# Research

## Frameworks for systems that already run

When software decides something about a person, can that person get it corrected?

The method is the same every time. Write down what a system has to do before
anyone can correct it. Then test a real one against that, usually while the
people who run it are defending it.

Canonical: https://anivar.net/research/
The framework in one page: https://anivar.net/corrigibility.md
Terminology: https://anivar.net/corrigibility/glossary.md

## The papers

Open access · CC0 1.0 · SSRN.

### Corrigibility as a Structural Precondition for Digital Public Infrastructure: A Cybernetic Framework

Deterministic public infrastructure · vv3.0 · 54 pages
doi:10.2139/ssrn.6059075 · full text: https://anivar.net/papers/dpi.md

### Epistemic Capture and the Action Boundary: Corrigibility for Learned and Agentic Public Infrastructure

Learned and agentic infrastructure · vrev. 11 Jul 2026 · 37 pages
doi:10.2139/ssrn.6669318 · full text: https://anivar.net/papers/epi.md

## The drafts at the IETF

A signature tells you which key signed. It does not tell you who was allowed to act, or who the decision was about. When software acts for someone those are separate facts, and they have to travel with the request. These drafts add them.

### draft-aravind-oauth-operator-of-record-00

IETF · OAuth · individual · Posted 19 Jul 2026

The party accountable for an agent's action, carried in the token rather than inferred from the key that signed it.

In plain terms: When software acts for you, someone has to be answerable for it. This makes that person or organisation part of the request itself, so it cannot be worked out after the fact — or denied.

Scope: Carries an accountable operator through the exchange. It does not assign liability, adjudicate disputes, or verify the claim is true.

https://datatracker.ietf.org/doc/draft-aravind-oauth-operator-of-record/

### draft-aravind-oauth-decision-subject-00

IETF · OAuth · individual · Posted 19 Jul 2026

The person a decision is about, named in the exchange — distinct from the party who requested it and the party who is authorised.

In plain terms: The person a system decides about is often not the person using it. If a decision is never recorded as being about you, there is nothing for you to appeal. This writes you into the record.

Scope: Adds a subject identity to token and decision exchanges. It does not create appeal rights, define who may exercise them, or specify the remedy.

https://datatracker.ietf.org/doc/draft-aravind-oauth-decision-subject/

### draft-ranjbar-dane-did-01

IETF · DANE · individual · Posted 1 Aug 2026 · co-authored with Kaveh Ranjbar

Decentralised identifiers bound to the DNS through DANE, so a DID resolves against a name whose control is already provable — rather than against a registry that has to be trusted separately.

In plain terms: An agent's identity should be checkable the same way a website's is, against the domain that vouches for it — not against a list somebody else keeps and can quietly edit.

Scope: Binds a name to a key and the key to the DID document it signs. It does not define a DID method, govern who may register a name, or replace the subject's own document.

https://datatracker.ietf.org/doc/draft-ranjbar-dane-did/

## What is still going, and what is finished

### Active

#### OpenSLM

Standardisation · Base specification

A standardisation organisation for small language models — it turns the inspectability requirement into something a vendor can be held to, so a claim about a model is checked against a published profile rather than a launch post.
- Publishes: Versioned specifications · conformance levels
- Disclosure: LWD-R — logic, weights, data, representation
- Base specification ↗: https://openslm.ai/accord/

#### When procedure becomes software

Computational institutions · Essays · paper in progress

What changes when an institution’s judgement is replaced by a string comparison: an officer who once reconciled spellings on the ground becomes an OCR pass and an exact match, and the discrepancy is reported as the citizen’s.
- Cases: Electoral rolls · school and welfare systems
- Published: India’s Centralisation Migraine — The Wire, 2025
- India’s Centralisation Migraine — The Wire, 2025: https://thewire.in/government/indias-centralisation-migraine-when-tech-and-finance-crush-federalism
- The Layer 8 →: /writing/

### Standing

#### Identity as infrastructure

Digital identity · Review · court record

Enrolment, authentication, and the mandates that accumulate around an identity system after it ships. The mandates issued downstream are part of what the system does, whatever the enrolment design says.
- Systems: Aadhaar · UPI · BHIM · Aarogya Setu · CoWIN
- Notes: UPI security needs a bug tracker · Wrappers, Not Records
- Campaign: rethinkaadhaar.in — non-partisan campaign on India’s Aadhaar project
- Signed: Joint statement on equitable access to COVID vaccines · 2021
- UPI security needs a bug tracker: /writing/upi-security-needs-a-bug-tracker/
- Wrappers, Not Records: /writing/wrappers-not-records/
- rethinkaadhaar.in: https://rethinkaadhaar.in
- Joint statement on equitable access to COVID vaccines: https://internetfreedom.in/joint-statement-ensure-equitable-access-to-covid-vaccines/
- Action research →: #applied

#### India Stack Watch

Public digital infrastructure · Observatory

An architectural critique of India’s public digital infrastructure, component by component: what each one claims, what it does once deployed, and where the two diverge. The record is kept as the stack changes, so drift is visible over time.
- Surface: indiastack.in
- Covers: Identity · payments · health · consent
- Source: anivar/indiastack.in
- indiastack.in: https://indiastack.in
- anivar/indiastack.in: https://github.com/anivar/indiastack.in
- Observatory ↗: https://indiastack.in

#### Language at the device layer

Language technologies · Published standard

Indian-language input treated as infrastructure rather than as a feature: what a device must support before a language is usable on it, and what a national standard can and cannot compel. The same question returns at the namespace layer, where the root zone decides whether a script can exist in a domain name at all.
- Standard: BIS IS 16333 (Part 3)
- Software: Indic Keyboard — with the Indic Project; maintained by Jishnu Mohan
- Root zone: Neo-Brahmi Generation Panel · ICANN
- Record: Talks · 2005 onward
- Indic Keyboard: https://indic.app
- Neo-Brahmi LGR: https://www.icann.org/en/announcements/details/community-using-neo-brahmi-scripts-forms-generation-panel-for-developing-the-root-zone-label-generation-rules-lgr-26-5-2015-en
- Talks: /talks/

#### Rules at the root of the namespace

Internet governance · Root zone LGR

Rule-making at the layer beneath the applications. The Neo-Brahmi Generation Panel develops the Root Zone Label Generation Rules for Brahmi-derived scripts — which code point sequences are permissible in a top-level domain label, and which are held to be variants of each other. It decides whether a script can exist in the namespace at all.
- Panel: Neo-Brahmi Generation Panel · ICANN, formed 2015
- Bodies: ICANN · IETF · IGF · national consultations
- Record: ICANN60 · ICANN57 fellowship · IGF 2008 Hyderabad · IGF 2017 online
- Signed: OpenStand — the modern paradigm for standards, for the Indic Project
- Neo-Brahmi Generation Panel: https://www.icann.org/en/announcements/details/community-using-neo-brahmi-scripts-forms-generation-panel-for-developing-the-root-zone-label-generation-rules-lgr-26-5-2015-en
- Panel record ↗: https://icann-community.atlassian.net/wiki/spaces/croscomlgrprocedure/pages/95521558/Neo-Brahmi+GP
- OpenStand: https://open-stand.org/supporters/

### On record

#### Net neutrality

Telecom regulation · Filings · outcome on record

The Indian campaign ran through the formal consultation process. Zero rating was the mechanism at issue: a subsidy that decides which parts of the internet exist for a first-time user, alongside a licence regime for internet voice that would have priced it like a phone call.
- Role: Mozilla India · Policy and Advocacy Task Force
- Filed: MyGov, DoT committee report · letter to the Minister · TRAI differential pricing
- Outcome: Differential pricing barred, Feb 2016
- Presented at: London · Singapore · Cologne · Berlin · Hamburg · Frankfurt
- MyGov, DoT committee report: https://blog.mozillaindia.org/1406
- letter to the Minister: https://blog.mozillaindia.org/1418
- TRAI differential pricing: https://blog.mozillaindia.org/1558
- Speaking record →: /talks/

#### Software patents and the knowledge commons

Patents · 2006 – 2015

Section 3(k) of the Patents Act excludes computer programs per se from patentability. That exclusion has been reopened at intervals — 2006, 2009, 2012, and again in 2015, when the examination guidelines for Computer Related Inventions let a claim drafted around an apparatus carry the software with it. Each round was answered in the consultation of its day.
- Instances: 2006 · 2009 · 2012 · 2015
- Form: Consultation responses and joint letters, with free-software groups, industry bodies, academics and lawyers
- Record: Talks · open standards and patents, 2007 onward
- 2015 letter ↗: https://blog.smc.org.in/endsoftwarepatents2015-letter/
- Talks: /talks/

## Reviewed while they were running

Each of these was reviewed during the adversarial phase of the project, while it was live and while the people running it were defending it. Where they refused to let it be inspected, it went to court.

Aadhaar (2010–2018), UPI and BHIM (2017–2020), Aarogya Setu (2020–2021) and
CoWIN (2021). The Aarogya Setu review became Anivar Aravind v. Ministry of
Home Affairs & Ors. [W.P No. 7483 of 2020], Karnataka High Court; in January
2021 the Union and NIC were restrained from sharing application data without
user consent. Each case is set out at https://anivar.net/research/#applied

Machine index: https://anivar.net/llms.txt · Full text of everything: https://anivar.net/llms-full.txt
