←
AI for Government
Visionary · M5 · lesson 5 of 46 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
AI and the Social Contract
📖
now learning

AI and the Social Contract

15 min

When the governor of a mid-sized state asked her cabinet a deceptively simple question, "If AI eliminates 40,000 clerical jobs in this state over the next decade, whose problem is that?", the room went quiet. The labor secretary said it was the market's problem. The budget director said it was a federal problem. The state CIO, Aurelio Banda, said something the others had not considered: "It is our problem, because those 40,000 people vote, pay taxes, and called us to renew their licenses last week. The deal we have with them is changing, and they did not sign off." That deal, the unwritten agreement between government and the governed about who provides what, who bears which risks, and what each owes the other, is the social contract. AI is quietly renegotiating it. This lesson is for the leaders who will decide the new terms.

What the Social Contract Means in Practice

Strip away the philosophy and the social contract is a set of mutual expectations. Citizens accept the authority of government, its laws, its taxes, its decisions, in exchange for things: security, fair treatment, a functioning economy, a safety net when they fall, and a voice in how they are governed. Government's legitimacy rests on holding up its end. When the deal feels broken, legitimacy erodes, and erosion of legitimacy is the most expensive failure a government can suffer, because it raises the cost of everything else the state tries to do afterwards.

This is not a metaphor or a rhetorical flourish. When an agency deploys AI, it is exercising state power, and every deployment is a touch on the contract. A well-designed deployment can honour the contract and even strengthen it, demonstrating that the state can use new tools to serve people better. A badly designed one weakens the contract, sometimes visibly and sometimes invisibly, and the damage compounds across government rather than staying inside the agency that caused it. AI strains the deal along four fault lines at once. Aurelio's early mistake was treating each as a separate technology problem for a separate office.

The Inheritance: Five Strands of Contract Thinking

The tradition is worth knowing because each strand surfaces a different failure. Hobbes, in Leviathan of 1651, establishes the baseline trade: citizens accept the sovereign's authority in exchange for security. The Hobbesian question for AI is whether the state's new technical capabilities deliver security or become dangerous in new ways. Mass surveillance, facial recognition and predictive policing are directly Hobbesian, and the state's obligation is to ensure new powers are bounded by law and constrained by accountability rather than justified solely by their effectiveness.

Locke's Second Treatise of 1689 centres consent, limited government, and rights that predate and constrain the state. Its questions are whether citizens have meaningfully consented to being governed by a system, whether state power is genuinely limited, and whether those rights, now instantiated in constitutional form, are respected. Rousseau's Social Contract of 1762 frames the state as an expression of the general will, which sits in direct tension with technocratic rule. Its question is whether algorithmic governance bypasses democratic deliberation, substituting expert judgment for collective decision.

Rawls, in A Theory of Justice of 1971, introduces the original position and asks how institutions would be designed behind a veil of ignorance about one's own place in society. Applied to AI, the test is whether a system would be acceptable to someone who did not know whether they would be the subject of a correct or a mistaken decision. That is a powerful and uncomfortable test for fairness under risk. More recent authors extend the tradition further: Martha Nussbaum toward capabilities, asking whether a deployment expands or contracts what marginalised citizens can actually do, and Danielle Allen toward democratic equality, asking whether it treats every person as an equal participant in public life.

These are frameworks for asking questions, not procedures that return verdicts, and the source is careful that no single one is the correct lens. The discipline is to run a deployment past each and catch what one surfaces and another misses. A facial recognition system might look defensible from the Hobbesian angle and fail the Rawlsian test outright. A benefits triage system might pass the Rawlsian test and still fail the capabilities test for a specific group of beneficiaries. Together they are a richer checklist than any one alone, which is also the limit of what they are: running the checklist does not settle the question, it only stops you from missing half of it.

The Constitutional and Statutory Frame

In the American setting the tradition is instantiated in specific law that leaders are expected to know. The Due Process Clause of the Fifth Amendment and the Due Process and Equal Protection Clauses of the Fourteenth constrain how government may act on people. The Administrative Procedure Act, which the source cites at 5 USC 551, requires that agency action be neither arbitrary nor capricious and that adversely affected parties have notice and an opportunity to be heard; check that pinpoint citation against the statute itself before relying on it in writing. The Privacy Act of 1974 constrains how government collects, uses and discloses personal information. Title VI of the Civil Rights Act prohibits discrimination in federally funded programs, and Section 504 of the Rehabilitation Act prohibits discrimination against people with disabilities.

These translate into concrete obligations for AI. A rights-impacting decision must be explainable to the affected person in terms they can understand, or notice and the opportunity to be heard are formalities rather than protections. A system producing disparate impact across protected classes must be evaluated against the doctrinal frameworks that apply to it, and the source is explicit that those frameworks are not identical to each other. A system affecting benefits eligibility must preserve the due process protections established by Goldberg v. Kelly in 1970 and the cases that followed. The Blueprint for an AI Bill of Rights, published by the White House Office of Science and Technology Policy in 2022 as a non-binding framework, and OMB Memorandum M-24-10, issued in 2024, do not create new rights; they operationalise these existing authorities for AI.

The source distils the frame into six questions to answer before deploying any rights-impacting system. What rights or interests are affected? What process is the affected person entitled to? How will they learn the decision and the reasons for it? How can they contest it? How will disparate impact across protected classes be monitored and remedied? And who is ultimately accountable for each decision, with that accountability documented? A system that cannot answer these should not be deployed. Note what the six questions are and are not: answering them is a floor, and a deployment that answers all six can still be a bad idea on the merits.

Fault Line One: Workforce Displacement

The clearest pressure. When AI automates work, some people lose livelihoods. History says new jobs eventually appear, but "eventually" and "the same people" are doing enormous work in that sentence. A fifty-two-year-old benefits processor whose role is automated does not seamlessly become a prompt engineer, and the aggregate statistics that eventually look fine are assembled from individual decades that did not.

For Aurelio's state the worked example is deliberately concrete and deliberately hypothetical. Suppose AI handles 60 percent of routine call-centre and document-processing volume across state agencies over eight years. That might be 12,000 state positions, plus knock-on effects in private clerical work. Note that this is a different population from the governor's 40,000, which counted clerical jobs across the whole state economy rather than the state's own payroll, and neither figure is derived from the other. The social-contract question is not whether to automate, since efficiency pressure makes that nearly inevitable. It is what the state owes people displaced by a decision the state itself made.

The deliberate answers governments can choose among:

  • Reskilling at scale. Funded transitions into roles AI creates or cannot do, planned before layoffs rather than after.
  • Attrition-first automation. Phasing AI in as workers retire, trading some speed for far less human cost.
  • Redeployment. Moving people from automated tasks into higher-touch work, such as complex casework AI handles poorly.
  • Honest transition support. Extended benefits and placement help when none of the above fully absorbs the displaced.

Fault Line Two: The Quality and Universality of Services

AI can make government services dramatically better: instant answers, availability around the clock, faster benefits. It can also create a two-tier system. The citizen comfortable with a chatbot gets served at 11 p.m. in thirty seconds. The elderly, the person with limited English, the rural resident with poor connectivity, the person in crisis who needs a human being, can all be left behind by the very efficiency that serves everyone else.

The principle at stake is universality: government services, unlike commercial ones, must reach everyone, including the people a business would write off as unprofitable. Section 508, the federal requirement that government technology be accessible to people with disabilities, is one legal expression of this, but the principle runs broader than any single provision. An AI service that works brilliantly for 85 percent of citizens and fails the other 15 percent has not improved government; it has narrowed it. The design rule Aurelio adopted was that every AI service ships with a guaranteed human alternative, no harder to reach than the AI.

That rule deserves one honest qualification. A human alternative that exists on paper, staffed thinly, reachable only through a queue that the AI path does not have, is a formal answer to a real problem. The test is not whether the alternative exists but whether a person who needs it actually gets served in comparable time. Measure the human path's wait, abandonment and resolution rates alongside the AI path's, or you will have built the two-tier system you were trying to prevent and will have documentation proving you did not.

Fault Line Three: The Safety Net

The safety net, unemployment and disability and food and housing assistance, is the part of the contract that catches people when the economy or life knocks them down. AI touches it twice. It can administer the net better: detecting fraud, speeding eligibility, finding people who qualify but never applied. It can also damage it catastrophically when an opaque system wrongly denies benefits at scale, which is not a hypothetical risk but a documented pattern examined later in this lesson.

Displacement raises demand on the net at the same moment AI is reshaping who administers it, which is a coincidence of timing no agency plans for. The leadership question is whether your safety net is being made more accurate and humane by AI, or merely cheaper and harder to appeal. The two look identical on a budget spreadsheet and opposite to the family on the receiving end. The distinguishing evidence is not the accuracy metric. It is what happened to appeal volumes, appeal outcomes and time-to-resolution after deployment, which is a question most programs can answer only if someone decided in advance to ask it.

Fault Line Four: Equity and Democratic Voice

The deepest fault line. The social contract promises fair treatment and a say. AI systems trained on historical data can encode historical discrimination, producing decisions that look neutral and act biased, in policing, in lending oversight, in child-welfare screening, in hiring. And the move toward automated decisions can hollow out the citizen's voice, because it is hard to appeal a decision no human will explain and harder still to appeal one nobody will admit was made by a system.

This is where frameworks become tools rather than citations. The NIST AI Risk Management Framework, a voluntary federal guide for identifying and reducing AI risks, and OMB Memorandum M-24-10, which directs federal agencies to safeguard rights and safety in their AI use, push toward the same practices: test for biased outcomes, keep humans accountable for consequential decisions, and preserve a meaningful right to challenge. Used well, they give the contract's promises of fairness and voice an operational form. Used badly, they become a document produced once at authorization and never consulted again, which is the most common way a good framework fails.

What the Record Actually Shows

Four cases anchor this lesson, and the pattern across them matters more than any one. Arkansas's Medicaid algorithm cut home-care hours for disabled beneficiaries beginning in 2016, and litigation produced a federal court finding that the state had violated due process; the source notes the algorithm itself was held not confidential from affected parties, a precedent it says systems increasingly cite. Michigan's MiDAS unemployment fraud system falsely accused more than forty thousand workers of fraud between 2013 and 2015, operating with over 90 percent automation and, in the source's more specific figure, making decisions in 93 percent of cases without human review, with no effective appeal.

The Michigan remediation the source describes exceeded twenty million dollars, alongside reputational harm it judges will take a generation to repair. The Dutch toeslagenaffaire, running roughly from 2013 to 2019, falsely accused thousands of parents, disproportionately immigrants, of childcare benefits fraud, and the scandal forced the government's resignation in 2021. The United Kingdom's Post Office Horizon case, which the source is careful to note was not an AI system, produced analogous dynamics: automated outputs treated as authoritative, wrongful prosecutions of hundreds of people, and a public reckoning that took decades to arrive.

The common factor is not bad technology. It is bad social-contract design. In each case the state deployed a decision system that acted on people unilaterally, without transparency, without effective appeal, and without accepting accountability until it was forced to. The remediations, in every case, took the form of restoring the contract: transparency, explanation, appeal, independent review, documented accountability. Those elements cost far less to build at the start than to retrofit under litigation, and the agencies that treat them as overhead are not saving money. They are deferring a much larger bill and choosing to have it presented in public.

What the Trust Data Does and Does Not Tell You

Survey research from Pew Research Center, the Edelman Trust Barometer, the Stanford HAI AI Index, the Knight Foundation's work on trust in technology, and the Partnership for Public Service's Federal Trust Index documents a consistent pattern: trust in institutions has been declining across the democratic world, and government AI deployments are viewed with particular scepticism. The source cites a 2023 Pew survey finding that a majority of Americans are more concerned than excited about the role of AI in daily life, with concern concentrated in government use cases.

The source draws a conclusion from this that is worth carrying and worth narrowing. Its framing is that each deployment is either a deposit into or a withdrawal from a trust account, and that contract-honouring design compounds over time. As a way of taking the long view of a decision, that is useful. As a claim about cause and effect, it overstates what anyone can demonstrate: no agency has built legitimacy by shipping a transparency artifact, and survey instruments measure stated attitudes among people who mostly have not encountered your system. What the practices in this lesson reliably do is remove specific, identifiable reasons for people to withdraw trust, and make it possible to answer when someone asks what happened. That is a smaller claim than legitimacy on demand, and it is the one the evidence supports.

Six Practices That Hold the Contract

The source sets out six leadership practices that, applied consistently, keep government AI inside the envelope of the social contract. First, deliberative public engagement for rights-impacting deployments: engaging affected communities, civil society and subject-matter experts through a documented process before deployment, in a way that actually changes the design rather than announcing it. Second, appealable decisions with meaningful human review, meaning a defined path for the affected person to challenge a decision, with access to the decision, the reasons for it, and a reviewer empowered to reach a different conclusion.

Third, third-party audit for high-stakes deployments, with auditor selection, scope and reporting terms made public, since an audit whose scope was chosen privately answers whatever question was safe to ask. Fourth, sunset clauses requiring affirmative reauthorization after a defined period, so a deployment has to justify itself periodically rather than accumulating inertia. Fifth, documentation that meets transparency norms and would survive a public records request: model cards, decision logs, evaluation results and incident histories. Sixth, leadership modelling, in which the senior leader publicly describes the limits of the system alongside its benefits.

These reinforce each other, which is the strongest argument for doing all six. Public engagement reveals which decisions most need appeal paths. Appeal paths generate the data that makes an audit meaningful. Audit findings motivate what a sunset review should examine. Sunset clauses force re-engagement. Documentation supports all of them and supports the oversight, inspector general and judicial review that will arrive eventually whether or not you prepared for it. An agency that institutionalises the set builds a capability that can survive an incident. An agency that treats them as discretionary builds one that is always a single incident from losing the argument entirely.

Say plainly what none of the six delivers. A completed engagement process does not mean the public consented; it means you asked, recorded, and can show what you changed. A published model card does not make a system fair. A third-party audit does not certify safety; it reports what one auditor found, in one scope, at one time. The failure mode these practices invite is the artifact becoming the absolution, where the register entry, the assessment or the signed checklist is treated as having discharged the obligation it was meant to document. A completed checklist has never once made a false statement true, and a published register has never once given anyone an appeal.

A Usable Artifact: The Social-Contract Impact Screen

Aurelio's office now runs every significant AI initiative through this screen before approval. It forces the four fault lines onto the table while a decision can still be shaped, which is the only time any of the questions has a useful answer.

DimensionThe question leadership must answerRed flag
WorkforceWho is displaced, and what concrete transition do we owe them, planned before deployment?"The market will absorb them."
UniversalityDoes every citizen, including the least connected, get equal-quality access? Is there a guaranteed human path, and is it measured?The AI is the only door, or the human door has a longer queue.
Safety netDoes this make support more accurate and humane, or just cheaper and harder to appeal?Savings projected; appeal rights unchanged or weakened.
Equity and voiceHave we tested for biased outcomes and preserved a real right to challenge a decision?No bias testing; no human will explain the decision.
AccountabilityWho is the named person answerable for each decision, and where is that documented?Accountability described as shared across a governance body.
ReauthorizationWhen must this deployment justify itself again, and what evidence will it need?No end date; continuation is the default.
LegitimacyIf this were on the front page, would citizens feel the deal got fairer or more rigged?We would rather it stayed quiet.

The Leader's Stance

Aurelio reframed his own role over those years. He had thought his job was deploying AI efficiently. He came to see it as renegotiating the social contract responsibly, making sure that as the terms shift, they shift toward a deal citizens would still accept if it were explained to them plainly. That is not a technology task. It is the oldest task of government, wearing new clothes, and it is one of the few tasks that cannot be delegated to the office that owns the system.

The frame also has a practical advantage that is easy to miss. Political leadership changes, statutes evolve, and frameworks are revised or revoked. What endures is the basic compact that the state treats people with due process, equal respect, and some humility about its own fallibility. A leader anchored to that compact has a compass that stays valid when the other anchors move, which is the difference between an AI programme that survives a change of administration and one that has to be re-justified from nothing every time the guidance is rewritten.

Anti-Patterns

  • The artifact as absolution. Treating a published impact assessment, model card, register entry or completed checklist as having discharged the obligation it documents. The document records what you decided. It does not make the decision defensible, and a completed checklist has never once made a false statement true.
  • Consultation as ratification. Running public engagement after the design is fixed, then citing participation as evidence of consent. If nothing in the design could have changed as a result, the process produced a record and a grievance, not legitimacy.
  • The human path that exists only on paper. Publishing a human alternative that is thinly staffed, slower, or harder to reach than the automated one. Universality is measured in wait times and resolution rates, not in the existence of a phone number.
  • Accountability distributed until it vanishes. Assigning responsibility to a board, a committee or a governance function rather than a person. Every case in this lesson involved a decision system nobody in particular was answerable for.
  • Treating the philosophical frame as ornament. Citing legitimacy and public trust in the preamble of a memo whose body contains no appeal path, no bias testing and no reauthorization date. The frameworks are tests to fail, not language to borrow.
  • Confusing survey trust with earned trust. Trust indices measure stated attitudes among people who have mostly never touched your system. They will not tell you whether the people your system acted on were treated fairly, and improving them is not an objective a deployment can be tuned toward.
  • Deferring the contract cost. Deciding that transparency, appeal capacity and independent review are overhead to be added later. Every case in the record shows the bill still arrives, larger, in public, and on someone else's timetable.
  • Assuming a system that passed one lens has passed them all. A deployment can be secure, lawful, accurate and still fail on capability, equality of standing, or the question of whether anyone consented to being governed this way.

Practice Prompts

  • Take one AI system your organization operates or is procuring and run the six constitutional questions on it: rights affected, process owed, how the person learns the decision and its reasons, how they contest it, how disparate impact is monitored and remedied, and who is personally accountable. Write down which you could not answer.
  • Run the same system past each of the five contract lenses in turn. Find the one lens that raises a concern the others do not, and decide whether that concern changes the design or is being accepted.
  • Complete the social-contract impact screen for a live initiative, and be specific about the red flags rather than scoring yourself green. Bring the completed screen to whoever can still change the design.
  • For one automated service, measure the human alternative alongside the AI path: wait time, abandonment, resolution rate, and who uses it. If you cannot measure it, that is the finding.
  • Write the reauthorization case your most significant AI deployment would have to make in two years. What evidence would you need, and are you currently collecting any of it?
  • Draft, in one page and in plain language, the explanation an affected citizen would receive after an adverse automated decision. Give it to someone outside your field and ask them what they would do next.

Reflection

Think about a decision your organization has automated, and put yourself on the receiving end of it. You are the person the system decided against. What would you be told, in what language, through what channel, and how quickly? What would you have to do to challenge it, and how long would that take? Who would eventually look at your case, and would they have the authority and the information to reach a different answer? If any part of that sequence is uncomfortable to trace, you have found the part of the contract your deployment is currently borrowing against.

Then ask the question that outlasts your tenure. The systems you approve will still be running under leaders who did not choose them and may not know why the design is the way it is. What have you written down that would let a successor understand not just how the system works, but what it was permitted to do and why that boundary was drawn there? Institutional stewardship is largely the practice of making your reasoning legible to people you will never meet, and it is the quietest form of contract-keeping there is.

Glossary

  • Social contract. The mutual expectation that citizens accept the authority of the state in exchange for protection of rights, provision of collective goods, and fair procedure when the state acts on them.
  • Legitimacy. Citizens' belief that institutions are fair, responsive, and deserving of their trust and compliance, which is distinct from their legal authority to act.
  • Due process. The constitutional requirement that government give notice and a meaningful opportunity to be heard before adversely affecting protected interests.
  • Rights-impacting AI. An AI system whose output affects a person's civil rights, civil liberties, access to services, or other legally protected interests.
  • Universality. The obligation that public services reach everyone, including those a commercial provider would decline to serve.
  • Disparate impact. A facially neutral practice producing significantly different outcomes across protected groups, assessed under legal frameworks that are not identical to each other.
  • Original position. Rawls's device for testing an institution by asking whether it would be acceptable to someone ignorant of their own place in society.
  • Capabilities approach. Nussbaum's framing of justice in terms of what people are actually able to do and to be, rather than resources they nominally hold.
  • Sunset clause. A provision requiring affirmative reauthorization of a deployment after a defined period, so continuation is a decision rather than a default.
  • Third-party audit. Independent examination of a system by an auditor outside the deploying organization, whose value depends on the scope and reporting terms being public.

Closing

The social contract is not a topic that sits beside the technical work. It is the reason the technical work is permitted at all. Every case in the record began as a project with a business case, a schedule and a competent team, and became a constitutional problem because nobody in the room was asking what the state owed the people the system would act on. That question does not answer itself, it does not belong to the vendor, and it does not get easier to ask once the system is in production.

Aurelio's shift was from asking whether the technology worked to asking whether the deal it created was one citizens would accept if it were put to them plainly. That test is harder than any compliance check and more useful than all of them, because it cannot be satisfied by a document. It is answered by what actually happens to the person the system decided against: whether they were told, whether they could contest it, whether someone with authority looked, and whether anyone was answerable for the outcome. Get those right and the frameworks mostly take care of themselves. Get them wrong and no framework will save you.

Key Takeaways

  • Every deployment is an exercise of state power. AI is renegotiating the unwritten deal between government and citizens, and leaders either shape that shift deliberately or have it imposed by events.
  • Displacement is government's problem. When a public decision automates jobs, the state owes those workers a planned transition, not a shrug toward the market.
  • Universality is measured, not declared. Every AI service needs a human alternative as easy to reach as the AI, and the way to know you have one is to measure its wait and resolution rates.
  • The safety net can be improved or gutted by the same code. Watch appeal volumes, outcomes and time-to-resolution, because accuracy metrics will not distinguish the two.
  • Bias and voice are the deepest risks. Test for discriminatory outcomes and preserve a real right to challenge a consequential automated decision.
  • The frameworks are tests, not language. Five contract lenses and six constitutional questions surface different failures; running them is a floor, not a verdict.
  • The record is consistent. Arkansas, Michigan, the Dutch benefits scandal and the Horizon case all failed the same way: unilateral action, no transparency, no effective appeal, no accountability until forced.
  • Six practices hold the line. Deliberative engagement, appealable decisions, public-scope third-party audit, sunset clauses, durable documentation and honest public leadership reinforce one another.
  • No artifact discharges the obligation. A register, an assessment or a completed checklist records a decision; it does not make it defensible and it does not give anyone an appeal.
  • Run the screen before approval. Forcing workforce, universality, safety net, equity, accountability, reauthorization and legitimacy onto the table early is the leader's core job.

Frequently Asked Questions

Is the social contract a real constraint or just a way of talking about ethics? In the American setting it has been instantiated in specific law, which makes it operational rather than rhetorical. Due process and equal protection under the Fifth and Fourteenth Amendments, the Administrative Procedure Act, the Privacy Act of 1974, Title VI of the Civil Rights Act and Section 504 of the Rehabilitation Act all impose enforceable obligations that AI deployments inherit. The cases in this lesson were resolved in courts and legislatures, not in ethics seminars.

Do the OSTP blueprint and the OMB memorandum create new rights? The source is explicit that they do not. The Blueprint for an AI Bill of Rights is a non-binding framework published in 2022, and OMB Memorandum M-24-10 was issued in 2024; both operationalise existing constitutional and statutory authorities for AI deployments rather than creating fresh entitlements. That matters practically: an agency cannot dismiss an obligation because a framework was revised, since the underlying authority was never the framework.

How much human review is enough? The record suggests the wrong question is the percentage. Michigan's system operated with over 90 percent automation, and the source's more specific figure is that 93 percent of cases were decided without human review; but the failure was not the ratio alone, it was that the remaining review had no capacity, the appeal path did not work, and nobody was answerable. A defensible answer specifies which decisions require a human, what that human can actually see, whether they have authority to reach a different conclusion, and how long they have.

We published an algorithmic impact assessment. Are we covered? No, and this is the failure mode worth naming directly. An assessment documents your reasoning and makes it inspectable, which is genuinely valuable. It does not test the system, it does not create an appeal path, and it does not make a flawed design sound. Treating the artifact as the discharge of the obligation is the most common way a well-intentioned governance programme produces paperwork and no protection.

What if transparency would defeat the purpose of the system, as in fraud detection? Then narrow the transparency, not the accountability. The Arkansas case is instructive precisely because the algorithm was held not confidential from the people it acted upon. Even where full public disclosure would be counterproductive, the affected person still needs notice, reasons they can act on, and a route to challenge, and an independent reviewer still needs enough access to answer whether the system is behaving. Secrecy about mechanism is not the same as secrecy from the person decided against.

Where does a leader start with all of this? Start where a failure would be least reversible. Identify the deployment in your portfolio that acts on people most directly, and answer the six constitutional questions about it honestly this month. The gaps you find will be specific and mostly fixable: a missing appeal route, a decision notice nobody can understand, an accountability line that stops at a committee. Fixing those is worth more than a governance programme that starts with a framework and never reaches a live system.