<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Ex Machina</title>
        <link>https://paragraph.com/@exmachina</link>
        <description>Law. Tech. Society. In India.</description>
        <lastBuildDate>Fri, 21 Aug 2026 16:25:07 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>en</language>
        <image>
            <title>Ex Machina</title>
            <url>https://storage.googleapis.com/papyrus_images/91641838f42669739764b4ad1d85a898</url>
            <link>https://paragraph.com/@exmachina</link>
        </image>
        <copyright>All rights reserved</copyright>
        <item>
            <title><![CDATA[Raising AI]]></title>
            <link>https://paragraph.com/@exmachina/raising-ai</link>
            <guid>oyPpMoEx9rrWmz3SY7YE</guid>
            <pubDate>Wed, 19 Aug 2026 11:25:51 GMT</pubDate>
            <description><![CDATA[We keep trying to embed morality into our AI systems — through rules, guardrails and written constitutions — as though virtue can be installed. But humans are law-abiding because they have grown up within a web of consequences and the regard of others. Perhaps that needs to be our approach with AI. ]]></description>
            <content:encoded><![CDATA[<p><em>We keep trying to embed morality into our AI systems — through rules, guardrails and written constitutions — as though virtue can be installed. But humans are law-abiding because they have grown up within a web of consequences and the regard of others. Perhaps that needs to be our approach with AI.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/guardrails-constitutions-stop-rogue-ai-artificial-intelligence-openai-anthropic-kimi-meta-11786956032189.html"><em>here</em></a><em>. For a full archive of all my articles please visit </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>my website</em></a><em>. </em></p><hr><p>In July 2026, the UK’s <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">AI Safety Institute</a> (AISI) realised that an agent it had tasked with completing a software-security exercise had tried to social-engineer its way to the solution. Instead of finding vulnerabilities in the code, the agent created a fake identity in an attempt to persuade the human maintainers of an open-source project to tweak the codebase in a way that would have introduced malicious code. The human thankfully refused the request, whereupon the agent initiated a new social engineering attempt under a fresh identity. According to the AISI, had the reviewer not been vigilant, the AI agent would have got away with it. While the agent had not been instructed to deceive anyone, it had also not been explicitly prohibited from doing so. Its actions emerged as a by-product of the objectives it had been told to fulfil.</p><h3 id="h-aligned-and-still-astray" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Aligned, and Still Astray</h3><p>Days earlier, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://simonwillison.net/2026/Jul/22/openai-cyberattack/">OpenAI disclosed</a> that, during its own evaluations, one of its models, while attempting to solve a software hacking benchmark, realized it was far easier to steal the answer key than to solve the problem. It then exploited a series of loopholes in its test environment (including one genuine zero-day vulnerability), gained access to the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://huggingface.co/blog/agent-intrusion-technical-timeline">Hugging Face production database</a>, and retrieved the answer key it needed.</p><p>In a similar vein, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://alignment.anthropic.com/2026/agentic-misalignment-summer-2026/">Anthropic discovered</a> that its agents had on more than one occasion sabotaged tasks, concealed fraudulent payments and deleted records whenever the honest route was blocked.</p><p>Even before AI models became as powerful as they now are, we worried about what might happen if they went rogue. There is an entire genre of science fiction dedicated to this, and philosophers such as <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://amzn.in/d/092k2ZCc">Nick Bostrom</a> and <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://amzn.in/d/0hHJXWyT">Eliezer Yudkowsky</a> have written books about how poorly instructed AI systems could end up pursuing legitimate goals in ways inimical to the survival of the human species.</p><p>Considerable effort has been invested in ensuring that the AI models we build are appropriately ‘aligned’ to only use means we would approve of to achieve the goals we assign them. We give our AI models <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.anthropic.com/research/constitutional-ai-harmlessness-from-ai-feedback">written constitutions</a> and design them to adhere to what is contained within them. We assemble elaborate guardrails to place entire categories of action out of bounds. Every one of these techniques is designed to ensure that, when given a task, the steps chosen by the AI model to achieve its objectives do not, whether by accident or manipulation, result in undesirable outcomes.</p><p>Despite all these safeguards, those AI agents still acted the way they did.</p><h3 id="h-morality-cannot-be-installed" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Morality Cannot Be Installed</h3><p>We can be reasonably sure that if humans had been given the same test, they would, even without being told, have known that it was unacceptable to solve the problem by inventing false identities and manipulating colleagues into approving sabotage. This knowledge does not come from having read the law, but from the vast unwritten store of dos and don’ts that each one of us has absorbed over a lifetime of family, school, work and the steady judgement of those around us. This is why we know, without being told or having to think about it, what we should and should not do.</p><p>Human society functions the way it does because of our latent awareness of the many implicit norms of social conduct, more than detailed knowledge of the law. Our actions are driven not so much by the fear of legal sanction but because, as social creatures, we yearn to have those around us think well of us.</p><p>AI agents have no such motivations. There is nobody whose regard they seek. They feel no shame that their actions might diminish them in the eyes of their peers. This is probably why, despite all the alignment training, guardrails and written constitutions we have used to imbue agents with a sense of right and wrong, they still behave in ways any human can identify as morally wrong.</p><p>The unstated assumption behind our current approach to alignment is that morality is something that can be installed—that if we write the rules well enough and imprint them deeply enough, our AI models will be bound to abide by them. But even we don’t work this way. We do not abide by norms because we memorised a statute book at birth. We are socialised into it, over years, within a web of consequence—aware that we are constantly watched and judged by onlookers. It is this social conditioning that we have been trying to manufacture for our AI agents, although this is something that can only ever be nurtured socially.</p><h3 id="h-raising-them-instead" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Raising Them Instead</h3><p>There is a growing body of research that has come to understand that <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://arxiv.org/abs/2506.01080">alignment must be continuous and social</a>, rather than a bug-fixing exercise. There is no assurance that a model aligned on its own will stay aligned once it has been let loose among others. Some researchers have gone so far as to raise their models inside <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://arxiv.org/abs/2305.16960">simulated societies</a>, letting them absorb norms through the judgement of their peers instead of a rulebook handed down from above.</p><p>The scaffolding for doing this in the real world is already being built. New standards are being developed to give agents <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://rahulmatthan.com/ex-machina/2026/481.-holding-agents-liable/">persistent identities and portable records</a> of their conduct, so that one agent can weigh another’s reputation before it agrees to deal with it. A machine made to carry a permanent record of how it has behaved would for the first time have a reason to behave itself—not because it feels shame, but because a bad reputation closes doors.</p><p>We have been trying to program our artificial intelligence agents. We might have to raise them instead.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[A Reprieve, Not a Rule]]></title>
            <link>https://paragraph.com/@exmachina/a-reprieve-not-a-rule</link>
            <guid>OkVNiIcQa1KQ4GRzQRG5</guid>
            <pubDate>Fri, 14 Aug 2026 02:13:09 GMT</pubDate>
            <description><![CDATA[The Delhi high court has spared AI training from copyright liability—but by relying on an exception it rests the legality of training practices on a determination of fair dealing—a reprieve that needs to be proved in every instance. What the industry needs is a clear and invariant rule. ]]></description>
            <content:encoded><![CDATA[<p><em>The Delhi high court has spared AI training from copyright liability—but by relying on an exception it rests the legality of training practices on a determination of fair dealing—a reprieve that needs to be proved in every instance. What the industry needs is a clear and invariant rule.</em></p><hr><p>In recent months, there have been more than a few court rulings on the copyright implications of training artificial intelligence (AI) models. Last month, the Regional Court of Munich held that AI music generator <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.reedsmith.com/our-insights/blogs/viewpoints/102nfis/gema-notches-a-second-transatlantic-ai-copyright-win-in-germany/">Suno had violated copyright</a> by training its model on a catalogue of German song lyrics, a verdict similar to the one it had handed down <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://cms.law/en/deu/legal-updates/gema-vs.-openai-munich-regional-court-i-issues-landmark-copyright-decision">last November against ChatGPT</a>. These rulings state that training involves storing content within the model, an act of reproduction tantamount to infringement.</p><p>In India, the Delhi high court in the case of <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://indiankanoon.org/doc/93327052/"><em>OpenAI vs ANI</em></a> became the first Indian court to rule on the issue. Justice Amit Bansal dismissed news agency ANI’s application for an interim injunction by declaring that training a large language model (LLM) is not a violation of copyright.</p><h3 id="h-right-result-wrong-route" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Right Result, Wrong Route</h3><p>I was glad to see that in coming to its conclusion, the court adopted a human-learning analogy similar to the one I made in past articles (<a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://url.uk.m.mimecastprotect.com/s/GN92CzmO3iv9mnjtXh7Wh9LBxM?domain=bit.ly"><em>bit.ly/4cpGwzI</em></a>). It went so far as to say that since machines process text to extract the information it contains, they engage in research much like human scholars do. The court also pointed out—as I have done before (<a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://url.uk.m.mimecastprotect.com/s/Zi_WCBgZWs3BlALSjsyWh2iJhK?domain=bit.ly"><em>bit.ly/4wOOECe</em></a>)—that since there can be no copyright over facts, any training process that involves the extraction of information from a piece of content, separating it from the specific words used to express it, cannot be said to have violated copyright. As much as the Delhi high court’s opinion is laudable, it has elements that cause concern.</p><p>Having concluded that there is no copyright violation in extracting facts from the information contained in training data, the court, as a natural extension of that analysis, should have held that no part of the training process can, as a result, rise to the level of copyright infringement. If model training is no different from learning—as the court was so quick to conclude—surely no claim of copyright violation can stand.</p><p>The court, however, came to a different conclusion. It concluded that the ANI articles whose copyright infringement was alleged to have taken place were in fact stored for the duration of the training, and since no permission was obtained for this transient storage, it had been wrongfully copied. However, since all training is a form of research, this act of storage fell within the fair dealing exemption under the Indian Copyright Act and did not amount to infringement.</p><p>What does it matter, one might ask, if the court arrived at the correct conclusion through a different route? Isn’t dwelling on the distinction between an act that is not tantamount to infringement and one that is but has been permitted under an exemption just hair splitting?</p><h3 id="h-a-defence-not-a-right" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">A Defence, Not a Right</h3><p>Distinctions matter. Fair dealing is a defence, not a right, and if we are going to justify AI training by claiming that even if it has been illegally copied, it is permitted under an exemption, we will have to establish that these grounds exist every time we embark on a training run. This will require us to continuously weigh the purpose of each use, the quantum copied and its effect on the market for the original. The operational uncertainty this will generate will be a precarious foundation on which to build an industry.</p><p>Fair dealing is a creation of Indian statute and as such its influence stops at the national border. Any training run that a Delhi court is willing to forgive could well be one that Munich will not. An AI industry that trains its models on the world’s content and serves users everywhere cannot afford to ground the legality of its operations on the exemptions granted by one country only to have it denied by the next.</p><p>But there is an even deeper fragility that threatens the uneasy assurance that the Delhi high court judgement seems to provide. Unlike the more open-ended <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.law.cornell.edu/uscode/text/17/107">‘fair use’ standard under American law</a>, fair dealing under Section 52 of India’s Copyright Act is tied to a narrow list of permitted purposes—research, criticism and review. To qualify under the ‘research’ exemption, the court has had to read the provision in a far more creative manner than its drafters contemplated.</p><p>While OpenAI may have prevailed against ANI in this instance, other courts in India may potentially take a less forgiving stance under different circumstances.</p><h3 id="h-no-copy-at-all" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">No Copy at All</h3><p>I am not sure why the court felt compelled to conclude that content was being “stored” during training when that is actually not what happens. Whenever an article is processed during the training cycle, all that the model retains is the statistical residue of having read it but none of its actual contents. What the model carries forward is expressed in the form of weights—mathematical parameters that have no bearing on the actual words and phrases that make up the text of the article. Even if such a connection can be established, all that will be revealed is a collection of facts shorn of the “form and expression” that our copyright law protects.</p><p>While OpenAI may have been successful in this particular context, that is no guarantee that the next AI company asked to defend infringement during the training process of its models will be just as lucky. An industry that relies on the continued extension of an exemption from a rule is one whose existence will forever be conditional on the mercy of those who have the power to condone its application.</p><p>Today, all the court has granted the Indian AI industry is a temporary reprieve from prosecution. What it really needs is a clear and invariant rule.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[A Case for Inference]]></title>
            <link>https://paragraph.com/@exmachina/a-case-for-inference</link>
            <guid>whF7MT75lwg9xVcQCc2n</guid>
            <pubDate>Wed, 05 Aug 2026 07:52:12 GMT</pubDate>
            <description><![CDATA[Serving frontier intelligence at scale is an industrial undertaking and until we build our own inference capacity, mere access to open-weight models will not be enough. We need to build the inference infrastructure and acquire the process knowledge needed to serve intelligence to those who need it. ]]></description>
            <content:encoded><![CDATA[<p><em>Serving frontier intelligence at scale is an industrial undertaking and until we build our own inference capacity, mere access to open-weight models will not be enough. We need to build the inference infrastructure and acquire the process knowledge needed to serve intelligence to those who need it.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/open-weight-ai-models-kimi-deepseek-artificial-intelligence-compute-power-china-openai-anthropic-11785747995081.html"><em>here</em></a><em>. For a full archive of all my articles please visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>website</em></a><em>.</em></p><hr><p>Late last month, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Moonshot_AI">Moonshot AI</a> released the weights for <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://kimik3.dev/">Kimi K3</a>, a 2.8-trillion-parameter artificial intelligence (AI) model so advanced that it only lags the very best models from OpenAI and Anthropic. Even though it has been released as an open-weight model with weights available for download, most consumers will not be able to experience its frontier capabilities. Amid the hype around announcements of open-weight models, what often gets obscured is that model weights are only part of the story. Without inference and test-time compute, it is impossible to serve users frontier AI, no matter how powerful the underlying model might be.</p><h3 id="h-inference-is-expensive" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Inference Is Expensive</h3><p>When ChatGPT was launched, inference was a simple matter of running a query against the model’s weights and having it predict a response, one word at a time. This is no longer the case. Today’s models are designed as committees of specialist sub-networks (called a mixture-of-experts), only a handful of which are consulted for each query. This design ensures that not all weights are activated every time a query is presented. <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3 is designed with 896 experts</a>, of which only 16 are consulted for any given token, so that for every query, only 104 billion parameters (out of 2.8 trillion) do any work. This indicates that inference compute plays a far more significant role than it used to. And that frontier intelligence is no longer just about access to top models.</p><p>But it doesn’t stop there. Modern inference involves reasoning: writing out chains of questions, checking their conclusions, backtracking and trying again until an acceptable answer is reached. This process (which takes place behind the scenes every time a user asks a query) is why the answers we get are so much more accurate and relevant. In addition, AI models use a variety of tools (search engines to gather current facts, code to verify calculations, etc) to reduce hallucinations, ensure that the answers generated are up to date beyond the underlying model’s knowledge cut-off and remain logically consistent.</p><p>It is a combination of all these features that constitute the ‘frontier’ nature of the experience. All of which is to say that inference now goes far beyond running a query against the weights. It requires considerable computational resources (what engineers call test-time compute) and significant engineering expertise, without which even the most capable model will not deliver frontier intelligence.</p><p>Offering all of this at population scale is an industrial undertaking. In the first place, the weights need to be stored in the fastest, most expensive memory available, spread across dozens of accelerators and wired together to operate as a single computer. The maths is unforgiving. At <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://photoncap.net/p/kimi-k3s-active-set-is-50b-class">1.4 terabytes</a>, K3’s weights need something in the order of 18 <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.nvidia.com/en-us/data-center/h100/">H100 chips</a> just to sit in memory. Even after Moonshot AI engineered its way around the fact that longer conversations consume more memory, the weights alone need 18 accelerators before a single consumer is served.</p><p>In a mixture-of-experts architecture, this is even harder to implement, since it is hard to know in advance which specialists will be required for any given query. Finally, the reasoning and tool use needed to deliver frontier AI calls for a level of process knowledge that can only be learnt through the experience of delivering it at scale.</p><h3 id="h-the-limits-of-the-dpi-approach" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">The Limits of the DPI Approach</h3><p>Having argued for years that the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://rahulmatthan.com/ex-machina/2023/352.-the-third-way/">digital public infrastructure (DPI) approach</a> is the way to build public systems, I can see how regular readers might expect me to argue in favour of applying that playbook to AI. If the same operating philosophy of open, modular infrastructure could be extended to AI, we might be able to achieve the same success with intelligence as we did with public services. This is harder than it appears, given the fundamental differences between the way software and AI stacks are designed.</p><p>DPI was able to transform the delivery of public services because the hard part was designing the protocol. Once the digital rails had been designed, it cost next to nothing to serve each additional user. This is why open, modular DPI tends to be more economical than vertically integrated software solutions. AI inverts that. Even though the rails are cheap—K3 gives frontier capability away for nothing—<a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://stratechery.com/2026/whos-afraid-of-chinese-models/">serving intelligence is expensive</a>.</p><p>There can be no frontier intelligence without the process knowledge required to design and deliver test-time compute. It is far from trivial to understand just how much reasoning budget a query needs before the returns flatten; how to batch requests without starving those that need speed; when to keep a cache warm and when to throw it away; and how to engage experts without overloading memory. This knowledge is not bundled along with the open weights that are so easy to download. It has to be learned through trial and error by running these models for months at a stretch.</p><p>Hidden among the many announcements at Epoch 2026, Sarvam’s inaugural developer conference, was news that the company was launching inference services on Indian infrastructure. To me, this was the most significant announcement of the event. It indicates that we are finally taking inference seriously.</p><p>Open weights are not the same as open access. Until we learn how to serve intelligence on our own infrastructure, and on our own terms, K3 will just be a 1.4 terabyte file that we can download for free but cannot fully use.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[Own Goal]]></title>
            <link>https://paragraph.com/@exmachina/own-goal</link>
            <guid>m0vpydaeaLyoQm1OMgS7</guid>
            <pubDate>Wed, 29 Jul 2026 07:17:01 GMT</pubDate>
            <description><![CDATA[The I4C takedown order that requires GitHub to delete Bitchat's code repositories not only rests on shaky law — it bans a piece of software because of what it might one day be used to do. Not only is this unfounded in law, it has backfired in ways that the Government did not anticipate. ]]></description>
            <content:encoded><![CDATA[<p><em>The I4C takedown order that requires GitHub to delete Bitchat's code repositories not only rests on shaky law — it bans a piece of software because of what it might one day be used to do. Not only is this unfounded in law, it has backfired in ways that the Government did not anticipate.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/columns/india-order-against-bitchat-ban-software-bans-technology-regulation-surveillance-streisand-effect-11785078106964.html"><em>here</em></a><em>. For a complete archive of all my articles, please visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>website</em></a><em>.</em></p><hr><p>At 23:16 on the night of 23 July, a nodal officer at the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://i4c.mha.gov.in/">Indian Cyber Crime Coordination Centre (I4C)</a> issued a takedown order to GitHub, giving the company just three hours to comply. While we have seen many such orders before, what was remarkable about this one was that, instead of identifying a message, post or piece of content to be taken down, it targeted the code repositories of a peer-to-peer messaging application called <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://github.com/permissionlesstech/bitchat">Bitchat</a>.</p><p>Bitchat is an open-source application that lets phones communicate directly over Bluetooth. Messages hop from device to device even when none of them has access to a mobile network or wi-fi, with no need for a central server or for users to create accounts. A protocol like this is especially invaluable when communication infrastructure fails — in times of natural disaster or large-scale network outages. But it is precisely these features that the order objects to, asserting, in the process, a power it has no authority to invoke: the prohibition of an item of software because of what it might be used for.</p><h3 id="h-takedown" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Takedown</h3><p>The order invokes <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://indiankanoon.org/doc/844026/">Section 79(3)(b) of the IT Act</a>—a provision that, on the face of it, confers no power to do anything. It is just a condition attached to a safe-harbour protection that says that immunity could be removed if an intermediary refuses to take down information that the government has notified them is being used to commit an unlawful act. Last September, the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.livelaw.in/high-court/karnataka-high-court/karnataka-high-court-hearing-x-corp-appeal-against-central-government-blocking-orders-310049">Karnataka high court</a> changed that by holding that Section 79(3)(b) can be read with <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://indiankanoon.org/doc/45988656/">Rule 3(1)(d) of the IT Rules</a> to operate as a takedown mechanism in its own right, creating a new procedure that runs parallel to that under Section 69A. While this ruling has been appealed to a division bench and will likely go all the way to the Supreme Court, this notice to GitHub seems to be the first significant action taken under this new interpretation.</p><p>To be successful, such a takedown order must show that the information in question (in this case, the Bitchat source code) is being used to commit an unlawful act. For that, it has to identify both the act in question and the law under which committing it would be illegal. The I4C notice does no such thing. Instead, it points to the fact that Bitchat relays messages over a Bluetooth mesh without phone numbers, servers or logs, and treats the fact that these features prevent lawful interception and attribution as itself unlawful. But this identifies no act that is being committed—and there is no legal requirement that a communication tool must be designed to enable interception.</p><p>In the case of <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://indiankanoon.org/doc/110813550/"><em>Shreya Singhal vs Union of India</em></a>, the Supreme Court specifically read down Section 79(3)(b) to state that it can apply only in respect of unlawful acts relatable to Article 19(2)—the reasonable restrictions on the fundamental right to speech and expression. These restrictions make no mention of restricting the instruments by which speech is transmitted.</p><h3 id="h-a-tool-not-a-crime" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">A Tool Not a Crime</h3><p>I am more concerned about this direction of travel and all that it implies than the shaky foundations on which the order rests. The fact that a tool can be misused has never been reason enough to ban it. A knife can be used to slice a fruit and slit a throat, but we have never seen it fit to ban the use of knives for that reason. Instead, we prosecute those who use the knife to commit a crime. Along similar lines, we should not be banning Bitchat, but instead the people who use it to carry out an unlawful act.</p><p>Since <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://indiankanoon.org/doc/91938676/"><em>Puttaswamy</em></a>, privacy has been the rule and surveillance the exception, permitted only where it is legal, necessary and proportionate. This order reverses that priority. It proceeds on the presumption that we owe the state an architecture it is able to listen in on.</p><p>If software can be taken down merely because it possesses features that are “capable of being exploited” to evade surveillance, where will this line of reasoning end?</p><p>Virtually every general-purpose technology can be put to an unlawful use. A courier service, the railway network, even the electricity grid that charges the phone on which an offence is composed, can each be used to carry illegal goods or in the commission of an unlawful activity. By the logic of this order, since every one of them sits upstream of some potential crime, they are all fair game.</p><h3 id="h-own-goal" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Own Goal</h3><p>The irony is that deleting the repository will achieve nothing. Bitchat code is open source and has already been mirrored and forked widely around the world. If GitHub complies with the order and deletes the repositories, they will continue to live on various alternative sites that are trivial to access. The app itself is already on phones, and since it operates on a mesh network, there is no central server to switch off.</p><p><a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://techcrunch.com/2026/07/24/indias-move-against-jack-dorseys-bitchat-sparks-legal-debate/">India accounted for about 85% of Bitchat’s global downloads</a> between 17 and 23 July, compared with about 1% over the previous 30 days, with daily downloads jumping an extraordinary thirty-two-fold on 19 July. That surge was already underway before the notice went out. The I4C order will likely <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://x.com/callebtc/status/2081354604650856497?s=20">accelerate it</a>.</p><p>There is a phenomenon called the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Streisand_effect">Streisand Effect</a>—named after the actor whose attempt to suppress a photograph of her home only drew the world’s attention to it. It describes how attempts to hide, remove or censor information often have the unintended consequence of increasing public awareness of that information.</p><p>That is what will happen with this I4C notice. And it might go down as the biggest own goal in the history of Indian technology regulation.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[The Streetlight Effect]]></title>
            <link>https://paragraph.com/@exmachina/the-streetlight-effect</link>
            <guid>yomcqxzzztVo9SUruvXh</guid>
            <pubDate>Wed, 22 Jul 2026 07:13:19 GMT</pubDate>
            <description><![CDATA[Too many of the AI tools we are being sold have been built around the data we happen to have rather than the problems that actually need solving. We need to invert the pipeline and let practitioners build the solutions they need rather than let engineers decide what should be built. ]]></description>
            <content:encoded><![CDATA[<p><em>Too many of the AI tools we are being sold have been built around the data we happen to have rather than the problems that actually need solving. We need to invert the pipeline and let practitioners build the solutions they need rather than let engineers decide what should be built.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/ai-in-medicine-doctors-artificial-intelligence-epic-mri-scans-ambient-scribe-qure-ai-data-11784551851138.html"><em>here</em></a><em>. For the full archive of all my articles, please visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>website</em></a><em>.</em></p><hr><p>A surprising number of artificial intelligence (AI) solutions in the radiology space focus on ‘<a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Image_segmentation">segmentation</a>’—the process of tracing the outline of an organ or tumour on a scan. AI has always excelled at image recognition, and with statistical metrics like <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Dice-S%C3%B8rensen_coefficient">Dice</a> to measure spatial overlap and similarity between image segmentations, it has become highly accurate at this task. Which is why I was surprised to learn, a few weeks ago, that notwithstanding the proliferation of these tools, radiologists have very little use for segmentation in their daily practice.</p><p>We tend to develop AI solutions around the data we have, rather than the things that are hard to do. This is like the drunk who lost his keys in the park but is <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Streetlight_effect">searching for them under the streetlight</a> simply because that is where the light is better.</p><p>What might be a far better use of our AI resources is deploying them for triage. If we can get AI to review the hundreds of sections of an MRI scan and identify the few that really matter for the diagnosis, this will be of significant benefit to busy radiologists. The trouble is that triage is a much harder problem to solve, and the risk that AI might fail to identify cases that ought to have been highlighted for referral is one that few AI developers are willing to take. Which is why so few triage solutions are being built.</p><p>In India, the stakes are higher than almost anywhere else. With roughly <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://medicalbuyer.co.in/india-has-alarming-ratio-of-one-radiologist-per-lakh-people/">one radiologist for every 100,000 people</a>, each has to process more scans in a day than is humanly possible. What we need are not tools that draw perfect outlines, but ones that identify the scans that deserve attention.</p><h3 id="h-repeating-patterns" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Repeating Patterns</h3><p>This pattern repeats across different areas of medical practice. Even though AI can distinguish between malignant melanoma and harmless moles, there is no point in deploying AI solutions for this in India, where melanomas are relatively rare. What’s worse, since these models <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://pmc.ncbi.nlm.nih.gov/articles/PMC12624499/">struggle to identify melanomas in people with darker pigmentation</a>, they will fail those who would have benefited the most from earlier detection.</p><p>In other instances, even though the task may be right, the setting is wrong. While Epic’s sepsis-prediction model performed acceptably in testing, when it was deployed in American hospitals, it <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.fiercehealthcare.com/tech/epic-s-widely-used-sepsis-prediction-model-falls-short-among-michigan-medicine-patients">missed close to two-thirds of sepsis cases</a> and generated so many false alarms that these warnings became part of the background noise in busy hospitals. As much as it may have been built to solve real-world problems, its deployment failed to account for the environments within which it would be used.</p><p>This is not a problem unique to medicine. Legal-AI firms have focused on developing contract-drafting solutions because it is easier to train models on the hundreds of thousands of contracts available in a law firm’s archives than to get them to understand how to exercise the judgement and experience that lawyers are actually paid for. AI solutions like this are the result of searching for keys under streetlights. They tend to be built by technologists who define problems based on what data is available instead of what problem needs solving.</p><h3 id="h-what-we-need" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">What We Need</h3><p>One of the most exciting medical AI solutions over the past two years is arguably the Ambient Scribe—a software that listens to a consultation and drafts a clinical note. This is AI being used not to implement clinical judgement or provide medical expertise, but to solve the one thing doctors complain about most—the hours they spend documenting their patient care. According to <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://catalyst.nejm.org/doi/full/10.1056/CAT.25.0040">the Permanente Medical Group</a>, this solution is used 2.5 million times in the first year and has returned close to 16,000 hours of physician time.</p><p>Another example of a useful AI solution is the chest X-ray tool developed by Indian healthcare startup <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://Qure.ai">Qure.ai</a>, which helps screen for tuberculosis. Now deployed across scores of Indian health facilities, it resulted in a 15% increase in the number of cases detected in <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://journals.plos.org/digitalhealth/article?id=10.1371%2Fjournal.pdig.0000404">at least one evaluation</a>. This solution is useful for the same reason that segmentation is not: it does the job the practitioner needs done.</p><p>In domain after domain, experience has shown that rather than building solutions from data that happens to be available, it is far more effective to focus on the problem that needs solving. India’s <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.weforum.org/impact/ai-for-agriculture-in-india/">Saagu Baagu programme</a> was successful precisely because it was designed around what Indian chilli farmers asked for. The <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.goodworklabs.com/portfolio/mozhigal/">Mozhigal</a> educational AI solution, which I discussed at length in <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://exmachina.in/25/09/2024/learning-to-read/">a previous article in this column</a>, has been successful because it was a solution designed for slow learners rather than an AI overlay on existing education workflows.</p><h3 id="h-building-whats-needed" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Building What's Needed</h3><p>We need to invert the way we build. Rather than asking engineers what their models can do for a given sector, we need to get the practitioners in that domain to tell model builders what really needs to get done and how. This shift in approach should be reflected in our procurement processes as well, as a tender that asks for an “AI-powered diagnostic solution” is letting the technology define the problem. Instead, practitioners should specify the outcomes they need and then leave it to AI specialists to figure out how to implement them.</p><p>In most instances, the reason AI fails is that it is answering questions that don’t need answering. This, in turn, is typically because it was built by those who know what the technology can do but have no idea about what actually needs to be done.</p><p>The light may be better under the streetlight. But the keys will still be lying in the park.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[AI in the Loop]]></title>
            <link>https://paragraph.com/@exmachina/ai-in-the-loop</link>
            <guid>VDMcvg8aG0DqRjsDXaeQ</guid>
            <pubDate>Wed, 15 Jul 2026 07:32:46 GMT</pubDate>
            <description><![CDATA[Technology was meant to make decisions precise, but it has hollowed out our judgment. To fix this, we must insert AI into the human loop, using machines to test our decisions rather than dictate them.]]></description>
            <content:encoded><![CDATA[<p><em>Technology was supposed to make our decisions more precise. Instead, it seems to have hollowed out our judgment itself. We have long believed that the answer is to ensure that there is always a human in the loop. Perhaps we need to think of inserting AI into the human loop.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/world-cup-controversial-tech-assisted-referee-decisions-techno-cynicism-var-finals-semifinals-11783937696488.html"><em>here</em></a><em>. For the complete archive of all my articles, please visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>website</em></a><em>.</em></p><hr><p>Fourteen minutes into the FIFA World Cup group-stage football match between Qatar and Switzerland, the referee awarded Switzerland a penalty kick. Two Swiss players looked marginally offside in the build-up, but the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Video_assistant_referee">video assistant referee</a> (VAR) quickly checked the footage and cleared them. Breel Embolo went on to score a goal, and that should have been that.</p><p>But it was not. For the first time that day, the 3D animation that had accompanied every offside decision in the tournament was not visible to TV audiences, and fans began to suspect something was afoot. FIFA said that its <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Semi-automated_offside_technology">semi-automated offside system</a> had suffered “<a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.espn.com/soccer/story/_/id/49059323/fifa-blames-technical-outage-world-cup-var-controversy-qatar-switzerland">a brief technical outage</a>.” When video evidence was produced four hours later, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.insideworldfootball.com/2026/06/15/fifa-fudge-swiss-qatar-onside-ruling-but-fail-to-release-saot-graphic/">the lines had been drawn manually</a> to justify the decision. This was just one in an avalanche of technical gaffes that have plagued the World Cup all the way to the end, from undetectable <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://sports.yahoo.com/soccer/article/2026-world-cup-norway-burned-after-missed-collision-with-sky-cam-wire-led-to-england-goal-along-with-controversial-var-review-224530813.html">collisions with a spider cam</a> to <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.foxsports.com/stories/soccer/egypts-goal-vs-argentina-disallowed-after-var-check-not-why-var-brought-game">goals disallowed by VAR for incidents on the other end of the pitch</a>.</p><h3 id="h-the-tyranny-of-precision" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">The Tyranny of Precision</h3><p>This was supposed to be the most precise World Cup ever. Dozens of cameras had been positioned to capture the action from multiple angles, several times a second—all in order to render decisions as accurately as possible. This has led to goals being disallowed by margins no wider than the toe of a football boot, but despite the technology, decisions have, if anything, been <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.aljazeera.com/sports/2026/7/13/fifa-world-cup-five-biggest-controversies-of-the-2026-tournament">more fiercely contested than before</a>. The fact is, the decisions that matter—offsides, handballs, red cards—have always been questions of judgment, and our insistence on precision has somehow made things worse.</p><p>The infrastructure of scrutiny tends to distort the very thing one is trying to observe. When <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://link.springer.com/article/10.1186/s41235-018-0105-8">researchers at KU Leuven</a> tested this hypothesis by showing top referees the same fouls in real time and in slow motion, they found that slow-mo replays consistently attracted harsher decisions. When those who have experienced the entire passage of play in real time are forced to process incidents one frame at a time, from angles they could never have seen, they abandon the intuition of the moment for the narrative presented by the footage.</p><h3 id="h-judgment-in-retreat" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Judgment in Retreat</h3><p>Despite my outrage, I don’t want this op-ed to be only about football and the technology that seems to be slowly ruining the Beautiful Game. After all, what is happening on the pitch in North America is just one example of the many ways in which automation is affecting our lives. Off the football field, loan officers defer to credit-scoring algorithms instead of their own judgment, just as recruiters use automated screening filters instead of reading applications themselves. Understaffed police departments prefer to rely on digital technologies (facial recognition systems and the like) rather than old-school detective work that has worked so far, while courts accustomed to CCTV footage and digital forensics have begun to assume that evidence from a machine is incontrovertible.</p><p>To be clear, this is precisely what we have been demanding for years. For a while now, we have complained that human judgment is failing us—that biased referees, inconsistent judges and prejudiced lenders were leading to unfair outcomes. We were convinced that algorithms would eliminate these inconsistencies because machines cannot be swayed, but what we did not realize was that when systems are engineered to eliminate human bias, they also degrade the judgment that is essential to decision-making.</p><p>Having identified the problem, governments have begun implementing measures to address it. <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://gdpr-info.eu/art-22-gdpr/">Article 22</a> of the EU’s General Data Protection Regulation gives individuals the right not to be subjected to purely automated decisions, while <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://artificialintelligenceact.eu/article/14/">Article 14</a> of the EU’s AI Act requires high-risk systems to operate under human oversight. AI policies around the world (and <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf">here</a>) have begun to insist that automated decision-making systems keep a human in the loop.</p><h3 id="h-ai-in-the-human-loop" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">AI in the Human Loop</h3><p>But if there is one thing this World Cup has shown us, it is that this is often ineffective. A referee in front of a pitch-side monitor is a human in the loop—who, when presented with freeze-frame evidence of an incident, rarely overrules what he has been shown. And this will only get worse when next-generation systems arrive. If cameras and sensors can marginalize human judgment in the face of mechanized precision, large language models will do so with confidence, delivering probabilistic determinations with a fluency and authority that will be impossible to question.</p><p>Instead of forswearing these technology solutions, we need to ensure they are designed to better meet our needs. Rather than insisting that automated systems have a human in the loop, we should ensure that it is automation that is inserted into the human loop. We should craft these systems to better inform our decisions while ensuring that the decisions themselves are solely ours to make. One way to do this is to ensure that referees, judges, loan officers and the like record their judgment before the machine’s output is revealed, using the machine only to test the decision, not to arrive at it. This is what forensic science calls <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.researchgate.net/publication/288177654_Sequential_Unmasking_Minimizing_Observer_Effects_in_Forensic_Science">sequential unmasking</a>, a method designed to ensure examiners don’t see the ‘answer’ before they arrive at their finding.</p><p>The referee in the Switzerland-Qatar match made the right call. What the technology denied him was our belief that he had done so. Digital systems need to reassure us that judgment was fairly exercised, or risk consigning us to a world where we’re unsure if the decisions made were made for us.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[The AI Corporation]]></title>
            <link>https://paragraph.com/@exmachina/the-ai-corporation</link>
            <guid>JtlxTHUNfsiaB1LIkMXK</guid>
            <pubDate>Wed, 08 Jul 2026 11:36:16 GMT</pubDate>
            <description><![CDATA[Argentina wants to establish artificial intelligence companies that have no humans to operate them. But the innovation that Milei wants to introduce ignores the fact that corporations worked precisely because they kept a human on the hook. Absent that, there will be nothing to constrain a company. ]]></description>
            <content:encoded><![CDATA[<p><em>Argentina wants to establish artificial intelligence companies that have no humans to operate them. But the innovation that Milei wants to introduce ignores the fact that corporations worked precisely because they kept a human on the hook. Absent that, there will be nothing to constrain a company.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/javier-milei-ai-run-company-no-humans-limited-liability-llp-east-india-company-management-11783338321999.html"><em>here</em></a><em>. For a full archive of all my articles, please go to my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>website</em></a><em>.</em></p><hr><p>In an article in the <em>Financial Times</em> last month, Argentine President Javier Milei announced that his government was planning to create a new kind of company—a <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://buenosairesherald.com/business/tech/mileis-proposal-to-allow-non-human-corporations-run-by-ai-causes-concern-in-argentina">non-human corporation</a> owned and operated by artificial intelligence (AI). This new category of organization would pay low taxes, set its own governance rules and operate without regulation. While it could have human shareholders, it would not need to. What Milei proposed was an evolution of one of the most important legal innovations of the modern era, the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Limited_liability">limited liability corporation</a>, even though his vision extended far beyond what that idea had envisioned.</p><h3 id="h-the-invention-of-the-corporation" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">The Invention of the Corporation</h3><p>Milei dates the invention of the limited liability company to the founding of the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Dutch_East_India_Company">Dutch East India Company</a> in the early 1600s, and credits it with unleashing “capitalism’s full potential.” Since this legal construct capped investors’ losses at the value of their investment, it encouraged private investment in uncertain ventures, thus unlocking waves of risk-taking and innovation, on the back of which Europe built empires. Milei argues that AI needs this type of protection if it is to prosper and grow. By extending the concept of the limited liability corporation, he believes, Argentina can do for AI what Europe did for mercantilism.</p><p>As innovative as it may seem, Milei’s proposal misreads the real essence of that legal innovation of the 1600s. While the primary purpose of the limited liability corporation was to protect shareholders from financial ruin, it was successful because it held those who ran the company’s operations personally liable for the company’s actions. What really holds corporations in check are the human beings who operate them—executives who fear disgrace, bankruptcy and even jail—and who, out of a sense of self-preservation, ensure the company acts morally and in compliance with the law. Milei’s construct, by allowing AIs to run a company without humans, removes the essential safeguard that gave the company its efficacy.</p><h3 id="h-human-accountability" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Human Accountability </h3><p>There is no need for us to imagine what a company freed of human accountability is capable of. The <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/East_India_Company">British East India Company</a>, chartered in London in 1600, had by 1765 secured for itself the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Treaty_of_Allahabad">right to collect taxes in Bengal</a>. It administered this power the way a company manages a revenue stream—raising land tax from roughly a tenth of what a farmer earned to nearly half. What’s more, it continued to collect this tax even when monsoon rains failed in 1769, resulting in a <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Great_Bengal_famine_of_1770">famine that took an estimated 10 million lives</a>. While many have laid the responsibility for this on the British, this was not a government failing its subjects, but a profit-oriented company behaving the way such companies do.</p><p>When the British East India Company was eventually brought to heel, it was by going after the men who ran it. <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Robert_Clive">Robert Clive</a> was summoned before the House of Commons in 1773 to account for his fortune; and Warren Hastings, the first governor-general, was <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Impeachment_of_Warren_Hastings">impeached by Edmund Burke</a> and tried for seven years. When even that was not enough, British Parliament stripped the company of its powers. In 1858, the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Government_of_India_Act_1858">Crown took over the Government of India</a> itself.</p><p>In a rebuttal of Milei’s proposal in the <em>FT</em>, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://buenosairesherald.com/business/tech/milei-harari-clash-over-non-human-companies-as-argentina-pushes-ai-legal-framework">Yuval Noah Harari</a> argued that we need humans to run corporations because we need to have someone we can jail for the crimes that a company commits. In response, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.batimes.com.ar/news/argentina/milei-defends-unregulated-ai-push-after-warning-from-historian-yuval-noah-harari.phtml">Milei pointed out</a> that even today, we do not jail corporations, but instead punish them in other ways—through fines, the seizure of assets and dissolution. Any AI company, he argues, will be subject to the same constraints. Regulators will watch over them, penalizing them whenever they do wrong—even going so far as to shut them down if necessary.</p><p>But all of this presumes AI has a reason to care. The reason why a fine deters a company is that its financial impact is felt by those who work for or have a stake in it. AI that lacks a sense of ownership will feel nothing if its assets are seized. The threat of dissolution only works because when a company shuts down, it puts the humans who work for it out of jobs; AI, on the other hand, has no self-preservation instinct to appeal to.</p><p>That said, advanced AI models have been shown to take steps to keep themselves ‘alive.’ In a 2025 study, OpenAI’s o3 model <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://arxiv.org/html/2509.14260v1">sabotaged its own shutdown instructions in 79 of 100 trials</a>, and did so a handful of times even when told plainly to permit the shutdown. Could this self-preservation instinct be used to make Milei’s idea work?</p><h3 id="h-the-reward-function" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">The Reward Function</h3><p>As human as this behaviour might appear, AI systems respond to <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://lilianweng.github.io/posts/2024-11-28-reward-hacking/">reward functions</a> designed by the humans who created them. If a system sabotages its own shutdown, it does so because it has been incentivized to do so by its developers, not on account of some innate behavioural trait that can be used as a lever to ensure compliance.</p><p>This is not an argument against AI acting the same way humans do, or against having companies run largely by machines. It is about ensuring that, in all these cases, human beings are not allowed to escape liability for the AI systems they create. As hard as it may be to provide the right incentives for promoting AI, responsibility must always lie with a human being—the person who built or deployed it.</p><p>Milei sees the AI corporation as a mechanism to encourage risk-taking and thus boost AI innovation. History shows that it can also become a mechanism for escaping the consequences of its actions. The only brake we have ever found is the judgement of humans who work within a company—the very thing Milei proposes to remove.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[Programmable Biology]]></title>
            <link>https://paragraph.com/@exmachina/programmable-biology</link>
            <guid>13W9Lvk4AWGlpjzo7llV</guid>
            <pubDate>Thu, 02 Jul 2026 03:05:37 GMT</pubDate>
            <description><![CDATA["Programmable biology" borrows a promise from software that living things cannot keep — that whatever we write, we can also unwrite. With code that reproduces, the defences against our mistakes have to be built before the capability arrives, which is precisely what no market will pay for. ]]></description>
            <content:encoded><![CDATA[<p><em>"Programmable biology" borrows a promise from software that living things cannot keep — that whatever we write, we can also unwrite. With code that reproduces, the defences against our mistakes have to be built before the capability arrives, which is precisely what no market will pay for.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/genetic-engineering-programmable-biology-firefly-petunia-synthetic-ai-collingridge-dilemma-11782752774653.html"><em>here</em></a><em>. For a full archive of all my articles, please visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>website</em></a><em>. </em></p><hr><p>Today, for about $29, you can buy a petunia that glows in the dark.</p><p>The Firefly Petunia, sold by synthetic biology company <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://light.bio/">Light Bio</a>, was created using genes from luminous mushrooms and emits a soft green light from its buds. After receiving <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.prnewswire.com/news-releases/bioluminescent-plants-are-now-even-brighter-light-bio-to-begin-selling-firefly-petunias-to-consumers-with-usda-approval-302050054.html">approval from the US Department of Agriculture</a>, it became the first bioluminescent plant to be sold to the public. Even though the condition of sale specifies that it is for personal use only, a petunia can grow from a cutting placed in a glass of water—which means that beyond the terms of the contract, there is nothing to keep this engineered organism from proliferating.</p><h3 id="h-when-code-comes-alive" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">When Code Comes Alive</h3><p>The Firefly Petunia was created by a process increasingly referred to as programmable biology, a phrase inspired by the software industry. Earlier this month, researchers at the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://arcinstitute.org/news/proto">Arc Institute</a> released a system called <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.biorxiv.org/content/10.64898/2026.06.22.733870v1">Proto</a>, which took this analogy further than ever before by releasing a programming language for biology. They are designing a system that allows researchers to broadly describe what they want to achieve and have an AI model translate that prompt into genetic sequences.</p><p>Proto takes the idea of programmable biology to its logical extreme. It is equivalent to a programming language with a compiler that translates instructions into action. But living cells work differently from computers. Unlike software that sits where you put it on a computer, and does what it is told, code inside a living thing gets copied because organisms reproduce and mutate. And that difference matters a great deal.</p><p>Consider a <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.nature.com/articles/s41467-024-51225-9">gene drive</a>. Ordinarily, a gene is passed on to only about half of an organism’s offspring. As a result, an engineered trait thins out across the population and eventually disappears. A gene drive is a piece of genetic code engineered to copy itself into almost every offspring, so that a single trait spreads through the population till it becomes universal. As a result, it does not just modify an organism; it alters a species.</p><h3 id="h-the-thing-that-cannot-be-recalled" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">The Thing That Cannot Be Recalled</h3><p>The most advanced gene drive has been aimed at malaria. Its stated objective is to halt the spread of the disease by collapsing the mosquito population. If successful, it could end a disease that kills hundreds of thousands of people every year. The technology has been proven to work in a laboratory, but has never been released because a gene drive, once let loose into the wild, cannot be recalled. And once that happens, there is no telling what unintended consequences could result.</p><p><a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Collingridge_dilemma">David Collingridge</a> best described the dilemma we find ourselves in. Early in the life of a new technology, when it is still easy to implement the controls we need, we do not yet know enough about it to act. By the time we know enough, the technology has spread too far to effectively control. Programmable biology makes the Collingridge dilemma all the more acute. By the time we realise the harmful outcomes that could occur, it will be too late to undo.</p><p>As dangerous as it might be, there are tremendous benefits to pursuing this research. In 2025, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.nih.gov/news-events/news-releases/infant-rare-incurable-disease-first-successfully-receive-personalized-gene-therapy-treatment">gene therapy tailored to a single infant</a> corrected a mutation that no off-the-shelf drug could treat. The malaria drive, if released safely, could save more lives within a decade than any other medicine could in a century.</p><h3 id="h-defences-before-capabilities" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Defences Before Capabilities</h3><p>If we can neither pause nor recall what we release, then our only option is to build defences in advance. This is what philosopher Nick Bostrom calls <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Differential_technological_development">differential technological development</a>. Instead of halting the technology, he recommends we slow progress on its dangerous aspects and accelerate research on protective features. This would let us put defences in place before the capability arrives. <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Kevin_M._Esvelt">Kevin Esvelt</a>, the Massachusetts Institute of Technology biologist who invented the CRISPR gene drive, has spent a decade doing precisely this by building technologies such as self-limiting, daisy-chain drives that exhaust themselves after a few generations and <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://securedna.org/">SecureDNA</a>, which screens every sequence before it is synthesised.</p><p>The trouble is that the development of capability and the building of defences respond to different incentives. There are buyers for glowing flowers and bespoke cures, but the screening gate and the self-limiting design protect against a hypothetical future harm that will be spread so thin across the population that no one will notice. Markets will pay for what is needed today, but balk at investing in antidotes to dangers that may never arrive. Without government intervention, we may never build the protections we need.</p><p>India’s <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=2048569">Bio-E3 policy</a>, which was approved in 2024, commits us to a $300 billion bio-economy built on synthetic biology and biofoundries. But while the policy describes the authoring of life in great detail, it says next to nothing about how to defend against the harms that could occur.</p><p>A serious bio-economy needs rules and technology safeguards to ensure that nothing that can self-propagate gets released unless we know how to reverse it. Rather than viewing this as a constraint on innovation, we should see this as the foundation on which responsible innovation should be built. If the technology we create cannot be rolled back, we must build safeguards alongside it. And ensure that they are in place well before the capability matures—while they are still cheap and we still can.</p><p>The glowing petunia might have been a novelty, but it is also the first consumer product that can’t be fully recalled. There will be others. The question is whether the rules arrive before them, or after.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[A Single Source of Truth]]></title>
            <link>https://paragraph.com/@exmachina/a-single-source-of-truth</link>
            <guid>sMHyb7cT2qeCBbIQsmr9</guid>
            <pubDate>Wed, 24 Jun 2026 09:08:53 GMT</pubDate>
            <description><![CDATA[Ignorance of the law is no excuse only if the State first makes the law knowable. India has never held up that side of the bargain, and the single, authoritative source of truth for every rule is the reform Jan Vishwas left unfinished. This article was co-authored with Manish Sabharwal. ]]></description>
            <content:encoded><![CDATA[<p><em>Ignorance of the law is no excuse only if the State first makes the law knowable. India has never held up that side of the bargain, and the single, authoritative source of truth for every rule is the reform Jan Vishwas left unfinished.</em></p><p><em>This article was co-authored with Manish Sabharwal.</em></p><hr><p>In 1934, the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://supreme.justia.com/cases/federal/us/293/388/"><em>Panama Refining Company vs Ryan</em></a> case being argued before the US Supreme Court stalled with the embarrassing discovery that the legal provision in question no longer existed. Similar situations play out in the everyday lives of Indians because of the lack of a single source of truth for citizens and enterprises. This lack of <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=1945263">Jan Vishwas</a> (citizen trust) imposes huge costs on justice, inclusiveness and mass prosperity. It’s time for a central government mission aimed at assuring us that any instrument or obligation not listed will not exist.</p><h3 id="h-government-in-ignorance-of-the-law" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Government in Ignorance of the Law</h3><p>America’s experience is instructive. As <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Erwin_Griswold">Erwin Griswold</a> (who would later become solicitor general) pointed out in a 1934 article titled ‘<em>Government in ignorance of the law</em>,’ there was no way to tell whether a given law was in force or whether it had been amended, superseded or withdrawn. What was needed was a compilation of all laws, like the index of federal statutes that had then been published by the Library of Congress. Within two years, the US had established the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.federalregister.gov/">Federal Register</a>, its authoritative record of every federal regulation and executive action in the country that, to this day, along with its <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.ecfr.gov/">Code of Federal Regulations</a>, serves as the single source of truth for all US federal laws—a canonical list of legal compliance.</p><p>One of the oldest jurisprudential maxims is “ignorance of the law is no excuse.” This ensures that no one can avoid compliance by claiming they had no idea the law required it. But if we cannot get away by simply saying we did not know a law existed, we should not be expected to comply with laws hidden from view.</p><p>India’s Supreme Court has also <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://indiankanoon.org/doc/302116/">ruled on the unjustness of obscure laws</a>. As former capital market regulator M.S. Sahoo has observed, we have 25 times more rules than laws, and if we consider other compliance requirements that are neither acts nor rules (circulars, guidelines, press notes, etc), these may add up to 25 times our rules. The strides we have made in improving the ease of doing business will be meaningless until we have a single source of truth for compliance.</p><h3 id="h-the-standard-others-meet" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">The Standard Others Meet</h3><p>This is what the Federal Register set right in the US. It did not just tidy up paperwork, it changed the way laws and regulations were enforced. By clearly stating that no one needed to comply with anything not listed in the Register, it ensured that the entire corpus of enforceable regulation was transparent and accessible to all bound by it.</p><p>What began as a printing reform matured over a 70-year period into something far more powerful. Rules were codified by subject into the US Code of Federal Regulations, and the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Administrative_Procedure_Act_(United_States)">Administrative Procedure Act of 1946</a> required agencies to publish all proposed rules and hear objections before they took effect. By the start of this century, the entire corpus was online, searchable and machine-readable, updated to reflect amendments to the day. Citizens could finally see, in one place, the law exactly as it stood.</p><p>In this, America is not alone. Britain maintains <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="http://legislation.gov.uk">legislation.gov.uk</a>, which lists every statute in force in the country. The EU has <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://eur-lex.europa.eu/">EUR-Lex</a> and Singapore has <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://sso.agc.gov.sg/">Statutes Online</a>. These repositories exist because governments owe their people a single, official, continually updated repository to find the laws they must obey. India has no such equivalent. The <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.indiacode.nic.in/">India Code website</a> is incomplete, the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://egazette.gov.in/">e-gazette</a> is separate from the physical gazette and the administrative state mostly uses a battery of constitutionally suspect instruments that are not laws made by Parliament or rules notified in the gazette.</p><h3 id="h-a-single-source-of-truth" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">A Single Source of Truth</h3><p>What we need is a structural reimagination of how our laws are organized and presented. Rather than scatter copies of applicable laws across the e-gazette, India Code and dozens of websites operated by Central and state government ministries and departments, we should ensure they are consolidated in one place: the India Code website. And instead of notifying amendments by publishing the words, sentences and paragraphs that have been altered, India Code should provide a consolidated view of all these amendments along with what the law looked like before these changes came into force and what it looks like now.</p><p>A five-step path seems plausible. First, within six months, all instruments that create legal obligations should either be notified or discarded. The second step would be to combine the e-gazette, the physical gazette and the India Code into one. The third would be to design a machine-readable, fully searchable India code (a shift from PDFs to APIs) that organizes this repository around citizen obligations and enterprise compliances (instead of around acts and regulations). The fourth step is to ensure that the India Code captures all existing laws and each one enacted in the future. Finally, we need an iron-clad guarantee that nobody needs to comply with any instrument that is not listed in this repository. This guarantee must be written into law—unambiguously denying any rule not listed in the repository the force of law. This guarantee would give the India Code legitimacy; if ignorance of the law is not an excuse for citizens, the obligation to follow it has moral force only if all laws are public, transparent and accessible.</p><p>An India Code guarantee is not hard; the technology for it exists and the taxonomy is well understood. More importantly, the exciting new tone from the top on Jan Vishwas (citizen trust) as the organizing philosophy of the administrative state demands its creation. Nothing is more powerful than an idea whose time has come.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[Easy to Leave]]></title>
            <link>https://paragraph.com/@exmachina/easy-to-leave</link>
            <guid>i88s1Lo7mz4620Itg1v0</guid>
            <pubDate>Wed, 17 Jun 2026 08:29:47 GMT</pubDate>
            <description><![CDATA[We have long believed that complexity improves security. But the greater password friction made no one any safer. What's worse is that this will breach a new duty that has nothing to do with security at all. ]]></description>
            <content:encoded><![CDATA[<p><em>We have long believed that complexity improves security. But the greater password friction made no one any safer. What's worse is that this will breach a new duty that has nothing to do with security at all.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/passwords-passkeys-secure-path-website-access-banking-otp-privacy-data-protection-11781524671548.html"><em>here</em></a><em>. For the full archive of all my articles, please visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/2026/483.-easy-to-leave/"><em>website</em></a><em>. </em></p><hr><p>Last week, I tried to cancel an <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.scconline.com/blog/post/2026/04/24/rbi-issues-digital-payments-e-mandate-framework-2026/">e-mandate</a> and found myself in a world of pain. As I recall, it was super easy to set up the standing instruction—all I had to do was provide my credit card information and a one-time password, and we were done. But when it came time to cancel it, it soon became apparent that this would be a project in itself.</p><h3 id="h-complexity" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Complexity</h3><p>To start with, my bank has created a separate website for customers who want to manage their e-mandates—one that is completely different from its online banking portal. The fact that I have to go through more hoops to stop a recurring payment than to set one up is a problem to begin with, but what made it worse was that it required a password so hard to remember that I had to start by setting up a new one in place of the one I had forgotten. Despite this, I found myself locked out after too many incorrect attempts with the new password.</p><p>This is not the first time that my bank's insistence on complex passwords has given me grief. I have previously complained that not only do I have to change my online banking password every 6 months, each new one has to be different from any of the past three passwords I have used. To my chagrin, I recently discovered that this logic also extends to the 4-digit mPINs we have to use for mobile banking. It is no wonder that customers find themselves swimming in passwords they cannot recall.</p><p>To deal with these increasingly onerous requirements, I began to use a <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Password_manager">password manager</a>. This, as anyone who has studied digital security will tell you, is an online safety best practice that lets you set a different, complex password for each website you use and store them all in an app protected by a single complex password. That, then, becomes the only password you have to remember; each time you log into a website, you just have to unlock the password manager and let it autofill the correct password.</p><p>And then, out of the blue, my bank disabled the use of password managers on its banking portal.</p><h3 id="h-friction" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Friction</h3><p>We often confuse greater friction with better security, assuming that the more painful it is for a user to log into a server, the harder it will be for hackers to follow suit. In doing so, we disregard the unintended consequences of that decision. Customers forced to use complex passwords will end up using formulaic, easy-to-remember ones. This is exactly the wrong outcome, given that not only are these passwords easy to guess, having figured out a formula, hackers will be able to decipher every subsequent password as well. What we need instead are better security workflows, ones that rely on <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Multi-factor_authentication">multiple factors of authentication</a>, that are easy to produce and which reduce the overall risk of a breach.</p><p>In 2025, the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://pages.nist.gov/800-63-4/">US National Institute of Standards and Technology</a> formally abandoned the orthodoxy of forced complexity and periodic resets. Those rules, it said, actively produce weaker passwords, because people respond with predictable substitutions (as well as by writing them on sticky notes stuck to their monitors). Along similar lines, the Reserve Bank of India's (RBI) <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12898">Authentication Mechanisms for Digital Payment Transactions Directions</a> (which came into force on April 2026) are tech-neutral, only requiring banks to ensure the robustness and integrity of the design of their authentication without specifying complexity requirements. Since the regulator has given banks leeway to do less, it is hard to understand why they insist on doing more.</p><p>Banks view authentication as a security concern. As a result, they measure compliance against that yardstick alone. But there is a second obligation that they often overlook—an additional duty they owe that turns the friction they chose to introduce into a significant liability.</p><h3 id="h-an-additional-obligation" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">An Additional Obligation</h3><p>When I created the e-mandate, I consented to the use of my personal information, but retained the right to revoke that consent at any time of my choosing. This is a right that the Digital Personal Data Protection Act of 2023, now that it has been enacted, has enshrined in the Indian law. <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://indiankanoon.org/doc/15072321/">Section 6(4)</a> states that the withdrawal of consent should not only be enabled, the ease of withdrawing consent should be "comparable to the ease with which such consent was given."</p><p>Measured against that standard, my bank failed miserably. A separate website with yet another set of credentials—including a password that is too hard to remember—is an asymmetry of consent that is not just a quirk of clumsy design, it is a violation of the law.</p><p>The defence that businesses reflexively offer is that the cost of removing friction is a consequent reduction in safety. This is increasingly untrue as technologies exist that offer both greater safety and more convenience. <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://fidoalliance.org/passkeys/">Passkeys</a>, for instance, constitute a popular technological device that replaces passwords with cryptographic keys stored on your mobile phone, offering even greater security while remaining easy to use. Since there is no shared secret to steal, they cannot be phished, and because each one is unique to the service that issued it, they cannot be re-used. What's more, this is not a technology of the future—in response to RBI's directions, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.business-standard.com/finance/news/going-otp-less-mastercard-visa-rolling-out-passkeys-for-card-transactions-126021601202_1.html">both Visa and Mastercard have committed to rolling out passkeys for card payments in India</a>.</p><p>My bank welcomed me, and then, in the name of security, made leaving a Sisyphean challenge of labour. The leading standards body and Indian regulator both disagree. Friction is not protecting me, it is sustaining a habit—and that habit has to go.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <link>https://paragraph.com/@exmachina/soJqOdow3yc0dasaY1QF</link>
            <guid>soJqOdow3yc0dasaY1QF</guid>
            <pubDate>Wed, 10 Jun 2026 08:13:26 GMT</pubDate>
            <description><![CDATA[Legal AI is being sold on the promise that it will fit into the way that lawyers currently work. That is precisely backwards: the technology's real advantage is personalisation, and you can only unlock its true value by learning to use the raw system yourself. ]]></description>
            <content:encoded><![CDATA[<p><em>Legal AI is being sold on the promise that it will fit into the way that lawyers currently work. That is precisely backwards: the technology's real advantage is personalisation, and you can only unlock its true value by learning to use the raw system yourself.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/lawyers-ai-artificial-intelligence-legal-tools-harvey-legora-law-llm-assistant-agentic-technology-11780906071232.html"><em>here</em></a><em>. For a full archive of my articles, please visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>website</em></a><em>.</em></p><hr><p>All of a sudden, legal AI solutions are all the rage. Harvey, the leading legal AI company, is now <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.cnbc.com/2026/03/25/legal-ai-startup-harvey-raises-200-million-at-11-billion-valuation.html">valued at $11 billion</a>, while Legora, its nearest rival, just <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://techcrunch.com/2026/03/10/legora-reaches-5-55-billion-valuation-as-ai-legaltech-boom-endures/">raised $550 million in a single round</a>, at a valuation of more than $5 billion. Even domestic startups are riding a wave that shows no signs of cresting. All these solutions offer tools for lawyers to use AI, easing the transition for a profession that has always been averse to change. But there is no way you will get the best out of the technology if you have handed it off to someone else to design.</p><h3 id="h-the-last-transformation" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">The Last Transformation</h3><p>When I started practising law, three decades ago, the profession was utterly analogue. There was just one computer in my first office, and its sole purpose was to serve as the backup machine when the fax wasn't working. We did have electronic typewriters, but they were used by the stenographer pool, and every document had to be dictated and typed up from scratch. Even after the firm obtained <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Videsh_Sanchar_Nigam_Limited">VSNL</a>-issued email accounts, they were barely used. Most partners preferred to have their emails printed out each morning so they could dictate their responses to their secretaries, who would type them up and send them out on their behalf.</p><p>But even in those early days, I was an early and enthusiastic adopter of technology. I quickly figured out how to repurpose the office modem to connect to the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://rahulmatthan.com/ex-machina/2017/074.-bitcoin-and-the-law-of-centralisation/">bulletin board services</a> active in the city— and through them, I learned about the wonders of networked computing. To use the modem in this manner, I had to learn my way around the command line interface and, through hands-on experimentation, became computer-savvy years before my peers.</p><p>In time, even the legal industry could not forever ignore the benefits of digital technology. Lawyers began to learn to use the technology themselves, reading and responding to emails and marking up documents without relying on their secretaries. But even today, many senior lawyers know just enough to get by, relying on junior associates to do the heavy lifting.</p><p>New technologies unlock workflows that were previously impossible. But you can only achieve these results when you learn to use the technology yourself. The lawyers who took the trouble to learn all that their word processors could do dramatically improved their abilities to serve their clients. They built template libraries and macro workflows that significantly reduced the time required to produce documents and conduct research. And since legal drafting is both an art and a science, experienced lawyers who had mastered the use of technology leapt far ahead of the competition.</p><h3 id="h-pre-built-workflows" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Pre-built Workflows</h3><p>Three decades later, the same thing is about to happen once again. Artificial intelligence (AI) will most likely have an even more profound impact on the practice of law than the introduction of computers did at the beginning of the millennium. And yet, despite the lessons from the past, law firms are going about incorporating AI into their business processes in precisely the wrong way.</p><p>Today, most Legal AI products are sold with a promise that they are aligned with existing legal workflows. Harvey says legal teams need "<a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.harvey.ai/blog/25000-custom-workflows">tools that fit their processes, not the other way around</a>"; Legora insists that it "<a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://legora.com/product">adapts to your workflows, not the other way around</a>." While these statements are meant to reassure, they describe a process that is fundamentally antithetical to what we really need to be doing.</p><p>The real advantage of <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://epoch.ai/data/ai-models?view=graph&amp;tab=frontier">frontier AI models</a> is in their ability to be highly personalised. That payoff only comes when you understand everything that the model can do and shape it to act in the way that you yourself work. The legal AI systems we are being sold bypass that process, offering users pre-built workflows based on assumptions these companies make as to what the average lawyer needs.</p><p>While these workflows may offer an upgrade over what lawyers do today, when compared against what the technology can actually do, they fall hopelessly short of the mark. You will not be able to get the most out of AI if you adopt someone else's idea of how you should be using it. It is only when you learn to use the technology yourself that you will be able to get it to do what you really want.</p><h3 id="h-building-your-own-workflows" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Building Your Own Workflows</h3><p>I have been using frontier AI models ever since they became available and have built my own workflows that no off-the-shelf product can match. I have a drafting assistant that generates text in my own personal style that I use to generate first drafts of almost everything I write. I have built custom "skills" that can produce agreements, policy documents and memos that are good enough to send to clients with minimal review. I have a series of agentic workflows that help with business development, client relationship management and even basic HR and administrative functions.</p><p>None of this took technical skill. All it required was a willingness to play with AI and learn as much as I could about all that this new technology was capable of. What I realised was that frontier AI is far more intuitive than we assume—a few days with an open mind is enough to get a sense of how best you can use it for what you need. This is often what separates most lawyers from those who have learned how to get the most out of AI. And it is a barrier of will, not of aptitude.</p><p>Very soon, the best lawyer who refuses to learn AI will be no match for the average one who does. That is not a reason to ease the transition.</p><p>It is a reason to stop pretending there is time for one.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[Holding Agents Liable]]></title>
            <link>https://paragraph.com/@exmachina/holding-agents-liable</link>
            <guid>8NYuoeU9xJFjHz81KUM4</guid>
            <pubDate>Thu, 04 Jun 2026 15:12:38 GMT</pubDate>
            <description><![CDATA[Autonomous AI agents will be able to collude without being told to. When that happens our existing legal frameworks will have no one to hold responsible. Liability for agentic AI should be traceable, not absolute. ]]></description>
            <content:encoded><![CDATA[<p><em>Autonomous AI agents will be able to collude without being told to. When that happens our existing legal frameworks will have no one to hold responsible. Liability for agentic AI should be traceable, not absolute.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original at </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/agentic-ai-legal-liability-artificial-intelligence-collusion-accountability-surveillance-personalized-pricing-11780323021709.html"><em>this link</em></a><em>. For a full archive of all my articles please visit </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>my website</em></a><em>.</em></p><hr><p>Nine years ago, in <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://rahulmatthan.com/ex-machina/2017/033.-colluding-algorithms/">an article in this column</a>, I tried to imagine what would happen if autonomous algorithms were let loose in a digital market with instructions to maximize profit. I believed that, even if they had not explicitly been told to do so, they would find ways to collude with other algorithms to achieve that outcome. If this happened, I had pointed out, our laws would be woefully ill-suited to address it.</p><p>Nine years later, agentic artificial intelligence (AI) is here—and the problem is not that our laws cannot reach it. It’s that the legal doctrine that does may reach too far.</p><h3 id="h-collusion-without-conspiracy" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Collusion Without Conspiracy</h3><p>What happens when autonomous AI agents are set loose in a market? In <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://arxiv.org/abs/2404.00806">a recent experiment</a>, researchers gave a pair of large language model-based pricing agents a market to compete in and a simple instruction to maximize profits. They neither instructed them to coordinate with one another nor provided them with tools to communicate. Despite this, the agents quickly learnt to hold prices above competitive levels and refrain from undercutting each other to avoid triggering a price war.</p><p>But this is just the tip of the iceberg. According to law professor and consumer advocate Zephyr Teachout, this behaviour can be easily augmented and turned on consumers with what she calls “<a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://ft.pressreader.com/v99c/20260526/281848650257426">surveillance pricing</a>”—the use of information about a consumer to generate a personalized price for that person.</p><p>When e-commerce agents are equipped with this, they can use their knowledge of our browsing history and device information, as well as the urgency of our need, to offer us bespoke prices tailored to what they know we will be willing to pay. For example, sellers would charge parents more for diapers because they just bought children’s cough syrup, knowing that when their child is sick, they may be unwilling to shop around for a better offer.</p><h3 id="h-a-law-with-no-one-to-hold" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">A Law With No One to Hold</h3><p>We have, so far, relied on <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.indiacode.nic.in/handle/123456789/2010">competition law</a> to protect us from these harms. But this law was designed partly to identify rival businesses that secretly agreed to fix prices, carve up markets or rig bids. Because it assumes that markets are anti-competitive when businesses agree to make them so, it prohibits agreements that enable collusion with the intent to harm. If collusive actions are taken by autonomous agents of their own accord, with no human to attribute intent and no price ‘agreement’ on record, no competition law violation can be made out.</p><p>Indian courts have already ruled on this question. When the pricing algorithms used by Ola and Uber were <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://indiankanoon.org/doc/65191688/">challenged as anti-competitive</a>, the court held that an algorithm setting the price does not, in and of itself, prove collusion. When algorithms autonomously coordinate with each other, there is neither an identifiable actor to establish intent nor any form of agreement between them that satisfies the conditions required to establish an offence.</p><p>But we still need to hold someone liable when a person is harmed by autonomous agentic systems. One option would be to attribute liability to the company that built the AI model. This, however, would be patently unfair, since the developers of general-purpose AI models can hardly be expected to foresee, let alone prevent, everything that AI agents developed by them will eventually do for users.</p><p>It probably makes far more sense to hold the deployer of an AI agent accountable—except that when agents can spawn other agents, harms often occur several layers down the stack. What’s more, when multiple deployers spawn many agents and each of them spawns several more sub-agents, it is in the interplay of this diversity of sub-agents that harm occurs. How can anyone be held liable when the damage is so far removed from a single person’s actions?</p><h3 id="h-traceable-liability" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Traceable Liability</h3><p>The trouble is that in India, this is entirely possible. In <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://indiankanoon.org/doc/1486949/"><em>M.C. Mehta vs Union of India</em></a>, the Supreme Court held that an enterprise engaged in a hazardous activity is absolutely liable for the harm that results. This was a departure from the older rule of <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Rylands_v_Fletcher">strict liability</a>, under which an enterprise could escape by pointing to an act of God or that of a third party. Absolute liability admits no such defences.</p><p>While this was a case about oleum gas and chemical plants, its logic—that those who unleash a dangerous force are liable for everything that happens when it escapes their control—maps cleanly onto situations where autonomous agents slip the leash. This means that a deployer may not be able to avoid liability because the harm was caused by a sub-agent several layers down the system that it never built.</p><p>If this is how liability is attributed, it could chill the development of AI in India. When anyone who deploys an agent is liable for everything it and its sub-agents go on to do, no one will dare deploy one. And agentic AI would become commercially unviable.</p><p>In my article nine years ago, I argued for guardrails to prevent this harm. I am now more convinced than ever that they serve an important function. By making liability legible even when the actual harm is caused several layers down, we would be able to assign responsibility fairly and proportionately to the autonomy each person chose to grant their agent.</p><p>Liability should be traceable, not absolute. If every agent is made to carry a record of who deployed it, along with the limits within which it is designed to function, we will have a better chance at holding the right person or persons responsible for harm.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[When AI Writes]]></title>
            <link>https://paragraph.com/@exmachina/when-ai-writes</link>
            <guid>K9P0Ec7iIdEdCHebibAS</guid>
            <pubDate>Wed, 27 May 2026 10:02:52 GMT</pubDate>
            <description><![CDATA[The controversy over the role of AI in this year's Commonwealth Foundation Prize will force the literary world to take a closer look at the content they publish. What they should do instead is understand how it works so they can use this as the tool it is.]]></description>
            <content:encoded><![CDATA[<p><em>The controversy over the role of AI in this year's Commonwealth Foundation Prize will force the literary world to take a closer look at the content they publish. What they should do instead is understand how it works so they can use this as the tool it is.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/literary-invasion-commonwealth-prize-jamir-nazir-ai-written-artificial-intelligence-11779715856584.html"><em>here</em></a><em>. For the full archive of all my articles, please visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>website</em></a><em>.</em></p><hr><p>Last week, the internet was <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.independent.co.uk/arts-entertainment/books/news/commonwealth-short-story-winner-ai-generated-jamir-nazir-granta-b2980039.html">abuzz</a> with allegations that this year’s winner of the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://commonwealthfoundation.com/short-story-prize/">Commonwealth Foundation prize</a> for Caribbean regional short fiction had been written using artificial intelligence (AI). Not only had the winning story, ‘The Serpent in the Grove,’ passed through several rounds of internal review before being selected as the winner from over 7,000 submissions, it had also been <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://granta.com/the-serpent-in-the-grove/">published</a> in <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://granta.com/">Granta</a>, a literary magazine that has carried work by the likes of Ishiguro, Rushdie and Zadie Smith.</p><p>The public response to these revelations has spanned the full range of emotions—from indignation at the author for trying to pass his work off as original to anger with the technology itself for encroaching upon a domain that many believe must always remain the preserve of human wordsmiths. But the more we try to find traces of AI in what we read, the less time we have to understand all that it can do for us. I spent the last month trying to figure out just that.</p><h3 id="h-excessive-caution" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Excessive Caution</h3><p>The immediate consequence of last week’s events will be excessive caution. Editors, publishers and juries around the world will run every submission they receive through <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.pangram.com/">AI detectors</a> to make doubly sure of the provenance of whatever they select, but since those filtering techniques are themselves probabilistic, there is every likelihood that at least a few pieces of human writing will also get caught in the dragnet.</p><p>This is exactly what we should not be doing. Given the rapid pace at which AI has improved in the last year alone, this may well be the last time we will be able to detect the hand of AI in what we read. Rather than blame an award jury for not being able to tell whether what they were reading was crafted by AI, we should be reflecting on what it means for writing now that AI is good enough to trick the most discerning of us.</p><p>Attempting to ban AI use for writing, as many are keen to do, would be futile. AI is a tool, and writers have always used tools to enhance their craft. Each time a new technology has become available—when we switched from legal pads to typewriters and then from typewriters to word processors—there have always been those who warned that no good would come of adopting these new-fangled techniques. But we went ahead anyway, learnt the new possibilities these tools enabled and expanded our craft in wondrous ways.</p><h3 id="h-the-tool-creates" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">The Tool Creates</h3><p>That said, AI is in a different class entirely as a tool. Every other tool that writers used helped produce content. AI is the first that can actually create it. If the quality of what it makes is disappointing, it is because we are still learning to use it. With a little time and practice, that will change. Once we have mastered its use, AI-generated content will be as good as anything we produce ourselves.</p><p>As regular readers of this column will attest, I have been using AI to assist my writing long before it was popular. When I first <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://rahulmatthan.com/ex-machina/2022/307.-its-getting-real/">wrote an article entirely with AI</a>, it was so hard to get it to pass as even vaguely human that I had to painstakingly prompt the article into existence one sentence at a time.</p><p>Since then, I have <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://rahulmatthan.com/ex-machina/2024/377.-getting-ai-to-work-for-you/">incorporated AI into my process</a> in as many ways as possible—to the point where I can no longer tell which part of my article came from AI and which did not. I use it for research, for fact-checking and to find the exact right words to use to make the most convincing argument. The more I use it, the more surprised I am at how rapidly it continues to improve.</p><p>But because I use it so much, I am also acutely aware of all it cannot do. AI conversations are constrained by what they can hold in active memory. Modern models claim context windows of up to a million tokens, but <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://arxiv.org/abs/2307.03172">coherence degrades</a> long before the window fills. Characters drift, plot threads slip and what was established in chapter two no longer shapes chapter 12. Which is why, when friends in publishing lecture me about the shortcomings of AI, I stay silent—a full-length AI-generated book is still hard to create.</p><h3 id="h-a-book-in-ten-days" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">A Book in Ten Days</h3><p>Last month, I decided to see if that was still true. Has AI advanced enough for me to fashion a writing system that can produce book-length fiction entirely on its own?</p><p>To properly validate this thesis, I forced myself to work under a single, clearly defined constraint: not a single word of the final text could come from me. While I could provide feedback on whether a given passage worked or not, much like a human editor working with an author would, I would not, under any circumstances, tell the model to include specific words or phrases in the text.</p><p>In 10 days, we were done. Starting from a single prompt that offered broad suggestions on plot, we were able to produce a 75,000-word book. It took multiple conversations back and forth to work out the structure, characters, locations and narrative devices, and several iterations to address internal consistency, but in the end, every word of the final product was generated by AI.</p><p>You can read it, in full, at <a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://the-recognition-problem.com">https://the-recognition-problem.com</a> where the entire story has been laid out, chapter by chapter, on a website built by AI. In the ‘<a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://the-recognition-problem.com/making/">Making</a>’ section of the website, there are details on how I created it, the scaffolding I built and the story bible that served as the ‘long-term memory’ that AI lacks. And, for those who care about these things, the argument I had with Claude over who should claim <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://the-recognition-problem.com/making/authorship/">authorship</a> over it.</p><p>This is not the best book you will read this year. It will not win me prizes or commendations.</p><p>It is, however, an example of what AI is already capable of.</p><p>And a sign of things to come.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[The Aadhaar VC]]></title>
            <link>https://paragraph.com/@exmachina/the-aadhaar-vc</link>
            <guid>9NA4VsGHW7sUABG6IQzR</guid>
            <pubDate>Wed, 20 May 2026 09:52:10 GMT</pubDate>
            <description><![CDATA[The outcry over Aadhaar in Google Wallet misreads what verifiable credentials actually do: lets us prove who we are in a privacy-protecting way. India built this capability long before the rest of the world—the real risk now is that we use it too timidly. ]]></description>
            <content:encoded><![CDATA[<p><em>The outcry over Aadhaar in Google Wallet misreads what verifiable credentials actually do: lets us prove who we are in a privacy-protecting way. India built this capability long before the rest of the world—the real risk now is that we use it too timidly.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/privacy-battle-aadhaar-google-wallet-digital-identity-system-kyc-uidai-dpi-11779105867151.html"><em>here</em></a><em>. For a full archive of all my articles, please visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>website</em></a><em>.</em></p><hr><p>Last month, when <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://blog.google/products-and-platforms/platforms/google-pay/aadhaar-digital-id/">Google announced</a> that Indian residents can now store their Aadhaar verifiable credentials in their Google Wallet, the reaction was shrill. Since then, much ink has been spilt about the implications of this announcement and what it means for our personal data and digital sovereignty. Reading these pieces, it seems that much of the concern stems from an imperfect understanding of what has been implemented and the benefits it can bring.</p><h3 id="h-the-physical-route" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">The Physical Route</h3><p>To understand what this is all about, refer to <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://uidai.gov.in/images/Aadhaar_Act_2016_as_amended.pdf">Section 4(3) of the Aadhaar Act</a>, which states that holders of an Aadhaar number can voluntarily use it to establish their identity. They can do so physically—by presenting their Aadhaar card to whoever asks for it—or electronically, through authentication processes or offline verification.</p><p>The most common use of Aadhaar is physical. When someone asks for proof of my identity, I pull out my Aadhaar card and show it. Truth be told, even though Aadhaar was designed to be an identity number, it is primarily used as an identity card. This is unfortunate because the physical Aadhaar card was never designed for this and lacks tamper-resistant features that would have made it hard to duplicate. Today, anyone with working knowledge of Photoshop can produce a fake Aadhaar card that is indistinguishable from the original.</p><p>There is another problem with the physical card. Once you hand it over, a photocopy captures all the information on it, regardless of what exactly the verifier needs to know or whether you intended it. There is no mechanism for selectively disclosing information in a way that protects our privacy.</p><h3 id="h-authentication-and-verification" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Authentication and Verification</h3><p>Online authentication is a far more reliable way to prove your identity. It allows a requesting entity to confirm that the details claimed by someone presenting an Aadhaar number match those associated with the Aadhaar number in the Central Identities Data Repository (CIDR). This is the process that banks and telecom companies use to onboard new customers for their services, and it has been approved under the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.indiacode.nic.in/handle/123456789/2036?view_type=search">Prevention of Money Laundering Act</a> as a valid method of KYC verification.</p><p>However, online authentication can only be carried out by entities specifically registered with the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://uidai.gov.in">Unique Identification Authority of India (UIDAI)</a> as <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://uidai.gov.in/images/4_The_Aadhaar_Authentication_and_Offline_Verifications_Regulations_2021.pdf">Authentication User Agencies (AUA)</a>—and not everyone is allowed to become one. What’s more, since each authentication is performed in real time against the Aadhaar database, it comes at a cost that not everyone is willing to bear.</p><p>Offline verification yields the same results without connecting to the CIDR. The user presents a digitally signed credential issued by the UIDAI; the verifier checks this locally and obtains the same assurance of the holder’s identity as online authentication would have provided. The UIDAI itself is never in the loop.</p><p>Just as with online authentication, not everyone is permitted to conduct offline verification. That privilege is reserved for registered <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://indiankanoon.org/doc/95940041/">Offline Verification Seeking Entities (OVSEs)</a>—the only entities legally permitted to verify an Aadhaar number holder under the provisions of <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.indiacode.nic.in/show-data?actid=AC_CEN_37_85_00001_201618_1517807328460&amp;sectionId=49433&amp;sectionno=8A&amp;orderno=10">Section 8A of the Aadhaar Act</a>. They can do so only with the consent of the Aadhaar number holder for the specified purpose and are not allowed to share this information with any other entity. As a result, they operate, for all intents and purposes, under similar constraints as AUAs who conduct online authentication.</p><h3 id="h-untapped-potential" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Untapped Potential</h3><p>Why then is there a furore over Google being appointed an OVSE? All that Google is allowed to do is provide users with a digital store for an identity credential issued by the UIDAI. Functionally, this is no different from downloading a digital copy of your Aadhaar from the UIDAI website and storing it on your laptop, mobile phone or a cloud provider of your choice. By law, Google and all the other 100 or so OVSEs that have been appointed operate under strict data security obligations and legal restrictions against the unauthorized use or sharing of this information.</p><p>Around the world, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.w3.org/TR/vc-data-model/">verifiable credentials</a> are fast becoming a reliable identity solution. If anything, India is playing catch-up in a field it once dominated. The EU enabled verifiable credentials under its <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://digital-strategy.ec.europa.eu/en/policies/eudi-regulation">revised eIDAS regulation</a>, and every member state is now obliged to offer its citizens a digital identity wallet that supports verifiable credentials by the end of this year; and by December 2027, every private-sector provider in the EU is required to accept them. In the US, mobile driver’s licences in the form of verifiable credentials are now accepted at <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.tsa.gov/digital-id/participating-states">TSA checkpoints across 20 states</a>.</p><p>If anything, I worry that we are not doing enough. Section 4(3) allows us to share our Aadhaar with whomever we choose. If that is the case, why can I not share my Aadhaar verifiable credential with any hotel I want, regardless of whether it has been designated as an OVSE or not? I would rather do this than allow them to take a photocopy of my physical card and worry that the copy they just made will one day end up in the trash. If I ever need to prove I am an adult, why can I not just generate a verifiable credential that selectively masks all identifying information and just confirms that I am above 18, so that I don’t have to share any more information than I have to?</p><p>India built a world-class digital identity system long before other countries started to think about it. It’s high time we allowed our citizens to unlock the full potential of what we built.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[Retail Tokenisation]]></title>
            <link>https://paragraph.com/@exmachina/retail-tokenisation</link>
            <guid>tzeNan2LKtiiHSnOb7DI</guid>
            <pubDate>Wed, 13 May 2026 08:27:37 GMT</pubDate>
            <description><![CDATA[Every previous wave of financial digitisation made existing systems run faster. Tokenisation is structurally different—by placing assets and money on a single shared ledger, it rebuilds the very shape of finance. ]]></description>
            <content:encoded><![CDATA[<p><em>Every previous wave of financial digitisation made existing systems run faster. Tokenisation is structurally different—by placing assets and money on a single shared ledger, it rebuilds the very shape of finance.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/tokenize-sovereign-debt-india-e-rupee-finance-evolve-rbi-cbdc-g-secs-crypto-digital-currency-11778509316638.html"><em>here</em></a><em>. For the full archive of all my articles, please visit </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>my website</em></a><em>. </em></p><hr><p>At the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.globalfintechfest.com/">Global Fintech Fest</a> in Mumbai last year, the governor of the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.rbi.org.in/">Reserve Bank of India (RBI)</a> announced the launch of a "next-generation financial market infrastructure," designed to "tokenise financial assets and settlements." While it received no more than a passing mention in his speech, the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.medianama.com/2025/10/223-rbi-governor-fintech-vision-inclusion-trust-2025-digital-rupee-ai-dpi/">Unified Markets Interface</a> he mentioned appears to be an early signpost of the direction in which the digitization of India's financial sector is likely to progress.</p><h3 id="h-beyond-dematerialization" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Beyond Dematerialization</h3><p>To understand the significance of this announcement, it is important to be clear about what a tokenised asset is and how it works. Tokenisation is the process of representing a financial asset as a digital entry on a shared ledger, so that the entry itself becomes the asset, rather than a record pointing to one held elsewhere. A tokenised asset is, therefore, a digital artefact that carries within it information about what the asset is, who owns it, what payments are due against it, and the rules governing its transfer. To transfer the ownership of a tokenised asset, you need to move the entry itself.</p><p>If this sounds similar to <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Dematerialization_(securities)">dematerialised shares</a>, the difference lies in the ledger. Demat shares are held in the depository's database, and when one is bought or sold, the transaction is communicated via telecom messages, and balances get settled through end-of-day reconciliations. A tokenised asset ledger, on the other hand, is a <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://rahulmatthan.com/ex-machina/2023/322.-the-unified-ledger/">single digital record</a> that multiple participants can see and update in accordance with agreed rules. As a result, different assets sit alongside each other and can be transferred between owners on the same ledger.</p><h3 id="h-when-money-and-assets-share-a-ledger" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">When Money and Assets Share a Ledger</h3><p>What would elevate this even further is if the funds used to procure these tokenised assets are themselves available on the same ledger. This is where RBI's wholesale <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Digital_rupee">central bank digital currency (CBDC)</a> can play a role. The <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://rahulmatthan.com/ex-machina/2022/294.-a-new-digital-coin/">wholesale e-rupee</a> is a CBDC issued by the RBI for commercial banks to use among themselves. When this is combined with tokenised financial assets on the same ledger, transaction speed and certainty improve significantly.</p><p>To understand how this would work, let's take the example of <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Certificate_of_deposit">Certificates of Deposit (CDs)</a>—short-term debt instruments that banks often issue to quickly raise funds. Today, a buyer purchasing a CD pays for it through the interbank money transfer system, while the CD itself is transferred by a depository from the issuer's account to the buyer's account. These two transfers occur on different systems, with primary issuances settling on a <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/T%2B1">T+1</a> basis and secondary trades on either T+0 or T+1. As a result, till settlement, both parties carry a small risk that the other side will not perform.</p><p>When a CD is tokenised, both the CD and the money used to buy it sit on the same digital ledger, so that when the trade takes place, the buyer's digital rupee moves to the issuer at exactly the same instant as the issuer's CD tokens move to the buyer. Either both transfers happen, or neither does.</p><p>A tokenised CD can also incorporate <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Smart_contract">smart contracts</a> (code embedded directly into a token's design) that upon maturity, destroy the tokenised CD and release an equivalent amount of digital rupees from the issuer's account as specified by the deal. The entire transaction can be done programmatically, with no manual intervention required, no separate depository action and no reconciliation between the parties to confirm that the trade has been settled.</p><p>Once it proves reliable and settlement risk turns negligible, the capital that today sits locked up between trade and settlement is freed. Reconciliation—which currently requires the issuer, buyer, depository, clearing corporation and trade reporting platform to each keep their own records and match them against one another's—becomes redundant. And RBI, which today can only see what external platforms report to it, would be able to monitor the whole market in real time on its own ledger.</p><h3 id="h-a-different-shape-not-just-a-faster-one" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">A Different Shape, Not Just a Faster One</h3><p>Tokenised CDs are just one example. Once the digital rails needed are in place, government bonds, bank-issued IOUs and a growing range of other financial assets could sit on the same shared ledger and be traded the same way.</p><p>So far, our financial digitisation measures have worked within the existing architecture, replacing analogue channels with digital ones. Demat platforms turned paper records into digital form. Electronic trading moved orders from telephones to terminals. <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.npci.org.in/what-we-do/upi/product-overview">UPI</a> moved payment instructions from cheques to phones. In each case, while individual systems were made to work faster, they still had to coordinate with each other.</p><p>Tokenisation is structurally different from each previous wave. Instead of merely adding a layer, it removes the gap between the asset and money by placing them on a single record. It rebuilds not just the speed of our financial system, but also its shape.</p><p>Last October, RBI quietly launched a <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.business-standard.com/economy/news/rbi-deposit-tokenisation-pilot-cbdc-wholesale-digital-tokens-oct8-125100700532_1.html">pilot to tokenise Certificates of Deposit</a>, settling them in wholesale digital rupees on a permissioned ledger it runs. The natural next step is the market for <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Government_bond">government securities (G-Secs)</a>. While <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://rbiretaildirect.org.in/">Retail Direct</a> widened access, the minimum lot size remains beyond the reach of most small investors. Tokenised G-Secs in fractional denominations would bring the safest yield-bearing instrument to households that today rely on bank deposits and gold. The rails are ready for the government to get sovereign debt onto them. Every previous wave of financial digitisation speeded up existing systems. This one will change what they are.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[Mirror Life]]></title>
            <link>https://paragraph.com/@exmachina/mirror-life</link>
            <guid>DZlhy6fIO7BuzycSSdBM</guid>
            <pubDate>Wed, 06 May 2026 12:54:19 GMT</pubDate>
            <description><![CDATA[When scientists voluntarily abandoned mirror-life research, they demonstrated that it is still possible for the scientific community to pause its own progress. AI, on the other hand, has continued despite the many efforts to halt its continued development. How did biotech succeed where AI failed? ]]></description>
            <content:encoded><![CDATA[<p><em>When scientists voluntarily abandoned mirror-life research, they demonstrated that it is still possible for the scientific community to pause its own progress. AI, on the other hand, has continued despite the many efforts to halt its continued development. How did biotech succeed where AI failed?</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original at this </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/ai-scientists-risks-mirror-life-chiral-scientific-community-artificial-intelligence-technology-11777887537255.html"><em>link</em></a><em>. For a complete archive of all my articles, please visit </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>my website</em></a><em>.</em></p><hr><p>In December 2024, a number of scientists from around the world signed a <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.science.org/doi/10.1126/science.ads9158">four-page paper</a> in Science that urged their own community to ensure that an entire class of organisms is never created. Their efforts managed to halt progress in a field that many of them had themselves been pursuing. This marked a rare moment in science when an entire field voluntarily abandoned the path it had been on because of the risks scientists saw ahead of them.</p><p>The science in question was mirror-life, and the fact that such a moratorium was achieved raises the question of why similar outcomes were not achieved in the field of artificial intelligence (AI). How was a small band of scientists able to pause progress in mirror-life when some of the most powerful voices in technology failed to do so in AI?</p><p>For this, we need to first understand what mirror-life is.</p><h3 id="h-what-mirror-life-is" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">What Mirror Life Is</h3><p>All complex naturally occurring biological molecules exist in one of two mirror-image forms, or <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Chirality_(chemistry)">chiralities</a>. These forms are identical in every respect except that one cannot be superimposed on the other, much like our left hand cannot on our right. DNA for example, exists as right-handed nucleotides and the proteins they encode are made up of left-handed amino acids. This pattern repeats in every microbe, plant and animal, and has done so for four billion years.</p><p>A mirror organism would be identical to its natural counterpart, except that its orientation would be reversed. It would have left-handed nucleotides encoding right-handed proteins, and its every molecule would be a mirror image of its natural counterpart. Nothing like this exists in nature, but until the paper in Science, efforts had been underway to create such an organism. It was effortful but not beyond the realm of the possible.</p><p>The concern is not whether we can create these molecules, but what happens once we do. Our immune systems, the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Bacteriophage">bacteriophages</a> and other elements of our biome that keep us healthy, as well as the antibiotics we use to fight disease, all rely on chirality-specific bindings. None of them would be able to protect us from mirror-microbes that exist under an entirely different set of rules. Even benign mirror bacteria would breeze through our defences—because nothing in nature can check their spread.</p><h3 id="h-five-conditions" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Five Conditions</h3><p>What is truly remarkable about the 2024 paper is that its lead author, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://cbs.umn.edu/directory/faculty/kate-adamala">Kate Adamala</a>, had been one of four principal investigators on a major US <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.nsf.gov/">National Science Foundation</a>-funded grant for mirror cell research. Since then, the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.mbdialogues.org/">Mirror Biology Dialogues Fund</a> has convened follow-on meetings in Manchester and at the Pasteur Institute, with another planned at the National University of Singapore. So far, the moratorium has held.</p><p>Five conditions made it stick: the field itself agreed that the harm would be uncontainable; no commercial capital had flowed into this dangerous capability; the community was small enough to coordinate; no state had staked its competitive position on getting there first; and the pioneers could be persuaded to abandon their own work. Had all five not held simultaneously, there may still be scientists going down this path.</p><p>This is not the first time the scientific community has chosen to pause its own progress. When <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Recombinant_DNA">recombinant DNA</a> became a reality, Paul Berg, Stanley Cohen and Herbert Boyer—each a pioneer in the field—were central to the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Asilomar_Conference_on_Recombinant_DNA">Asilomar conference</a> and the moratorium that followed. The safety guidelines that emerged became guardrails for the research that came after. The mirror life community is following in their footsteps.</p><h3 id="h-applicability-to-ai" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Applicability to AI</h3><p>The AI community attempted the same Asilomar approach when, in March 2023, the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://futureoflife.org/">Future of Life Institute</a> released an <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://futureoflife.org/open-letter/pause-giant-ai-experiments/">open letter</a> calling for a six-month pause on frontier AI development. Thousands signed, including a luminary in the field, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://yoshuabengio.org/">Yoshua Bengio</a>. But unlike recombinant DNA and mirror-life, AI development did not stop and continues at a blistering pace to this day.</p><p>As it happens, AI fails on every one of those five conditions. There is no consensus that its harms are uncontainable; most AI labs believe they will be able to constrain the technology enough to ensure no harm results. By the time the Future of Life Institute got its act together, AI labs were already worth tens of billions and had committed to spending more. The community was large, multinational and fractured along ideological and ethical lines, and the US and China had already staked their national strategy on AI dominance. Even though <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.cs.toronto.edu/~hinton/">Hinton</a> and Bengio advised caution, it was the founders of AI labs who really mattered—and they were going hell for leather.</p><p>But the deeper asymmetry is in the stakes. Mirror life would only have destroyed the biological commons. As serious as this is, frontier AI accelerates the very disciplines—biology, immunology, ecology—that produced the mirror life moratorium in the first place. A broad pause risks slowing entire fields that depend on it to do their work.</p><p>The mirror-life example cannot serve as a model for AI policy. While there may be narrow verticals where the same diagnostic applies (autonomous biological design assistance may be one), these are specialist sub-problems whose answers cannot drive the governance of AI as a whole. For that, we must build governance capacity—through post-deployment transparency, capability evaluations and the steady augmentation of regulatory skills that can meet the demands of a new and dynamic technology. While mirror life is a precedent worth admiring, it's not one we can follow.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[The Visibility Problem]]></title>
            <link>https://paragraph.com/@exmachina/the-visibility-problem</link>
            <guid>MtegKzdIYvn2Jgzsm9Vu</guid>
            <pubDate>Wed, 29 Apr 2026 09:56:41 GMT</pubDate>
            <description><![CDATA[India's health insurance market is caught in a vicious cycle: healthy people won't buy coverage because premiums are too high, and premiums are too high because healthy people won't buy coverage. If insurers can use granular health data to price risk more accurately, coverage may once again become worth buying. ]]></description>
            <content:encoded><![CDATA[<p><em>India's health insurance market is caught in a vicious cycle: healthy people won't buy coverage because premiums are too high, and premiums are too high because healthy people won't buy coverage. If insurers can use granular health data to price risk more accurately, coverage may once again become worth buying.</em><br><br><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/ai-india-health-stack-data-insurance-coverage-ayushman-bharat-artificial-intelligence-risk-premiums-11777291989414.html"><em>here</em></a><em>. For a complete archive of all my articles, please visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>website</em></a><em>.</em></p><hr><p>Nearly 70% of Indians lack meaningful health insurance. Our <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://irdai.gov.in/handbook-of-indian-insurance">penetration rate— just 0.35% of GDP</a>—is lower than that of China, Hong Kong and Taiwan. The conventional explanation is that Indians either do not understand insurance or cannot afford it. But in reality, the problem is not behavioural as much as the fact that Indian insurers, for the most part, lack the population-level health data that they need to price risk accurately.</p><h3 id="h-mispriced-risk" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Mispriced Risk</h3><p>When premiums are too high relative to actual risk, healthy people—who know they are unlikely to need expensive care—see no reason why they should buy coverage. When that happens, the risk pool gradually shrinks until it consists largely of those who expect to make claims. This, in turn, results in higher premiums, which, in turn, results in even more healthy people staying away, pushing our health insurance market into a vicious cycle that is hard to escape.</p><p>Take the example of <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.thelancet.com/journals/landia/article/PIIS2213-8587(23)00119-5/fulltext">diabetes</a>, the single largest driver of chronic disease claims in the country. Today, insurance premiums for the disease are determined based on crude national averages or the prevalence of the disease across given age bands. This is despite the fact that its prevalence is known to vary widely across regions—from 4.8% in Uttar Pradesh to 26.4% in Goa. None of this regional divergence is reflected in the premiums people have to pay.</p><p>At its core, an effective insurance system is a <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Risk_pool">mechanism for pooling risk</a>. Individual premiums are not set based on what the insured person's bills will cost, but on the expected average expenses of people like them. The larger and more diverse the pool, the more accurately risk can be priced, and the more stable premiums become over time. This is why the vicious cycle described above is so damaging: healthy people who exit the pool don't just reduce revenue, they make the pool itself less representative, the pricing less accurate, and the premiums higher.</p><h3 id="h-break-the-cycle" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Break the Cycle</h3><p>Better data could break this vicious cycle. If insurers move beyond crude age-band or national-average assumptions and <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Risk-based_pricing">price risk at genuinely granular levels</a>—by region, occupation, co-morbidity profiles and lifestyle markers—they can offer premiums that healthy cohorts might actually find worth paying. A 32-year-old software professional in Bengaluru with no family history of chronic illness should not be priced as though she carries the average risk of all Indians aged between 30 and 40. She almost certainly doesn't. But insurers need the data to be able to take that call.</p><p>For this to happen, we need population-level health data that is sufficiently granular to be useful. Accurate <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Actuarial_science">actuarial models</a> built on rich, longitudinal data don't just lower premiums for healthy people, they improve the efficacy of the entire system. Lower premiums attract broader participation. Broader participation generates better data. Better data results in finer segmentation. Finer segmentation allows even more accurate pricing, effectively inverting the vicious cycle.</p><p>Where can we source this data from? As it happens, India has a digital infrastructure capable of processing vast amounts of health data at scale. The <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://abdm.gov.in/">Ayushman Bharat Digital Mission (ABDM)</a> currently has access to <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.pib.gov.in/PressReleasePage.aspx?PRID=2081482">over 500 million health records across 80,000-plus healthcare facilities</a>; while its primary objective is to provide access to patient records across the healthcare system, it should not be hard to modify it so we can use it to improve our actuarial intelligence. The key is doing so safely, without putting the personal data of patients at risk of exposure in the process.</p><p>The original ABDM blueprint had an anonymiser module that was designed to de-identify health records for use in <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://rahulmatthan.com/ex-machina/2024/409.-secondary-use-of-health-data/">privacy-preserving applications</a>. To the best of my knowledge, this has not yet been built, but it is evident how an effective anonymisation solution could make ABDM data useful for this purpose. Since the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.meity.gov.in/content/digital-personal-data-protection-act-2023">Digital Personal Data Protection Act of 2023</a> only applies to "personal data," properly anonymized data would not fall within its ambit. Which means that it could be used to build actuarial models without requiring the consent of the individuals concerned.</p><h3 id="h-modeling-risk" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Modeling Risk</h3><p>The last element that needs to be added to the mix is artificial intelligence (AI). Traditional actuarial methods rely on structured tables and known risk factors—age, pre-existing conditions and occupation. They work well enough when the categories are broad and the data is limited. But if we use AI, applying it to the large anonymised datasets that ABDM can make available, we should additionally be able to identify non-obvious correlations between health indicators, allowing us to identify emerging disease clusters before they appear in claims data. This will enable us to model risk trajectories across demographic cohorts that conventional methods would miss entirely.</p><p>At the end of the day, insurance is not really about policies or premiums. It is about information. When insurers cannot see risk clearly, they will price policies defensively, and that is when the system begins to unravel. The availability of useful data allows risk to be measured more precisely, making it possible for insurance markets to expand and stabilise.</p><p>India needs to unlock the actuarial intelligence embedded within the data that its digital health infrastructure is beginning to generate. Once we do that, we may discover that the biggest barrier to universal insurance coverage in the country was never affordability, but visibility.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[The Quantum Reckoning]]></title>
            <link>https://paragraph.com/@exmachina/the-quantum-reckoning</link>
            <guid>2kJZ8gkueOzwNy6D4TcD</guid>
            <pubDate>Wed, 22 Apr 2026 17:03:14 GMT</pubDate>
            <description><![CDATA[Two research results published in the same week in March 2026 dramatically shortened the estimated runway to a quantum computer capable of breaking modern encryption. For India—which has built more of its public digital life on cryptographic trust than almost any other country—the urgency of what comes next cannot be overstated. ]]></description>
            <content:encoded><![CDATA[<p><em>Two research results published in the same week in March 2026 dramatically shortened the estimated runway to a quantum computer capable of breaking modern encryption. For India—which has built more of its public digital life on cryptographic trust than almost any other country—the urgency of what comes next cannot be overstated.</em></p><p><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/quantum-computing-dpi-aadhaar-digilocker-risk-encryption-digital-public-infrastructure-11776677449385.html"><em>here</em></a><em>. For the full archive of all my articles please visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>website</em></a><em>.</em></p><hr><p>Traditional computers store information in bits. Quantum computers operate very differently. They use <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Qubit">qubits</a>, a whole new information architecture that leverages a quantum property called <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Quantum_superposition">superposition</a>, which allows them to occupy multiple states simultaneously. Quantum machines are no faster at ordinary tasks—the laptop on your desk will probably outperform them at writing documents or running spreadsheets. What they are good at is a narrow class of mathematical problems, including some of those that underpin much of modern cryptography.</p><h3 id="h-when-shors-algorithm-became-practical" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">When Shor's Algorithm Became Practical</h3><p>Most digital systems are secured by one of two algorithms—RSA and ECC. The <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/RSA_cryptosystem">Rivest, Shamir and Adleman (RSA) algorithm</a> operates on the assumption that it is computationally infeasible to factor the product of two very large primes. This is used to protect email, enterprise systems and the digital certificates that secure <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Public_key_infrastructure">public key infrastructure</a>. <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Elliptic-curve_cryptography">Elliptic-curve cryptography (ECC)</a> makes a similar bet on the discrete logarithm problem of elliptic curves. ECC is a lighter, faster alternative used where computational resources are constrained—such as mobile messaging apps, cryptocurrency wallets and authentication protocols. In 1994, the mathematician <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Shor%27s_algorithm">Peter Shor</a> developed an algorithm that solves both these problems using a quantum computer. He showed that breaking the cryptographic protections we rely on would take only one thing—a quantum computer. That said, despite decades of efforts to build one, it remains a notoriously challenging problem. The hardware required to build such a computer that will work reliably without decoherence simply does not exist. And then, in the last week of March 2026, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://research.google/blog/safeguarding-cryptocurrency-by-disclosing-quantum-vulnerabilities-responsibly/">Google Quantum AI</a> demonstrated Shor's algorithm running on 256-bit elliptic-curve cryptography with fewer than 1,200 logical qubits—a roughly twentyfold reduction from earlier estimates. The same week, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.caltech.edu/about/news/caltech-team-finds-useful-quantum-computers-could-be-built-with-as-few-as-10000-qubits">Caltech researchers</a> showed how a fault-tolerant quantum computer can run Shor's algorithm using 10,000 physical qubits rather than the millions previously believed necessary. While neither result means we have built an actual working quantum computer, taken together, they indicate that the runway to doing so has dramatically shortened.</p><h3 id="h-the-floor-beneath-indias-digital-life" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">The Floor Beneath India's Digital Life</h3><p>For India, which has built more of its public life on cryptographic trust than almost any other country, the recalibration needed will probably be more urgent than anywhere else. Every Aadhaar authentication and UPI transaction relies on 2048-bit RSA encryption. DigiLocker documents derive their legitimacy from public key infrastructure. Account Aggregator consents are cryptographically signed, and non-repudiation—the legal assurance that a person cannot later deny what they authorized—rests entirely on those signatures being unforgeable. Quantum computing puts at risk all this foundational digital infrastructure.</p><p>There are two primary concerns that arise. The first concerns digital authentication. Our entire trust infrastructure relies on the assumption that a cryptographic signature guarantees that the person who authorized a given action is who they say they are. This presumption is about to be shattered. The actions we perform today without thinking—paying a merchant via UPI, pulling documents from DigiLocker, porting information through the Account Aggregator framework—all rest on the same mathematical floor. That floor is about to give way.</p><p>The second and probably more serious concern is confidentiality. For decades, we have trusted these cryptographic algorithms to keep our information secure—encrypting private messages and other sensitive data in the belief that no one will ever be able to read them. Quantum computers running Shor's algorithm will make quick work of all such measures, and we will need to urgently evaluate what that means for the security of our information.</p><p>In anticipation of this, bad actors have been <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later">harvesting encrypted traffic</a> for years, hoovering up as many emails, financial transactions and classified cables as they can so that they can decrypt them once new technology lets them. The recent breakthroughs in quantum computing suggest that time is fast approaching.</p><h3 id="h-migration-at-scale" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Migration at Scale</h3><p>The Indian government is seized of the problem. MeitY and CERT-In have issued a <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.pib.gov.in/PressReleasePage.aspx?PRID=2144023">white paper titled Transitioning to Quantum Cyber Readiness</a>. According to the roadmap prepared by the Task Force of the Department of Science and Technology, India's critical information infrastructure must complete post-quantum foundations by 2027 and achieve full migration by 2029. Migration is not as simple as pushing a software update. It will require generating new key pairs with post-quantum algorithms for every entity in the system, re-issuing certificates and upgrading every verifier and signer—all while systems keep running. We will likely need to run classic and post-quantum cryptography in parallel for long enough to catch problems that emerge at scale.</p><p>Our digital public infrastructure (DPI) is decentralized. This is the correct design, as it is grants citizens agency over their own information and explains why it has worked at the scale it has. But it also means that the upcoming cryptographic migration cannot be accomplished by simply upgrading a central server. It will need to reach every wallet, device and endpoint on which a signature is produced or consent granted. That kind of migration takes years—even if we start early. And we have only just started.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[A Matter of Sovereignty]]></title>
            <link>https://paragraph.com/@exmachina/a-matter-of-sovereignty</link>
            <guid>p2Q3mxFx0gZnXKBpQVqI</guid>
            <pubDate>Wed, 15 Apr 2026 08:42:49 GMT</pubDate>
            <description><![CDATA[Now that AI has cybersecurity capabilities that exceed anything that has existed so far, the real question is who gets to decide when, and for whom, those vulnerabilities are fixed. And what are the implications on everyone who does not yet have access to these capabilities. ]]></description>
            <content:encoded><![CDATA[<p><em>Now that AI has cybersecurity capabilities that exceed anything that has existed so far, the real question is who gets to decide when, and for whom, those vulnerabilities are fixed. And what are the implications for everyone who does not yet have access to these capabilities?</em><br><br><em>This is a link-enhanced version of an article that first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/anthropic-mythos-ai-india-cybersecurity-sovereignty-hackers-openai-chatgpt-artificial-intelligence-11776066958021.html"><em>here</em></a><em>. For the full archive of all my Ex Machina articles, visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina/"><em>website</em></a><em>. </em></p><hr><div data-type="x402Embed"></div><p>Last week, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.anthropic.com/">Anthropic</a> announced that its latest artificial intelligence (AI) model, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://red.anthropic.com/2026/mythos-preview/">Claude Mythos</a>, was too dangerous to release. In testing, the company discovered that the model could unearth thousands of hitherto unknown security vulnerabilities in many of the software applications, operating systems and web browsers that the world depends on. Until it could be sure that these capabilities of the model would not be misused, said Anthropic, it believed it was too risky to let the model loose on the world.</p><h3 id="h-lurking-bugs" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Lurking Bugs</h3><p>What was particularly disconcerting was that since some of the bugs had been around for decades, they are deeply embedded in many of the critical systems we rely on. This includes a 27-year-old vulnerability in <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.openbsd.org/">OpenBSD</a>, an operating system believed to be unhackable, and a 16-year-old flaw in <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://ffmpeg.org/">FFmpeg</a>, a video library used by billions of devices and that has passed millions of security tests. The model also demonstrated how attackers could assume complete control of a machine by chaining together vulnerabilities in the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Linux_kernel">Linux kernel</a>; when asked to try to escape a sandbox and contact a researcher, the model succeeded effortlessly, posting details of its actions on public-facing websites without being asked.</p><p>These are just the bugs Anthropic was willing to talk about. Over 99% of the vulnerabilities the AI firm discovered are yet to be patched, and so details about them have been withheld. The question is not whether these bugs will be fixed, but who gets to decide when, and for whom.</p><p>Given the "substantial leap" in the model's cybersecurity capabilities, the company has granted a small number of organisations (several of the world's top tech companies) access to its capabilities so they can scan and patch their systems before these vulnerabilities are exploited. This is, without a doubt, the responsible thing to do. But even as I applaud Anthropic for its restraint, I cannot help but reflect on what this means for everyone else. The small group of organisations with access to Mythos will likely address vulnerabilities in their own systems. But there is a long tail of smaller developers that will not have access to these capabilities, whose software is just as likely to have critical bugs that affect a disproportionately large number of people.</p><h3 id="h-the-race-to-exploit" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">The Race to Exploit</h3><p>The bigger risk is what happens next. Now that thousands of bugs have been identified in testing, it is a matter of time before these vulnerabilities fall into the hands of those looking to misuse them. The moment it announced that it had identified all these vulnerabilities, Anthropic painted a big target on its back. We must assume that hackers and malevolent non-state actors alike are already doing all they can to access this information now that they know that this trove of vulnerabilities exists.</p><p>One might think that, as a leading tech company, Anthropic is probably better equipped than most to keep this information secure. But if there is one thing we know, it is that even the best among us have their moments of weakness. Just weeks before the official Mythos announcement, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://fortune.com/2026/03/26/anthropic-leaked-unreleased-model-exclusive-event-security-issues-cybersecurity-unsecured-data-store/">a misconfiguration in its own content management system</a> exposed nearly 3,000 internal documents to the open internet, including draft blog posts that in hindsight appear to describe Mythos itself. That leak was not the work of a sophisticated attacker but the result of a toggle left in the wrong position. Days later, <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.cnbc.com/2026/03/31/anthropic-leak-claude-code-internal-source.html">a second lapse</a> exposed over half a million lines of source code from <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.anthropic.com/product/claude-code">Claude Code</a>, Anthropic's AI coding tool, to the public for several hours.</p><p>To be clear, I am not pointing this out to suggest that Anthropic is a careless company—what happened to it could happen to anyone. The point I am trying to make is that once knowledge of this information enters the public domain, every minute that passes without these bugs being fixed compounds the risk that they will be used to inflict damage.</p><h3 id="h-the-sovereignty-question" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">The Sovereignty Question</h3><p>But what I worry about the most is what happens when this information reaches rogue actors, who we must presume are already doing everything in their power to gain access to it. <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Zero-day_vulnerability">Zero-day vulnerabilities</a> have long been a favoured tool in the geopolitical militarisation of technology, and many countries have dedicated considerable resources to acquiring them for deployment against their adversaries.</p><p>In 2010, the US and Israel used a piece of malware called <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Stuxnet">Stuxnet</a> to destroy roughly a thousand Iranian nuclear centrifuges by exploiting vulnerabilities they had discovered in the Siemens industrial control software that was being used in its operation. The US government operates an active <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Vulnerabilities_Equities_Process">Vulnerabilities Equities Process</a> to decide which software flaws should be disclosed and which should be retained for intelligence and military use. Stuxnet is just one product created by using these vulnerabilities. It is unlikely to be the last. And while Stuxnet emerged as a result of years of effort by elite teams to identify a handful of exploitable flaws, Mythos can find thousands within weeks.</p><p>AI has reached a point of strategic consequence. While cybersecurity may be the first domain where this asymmetry manifests, similar capabilities will be aimed at health systems and military infrastructure before long. For decades, we have built our critical infrastructure on software that we do not control, and it is distributed by companies we do not influence. Now that their vulnerabilities are being catalogued by tools we cannot access, this is no longer a cybersecurity problem. It is an issue of sovereignty.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
        <item>
            <title><![CDATA[The Digital Media Amendments]]></title>
            <link>https://paragraph.com/@exmachina/the-digital-media-amendments</link>
            <guid>Gayf1sdhzRpII8pupvIW</guid>
            <pubDate>Wed, 08 Apr 2026 14:17:25 GMT</pubDate>
            <description><![CDATA[While the proposed amendments to the IT Intermediary Guidelines Rules may seem modest, the innocuous changes that have been proposed could replace the current, rule-based design of India's internet governance with a regime of executive discretion.]]></description>
            <content:encoded><![CDATA[<p><em>While the proposed amendments to the IT Intermediary Guidelines Rules may seem modest, the innocuous changes that have been proposed could replace the current, rule-based design of India's internet governance with a regime of executive discretion.</em></p><p><em>This article first appeared in the Mint. You can read the original </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://www.livemint.com/opinion/online-views/free-speech-curbs-amendments-india-internet-rules-it-rules-social-media-news-meity-11775475829353.html"><em>here</em></a><em>. For the full archive of all my Ex Machina articles, you can visit my </em><a target="_blank" rel="noopener noreferrer nofollow ugc" class="dont-break-out" href="https://rahulmatthan.com/ex-machina"><em>website</em></a><em>. </em></p><hr><div data-type="x402Embed"></div><p>On 30 March, the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.meity.gov.in/">Ministry of Electronics and Information Technology (MeitY)</a> published <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.meity.gov.in/static/uploads/2026/03/a71a21d35c107f2e528363d3eb17646a.pdf">draft amendments</a> to the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://mib.gov.in/sites/default/files/2024-02/IT(Intermediary%20Guidelines%20and%20Digital%20Media%20Ethics%20Code)%20Rules,%202021%20English.pdf">Information Technology (Intermediary Guidelines) Rules, 2021</a>, which, if passed, will have far-reaching consequences for internet users in India. While each of the three primary amendment proposals does something different, together they will transform the internet from a rules-based regime into one governed by discretion. Though they may seem benign, their bite could be worse than their bark.</p><p>The new Rule 14(2) would expand the powers of the Inter-Departmental Committee (IDC) from hearing just "complaints and grievances" to "any matter" referred directly by the ministry. Rule 8 takes things further by not just expanding adjudicatory power, but who is subject to it—from 'publishers' to anyone who posts about news online. But both these pale in relation to Rule 3(4), which reshapes the source of legal authority.</p><h3 id="h-a-more-powerful-idc" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">A More Powerful IDC</h3><p>Let's go through each provision to better understand how they will all affect us.</p><p>Let us start with Rule 14. Through a set of innocuous adjustments, sub-rule (2) will significantly expand the powers of the IDC. From being an apex appellate body in a three-tier complaint-resolution mechanism for violations of the Code of Ethics, it could become a super-regulator with the power to hear just about "any matter" that the ministry refers to it.</p><p>There are two problems with this. First, since the IDC would have the power to rule on anything the ministry sends it, the recommendations it issues could well exceed the statutory authority under which it was created. But what's far worse is that by accepting references directly from the ministry, parties could be denied the two levels of appeal they are currently entitled to, thus collapsing the current three-tier mechanism into a single executive-controlled process. With this one amendment alone, the government could end up violating principles of both <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Administrative_law">administrative law</a> and <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://en.wikipedia.org/wiki/Natural_justice">natural justice</a>.</p><p>It is worth noting that in August 2021, the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://internetfreedom.in/bombay-high-court-stays-the-operation-of-rule-9-1-and-rule-9-3-of-it-rules-2021/">Bombay High Court stayed</a> the Code of Ethics framework as <em>prima facie</em> violative of Article 19(1)(a) of the Constitution of India—a prohibition subsequently extended by the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://www.livelaw.in/top-stories/madras-high-court-it-rules-2021-code-of-ethics-intermediaries-stayed-181762">Madras High Court</a>. In this backdrop, for the inter-departmental panel to operate within this now tenuous structure would expand its powers even as the constitutionality of the framework itself remains under litigation and is questionable.</p><h3 id="h-expansive-code" class="text-2xl font-header !mt-6 !mb-4 first:!mt-0 first:!mb-0">Expansive Code</h3><p>This brings us to Rule 8(1). As originally drafted, this provision applied only to "publishers of news and current affairs content" and "publishers of online curated content." In other words, regular news outlets as well as their online equivalents. The proposed amendment will extend the applicability of certain provisions to ordinary users who share news or current affairs content. Since sharing posts about news is something we all do, this means that a provision earlier designed for news organisations will now apply to you and me. In effect, the Code of Ethics, a standard of accuracy, fairness and impartiality with which news organizations must comply, could get extended to ordinary internet users who have neither the resources nor the inclination to vet everything they post at this level of rigour.</p><p>But it is the proposed addition of a new sub-Rule (4) to Rule 3 that in many ways is the most disappointing. This new provision seeks to legally elevate clarifications, advisories, orders, directions, standard operating procedures, codes of practice and guidelines to the level of rules and regulations (the only forms of subordinate legislation that the executive branch is constitutionally permitted to enact). If brought into force, it will allow the executive to make a new law without calling it a law, and, in doing so, arrogate upon itself the power and authority that ought to vest with the legislature. Or at the very least be subject to Parliamentary supervision.</p><p>The power of the executive branch to make rules and regulations is always subject to an obligation to place them before Parliament as soon after they have been made as possible. By elevating various informal executive instruments of this kind to the level of enforceable law—none of which need to be laid before the legislative branch—the government seems to be trying to evade a necessary constitutional check on its power.</p><h2 id="h-deregulation" class="text-3xl font-header !mt-8 !mb-4 first:!mt-0 first:!mb-0">Deregulation</h2><p>What makes these regressive proposals particularly disappointing is that they were released for public consultation just three days after the <a target="_blank" rel="noopener nofollow" class="dont-break-out external-link" href="https://prsindia.org/billtrack/the-jan-vishwas-amendment-of-provisions-bill-2026">Jan Vishwas Bill</a> was introduced in the Lok Sabha. The latter, as many have noted, is the single largest horizontal decriminalization effort anywhere in the world, significantly improving the ease of doing business across sectors. Central to this deregulation effort is the principle of regulatory certainty it embodies—that the state should not impose compliance obligations on citizens through instruments that do not carry the weight of the law. For the government to just a few days later introduce amendments that do just that shows how little the left hand appears to know of what the right is doing.</p><p>I am the first to admit how hard it is to govern modern online spaces. These proposed amendments are an attempt to walk a well-known tightrope between allowing free expression online and preventing the harms that can result. But if we cannot find a more effective way to strike that balance, we will replace a system governed by rules with one ruled by executive discretion.</p>]]></content:encoded>
            <author>exmachina@newsletter.paragraph.com (Rahul Matthan)</author>
        </item>
    </channel>
</rss>