Rights-Based AI in Cyber–Physical Systems: A Governance Framework for Socio-Technical Resilience and Trust
Abstract
1. Introduction
- This paper reframes the CPS as governance infrastructure: This paper extends the CPS sensing–inference–actuation model from engineering safety to socio-technical governance, where the “plant” includes people, institutions, and rights exposure—and where failures are legitimacy and due-process failures, not just technical errors.
- This paper defines a scope-explicit target for high-consequence AI: This paper positions predictive and biometric AI in public workflows as end-to-end pipelines (data → model → decision → actuation → feedback), making the system—not the algorithm—the unit of governance and accountability.
- This paper introduces the 3R architecture (Risk–Rights–Rules): This paper proposes a systems-theoretic framework where rights and legal rules operate as enforceable constraints on the CPS loop, while risk tools manage residual uncertainty within non-negotiable boundaries.
- This paper operationalizes governance via a “3R Assurance Case”: This paper provides an implementable assurance object using Goal-Structuring Notation (GSN) to connect top-level rights/rule claims to assumptions, evidence artifacts, and specific control points in the loop.
- This paper adds a structured auditing and testing approach: This paper specifies the evidence package needed for auditability (e.g., demographic error testing, uncertainty bounds, logging/provenance, red-teaming, and procurement audit rights) and ties it to lifecycle checkpoints aligned with NIST AI RMF and the EU AI Act/FRIA.
- This paper derives control failures using systems safety methods: This paper applies STAMP/STPA to translate rights-relevant harms into unsafe control actions, enabling the systematic identification of “pinch points” where governance controls must intervene.
- This paper produces procurement and vendor-governance requirements: This paper converts the framework into actionable requirements for procurement, contracting, and ongoing oversight, supporting engineers, auditors, and legal reviewers with a testable definition of rights-based CPS governance.
2. Literature Review
2.1. Socio-Technical CPS and Systems-Level Governance
2.2. Uncertainty, Accountability, and Legal Certainty
2.3. Biometric Systems, Demographic Error, and Rights Exposure
2.4. Fairness Beyond Metrics: Feedback Loops and Institutional Context
2.5. Human-in-the-Loop Oversight and the “Moral Crumple Zone”
2.6. Governance Baselines and Operationalization into Assurance Artifacts
3. Cyber–Physical Systems, Critical Infrastructure, and Rights-Risk Coupling
3.1. CPS as Governance Infrastructure: The Engineering of Public Law
3.2. Critical Infrastructure and the Cascading Failure of Rights
3.3. The Rights–Risk Coupling: Why “Risk-Only” Paradigms Fail
- Biometric Disparity as System Failure
- ○
- A body of research on face recognition repeatedly finds that error rates and decision thresholds vary by demographic cohort, and that uniform thresholds can therefore impose unequal false-match burdens across groups [43,44]. Normatively, these differentials are best analyzed as distributional harms (disparate burdens of erroneous identification/verification) rather than mere implementation defects, because higher false match rates for a protected group predictably translate into more frequent wrongful interventions, such as secondary screening, denial of access, and investigative escalation, for that group [7,13,45].
- ○
- When a uniform operational threshold is applied in a high-throughput setting, statistical error becomes a procedural burden, with more stops, more delays, and more escalations, borne unevenly by identifiable groups [13,45]. This is precisely why the 3R framework treats rights as control constraints. A rights-consistent loop must require (i) demographic disparity testing as a precondition for deployment, (ii) threshold governance tied to error distributions, and (iii) actuation constraints that prevent error-prone groups from absorbing the system’s friction as a stable output [13,45].
- Actuation-Sensing Feedback Loops
- ○
- In predictive policing and CPS actuation (e.g., reallocating patrols), these processes reshape the data-generating process (e.g., observed arrests, stops, and recorded incidents). The inference layer then treats these observations as updated evidence of “risk,” generating a self-reinforcing loop that can concentrate policing in the same neighborhoods even when the true underlying rates do not justify it [46]. Technically, the system can appear “stable” because it continually confirms its own predictive target via endogenous data; normatively, it is unstable because it can amplify historically patterned disparities and convert prior over-policing into future “evidence” [24,47].
- ○
- Studies show that predictive policing systems can reproduce enforcement concentration because the system learns from “discovered” incidents rather than underlying incidents [46]. Moreover, policing data is shaped by prior enforcement patterns and surveillance practices, which can embed civil-rights harms into the data pipeline itself [24,47]. This means risk is confounded with enforcement intensity. A risk-only paradigm fails because it treats the feedback signal as ground truth; a rights-aware control paradigm must constrain the loop so that actuation does not manufacture the evidence that justifies more actuation [24,46,47].
3.4. The Global Normative Perspective: Public Health as Critical Infrastructure
4. Analytical Framework: The Risk–Rights–Rules (3R) Architecture
4.1. Systems-Theoretic Safety and the Formalization of Rights as Control Constraints
4.2. The Governance Triad: Disentangling Lifecycle, Operation, and Enforceability
4.3. The “Liability Sponge” Counter-Argument and Response
4.4. Evidence Discipline: Assurance Cases and Goal-Structuring Notation (GSN)
- Top-Level Goal (G1): The CPS deployment is rights-consistent.
- Context (C1): This refers to the applicable hard-law duties and rights safeguards [70].
4.5. Corporate Responsibility and Remedy in the CPS Ecosystem
5. Methodology: A Socio-Technical Systems (STSs) Approach to Governance Auditing
5.1. Research Design: Multi-Case Theory Building and Replication Logic
5.2. Analytical Instrument: The CPS-Governance Mapping Protocol
5.3. Data Corpus and Evidence Ranking (Auditability Constraint)
- Tier 1. Primary governance records (used as case evidence, not as “scholarly citations”)We prioritize judicial decisions, statutory instruments, official audit records, and regulator findings as primary data and analyze them using systematic document analysis procedures [95]. Where the case involves live facial recognition governance, we supplement primary legal materials with peer-reviewed scholarly analyses of the Bridges litigation and UK LFR governance [96,97].
- Tier 2. Peer-reviewed technical and socio-legal benchmarksWe use peer-reviewed studies as benchmarks for performance and harm to avoid reliance on vendor claims. For face recognition disparities, we rely on independent, peer-reviewed evaluations that demonstrate demographic differences and threshold effects [44,98,99,100]. For predictive policing feedback loops and endogenous data generation, we rely on peer-reviewed work demonstrating runaway reinforcement mechanisms and their civil rights implications [24,47,101].
- Tier 3. Non-peer-reviewed corroboration (strictly scoped)We do not treat journalism/NGO reports as evidentiary anchors. Where used, they serve only to identify timelines, surface contested claims, and locate missing artifacts, each of which is then treated as a governance risk indicator requiring corroboration in Tier 1–2 materials. These sources could also include investigative reports used solely to establish timelines and identify evidence gaps, which we then analyze as Governance Risks [95,102].
5.4. The Formal Verification Strategy: Assurance Cases and GSN
5.5. Within-Case Process Tracing (CPT)
5.6. Ethical Integrity and Harm Minimization
5.7. Critical Appraisal of the Methodology: Strengths, Weaknesses, and Counter-Arguments
6. Case Portfolio: Auditing Coercive-Power CPS Through the 3R Lens
6.1. Case 1. Live Facial Recognition (LFR) in the UK—The Sensing Scope Failure
- Technical Audit of the LoopThe sensing layer captured real-time biometric data from CCTV feeds in public spaces; the inference layer generated probabilistic match outputs; and the actuation layer triggered officer attention/engagement based on match alerts [107]. The 3R-relevant point is that “control” was exercised at two upstream points that typical model audits ignore: (i) siting (where/when the cameras and matching were activated) and (ii) watchlisting (who was eligible to be flagged). These are not peripheral parameters; they are the governance-relevant control-law of the system [10,97,108].
- The Governance Pinch PointThe core deficiency was not simply the model performance but a rules/constraints failure at the sensing and watchlisting boundary: peer-reviewed legal analyses of Bridges emphasize that the deployment lacked sufficiently clear and bounded criteria governing where LFR could be used and who could be placed on the watchlist, creating an excessive discretion problem incompatible with the rule-of-law requirements of legality, foreseeability, and non-arbitrariness. In 3R terms, this is a Sensing-Scope (Rules) failure: absent hard constraints on sensing scope and watchlist construction, “risk detection” defaults into the open-ended biometric surveillance capacity [10,97,108]. The system performed a high-impact control action (population-level biometric sensing) without a sufficiently specified constraint set governing when that action is permitted [8,10].
- Socio-Technical ConsequencesThe system’s institutional viability depended on enforceable constraints at the sensing boundary; absent those constraints, the deployment was found to be unlawful and could not be stabilized through accuracy improvements alone [10]. This provides a sharp inference for your framework: when the legality of the sensing scope is underdetermined, “better accuracy” is non-responsive to the legal failure mode because the harm mechanism is discretion, not error. This is why the minimum-viable control is not only a performance dossier but a scope-control instrument (siting and watchlisting rules) that is auditable and enforceable [10,70]. This demonstrates that public trust and legitimacy are central to police LFR acceptability and governance, independently of technical claims [107].
6.2. Case 2. Border Facial Biometrics (US)—The Actuation Gate Failure
- Technical Audit of the LoopThe system performs a facial comparison for identity verification using gallery-based matching and/or verification workflows (e.g., comparing a live capture to pre-staged image galleries associated with travel documents/manifests), then acts on the outcome (clearance vs. diversion to secondary screening) [111,112]. The “clearance vs. diversion” routing is the rights-relevant actuation gate: it operationalizes a probabilistic inference as a constraint on movement and time, and it is where lawful-basis, proportionality, and reviewability must bind in practice [111,112].
- The Governance Pinch PointThe principal risk is actuation-gate erosion: under throughput and workload pressure, “algorithm-in-the-loop” designs can induce automation bias, leading operators to defer to probabilistic outputs as de facto commands rather than as uncertain signals, unless systems are designed for meaningful human control (time, authority, override, and accountable procedure) [25,113]. Accordingly, the 3R audit treats the actuation gate as a control constraint that must specify (and log) the following: (i) when secondary screening is legally warranted; (ii) what evidence must be recorded to enable an after-the-fact review (including confidence/uncertainty and any escalation rationale); and (iii) what review/override path is available under the real tempo (who can pause; what triggers a mandatory second-person review; and what the recourse channel is) [84,111,112,113]. This reframes “HITL” from a slogan into an auditable control property: oversight must be demonstrable in logs and workflow traces, not assumed [67,84].
- Socio-Technological ConsequencesEven where systems are operationally effective, biometric error differentials documented in the peer-reviewed biometrics literature imply distributional procedural burdens: higher false non-match or false match rates for some demographic groups can translate into disproportionate delays, repeated screening, or escalations [13]. We term this accumulation of unequal procedural burden “rights debt”: a measurable governance externality in which the system’s throughput optimization is partly achieved by offloading friction onto identifiable groups over time. A rights-consistent actuation gate must include disparity-sensitive monitoring and a corrective control loop (threshold governance plus review triggers plus remedial pathways); otherwise, inequality becomes an operational invariant of the system [13,70].
6.3. Case 3. Chicago Strategic Subject List (SSL)—The Feedback Loop Failure
- Technical Audit of the LoopThe inference engine leveraged administrative/policing data and social-network features; the actuation layer included targeted interventions (e.g., custom notifications and other forms of intensified attention) [114]. This is a structurally feedback-prone control loop. Actuation (increased attention/contact) changes what is discovered and recorded, which can then be re-ingested as evidence of future risk [23,46].
- The Governance Pinch PointScholarly analyses of the SSL emphasize limited transparency, weak evidence of effectiveness, and accountability deficits in the generation and use of scores [115]. Critically, the system architecture is vulnerable to endogenous bias: increased patrol attention or contact can increase the number of detected incidents and recorded police interactions, which the inference layer may then treat as confirmation of elevated risk, producing a self-reinforcing allocation dynamic [23,46,115]. This is not just bias; it is a control failure in which the feedback signal is contaminated by the controller’s own interventions.
- Socio-Technological ConsequencesThis dynamic is consistent with formal and empirical demonstrations of runaway feedback loops in predictive policing, in which the model repeatedly allocates attention to the same communities when trained on “discovered” policing data [23,46]. In 3R terms, this is a Rules-and-Rights failure at the feedback boundary. The system lacks constraints that distinguish “risk” from “policing intensity,” thereby undermining the trust and legitimacy required for effective public safety governance [24,47]. The minimum viable control is therefore not only transparency, it is a feedback-discrimination protocol: (i) the explicit separation of enforcement-intensity features from risk targets, (ii) monitoring that detects endogeneity, and (iii) governance rules that prevent self-generated data from being treated as independent evidence [23,24,46].
6.4. Comparative Analysis: Synthesis of Socio-Technical Failure Mechanisms
- Scope–Speed–Feedback Trade-Offs (Mechanism Clarification)Across cases, the recurring mechanism is not bad AI, but missing constraints at distinct control points: (i) scope constraints on sensing and watchlisting (Case 1), (ii) procedural gates that preserve contestability under throughput (Case 2), and (iii) feedback controls that prevent endogenous data from being misread as objective risk (Case 3) [96,109]. The comparative implication is actionable: each failure mode maps to a different minimum viable control class, scope-control instruments, actuation-gate controls, and feedback-discrimination controls, each with distinct evidence obligations in the assurance case [70,80].
- Socio-Technological Consequences: The Chilling Effect and Trust DegradationWhere a coercive-power CPS becomes opaque and difficult to contest, the empirical literature on the surveillance-induced chilling effects documents the deterrence of lawful information seeking and democratic discourse [116,117]. The 3R connection is not abstract. The chilling effects are a population-level feedback mechanism—reduced engagement, reduced reporting, and reduced civic participation—that degrades institutional legitimacy and weakens the quality of the very data streams governance systems rely upon. This is why trust degradation is a systems risk, not an external social concern [75,76,118,119].
- Cross-Case InferenceAcross the portfolio, the recurring failures are control-structure failures, missing constraints, weak feedback discrimination, and actuation without procedural gates, rather than isolated model defects. These minimum-viable controls should be translated into procurement-ready and oversight-ready assurance artifacts: (i) scope-control instruments (siting and watchlisting rules); (ii) threshold/performance dossiers (including disparity tests and drift monitoring); (iii) logging and intervention audit schemas; (iv) feedback-monitoring protocols distinguishing risk from enforcement intensity; and (v) enforceable governance-for mechanisms (audit access, sanctions, and remedy/contestability) [25,68,70,80].
7. Operationalizing Rights as Resilience Constraints: From Normative Claims to Engineering Invariants
7.1. The Engineering of Rights: Requirements Decomposition
7.2. Actuation Gates as Dynamic Stability Mechanisms
| Algorithm 1: Rights-Aware Actuation Gate (RAAG) |
| Input: inference output ŷ_t, uncertainty estimate σt, drift/OOD flag dt, rights constraints Cr |
| Output: actuation decision u_t |
| If dt = TRUE or σt > σmax: |
| block high-consequence actuation |
| generate counterfactual explanation |
| trigger mandatory human review with override authority |
| log rights-check failure |
| Else if violates Cr(xt): |
| block actuation |
| generate contestability packet |
| log constraint violation |
| Else: |
| allow bounded actuation |
| log justification and evidence |
7.3. The “Governance for AI” Layer: Enabling Innovation Through Enforceable Rules
7.4. Socio-Technological Consequences of Failed Operationalization
- The Legitimacy Crisis and Adversarial AdaptationWhen systems are opaque, unreviewable, or self-reinforcing, the affected populations and organizations rationally adapt by withholding cooperation, disputing outputs, or gaming signals, reducing data quality and degrading system performance. In 3R terms, the loss of legitimacy becomes a negative feedback shock that undermines the evidence base on which the system relies [75,76].
- The “Liability Sponge” Backlash and Institutional DeskillingWhen humans are held responsible even though they are operationally unable to control automated processes, responsibility collapses onto frontline operators [28]. The Post Office Horizon IT Inquiry documents how the presumption of system reliability, coupled with weak contestability and governance failures, produced catastrophic accountability outcomes and prolonged institutional denial [135]. If the evidence cannot be audited and challenged, the system becomes a black box tribunal, and legitimacy fails.
- Kinetic Escalation or High-Friction EscalationWhen due-process safeguards are absent at actuation, errors translate into coercive outcomes (detention, denial, and intensified scrutiny), which then trigger predictable second-order effects—injunctions, litigation, or program termination—forcing systems offline. This is exactly what the UK LFR case demonstrates: scope constraints were missing, so the system became legally unstable and could not be “patched” by accuracy claims [10].
7.5. Standards, Oversight, and Enforcement Gaps
7.6. Realizing the 3R Framework: The “Audit-Ready” Architecture
8. Discussion: Designing Legitimacy into AI-Enabled CPS
8.1. Bridging the Stochastic–Deterministic Gap: Probabilistic Authority
8.2. Countering the “Efficiency Trap”: Legitimacy as a Stabilizing Feedback
8.3. Cross-Analysis of Failure Modes: The Function Creep and Discretion Leak
- Function Creep (Sensing Layer)Function creep, the expansion of a system beyond its originally justified purpose without transparent authorization, is a mature conceptual and legal phenomenon [140]. In Case 1, the failure mechanism is function-creep-ready by construction. If siting and watchlisting rules are under-specified, the same sensing infrastructure can be extended across contexts (new locations, new watchlists, and broader purposes) without the procedural burdens that normally constrain public power. The design implication is that creep can be made auditably visible and procedurally contestable through scope-control instruments: purpose-bound authorization, watchlist governance logs, and immutable records of when/where sensing was activated [10,66,140].
- Discretion Leak (Inference Layer)Discretion leak occurs when policy discretion is silently displaced into model updates, threshold adjustments, feature changes, or vendor-controlled tuning without public-law safeguards governing changes in the decision criteria [38,134,144]. Modern deployments often depend on multi-actor service models where upstream providers can update components that materially affect outcomes, while downstream public agencies have limited visibility (accountability horizon) [134]. Legitimacy therefore requires treating material model/threshold updates as governance events, documentation, reasons, evidence refresh, and oversight triggers, because a threshold shift can function as a de facto policy change even if no statute changed [70,80,144].
8.4. Designing Contestability into the Actuation Pathway
8.5. Critical Reflection: The Future of “Rule-Enforced” Innovation
8.6. Risk Types, Sources, and Governance Implications in Socio-Technical CPS
8.7. Evidence Map (Claim → Evidence Type → Strength → Transferability)
9. Conclusions
9.1. Synthesis of the 3R Framework and the Triadic Governance Model
9.2. Lessons from the Case Portfolio: The Cost of Normative Fragility
9.3. High-Impact Call to Action: Designing for Contestability and Remedy
- Mandatory control-point constraints (scope, actuation, and feedback). Every high-consequence AI-enabled CPS must implement enforceable constraints at the specific control points where authority is exercised: (i) scope-control instruments (siting + watchlisting rules) for sensing; (ii) rights-aware actuation gates that are uncertainty-sensitive and legally bounded; and (iii) feedback-discrimination controls that prevent endogenous data from being misread as objective risk [10,23,46,70,80]. Different failure modes require different controls, and “accuracy upgrades” cannot substitute for missing constraints.
- Contestability-by-design through auditable adverse action packets. Whenever the system produces a high-friction intervention, it must emit a contestability artifact at the moment of actuation: (i) the decision and the authorizing rule/constraint, (ii) a minimally sufficient, action-guiding explanation (often counterfactual), and (iii) the review/appeal channel. Counterfactual explanations can support recourse without full model disclosure, but only when paired with real review pathways and logged evidence [11,82,84].
- Audit-ready architectures and enforceable procurement in algorithmic supply chains. Public-sector procurement must contract for audit rights, evaluation access, change control (versioning/rollback/release gates), and continuous logging; otherwise, the assurance case cannot be maintained in the face of drift, vendor updates, and system entanglement [38,66,70,80,134]. This is the engineering meaning of rule-enforced innovation. Innovation remains deployable when normative stability is auditable rather than presumed [70,79,80,120].
9.4. Barriers to Real-World Implementation of the 3R Framework
9.5. Future Research Directions: Filling the Gap
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- National Academies of Sciences, Engineering, and Medicine. A 21st Century Cyber-Physical Systems Education; The National Academies Press: Washington, DC, USA, 2016. [Google Scholar] [CrossRef]
- Lee, E.A. The Past, Present and Future of Cyber-Physical Systems: A Focus on Models. Sensors 2015, 15, 4837–4869. [Google Scholar] [CrossRef] [PubMed]
- Eubanks, V. Automating Inequality: How High-Tech Tools Profile, Police, and Punish the Poor; St. Martin’s Press: New York, NY, USA, 2018. [Google Scholar]
- Narayanan, A.; Kapoor, S. AI Snake Oil: What Artificial Intelligence Can Do, What It Can’t, and How to Tell the Difference; Princeton University Press: Princeton, NJ, USA, 2024. [Google Scholar]
- Dressel, J.; Farid, H. The Accuracy, Fairness, and Limits of Predicting Recidivism. Sci. Adv. 2018, 4, eaao5580. [Google Scholar] [CrossRef]
- Crawford, K.; Schultz, J. Big Data and Due Process: Toward a Framework to Redress Predictive Privacy Harms. Boston Coll. Law Rev. 2014, 55, 93–128. Available online: https://bclawreview.bc.edu/articles/620?utm_source=chatgpt.com (accessed on 15 December 2025).
- Selbst, A.D.; Boyd, D.; Friedler, S.A.; Venkatasubramanian, S.; Vertesi, J. Fairness and Abstraction in Sociotechnical Systems. In Proceedings of the 2019 ACM Conference on Fairness, Accountability, and Transparency (FAT* ’19), Atlanta, GA, USA, 29–31 January 2019; Association for Computing Machinery: New York, NY, USA, 2019; pp. 59–68. [Google Scholar] [CrossRef]
- Leveson, N.G. Engineering a Safer World: Systems Thinking Applied to Safety; MIT Press: Cambridge, MA, USA, 2012. [Google Scholar]
- Citron, D.K.; Pasquale, F. The Scored Society: Due Process for Automated Predictions. Wash. Law Rev. 2014, 89, 1–33. Available online: https://digitalcommons.law.uw.edu/wlr/vol89/iss1/2/ (accessed on 11 December 2025).
- R (On the Application of Edward Bridges) v the Chief Constable of South Wales Police and Others, [2020] EWCA Civ 1058, Case No. C1/2019/2670 (Court of Appeal (Civil Division). 11 August 2020. Available online: https://caselaw.nationalarchives.gov.uk/ewca/civ/2020/1058 (accessed on 11 December 2025).
- Calo, R.; Citron, D.K. The Automated Administrative State: A Crisis of Legitimacy. Emory Law J. 2021, 70, 797. [Google Scholar]
- Hüllermeier, E.; Waegeman, W. Aleatoric and Epistemic Uncertainty in Machine Learning: An Introduction to Concepts and Methods. Mach. Learn. 2021, 110, 457–506. [Google Scholar] [CrossRef]
- Grother, P.; Ngan, M.; Hanaoka, K. Face Recognition Vendor Test (FRVT), Part 3: Demographic Effects; NISTIR 8280; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2019. [Google Scholar] [CrossRef]
- Smuha, N.A. Beyond the Individual: Governing AI’s Societal Harm. Internet Policy Rev. 2021, 10, 1–32. [Google Scholar] [CrossRef]
- De Gregorio, G.; Dunn, P. The European risk-based approaches: Connecting constitutional dots in the digital age. Common Mark. Law Rev. 2022, 59, 473–500. [Google Scholar] [CrossRef]
- Ebers, M. Truly Risk-based Regulation of Artificial Intelligence: How to Implement the EU’s AI Act. Eur. J. Risk Regul. 2025, 16, 684–703. [Google Scholar] [CrossRef]
- National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0); NIST AI 100-1; NIST: Gaithersburg, MD, USA, 2023. [Google Scholar] [CrossRef]
- European Parliament and Council of the European Union. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828. Off. J. Eur. Union 2024, 2024/1689. Available online: https://data.europa.eu/eli/reg/2024/1689/oj (accessed on 10 December 2025).
- Mantelero, A. The Fundamental Rights Impact Assessment (FRIA) in the AI Act: Roots, legal obligations and key elements for a model template. Comput. Law Secur. Rev. 2024, 54, 106020. [Google Scholar] [CrossRef]
- Kelly, T.P.; Weaver, R.A. The Goal Structuring Notation–A Safety Argument Notation. In Proceedings of the Workshop on Assurance Cases: Best Practices, Possible Obstacles and Future Opportunities (DSN 2004), Florence, Italy, 28 June–1 July 2004. [Google Scholar]
- Hawkins, R.; Kelly, T. A Software Safety Argument Pattern Catalogue; Technical Report YCS-2013-482; Department of Computer Science, University of York: York, UK, 2013; Available online: https://www-users.york.ac.uk/~rdh2/papers/patternCatalogue.pdf (accessed on 12 December 2025).
- Green, B.; Hu, L. The Myth in the Methodology: Towards a Recontextualization of Fairness in Machine Learning. In Proceedings of the Machine Learning: The Debates Workshop, 35th International Conference on Machine Learning (ICML 2018), Stockholm, Sweden, 14 July 2018; Available online: https://api.semanticscholar.org/CorpusID:49544563 (accessed on 10 December 2025).
- Ensign, D.; Friedler, S.A.; Neville, S.; Scheidegger, C.; Venkatasubramanian, S. Runaway Feedback Loops in Predictive Policing. In Proceedings of the 1st Conference on Fairness, Accountability and Transparency (FAT* 2018), PMLR: 2018, Proceedings of Machine Learning Research, New York, NY, USA, 23–24 February 2018; Friedler, S.A., Wilson, C., Eds.; Volume 81, pp. 160–171. Available online: https://proceedings.mlr.press/v81/ensign18a.html (accessed on 16 December 2025).
- Richardson, R.; Schultz, J.; Crawford, K. Dirty Data, Bad Predictions: How Civil Rights Violations Impact Police Data, Predictive Policing Systems, and Justice. NYU Law Rev. 2019, 94, 192–233. [Google Scholar]
- Parasuraman, R.; Manzey, D.H. Complacency and Bias in Human Use of Automation: An Attentional Integration. Hum. Factors 2010, 52, 381–410. [Google Scholar] [CrossRef]
- Skitka, L.J.; Mosier, K.L.; Burdick, M. Does Automation Bias Decision-Making? Int. J. Hum.-Comput. Stud. 1999, 51, 991–1006. [Google Scholar] [CrossRef]
- Lyell, D.; Coiera, E. Automation Bias and Verification Complexity: A Systematic Review. J. Am. Med. Inf. Assoc. 2017, 24, 423–431. [Google Scholar] [CrossRef]
- Elish, M.C. Moral Crumple Zones: Cautionary Tales in Human–Robot Interaction. Engag. Sci. Technol. Soc. 2019, 5, 40–60. [Google Scholar] [CrossRef]
- Baheti, R.; Gill, H. Cyber-physical Systems. In The Impact of Control Technology; Samad, T., Annaswamy, A.M., Eds.; IEEE Control Systems Society: Piscataway, NJ, USA, 2011; pp. 161–166. [Google Scholar]
- Lee, E.A. Cyber Physical Systems: Design Challenges. In Proceedings of the 11th IEEE International Symposium on Object/Component/Service-Oriented Real-Time Distributed Computing (ISORC 2008); Orlando, FL, USA, 5–7 May 2008, IEEE Computer Society: Los Alamitos, CA, USA, 2008; pp. 363–369. [Google Scholar] [CrossRef]
- Hildebrandt, M. Law as Computation in the Era of Artificial Legal Intelligence: Speaking Law to the Power of Statistics. Univ. Tor. Law J. 2018, 68, 12–35. [Google Scholar] [CrossRef]
- Yeung, K. Algorithmic Regulation: A Critical Interrogation. Regul. Gov. 2018, 12, 505–523. [Google Scholar] [CrossRef]
- Bayamlıoğlu, E.; Leenes, R. The “Rule of Law” Implications of Data-Driven Decision-Making: A Techno-Regulatory Perspective. Law Innov. Technol. 2018, 10, 295–313. [Google Scholar] [CrossRef]
- Kehl, D.; Guo, P.; Kessler, S. Algorithms in the Criminal Justice System: Assessing the Use of Risk Assessments in Sentencing; Responsive Communities Initiative, Berkman Klein Center for Internet & Society, Harvard Law School: Cambridge, MA, USA, 2017. [Google Scholar]
- Ouyang, M. Review on Modeling and Simulation of Interdependent Critical Infrastructure Systems. Reliab. Eng. Syst. Saf. 2014, 121, 43–60. [Google Scholar] [CrossRef]
- Rinaldi, S.M.; Peerenboom, J.P.; Kelly, T.K. Identifying, Understanding, and Analyzing Critical Infrastructure Interdependencies. IEEE Control Syst. Mag. 2001, 21, 11–25. [Google Scholar] [CrossRef]
- Gama, J.; Žliobaitė, I.; Bifet, A.; Pechenizkiy, M.; Bouchachia, A. A Survey on Concept Drift Adaptation. ACM Comput. Surv. 2014, 46, 44. [Google Scholar] [CrossRef]
- Sculley, D.; Holt, G.; Golovin, D.; Davydov, E.; Phillips, T.; Ebner, D.; Chaudhary, V.; Young, M.; Crespo, J.-F.; Dennison, D. Hidden Technical Debt in Machine Learning Systems. In Advances in Neural Information Processing Systems 28; Cortes, C., Lawrence, N.D., Lee, D.D., Sugiyama, M., Garnett, R., Eds.; Curran Associates, Inc.: Red Hook, NY, USA, 2015; pp. 2503–2511. [Google Scholar]
- Van der Vlist, F.; Helmond, A.; Ferrari, F. Big AI: Cloud Infrastructure Dependence and the Industrialisation of Artificial Intelligence. Big Data Soc. 2024, 11, 1–16. [Google Scholar] [CrossRef]
- De Laat, P.B. Big Data and Algorithmic Decision-Making: Can Transparency Restore Accountability? ACM SIGCAS Comput. Soc. 2017, 47, 39–53. [Google Scholar] [CrossRef]
- Carswell, G.; De Neve, G. Transparency, Exclusion and Mediation: How Digital and Biometric Technologies Are Transforming Social Protection in Tamil Nadu, India. Oxf. Dev. Stud. 2022, 50, 126–141. [Google Scholar] [CrossRef]
- Dixon, P. A Failure to “Do No Harm”—India’s Aadhaar Biometric ID Program and Its Inability to Protect Privacy in Relation to Measures in Europe and the U.S. Health Technol. 2017, 7, 539–567. [Google Scholar] [CrossRef]
- Cavazos, J.G.; Phillips, P.J.; Castillo, C.D.; O’Toole, A.J. Accuracy Comparison across Face Recognition Algorithms: Where Are We on Measuring Race Bias? IEEE Trans. Biom. Behav. Identity Sci. 2021, 3, 101–111. [Google Scholar] [CrossRef]
- O’Toole, A.J.; Phillips, P.J.; An, X.; Dunlop, J. Demographic Effects on Estimates of Automatic Face Recognition Performance. Image Vis. Comput. 2012, 30, 169–176. [Google Scholar] [CrossRef]
- Barocas, S.; Selbst, A.D. Big Data’s Disparate Impact. Calif. Law Rev. 2016, 104, 671–732. [Google Scholar] [CrossRef]
- Lum, K.; Isaac, W. To Predict and Serve? Significance 2016, 13, 14–19. [Google Scholar] [CrossRef]
- Brayne, S. Big Data Surveillance: The Case of Policing. Am. Sociol. Rev. 2017, 82, 977–1008. [Google Scholar] [CrossRef]
- Cybersecurity and Infrastructure Security Agency (CISA). Healthcare and Public Health Sector. Available online: https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/healthcare-and-public-health-sector (accessed on 10 December 2025).
- Canada’s Critical Infrastructure (CI). Public Safety Canada. 2025. Available online: https://www.publicsafety.gc.ca/cnt/ntnl-scrt/crtcl-nfrstrctr/cci-iec-en.aspx (accessed on 12 December 2025).
- Gostin, L.O.; Katz, R. The International Health Regulations: The Governing Framework for Global Health Security. Milbank Q. 2016, 94, 264–313. [Google Scholar] [CrossRef]
- Katz, R.; Fischer, J.E. The Revised International Health Regulations: A Framework for Global Pandemic Response. Glob. Health Gov. 2010, 3, 1–18. Available online: https://blogs.shu.edu/ghg/files/2011/11/Katz-and-Fischer_The-Revised-International-Health-Regulations_Spring-2010.pdf (accessed on 10 December 2025).
- Katz, R. Use of Revised International Health Regulations during Influenza A (H1N1) Epidemic, 2009. Emerg. Infect. Dis. 2009, 15, 1165–1170. [Google Scholar] [CrossRef]
- World Health Organization (WHO). International Health Regulations (2005): As amended in 2014, 2022 and 2024. 2025. Available online: https://apps.who.int/gb/bd/pdf_files/IHR_2014-2022-2024-en.pdf (accessed on 10 December 2025).
- World Health Organization (WHO). IHR Core Capacities. Available online: https://www.emro.who.int/international-health-regulations/about/ihr-core-capacities.html (accessed on 11 December 2025).
- Martinez-Martin, N.; Wieten, S.; Magnus, D.; Cho, M.K. Digital Contact Tracing, Privacy, and Public Health. Hastings Cent. Rep. 2020, 50, 43–46. [Google Scholar] [CrossRef]
- Klenk, M.; Duijf, H. Ethics of Digital Contact Tracing and COVID-19: Who Is (Not) Free to Go? Ethics Inf. Technol. 2021, 23, 69–77. [Google Scholar] [CrossRef]
- Shachar, C.; Gerke, S.; Adashi, E.Y. AI Surveillance during Pandemics: Ethical Implementation Imperatives. Hastings Cent. Rep. 2020, 50, 18–21. [Google Scholar] [CrossRef]
- Orzechowski, M.; Schochow, M.; Steger, F. Balancing Public Health and Civil Liberties in Times of Pandemic. J. Public Health Policy 2021, 42, 145–153. [Google Scholar] [CrossRef]
- Rinaldi, A.; Teo, S.A. The Use of Artificial Intelligence Technologies in Border and Migration Control and the Subtle Erosion of Human Rights. Int. Comp. Law Q. 2025, 74, 61–89. [Google Scholar] [CrossRef]
- Delfos, J.; Zuiderwijk, A.M.G.; van Cranenburgh, S.; Chorus, C.G.; Dobbe, R.I.J. Integral System Safety for Machine Learning in the Public Sector: An Empirical Account. Gov. Inf. Q. 2024, 41, 101963. [Google Scholar] [CrossRef]
- Patriarca, R.; Chatzimichailidou, M.; Karanikas, N.; Di Gravio, G. The Past and Present of System—Theoretic Accident Model And Processes (STAMP) and Its Associated Techniques: A Scoping Review. Saf. Sci. 2022, 146, 105566. [Google Scholar] [CrossRef]
- Rotenberg, M. Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law (Council Eur.). Int. Leg. Mater. 2025, 64, 859–902. [Google Scholar] [CrossRef]
- Bietti, E. From Ethics Washing to Ethics Bashing: A View on Tech Ethics from Within Moral Philosophy. In Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency (FAT* ’20); Association for Computing Machinery: New York, NY, USA, 2020; pp. 210–219. [Google Scholar] [CrossRef]
- Mitchell, M.; Wu, S.; Zaldivar, A.; Barnes, P.; Vasserman, L.; Hutchinson, B.; Spitzer, E.; Raji, I.D.; Gebru, T. Model Cards for Model Reporting. In Proceedings of the Conference on Fairness, Accountability, and Transparency (FAT* ’19); Association for Computing Machinery: New York, NY, USA, 2019; pp. 220–229. [Google Scholar] [CrossRef]
- Gebru, T.; Morgenstern, J.; Vecchione, B.; Vaughan, J.W.; Wallach, H.; Daumé, H., III; Crawford, K. Datasheets for Datasets. Commun. ACM 2021, 64, 86–92. [Google Scholar] [CrossRef]
- Raji, I.D.; Smart, A.; White, R.N.; Mitchell, M.; Gebru, T.; Hutchinson, B.; Smith-Loud, J.; Theron, D.; Barnes, P. Closing the AI Accountability Gap: Defining an End-to-End Framework for Internal Algorithmic Auditing. In Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency (FAT* ’20); Association for Computing Machinery: New York, NY, USA, 2020; pp. 33–44. [Google Scholar] [CrossRef]
- Green, B. The Flaws of Policies Requiring Human Oversight of Government Algorithms. Comput. Law Secur. Rev. 2022, 45, 105681. [Google Scholar] [CrossRef]
- Green, B.; Chen, Y. The Principles and Limits of Algorithm-in-the-Loop Decision Making. Proc. ACM Hum.-Comput. Interact. 2019, 3, 50. [Google Scholar] [CrossRef]
- Wagner, B. Liable, but Not in Control? Ensuring Meaningful Human Agency in Automated Decision-Making Systems. Policy Internet 2019, 11, 104–122. [Google Scholar] [CrossRef]
- Mökander, J.; Axente, M.; Casolari, F.; Floridi, L. Conformity Assessments and Post-market Monitoring: A Guide to the Role of Auditing in the Proposed European AI Regulation. arXiv 2021, arXiv:2111.05071. [Google Scholar] [CrossRef]
- Council of Europe. Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law; CETS No. 225; Council of Europe: Strasbourg, France, 2024; Available online: https://rm.coe.int/1680afae3c (accessed on 12 December 2025).
- Van Kolfschooten, H.; Shachar, C. The Council of Europe’s AI Convention (2023–2024): Promises and pitfalls for health protection. Health Policy 2023, 138, 104935. [Google Scholar] [CrossRef]
- Chan, K.J.D.; Papyshev, G.; Yarime, M. Balancing the tradeoff between regulation and innovation for artificial intelligence: An analysis of top-down command and control and bottom-up self-regulatory approaches. Technol. Soc. 2024, 79, 102747. [Google Scholar] [CrossRef]
- Gikay, A.A. Risks, innovation, and adaptability in the UK’s incrementalism versus the European Union’s comprehensive artificial intelligence regulation. Int. J. Law Inf. Technol. 2024, 32, eaae013. [Google Scholar] [CrossRef]
- Lee, J.D.; See, K.A. Trust in automation: Designing for appropriate reliance. Hum. Factors 2004, 46, 50–80. [Google Scholar] [CrossRef]
- Tyler, T.R. Why People Obey the Law; Princeton University Press: Princeton, NJ, USA, 2006. [Google Scholar]
- Fjeld, J.; Achten, N.; Hilligoss, H.; Nagy, A.; Srikumar, M. Principled Artificial Intelligence: Mapping Consensus in Ethical and Rights-based Approaches to Principles for AI; Berkman Klein Center for Internet & Society, Harvard University: Cambridge, MA, USA, 2020; Available online: https://cyber.harvard.edu/publication/2020/principled-ai (accessed on 12 December 2025).
- Matthias, A. The responsibility gap: Ascribing responsibility for the actions of learning automata. Ethics Inf. Technol. 2004, 6, 175–183. [Google Scholar] [CrossRef]
- Floridi, L. Establishing the rules for building trustworthy AI. In Ethics, Governance, and Policies in Artificial Intelligence; Floridi, L., Ed.; Springer: Cham, Switzerland, 2021; pp. 41–45. [Google Scholar] [CrossRef]
- Rushby, J. Understanding and Evaluating Assurance Cases; Contractor Report NASA/CR–2015-218802; NASA Langley Research Center: Hampton, VA, USA, 2015. [Google Scholar]
- Hoekstra, J.; Diker-Vanberg, A. Can AI Tools Enhance Access to Remedies as Envisaged under the UN Guiding Principles on Business and Human Rights: Yay or Nay? A Critical Assessment. Int. Rev. Law Comput. Technol. 2025, 39, 1–22. [Google Scholar] [CrossRef]
- Wachter, S.; Mittelstadt, B.; Russell, C. Counterfactual Explanations without Opening the Black Box: Automated Decisions and the GDPR. Harv. J. Law Technol. 2018, 31, 841–887. [Google Scholar] [CrossRef]
- Ustun, B.; Spangher, A.; Liu, Y. Actionable Recourse in Linear Classification. In Proceedings of the Conference on Fairness, Accountability, and Transparency (FAT* ’19), Atlanta, GA, USA, 29–31 January 2019; Association for Computing Machinery: New York, NY, USA, 2019; pp. 10–19. [Google Scholar] [CrossRef]
- Kroll, J.A.; Huey, J.; Barocas, S.; Felten, E.W.; Reidenberg, J.R.; Robinson, D.G.; Yu, H. Accountable Algorithms. Univ. Pa. Law Rev. 2017, 165, 633–705. Available online: https://scholarship.law.upenn.edu/penn_law_review/vol165/iss3/3/ (accessed on 14 December 2025).
- Yin, R.K. Case Study Research and Applications: Design and Methods, 6th ed.; SAGE Publications, Inc.: Thousand Oaks, CA, USA, 2018; Available online: https://uk.sagepub.com/en-gb/eur/case-study-research-and-applications/book250150 (accessed on 13 December 2025).
- Eisenhardt, K.M. Building Theories from Case Study Research. Acad. Manag. Rev. 1989, 14, 532–550. [Google Scholar] [CrossRef]
- Baxter, G.; Sommerville, I. Socio-technical Systems: From Design Methods to Systems Engineering. Interact. Comput. 2011, 23, 4–17. [Google Scholar] [CrossRef]
- Åström, K.J.; Murray, R.M. Feedback Systems: An Introduction for Scientists and Engineers; Princeton University Press: Princeton, NJ, USA, 2008; Available online: https://authors.library.caltech.edu/records/yzs24-xsx88 (accessed on 13 December 2025).
- Breaux, T.D.; Antón, A.I. Analyzing Regulatory Rules for Privacy and Security Requirements. IEEE Trans. Softw. Eng. 2008, 34, 5–20. [Google Scholar] [CrossRef]
- Otto, P.N.; Antón, A.I. Addressing Legal Requirements in Requirements Engineering. In Proceedings of the 15th IEEE International Requirements Engineering Conference (RE 2007), New Delhi, India, 15–19 October 2007; IEEE: Piscataway, NJ, USA, 2007; pp. 5–14. [Google Scholar] [CrossRef]
- Ghanavati, S.; Amyot, D.; Rifaut, A. Legal Goal-Oriented Requirement Language (Legal GRL) for Modeling Regulations. In Proceedings of the 6th International Workshop on Modeling in Software Engineering (MiSE 2014); Hyderabad, India, 31 May–7 June 2014, Association for Computing Machinery: New York, NY, USA, 2014; pp. 1–6. [Google Scholar] [CrossRef]
- Chaal, M.; Valdez Banda, O.A.; Glomsrud, J.A.; Basnet, S.; Hirdaris, S.; Kujala, P. A Framework to Model the STPA Hierarchical Control Structure of an Autonomous Ship. Saf. Sci. 2020, 132, 104939. [Google Scholar] [CrossRef]
- Pasquale, F. The Black Box Society: The Secret Algorithms That Control Money and Information; Harvard University Press: Cambridge, MA, USA, 2015. [Google Scholar]
- Burrell, J. How the Machine “Thinks”: Understanding Opacity in Machine Learning Algorithms. Big Data Soc. 2016, 3, 1–12. [Google Scholar] [CrossRef]
- Bowen, G.A. Document Analysis as a Qualitative Research Method. Qual. Res. J. 2009, 9, 27–40. [Google Scholar] [CrossRef]
- Purshouse, J.; Campbell, L. Automated Facial Recognition and Policing: A Bridge Too Far? Leg. Stud. 2022, 42, 209–227. [Google Scholar] [CrossRef]
- Urquhart, L.; Miranda, D. Policing Faces: The Present and Future of Intelligent Facial Surveillance. Inf. Commun. Technol. Law 2022, 31, 194–219. [Google Scholar] [CrossRef]
- Cook, C.M.; Howard, J.J.; Sirotin, Y.B.; Tipton, J.L.; Vemury, A.R. Demographic Effects in Facial Recognition and Their Dependence on Image Acquisition: An Evaluation of Eleven Commercial Systems. IEEE Trans. Biom. Behav. Identity Sci. 2019, 1, 32–41. [Google Scholar] [CrossRef]
- Buolamwini, J.; Gebru, T. Gender Shades: Intersectional Accuracy Disparities in Commercial Gender Classification. In Proceedings of the 1st Conference on Fairness, Accountability and Transparency (FAT* 2018), New York, NY, USA, 23–24 February 2018; Friedler, S.A., Wilson, C., Eds.; PMLR, 2018; Volume 81, pp. 77–91. Available online: https://proceedings.mlr.press/v81/buolamwini18a.html (accessed on 6 December 2025).
- Klare, B.F.; Burge, M.J.; Klontz, J.C.; Vorder Bruegge, R.W.; Jain, A.K. Face Recognition Performance: Role of Demographic Information. IEEE Trans. Inf. Forensics Secur. 2012, 7, 1789–1801. [Google Scholar] [CrossRef]
- Hung, T.-W.; Yen, C.-P. Predictive Policing and Algorithmic Fairness. Synthese 2023, 201, 1–29. [Google Scholar] [CrossRef]
- Brauneis, R.; Goodman, E.P. Algorithmic Transparency for the Smart City. Yale J. Law Technol. 2018, 20, 103–176. [Google Scholar] [CrossRef]
- Beach, D.; Pedersen, R.B. Process-Tracing Methods: Foundations and Guidelines, 2nd ed.; University of Michigan Press: Ann Arbor, MI, USA, 2019. [Google Scholar]
- Miles, M.B.; Huberman, A.M.; Saldaña, J. Qualitative Data Analysis: A Methods Sourcebook, 3rd ed.; SAGE: Thousand Oaks, CA, USA, 2014. [Google Scholar]
- Office of the United Nations High Commissioner for Human Rights (OHCHR). Guiding Principles on Business and Human Rights: Implementing the United Nations “Protect, Respect and Remedy” Framework; United Nations: New York, NY, USA, 2011. [Google Scholar]
- Kotsoglou, K.N.; Oswald, M. The Long Arm of the Algorithm? Automated Facial Recognition as Evidence and Trigger for Police Intervention. Forensic Sci. Int. Synerg. 2020, 2, 86–89. [Google Scholar] [CrossRef]
- Bradford, B.; Yesberg, J.A.; Jackson, J.; Dawson, P. Live Facial Recognition: Trust and Legitimacy as Predictors of Public Support for Police Use of New Technology. Br. J. Criminol. 2020, 60, 1502–1522. [Google Scholar] [CrossRef]
- Gikay, A.A. Regulating Use by Law Enforcement Authorities of Live Facial Recognition Technology in Public Spaces: An Incremental Approach. Camb. Law J. 2023, 82, 414–449. [Google Scholar] [CrossRef]
- Lisle, D.; Bourne, M. The Many Lives of Border Automation: Turbulence, Coordination and Care. Soc. Stud. Sci. 2019, 49, 682–706. [Google Scholar] [CrossRef]
- Khan, N.; Efthymiou, M. The Use of Biometric Technology at Airports: The Case of Customs and Border Protection (CBP). Int. J. Inf. Manag. Data Insights 2021, 1, 100049. [Google Scholar] [CrossRef]
- U.S. Government Accountability Office. Facial Recognition: CBP and TSA Are Taking Steps to Implement Programs, but CBP Should Address Privacy and System Performance Issues; GAO-20-568; GAO: Washington, DC, USA, 2020. [Google Scholar]
- U.S. Government Accountability Office. Facial Recognition Technology: CBP Traveler Identity Verification and Efforts to Address Privacy Issues; GAO-22-106154; GAO: Washington, DC, USA, 2022. [Google Scholar]
- Cummings, M.L. Automation Bias in Intelligent Time Critical Decision Support Systems. In Proceedings of the AIAA 1st Intelligent Systems Technical Conference, Chicago, IL, USA, 20–22 September 2004. [Google Scholar] [CrossRef]
- Strategic Subject List—Historical (SSL) Dataset Documentation. Available online: https://data.cityofchicago.org/Public-Safety/Strategic-Subject-List-Historical/4aki-r3np/about_data (accessed on 27 January 2026).
- Ferguson, A.G. The Rise of Big Data Policing: Surveillance, Race, and the Future of Law Enforcement; NYU Press: New York, NY, USA, 2017. [Google Scholar]
- Penney, J.W. Chilling Effects: Online Surveillance and Wikipedia Use. Berkeley Technol. Law J. 2016, 31, 117–182. [Google Scholar]
- Stoycheff, E. Under Surveillance: Examining Facebook’s Spiral of Silence Effects in the Wake of NSA Internet Monitoring. J. Mass Commun. Q. 2016, 93, 296–311. [Google Scholar] [CrossRef]
- Murray, D.; Fussey, P.; Hove, K.; Wakabi, W.; Kimumwe, P.; Saki, O.; Stevens, A. The Chilling Effects of Surveillance and Human Rights: Insights from Qualitative Research in Uganda and Zimbabwe. J. Hum. Rights Pract. 2024, 16, 397–412. [Google Scholar] [CrossRef]
- Zuboff, S. The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power; Public Affairs: New York, NY, USA, 2019. [Google Scholar]
- Woods, D.D. Four Concepts for Resilience and the Implications for the Future of Resilience Engineering. Reliab. Eng. Syst. Saf. 2015, 141, 5–9. [Google Scholar] [CrossRef]
- Perrow, C. Normal Accidents: Living with High-Risk Technologies; Basic Books: New York, NY, USA, 1984. [Google Scholar]
- Van Lamsweerde, A. Requirements Engineering: From System Goals to UML Models to Software Specifications; Wiley: Chichester, UK, 2009. [Google Scholar]
- Hardt, M.; Price, E.; Srebro, N. Equality of Opportunity in Supervised Learning. In Advances in Neural Information Processing Systems, Proceedings of the 30th International Conference on Neural Information Processing Systems; Barcelona, Spain, 5–10 December 2016, Curran Associates Inc.: Red Hook, NY, USA, 2016. [Google Scholar]
- Ovadia, Y.; Fertig, E.; Ren, J.; Nado, Z.; Sculley, D.; Nowozin, S.; Dillon, J.V.; Lakshminarayanan, B.; Snoek, J. Can You Trust Your Model’s Uncertainty? Evaluating Predictive Uncertainty under Dataset Shift. In Advances in Neural Information Processing Systems, Proceedings of the 33rd International Conference on Neural Information Processing Systems, Vancouver, BC, Canada, 8–14 December 2019; Curran Associates Inc.: Red Hook, NY, USA, 2019. [Google Scholar]
- Gal, Y.; Ghahramani, Z. Dropout as a Bayesian Approximation: Representing Model Uncertainty in Deep Learning. In Proceedings of the 33rd International Conference on Machine Learning (ICML), New York, NY, USA, 19–24 June 2016. [Google Scholar]
- Hendrycks, D.; Gimpel, K. A Baseline for Detecting Misclassified and Out-of-Distribution Examples in Neural Networks. arXiv 2017, arXiv:1610.02136. [Google Scholar]
- Hendrycks, D.; Dietterich, T. Benchmarking Neural Network Robustness to Common Corruptions and Perturbations. arXiv 2019, arXiv:1903.12261. [Google Scholar] [CrossRef]
- Amodei, D.; Olah, C.; Steinhardt, J.; Christiano, P.; Schulman, J.; Mané, D. Concrete Problems in AI Safety. arXiv 2016, arXiv:1606.06565. [Google Scholar] [CrossRef]
- Orseau, L.; Armstrong, S. Safely Interruptible Agents. In Proceedings of UAI, Jersey City, NJ, USA, 25–29 June 2016; AUAI Press: Arlington, VA, USA, 2016. [Google Scholar]
- Marusich, L.R.; Bakdash, J.Z.; Zhou, Y.; Kantarcioglu, M. Using AI Uncertainty Quantification to Improve Human Decision-Making. In Proceedings of the 41st International Conference on Machine Learning (ICML), PMLR 2024, Vienna, Austria, 21–27 July 2024; JMLR: Norfolk, MA, USA, 2024; pp. 34949–34960. [Google Scholar]
- Blind, K.; Münch, F. The Interplay between Innovation, Standards and Regulation in a Globalising Economy. J. Clean. Prod. 2024, 445, 141202. [Google Scholar] [CrossRef]
- ISO/IEC 42001:2023; Information Technology—Artificial Intelligence—Management System. International Organization for Standardization: Geneva, Switzerland, 2023.
- ISO/IEC 23894:2023; Information Technology—Artificial Intelligence—Guidance on Risk Management. International Organization for Standardization: Geneva, Switzerland, 2023.
- Cobbe, J.; Veale, M.; Singh, J. Understanding Accountability in Algorithmic Supply Chains. In Proceedings of FAccT; Association for Computing Machinery: New York, NY, USA, 2023. [Google Scholar]
- Post Office Horizon IT Inquiry. Volume 1 of the Post Office Horizon IT Inquiry Final Report; UK Inquiry Report: London, UK, 2025. [Google Scholar]
- European Union. Regulation (EU) 2016/679 (General Data Protection Regulation). Off. J. Eur. Union 2016, L 119, 1–88. [Google Scholar]
- European Commission. When Is a Data Protection Impact Assessment (DPIA) Required? Available online: https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations/obligations/when-data-protection-impact-assessment-dpia-required_en (accessed on 6 January 2026).
- European Commission. AI Act. Available online: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai (accessed on 6 January 2026).
- König, P.D.; Wenzelburger, G. The Legitimacy Gap of Algorithmic Decision-Making in the Public Sector: Why It Arises and How to Address It. Technol. Soc. 2021, 67, 101688. [Google Scholar] [CrossRef]
- Koops, B.-J. The Concept of Function Creep. Law Innov. Technol. 2021, 13, 29–56. [Google Scholar] [CrossRef]
- Grimmelikhuijsen, S.; Meijer, A. Legitimacy of Algorithmic Decision-Making: Six Threats and the Need for a Calibrated Institutional Response. Perspect. Public Manag. Gov. 2022, 5, 232–252. [Google Scholar] [CrossRef]
- Ruschemeier, H.; Hondrich, L. Automation Bias in Public Administration—An Interdisciplinary Perspective from Law and Psychology. Gov. Inf. Q. 2024, 41, 101953. [Google Scholar]
- Binns, R. Algorithmic Accountability and Public Reason. Philos. Technol. 2018, 31, 543–556. [Google Scholar] [CrossRef]
- Strandburg, K.J. Rulemaking and Inscrutable Automated Decision Tools. Columbia Law Rev. 2019, 119, 1851–1885. [Google Scholar]
- Harcourt, B.E. Against Prediction: Profiling, Policing, and Punishing in an Actuarial Age; University of Chicago Press: Chicago, IL, USA, 2007. [Google Scholar]
- Bayamlıoğlu, E. The Right to Contest Automated Decisions under the General Data Protection Regulation: Beyond the So-Called “Right to Explanation”. Regul. Gov. 2022, 16, 1058–1078. [Google Scholar] [CrossRef]
- Christie, J. The Post Office Horizon IT Scandal and the Presumption of the Dependability of Computer Evidence. Digit. Evid. Electron. Signat. Law Rev. 2020, 17, 49–70. [Google Scholar] [CrossRef]




| Feature | Case 1. UK LFR | Case 2. U.S. Border | Case 3: Chicago SSL |
|---|---|---|---|
| Primary failure mode | Sensing-scope (rules) failure | Actuations-gate (control) erosion | Feedback-loop endogeneity |
| Governance deficit | Unbounded watchlisting/siting discretion | Deference under throughput; weak contestability at actuation | Endogenous data generation; weak effectiveness evidence |
| Normative injury | Privacy/legality; foreseeability | Procedural fairness/equity (distributional burdens) | Liberty/fairness via intensified attention |
| Resilience outcome | Legally unstable (judicially invalidated) | Operationally sustained with distributive frictions (“rights debt”) | Institutionally unstable (legitimacy/effectiveness contested) |
| Risk ID | Risk Type | Primary Source | Typical Sources/Mechanisms | Governance Implications | Empirical Grounding |
|---|---|---|---|---|---|
| R1 | Sensing scope and authorization failure | Sensing boundary | Overbroad siting, watchlisting, or data capture without bounded purpose/criteria; open-ended surveillance capacity | Scope-control instruments (purpose limitation, siting and watchlisting rules), activation logs, authorization lineage; audit rights over scope changes | Bridges/LFR as scope-control failure (legality not patchable by accuracy) |
| R2 | Data quality and representativeness risk | Sensing + lifecycle | Skewed/dirty administrative data; non-representative samples; measurement bias | Data provenance, sampling justification, dataset documentation, minimum quality gates; evidence of population validity | Documented in governance literature on data quality and administrative data limits |
| R3 | Privacy/unlawful processing risk | Sensing + rules | Large-scale monitoring, sensitive data processing, weak DPIA/FRIA alignment | DPIA/FRIA (as applicable), lawful-basis mapping, retention and minimization controls; auditable compliance artifacts | EU AI Act lifecycle governance plus FRIA; DPIA practice in data protection regimes |
| R4 | Uncertainty mismanagement (probabilistic authority) | Inference to actuation | Aleatoric/epistemic uncertainty treated as fact; scores become self-executing decisions | Uncertainty measurement; actuation gates linked to uncertainty thresholds (pause/review/verification); adverse action packet includes confidence and basis | Framed in the manuscript as a core cause of legal certainty erosion in stochastic loops |
| R5 | Demographic performance differentials (rights exposure) | Inference to actuation | Differential false negative/false positive rates by group; threshold effects; unequal procedural burden (rights debt) | Mandatory demographic evaluation; threshold governance tied to disparity tests; remedial controls (review triggers, alternative verification, monitoring) | NIST FRVT as empirical anchor for demographic differentials in face recognition performance |
| R6 | Model validity/specification mismatch | Inference | Model trained for one context used in another; proxy targets for legally relevant standards | Task/construct validity review; intended-use constraints; periodic re-validation and documentation | Observed across high-consequence ML deployments when constructs and legal standards diverge |
| R7 | Drift/dataset shift/out-of-distribution degradation | Lifecycle (operations) | Performance decay as environment changes; previously valid evidence becomes stale | Post-deployment monitoring, drift triggers, evidence-refresh rules, controlled rollback; assurance case updated as a living artifact | Recognized in operational ML as a recurring failure mode; addressed via monitoring and change control |
| R8 | Actuation-gate erosion (automation bias) | Actuation + human factors | Operators defer to alerts/scores under tempo; human-in-the-loop becomes rubber stamp | Meaningful human control evidenced in workflow traces: time-to-review, override authority, second checks, justification logging | Human–automation interaction research on automation bias; operational border/security workflows |
| R9 | Due-process/contestability failure (black box tribunal) | Actuation + governance | No notice, no reasons, weak appeal/correction pathways; opaque evidence | Contestability-by-design: adverse action packets, reasons-giving, appeal channels, correction SLAs; auditable recourse records | Common governance failure in high-friction public decisions shaped by automated inferences |
| R10 | Feedback endogeneity/runaway reinforcement | Feedback loop | Interventions change what gets observed; discovered data treated as objective truth; self-reinforcing patrol/attention | Feedback-discrimination protocol: separate enforcement intensity from risk; monitor endogeneity; constrain retraining inputs | Predictive policing literature; Chicago SSL used as an archetype of feedback-loop failure |
| R11 | Auditability and traceability failure (evidence gaps) | Lifecycle + oversight | Missing logs/versioning; cannot reconstruct decisions; evidence not inspectable | Audit-ready event record: model/version ID, monitoring status, authorizing rule/constraint, human action record; retention and access | Audit practice and governance baselines emphasize traceability; discussed in the manuscript |
| R12 | Update/change-control discretion leak | Supply chain + lifecycle | Vendor/integrator changes thresholds/models/features as de facto policy changes | Change-control governance: materiality thresholds, approval workflows, evidence refresh, external audit rights for updates | Observed in multi-actor service models; highlighted as discretion migration into configuration |
| R13 | Accountability diffusion (multi-actor supply chain) | Supply chain + rules | Cloud/model provider/integrator/deployer split responsibilities; no one holds evidence | Contract for evaluation access, audit rights, telemetry/logging, exit/portability; named responsibility matrix | Supply-chain governance literature; procurement leverage emphasized in the manuscript |
| R14 | Governance-washing (non-enforceable controls) | Rules and institutions | Principles without verifiable criteria; ethics statements substitute for enforceable evidence | Bind claims to evidence via 3R Assurance Case (GSN); enforceability primitives (conformity assessment, post-market monitoring) | NIST AI RMF and EU AI Act provide baselines; assurance-case approach operationalizes them |
| R15 | Legitimacy collapse/chilling effects as systems risk | Population-level feedback | Opacity and unfair burdens reduce cooperation; adversarial adaptation; trust erosion degrades system inputs | Treat legitimacy as a design requirement: transparency, contestability, bounded scope, auditability; monitor trust proxies | Socio-technical governance literature; framed as destabilizing feedback in the manuscript |
| Claim Family | Claim (Short) | Claim Role | Evidence Tier(s) | Strength | Transferability | Key Limitations/Boundary Conditions | Primary Anchors in Paper |
|---|---|---|---|---|---|---|---|
| Systems-theoretic framing | Rights breaches should be treated as control failures at the actuation boundary (system-level, not model-only). | Conceptual + methodological | Tier 2 + Tier 1 (case mechanism tests) | Moderate → Strong (case-dependent) | High (design principle); medium (implementation details) | Strength increases when actuation pathways and safeguards are documented; weaker when internal decision logic is inaccessible. | STPA/STAMP + CPS-Governance Mapping Protocol; replication logic across cases. |
| Uncertainty and legal certainty | Uncertainty must be operationalized and linked to actuation gates to avoid ‘confident form, fragile substance’. | Conceptual + methodological | Tier 2 + Tier 3 + Tier 1 (where available) | Moderate | High (general); medium (threshold selection) | Operational thresholds depend on task, harm severity, and workflow tempo; requires monitoring and override evidence. | Uncertainty literature + actuation-gate requirements; audit-ready event record. |
| Biometrics disparity | Demographic error differentials in face recognition can create differential rights exposure in policing/border workflows. | Empirical (benchmark) + governance implication | Tier 2 (benchmarks) + Tier 1 (governance records) | Strong (existence of differentials); Moderate (downstream magnitude) | Medium | Magnitude depends on population, sensing conditions, thresholds, and downstream intervention design; requires context-specific testing. | NIST FRVT + peer-reviewed disparity studies; case linkage to escalation workflows. |
| Predictive policing feedback | Actuation reshapes the data-generating process, producing runaway feedback and endogenous evidence in enforcement allocation. | Empirical (mechanism) | Tier 2 + Tier 1 (where documented) | Strong (mechanism); Moderate (local magnitude) | Medium | Severity depends on coupling between enforcement intensity and recorded incidents; retraining practices and feature design. | Runaway feedback loop studies; ‘dirty data’ and civil-rights implications literature. |
| HITL and accountability | Human-in-the-loop can be a governance fig leaf under automation bias; accountability can collapse onto operators. | Empirical (human factors) + governance implication | Tier 2 + within-case tracing | Strong (bias tendency); Moderate (operational rates) | High (risk class); medium (severity) | Depends on workload, UI design, incentives, and time pressure; must be evidenced in workflow traces. | Automation bias literature; ‘moral crumple zone’; process tracing of actuation pinch points. |
| Auditability as governance variable | If evidence cannot be audited (logs/versioning/provenance missing), governance fails; opacity is a governance finding. | Methodological | Tier 1 + Tier 3 | Moderate → Strong | High | Trade secrecy and access constraints can block diagnosis of internal causes; mitigated by evidentiary deltas and counterfactual assurance. | Evidence hierarchy section; assurance-by-evidence; audit-ready architecture requirements. |
| 3R Assurance Case operationalization | A 3R Assurance Case (GSN) translates rights and legal rules into auditable claims, assumptions, and evidence across lifecycle control points. | Methodological (implementation artifact) | Tier 3 + Tier 2 (assurance practice) | Moderate | High | Effectiveness depends on enforceable procurement/audit rights and keeping the artifact live under drift and updates. | NIST AI RMF + EU AI Act lifecycle logic; GSN assurance-case method; post-market monitoring hooks. |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Niazi, M.; Hassani, H.; Lee, M. Rights-Based AI in Cyber–Physical Systems: A Governance Framework for Socio-Technical Resilience and Trust. Automation 2026, 7, 96. https://doi.org/10.3390/automation7030096
Niazi M, Hassani H, Lee M. Rights-Based AI in Cyber–Physical Systems: A Governance Framework for Socio-Technical Resilience and Trust. Automation. 2026; 7(3):96. https://doi.org/10.3390/automation7030096
Chicago/Turabian StyleNiazi, Maral, Hossein Hassani, and Madison Lee. 2026. "Rights-Based AI in Cyber–Physical Systems: A Governance Framework for Socio-Technical Resilience and Trust" Automation 7, no. 3: 96. https://doi.org/10.3390/automation7030096
APA StyleNiazi, M., Hassani, H., & Lee, M. (2026). Rights-Based AI in Cyber–Physical Systems: A Governance Framework for Socio-Technical Resilience and Trust. Automation, 7(3), 96. https://doi.org/10.3390/automation7030096

