Civic / Privacy / Digital Rights

The Algorithmic State of Exception: Emergency Powers, Machine-Speed Intervention, and the Risk of Permanent Surveillance Infrastructure

Report summary

The convergence of automated computational systems and extraordinary executive authority has engendered a profound constitutional and administrative crisis: the emergence of the algorithmic state of exception. Historically, emergency jurisprudence—encompassing public health crises, natural disasters

Status
Research archive item
Category
Civic / Privacy / Digital Rights
Length
7,765 words
Reading time
36 minutes
Report type
guidance

Key topics

  • Civic / Privacy / Digital Rights
  • Civic
  • Privacy
  • Digital Rights
  • AI
  • .NET
  • Semantic Systems
  • Research Archive
  • Audit

Research provenance

Archive status
Research archive item
Content identity
sha256:db4ff485271b767040fd48c5477a2a3073db257b72bef340875c0fd534b83e5c

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

1. Executive Summary

The convergence of automated computational systems and extraordinary executive authority has engendered a profound constitutional and administrative crisis: the emergence of the algorithmic state of exception. Historically, emergency jurisprudence—encompassing public health crises, natural disasters, mass violence, financial instability, cyberattacks, and environmental contamination—has relied on strict temporal boundaries, rigorous evidentiary standards, and intense judicial oversight to ensure that the suspension of ordinary legal norms does not permanently alter the democratic baseline1. However, as governments increasingly delegate crisis detection and mitigation to algorithmic systems, the foundational assumptions of emergency law are being systematically dismantled3. Machine-speed interventions, capable of identifying threats and deploying coercive state power in milliseconds, bypass the human friction necessary for procedural due process and legislative accountability5. This comprehensive analysis investigates the mechanics of how narrowly justified safety powers, authorized during acute crises, evolve into permanent systems of machine judgment. By synthesizing verified current law, historical emergency precedent, and documented institutional practice, the research identifies critical vulnerabilities in contemporary crisis management. It explores the constitutional boundaries of derogable rights under the International Covenant on Civil and Political Rights (ICCPR) and the Siracusa Principles, contrasting these human rights baselines with the operational realities of systems like the Michigan Integrated Data Automated System (MiDAS) and federal administrative watchlists7. Furthermore, the analysis evaluates the efficacy of technical standards, such as the NIST SP 800-88 Revision 2 media sanitization guidelines, and regulatory frameworks like the European Union Artificial Intelligence Act, in constraining exception creep9. To bridge the gap between rapid technological intervention and enduring constitutional accountability, this report introduces nine required analytical models, including the Emergency-to-Normalization Ladder, the Sunset and Data-Purge Protocol, and the Machine-Speed Automatic Stay. Through the examination of ten specialized scenarios, the research demonstrates that while machine-speed intervention is often a normative necessity to avert catastrophic harm, speed does not eliminate the requirement for accountability. The deployment of automated emergency systems must be unconditionally paired with cryptographic data sealing, mandatory model retirement, and robust, non-derogable human standing boundaries to prevent the state of exception from calcifying into the normal operating system of modern governance.

2. Definition of an Algorithmic State of Exception

The theoretical foundation of the state of exception finds its most potent articulation in the Weimar-era jurisprudence of Carl Schmitt, who established that sovereignty is ultimately defined by the power to decide on the exception—the moment when the survival of the state necessitates the suspension of the juridical order11. Giorgio Agamben subsequently expanded this framework, observing that modern political power increasingly utilizes the exception not as a temporary departure from the rule of law, but as a permanent, systemic paradigm of governance where the boundaries between crisis and normality irrevocably blur13. An algorithmic state of exception represents the technological actualization and acceleration of Agamben’s permanent exception. It occurs when the sovereign decision to suspend ordinary constitutional norms, assess evidence, and execute coercive action is delegated to automated computational logic. This paradigm shift fundamentally alters the nature of governmental power in three distinct ways. First, the locus of the sovereign decision is transferred from an accountable human executive to an opaque statistical model. In the classical model, a human actor observes a threat, deliberates, and formally declares an emergency4. In the algorithmic model, sensors ingest continuous streams of biometric, financial, or environmental data, and the machine algorithmically declares the exception at the level of the individual or population, triggering automated interventions without synchronous human oversight3. Second, the algorithmic exception distorts temporality. Traditional emergencies are legally defined by their impermanence. An algorithmic emergency, however, encodes the crisis into persistent data weights, predictive models, and permanent digital registries3. The infrastructure constructed to manage an acute event—such as a pandemic or a riot—establishes a pervasive surveillance architecture that resists dismantling, creating an "Artificial State of Exception" wherein reality is continuously reconstructed by the machine to justify its own persistent operation4. Third, the algorithmic state of exception eviscerates the traditional mechanisms of legal contestation. Because the intervention occurs at machine speed, the classical constitutional protections of notice and pre-deprivation hearings are rendered obsolete5. The affected individual is left to navigate an asymmetric digital bureaucracy where the burden of proof is inverted, forcing the citizen to prove their innocence against an algorithm whose proprietary logic the state itself often cannot explain15.

3. Emergency-Law Baseline

Distinguishing Emergency from Ordinary Risk

The foundational inquiry in emergency jurisprudence is defining what legally distinguishes a genuine emergency from ordinary, manageable risk. Under verified current international law, specifically Article 4(1) of the ICCPR, a public emergency must reach a threshold that "threatens the life of the nation"1. The Siracusa Principles, adopted by the United Nations Economic and Social Council in 1984, further clarify this baseline: ordinary risks are addressed through standard administrative rulemaking and statutory enforcement, whereas an emergency constitutes an exceptional, imminent, and existential crisis affecting the whole population or territory, justifying the temporary bypass of normal procedures1. Ordinary risk management is proactive and highly regulated; emergency intervention is reactive and relies on the doctrine of necessity to mitigate immediate, catastrophic harm.

Declaration, Authority, and Duration

The authority to declare an emergency and invoke extraordinary powers is typically vested in the executive branch, though heavily constrained by constitutional checks. In United States historical emergency precedent, Youngstown Sheet & Tube Co. v. Sawyer established a definitive boundary on executive power, demonstrating that the President cannot unilaterally seize private property (in that instance, steel mills) to avert a crisis without explicit or implied congressional authorization2. At the state level, documented institutional practice reveals strict temporal and procedural limitations. For example, under the Illinois Emergency Management Agency Act (20 ILCS 3305), the Governor is granted the authority to proclaim a disaster and assume extraordinary powers, including the suspension of regulatory statutes, the control of ingress and egress, and the commandeering of private property17. However, these powers are strictly limited in duration. Verified current law mandates that the Governor may only exercise these powers "for a period not to exceed 30 days"17. While executives often attempt to chain these 30-day declarations to manage ongoing crises (as seen during the COVID-19 pandemic), legislative bodies actively contest this practice. Proposed amendments in Illinois (e.g., SB 103 and HB 1463\) sought to render any extension void without explicit General Assembly approval within five days, illustrating the ongoing constitutional friction regarding the duration of emergency authority18.

Evidentiary Justifications for Activation

The evidence required to justify the activation of emergency powers must be empirical, substantial, and proportionate. In the context of public health, the legal baseline was established in Jacobson v. Massachusetts (1905), which upheld mandatory vaccination laws but required that emergency health interventions possess a "real or substantial relation" to the protection of public health and not be an arbitrary, unreasonable infringement on fundamental rights20. Modern human rights frameworks echo this, demanding that emergency measures be strictly required by the exigencies of the situation, utilizing the least restrictive means available7.

Derogable vs. Non-Derogable Rights

During a verified emergency, states possess the legal authority to derogate from—temporarily suspend—certain rights. Derogable rights typically include freedom of movement, assembly, expression, and standard privacy protections, which may be restricted to enforce quarantines, curfews, or emergency surveillance1. Conversely, non-derogable rights represent the absolute boundary of state power; they cannot be suspended under any circumstances, regardless of the severity of the crisis. Under ICCPR Article 4, non-derogable rights include the right to life, freedom from torture, freedom from slavery, the principle of legality in criminal law (protection against retroactive punishment), and the right to recognition as a person before the law1. Furthermore, regional legal instruments, such as the American Convention on Human Rights (Article 27), explicitly designate the right of habeas corpus as non-derogable1. The requirement that coercive acts of the state be grounded in legally established procedures remains a persistent baseline; deportations or detentions conducted entirely outside a public, legal framework cannot satisfy the requirement of lawfulness, even in a crisis23.

4. Machine-Speed Intervention

The Alteration of Traditional Oversight

The integration of automated decision-making into emergency governance profoundly disrupts the established constitutional mechanisms of oversight. Traditional administrative law relies on human friction: a human agent assesses facts, applies rules, and executes a decision, a process that inherently provides time for notice and an opportunity for the affected individual to be heard3. When intervention occurs at machine speed, this friction is eliminated. The constitutional standard for procedural due process in the United States is governed by the balancing test established in Mathews v. Eldridge3. The Mathews test requires courts to weigh three factors: the private interest affected by the official action, the risk of an erroneous deprivation under current procedures alongside the probable value of additional safeguards, and the government's interest, including the administrative and fiscal burdens of additional process5. In a machine-speed emergency, the government's interest in instantaneous action to avert disaster is mathematically maximized. However, the risk of erroneous deprivation also scales exponentially, as algorithmic systems rapidly propagate false positives without human contextual correction3. Automation devalues the traditional due process hearing by denying meaningful pre-deprivation notice and creating an environment where human review officers exhibit extreme automation bias—a psychological deference where the machine's output is presumed infallible3.

Preserving a Meaningful Opportunity to Challenge

To preserve constitutional legitimacy, automated systems must be engineered to provide alternative mechanisms for challenge. Recognizing this necessity, the European Union's Artificial Intelligence Act (EU AI Act) classifies AI systems used in emergency first response (e.g., emergency call triage, dispatching police or firefighters) as high-risk25. Crucially, Article 14 of the EU AI Act mandates "human oversight," requiring that these systems be designed in a way that allows human operators to fully understand the system's capacities, intervene in its operation, and override or reverse its outputs to protect fundamental rights9.

Required Analytical Model 1: Emergency Activation Threshold

As a normative proposal for systems-safety engineering, an automated emergency system cannot be permitted to unilaterally activate coercive measures without satisfying a cryptographically secured Emergency Activation Threshold. This model functions as an automated constitutional logic gate requiring three simultaneous, verified inputs:

1. Magnitude Input: Real-time sensor data mathematically proving that the anomaly exceeds standard deviations of ordinary risk by a statutorily defined factor (e.g., cyber-intrusions into critical infrastructure exceeding 10,000 requests per second).

2. Imminence Input: A computed velocity metric demonstrating that human deliberation would guarantee irreversible catastrophic failure before mitigation could occur.

3. Authorization Token: An active, legally verified cryptographic key issued by the executive branch and countersigned by an independent judicial or legislative authority.

If any of these three inputs fail, the system must default to a passive advisory state, incapable of independent coercive action.

Required Analytical Model 4: Machine-Speed Automatic Stay

Because machine-speed interventions routinely bypass pre-deprivation hearings, the legal system must provide a synchronous counter-measure: the Machine-Speed Automatic Stay. Under this model, if an algorithmic emergency system issues a coercive command against a citizen (e.g., freezing a bank account during a financial panic, or revoking a transit pass during a pandemic), the affected individual can immediately trigger an automatic stay via a standardized digital challenge protocol. Upon activation, the algorithm's coercive action is instantly suspended or placed in escrow for a maximum of 24 hours, forcing the system to route the case to a human adjudicator. The government may override the stay only if the algorithm can generate a mathematical proof demonstrating that suspending the intervention poses an immediate, quantifiable risk of physical casualty or systemic collapse. This mechanism satisfies the Mathews v. Eldridge requirement for balancing government interests while restoring the individual's power to interrupt automated harm24.

5. Exception Creep and Infrastructure Permanence

The Repurposing of Surveillance Infrastructure

The most significant long-term threat posed by the algorithmic state of exception is "exception creep." During an acute crisis, the public generally accepts the deployment of invasive surveillance technologies—such as Bluetooth proximity tracing, drone monitoring, or facial recognition—under the premise that they are temporary necessities12. However, once the emergency recedes, the physical hardware, software architectures, and massive datasets remain. Bureaucratic inertia, combined with the sunk costs of public procurement, strongly incentivize state agencies to retain these tools3. Consequently, technologies acquired for emergency management are repurposed for routine governance. Systems designed to track infectious disease outbreaks are integrated into local law enforcement databases; aerial drones purchased for wildfire evacuations are utilized to monitor civilian protests; and emergency benefits algorithms are turned inward to profile citizens for routine tax or welfare fraud23. This process transforms the exception into the permanent baseline, silently eroding civil liberties without legislative debate.

Documented Institutional Practice: The MiDAS Failure

The devastating potential of automated administrative systems is starkly illustrated by the documented institutional practice in Michigan. In an attempt to modernize and detect fraud, the Michigan Unemployment Insurance Agency deployed the Michigan Integrated Data Automated System (MiDAS), a $46 million algorithmic system6. The state subsequently laid off a significant portion of its human fraud-detection workforce, delegating the decision-making process almost entirely to the algorithm6. MiDAS operated with catastrophic inaccuracy. The algorithm automatically flagged over 40,000 claimants for unemployment fraud based on deeply flawed logic. Operating without meaningful human oversight, MiDAS issued electronic notices to digital portals rather than utilizing physical mail, ensuring that most victims remained unaware of the accusations until the 30-day appeal window had closed6. Once the algorithmic determination became final, the system automatically initiated administrative garnishments, seizing federal tax refunds and docking wages at machine speed6. In the ensuing litigation, Bauserman v. Unemployment Insurance Agency, the Michigan Supreme Court determined that the state's actions constituted an unconstitutional deprivation of property without due process of law, holding that the actionable harm occurred the moment the automated system seized the plaintiffs' property8. The MiDAS disaster serves as a definitive case study in exception creep: an algorithmic system designed for systemic efficiency operated as an unaccountable sovereign, stripping citizens of their constitutional rights at scale.

Required Analytical Model 2: Emergency-to-Normalization Ladder

The transition from crisis to permanent surveillance follows a predictable systemic pathology, modeled here as the Emergency-to-Normalization Ladder:

1. The Catalyst Event: A legitimate, severe crisis triggers public demand for immediate action11.

2. The Procurement Bypass: Executive agencies bypass normal competitive bidding, privacy impact assessments, and legislative debate to rapidly acquire automated solutions under emergency statutory exceptions17.

3. The Deployment Phase: The system operates with high public compliance; civil liberties objections are marginalized by the urgency of the threat.

4. Mission Creep: As the primary threat wanes, the system's operational parameters are quietly expanded to identify secondary, non-emergency risks in order to justify its continued funding.

5. Bureaucratic Integration: The emergency system's data outputs are integrated into routine interagency pipelines via API, silently fusing emergency intelligence with standard law enforcement and administrative databases.

6. Normalization: The formal legislative emergency expires, but the algorithmic system remains active under generalized statutory authority, establishing a permanent, pervasive surveillance architecture13.

Required Analytical Model 3: Temporary Power Lifecycle

To disrupt the normalization ladder, jurisdictions must mandate a systems-engineering framework called the Temporary Power Lifecycle for all emergency technologies:

  • Phase 1: Dormancy: The infrastructure is constructed but cryptographically locked at the hardware level.
  • Phase 2: Dual-Key Unlocking: The system is activated solely via a dual-key cryptographic mechanism requiring synchronous executive authorization and legislative/judicial countersignature, valid only for a strict temporal window (e.g., 30 days)18.
  • Phase 3: Active Intervention: The system operates under strict constraints, providing the Machine-Speed Automatic Stay protocol to affected citizens.
  • Phase 4: Mandatory Tapering: As the authorization window nears expiration, the software autonomously throttles data ingestion and halts automated coercive outputs.
  • Phase 5: Algorithmic Guillotine: Upon precise expiration, the system logically and physically disables its own API ports and severs network connections. Reactivation requires a completely new legal and cryptographic initialization.

Required Analytical Model 7: No-Secondary-Use Rule

To prevent data fusion, the No-Secondary-Use Rule acts as an absolute legal and technical barrier. It mandates that any data collected, or models generated, under emergency derogations must reside in physically air-gapped or strictly logically siloed environments. The data cannot be queried, cross-referenced, or transferred to law enforcement, immigration, tax, or ordinary public-benefits agencies. Any programmatic attempt to bypass these silos automatically triggers a system halt and generates an immutable violation log directed to an independent Inspector General.

6. Data, Model, and Identity Persistence

Deletion, Sealing, and De-linking After the Event

When an emergency concludes, the persistence of the data collected during the event poses a severe threat to privacy. Standard data deletion practices—such as deleting file pointers or reformatting drives—are insufficient, as forensic techniques can easily recover the data. Verified current technical capability regarding data destruction is governed by the National Institute of Standards and Technology (NIST) Special Publication 800-88 Revision 2, Guidelines for Media Sanitization31. NIST SP 800-88 defines three levels of sanitization: Clear, Purge, and Destroy33. While "Clear" relies on logical overwriting suitable for low-risk data, emergency surveillance data requires a "Purge" standard10. The most effective method for achieving a machine-speed purge across distributed cloud infrastructure is Cryptographic Erasure (CE)31. If all emergency data is encrypted at rest using strong algorithms (e.g., AES-256), the state can instantly and irreversibly sanitize petabytes of data simply by destroying the cryptographic keys. Once the keys are destroyed, accessing the target data becomes computationally infeasible, effectively achieving total data destruction without requiring the physical shredding (the "Destroy" standard) of the storage media31.

Required Analytical Model 5: Sunset and Data-Purge Protocol

The Sunset and Data-Purge Protocol operationalizes NIST standards into emergency legislation. It requires that all emergency systems be designed with a "Time-to-Live" (TTL) architecture tied to the statutory duration of the emergency (e.g., 30 days under ILCS 3305\)17.

1. All database entries are tagged with a cryptographic expiration timestamp.

2. If the legislature does not formally renew the emergency declaration, a system chron-job automatically executes a NIST 800-88 Cryptographic Purge, permanently destroying the encryption keys31.

3. The system generates a public cryptographic hash verifying the destruction of the key, allowing independent auditors and civil society to mathematically verify compliance without accessing the underlying, now-inaccessible data.

The Treatment of Models Trained on Emergency Data

A massive vulnerability in current privacy law concerns the persistence of machine learning models. Even if the raw emergency data is purged, artificial intelligence models trained on that data retain complex statistical weights, patterns, and biases. In many cases, advanced attacks can extract personally identifiable information directly from the model weights.

Required Analytical Model 6: Emergency Model Retirement Standard

Under the Emergency Model Retirement Standard, any algorithm, neural network, or predictive model trained substantially on data acquired via emergency surveillance powers must be classified as legally contaminated. The state cannot retain the model for secondary tasks (e.g., using a riot-control crowd prediction model to optimize normal city traffic) because the foundational intelligence was extracted without consent under coercive conditions. Upon the expiration of the emergency, the model weights themselves must be subjected to Cryptographic Erasure, forcing agencies to rely on ordinary, constitutionally compliant datasets for routine governance.

False Positives and the Persistence of Harm

When emergency data or models are not purged, the resulting false positives circulate indefinitely, creating invisible, Kafkaesque barriers for citizens. In the case of Ibrahim v. Department of Homeland Security, a Stanford doctoral student was erroneously placed on the federal No-Fly List due to a minor administrative error by an FBI agent35. The error cascaded through interconnected databases, resulting in her detention, the revocation of her visa, and a nearly decade-long legal battle to clear her name37. The Ibrahim case, alongside the Bauserman MiDAS disaster, proves that when emergency systems and watchlists are permitted to operate indefinitely without rigorous correction mechanisms, false positives are not merely temporary inconveniences; they become permanent identity stains that deprive individuals of employment, travel, and liberty long after the initial threat has subsided8.

7. Ten Scenarios of Algorithmic Exception

To rigorously evaluate the application of the analytical models, the following ten fictional scenarios examine how machine-speed interventions operate across diverse emergency scopes, detailing the specific parameters required to prevent infrastructure permanence.

Scenario 1: Infectious-Disease Exposure Notification

AttributeSpecification
Emergency TriggerOutbreak of a novel, highly lethal airborne respiratory pathogen.
Evidence AvailableBluetooth proximity graphs (DP-3T), mass-transit biometric temperature scans, regional wastewater genomic sequencing.
Intervention AuthorizedAutomated issuance of mandatory 14-day digital quarantine orders; algorithmic deactivation of public transit access cards for exposed cohorts.
Duration60 days, strictly tied to the legislative public health emergency declaration.
Affected RightsFreedom of movement, freedom of assembly, privacy rights.
Contest RouteMachine-Speed Automatic Stay triggered via mobile application, requiring a human epidemiologist to review the exposure evidence within 12 hours.
Deletion or Sealing ObligationNIST 800-88 Cryptographic Purge of all centralized proximity graphs and transit logs immediately upon emergency expiration31.
Oversight BodyJoint Congressional Public Health and Privacy Commission.
System Fully Retired?Yes. All encryption keys destroyed; infrastructure returns to dormancy.
Risk of RecurrenceLow, provided cryptographic erasure is publicly verified via hash publication.

Scenario 2: Wildfire Evacuation

AttributeSpecification
Emergency TriggerCatastrophic, fast-moving wildfire threatening the perimeter of a major metropolitan area.
Evidence AvailableSatellite thermal imaging (FIRMS), autonomous vehicle telemetry, drone visual feeds, automated traffic density maps.
Intervention AuthorizedAlgorithmic commandeering of connected civilian vehicles to enforce one-way evacuation routing; automated digital geofencing to prevent civilian reentry.
Duration7 days (active conflagration phase).
Affected RightsProperty rights (vehicle control), freedom of movement.
Contest RoutePost-deprivation administrative claims for property seizure, routed through an Emergency Management Claims Commission (analogous to 20 ILCS 3305/7)17.
Deletion or Sealing ObligationCryptographic sealing of all private vehicle trajectory and location data.
Oversight BodyState Emergency Management Agency and local judiciary.
System Fully Retired?Yes. Geofences are dissolved.
Risk of RecurrenceModerate. Traffic optimization models may be retained by state transit authorities, violating the Emergency Model Retirement Standard.

Scenario 3: Financial Panic Controls

AttributeSpecification
Emergency TriggerCoordinated algorithmic bank run driven by deep-fake disinformation, threatening catastrophic domestic liquidity collapse.
Evidence AvailableHigh-frequency transaction logs, social media sentiment analysis, interbank liquidity metrics.
Intervention AuthorizedMachine-speed freeze of retail banking withdrawals exceeding $1,000 per day; automated suspension of designated digital asset block transfers.
Duration72 hours (executive-ordered banking holiday).
Affected RightsProperty rights, economic liberty.
Contest RouteDuration is hard-capped to prevent prolonged deprivation; emergency hardship overrides routed to asynchronous human bank managers.
Deletion or Sealing ObligationPurge of all predictive behavioral profiles generated during the sentiment analysis phase.
Oversight BodyFederal Reserve and Consumer Financial Protection Bureau (CFPB).
System Fully Retired?No.
Risk of RecurrenceHigh. Financial institutions quietly integrate the algorithmic "panic detection" logic into routine commercial risk and credit assessments, constituting unauthorized exception creep.

Scenario 4: Critical-Infrastructure Cyberattack

AttributeSpecification
Emergency TriggerState-sponsored malware attack disabling regional water treatment facilities and electrical grids.
Evidence AvailableDeep packet inspection logs, network traffic anomalies, SCADA system automated alerts.
Intervention AuthorizedMachine-speed severing of external internet connections for affected sectors; algorithmic throttling of civilian power grids to route energy to hospital life-support systems.
Duration14 days.
Affected RightsAccess to information, commercial property rights, liberty (due to infrastructure collapse).
Contest RouteUtility operators hold physical override keys, mandated by EU AI Act Article 14 human oversight principles for critical infrastructure9.
Deletion or Sealing ObligationOverwriting (NIST Clear) of civilian IP traffic logs captured collaterally during the defense operations31.
Oversight BodyCybersecurity and Infrastructure Security Agency (CISA).
System Fully Retired?Yes. Network bridges are re-established.
Risk of RecurrenceLow. Standard operational baseline resumes immediately upon malware neutralization.

Scenario 5: School Threat Alert

AttributeSpecification
Emergency TriggerAggregated natural language processing (NLP) of student social media paired with geolocation indicating an imminent mass shooting.
Evidence AvailableSemantic analysis of text communications, geofenced mobile device tracking, automated public records scans.
Intervention AuthorizedAutomated lockdown of school facilities; algorithmic dispatch of local SWAT units; predictive detention alerts for flagged individuals.
Duration24 hours.
Affected RightsLiberty, privacy, presumption of innocence, freedom of expression.
Contest RouteSubject to the Non-Derogable Human Standing boundary: no physical apprehension can occur unless a human magistrate reviews the algorithmic output and signs a warrant.
Deletion ObligationImmediate destruction of psychological profiles generated on innocent students.
Oversight BodyLocal judiciary and civilian school board.
System Fully Retired?No.
Risk of RecurrenceVery High. The school district decides to leave the surveillance architecture running permanently "just in case," normalizing total digital surveillance of the student body.

Scenario 6: Terrorist-Attack Response

AttributeSpecification
Emergency TriggerDetonation of an explosive device in a central urban transit hub.
Evidence AvailableCCTV facial recognition matching, mass cell-tower data dumps, acoustic gunshot detection sensors.
Intervention AuthorizedAlgorithmic halting of all regional public transit; real-time predictive tracking for suspect apprehension; automated watchlist cross-referencing.
Duration30 days (requires explicit legislative re-authorization to extend).
Affected RightsFourth Amendment protections against unreasonable search, freedom of movement, privacy.
Contest RouteHabeas corpus remains strictly non-derogable1. Any algorithmically identified suspect detained must be presented to a judge within 48 hours.
Deletion or Sealing ObligationNo-Secondary-Use Rule: Facial recognition databases compiled during the manhunt must be siloed and eventually purged, preventing integration with routine traffic enforcement databases.
Oversight BodyForeign Intelligence Surveillance Court (FISC) and Inspector General.
System Fully Retired?No.
Risk of RecurrenceHigh. Historical precedent demonstrates that post-attack surveillance architectures invariably expand their scope to target domestic non-terrorist criminal activity.

Scenario 7: Urban Unrest Monitoring

AttributeSpecification
Emergency TriggerWidespread riots and civil disorder following a systemic political crisis, threatening supply chains and urban safety.
Evidence AvailablePersistent drone surveillance, social media network mapping, automated license plate readers (ALPR).
Intervention AuthorizedAlgorithmic enforcement of curfews (automated issuing of fines via ALPR and geolocation); localized throttling of mobile network bandwidth in designated protest zones.
Duration10 days.
Affected RightsFreedom of speech, freedom of assembly, movement.
Contest RouteIssuance of an After-Action Accountability Receipt to anyone fined or detained, providing the exact algorithmic logs used to target them, facilitating post-emergency judicial review.
Deletion or Sealing ObligationPurge of all cellular location data for individuals not charged with violent felonies.
Oversight BodyDepartment of Justice Civil Rights Division.
System Fully Retired?Yes. Curfew lifted and drones grounded.
Risk of RecurrenceModerate. Local municipalities frequently resist purging ALPR data, citing general public safety retention policies.

Scenario 8: Environmental Contamination

AttributeSpecification
Emergency TriggerMassive derailment resulting in a toxic chemical spill, creating a lethal atmospheric plume over a populated region.
Evidence AvailableReal-time atmospheric chemical sensors, weather pattern prediction models, smart-home HVAC sensor telemetry.
Intervention AuthorizedMachine-speed shutdown of civilian HVAC systems in the plume path to prevent toxic intake; automated deployment of containment protocols.
Duration48 hours.
Affected RightsPrivacy (intrusions into home networks), property control.
Contest RouteImmediate human override capabilities built into smart-home applications, though strongly advised against by emergency prompts.
Deletion or Sealing ObligationRoutine overwriting (NIST Clear) of civilian home telemetry data upon plume dissipation31.
Oversight BodyEnvironmental Protection Agency (EPA).
System Fully Retired?Yes.
Risk of RecurrenceLow. The intervention is highly localized and data is low-sensitivity.
AttributeSpecification
Emergency TriggerCoordinated abduction of several children by a transnational human trafficking syndicate.
Evidence AvailableReal-time global facial recognition API scraping across all public, private, and commercial connected camera feeds.
Intervention AuthorizedUnrestricted activation of a biometric dragnet, instantly identifying and tracking all individuals matching the suspects or victims.
Duration72 hours (Digital AMBER Alert equivalent).
Affected RightsUniversal privacy, anonymity in public spaces, freedom from general warrants.
Contest RouteThe system operates continuously, but state actors are legally barred from acting upon or executing warrants for unrelated crimes (e.g., drug possession) incidentally detected during the biometric sweep.
Deletion or Sealing ObligationEmergency Model Retirement Standard: The ad-hoc facial recognition model and all collateral civilian biometric maps are cryptographically destroyed post-recovery.
Oversight BodyIndependent Biometrics Commissioner.
System Fully Retired?Yes.
Risk of RecurrenceModerate. Commercial technology vendors may attempt to secretly retain the model weights to improve their proprietary algorithms.

Scenario 10: Unresolved Case (The Expired System)

AttributeSpecification
Emergency TriggerA 2024 regional border security and migration crisis, declared a national emergency.
Evidence AvailableAutomated social media scraping, financial remittance patterns, predictive criminality scoring algorithms.
Intervention AuthorizedAssignment of a permanent "risk score" to targeted demographics, used to automate and accelerate deportation and resource denial proceedings.
DurationThe statutory emergency declaration formally expired in 2025\.
Affected RightsEqual protection, due process, freedom from discrimination.
Contest RouteNone effectively available. Individuals are denied employment, travel, or banking services based on opaque, algorithmic determinations without a defined appeals process.
Deletion or Sealing ObligationIgnored. The Sunset and Data-Purge Protocol was never executed. Data was seamlessly integrated into standard interagency law enforcement environments.
Oversight BodyNone (The system has become an "Orphaned System" with no direct accountability).
System Fully Retired?No.
Risk of RecurrenceAbsolute. The algorithmic false positive continues to circulate invisibly. It acts as an unaccountable digital barrier, permanently altering the lives of ordinary citizens, perfectly replicating the enduring constitutional harms documented in both the federal Ibrahim No-Fly List litigation36 and the Michigan MiDAS disaster8.

8. Sunset, Retirement, and Correction Architecture

To prevent scenarios like the unresolved tenth case, the architecture of an algorithmic state of exception must be inherently brittle—engineered to break down safely and irreversibly when legal authorization concludes. Oversight must not rely solely on bureaucratic goodwill; it must be technologically enforced.

Review Mechanisms

Review must be multifaceted and interdisciplinary:

  • Legislatures must mandate hard cryptographic sunsets within the authorizing emergency statute itself. Any procurement of automated emergency technology must include a legally binding Time-to-Live (TTL) parameter.
  • Courts must exercise de novo review over any deprivations resulting from algorithmic systems, refusing the psychological tendency to defer to the "infallibility" of machine logic3. The burden of proof must remain with the state to validate the algorithm's output.
  • Inspectors General require unconditional, direct API access to audit the system's decision-trees, operational logic, and strict compliance with the No-Secondary-Use rule.
  • Civil Society and Affected Persons must be granted clear legal standing to challenge the system's continued existence and demand cryptographic verification of data purges post-emergency.

Effective Response Without a Permanent Registry

A central question is whether an emergency response can remain effective without creating a permanent, person-level risk registry. Based on current technical capabilities in decentralized architecture, the answer is definitively yes. For instance, localized threats can be managed using privacy-preserving technologies like edge computing and decentralized cryptographic identifiers (similar to the DP-3T protocols used during early pandemic contact tracing). If algorithmic risk assessment occurs "on the edge" (locally on a user's device or utility node) rather than in a centralized state database, the system can issue rapid alerts or interventions without transmitting personally identifiable information to the sovereign. By aggregating only anonymized telemetry, the state can monitor the macro-level trajectory of a crisis and direct resources effectively, without ever constructing the permanent, centralized surveillance registries that facilitate exception creep.

9. Oversight and After-Action Review

The adaptation of due process to the algorithmic age requires recognizing that traditional pre-deprivation hearings are often physically impossible when responding to machine-speed crises. However, the elimination of the pre-deprivation hearing mandates a corresponding strengthening of post-deprivation accountability5.

Required Analytical Model 8: After-Action Accountability Receipt

Because the "black box" nature of AI obscures the rationale behind state action, individuals subjected to automated deprivations are severely disadvantaged in mounting a defense15. The After-Action Accountability Receipt corrects this asymmetry. It is an unalterable digital ledger entry provided to every individual affected by an automated emergency action. It must detail:

1. The precise statutory authority and executive order justifying the action.

2. The specific data points and sensor inputs ingested by the algorithm to target the individual.

3. The algorithmic weights, threshold scores, or decision-tree logic that produced the adverse outcome.

4. A direct, low-friction hyperlink to an expedited administrative appeals portal. This mechanism forces transparency, satisfying the constitutional requirement for notice and allowing the citizen to challenge the specific data inputs that led to their deprivation24.

Required Analytical Model 9: Non-Derogable Human Standing Boundary

Ultimately, technical solutions cannot entirely replace legal absolutes. The Non-Derogable Human Standing boundary establishes the absolute limits of algorithmic governance. It dictates that certain fundamental legal states are so vital to human dignity and constitutional order that they can never be altered exclusively by a machine, regardless of the severity or imminence of the emergency. Under this rule, an algorithmic system may alert, recommend, or temporarily stay, but it may never unilaterally execute:

1. The deployment of lethal force.

2. The physical, indefinite detention of a human being, or the suspension of habeas corpus1.

3. The stripping of citizenship, legal personhood, or fundamental identification.

4. The termination of subsistence-level social benefits without a synchronous human hearing24. If a system attempts to execute any of these actions without a cryptographically verified human signature, the system must trigger an automatic hard fault.

10. Counterarguments and Limiting Cases

The Argument for Rapid Intervention

It is a dangerous analytical fallacy to assume that temporary emergency powers, or the automated systems used to execute them, are automatically illegitimate or inherently tyrannical. In specific limiting cases, the velocity and scale of a modern threat eclipse human cognitive and bureaucratic capacity. Consider a scenario involving extreme environmental contamination, such as the rapid dispersion of a lethal chemical plume over a densely populated area, or a highly sophisticated, self-propagating cyberattack crippling national electrical infrastructure. In these instances, waiting for a human committee to convene, debate the evidence, and manually authorize the severance of network nodes or the shutdown of ventilation systems would guarantee mass casualties and systemic collapse. In these specific, highly volatile contexts, machine-speed intervention is not merely legally justifiable under the doctrine of necessity; it is a moral imperative required to fulfill the state's primary duty: the preservation of the life of the nation1.

Why Speed Does Not Eliminate Accountability

However, acknowledging the necessity of rapid intervention does not absolve the state from accountability; it merely displaces it chronologically. The fatal error in systems like Michigan's MiDAS was not necessarily that it operated quickly, but that it operated quickly without a safety net—issuing severe penalties and seizing assets with zero human oversight, based on opaque and deeply flawed logic6. Speed is required during the intervention phase of a crisis. Accountability belongs to the review and retirement phases. By separating these temporalities—allowing the machine to act instantaneously to mitigate the disaster, but legally empowering the human to review, correct, and cryptographically purge the system instantaneously once the threat has passed—we ensure that the algorithmic state of exception serves the rule of law, rather than permanently supplanting it.

11. Open Research Questions

As the technological capacity for algorithmic governance expands, several critical areas demand urgent interdisciplinary research:

1. Cryptographic Enforcement of Law: How can constitutional sunsets and jurisdictional boundaries be hardcoded directly into silicon and firmware, ensuring that emergency hardware physically "bricks" itself upon the expiration of legal authority, immune to software overrides?

2. Combating Automation Bias: How can user interfaces for human oversight (as mandated by the EU AI Act) be psychologically engineered to actively combat automation bias, forcing human adjudicators to critically evaluate algorithmic recommendations rather than reflexively rubber-stamping them?

3. Cross-Border Algorithmic Emergency: When an automated emergency system (e.g., a financial contagion halt or global biometric dragnet) affects transnational data flows and foreign citizens, which jurisdiction's due process standards govern the post-deprivation hearings?

4. Mathematical Model Unlearning: Can machine learning models be mathematically forced to "unlearn" specific emergency datasets without destroying the foundational utility of the entire model, thereby providing a technical solution to the Emergency Model Retirement Standard?

Web-Ready Package

Public Summary

When catastrophic crises strike—from pandemics and cyberattacks to natural disasters—governments rely on emergency powers to save lives. Increasingly, these extraordinary powers are delegated to algorithms capable of detecting threats and deploying state power at machine speed. But what happens when the emergency ends? The "Algorithmic State of Exception" occurs when temporary surveillance tools, automated quarantines, and predictive watchlists are quietly normalized, transforming short-term safety measures into a permanent infrastructure of machine judgment. This report investigates how automated systems frequently violate due process when operating without human oversight, leading to mass false accusations and unconstitutional asset seizures. To prevent temporary emergencies from becoming the permanent operating system of governance, we propose strict legal and technical safeguards: cryptographic data purging, mandatory model retirement, and automatic machine-speed stays. While algorithmic speed is vital in a crisis, it does not eliminate the absolute requirement for democratic accountability.

Ten Key Findings

1. The Algorithmic Exception: Automated crisis management shifts sovereign decision-making from accountable human executives to opaque computational code.

2. Due Process Failures: Machine-speed actions routinely bypass the constitutional right to a pre-deprivation hearing, forcing citizens to prove their innocence after the harm has occurred.

3. The MiDAS Warning: Documented cases, such as Michigan's automated fraud system, prove that algorithms deployed without human oversight can unlawfully seize assets and inflict mass constitutional injury.

4. Data Persistence: Emergency data must not just be overwritten; it must be cryptographically purged (NIST 800-88 standard) to ensure it cannot be recovered or abused post-crisis.

5. Model Contamination: Artificial intelligence models trained on emergency data retain sensitive patterns and biases; they must be retired entirely when the crisis concludes.

6. Exception Creep: Surveillance technologies purchased for acute emergencies are consistently repurposed for standard, non-emergency policing and administrative governance.

7. Human Oversight is Law: Emerging regulatory frameworks, like the EU AI Act, recognize the danger of autonomous systems and strictly mandate human override capabilities for high-risk emergency AI.

8. The Automatic Stay: Citizens must be provided a standardized digital mechanism to immediately pause automated coercive actions, forcing synchronous human review.

9. Accountability Receipts: Affected individuals must receive a transparent, immutable ledger detailing exactly how and why an algorithm targeted them.

10. Non-Derogable Standing: Algorithms must never be permitted, under any circumstances, to unilaterally execute lethal force, indefinite detention, or the stripping of legal personhood.

Emergency-Powers Glossary

  • Algorithmic State of Exception: The delegation of extraordinary sovereign emergency powers to automated systems, creating the risk of permanent, unchallengeable digital governance.
  • Cryptographic Purge: The instantaneous and irreversible destruction of data achieved by deleting the encryption key used to secure it (compliant with NIST SP 800-88).
  • Derogation: The legal, temporary suspension of certain human rights obligations by a state during an existential crisis.
  • Non-Derogable Rights: Fundamental human rights (e.g., freedom from torture, the right of habeas corpus) that remain absolute and can never be suspended, even during a catastrophe.
  • Exception Creep: The gradual, often silent integration of invasive emergency surveillance tools into the routine, everyday functions of government.

Ten FAQs

1. What is an algorithmic state of exception? It occurs when a government uses automated AI systems to independently enforce emergency rules, risking the permanent loss of civil liberties as the machine takes over decision-making.

2. Can a government legally suspend constitutional rights? Yes, under strict international guidelines (like ICCPR Article 4), but only temporarily, and the suspension must be strictly proportionate to a threat that endangers the nation.

3. What are non-derogable rights? These are absolute rights that cannot be suspended under any emergency, such as the right to life, freedom from slavery, and recognition before the law.

4. How does machine-speed technology change due process? It acts faster than a human can receive notice or appeal a decision, meaning traditional safeguards are bypassed and new "post-deprivation" accountability tools are urgently needed.

5. What happened with Michigan's MiDAS system? The state deployed an automated fraud-detection system that falsely accused tens of thousands of citizens, illegally seized their tax refunds, and bypassed basic due process, demonstrating the severe dangers of unchecked algorithms.

6. Should we completely ban the use of AI in emergencies? No. Rapid, machine-speed intervention is absolutely necessary for fast-moving threats like cyberattacks, but these systems require strict, technologically enforced oversight.

7. What happens to all the surveillance data when the emergency is over? Historically, it persists and is shared across agencies. It must be subjected to a legally mandated "Sunset and Data-Purge Protocol" to ensure its total destruction.

8. What is the No-Secondary-Use rule? It is a proposed legal and technical barrier preventing emergency surveillance data from ever being queried or used for routine, non-emergency law enforcement or tax purposes.

9. How can a citizen challenge an algorithm during a crisis? Through the implementation of a "Machine-Speed Automatic Stay," a digital mechanism that allows a citizen to instantly pause an automated punishment until a human reviews the case.

10. Can an AI model "unlearn" emergency data? Currently, it is mathematically and technically highly difficult; therefore, models trained on sensitive emergency data should be retired and destroyed entirely once the crisis ends.

"Did the emergency really end?" Checklist

  • \[ \] Has the legislative branch formally revoked the statutory emergency declaration?
  • \[ \] Have all emergency-specific databases been subjected to a verifiable cryptographic purge?
  • \[ \] Have machine learning models trained on the crisis data been permanently retired?
  • \[ \] Have physical surveillance sensors (drones, ALPRs) deployed specifically for the crisis been grounded or dismantled?
  • \[ \] Is routine interagency data-sharing blocked from accessing any residual emergency logs?
  • \[ \] Have all individuals falsely flagged by the automated system been identified and issued formal clearance notices?

Lifecycle Diagram Description

Visual Layout: A circular flow-chart illustrating the "Temporary Power Lifecycle."

  • Top (12 o'clock): It begins with the Catalyst Event, depicted by a warning icon.
  • Right (3 o'clock): Moves clockwise to a dual-key Cryptographic Unlocking phase, requiring both an Executive icon and a Judicial icon to turn simultaneously.
  • Bottom Right (4 to 8 o'clock): The cycle flows into Active Intervention, featuring an internal, rapid loop connecting "Machine Action" and "Human Stay."
  • Left (9 o'clock): As a visual countdown timer nears zero, the flow enters Mandatory Tapering, with data streams visually shrinking.
  • Center/Bottom (Ending Point): The cycle terminates at a bold red lock symbolizing the Algorithmic Guillotine, which severs the connection and deletes the model weights, physically preventing the cycle from repeating without a completely new legislative key.

Six Short Warning Callouts

1. The Creep Effect: "Surveillance bought for the pandemic will invariably be used to police the protest."

2. The Speed Trap: "Machine-speed intervention demands machine-speed accountability."

3. The MiDAS Lesson: "When algorithms act as judges, false positives destroy lives at scale."

4. Data Immortality: "Without cryptographic purging, your emergency data lives forever."

5. The Black Box: "An emergency algorithm lacking an audit trail is a constitutional crisis waiting to happen."

6. The Absolute Limit: "Algorithms may recommend, but human beings must decide on liberty and life."

Proposed Page Title, Meta Description, and Search Phrases

  • Page Title: The Algorithmic State of Exception: AI, Emergency Powers & Civil Liberties
  • Meta Description: Explore how automated emergency powers and machine-speed AI threaten civil liberties, and discover the legal, technical, and constitutional safeguards needed to prevent a permanent surveillance state.
  • Search Phrases: algorithmic state of exception, emergency powers AI, machine-speed intervention, AI civil liberties, algorithmic due process, NIST 800-88 cryptographic purge, EU AI Act emergency services, automated decision making governance, exception creep, Carl Schmitt algorithm.

Works cited

1. Counter-Terrorism Module 7 Key Issues: Derogation during Public, https://www.unodc.org/e4j/fr/terrorism/module-7/key-issues/derogation-during-public-emergency.html

2. Infecting Constitutional Precedent: An Analysis of Federal Intrastate, https://houstonlawreview.org/article/30084-infecting-constitutional-precedent-an-analysis-of-federal-intrastate-quarantine-power-through-the-lens-of-the-covid-19-pandemic

3. Technological Due Process, https://openscholarship.wustl.edu/cgi/viewcontent.cgi?article=1166\&context=law\_lawreview

4. AI Can Now Manufacture the Public That Constitutions Take for, https://www.jurist.org/commentary/2026/08/ai-can-now-manufacture-the-public-that-constitutions-take-for-granted/

5. Rationality (Chapter 4\) \- Combatting the Code, https://www.cambridge.org/core/books/combatting-the-code/rationality/663FCA8002041D1449226245693027F2

6. The Seven-Year Struggle to Hold an Out-of-Control Algorithm to, https://themarkup.org/newsletter/hello-world/the-seven-year-struggle-to-hold-an-out-of-control-algorithm-to-account

7. Human Rights Principles in Public Health Emergencies, https://petrieflom.law.harvard.edu/2023/11/07/human-rights-principles-in-public-health-emergencies-from-the-siracusa-principles-to-covid-19-and-beyond/

8. Bauserman v. Unemployment Insurance Agency :: 2022 \- Justia Law, https://law.justia.com/cases/michigan/supreme-court/2022/160813.html

9. EU AI Act: Summary & Compliance Requirements \- ModelOp, https://www.modelop.com/ai-governance/ai-regulations-standards/eu-ai-act

10. NIST 800-88 Purge Certification: Key Audit Requirements, https://hummingbirdinternational.net/blog/compliance-regulations/nist-800-88-purge-certification/

11. The State of Exception Between Schmitt and Agamben \- PMC, https://pmc.ncbi.nlm.nih.gov/articles/PMC9510511/

12. Literature in a State of Emergency, http://scalar.usc.edu/works/cherchez-le-texte-proceedings-of-the-elo-2013-conference-1/literature-in-a-state-of-emergency

13. Glory and the Empty Throne: The State of Emergency That Never Ends, https://medium.com/@krigerbruce/glory-and-the-empty-throne-the-state-of-emergency-that-never-ends-2f5bd7cda003

14. Agamben, Giorgio | Internet Encyclopedia of Philosophy, https://iep.utm.edu/agamben/

15. The Automated Administrative State: A Crisis of Legitimacy, https://scholarlycommons.law.emory.edu/cgi/viewcontent.cgi?article=1418\&context=elj

16. The Constitution and the Coronavirus \- Podcast, https://constitutioncenter.org/news-debate/podcasts/the-constitution-and-the-coronavirus

17. 20 ILCS 3305/7, https://www.ilga.gov/documents/legislation/ilcs/documents/002033050K7.htm

18. SB0103 \- Illinois Compiled Statutes, https://www.ilga.gov/documents/legislation/102/SB/PDF/10200SB0103.pdf

19. HB1463 104TH GENERAL ASSEMBLY \- ILGA.gov, https://ilga.gov/ftp/legislation/104/HB/10400HB1463.htm

20. Supreme Court of the United States, https://www.supremecourt.gov/DocketPDF/20/20-305/157289/20201009115241558\_2020%2010%2009%20Scholars%20Amicus.pdf

21. Economic Liberty Takings \- The George Mason Law Review, https://lawreview.gmu.edu/print\_\_issues/economic-liberty-takings/

22. (PDF) Emergency and Escape: Explaining Derogations from Human, https://www.researchgate.net/publication/48346655\_Emergency\_and\_Escape\_Explaining\_Derogations\_From\_Human\_Rights\_Treaties

23. Perspectives – Harvard International Law Journal, https://journals.law.harvard.edu/ilj/category/content/article-series/perspectives/

24. Individual rights \- Procedural due process \- PastPaperHero, https://www.pastpaperhero.com/resources/ncbe-mbe-individual-rights-procedural-due-process

25. Human oversight in the European Union \- AI Laws of the World, https://intelligence.dlapiper.com/artificial-intelligence/?t=11-human-oversight\&c=EU

26. EU AI Act \- ETO AGORA, https://agora.eto.tech/instrument/757

27. The Scored Society: Due Process for Automated Predictions, https://scholarship.law.bu.edu/cgi/viewcontent.cgi?article=1611\&context=faculty\_scholarship

28. GRANT BAUSERMAN V UNEMPLOYMENT INSURANCE AGENCY, https://law.justia.com/cases/michigan/court-of-appeals-published/2019/333181.html

29. BAUSERMAN v. UNEMPLOYMENT INSURANCE AGENCY (2022), https://caselaw.findlaw.com/court/mi-supreme-court/2181105.html

30. (PDF) The “War” Against Covid-19: State of Exception, State of, https://www.researchgate.net/publication/354609638\_The\_War\_Against\_Covid-19\_State\_of\_Exception\_State\_of\_Siege\_or\_Constitutional\_Emergency\_Powers\_The\_Italian\_Case\_in\_Comparative\_Perspective

31. NIST 800 88 Rev.2 Guidelines on Media Sanitization, https://www.bitraser.com/article/nist-800-88-r2-media-sanitization-guidelines.php

32. Data Sanitization | University IT, https://uit.stanford.edu/security/data-sanitization

33. NIST 800-88 Data Destruction Guide \- CyberCrunch, https://ccrcyber.com/nist-800-88-data-destruction

34. 2026 HIPAA Data Destruction Guide \- STS Electronic Recycling, https://www.stselectronicrecyclinginc.com/hipaa-2026-data-destruction

35. Petition for a Writ Of CertiOrari \- Supreme Court of the United States, https://www.supremecourt.gov/DocketPDF/22/22-1158/267754/20230525160251063\_Petition.pdf

36. AHMED v. GABLE et al, No. 1:2021cv03333 \- Document 23 (D.D.C., https://law.justia.com/cases/federal/district-courts/district-of-columbia/dcdce/1:2021cv03333/238719/23/

37. The Automated Administrative State: A Crisis of Legitimacy, https://scholarship.law.bu.edu/cgi/viewcontent.cgi?article=1835\&context=faculty\_scholarship

38. Brief of Amici Curiae Former Consular Officers in Support of, https://scholar.smu.edu/cgi/viewcontent.cgi?article=1375\&context=law\_faculty

39. US case highlights AI concerns as government agencies automate, https://roboticslawjournal.com/news/us-case-highlights-ai-concerns-as-government-agencies-automate-38981933

40. The Extreme Right as a Defender of Human Rights? Parliamentary, https://www.mdpi.com/2075-471X/11/2/17