Structural precondition

Corrigibility

The structural precondition for public infrastructure that can be corrected by the people it governs.

Five jointly necessary tests — EXIT, CODE, AUDIT, GOVERN, FORK — close a corrective feedback loop. Removing any one opens the loop, and correction becomes discretionary.

Free · CC0 1.0 · open access

Thesis

Digital Public Infrastructure is not merely a collection of software stacks; it is the encoding of political arrangements into technical artifacts. Because these systems apply fixed rules to the infinite variety of human life, they will inevitably misclassify, exclude, or fail specific users. The critical question is not whether errors occur, but whether the architecture permits those affected to detect, correct, and reverse them before harm becomes permanent.

Paper I · Introduction

The framework is governance-agnostic but politically pointed. Systems promoted globally as model DPI — Aadhaar, UPI, large parts of the India Stack export agenda — fail one or more of the five tests when measured structurally. Systems that already run the world — Linux, Kubernetes, the Web — pass them. The framework is the apparatus that makes that comparison falsifiable rather than rhetorical.

The invariant

What the invariant guarantees

Corrigibility guarantees the architectural capacity for affected participants to detect error, signal harm, and trigger correction. Five conditions form a closed corrective loop; the failure of any one converts the system to open-loop, in which errors accumulate without bound.

Fatal failure Partial compliance is functionally equivalent to complete failure.
  1. Observability Sensor Errors are detectable. CODE·AUDIT
  2. Participation Error signal The affected can refuse. EXIT
  3. Constraint Actuator Correction is binding. GOVERN
  4. Replacement Selection The loop can be reproduced. FORK

Figure 1 · Four control layers form a closed feedback loop.

Cybernetics

Ashby’s Law of Requisite Variety (1956): a controller needs variety matching the system it regulates. Where it does not, regulation has failed.

Commons governance

Ostrom’s constitutional constraint: rules that the people bound by them can modify.

Free software

The right to reproduce — the freedom to fork is what makes replacement more than a threat.

The five conditions are derived from these three, not asserted. Paper I, §3.

The tests

Jointly necessary, individually insufficient

Each test is stated formally, then verified differently for deterministic (DPI) and learned (EPI) infrastructure.

EXIT

§
Reversibility of Participation
∀ user state s ∈ S, ∃ transition s → s₀ such that the exit penalty π(s → s₀) < τ_exit

Users must possess the capacity to withdraw without disproportionate penalty. Irrevocable consent functions structurally as mandatory lock-in — when a system becomes a prerequisite for existence, refusal stops being feedback and becomes a survival penalty.

DPI
A non-digital path achieves equivalent outcomes — cash for payments, paper ID for identification.
EPI
A human fallback is guaranteed and accessible; automated decisions can be opted out of.
Failure
Aadhaar — opting out cuts off banking, rations, connectivity. The penalty is existential.

CODE

§
Inspectability of Logic
For any decision function f: X → Y, ∃ a publicly accessible artifact A_f specifying f(x) ∀ x ∈ X

Power in a digital system resides in execution. If the execution path is hidden, that power is not merely unaccountable; it is structurally unobservable to those it governs.

DPI
Source, schemas and rule definitions are publicly inspectable — executable artifacts, not open-standards branding.
EPI
LWD-R disclosure — Logic, Weights, Data, Representation.
Failure
Open weights with proprietary training data; ontological capture where the categories are non-contestable.

AUDIT

§
Independent Verification
∀ external party P, Access(P, ε_S) = true without Authorize(Operator, P)

Inspection enables understanding; verification enables truth. A system is verifiable only if external, permissionless actors can test its behaviour and measure error rates in production — without asking the operator first.

DPI
Production endpoints can be probed; logs accessible; error rates publishable by third parties.
EPI
Statistical bounds monitored continuously; variety drift measured; red-teaming permitted.
Failure
Audit theatre — operator-controlled certification that yields a stamp without independent measurement.

GOVERN

§
Constitutive Constraint
∃ G: Rules → Rules′ that is (1) accessible to affected parties, (2) binding on the operator, (3) chained in custody

Verification identifies error; constitutive constraint enforces correction. Consultations, multi-stakeholder forums and feedback portals do not satisfy GOVERN unless their output binds the operator.

DPI
A binding RFC process with chain of custody — IETF, W3C, Linux kernel maintainership.
EPI
The Action Boundary Protocol — a deterministic envelope around stochastic inference.
Failure
GDoS — agentic systems acting faster than governance can review.

FORK

§
Independent Reproduction
∃ S′ instantiable by an independent party, with public artifacts and portable state U_S → U_S′

The ultimate check on power is the ability to recreate it. LibreOffice, MariaDB, OpenSearch and Valkey all emerged when governance variety collapsed. Natural barriers do not disqualify; only constructed barriers do.

DPI
Code, schemas, protocols and user state are portable; competition is not legally prohibited.
EPI
The training pipeline is reproducible — compute, data and pipeline access are not gated by capital asymmetry alone.
Failure
Compute capture — open weights without affordable retraining make FORK theoretical.

Why partial compliance fails

Two results in Paper I do the structural work. They are why a system can satisfy four tests and still operate open-loop, and why publishing an artifact is not the same as opening a loop.

Weakest-layer principle

Corrigibility is the minimum across layers, not the average

A system’s corrigibility status equals its weakest layer across any test dimension. Strength at one layer cannot compensate for failure at another.

This is what open-washing exploits. Releasing SDKs passes CODE at the interface layer while core logic stays proprietary — failing CODE at the execution layer. That is not partial corrigibility; it is total failure at the layer that determines outcomes, and it propagates to the system verdict.

Post-execution fallacy

Grievance is not feedback

Courts, ombudsmen and grievance officers operate on bureaucratic time, measured in months. Infrastructure operates on digital time, measured in milliseconds. A system that wrongly deletes a beneficiary and relies on a court order six months later is structurally ungoverned for that duration.

Channels that record dissatisfaction without a binding mechanism to modify execution are not a feedback loop — the paper calls them roach motels for complaints. Governance has to function inside the execution loop, blocking prohibited states before they manifest, and its claims must be evidentiary rather than declarative.

The absence is not peculiar to one system. Paper I records that the World Bank’s digital-wallet policy notes — the series specifying the coming decade’s identity substrate — contain no subject-corrective vocabulary at all: redress, grievance, appeal, recourse, contestation and correction appear nowhere in either architectural note, while issuer-side revocation recurs throughout.

Evidence

The tests return verdicts, not opinions

Paper I applies the five tests across three categories: government systems promoted as DPI, platform infrastructure claiming openness, and infrastructure that satisfies all five. The evaluations assess governance architecture, not operational performance — a system can be simultaneously useful and incorrigible.

Government infrastructure

Systems designated as DPI exhibit a consistent failure mode: partial compliance on the technical tests — EXIT, CODE, AUDIT — while failing structurally on GOVERN and FORK. By holding a monopoly on execution, they render the feedback loop inoperable.

Platform infrastructure

Technical openness does not produce accountability. Open weights, open protocols and open standards can each mask a closed correction loop.

The artifact is open. The correction loop is closed. Seeing the machine does not govern it.

Eighteen systems pass all five

Paper I · Table 6
Linux Kernel
Linux Foundation
Let’s Encrypt
ISRG
Wikipedia
Wikimedia Foundation
Matrix Protocol
Matrix.org Foundation
Bluesky · AT Protocol
Bluesky PBC
PostgreSQL
PGDG
IPFS
Protocol Labs
Bitcoin
Decentralised
Kubernetes
CNCF
Firefox
Mozilla Foundation
Apache HTTP
Apache Foundation
Apache Kafka
Apache Foundation
OpenSearch
Linux Foundation
Valkey
Linux Foundation
Hyperledger
LF Decentralized Trust
LibreOffice
Document Foundation
MariaDB
MariaDB Foundation
Eclipse IDE
Eclipse Foundation

A pattern emerges that the framework does not flatter: these systems are predominantly non-essential. No individual’s survival depends on reaching Linux or Let’s Encrypt. The correlation between corrigibility and non-essentiality is structural, and it is the problem the political economy half of the paper is written to explain.

Action research

Adversarial intervention in deployed systems

The method is action research: the review proceeds through an intervention in the system being studied. Conducted while an operator is defending that system, it yields different evidence from a cooperative review — trust boundaries are stated under pressure, and every claim meets a counter-claim. Two of these were reviewed through public technical work; the third continued in a forum that binds the operator, which is the route left when inspection is refused.

Identity infrastructure2010 – 2018

Aadhaar

Reviewed the authentication path, the federation of consumer portals around it, and the gap between a voluntary design and the mandates issued downstream. Parts of this review were prepared for counsel in the Aadhaar proceedings, where I was not a party.

The failure sat at the trust boundary.
Numbers surfaced through federated government portals rather than through the core registry — an integration-layer exposure that the operator's own denials did not address. CODE · AUDIT
Enrolment became a precondition of service.
University, school and municipal systems made enrolment a precondition of service, which is the exit penalty the framework names, and it is visible only in deployment. EXIT

Reporting indexed on In the Media — 2017, filed under Aadhaar.

Payment infrastructure2017 – 2018

UPI · BHIM

Reviewed the client permission surface, the consent terms, and what an identifier alone was sufficient to authorise, while the rollout was under way.

An identifier was enough to bind a payment.
A one-rupee transfer demonstrated that a published Aadhaar number resolved to a live account — the number belonged to the then TRAI chairman, who had published it as a challenge and was reported to be unaware of the binding. AUDIT
The permission surface exceeded the stated function.
The permission surface requested capabilities the stated function did not require, under terms whose obligations could not be read off the document. CODE · EXIT

Also taught as security review — Observer Research Foundation, 2017.

Contact-tracing infrastructure2020 – 2021

Anivar A Aravind v. Ministry of Home Affairs & Ors.

Number
[W.P No. 7483 of 2020]
Forum
Karnataka High Court
Subject
Aarogya Setu, Data Protection, Privacy
Respondents
Union of India · NIC
Filed
2020
Order
Jan 2021 · data sharing restrained
Legal support
SFLC.in · Human Rights Law Network

The authority is the court record; this page is a pointer to it.

Case record ↗
What it established

Findings that bind the operator, which a design review cannot produce.

Data sharing was restrained.
In January 2021 the Union and NIC were restrained from sharing application data with other parties without user consent — a constraint the operator is held to. GOVERN
The mandate was narrowed on the record.
India was the only democracy to make its contact-tracing app mandatory (MIT Technology Review, May 2020); the claim that installation was compulsory for metro travel did not survive the proceedings. EXIT
A partial release leaves the decision path unobservable.
A client-side publication with the server side withheld leaves the decision path unobservable — the failure mode CODE names, argued against a live system rather than in the abstract. CODE · AUDIT

Contemporaneous reporting is indexed on In the Media — 2020–21, filed under Aarogya Setu.

Papers

Paper I establishes the invariant for deterministic infrastructure. Paper II extends it to learned and agentic systems. Both are now indexed on SSRN.

Paper I · DPI54 pp. · rev. 11 Jul 2026

Corrigibility as a Structural Precondition for Digital Public Infrastructure: A Cybernetic Framework

DPI is currently evaluated by aspirational criteria — interoperability, inclusion, openness, scale — that do not establish whether systemic errors can be corrected by affected participants. Five jointly necessary conditions form a closed corrective loop, derived from control theory, commons governance and free software, and formalised by control-topology mapping.

Corrigibility does not guarantee fairness. It guarantees reversibility.

CyberneticsCommonsFOSS

SSRN
10.2139/ssrn.6059075
Abstract
ssrn.com/abstract=6059075
Released
April 2026
Read PDF
Paper II · EPI37 pp. · rev. 11 Jul 2026

Epistemic Capture and the Action Boundary: Corrigibility for Learned and Agentic Public Infrastructure

Three structural pressures constrain corrigibility in learned systems: opacity of inference, requiring LWD-R disclosure — logic, weights, data, representation; concentration of training resources, or compute capture; and acceleration of automated action, a governance denial of service. The Action Boundary Protocol separates probabilistic inference from deterministic execution.

The invariant holds under stochastic verification.

LWD-RAction BoundaryVariety Drift

SSRN
10.2139/ssrn.6669318
Abstract
ssrn.com/abstract=6669318
Released
April 2026
Read PDF
Cite

How to cite

Both papers are CC0 1.0. The SSRN identifier is the primary citation.

ORCID
0009-0009-8995-0005
Paper I — DPI · BibTeX
@article{aravind2026corrigibility,
  title   = {Corrigibility as a Structural Precondition for
             Digital Public Infrastructure: A Cybernetic Framework},
  author  = {Aravind, Anivar A.},
  year    = {2026},
  url     = {https://github.com/anivar/corrigibility-framework},
  doi     = {10.2139/ssrn.6059075},
  license = {CC0-1.0},
  orcid   = {0009-0009-8995-0005}
}
Paper II — EPI · BibTeX
@article{aravind2026epi,
  title   = {Epistemic Capture and the Action Boundary:
             Corrigibility for Learned and Agentic Public Infrastructure},
  author  = {Aravind, Anivar A.},
  year    = {2026},
  url     = {https://github.com/anivar/corrigibility-framework},
  doi     = {10.2139/ssrn.6669318},
  license = {CC0-1.0},
  orcid   = {0009-0009-8995-0005}
}