SearcharxivSearch

arXiv · 2609.26264

Doctrine as a Fixed Point: A Formal Model of the Enforceable Penalty Ceiling when Human Oversight of AI Must Remain Effective

Abstract

Article 14 of the EU AI Act requires that a high-risk system be overseen by natural persons who understand its limits, remain alert to automation bias, and can disregard or override its output. That capability is invisible in the output and decays precisely when the system is good. A provider can certify it only by an outcome-contingent liability commitment, and how large a commitment courts will enforce is itself open. After Cavendish the enforceable multiple of actual loss is measured against the legitimate interest the clause protects; where that interest is preserved oversight capability, it exists only if the market separates, which requires a sufficiently permissive doctrine. We model the enforceable ceiling as a fixed point of an expectations map on a complete lattice. Existence follows from Knaster-Tarski. Because no case separates at compensation, compensation is always an equilibrium; once the doctrinal uplift clears a threshold set by the case population, a permissive equilibrium and a watershed appear, and the map inherits the provider's solvency cap, so an insurance withdrawal deep enough and long enough can destroy the permissive equilibrium, which returning cover does not restore. Perturbing the adjustment yields a closed-form long-run tipping point, exact recovery times, and the noise levels at which irreversibility fails. The welfare cost of the resulting trap is capped at the drafting cost of primary-obligation substitutes. The order-theoretic core is machine-checked in Lean 4 with an axiom-free report. Both AI-side parameters, shared-base-model intensity and provability, are matched to instruments available in 2026.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Andreas Bauer. 2026-09-23. Doctrine as a Fixed Point: A Formal Model of the Enforceable Penalty Ceiling when Human Oversight of AI Must Remain Effective. https://doi.org/10.2139/ssrn.7266560

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Privacy-Aware Sequential Learning

Sequential learning often relies on individuals reporting private information, with early reports shaping later beliefs and collective decisions. When such reports are sensitive, privacy protection creates a fundamental trade-off in the design of sequential feedback systems. We study this trade-off as a platform design problem: before reporting begins, the platform commits to a local privacy-preserving reporting protocol, seeking to improve final-decision accuracy while limiting the time required to accumulate sufficient evidence. Surprisingly, privacy protection can accelerate learning. With continuous Gaussian signals, smooth randomized response under metric differential privacy preserves asymptotic learning and yields a public log-likelihood ratio growing at rate $Θ_{\varepsilon}(\log n)$, faster than the nonprivate $Θ(\sqrt{\log n})$ benchmark, substantially reducing high-confidence stopping times. With heterogeneous privacy parameters, learning can be faster still; when privacy budgets are uniformly distributed on $[0,1]$, public belief grows at rate $Θ(n^{1/4})$. With binary signals, randomized response generates a nonmonotone relationship between privacy and decision accuracy because privacy affects both report informativeness and cascade thresholds. Stopping time can also be nonmonotone because stronger privacy reduces report informativeness while encouraging participation. Overall, privacy is not merely a constraint on information release, but a platform design lever shaping participation, stopping, and collective learning.

econ.TH

Singleton-Attainability and Transparent Access in Matching

Matching mechanisms differ in how much of an agent's preference ranking must be determined and reported to obtain a particular object. A mechanism is singleton-attainable (SA) if every object that an agent can obtain through some report can also be obtained by reporting only that object as acceptable. With an SA mechanism, once an attainable object has been identified, the agent need not rank or report any other object. Singleton-attainability identifies a distinct dimension in matching theory and market design: transparent access to attainable outcomes, separate from incentives, stability, welfare or equity. We establish general conditions for SA and derive its strategic implications. Top-lift invariance and truncation invariance together imply SA, while strategyproofness and stability each imply SA. By contrast, no Pareto improvement over a strategyproof, individually rational, and non-wasteful mechanism is SA. In particular, every Pareto improvement over Deferred Acceptance violates SA. We introduce report width, which measures how many acceptable objects may have to be reported to obtain an object. SA mechanisms have report width one. Report width is unbounded for a large class of efficient mechanisms that Pareto-improve Deferred Acceptance. Stable selection with report-induced priorities has width one when priorities are monotone and maximal width under reverse priority dominance. Rank-welfare maximization has width one when the outside-option rank is fixed and maximal width when it is report-dependent. These results reveal a structural divide, which we call the width dichotomy: across all mechanisms and families in our classification and all structural classes we study, report width is either one or unbounded.

econ.TH

Minimally rational reallocation of objects

Matching theory has largely evolved around two canonical rules: deferred acceptance (DA) in the marriage problem and top trading cycles (TTC) in the object reallocation problem. Although the two rules operate through different procedures, we show that they rest on a common axiomatic foundation. In the marriage problem, stability decomposes into individual rationality and pair rationality, and a classic result characterizes DA by these two axioms together with strategy-proofness for the proposing side. We show that individual rationality, pair rationality, and strategy-proofness likewise characterize TTC. More strongly, three weak rationality axioms concerning individuals and pairs, together with strategy-proofness, uniquely determine TTC. Even weak rationality requirements therefore rule out strategy-proof implementation when there is a cap on the size of exchange cycles.

econ.TH