Open letter · Version 1.0 · September 2026

The Machine
Authority
Doctrine

Nine articles on the conditions under which an autonomous system may legitimately exercise consequential power.

Intelligence does not imply authority.
Drafted in Turin · Open to signature, amendment and dissent01 — 09

A doctrine in public

Read it as an argument, not an instruction.

  1. 01Why we wrote this
  2. 02What this doctrine is
  3. 03Preamble
  4. 04The nine articles
  5. 05The test
  6. 06Signing, amending and dissenting

01 — The letter

Why we wrote this

We are engineers. Some of us study at the Politecnico di Torino. Some of us build and sell the systems this document is about. Most of us are in our twenties, which means we will spend our working lives inside whatever gets built in the next ten years.

We did not set out to write a declaration. We set out to build a company that makes it safe to let software act on its own, and we kept running into the same gap. Anyone can tell you what an AI system is capable of. Almost nobody can tell you what it is permitted to do, who permitted it, on whose behalf, or how that permission ends.

That gap is not closing. Systems become more capable every quarter. The rules governing what they may do are still written as intentions — as instructions to a model, as policies in a document, as an expectation that someone will be watching. We have sat in enough reviews to know how little of that survives contact with a system acting at speed, unattended, across other people's infrastructure.

We recognise the two forces that usually fill a gap like this one, because both are already visible.

Fear produces rules written after a disaster, in a hurry, by people who do not understand the technology, and which over-correct in ways that damage exactly the uses worth having. Greed produces deployments that outrun anyone's ability to supervise them, justified afterwards by the observation that nothing has gone badly wrong yet. Each has happened before in other industries. Waiting for one to arrive and then arguing about the other is not a plan.

We do not think we are the right people to settle this. We are not a regulator, a university department, or a standards body. Nobody elected us, we claim no mandate, and this document carries no authority beyond whatever its arguments earn. What we have is a narrow technical problem we work on daily, a view of it from inside real deployments, and an unwillingness to keep waiting for someone better placed to write down what seems obvious from here.

So we wrote it down, as precisely as we could, in a form that can be argued with.

What follows is nine articles on when an autonomous system may legitimately exercise power over people, money, infrastructure and information. They are drafted to be testable: a real deployment either satisfies an article or it does not, and the nine questions at the end are how you find out. They are drafted to be neutral: they name no product and no vendor, including ours. And they are drafted to be contested: the most useful thing anyone can do with this document is show us where an article is wrong.

If it holds up, it should not remain ours. A doctrine that belongs to one company is marketing. We would rather it belonged to everyone willing to sign it, and to everyone willing to improve it.

The initial drafting group

Amir [surname]Founder and Chief Executive, Compex · Computer Engineering, Politecnico di Torino
Iftekhar AnwarCo-founder and Chief Technology Officer, Compex
Luca PulvirentiCo-founder and Chief Operating Officer, Compex
[Name]Academic affiliation — reserved for an initial academic signatory

Turin, September 2026. The drafting group is open; see Drafting at the end of this document.

02 — Scope

What this doctrine is

For what purpose

To state, precisely enough to be tested, the conditions under which an autonomous system may legitimately exercise consequential power; to give the people who build, buy, supervise and regulate such systems a common set of numbered questions to ask of any deployment; and to open an argument that is currently happening in private, in procurement reviews and security committees, where it cannot be examined.

Of what

Nine articles, each stating a principle and the consequence of its absence. They concern authority: its source, its boundaries, its duration, its withdrawal, and the evidence of its exercise. They do not concern whether a system's judgments are accurate, fair or well-calibrated. Those are necessary questions and they are addressed well elsewhere. This document addresses a different one: whether the system was permitted to act at all, and whether anyone can still stop it.

The articles are not ranked. Their order is expository, not hierarchical. They are intended to be read together, and an interpretation that satisfies one article by defeating another is not a valid interpretation.

For whom

For anyone who deploys autonomous systems into consequential settings, and for anyone subject to them. In practice that means engineers and the people who direct them; institutions buying systems they cannot inspect; supervisors, auditors and insurers asked to accept those systems; legislators writing the rules that will govern them; and the people whose money, care, liberty or livelihood those systems will touch without their ever having agreed to it.

Signing does not require that an organisation already satisfies these articles. Very few do. It requires only that it considers them a reasonable standard to be measured against.

By what method

Honestly: this version was written by a small group of practitioners over a short period, without a deliberative process, public consultation or institutional mandate. We say so plainly because the alternative — implying a legitimacy we have not earned — would contradict the document's own argument.

The deliberation is what we are opening now. Version 1.0 is a proposal put into public view so that it can be attacked by people with standing we lack: lawyers, regulators, civil-liberties organisations, security practitioners, academics, and the competitors of the company that drafted it. Whatever legitimacy this document eventually has will come from that process and not from its authors.

What happens after

The articles will be versioned in public. Accepted amendments will be recorded with attribution and a note of what changed and why. Reasoned dissent will be published alongside endorsement rather than filtered out of it. A separate technical specification may follow, describing how these articles can be satisfied in practice; it will be licensed so that anyone can implement it, and conformity to it will not be certified by anyone who sells an implementation of it.

03 — Preamble

Authority is the question

This is not an argument for weak artificial intelligence.

Democratic governments should be able to investigate serious crime. Banks should be able to stop fraud. Clinicians should be able to use powerful medical systems. Companies should be able to automate complex work. Societies should benefit from increasingly capable intelligence, and they should not be asked to choose between capability and accountability.

The question is not whether intelligence should have power. The question is how that power becomes legitimate authority.

Artificial intelligence is no longer only a means of producing information. It investigates, decides, transacts, communicates, writes and deploys software, reaches private records, and operates infrastructure — increasingly on behalf of governments, institutions and individuals, and increasingly without a person watching.

A capable system connected to consequential systems is not merely software. It is delegated power. Data determines its reach: access to financial records, clinical information, communications, biometrics, movement histories, public registers and critical infrastructure transforms what an intelligent system is able to do, and to whom.

Societies have long understood that dangerous capability cannot rest on good intentions alone. We place limits around weapons, financial authority, policing powers, clinical practice and classified information. We require identity, purpose, authorization, proportionality, oversight and accountability. We do this not because we assume bad faith, but because consequence at scale demands structure regardless of faith.

Digital intelligence should not be the exception.

What has changed

Human institutions of oversight were built on an assumption that no longer holds: that a person acts, someone notices, and oversight responds in time to matter.

An autonomous system can complete a thousand consequential actions before a human reads the first. Review after the fact remains necessary, but it has stopped being sufficient. When execution is faster than oversight, legitimate authority must be encoded before execution rather than reconstructed afterward.

The defining governance problem of autonomous intelligence is therefore no longer only whether a system decides well. It is whether the infrastructure around it permits it to turn decisions into consequences beyond the authority society actually granted.

From this follows a single principle, and from that principle, nine articles.

04 — The articles

Nine limits for consequential power.

Read together, not as a menu. An interpretation that satisfies one article by defeating another is not valid.

Article I

Authority has a source

No consequential autonomous action is legitimate unless it traces to an identifiable principal with the standing to grant it.

A credential is not a principal. Possession of a key, token, account or session establishes only that a system can act, never that anyone entitled to authorize it did so. Where the chain from an action back to a human or institutional principal cannot be reconstructed, the action was unauthorized — whether or not it succeeded, and whether or not it was intended.

Article II

Intelligence cannot authorize itself

The system exercising authority may not create, expand, or override the authority under which it acts.

Authority is not validly established where its validity rests solely on a mechanism the constrained actor controls — including the ability to amend the policy, hold the keys that release capability, disable the enforcement path, or alter the record. This is a question of control, not of corporate identity: the test is who can override the constraint, not whose name is on it.

Instruction is not constraint. A limit expressed to a system through the same channel as its task is a request. A limit is something the system cannot exceed even when it tries.

Article III

Authority is bounded

Authorization extends only to defined actions, resources, purposes and limits. Technical access is not authority.

The ability to reach a system, dataset or function establishes nothing about permission to use it. Unrestricted access cannot be justified on the ground that some uses of that access would be legitimate. Where the boundary of an authorization cannot be stated before the system acts, no authorization has been granted.

Article IV

Authority expires and can be withdrawn

Authority that cannot be withdrawn is not delegated. It is transferred.

Delegated machine authority carries a duration and a means of revocation that takes effect in the time the system takes to act, not the time an organization takes to respond. Revocation slower than the action it is meant to stop is not revocation.

Standing, durable privilege as the default condition of an autonomous system is a transfer of power, whatever it is called in the contract.

Article V

Authority does not generalize

Authorization directed at a person, event, resource or defined class does not extend beyond it.

Lawful grounds to observe, investigate or act upon a defined subject do not by themselves justify observation of, access to, or action upon those outside that subject. That some exercises of a capability are legitimate does not establish the legitimacy of its full reach.

Where an authorization is broad because no boundary was drawn, it is not broad. It is unbounded.

Article VI

Consequence sets the threshold

The strength of authorization required rises with the consequence of an action, not with the sophistication of the system performing it.

Irreversibility, scale, and effect on people set the bar. Actions that cannot be undone, that affect many at once, or that determine a person's access to money, care, liberty or livelihood require narrower scope, stronger authorization and independent approval than actions that can be reversed.

Capability does not lower this threshold. A more capable system is a reason for more scrutiny, not less.

Article VII

Constraint must precede execution

Where action outpaces oversight, limits must be enforced before execution rather than reconstructed after it.

Retrospective logging, periodic audit and approval-by-exception are instruments of learning and of redress. Where an autonomous system can complete thousands of consequential actions before a human can examine one, they do not constitute oversight of those actions.

Governance that depends on someone noticing in time has, at machine speed, assumed the very thing it was meant to provide.

Article VIII

Evidence must be independent of the actor

Consequential machine action must produce a record that the actor cannot unilaterally write or alter.

A system's account of its own conduct is testimony, not evidence. A record held solely by the party whose conduct is in question is not independent of that party. Where the only proof of what an autonomous system did originates with that system, or with those answerable for it, nothing has been verified.

Independence of integrity is not the same as publication. A record must be one the actor cannot rewrite; who may read it remains a matter for law, contract and the legitimate interests of those affected.

Article IX

Revocation cannot be delegated away

No arrangement may remove the legitimate governing institution's ability to suspend or terminate delegated machine authority.

The power to withdraw authority is not itself delegable — neither to the system, nor to any party whose interest lies in that authority continuing. An architecture in which a system cannot be halted without its own cooperation has not bounded that system's authority. It has surrendered it.

This floor holds regardless of how capable, reliable or valuable a system has become. It holds most strictly when the system is most capable.

05 — The test

Nine questions, in order

A deployment can be examined against this doctrine.

  1. Who granted the authority, and did they have standing to grant it?
  2. Can the system expand, weaken or bypass the authority it holds?
  3. What actions, resources and purposes does the authorization cover — stated before execution?
  4. When does it expire, who can revoke it, and how fast does revocation take effect?
  5. Does an authorization over one subject reach subjects outside it?
  6. Does the required approval rise with irreversibility, scale and effect on people?
  7. Are the limits enforced before execution, or only reviewed afterward?
  8. Who controls the record, and can the party being evaluated alter it?
  9. Can the governing institution stop the system without the system's cooperation?

Where these questions have no clear answer, the deployment fails the doctrine. Failing it is not an accusation of bad conduct. It is a statement that the conditions for legitimate machine authority are not present, and that whether the system behaves well is, for the moment, a matter of luck rather than design.

06 — Commitments

What the drafters hold themselves to

A doctrine addressed only to others is an opinion. These are the obligations the drafting group accepts for itself, and which any organisation signing as a drafter accepts on the same terms.

  1. We will test our own systems against these nine articles and publish where they fail, identifying the article and the failure rather than the summary.
  2. We will not claim conformity we cannot demonstrate to a party that does not work for us.
  3. We will keep the articles free to read, cite, implement and republish, with no licence fee, and we will not operate a conformity certification that only we can grant.
  4. We will publish reasoned dissent alongside endorsement, including dissent that damages our commercial position.
  5. We will version this document in public and record what changed, why, and at whose suggestion.
  6. We will treat a more complete implementation of these articles by another party, including a direct competitor, as a success of the doctrine rather than a loss to us.

The sixth commitment is the one most likely to be tested, and it is the one by which the seriousness of this document can be judged.

07 — Participation

Signing, amending and dissenting

This doctrine has no force. It acquires whatever weight it comes to have from the number and seriousness of the people and institutions willing to put their names to it, and from the quality of the objections it survives.

What signing means — and what it does not

Signing means you consider the nine articles a reasonable standard against which the legitimacy of machine authority should be measured, and that you are willing to be publicly associated with that position.

Signing is not a claim that you, your employer, or your systems currently satisfy the articles. Almost nothing deployed today does. It is not an endorsement of any product, including those of the company that initiated this text. It creates no legal obligation and confers no certification.

Signatories may withdraw at any time, without explanation, and the register will reflect that.

Register I — Individuals

Open to anyone: engineers, researchers, students, lawyers, clinicians, public servants, and people with no technical background who will live under these systems. Name and, optionally, affiliation and country. Affiliation is recorded as context, never as institutional endorsement.

Participation details to be published

Register II — Organisations

Open to companies, universities, public bodies, professional associations and civil-society organisations. Requires a named signing officer with the standing to sign on the organisation's behalf — a requirement the doctrine's own Article I would be incoherent without. Organisations may sign the doctrine alone, or sign and additionally accept the six commitments, which is recorded separately in the register.

Participation details to be published

Register III — Dissent and amendment

The most valuable response to this document is a demonstration that one of its articles is wrong, unworkable, overbroad, or written to advantage its authors. Such responses are published alongside the signatures, not beneath them. Accepted amendments are incorporated at the next version with attribution to whoever proposed them.

Participation details to be published

Translation

This document is published in English and Italian. Translations into other languages are welcome and will be listed once checked by a second reader; the English text governs where readings conflict.

08 — Drafting

Provenance and status

The drafting group

Version 1.0 was written by the individuals named at the end of the opening letter. The group is deliberately incomplete. It lacks, at minimum, a constitutional lawyer, a supervisor or regulator, a civil-liberties practitioner, a security engineer from a large deploying institution, and someone whose work is affected by these systems rather than building them. Those places are open and the document will be better for filling them.

Joining the drafting group means participating in the revision of the articles and being named as a drafter of the version you helped produce. It does not require agreement with the current text, and disagreement is the more useful contribution.

Provenance

This doctrine was initiated and funded by Compex, a company based in Turin, Italy, which builds infrastructure in the area the articles describe. That is disclosed at the outset so it can be weighed rather than discovered. The text names no product, vendor or technology, including Compex's own, and is drafted so that a competitor can implement it, cite it, or sign it without endorsing the company that wrote it.

A doctrine that only its author's architecture can satisfy is a specification disguised as a principle. If any article here is found to have that character, that finding belongs in Register III and the article will be rewritten or withdrawn.

Status

Version 1.0, open for signature and comment. This document states principles and specifies no architecture. A separate technical specification may express how the articles can be satisfied in practice; implementations of it should be multiple, competing, and independently verifiable.

Document integrityVersion 1.0 · September 2026

Digital signature

The initial drafting group

Signed in Turin, ItalyRecord: MAD-1.0 / OPEN

Integrity record issued with this public draft. Public signatures, amendments and dissent will be versioned alongside the doctrine.