---
schema_version: "1.2.0"
id: "divine-design-framework:en:chapter-36"
work_id: "urn:systemstheology:book:divine-design-framework:chapter:chapter-36"
book_id: "divine-design-framework"
chapter_id: "digital-systems-automation-and-public-responsibility"
chapter_slug: "chapter-36"
title: "Digital Systems, Automation, and Public Responsibility"
book_title: "DDF: Faith, Science, and the Logic of One Reality"
language: "en"
source_language: "en"
translation_status: "source"
authors: ["Elijah Faviel"]
editorial_owner: "Elijah Faviel"
editors: []
review_scope: "portfolio"
review_status: "not_reviewed"
review_summary: "Formal external review of the wider V1 corpus has not yet been completed. Rethinking Reality received pastoral and theological feedback during its earlier development. Reviewer names are published only with permission."
review_required_domains: ["biblical studies and original languages","patristics and historical theology","philosophy and rival-worldview analysis","human genetics and population history","origin-of-life science","clinical psychology and research methods","safeguarding and abuse response","Spanish language and cultural review","Indonesian language and cultural review"]
review_domains: []
review_snapshot: "c050986f727f329d2607093b3e13fe1ec9d57270+working-tree.909d026a0c08"
review_required_for_stable: true
reviewers: []
content_version: "content-c54c65675ca4"
content_hash_sha256: "c54c65675ca46943c15bfe2f1bc49fba45c2cc9dad3653d789529092a8987e5f"
published_at: "2026-10-01T10:01:21.000Z"
modified_at: "2026-10-01T10:01:21.000Z"
canonical_url: "https://systemstheology.com/library/divine-design-framework/chapter-36/"
markdown_url: "https://systemstheology.com/research/books/divine-design-framework/en/chapter-36.md"
license: "All rights reserved; research use subject to the Use Policy"
license_url: "https://systemstheology.com/use-policy/"
correction_url: "https://systemstheology.com/library/divine-design-framework/chapter-36/#chapter-comments"
kind: "chapter"
chapter_number: 36
part_title: "Life Together in One World"
---

# Digital Systems, Automation, and Public Responsibility

<a id="digital-systems-automation-and-public-responsibility"></a>

A hardship fund refuses Nadia because another recipient shares her former mailing address. The address belonged to a temporary housing service used by separate households. The match is accurate; the inferred household identity is false. Software promotes that inference into duplicate receipt, then fraud, then refusal. The appeal screen repeats it.

A deployed service is the arrangement moving evidence to action: forms, databases, models, interfaces, staff permissions, rules and payments. Each transition can change meaning. No component need contain the whole mistake for the assembled process to impose it. A worker who sees but cannot reverse the problem supplies observation without remedy.

<a id="prediction-is-not-a-finding"></a>

## Prediction is not a finding

Training labels can record past referrals rather than independently established fraud. Agreement with them reveals the office's practice before it establishes anything about an applicant. Reusing unchallenged refusals as confirmed cases makes the mistake self-reinforcing.

Even sound labels leave a base-rate problem. In a hypothetical 1,000 applications, suppose 10 involve fraud. A classifier detects nine and flags 99 of the 990 legitimate applications: 90 percent sensitivity and 90 percent specificity, but only nine of 108 flags, about 8.3 percent, identify fraud. These counts illustrate arithmetic, not fund performance. A useful investigation prompt can be weak evidence of guilt.

A score of 0.8 is not an 80 percent probability without suitable calibration in the deployment population. Calibration still cannot determine a justified action independently of its costs. Investigation, clarification and refusal impose different burdens. Assessing only flagged cases conceals misses; asking staff to validate the model while relying on its warning can reproduce the inference being tested. Independent assessment must sample appropriate unflagged cases and examine abandoned applications. [^prediction-is-not-a-finding-1]

False witness includes a true fragment placed under a false heading. Ed/martyria, witness, sheqer/pseudos, falsehood, and mishqal, measure, concern what another is asked to believe and receive. Proverbs requires hearing before answering and scrutiny of the first persuasive account. Augustine distinguishes mistaken speech from intended deception without making careless error harmless or a useful lie innocent. Responsibility therefore differs among an employee trusting an inadequate display, a manager ignoring contrary evidence and a supplier knowingly overstating it. [^prediction-is-not-a-finding-2]

[^prediction-is-not-a-finding-1]: NIST, AI RMF 1.0 (2023), §§1.2.1, 5.2--5.4, https://doi.org/10.6028/NIST.AI.100-1.
[^prediction-is-not-a-finding-2]: Exodus 20:1--17; Leviticus 19:9--18, 33--37; Proverbs 11:1 and 18:13, 17; Augustine, Enchiridion 18--22, https://www.newadvent.org/fathers/1302.htm.

<a id="security-privacy-and-warranted-disclosure"></a>

## Security, privacy and warranted disclosure

Confidentiality, integrity and availability protect against different failures: stolen lists, altered destinations and inaccessible services. NIST CSF 2.0 organizes concurrent, continuing functions: Govern assigns strategy and responsibility; Identify maps assets and dependencies; Protect supplies safeguards; Detect recognizes compromise; Respond contains and communicates; Recover restores operation. Profiles reveal gaps rather than certify safety. Strong authentication also needs recovery for legitimate users who lose their device without admitting impostors. [^security-privacy-and-warranted-disclosure-1]

Privacy can fail when nothing is hacked. Authorized linkage can construct an unnecessary intimate profile; true or false inference can expose someone. Privacy Framework 1.0 distinguishes processing risks from cybersecurity and compliance risks. Identify-P and Govern-P establish processing and responsibilities; Control-P enables granular management; Communicate-P supports understanding; Protect-P addresses cybersecurity-related privacy events. These dated texts have distinct purposes. [^security-privacy-and-warranted-disclosure-2]

A click under dependence on essential assistance has limited evidential reach. Consent to eligibility checks does not authorize unrelated advertising or perpetual profiling. Public availability likewise does not authorize every new combination. Training usefulness does not settle permission, creators' rights or fair terms.

Faithful confidence, sod, and good acts done in secret, kryptos, make public observability an inadequate criterion of trust. God's final disclosure, apokalypto, delegates no omniscience to a platform. Necessary investigative retention differs from public searchability; protecting a survivor differs from destroying evidence to protect a perpetrator. An accurate location notification can enable stalking. The strongest surveillance argument begins with real concealed danger, but must establish necessity, proportion and controls against unrelated use. [^security-privacy-and-warranted-disclosure-3]

[^security-privacy-and-warranted-disclosure-1]: NIST, CSF 2.0 (2024), https://doi.org/10.6028/NIST.CSWP.29.
[^security-privacy-and-warranted-disclosure-2]: NIST, Privacy Framework 1.0 (2020), https://doi.org/10.6028/NIST.CSWP.01162020. This use does not assume its terminology is permanently current.
[^security-privacy-and-warranted-disclosure-3]: Proverbs 11:13--14; Matthew 6:1--18; Luke 12:1--12; 1 Corinthians 4:1--7.

<a id="attention-and-correction"></a>

## Attention and correction

Recommendation ranks scarce visibility; advertising adds a purchaser's objective; moderation removes, limits, labels or delays. A quotation documenting abuse can be misclassified as its endorsement. Identity verification can establish account authority without proving a speaker's truthfulness, while compulsory public legal names can expose witnesses. Easy enrollment, obscure cancellation and default visibility change the effort and information available for choice. Intensive use does not by itself diagnose addiction.

Reach, familiarity, confidence, expression, belief and action remain different outcomes. Removing Facebook reshares in a three-month 2020 election intervention reduced political/untrustworthy exposure and news knowledge without detectable changes in measured attitudes. That bounded null result must remain alongside amplification evidence. A network is not a biological infection of passive minds. [^attention-and-correction-1]

Correction must reach the places where error acts. Pausing amplification, restoring source context, replacing the misleading account, enabling acknowledgment, updating practice and retaining corrected status are distinct operations. A correction hidden from the original audience can fail; republishing a private history to prove correction can injure again. Rules themselves need challenge where companies or governments use protection to suppress inconvenient testimony.

Synthetic expression can translate or assist, but also fabricate evidence, impersonate and simulate commitments no person has made. Warmth supplies no proof of personal care. [^attention-and-correction-2]

[^attention-and-correction-1]: Guess et al., Science 381 (2023): 404--08, https://doi.org/10.1126/science.add8424. The repetition and outrage studies establish their own outcomes rather than the missing attitude effect.
[^attention-and-correction-2]: NIST, Generative AI Profile (2024), §§2.4, 2.7--2.9, https://doi.org/10.6028/NIST.AI.600-1.

<a id="consequential-tools-and-changed-work"></a>

## Consequential tools and changed work

A robot must connect perception to safe action within time, accounting for load, stopping distance and failure. Operational autonomy has a bounded task and support system; it establishes neither consciousness nor moral agency.

Tool access similarly turns proposals into consequential instructions. Permission to summarize does not authorize disclosing records or changing bank details. Instructions embedded in retrieved material have not acquired the user's authority. Controls at action boundaries must limit what a mistaken interpretation can accomplish. Direct and indirect prompt injection differ from poisoned training data. [^consequential-tools-and-changed-work-1]

If a payment acknowledgment is lost, retrying can duplicate an award. Preserving the identity of the authorized transaction and checking its state separates requested, accepted, completed and failed acts. Safe stopping likewise depends on the task: abrupt power loss may endanger a loaded cart; account suspension may require an assisted route to essentials.

ILO's 2025 exposure index evaluates tasks through worker assessment, expert review and AI-assisted scoring, grouped in four gradients. It estimates some generative-AI exposure in about one quarter of global employment, uneven across occupations, countries and sexes, with clerical work especially exposed. Transformation is more general than wholesale occupational disappearance; remaining tasks can still form fewer or worse jobs. The study estimates technological possibility, not completed displacement. [^consequential-tools-and-changed-work-2]

Connectivity, integration costs, staffing and chosen judgment boundaries influence adoption. Saved labor becomes a better job only through appropriate pay, authority and expectations. Transition requires funded learning and workers' voice. Annotation, maintenance, exception handling and distressing moderation remain work, sometimes transferred to contractors; hardware and energy remain material dependencies. Human dignity does not depend on outperforming artifacts.

[^consequential-tools-and-changed-work-1]: NIST, Generative AI Profile, §2.9.
[^consequential-tools-and-changed-work-2]: Gmyrek et al., ILO Working Paper 140 (2025), https://doi.org/10.54394/HETP0387. A Polish task base, a 1,640-person survey and expert review inform mapping to ISCO-08; the estimates omit unknown future advances and new jobs.

<a id="authority-that-can-refuse-deployment"></a>

## Authority that can refuse deployment

Outsourcing expertise does not outsource the deployer's imposed decision. Human is a role, not a safeguard: a signature needs evidence, competence, time and freedom to disagree. Technical assurance, legal compliance, moral purpose and public legitimacy are separate questions: excellent classification can serve an unjust exclusion.

NIST AI RMF's Govern, Map, Measure and Manage functions support narrower use, simpler alternatives or nondeployment as well as continuation. Appeal, override, recovery and change management require owners and resources. Its generative profile adds selected risks concerning fabricated authority, dependence, private information and external components; proposed mitigations still need evidence. OECD's amended 2024 principles join beneficial development, rights and democratic values, transparency, robustness/safety and accountability, including social dialogue. These frameworks contribute practical knowledge, not doctrinal authority or automatic enforceable rights. [^authority-that-can-refuse-deployment-1]

UNESCO's platform guidelines join human-rights due diligence, rights-respecting design/moderation, transparency, user tools and stakeholder accountability. Supported moderators, accessible complaints, intelligible reasons and independent research make these operational. Transparency is not accomplished by an unintelligible mass of documents. [^authority-that-can-refuse-deployment-2]

The EU Digital Services Act supplies a jurisdiction-specific arrangement for covered intermediaries serving Union recipients. Article 20's specified platform complaints require qualified supervision beyond solely automated decisions, with small-enterprise exclusions and exceptions. Designated very large services face systemic-risk assessment and mitigation. Article 40 distinguishes vetted requests through the relevant coordinator from qualified access to already public interface data; affiliation, independence, funding, necessity and protected interests constrain access. The 2025 delegated regulation adds technical procedures. A legal requirement is not evidence that usable data or effective protection followed. [^authority-that-can-refuse-deployment-3]

[^authority-that-can-refuse-deployment-1]: NIST, AI RMF, §§5.1--5.4 and Manage 2, 4; Generative AI Profile, §§2.12, 3; OECD/LEGAL/0449, amended May 3, 2024, https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449.
[^authority-that-can-refuse-deployment-2]: UNESCO, Guidelines for the Governance of Digital Platforms (2023), https://unesdoc.unesco.org/ark:/48223/pf0000387339.
[^authority-that-can-refuse-deployment-3]: Regulation (EU) 2022/2065, Articles 2, 19--20, 33--35 and 40, https://eur-lex.europa.eu/eli/reg/2022/2065/oj; Delegated Regulation (EU) 2025/2050, https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202502050. The platform provision does not by itself govern the invented fund.

<a id="an-appeal-that-changes-the-service"></a>

## An appeal that changes the service

The invented fund provides an assisted telephone route, a funded urgent deadline and a reviewer able to inspect original evidence and reverse refusal. Nadia need not expose the other recipient's private circumstances. Identity and need checks support a provisional emergency payment, counted toward any later award without converting refusal into undisclosed debt.

The reviewer establishes separate households and eligibility. The fund withdraws the false link and fraud finding, pays the remaining award and confirms receipt. It retains the accurate address match and restricted history of the error with corrected status. The supplier updates operative records and later decision data; the refusal ceases to count as confirmed fraud.

Repair extends to cached summaries, retrieved copies and training labels wherever the old account continues acting. A changed authoritative record or decision rule may suffice; containment is not proof of changed learned parameters. Proportionate retention supports accountability without making a true past wrong an unlimited present verdict.

The fund reviews other refusals depending on the same link, pays owed awards and agreed redress costs, and funds staff correction. It suspends the classifier while retaining narrowly described retrieval and matching. Simpler competent decisions and review replace the defective route; added work must not create a new inaccessible backlog. Knowing neglect requires separate investigation, while owed correction need not await every culpability finding.

Evaluation must count received assistance, detected genuine fraud, urgent and ordinary timing, privacy, applicant burdens, staff work and costs. More complaints can mean worse harm or better access; fewer can mean improved service or futility. Compare competent alternatives using appropriate samples, including abandoned applications. Known harmful refusals cannot be maintained as a convenient control. Equal outcomes at less burden favor the simpler method.

<a id="images-marks-and-the-person"></a>

## Images, marks and the person

An image, tselem/eikon, can represent without creating the represented person's worth. Revelation's speaking image and charagma join demanded worship, deception, persecution and conditioned commerce. Technical resemblance identifies no fulfillment: credentials can protect access. The serious analogy concerns a power using signs and economic dependence to require allegiance it cannot rightfully command. The Lamb's truthful witnesses supply the positive counterpart. [^images-marks-and-the-person-1]

Ordinary trust in demonstrated competence is not worship. Technical lordship begins when efficiency or prediction becomes immune to judgment. Ephesians joins truthful speech, work and generosity to learning Christ and life in the personal Spirit: ganav/klepto, stealing, must cease through changed conduct, not a new label. [^images-marks-and-the-person-2]

Archives and generated likenesses can preserve memory after death. Continued output does not establish continued presence of the one who lived. Digital services properly serve persons when their representations remain corrigible and their powers reach an actual good. They cannot manufacture communion or resurrection.

[^images-marks-and-the-person-1]: Genesis 1:26--31; Colossians 1:15--20; Revelation 13--14.
[^images-marks-and-the-person-2]: Ephesians 4:17--32.
