

Official Indian records anchor the national reading. Comparative primary sources reveal the mechanisms already operating elsewhere.
R/01Office of the Principal Scientific Adviser, Government of India

India AI Governance Guidelines

India’s national risk-based governance architecture, proposed institutions, accountability mechanisms and techno-legal approach.

2025
R/02Office of the Principal Scientific Adviser, Government of India

Strengthening AI Governance Through a Techno-Legal Framework

Official publication record and current policy work on technical mechanisms supporting AI governance.

2026
R/03Reserve Bank of India

FREE-AI Committee Report

Sectoral analysis of AI governance, autonomous agents, third-party risk, consumer protection, board policy, assurance and incident reporting.

2025
R/04Ministry of Electronics and Information Technology

Digital Personal Data Protection Rules 2025

India’s notified implementation framework for the Digital Personal Data Protection Act, including its phased commencement.

2025
R/05NITI Aayog

Operationalizing Principles for Responsible AI

Indian institutional proposals for translating responsible-AI principles into lifecycle practice and enforcement mechanisms.

2021
R/06National Institute of Standards and Technology

Artificial Intelligence Risk Management Framework 1.0

Lifecycle framework for governing, mapping, measuring and managing AI risks within organisational practice.

2023
R/07Organisation for Economic Co-operation and Development

Recommendation of the Council on Artificial Intelligence

International principles for transparency, explainability, robustness, traceability and accountability across the AI lifecycle.

2019 · updated 2024
R/08European Union

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Binding risk-based duties covering providers and deployers, including human oversight, logging and impact assessment.

2024 · consolidated 2026
R/09Treasury Board of Canada Secretariat

Directive on Automated Decision-Making

Operational public-administration regime for impact assessment, notice, explanation, peer review, human intervention and recourse.

2019 · amended 2025
R/10Government Digital Service, United Kingdom

Algorithmic Transparency Recording Standard Hub

Mandatory central-government transparency standard and public repository for algorithm-assisted decisions.

2023 · updated 2025
R/11Council of Europe

Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law

Treaty framework for accountability, impact assessment, procedural safeguards, complaint and remedy.

2024
R/12UNESCO

Guidelines for the Use of AI Systems in Courts and Tribunals

Judicial context for assistive use, human supervision, transparency, accountability and rights protection.

2025
R/13United States Office of Management and Budget

M-25-21 — Accelerating Federal Use of AI through Innovation, Governance, and Public Trust

Current federal agency governance, use-case inventory and high-impact AI requirements; replaces M-24-10.

2025
R/14United States Office of Management and Budget

M-25-22 — Driving Efficient Acquisition of Artificial Intelligence in Government

Public procurement controls for testing, data and IP rights, documentation, portability, competition, subcontractors and vendor exit.

2025

Nataraja Labs
Research Foundation

Dossier / 002 · 1.0

The machine is governed where authority can still be named.

Nataraja Labs Research Foundation (2026), Who Governs the Machine?, Dossier 002, version 1.0. First released 2 September 2026. First public edition. Corrections and substantive evidence are invited at contact@natarajalabs.org.

Download citable PDF Read Transaction 001 Return to editions