AI Governance · Legitimacy · Institutional Design
The Gradient
How AI Replaces Human Judgment Without Anyone Deciding That It Should
Abstract
There will be no moment when a government announces that machines now make the decisions. There will be no vote, no treaty, no constitutional amendment. What will happen — what is already happening — is a gradient so smooth that no single step feels like the one that mattered. An assistant summarizes. A draft appears. A recommendation is generated. A human approves. The approval becomes routine, the routine automatic, the automatic invisible.
The absorption of human judgment follows a sequence that is consistent across every institution where it has begun, and the decisive step is the fourth: the human still signs, but can no longer independently evaluate what is being signed — the analysis too complex, the caseload too large, the reasoning too opaque. The signature remains human. The judgment does not. Every democracy is heading there, differing only in speed, in which branch arrives first, and in whether anyone builds the infrastructure to make the transition legitimate before citizens discover it has already happened.
This essay maps the five roads to that convergence — China by design, the United States through the private sector, the European Union in resistance, the United Kingdom by experiment, India by necessity — and argues that what results is not a technology problem but a legitimacy problem. Legitimacy under algorithmic governance requires the one thing no government can supply for itself: independent verification, by an institution that the governments it audits do not control. No such institution exists. Its analogues in finance, nuclear energy, and human rights were each built after the crisis that proved them necessary. The question is whether this one is built before.
I — The Seven Steps Nobody Voted For
An assistant summarizes. A draft appears. A recommendation is generated. A human approves. The approval becomes routine. The routine becomes automatic. The automatic becomes invisible. And one day a citizen asks who decided, and the answer is: no one, and everyone, and a system that was never formally given the authority it now functionally holds. This is not a prediction. It is a description of the present, extrapolated honestly.
The absorption of human judgment by artificial intelligence follows a sequence that is remarkably consistent across every institution where it has begun. The steps are not imposed. They are adopted, one reasonable efficiency gain at a time.
First, AI assists: it searches, summarizes, retrieves. The human does the thinking. This is where most institutions believe they are. Second, AI drafts: it produces the first version of a document, analysis, or recommendation. The human edits. This is where most institutions actually are, whether they admit it or not. Third, AI recommends: it presents a proposed decision with supporting analysis. The human approves. This feels like oversight, and for a time it is.
Fourth — and this is the step that matters — the human reviews but can no longer independently evaluate the recommendation. The analysis is too complex, the data too voluminous, the reasoning too opaque, or simply the caseload too large for the human to do anything other than trust the output. The signature is still human. The judgment is not.
Fifth, AI decides and the human is notified. This already exists in fraud detection, algorithmic trading, automated tax assessment, and content moderation at scale. Sixth, human oversight becomes structural and periodic — quarterly audits, annual reviews — rather than per-decision. The institution has become an AI system with a human governance wrapper. Seventh is the scenario people debate in conferences: fully autonomous AI governance. It is also the least important step, because by the time it arrives, the substance of the transition happened long ago, at Step 4, when the human stopped being able to say no on the basis of independent understanding.
Step 4 is where legitimacy dies in practice while surviving in law.
Every democracy on earth is heading there. They differ only in speed, in which branch of government arrives first, and in whether anyone builds the infrastructure to make it legitimate before citizens discover it has already happened.
II — Five Roads to the Same Place
The speed varies. The destination does not.
China arrives first, by design. The party-state model already treats governance as an optimization problem — automated surveillance, algorithmic resource allocation, and a patchwork of local and corporate scoring pilots that are considerably more fragmented than their Western reputation suggests. AI in executive function is not a disruption of the Chinese system; it is its logical completion. The party retains the override key, but daily governance of 1.4 billion people is increasingly performed by systems no individual official can meaningfully review. This model is the fastest and the most fragile. Algorithmic governance works until it compounds a systemic error at population scale, and the institution that would catch it — an independent judiciary, a free press, an external auditor — does not exist. The efficiency is real. The failure mode, when it arrives, will be catastrophic.
The United States arrives without noticing, through the private sector. Credit scoring determines who gets housing. Content moderation determines who gets speech. Insurance algorithms determine who gets healthcare. Hiring models determine who gets employment. None of these are government in the constitutional sense. All of them are governance in the functional sense — they allocate life chances at scale, algorithmically, with no public accountability framework, because the Constitution constrains the state, not corporations. The formal government remains human-operated and increasingly slow by comparison. The effective government — the one that touches a citizen's daily life — is substantially algorithmic, privately operated, and subject to no verification regime anyone designed. America's AI governance arrives not through a decision but through an absence: the absence of anyone asking who governs the governors.
The European Union arrives last, resisting every step. Every institutional antibody fires: data protection, the AI Act's high-risk classification, administrative-law traditions requiring human decision-makers, the precautionary principle, trade unions protecting civil-service employment, and a political culture that treats algorithmic governance as someone else's pathology. (Regulation (EU) 2024/1689) This slowness is genuinely costly, and the cost is now quantifiable. Europe holds on the order of five per cent of global AI compute, and its largest machine draws roughly 83 megawatts against 1,250 megawatts for the largest in the United States — a fifteen-fold gap in the physical substrate on which any augmented administration would have to run. (Compute capacity estimates, 2026) European public administration becomes progressively less capable relative to augmented administrations elsewhere. Permit backlogs, judicial delays, regulatory enforcement gaps — all widen. But the paradox is that resistance buys time, and time spent building governance infrastructure before deployment is the correct sequence, even when it feels like falling behind. Europe is the only bloc attempting to define what legitimate AI governance looks like before deploying AI in governance. That it does so slowly and imperfectly does not change the fact that it is the only one attempting it at all.
The United Kingdom experiments openly. Post-Brexit flexibility, common-law adaptability, and a centralized government make Britain the likeliest Western democracy to reach Step 5 in specific executive domains — tax, benefits, border control — within three years. The risk is the Dutch scenario at national scale. The Netherlands' childcare-benefits scandal — where an algorithmic fraud-detection system falsely accused and financially destroyed thousands of families — is the cautionary tale that should hang above every government AI deployment. (Dutch Parliamentary Inquiry, 2020–2021) It demonstrated that automated injustice compounds silently, surfaces late, and devastates people who have no recourse against a system that was never formally given the power it exercised. The UK has neither the EU's precautionary framework nor America's litigious culture to catch such errors early. It has the ombudsman, and the ombudsman does not scale.
India adopts by necessity rather than ambition. A case backlog exceeding 50 million, insufficient administrative capacity at every level, and a judiciary so overwhelmed that justice delayed has become justice in name only. (National Judicial Data Grid) India does not adopt AI governance because it believes in the technology. It adopts it because the human alternative has already failed. AI-assisted judicial triage, automated land-record verification, algorithmic tax enforcement — all arrive within years, driven by state incapacity. The governance quality may actually improve over the human baseline, because in contexts where the human baseline is corruption, delay, and dysfunction, algorithmic governance does not need to be good. It needs to be less bad. That is the truth the Western debate finds uncomfortable and the developing world finds obvious.
III — The Convergence
Every path leads to the same structural condition between now and the early 2030s: humans formally in the loop, functionally unable to override, signing outputs they can no longer independently evaluate. The fiction that a human decided will be maintained by every institution because the fiction is load-bearing — it carries the legitimacy that makes the decision enforceable. Remove the fiction without replacing it, and the institution collapses. Maintain the fiction after it becomes visibly false, and the institution collapses differently, through the slower poison of public contempt.
This is not a technology problem. It is a legitimacy problem, and it is the central political problem of the next decade.
The question is not whether AI will govern. It already does, partially, in every jurisdiction listed above. The question is whether the transition from partial to pervasive happens inside a framework that can make it legitimate — or outside one, discovered after the fact, with no mechanism for accountability, correction, or trust.
IV — What Legitimacy Requires
Legitimacy in a world of algorithmic governance requires one thing that no government can provide for itself: independent verification.
A government that deploys AI in its own operations and audits that AI with its own institutions is self-certifying. Self-certification has never been accepted as a basis for trust in any high-stakes domain — not in financial auditing, not in pharmaceutical safety, not in nuclear inspection, not in elections. There is no reason it should be accepted for the systems that decide tax liability, welfare eligibility, criminal sentencing, or regulatory enforcement.
A government that audits its own algorithms is not being audited. It is being described.
What is needed is an institution that can examine AI systems deployed in governance and certify — credibly, independently, to citizens and not only to the deploying authority — that the systems are lawful, unbiased within defined tolerances, transparent in their reasoning, and subject to meaningful human override when override matters. The institution must be independent of the governments it audits. It must be technically capable of examining systems that are, by design, too complex for any single human to evaluate. And its judgment must be trusted across jurisdictions, because AI governance will be cross-border long before AI governance frameworks are.
No such institution exists today. What exists instead is a demonstration of the gap, running in real time.
The mechanism the world currently relies on to govern who may hold advanced AI capability is export control — a licensing regime administered by a national bureaucracy, in the service of that nation's strategic interest. It is being asked to do a job it was never designed for, and the strain is visible from three directions. Enforcement is overstretched: the past year alone has produced roughly $420 million in chip-smuggling penalties, including an alleged $2.5 billion scheme to divert accelerators to China. (BIS enforcement actions, 2025–2026) The chokepoint, it turns out, leaks — and each leak is discovered after the fact, by a regulator, rather than prevented by a verification regime. Meanwhile the safeguards attached to the largest approved transfers are negotiated in private and recorded nowhere binding: in the landmark Gulf compute agreements, the security guardrails — the divestment of Chinese technology, the standing up of a "regulated technology environment" — were settled outside the rule text itself, which makes them commitments of trust rather than obligations subject to independent audit. And the politics have curdled predictably: senior legislators have alleged conflicts of interest in the approval process, an allegation whose merits are contested but whose existence is itself the point. A regime that cannot demonstrate its own integrity to its own legislature cannot supply legitimacy to anyone else.
This is what governance-by-bilateral-deal looks like: capability allocated by negotiation rather than by rule, safeguards resting on the good faith of the counterparty, enforcement arriving after the diversion, and no independent party in a position to verify any of it. Export controls have quietly changed function — from an instrument for denying capability to adversaries into an instrument for rewarding partners — and the shift has moved the world from a rules-based technology order toward a deal-based one. Deals do not scale into legitimacy. They cannot be audited by anyone outside the room, and the parties inside it have every incentive not to look too closely. The self-certification problem in AI governance is not a theoretical objection to a future arrangement. It is the present arrangement.
Its closest analogues are the institutions that have historically performed exactly this function in other domains: independent bodies, internationally governed, trusted precisely because no single party controls them. The financial system has its auditors and its Basel standards. Nuclear energy has the IAEA. Human rights have the courts in Strasbourg and San José. Each of these emerged not from foresight but from crisis — the crisis that made the need undeniable and the institution inevitable. The question for the AI transition is whether the institution can be built before the crisis or only after. The pattern of history is not encouraging. But the pattern of history also never had the advantage of seeing the gradient this clearly in advance.
V — The Economics of Verification
The objection to independent verification is always the same: who pays?
The answer may be the parties who need it most and know it — even if they would never say so publicly.
The large model providers — the companies whose systems will increasingly power governmental and institutional AI — face an existential reputational risk they cannot manage alone. The first time a frontier model produces a catastrophically wrong output inside a government system — a wrongful mass denial of benefits, a discriminatory sentencing pattern, a failed public-health triage — the political backlash lands on the model provider as much as on the deploying government. The provider will say: we sold a general-purpose tool; the government deployed it irresponsibly. The public will not care about the distinction. The brand damage will be existential.
Independent verification is, for the model provider, an insurance policy. A system that has been certified by an institution the public trusts transfers liability from the provider to the framework. The provider's rational incentive is not to resist verification but to fund it — the same way the financial industry funds its own auditing infrastructure, not out of virtue but out of the recognition that the alternative is unlimited, uninsurable reputational exposure.
The mechanism is straightforward: a fraction of inference revenue — a basis-point levy on API calls used in high-stakes institutional contexts — flows to the verification institution as a condition of the institution's certification. The levy is small enough to be commercially negligible and large enough, at the scale of frontier AI revenue, to fund a serious institution. Providers who submit to certification gain a trust mark that governments can require in procurement; providers who decline bear the full reputational risk of uncertified deployment. The market sorts itself.
This is not hypothetical economics. It is the model that funds every serious standard-setting and certification body in the world — from ISO to the PCAOB to ICANN. The regulated fund the regulator because the regulation protects the regulated. The same logic applies, and the providers sophisticated enough to see the liability curve are sophisticated enough to see the hedge.
— The Timeline That Matters
The gradient will not pause while institutions are designed. Step 4 — the rubber stamp that still carries a human signature — is arriving in executive agencies across every advanced economy within three years. In judicial systems, it is arriving through AI-drafted briefs, AI-assisted research, and AI-recommended outcomes that judges adopt at rates indistinguishable from the system's own output. In legislative processes, it is arriving through AI-drafted regulatory text, AI-generated impact assessments, and AI-produced consultation analysis.
None of these will be announced. All of them will be discovered — by journalists, by litigants, by citizens who notice that the "human decision" affecting their life was produced in a format no human types in and at a speed no human works at.
The window between now and that discovery is the window for building the verification institution. It is not a long window. The gradient is smooth, but it is not slow.
The institutions that have historically performed this role — the independent auditors, the international inspectorates, the neutral verifiers — were all built after the crisis that proved they were necessary. The childcare-benefits scandal, the wrongful convictions, the discriminatory credit denials, the welfare deaths — each of these was, in retrospect, the signal that should have prompted the institution before the damage. Each time, the institution came after.
This time, the gradient is visible. The destination is legible. The institution is describable. The only question is whether it is built in the years before the crisis or in the wreckage after.
This essay describes the problem. The institutional response — where such a verification body might be domiciled, how it might be governed, and what its first applications would be — is explored in The Trust Layer: What Europe Should Build Instead of a Frontier Lab. The views expressed are the analytical position of the author in a personal capacity and do not constitute investment, legal, or policy advice.
Sources
- 1. Regulation (EU) 2024/1689 (the Artificial Intelligence Act), on high-risk classification and human-oversight obligations.
- 2. Dutch Parliamentary Inquiry into the childcare benefits scandal (toeslagenaffaire), 2020–2021.
- 3. National Judicial Data Grid (India), on pending-case volumes across Indian courts.
- 4. Bureau of Industry and Security (US Department of Commerce), export-control enforcement actions and penalties, 2025–2026; reporting on the security conditions attached to Gulf compute agreements.
- 5. Comparative estimates of global AI compute capacity and national supercomputer power draw, 2026.
- 6. International Atomic Energy Agency, safeguards and inspection framework, as an analogue for independent cross-border verification.
- 7. Basel Committee on Banking Supervision, and the Public Company Accounting Oversight Board (PCAOB), on industry-funded independent oversight.