top of page
Search

When the Law Delegates to a Probability Distribution

What happens when the same legal system can produce two different decisions from the same facts?


Imagine an immigration authority using a generative AI system to evaluate applications.


The legal facts are the same.


The applicable rules are the same.


The model is the same.


The instructions are the same.


One execution produces:


Approve.


Another produces:


Reject.


Nothing legally relevant has changed.


What changed was the computational path through which the system generated its answer.


This creates a problem that traditional legal theory was not built to solve.


Law knows how to delegate authority to judges, agencies, officials, administrative bodies, and other identifiable decision-makers.


But what exactly happens when authority is exercised through a system that does not contain one predetermined decision?


What happens when the institution has authorized a machine capable of generating a distribution of possible decisions?


That is the question at the center of my new paper:


Delegation to a Probability Distribution: Rethinking Legal Authority in Stochastic Systems


The problem is not simply whether artificial intelligence can make legal decisions.


The deeper problem is this:


Does authorizing a system mean authorizing every decision that system can possibly generate?


The answer cannot automatically be yes.




The Difference Between a Rule and a Distribution


Traditional legal delegation can be simplified like this:


Authority → Decision-maker → Decision


A legislature authorizes an agency.


An agency authorizes an official.


The official exercises legally bounded discretion.


The resulting decision can normally be attributed to someone occupying a recognized institutional role.


Generative AI introduces another structure:


Authority → Model → Probability distribution → Selection → Output


The distinction is fundamental.


A generative system does not necessarily contain a single answer waiting to be retrieved.


It assigns probabilities across possible continuations and produces an output through a decoding or sampling process.


That means the institution may approve the architecture without determining which particular legally consequential output will eventually be produced.


This creates what I call the:



Distributional Authorization Gap


The central proposition is simple:


Authorization of the system does not necessarily imply authorization of every possible output of the system.


Or more formally:


Authorization(Model) ≠ Authorization(All Possible Outputs)


This sounds technical.


Its consequences are not.


If a public authority deploys a probabilistic system capable of producing legally incompatible outcomes under materially identical conditions, legal theory must explain what transforms one generated output into an authorized exercise of public authority.


The fact that the machine was approved cannot be the entire answer.




Randomness Is Not the Same as Legal Discretion


Human decision-making is not perfectly predictable.


Judges disagree.


Administrators interpret ambiguous rules.


Investigators weigh evidence differently.


Two officials can sometimes reach different conclusions.


But that does not make human judgment equivalent to computational stochasticity.


A judge can exercise discretion within a legally constituted office.


The law can ask:


What considerations were permitted?


What reasons were given?


Was the decision within jurisdiction?


Was the evidence sufficient?


Was the interpretation legally available?


Was discretion exercised according to the governing standard?


With a generative system, another source of variation enters the chain.


Even while the legally relevant input remains constant, the computational process itself may allow different outputs.


The legal question therefore changes.


It is no longer enough to ask:


Was the AI system authorized?


The law must also ask:


What exactly was authorized within the space of outcomes the system could produce?


That is a different problem.




A Simple Example


Suppose an agency authorizes an AI system to classify applications.


For Applicant X:


Run A → Eligible


Run B → Ineligible


Assume both runs use the same:


• factual record,

• governing law,

• model,

• system instructions,

• institutional procedure.


If both outputs were technically possible, does that make both legally valid?


Not necessarily.


Technical possibility and legal authorization are different categories.


A machine can be functioning exactly as designed while still producing an output whose legal status is unclear.


This is why reliability alone does not solve the problem.


Accuracy alone does not solve it.


Explainability alone does not solve it.


Human oversight alone does not solve it.


The underlying jurisprudential question remains:


Why does this particular computational realization count as an exercise of the institution's legal competence?




The Missing Unit of Authorization


Existing debates often frame the issue as a choice between two possibilities:


Either the human decides,


or the algorithm decides.


That distinction is increasingly insufficient.


A stochastic decision architecture contains several analytically distinct stages:


Institutional authority



Generative architecture



Distribution of possible outputs



Selection mechanism



Particular output



Institutional adoption



Legal consequence


Each stage matters.


The model is not identical to the distribution.


The distribution is not identical to the sampling or decoding mechanism.


The selection mechanism is not identical to the final output.


And the final output is not automatically identical to a legally valid institutional act.


Legal theory therefore needs to identify where authorization enters this chain and how it reaches the final decision.


Otherwise, the word “delegation” hides more than it explains.




Why Human Oversight Does Not Automatically Fix It


One common response is simple:


Put a person in the loop.


But the presence of a human does not answer the structural question.


Suppose the AI produces a recommendation and an official routinely approves it.


Formally, the human signs.


But who structured the decision?


Who selected the relevant variables?


Who narrowed the available categories?


Who generated the recommendation?


Who determined which output appeared before the official?


If the human merely ratifies a machine-generated result, legal authority may remain formally human while the operative decision architecture has moved elsewhere.


A signature proves that somebody approved the output.


It does not necessarily prove that the legally relevant judgment originated with that person.


This distinction becomes increasingly important as AI systems move from simple information retrieval into ranking, classification, recommendation, eligibility analysis, compliance review, risk assessment, and administrative decision support.




The Core Claim


The law has traditionally focused on who receives delegated authority.


Stochastic systems force another question:


What range of outcomes has actually been authorized?


That changes the unit of analysis.


The problem is no longer only:


Authority → Agent


It becomes:


Authority → Decision architecture → Distribution → Particular legal act


The crucial break occurs between the distribution and the individual output.


An institution can authorize the use of a system without necessarily authorizing every legally consequential event that lies within that system's computational possibility space.


That is the Distributional Authorization Gap.


And it creates a new problem of legal attribution.




A Stochastic Delegation Test


The paper develops a framework for determining when institutional use of a probabilistic system can produce legally imputable decisions.


Four questions become central.



1. Boundedness


Is the legally permissible output space actually bounded?


A system capable of producing many technically possible answers cannot simply inherit legal validity across the entire distribution.


The institution must determine which outputs fall within delegated competence.



2. Legally Relevant Variability


Not every variation matters.


Two outputs may use different wording while reaching the same legal conclusion.


The important variable is whether stochastic variation can change rights, duties, benefits, sanctions, eligibility, liability, status, or another legally relevant consequence.



3. Reconstruction


Can the institution reconstruct the decision-producing event?


If a legally consequential output cannot be meaningfully connected to the model configuration, inputs, selection process, institutional rules, and relevant execution conditions, accountability becomes structurally weaker.



4. Institutional Imputation


What legal rule converts the computational output into an act of the institution?


This may be the most important question.


Machines generate outputs.


Institutions generate legal consequences.


The bridge between the two cannot simply be assumed.




This Is Not Only About Courts


The issue extends far beyond judicial decision-making.


Consider:


Immigration.


Tax administration.


Social benefits.


Insurance.


Banking compliance.


Public procurement.


Licensing.


Employment screening.


University admissions.


Credit decisions.


Fraud detection.


Administrative sanctions.


Risk classification.


Healthcare allocation.


Corporate compliance.


In all of these environments, probabilistic systems can influence decisions that alter real rights, opportunities, resources, and obligations.


The technical system may not formally possess legal authority.


It does not need to.


If its output becomes the operative basis for institutional action, the architecture participates in the exercise of authority.


The law therefore needs to examine not only the formal decision-maker but the complete decision-producing chain.




Why It Matters for Everyone


This is not an abstract problem limited to jurisprudence.


Citizens should care because a government decision affecting them may increasingly originate inside a probabilistic process.


Lawyers should care because traditional doctrines of competence, attribution, discretion, review, and reasons assume structures that generative systems can disrupt.


Judges should care because reviewing the legality of an outcome may require understanding the architecture that generated it.


Regulators should care because certifying a model does not necessarily validate every output the model can produce.


Developers should care because technical decisions about decoding, thresholds, sampling, system instructions, and output constraints may acquire legal consequences.


Public institutions should care because responsibility cannot disappear merely because the computational system performed as designed.


Companies should care because the same structure appears whenever AI-generated classifications or recommendations become operational decisions.


The central issue is not whether artificial intelligence is intelligent enough to exercise authority.


The issue is whether legal institutions know what they are authorizing when they place probabilistic systems inside decision-making structures.


A deterministic rule can be inspected.


A human official can be questioned.


A probabilistic architecture introduces another object:


a space of possible decisions.


Law has doctrines for delegating competence.


It now needs a theory for what happens when competence encounters probability.




The Question That Remains


The future of AI governance will not be decided only by whether models are accurate, explainable, unbiased, or safe.


Those questions matter.


But a system can be accurate in aggregate and still produce a legally problematic individual decision.


It can be explainable and still operate beyond the institution's authorized decision space.


It can have a human reviewer and still determine the frame within which that human acts.


It can comply technically with its design while generating an outcome whose legal authorization remains uncertain.


That is why the question must move one level deeper.


Not:


Can AI make decisions?


But:


What makes one stochastic output a legally authorized decision?


Until that question has an answer, the architecture may be technically operational while the authority exercised through it remains jurisprudentially incomplete.




Read the Paper


Agustin V. Startari

Delegation to a Probability Distribution: Rethinking Legal Authority in Stochastic Systems


Full paper:


https://zenodo.org/records/22233599




Call to Action


Read more of my work on artificial intelligence, language, authority, and institutional responsibility:


Website:

https://www.agustinvstartari.com/


SSRN Author Page:

https://papers.ssrn.com/sol3/cf_dev/AbsByAuth.cfm?per_id=7639915 (https://papers.ssrn.com/sol3/cf_dev/AbsByAuth.cfm?per_id=7639915)


Zenodo Publications:

https://zenodo.org/search?q=%22Agustin%20V.%20Startari%22




Author


Agustin V. Startari is a linguistic theorist, author, and researcher in historical studies. His work examines how language, artificial intelligence, and formal systems redistribute authority, agency, and responsibility in contemporary institutions. He is the author of Grammars of Power, Executable Power, and The Grammar of Objectivity.


Researcher ID: K-5792–2016


Author website:

https://www.agustinvstartari.com/


SSRN Author Page:

https://papers.ssrn.com/sol3/cf_dev/AbsByAuth.cfm?per_id=7639915 (https://papers.ssrn.com/sol3/cf_dev/AbsByAuth.cfm?per_id=7639915)




Ethos


I do not use artificial intelligence to write what I don’t know. I use it to challenge what I do. I write to reclaim the voice in an age of automated neutrality. My work is not outsourced. It is authored.


— Agustin V. Startari

 
 
 

Recent Posts

See All

Comments


bottom of page