Why Black Boxes Are a Governance Failure
A loan is denied, and the applicant is told nothing beyond "risk model." The loan officer cannot explain the decision because the basis for the outcome is unavailable in any form that supports review. The applicant has no recourse because there is nothing concrete to contest.
Most automated decision systems work this way. Inputs go in, outcomes come out, and the basis for judgment stays locked inside.
The Governance Problem
When the basis for a decision is unavailable, accountability collapses into ceremony: someone signs off, someone takes the call, but they are not responsible for the decision — they are responsible only for trusting the system that made it. The system cannot be questioned. The person can. This transfers liability from the process to the operator, who becomes the last line of defense for a decision they cannot review, cannot justify, and cannot meaningfully challenge.
*Reviewability*, as I use the term here, means the ability to understand the basis for a system outcome in a form that supports policy and oversight. Without that capacity, oversight is a label rather than a function.
Quiet Failure Modes
What matters about system failure is whether it can be seen, understood, and corrected. In black-box systems, failure modes are quiet. They do not announce themselves. They accumulate. A subtle drift in decision patterns. A gradual overweighting of one factor. A slow exclusion of a population that was never explicitly filtered. These failures do not trigger alarms. They persist until someone notices — if anyone ever does.
Errors, you can fix. Hidden decisions compound — each one slightly off, each one building on the last, until the cumulative drift is systemic and the original cause is buried under months of uncorrected outputs.
Reviewability as Civic Infrastructure
Certain systems have crossed a threshold. They make decisions about people, resources, access. They allocate power. Any system that allocates power without explanation is exercising authority without consent, and that is a governance failure regardless of how sophisticated the model is.
Reviewability should be table stakes for any system allocating public resources. If you cannot examine the basis for an outcome, you cannot meaningfully challenge it — and a decision that cannot be challenged is just an edict.
Decision Flow: With vs. Without Inspection
Two models side by side. In the opaque version, a request enters the system and a result exits. The path between them is unknowable, errors are invisible, and accountability is performative. In the governed version, the same request passes through checkpoints that support explanation, challenge, and correction.
The governed model matches the opaque one in speed and capability. The difference is that its decisions can be read in public terms.
Modern systems must be built to answer for themselves, because decisions that affect people get challenged. If you cannot explain the basis for an outcome in terms operators and affected people can challenge, you do not have accountability. You have a rubber stamp.
The bar: if your system makes decisions about people, make those decisions explainable and contestable. Anything less is decoration.