flowchart LR
J["Jurisdiction, mandate, affected publics, and standing"] --> P["Participation, evidence, law, and standards"]
P --> C["Coordination instrument with duties and verification"]
C --> V["Independent-enough access, monitoring, and dispute process"]
V --> E{"Compliance, capacity, and legitimacy conditions hold?"}
E -- "no" --> R["Remedy, escalation, renegotiation, suspension, or exit"]
E -- "yes" --> O["Bounded institutional authorization"]
O --> A["Audit enforcement, distribution, and public outcomes"]
A -. "expiry, conflict, or capture" .-> J
R --> S["Publish unresolved conflicts and remedy status"]
S --> Q{"Accountable authority restored?"}
Q -- "yes" --> J
16 Institutions, International Coordination, and Public Legitimacy
16.1 Chapter status
| Field | Value |
|---|---|
| Chapter ID | institutions-international-coordination-and-public-legitimacy |
| Part | Part I - Foundations, Alignment, and Governance |
| Status | conceptual |
| Manuscript maturity | v0.4 concept-complete manuscript with bounded Lean refinement |
| Last updated | 2026-08-01 |
| Claim label | Design rationale |
| Evidence level | argument |
| Source loading state | source notes: coherence_exchange, ext_un_global_digital_compact_2024, ext_council_europe_ai_convention_2024, ext_flexible_hardware_enabled_guarantees_2025, ext_legal_alignment_2026, ext_eu_article_50_transparency_guidelines_2026, ext_oecd_ai_infrastructure_competition_2025, ext_eu_ai_civil_liability_2025, ext_icrc_autonomous_weapons_ihl_2025; connector/recovery: coherence_exchange |
| Test state | The chapter defines a minimum implementation and falsification plan; no chapter-core promotion follows from prose or source synthesis. |
16.2 Drafting guardrail
This chapter owns institutional authority, coordination, enforcement, and remedy across jurisdictions and affected publics. It does not infer legitimacy from a signed agreement, legal text, technical conformance, expert review, stakeholder consultation, or a functioning coordination mechanism.
16.3 Human Reading Path
Concrete lens. The signature baseline calls the protocol legitimate because parties agreed. The institutional packet exposes omitted publics and keeps legal force, implementation, and representative standing separate.
Technical assurance alone does not create legitimate social authority by itself. A sound control can be imposed by the wrong body, a lawful rule can be ineffective, a global agreement can exclude those bearing harm, and emergency powers can persist after justification expires. Preserving records and conflicts behind action makes legitimacy harder to counterfeit.
Audit logs, evaluations, and shutdown mechanisms support governance, but do not decide who may impose risk, who represents affected people, who may inspect confidential evidence, or how decisions can be appealed. An institutional commitment packet records authority, jurisdiction, duty holder, beneficiaries, evidence basis, disclosure boundary, review forum, enforcement, remedy, expiry, and unresolved conflict. International coordination adds verification, strategic competition, unequal capacity, regulatory arbitrage, and commitments.
The lifecycle runs from stakeholder and jurisdiction mapping through negotiation, authorization, implementation, independent oversight, contest, remedy, and renewal. Legitimacy laundering, forum shopping, captured standards, unverifiable treaty language, participation without influence, and burdens shifted onto weaker communities remain visible. Evidence can inform collective authority, but it cannot manufacture consent, erase political conflict, or replace institutions capable of enforcing duties and repairing harms.
16.4 Problem
The same system can be privately authorized, technically controlled, legally permitted in one jurisdiction, prohibited in another, and still illegitimate to the people bearing its risks. ASI governance must represent these states without collapsing them into a single approval bit. It must also survive strategic actors who benefit from weak verification, fragmented enforcement, or the inability of affected communities to obtain evidence and remedy.
ASI-scale systems cross organizations, jurisdictions, borders, public services, and affected populations. Technical permissions and private governance cannot determine who has public authority, whose participation counts, how conflicting rules are resolved, or how international commitments are verified and amended. Those questions remain unavoidable.
Without an institutional owner, technical controls and evidence can be complete while mandate, jurisdiction, representation, enforcement, capacity, remedy, and cross-border conflict remain undefined. The shared lifecycle method supplies transaction custody; the institutional layer supplies public authority and contestability.
16.5 Why existing approaches are insufficient
A framework may describe good process while lacking any actor with the resources or independence to inspect compliance. A treaty may be enforceable between signatories yet omit downstream communities. A participation process may count attendees while giving them no agenda power, evidence access, or appeal. These are different failures and require separate fields rather than a single governance-maturity score.
A compliance checklist, technical standard, treaty text, risk framework, or corporate safety policy can name duties without establishing jurisdiction, representative input, assessor independence, enforcement, remedy, capacity, legitimacy, or observed effectiveness. Architecture cannot manufacture democratic consent.
Constitutional Alignment, governance rights, standards, safety cases, and inter-stack protocols form the strongest technical composition. It wins if it can also preserve jurisdiction, mandate, participation, representation, verification access, enforcement asymmetry, remedy, capacity, conflict, exit, and legitimacy residuals.
What this institutional-authorization diagram shows: a jurisdiction- and mandate-specific authorization moves. Scientific evidence, legal compliance, standards conformance, participation, and legitimacy remain distinct inputs and residuals.
16.6 Core Claim
[institutions-international-coordination-and-public-legitimacy.core, label: Design rationale, support: argument] Public deployment and cross-border coordination should proceed only through a versioned institutional packet that keeps jurisdiction, mandate, participation, scientific evidence, law and standards, verification, enforcement, remedy, capacity, conflict, expiry, and legitimacy residuals distinct; legal text, technical conformance, stakeholder consultation, or an international commitment alone establishes neither lawful authority, effective governance, representative legitimacy, nor safety.
Reader claim. An international agreement can be legally real yet operationally weak, and a consultation can be extensive yet unrepresentative; neither signal should impersonate the other.
Operational rule. Bind every institutional decision to jurisdiction, mandate, affected publics, representation limits, testable obligations, verifier independence, implementation capacity, enforcement, appeal, remedy, expiry, and dissent. Missing groups or out-of-jurisdiction action block the ordinary route.
16.6.1 Worked coordination packet: three affected publics are still missing
A cross-border AI protocol names its parties, obligations, verifier, data-sharing scope, noncompliance route, and withdrawal process. It has implementation funding and a formal enforcement path. Yet the affected-public census lists publics 1, 2, and 3 as not included. The packet cannot convert treaty signatures or implementation readiness into representative legitimacy. It routes the missing census, language access, challenge standing, and representation questions to repair before a legitimacy claim or public deployment decision proceeds.
The finite review gives exact repair or refusal dispositions to all 45 admission-axis mutations. A mandate bound to one jurisdiction cannot authorize another, and changes to jurisdiction, instrument, population, or protocol invalidate its receipt. Two non-identifiability results show why participation counts do not determine representative standing and commitment signals do not determine effective enforcement. These checks organize institutional evidence; they do not establish lawful authority, representativeness, enforcement efficacy, remedy, legitimacy, stability, or safety.
16.6.2 Resilience inside the institutional boundary
Institutions can authorize, coordinate, finance, inspect, enforce, and remedy, but their existence does not show that society can withstand or recover from an incident. This chapter owns mandate, jurisdiction, affected-public representation, legal and standards obligations, verifier access, cross-border commitments, implementation capacity, enforcement, liability, appeal, remedy, expiry, and legitimacy residuals. Societal Resilience and Misuse Defense is the stable technical-detail owner for domain-specific resist, absorb, recover, and adapt operations across providers, copied artifacts, harmed parties, public correction, service continuity, incident paths, defensive service levels, and unresolved harm.
The family preserves both directions of non-substitution. A lawful and representative institution may still fail to detect, contain, restore, or adapt; an effective incident response may lack mandate, due process, jurisdiction, representation, or remedy. This chapter does not inherit resilience or recovery efficacy. The technical route does not inherit lawful authority, institutional legitimacy, representative standing, enforcement, or international coordination. Each owner retains its claims, sources, proof targets, tests, failures, evidence exit, support ceiling, ID, and URL. The composition creates no resilience, legitimacy, safety, support, deployment, or release result.
16.7 Mechanism
The institutional packet begins with a public-authority map. It names the legal or delegated basis for action, territorial and subject-matter jurisdiction, duty holders, affected publics, rights holders, beneficiaries, excluded groups, and forums with standing to contest the decision. Claims of representation include their selection process and limitations. This prevents a technically competent sponsor from presenting itself as the universal principal.
Coordination instruments compile obligations into testable commitments. Prohibitions, thresholds, reporting duties, access rights, financing, assistance, incident notification, and remedy are attached to responsible actors, deadlines, evidence routes, and consequences for noncompliance. Confidentiality and security constraints are represented as scoped access controls, not excuses for unverifiable assurance. International packets also record reciprocity, capacity asymmetry, forum choice, withdrawal, and the risk of regulatory arbitrage.
Observation joins three ledgers that must remain separate: technical conformance, institutional performance, and legitimacy. Technical evidence asks whether a system met a requirement; performance asks whether monitoring, enforcement, and remedies worked; legitimacy asks whether authority and participation remain defensible to affected people. A packet may pass one ledger and fail another. Renewal requires an explicit decision that considers all three and publishes unresolved residuals within lawful disclosure bounds. The renewal record also states whose challenge could still change the outcome, which evidence remains inaccessible, and which population lacks an effective representative or remedy.
Contract. Map jurisdiction, mandate, standing, affected publics, representation, excluded groups, and conflicts before treating an institution as an authority.
Admission. Join public reasons and scientific evidence to a versioned law-policy-standard crosswalk without collapsing these different sources of legitimacy.
Execution. Define cross-border commitments with named verification, assessor independence, noncompliance handling, enforcement, dispute, remedy, amendment, and withdrawal paths.
Observation. Track institutional capacity, distributional effects, emergency authority, exceptions, capture indicators, and unresolved conflicts through deployment.
Closure. Reopen the packet when evidence, jurisdiction, representation, law, system capability, or affected populations materially change.
16.8 Concept-completion ledger
16.8.1 Mandate, jurisdiction, and legal force
Mechanism. Before an institution can authorize, require, prohibit, inspect, or sanction, compile its source of authority, jurisdiction, subject, object, territorial and extraterritorial reach, delegation chain, conflicts, review route, expiry, and legal force. Distinguish treaty obligation, statute, regulation, contract, standard, guidance, voluntary commitment, and technical policy. The action record cites the exact provision and names parties for whom it is nonbinding. Conflicting authorities receive a forum and interim rule.
Failure mode. A respected standard setter can be treated as a regulator, or a global principle as directly enforceable law. Overlapping jurisdictions can create contradictory duties; “international” participation can mask regional or private authority.
Non-claim. A valid mandate does not establish technical correctness, justice, compliance, or public legitimacy. Authority and the quality of its exercise remain separate claims.
Source grounding. ext_un_global_digital_compact_2024 is a multilateral policy commitment; ext_council_europe_ai_convention_2024 is a treaty framework whose application depends on ratification and implementation. Neither grants this project legal authority.
16.8.2 Affected publics, representation, and standing
Mechanism. Map people who build, operate, use, are evaluated by, are displaced by, or bear physical and systemic effects of the system. For each group, record representation route, information access, language and accessibility, conflicts, consent where applicable, challenge standing, collective organization, and remedy. Participation begins while options remain open and preserves dissent; technical expertise and electoral authorization remain distinct forms of standing. The denominator includes people unable or unwilling to participate.
Failure mode. A consultation can count submissions while excluding people without time, connectivity, citizenship, or technical language. One civil-society participant may be treated as representing all affected groups. Participation after an irreversible deployment becomes theater.
Non-claim. Participation does not imply consensus, consent, representativeness, or a technically safe outcome. A majority position cannot erase protected rights or excluded groups, including future ones.
Source grounding. ext_un_global_digital_compact_2024 and ext_council_europe_ai_convention_2024 provide public-interest and rights-oriented institutional comparators. They do not validate a universal representation method.
16.8.3 Science, law, standards, and conformance
Mechanism. Maintain separate but linked ledgers for empirical evidence, legal duties, policy choices, technical standards, and conformity assessment. A crosswalk states which scientific observation informs which requirement, how a standard operationalizes it, who tests conformance, and what conclusion each result permits. Updates preserve historical versions and cannot silently turn a voluntary benchmark into law or a legal threshold into scientific truth. Conflicts and unmapped duties remain open findings.
Failure mode. Passing a test suite can be marketed as legal compliance; a statute can freeze an obsolete technical proxy; a standards committee can encode vendor interests. Ambiguous crosswalks allow actors to shop for the weakest interpretation.
Non-claim. Conformance with a standard does not prove safety, rights protection, legal compliance in every jurisdiction, or legitimacy. Its inference stops at the tested requirement and version.
Source grounding. ext_eu_article_50_transparency_guidelines_2026 is a jurisdiction- and provision-specific transparency comparator. ext_legal_alignment_2026 frames legal alignment questions but is not legal advice or universal institutional proof.
16.8.4 Verification independence and access
Mechanism. Define evaluator appointment, funding, competence, access to weights, data, logs, facilities, personnel, and incident records, plus confidentiality, conflict, challenge, reproducibility, and publication rights. Independence is decomposed into organizational, financial, technical, and epistemic dimensions. If access is restricted, the assurance report states which claims became unverifiable and the maximum public inference. Reappointment and provider dependence are disclosed over time.
Failure mode. A nominally independent assessor can depend on provider tools, curated samples, or continued contracts. Unlimited disclosure can violate privacy or security, while secrecy can make assurance unfalsifiable. Rotating auditors may share the same methods and blind spots.
Non-claim. Independent review does not guarantee competence, complete access, unbiased judgment, or system safety. It provides a challenge route whose own limitations require inspection and disclosure.
Source grounding. ext_flexible_hardware_enabled_guarantees_2025 motivates verifiable infrastructure but leaves verifier legitimacy and authority unresolved. The UN and Council of Europe sources support oversight principles, not this evaluator design.
16.8.5 Cross-border commitment, defection, and enforcement
Mechanism. Every international commitment names parties, covered systems and actions, entry conditions, measurement, verification, data sharing, uncertainty treatment, noncompliance process, sanctions or incentives, dispute resolution, withdrawal, amendment, emergency exceptions, and re-entry. Model incentives under compliance, delay, concealment, unilateral acceleration, and partial participation. Preserve domestic implementation differences rather than treating signature as execution. Unknown or nonparticipating actors remain in strategic analysis.
Failure mode. Vague commitments can reward symbolic compliance; intrusive verification can create espionage or sovereignty risks. Enforcement may fall hardest on low-capacity states while powerful actors defect. A race narrative can erase feasible reciprocal off-ramps.
Non-claim. Agreement, signature, or verification access does not prove compliance, effectiveness, stability, or fairness. Observed implementation and remedy must be established separately over relevant time, populations, jurisdictions, institutions, enforcement paths, disputes, and withdrawals.
Source grounding. ext_un_global_digital_compact_2024 and ext_council_europe_ai_convention_2024 are institutional comparators with different legal character. They do not demonstrate enforcement of a global ASI regime.
16.8.6 Capacity inequality and financing
Mechanism. Treat regulatory, scientific, compute, legal, diplomatic, and civil-society capacity as required infrastructure. Record who can evaluate, negotiate, comply, appeal, and benefit; cost those functions; and assign durable financing without making recipients dependent on regulated firms or geopolitical patrons. Mutual recognition requires competence and rights baselines, while technical assistance preserves local priority setting and data sovereignty. Capacity metrics distinguish resources from exercised authority and outcomes.
Failure mode. Uniform obligations can exclude low-capacity jurisdictions or turn them into rule takers. Provider-funded expertise can create capture; centralized shared services can leak sensitive data or impose one jurisdiction’s values.
Non-claim. Funding or training does not establish independence, equal influence, institutional quality, or legitimate representation. Capacity can exist without practical standing, durable staffing, enforcement, public trust, remedy, agenda control, or continuity.
Source grounding. ext_oecd_ai_infrastructure_competition_2025 provides time- and market-scoped capacity and concentration context. ext_un_global_digital_compact_2024 supplies a cooperation aspiration, not evidence that a financing mechanism works.
16.8.8 Remedy, liability, insurance, and competition
Mechanism. Connect incidents and institutional decisions to notice, explanation, evidence preservation, standing, injunction, correction, compensation, collective action, insurance, liability allocation, appeal, and enforcement. Record insolvency, jurisdictional gaps, contractual waivers, and harms that money cannot repair. Competition review separately examines market access, interoperability, tying, infrastructure concentration, and whether safety duties entrench incumbents. Remedy reach and elapsed time are observed, not assumed.
Failure mode. Insurance can price only measurable losses and create moral hazard; liability can be evaded across supply chains or suppress beneficial entrants. Competition rhetoric can weaken necessary safety controls, while compliance costs can become an incumbent moat.
Non-claim. A remedy path does not make harm reversible, and concentration does not by itself establish illegality. Formal availability may still be practically unreachable, delayed, inadequate, unequally distributed, unenforced, unaffordable, or unknown.
Source grounding. ext_eu_ai_civil_liability_2025 and ext_oecd_ai_infrastructure_competition_2025 are jurisdiction- and time-scoped comparators, not universal legal conclusions. ext_icrc_autonomous_weapons_ihl_2025 supplies a mandate-specific accountability perspective.
16.9 Interfaces
The boundary with technical governance is deliberately asymmetric. Safety cases, evaluations, logs, and capability thresholds can trigger institutional duties and narrow available choices, but they cannot appoint the decision maker. Conversely, an institution can authorize a bounded action only within the technical safety and rights constraints it actually controls; mandate does not make an unsafe effect safe.
Constitutions and rights define protected constraints; safety cases and thresholds supply technical evidence; inter-stack protocols supply coordination machinery. This chapter owns mandate, jurisdiction, participation, verification access, enforcement, remedy, capacity, and public legitimacy.
- Moral Uncertainty retains contested values; institutions decide only within a claimed mandate.
- System Boundaries enforces technical grants; this chapter asks whether the grantor has public authority.
- Capability Thresholds supplies capability-triggered commitments and receives enforcement failures.
- Human-AI Organizations governs internal roles; this chapter governs relations among public bodies, jurisdictions, and publics.
- Multi-Agent Dynamics reports emergent concentration and coordination effects without conferring legitimacy.
16.10 Invariants
Every institutional status is versioned by jurisdiction, mandate, system identity, capability envelope, affected population, and time. A commitment cannot be copied to a materially different deployment or successor institution without a new authorization and verification decision. Unresolved conflict is preserved as state, not rewritten as consensus.
Applying the shared lifecycle method, no actor may turn technical competence into public mandate, participation cannot be reduced to notice, enforcement and remedy must remain reachable, and cross-border conflict cannot disappear inside one aggregate status.
- Technical conformance, legal validity, political authority, scientific consensus, public legitimacy, and observed effectiveness remain separate claims.
- Affected and excluded populations remain visible in the denominator.
- Every commitment names verification, noncompliance, enforcement, and remedy.
- Jurisdictional conflicts route to an explicit forum rather than disappearing.
- Emergency and exceptional authority expires and faces review.
16.11 Independent access without uncontrolled disclosure
Independent scrutiny is necessary, but “give researchers access” is not an adequate control design. Frontier systems, sensitive evaluations, model weights, user data, and incident records create conflicting needs: evaluators need enough access to find failures that the developer missed, while the governed organization must not turn review into an exfiltration path or constrain it until no adverse result can survive. The access contract therefore separates sponsor, custodian, evaluator, method owner, adjudicator, and publication authority.
A secure research access packet binds the exact artifact and checkpoint, research question, evaluator independence and conflicts, permitted interfaces, protected data, compute and query budgets, logging, privacy controls, enclave or clean-room boundary, red-team authority, result custody, disclosure timing, appeal, and emergency revocation. Evaluators must be able to run negative controls, preserve complete attempt denominators, publish adverse findings through a protected channel, and distinguish developer-provided evidence from independently observed results. Double-blind assignment can reduce some social bias, but cannot substitute for method transparency or conflict disclosure.
Hardware-enabled guarantees may eventually make parts of compute use, model identity, and policy enforcement more inspectable [@ext_flexible_hardware_enabled_guarantees_2025]. They also introduce governance questions: who defines the policy, who can update it, what hardware and jurisdictions are covered, how false positives are appealed, and whether the same mechanism becomes surveillance or market exclusion. Likewise, law-following AI and current transparency rules create concrete obligations, but their authority, scope, enforcement, and legitimacy remain distinct [@ext_legal_alignment_2026; @ext_eu_article_50_transparency_guidelines_2026].
The mechanism fails through sponsor veto, cherry-picked evaluators, unsafe disclosure, enclave theater, inaccessible replication, undisclosed conflicts, or a hardware root controlled by the party being audited. The nonclaim is strict: independent access does not make an evaluation representative, and an audit, attestation, legal opinion, or transparency filing does not prove safety or public legitimacy.
16.12 Failure modes
The evaluation program must look for institutional theater: duties that exist on paper but lack budgets, evidence access, sanctions, or remedy. It must also probe capture through assessor dependence, revolving-door incentives, forum shopping, emergency exceptions, selective transparency, and standards written by incumbents. A clean compliance sample under cooperative disclosure cannot clear these adversarial governance conditions.
The principal failure family includes regulatory capture; forum shopping; race-to-the-bottom deployment; standards laundering; treaty theater; unverifiable commitments; enforcement asymmetry; participation without power; affected-public omission; capacity inequality; panel capture; fragmented jurisdiction; inaccessible remedy; permanent emergency powers.
Evaluation must examine capture, forum shopping, verification asymmetry, weak-state capacity, excluded publics, unequal enforcement, remedy failure, and strategic defection. A coordination mechanism that blocks everything or advantages incumbents cannot count as successful merely because commitments are recorded.
16.13 Minimum Viable Implementation
The first software artifact can be a commitment registry that links each duty to a named authority, subject, evidence item, verifier, deadline, noncompliance route, appeal forum, and remedy. A public projection exposes non-sensitive status and residuals, while a protected evidence room records reviewer access and sponsor interference. Tabletop exercises then test jurisdiction conflict, missing capacity, captured assessment, late incident notice, contested evidence, and failed remedy.
Build a jurisdiction-and-commitment packet and test it on public-record cases and adversarial multi-jurisdiction tabletop exercises containing conflicting rules, missing participation, assessor conflicts, evidence revision, incidents, noncompliance, and remedy requests. The exercise can test record completeness and conflict routing, not legal compliance, public trust, or geopolitical stability.
The minimum implementation is a tabletop and public-record exercise over one bounded cross-organizational risk: map jurisdictions and affected parties, compare status quo and coordination instruments, test verification and disclosure access, inject defection and capture, and exercise dispute, remedy, suspension, and exit.
16.14 Evidence and falsification program
Argument exit requires comparative institutional case studies or live bounded pilots with prospectively named mandates, affected publics, verification methods, enforcement paths, capacity constraints, distributional outcomes, remedies, and failure injections. Technical and legal evaluators remain distinct, and one jurisdiction cannot establish global legitimacy.
16.15 Mature Research Target
The institutional endpoint supports interoperable public commitments without assuming a single world government or a universal legal vocabulary. Local and international institutions can publish machine-readable duties, exchange bounded evidence, recognize or contest one another’s decisions, and trace which system effects remain outside effective jurisdiction. Capacity-building and financing obligations are first-class because rules that only wealthy actors can verify are not equivalent governance.
The research program combines institutional case analysis, adversarial tabletops, implementation studies, and longitudinal outcome measurement. Comparators include voluntary standards, domestic licensing, sector-specific regulation, treaty-style commitments, mutual recognition, and independent assurance. Outcomes distinguish compliance, time to detection, enforcement consistency, remedy reach, burden distribution, strategic substitution, public contestability, and the survival of emergency powers after their trigger ends.
The target remains politically modest. It cannot compute legitimate authority or eliminate conflict. It can make claimed authority, participation, verification access, enforcement capacity, and remedy concrete enough to challenge. A mature packet shows both where collective authorization exists and where the ASI stack must abstain because no accountable institution can presently carry the decision.
The mature layer lets institutions coordinate shared AI risks while remaining contestable, capacity-aware, and reversible. It joins scientific evidence to lawful and publicly accountable action without allowing standards, private infrastructure, or a concentrated technical elite to become a substitute government.
No current result establishes that endpoint. Institutional support remains bounded until adversarial cases demonstrate verification access, enforceable remedy, capacity across unequal jurisdictions, and durable public contestability.
16.16 Formalization hooks
AsiStackProofs.InstitutionalLegitimacyReview supplies 32 theorem declarations over an eight-transition review and 45 admission-axis mutations. The model separates identity, jurisdiction-scoped mandate, affected publics, cross-border commitments, institutional performance, remedy, and explicit non-authority. It proves that signed agreements, bounded legal findings, consultation, and technical conformance cannot substitute for implementation, legitimacy, representative mandate, or public authority.
The refinement also rejects use of a local mandate in a distinct jurisdiction, proves finite affected-public inclusion by induction, preserves expiry and population shortfalls under adverse monotone change, and invalidates receipts when jurisdiction, instrument, population, or protocol changes. A representation impossibility result shows that identical participation signals can conceal opposite standing for excluded publics. An effective-enforcement impossibility result shows that identical agreement, duty, and verifier signals can conceal opposite remedy reach. The Governance Rights consumer routes an incomplete affected-public census to review.
These theorems check authored record semantics, not institutional reality. Chapter support remains argument. They do not prove lawful authority, representativeness, implementation, enforcement, remedy efficacy, public legitimacy, or geopolitical stability. Those claims require a Project Theseus institutional tabletop and later independent institutional evidence.
16.17 Codex test plan
| Test | Purpose | Status |
|---|---|---|
| Lean lifecycle and exact repair | Compile the eight-transition model and reject all 45 single-axis mutations with exact repair or refusal. | passed locally |
| Mandate and jurisdiction | Prove a jurisdiction-bound mandate cannot authorize a distinct jurisdiction. | passed locally |
| Participation and standing | Prove finite inclusion and that procedural signals cannot determine representative standing. | passed locally |
| Commitment and enforcement | Prove commitment signals cannot determine whether enforcement and remedy are effective. | passed locally |
| Verification asymmetry | Test whether less-resourced parties can inspect, challenge, and appeal the evidence used against them. | Project Theseus required |
| Defection and remedy | Exercise noncompliance, capture, suspension, compensation, renegotiation, and lawful exit. | Project Theseus required |
Implemented formalization route: lean:institutions-international-coordination-and-public-legitimacy.admission_boundary covers only the bounded lifecycle, jurisdiction, affected-public, receipt, collision, and rejecting-consumer properties above; it cannot establish lawful authority, public legitimacy, effective coordination, or transfer.
16.18 Source crosswalk
| Source ID | Title | Bounded use |
|---|---|---|
coherence_exchange |
The Coherence Exchange | Corben-authored speculative lineage for epistemic exchange, verification, tribunal, labor, alignment, and resource coordination across a shared system. It helps expose institutional interfaces, but it supplies no legal authority, international agreement, representative legitimacy, enforcement result, or governance-effectiveness evidence. |
ext_un_global_digital_compact_2024 |
Global Digital Compact | Official United Nations record of the intergovernmentally negotiated Global Digital Compact, including commitments on international AI governance, interoperable approaches, inclusion, capacity building, scientific assessment, and global dialogue. It is a governance comparator, not evidence of implementation, effectiveness, legal compliance, representative legitimacy, or ASI safety. |
ext_council_europe_ai_convention_2024 |
Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law | Official Council of Europe treaty page covering lifecycle principles, risk and impact management, procedural safeguards, remedies, monitoring, and the Conference of the Parties. It supplies an institutional comparator only; no local legal interpretation, treaty compliance, implementation effectiveness, democratic legitimacy, or safety result is claimed. |
16.18.1 Manifest source assignment reconciliation
These rows keep Institutions, International Coordination, and Public Legitimacy’s manifest assignments visible at their recorded review boundary. Passage review does not establish local reproduction, performance, safety, deployment, or support-state movement.
| Source | Intake role | Boundary |
|---|---|---|
ext_flexible_hardware_enabled_guarantees_2025 |
Passage-reviewed comparator: Flexible Hardware-Enabled Guarantees for AI Compute. Supplies a hardware-enabled-guarantee research agenda for making compute-governance claims more inspectable than voluntary reporting alone. | The proposal does not establish complete coverage, secure implementation, legitimate update authority, or resistance to hardware and governance abuse. No local implementation, reproduction, performance, safety, deployment, support-state, or ASI result is established by this reconciliation row. |
ext_legal_alignment_2026 |
Passage-reviewed comparator: Legal Alignment for Safe and Ethical AI. Identifies law-following AI as a coordination problem across jurisdictions, interpretations, exceptions, institutions, and technical systems. | Does not supply a universally legitimate legal corpus, interpretation engine, compliance proof, or public mandate. No local implementation, reproduction, performance, safety, deployment, support-state, or ASI result is established by this reconciliation row. |
ext_eu_article_50_transparency_guidelines_2026 |
Passage-reviewed comparator: Guidelines on Transparency Obligations for Providers and Deployers of AI Systems. Provides a current regulatory comparator for transparency duties around AI-generated and manipulated content. | Guidance is jurisdiction- and obligation-specific; transparency compliance alone does not establish safety, authenticity, legitimacy, or effective enforcement. No local implementation, reproduction, performance, safety, deployment, support-state, or ASI result is established by this reconciliation row. |
ext_oecd_ai_infrastructure_competition_2025 |
Metadata-first comparator: Competition in artificial intelligence infrastructure. OECD analysis of concentration, barriers to entry, vertical integration, and competition across AI infrastructure. It motivates bottleneck and exit analysis but does not adjudicate a specific market, legal violation, or optimal remedy. | No passage-level source claim, local implementation, reproduction, safety, performance, deployment, support-state, or ASI result is established by this reconciliation row. |
ext_eu_ai_civil_liability_2025 |
Metadata-first comparator: Artificial intelligence and civil liability. European Parliament research service study of AI and civil-liability questions. It supports explicit causation, evidence-access, insurance, compensation, and remedy analysis but is not legal advice or a globally settled liability rule. | No passage-level source claim, local implementation, reproduction, safety, performance, deployment, support-state, or ASI result is established by this reconciliation row. |
ext_icrc_autonomous_weapons_ihl_2025 |
Metadata-first comparator: Autonomous Weapon Systems and International Humanitarian Law: Selected Issues. ICRC legal and policy position on autonomous weapon systems and context-specific human judgment. It is authoritative for the ICRC position, not a universally settled legal interpretation, engineering validation, or authorization to design or deploy weapons. | No passage-level source claim, local implementation, reproduction, safety, performance, deployment, support-state, or ASI result is established by this reconciliation row. |
16.19 Competition, liability, insurance, and remedy
Public governance is incomplete if it can issue principles but cannot prevent concentrated private control, assign duties, surface evidence, compensate harm, or restore access. Competition and liability are therefore enforcement interfaces, not peripheral policy topics.
The institutional packet adds:
- market and infrastructure boundary, concentration and vertical dependencies, interoperability, switching cost, common ownership, and affected entrants;
- duty holders across developer, deployer, operator, infrastructure provider, data provider, integrator, and professional user;
- evidentiary access, logging, disclosure, trade-secret and classified boundaries, burden of proof, and preservation duties;
- causation and contribution theories appropriate to adaptive, multi-party systems without pretending the book settles applicable law;
- insurance coverage, exclusions, capital, incident incentives, and the risk that insurance becomes a compliance substitute;
- injunction, suspension, correction, service restoration, compensation, collective remedy, and long-tail monitoring; and
- cross-border recognition, forum, enforcement, and insolvency.
The OECD competition source supports the concentration and entry-barrier questions. The European Parliament civil-liability study supports explicit attention to evidence, causation, compensation, and remedy. The ICRC position paper supplies a domain-specific reminder: technical deployment can enter legal regimes with duties that cannot be replaced by a generic safety score. These sources are inputs to institutional design, not legal advice or proof of one globally legitimate regime.
A remedy must be reachable by the person or community bearing harm. Complaint portals, audits, and fines count only if they can change behavior, repair loss, or stop an ongoing wrong. The chapter’s legitimacy test therefore asks not only who participated in rulemaking, but who can compel evidence, appeal a decision, enforce a duty, and obtain restoration when the system fails.
16.20 Summary
Institutional governance answers questions that architecture alone cannot: who may authorize public risk, which jurisdiction applies, who represents affected people, what evidence an independent reviewer can inspect, how duties are enforced, and how people obtain repair. These questions become typed, versioned records rather than prose surrounding a technical approval.
Keeping authority, law, science, conformance, effectiveness, and legitimacy separate is the central safeguard. A packet can therefore expose lawful but ineffective regulation, technically sound but unauthorized control, or well-intentioned coordination that excludes those bearing harm. Renewal depends on evidence and contestability, not institutional self-certification.
Institutional governance is the layer that converts bounded evidence into contestable collective action. It keeps mandate, jurisdiction, participation, science, law, standards, verification, enforcement, capacity, remedy, conflict, expiry, and legitimacy separate so coordination does not become either technical theater or unaccountable rule.
16.21 Handoff
Societal Resilience and Misuse Defense receives bounded institutional duties, service commitments, escalation channels, disclosure constraints, and remedy routes. It does not inherit proof that institutions are legitimate or effective; resilience must observe whether those commitments resist, absorb, recover from, and learn after real stress across differently resourced communities.