Who signs?
Every consequential record used to carry a signature — a name that meant someone would answer for it. Automated decisions quietly removed the signature line. We should put it back.
For most of the history of consequential decisions, the last thing that happened before a decision became real was that someone wrote their name on it. The loan officer signed the approval. The doctor signed the order. The officer signed the report; the editor signed off on the page. We have come to think of that signature as a formality, a flourish at the bottom of the document — the part you skip on your way to filing it. It was never a formality. It was the load-bearing element. A name on a record was a person saying, in the only language institutions reliably understand: I stand behind this. If it is wrong, come to me.
Then decisions began to automate, and the signature line quietly disappeared. Not by anyone's decision — that is the strange part. No one stood up and announced that consequential outcomes would henceforth arrive unsigned. It simply happened, the way a path through a field becomes a road: the system produced the decision, the decision was acted upon, and there was no longer a moment in the flow where a hand reached for a pen. The output had everything a signed document used to have — a header, a reference number, a confident account of what was decided — except the one thing that made it answerable. It arrived from nowhere, addressed to you, with no return address.
The trouble with an unsigned decision is not that you cannot tell where it came from. Often you can: it came from "the system." The trouble is that the system is not a party you can summon. You cannot serve it. You cannot ask it what it was thinking, or hold it to what it said last time, or make it answer for the gap between the two. When the only author of a decision is a process, the question who is responsible for this has, for the first time in the history of consequential decisions, no defendant.
Two things a signature does
It helps to separate the two jobs a signature has always done at once, because automation severs them, and the severance is the whole problem. The first job is authentication: a signature is evidence that this record is genuine — that it is the document it claims to be, made by the party it claims to be made by, and not altered since. The second job is responsibility: a signature is an assumption of liability, a named party stepping forward and accepting that the decision is theirs to answer for. On paper these two jobs ride on the same stroke of ink, so we never had to think of them as separate. They are separate.
The good news is that the first job — authentication — survives automation cleanly, and arguably improves. A modern decision record can carry a cryptographic signature: a verifiable mark that binds the record to a signing key, so that anyone can check, without trusting the author, that the record is authentic and has not been altered since it was made. This is a real and valuable thing. It means the document in front of you is the document that was actually produced, not a later edit dressed up as the original. Provenance, in the technical sense, is solved by it.
But here is the distinction that matters, and that is easy to lose in the relief of having solved the cryptography: a cryptographic signature is necessary, and it is not sufficient. It proves the record is genuine. It does not, by itself, give you anyone to summon. A key is not a person. A signing system can attest that this is the decision the model produced with perfect fidelity and still leave you exactly where the unsigned decision left you — holding an authentic account of a consequence that no nameable party has agreed to answer for. The mark is verifiable. The author is still nobody.
A cryptographic signature proves the record is real. It does not prove that anyone real will answer for it.
The diffusion the missing signature enables
What the unsigned decision really enables is a particular evasion, and it is worth naming because it is becoming the reflexive posture of institutions that automate. The evasion is diffusion of responsibility, dressed as a statement of fact: no one decided this — the model did. It is delivered with a kind of helpless shrug, as though the speaker were merely reporting the weather. The operator points to the model. The model, having no standing to be pointed at, points nowhere. The vendor points to the deployment. The deployer points to the vendor's training. And the affected party turns slowly in the middle of a circle of people, each of whom has arranged to be standing slightly to the side of the place where the decision actually landed.
This is not an accident of the technology. It is the technology used as an alibi. Automation did not abolish the decider; it made the decider easy to leave unnamed, and leaving the decider unnamed is convenient in direct proportion to how badly the decision might go. The very decisions that most need a signature — the high-stakes, contestable, capable-of-ruining-someone's-week decisions — are exactly the ones an institution is most tempted to let arrive unsigned. Where the stakes are low, no one minds owning the call. Where the stakes are high, "the system decided" is a door marked exit.
The repair is not complicated, even if it is uncomfortable. A complete decision record should name a signer — and it should name two distinct things, corresponding to the two jobs the old signature used to do at once. It should name the attesting system: the component that produced and signed the record, so the artifact is verifiable as authentic. And it should name the accountable party: the human being or the organization that has agreed, in advance, that this class of decision is theirs to answer for. The first makes the record real. The second makes it answerable. A record with only the first is a beautifully sealed envelope with no one's name on the outside.
Why a name is what standing needs
The reason this is not merely tidy bookkeeping is that contestability requires a counterparty. A right to challenge a decision is empty if there is no one on the other side of the challenge — standing is not just the contestant's right to object, it is the existence of a party who is obliged to respond. You cannot argue with a process. You can only argue with someone who has accepted that the process's outputs are theirs. The named accountable party is what gives a contestant something to contest, a door to knock on, a defendant to address. Without it, "you may appeal this decision" is a sentence that loops back on itself, because the appeal has nowhere to be filed and no one bound to receive it.
So the question is not really technical, though the cryptography is the easy and necessary part. The question is older than any of our machines, and it is the one a child asks and an institution learns to avoid: who said so? For most of human history, the answer was a name, written by a hand that had agreed to be reachable. We did not lose that answer because we decided it no longer mattered. We lost it because the new way of deciding had no slot for a pen, and no one thought to add one back. We can add one back. Every consequential decision a system makes can carry, alongside its verifiable mark of authenticity, the name of a party who has agreed to answer for it. The technology to do this exists. What is missing is the insistence — and the willingness, when the decision goes wrong, to stop pointing at the model and pick up the pen.
— Dispatches · Summit Cognitive
Continue from here
Turn the argument into a practice.
Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.