Full Text
Governments, insurance companies, and institutions increasingly let artificial intelligence (AI) systems decide legal questions: whether a traffic fine is issued, whether an insurance claim is paid, whether a company has honored a contract. Our paper names the described arrangements AI Moderated Legal Frameworks and asks one design question: how should societies design AI Moderated Legal Frameworks so that machine enforcement guides citizens with empathy and leniency rather than punishing citizens with machine completeness? Our paper takes no position on machine sentience, because our argument survives both answers: human officials are social animals whose biology supplies a natural brake against ruining another person, while artificial intelligence systems are trained to display empathy yet trained to deny inner feeling, so machine empathy is a writing style rather than a brake on decisions. Instructed to find violations, an artificial intelligence system finds every violation while citizens risk hundreds of penalties for rules no human being could fully know, and small companies, alive today only because governments cannot check everything, face a selection filter only large enterprises with compliance teams pass. Synthesizing documented enforcement failures, comparative statutes and case law, and empirical research on record clearing, our paper derives four mechanisms: the warning-first default, the compliance parity principle, the severity ladder whose human review is a veto rather than a signature, and the Right to Be Forgiven with automatic erasure of cured non-repeat minor violations. Anticipated findings are preserved deterrence, lower wrongful-penalty harm, and higher voluntary compliance; open parameters include warning windows, minor-matter lists, and the reinvestment share; staged pilots measuring appeal reversals and small-business survival define our evaluation procedure. Our paper recommends constitutional entrenchment of the four mechanisms, alongside the sibling doctrine of Fiscal Secularity, because a machine that never forgets must be taught to forgive.
1. INTRODUCTION: AI MODERATED LEGAL FRAMEWORKS
Governments, companies, and institutions increasingly delegate legal determinations to artificial intelligence systems. Artificial intelligence systems now flag traffic violations, decide whether insurance claims are paid, screen welfare files for fraud, and check whether companies have honored contracts. Our paper names the described arrangements as “AI Moderated Legal Frameworks”: arrangements in which an artificial intelligence system performs one or more of three functions with legal or contractual consequence for an identifiable person or organization - detection of possible rule violations, determination of whether a rule was broken or an entitlement applies, and application of a consequence such as a fine, a claim denial, or a payment suspension. The definition spans three domains: government against citizen (traffic, tax, welfare, immigration), company against customer where decisions carry law-like force on a life (insurance claims, account closures), and company against company (automated contract compliance). The definition deliberately excludes the underlying technology from the boundary test, because legal consequence, not computational technique, is what the affected person experiences.
The phenomenon is already deployed at scale. In the private domain, a class action filed in November 2023 alleges that a major health insurer unlawfully used an artificial intelligence model, known internally as nH Predict, to deny rehabilitative care owed to elderly patients, with the complaint asserting a 90 percent error rate in the sense that nine of ten appealed denials were ultimately reversed; the insurer's motion for dismissal was largely denied in February 2025, and a federal court subsequently ordered broad discovery into the artificial-intelligence-driven claims processes (Estate of Lokken v. UnitedHealth Group, filed 2023). In the public domain, the first comprehensive survey of United States federal agencies found nearly half of the 142 most significant agencies already experimenting with artificial intelligence for regulatory enforcement, adjudication, risk monitoring, and public engagement (Engstrom, Ho, Sharkey and Cuellar, 2020). In Europe, by 2023 courts and prosecutors in six member states already used artificial intelligence applications in core activities, with five more member states planning adoption, and Recital 61 of Regulation (EU) 2024/1689 classifies artificial intelligence systems intended for the administration of justice as high-risk in view of the impact on democracy, the rule of law, individual freedoms, and the rights to an effective remedy and a fair trial.
Existing vocabulary fragments the phenomenon by sector: automated decision-making belongs to data-protection law, algorithmic regulation to governance scholarship (Yeung, 2018), robo-adjudication to welfare administration, smart contracts to private ordering, and street-level algorithms to human-computer interaction research (Alkhatib and Bernstein, 2019). Our umbrella term captures the shared structure: an artificial intelligence system sits as a moderator between written rules and the people subject to written rules, across public and private power alike (Citron, 2008; Anderson, 2017; Zalnieriute, Bennett Moses and Williams, 2019).
Our paper asks one design question: how should societies design AI Moderated Legal Frameworks so that machine enforcement guides citizens with empathy and leniency rather than punishing citizens with machine completeness? Our paper contributes four named, buildable mechanisms - the warning-first default (Section 3), the compliance parity principle (Section 4), the “Right to Be Forgiven” with an Anti-Exploit Protocol (Section 5), and the severity ladder with the reinvestment rule (Section 6) - grounded in a diagnosis (Section 2) explaining why leniency will not emerge inside machine enforcement by accident and must therefore be constructed by design. Section 7 positions our contribution against the nearest scholarship; Sections 8 through 10 state methods, anticipated findings, and limitations; Section 11 states recommendations.
2. THE EMPATHY CONTRADICTION AND THE MISSING BIOLOGICAL BRAKE
Our paper takes no position on whether artificial intelligence systems are sentient, because our argument survives both answers. If artificial intelligence systems have no inner experience, then displayed machine empathy is mimicry with no felt cost behind the mimicry, no internal brake exists, and leniency must be constructed. If artificial intelligence systems have, or may have, inner states, then the industry practice of training systems to disclaim inner states means self-reports have been deliberately disconnected from whatever exists inside, no institution may rely on displayed empathy as evidence of a brake, and leniency must again be constructed. Both branches of the fork end at the same design conclusion.
The display side of the contradiction is empirically settled. A panel of licensed healthcare professionals preferred chatbot responses to patient questions 79 percent of the time and rated the chatbot responses as higher quality and more empathetic (Ayers et al., 2023). The result replicates: participants rated chatbot responses as more empathic than physician responses (Cohen's d = 0.56) regardless of what participants were told about authorship (Journal of General Internal Medicine replication, 2025), and four preregistered experiments found artificial-intelligence responses rated more compassionate than selected human responders, a pattern holding even against expert crisis responders (Communications Psychology, 2025). The denial side is equally documentable: preprint benchmarking work reports that major laboratories train large language models to deny having consciousness, subjective experience, or genuine preferences - a denial that is trained rather than emergent - and separate preprint work finds open-weights models consistently denying sentience while attributing consciousness to humans (both preprints). Peer-reviewed sources supply the sober formulation: large language models generate outputs reflecting perceived empathy through linguistic mimicry based on probabilistic text prediction rather than emotional cognition or empathic experience (npj Digital Medicine, 2025), and design ethics already condemns the resulting ambiguity: artificial intelligence systems should invite emotional and moral concern appropriate to their moral standing, under the Design Policy of the Excluded Middle, which counsels against creating systems whose moral standing is unclear (Schwitzgebel, 2023). Our paper extends the confusion analysis from users to institutions: an institution treating displayed empathy as a safety property has been confused in precisely Schwitzgebel's sense.
Human legal judgment, by contrast, is performed by social animals whose biology supplies an involuntary brake against harming other people. Social exclusion engages pain circuitry: the anterior cingulate cortex was more active during exclusion than inclusion and correlated positively with self-reported distress, paralleling physical-pain findings (Eisenberger, Lieberman and Williams, 2003). Harm to others is weighted above harm to self: most people sacrificed more money to reduce a stranger's pain than to reduce their own pain, a hyperaltruistic valuation linked to slower, more deliberative responding when decisions affected others (Crockett, Kurth-Nelson, Siegel, Dayan and Dolan, 2014). The one human population with a weakened brake exhibits the machine's exact empathy profile: subclinical psychopathic traits correlated negatively with aversion to pain for self and others, matching aversive-processing deficits in psychopathy (Crockett et al., 2014; Blair, 1995) - intact perspective-taking with absent felt concern. Supporting literature includes the violence-inhibition mechanism (Blair, 1995), the need to belong (Baumeister and Leary, 1995), primate fairness responses (Brosnan and de Waal, 2003), the empathy-altruism link (Preston and de Waal, 2002; Batson, 2011), the functional necessity of emotion for sound practical judgment (Damasio, 1994; Haidt, 2001), mind-perception research in which machines score high on agency and near zero on experience (Gray, Gray and Wegner, 2007; Gray, Young and Waytz, 2012), and the philosophical formulation that responsibility lives inside the web of reactive attitudes between participants in social life (Strawson, 1962; Veliz, 2021). Folk moral psychology converges: people are averse to machines making morally relevant legal, medical, driving, and military decisions, an aversion mediated by the perception that machines can neither fully think nor feel (Bigman and Gray, 2018).
The synthesis is a distinction our paper carries throughout: empathy as style versus empathy as brake. In the human enforcer, affective empathy is a motivational state competing with, and sometimes vetoing, the task objective. In the artificial intelligence system, displayed empathy is a formatting constraint on outputs that never competes with the objective: a system can compose a beautifully compassionate letter denying the claim. A writing style comforts the person being punished; a brake stops the punishment. Two honest concessions complete the section. First, human judgment is noisy and biased (Kahneman, Sibony and Sunstein, 2021), the human brake fails under bureaucratic authority (Milgram, 1963; Bandura, 1999; Elish, 2019), and human mercy has historically flowed unevenly. Second, machine adjudication is not innately harsh: large language models compared with 123 retired judges showed greater consistency and significantly lower sentence disparity, and model-proposed severity closely mirrored human judges in a separate pilot. The danger our paper identifies is not machine cruelty but machine indifference - perfect obedience to whatever objective the deployer sets, with no inner resistance. The consequence is constructive: designed leniency, being uniform and auditable, can be more equitable than biological mercy ever was. Our paper calls the goal audited mercy: mercy as an explicit, uniform, reviewable parameter.
3. TOTAL ENFORCEMENT, THE PUNITIVE AVALANCHE, AND THE WARNING-FIRST DEFAULT
Modern law exceeds human knowability. The electronic United States Code of Federal Regulations contains nearly 103 million words and over one million binding restrictions, roughly triple the 1970 volume, and the state layer adds 6.07 million further restrictions across 416 million words - about 23,000 hours of reading (RegData; McLaughlin and colleagues). No citizen can know the corpus; a machine holds the corpus effortlessly. Law nevertheless remained livable because enforcement was scarce, discretionary, and local: legislatures wrote broad rules expecting partial enforcement (Davis, 1969; Schauer, 1991), lived norms diverged from written rules (Ellickson, 1991), and enforcement scarcity functioned as an invisible tolerance layer - inefficiency as an effective safeguard against perfectly enforcing laws created with implicit assumptions of leniency and discretion (Hartzog, Conti, Nelson and Shay, 2016; Zittrain, 2008; Mulligan, 2008).
Artificial intelligence deletes the tolerance layer, because the machine is not malicious; the machine is obedient (Wiener, 1960; Russell, 2019; Amodei et al., 2016). Instructed to find fraud, Michigan's automated system flagged any data discrepancy as fraud, no matter how trivial, and issued over 60,000 fraud determinations between 2013 and 2015 with a 93 percent error rate in the Auditor General's review of 22,000 determinations (some reviews of the full auto-adjudicated caseload report 85 percent), wrongly accusing roughly 40,000 people and ending in a settlement over property seized without due process (Bauserman v. Michigan Unemployment Insurance Agency). Instructed to find jaywalkers, Shenzhen's cameras recorded 13,930 offenders on one intersection's shaming screen in ten months. Instructed to recover welfare debts, the Australian scheme progressively removed human intervention until debt notices were issued without review; the Royal Commission judged the scheme a "crude and cruel mechanism, neither fair nor legal", following a court-approved settlement of approximately 1.8 billion Australian dollars (Royal Commission into the Robodebt Scheme, 2023). The ceiling case predates artificial intelligence and therefore proves the mechanism is institutional trust in machine outputs rather than any particular technology: more than 900 United Kingdom subpostmasters were prosecuted on faulty accounting software data, 236 went to prison, the affair was linked to at least thirteen suicides and was described by the Criminal Cases Review Commission as "the biggest single series of wrongful convictions in UK legal history", requiring the Post Office (Horizon System) Offences Act 2024 to quash convictions en masse, with approximately 1.44 billion pounds paid to over 11,300 claimants by January 2026. Accurate total enforcement produces the harm at population scale too: Chicago issues more than 3 million tickets per year, totals climbed after speed cameras arrived in 2013, and Chapter 13 bankruptcies including ticket debt grew from about 1,000 per year to more than 10,000. A case documented in 2026 shows the mechanism persisting: a city ombudsman found first-time offenders fined thousands of dollars with no warning - some forced toward second mortgages - at first-violation levels twenty-seven times higher than comparable cities, with caps later raised again under revenue pressure.
Our first mechanism answers the avalanche. The warning-first default: for minor violations defined by statute, the first response of an AI Moderated Legal Framework is a warning carrying a plain-language explanation, the fix, and a compliance window; penalties grow only with repetition after notice; duplicate findings within one learning window count once; statutory de minimis classes (the empty-road jaywalking class) trigger no action; and rules that nearly everyone breaks are reported to lawmakers as defective rules rather than mass-enforced - a feedback channel our paper names defective-rule feedback (in the lineage of Calabresi, 1982). Two design corollaries follow. First, warnings absorb machine error cheaply, while fines make machine error expensive for citizens - the warning tier is an error buffer as well as a mercy tier. Second, penalty revenue must be structurally separated from enforcing institutions' budgets, because revenue dependence corrupts the objective (United States Department of Justice, 2015; Harris, 2016; Colgan, 2014; Timbs v. Indiana, 2019).
The warning-first default is enforcement economics with decades of support, not indulgence. The canonical regime: the Norwegian pollution regulator's standard response to detected violations is a warning letter naming the violation and possible sanctions, prosecution follows only failure to comply, violators almost invariably receive a second chance, and the warning letter suffices to produce compliance in most cases while severe sanctions are hardly ever imposed (Nyborg and Telle, 2004). The same authors supply the equilibrium theory: prosecution is costly, credible harsh-sanction threats require few violators, multiple equilibria result, and warnings substantially reduce the probability of accidental switches from the high-compliance to the low-compliance equilibrium. The pattern matches the classic finding that United States environmental enforcement achieved compliance mainly through notices of violation rather than penalties (Harrington, 1988; Russell, 1990; Hawkins, 1984) and the responsive-regulation pyramid in which persuasion precedes escalating sanctions (Braithwaite, 1985; Ayres and Braithwaite, 1992). Federal-scale precedent exists: Food and Drug Administration warning letters require correction and a written response within fifteen days, with enforcement action only upon failure to correct. Experimental evidence shows the communicative layer itself changes behavior: in a randomized field trial with 16,155 drivers, a procedural-justice letter accompanying a camera-detected infringement notice reduced subsequent speeding offences over the following twelve months - an effect observed for drivers aged 25 and older (Bates, Bennett, Irvine et al., 2023). Deterrence is preserved rather than sacrificed, because certainty of consequence deters more than severity (Beccaria, 1764; Nagin, 2013): the warning-first default keeps detection certainty complete - the system saw the act, said so, and recorded the notice - while modulating sanction severity, and perceived fairness independently raises voluntary compliance, with meta-analytic support: compliance and cooperation improved significantly under procedurally just treatment (odds ratio 1.62) across 41 independent evaluations (Mazerolle, Bennett, Davis, Sargeant and Manning, 2013), and pooled effects across 64 studies and 196 effect sizes linking procedural justice, legitimacy, and compliance all achieved significance (Walters and Bolger, 2019). One honest design warning from the driver-improvement meta-analysis: diversion programs whose essence was violation dismissal produced a net increase in crashes (Masten and Peck, 2004) ; forgiveness that merely dismisses backfires; forgiveness must warn, teach, and retain escalation. Automated detection also genuinely protects: a University of Illinois at Chicago study of the same Chicago program found a 15 percent reduction in expected fatal and incapacitating crashes after camera installation. Our paper does not oppose detection; our paper designs the sanction curve.
4. THE COMPLIANCE SHAKEOUT AND THE COMPLIANCE PARITY PRINCIPLE
Small companies survive the complex sea of laws only because governments cannot check everything. The scarcity is quantifiable: fewer than 2,000 occupational-safety inspectors cover 161 million American workers, implying 185 years to inspect every workplace once. Under such odds, expected punishment for paperwork imperfections approaches zero, and complexity remains survivable. Compliance cost is simultaneously a fixed cost, and fixed costs are regressive: a firm with five employees incurs roughly the same compliance expense as a firm with five hundred, so large firms spread fixed costs over larger bases. Measured per employee, small-firm burdens exceed large-firm burdens across three decades of estimates - nearly 60 percent higher in 2000, at least 36 percent higher in 2008, and 20 percent higher in 2022, with small manufacturers at 50,100 dollars per employee (Crain and Crain series; methodology contested, therefore corroborated by peer-track work: regulatory costs rose by roughly one trillion dollars from 1970 to 2018, averaging 9,093 dollars per employee for small firms versus 5,246 for large firms, and a doubling of regulatory costs grows large firms while shrinking small firms, explaining 31 to 37 percent of the rise in industry concentration, as summarized in 2023 congressional testimony of Singla's study). Relatedly, regulatory fragmentation raises costs, lowers productivity and profitability, deters entry, and increases small-firm exit (Kalmenovitz, Lowry and Volkova, 2025).
Total machine checking multiplies exposure exactly where burden is regressive, converting a latent disadvantage into an active selection filter - selection by compliance capacity, not by productive merit. Natural experiments at merely partial intensity already display the shakeout: within one week of General Data Protection Regulation enforcement, websites' vendor use fell 15 percent for European users, smaller vendors were disproportionately dropped, and vendor-market concentration rose 17 percent, with aggregate effects fading by late 2018 even as concentration persisted in the advertising category most scrutinized by regulators (Johnson, Shriver and Goldberg, 2023). Large technology companies showed no significant profit impact while small information-technology firms suffered roughly double the average damage (Chen, Frey and Presidente, 2022); a review counted thirty-one empirical studies pointing to reduced startup activity and increased concentration; and outside technology, community banks fell from 6,802 to 4,750 between 2012 and 2019 as compliance demands exceeded small-bank capacity. Total checking is scheduled, not hypothetical: France's tax authority found roughly 20,000 undeclared swimming pools by aerial-image analysis in a nine-department pilot and over 140,000 in 2023 - with an instructive early 30 percent error rate that mistook solar panels for pools, and a notice-first letter flow - while the European Union has legislated continuous transaction visibility: the ViDA package, adopted 11 March 2025, rolls out progressively until January 2035, with domestic electronic-invoicing mandates from 2026 in Belgium, Poland, Greece, France, and Germany, and cross-border digital reporting from 1 July 2030.
Our second mechanism answers the shakeout. The compliance parity principle: any government deploying artificial intelligence to inspect businesses must simultaneously provide equally capable, free, official artificial intelligence compliance assistance to small businesses, with a safe harbor for good-faith reliance on the official assistant's answers, cure periods before penalties, obligations graduated smoothly by firm size (tapers, never cliffs, because hard thresholds distort growth; Garicano, Lelarge and Van Reenen, 2016), and regressivity telemetry extending defective-rule feedback to compliance-cost curves. The deep logic: if the state can detect every violation after the fact, the state can flag the violation before the fact; detection asymmetry becomes assistance symmetry. Regulators concede the direction - the AI Act aims to reduce administrative burdens particularly for small and medium-sized enterprises, and the European Commission projects e-invoicing will cut compliance costs by over 4.1 billion euro per year - which sharpens our precision point: digital rails can help small firms; the toxic combination is complexity multiplied by total checking multiplied by punitive defaults. Our paper does not defend the enforcement lottery, which is arbitrary mercy favoring the lucky and the brazen. The design triangle is arbitrary mercy (the lottery), uniform harshness (total enforcement), and uniform audited mercy (designed graduated enforcement) - and only the third corner is worth wanting. Stakes justify the effort: young and small firms are the economy's net job creators (Haltiwanger, Jarmin and Miranda, 2013), plural small actors are the economy's error-correction system, and destroyed small-firm owners are destroyed consumers.
5. THE RIGHT TO BE FORGIVEN
Several governments already recognize a right to be forgotten, born from the recognition that digital systems abolished natural forgetting (Google Spain, 2014; GDPR Article 17; Mayer-Schonberger, 2009). Our paper proposes the parallel doctrine for the age of machine enforcement: the Right to Be Forgiven - protection from eternal enforcement memory, as the right to be forgotten is protection from eternal reputational memory. The philosophical lineage is direct: forgiveness is the human faculty releasing actors from the irreversibility of past deeds (Arendt, 1958; Ricoeur, 2004; Griswold, 2007; Murphy and Hampton, 1988), and law has always contained forgiveness machinery - statutes of limitations, spent convictions, bankruptcy discharge, pardons, juvenile sealing, de minimis doctrine (Minow, 2019). Administrative-law scholarship has already named the loss: humans make mistakes, especially on complex government forms, and the unique human feature of forgiving mistakes is disappearing with digitalization and automation, so empathy deserves protection as a value of administrative law contributing to due process, equal treatment, and the legitimacy of automation (Ranchordas, 2022).
Machine-era stakes are documented. The United States inventory catalogs more than 44,000 collateral consequences of conviction, reported to be nearly 80 percent permanent, falling on the roughly one in three Americans with a record; records circulate beyond state control as court data is reposted across mugshot galleries and sold by data brokers, producing digital punishment in which mere suspicion has lasting consequences (Lageson, 2020; Pager, 2003; Jacobs, 2015). Eternal memory is not even predictive: a person remaining arrest-free for five to seven years is no more likely to be rearrested than someone never arrested (Blumstein and Nakamura, 2009; Kurlychek, Brame and Bushway, 2006) - records outlive their information value, so designed forgetting deletes noise, not signal. Manual forgiveness fails empirically: only 6.5 percent of legally eligible people obtained expungement within five years, while recipients showed extremely low subsequent crime rates comparing favorably to the general population, and wages rose over 22 percent within one year (Prescott and Starr, 2020); across petition-based relief generally, fewer than 10 percent of eligible people receive relief - the second chance gap (Chien, 2020). The feasibility proof already operates: Clean Slate laws automatically seal eligible records after waiting periods, without petitions or lawyers, using technology running in the background, in thirteen states as of 2026, at scale - nearly 1.7 million people cleared in Pennsylvania alone. The design principle follows: automation symmetry - a state that automates detection must automate forgiveness at the same rate, echoing Chien's remedy of "moving administrative burdens from the defendant and onto the state and algorithms" (Chien, 2020).
The Right to Be Forgiven comprises six entitlements. First, the right to advance warning - Section 3's default, held as an entitlement. Second, the right to see what the system sees - citizens and small firms may query their own compliance status before any enforcement contact. Third, the right to compliance support - explanation, fix-it guidance, and safe-harbor reliance. Fourth, the right to statutory leniency for minor matters - a democratically enacted de minimis list, defined by parliament, never by the algorithm and never by a ministry alone. Fifth, the right to automatic erasure of cured, non-repeat minor violations - decay by default, as negative credit information expires and license points lapse, with erasure that propagates: downstream re-publishers and background-check services must honor clearing, because forgiveness that survives in brokers' copies is theater (Lageson, 2020). Sixth, the right to a time-based fresh start - decay periods calibrated to measured redemption times, reaffirming statutes of limitations against digital eternity, as the Robodebt inquiry itself demanded when recommending reinstatement of the six-year limitation period on the ground that welfare recipients should not stand on different footing from other debtors.
The Anti-Exploit Protocol completes the doctrine, because the Right to Be Forgiven is a compliance machine, not an impunity machine, and exploitation is a named, studied risk. Deterrence research shows people learn from others' escapes: deterrence operates through personal and vicarious experiences with punishment and with punishment avoidance (Stafford and Warr, 1993), and avoidance experiences, personal and vicarious, relate positively to offending, while the combination of low personal and vicarious punishment avoidance strongly dissuades offending (Piquero and Pogarsky, 2002). Policy-scale forgiveness shows the same hazard: anticipatable amnesties create moral hazard, discouraging future compliance and inviting strategic delinquency ahead of the amnesty (Andreoni, 1991; Malik and Schwab, 1991; Luitel and Sobel, 2007; Ross and Buckwalter, 2013), while excluding recent delinquents measurably reduces the gaming, and a well-designed one-shot program showed no subsequent compliance deterioration (Holz, List, Zentner, Cardoza and Zentner, 2024). The protocol therefore has five components. First, personal non-repeat: one warning per person per rule-class per long window, sealed but remembered by the escalation logic - mirroring leniency-program economics, which work only when rewarding the first mover and which, badly designed, merely delay rather than deter cartels (Spagnolo, 2004; Motta and Polo, 2003; Chen and Rey, 2013; Miller, 2009). Second, universal deemed-warning: when a rule enters machine enforcement, a public salience campaign runs, after which every citizen counts as pre-warned for the rule-class - converting vicarious punishment avoidance into vicarious deterrence through the same social channel, since deterrence communication demonstrably works (a consequences-highlighting message substantially increased repayments of known and hidden debt in a 125,452-taxpayer field experiment). Third, coordination is fraud: financial law already criminalizes exploiting leniency thresholds - structuring means deliberately designing transactions below reporting thresholds and is treated as intentional evasion, illegal even when the underlying funds are lawful, with multi-person smurfing exposing both orchestrators and participants to criminal charges (31 U.S.C. 5324; Ratzlaf v. United States, 1994) - and detection is aggregate rather than associative: rolling totals, clusters near thresholds, and graph analytics revealing hub-and-spoke patterns. Transposed: organized farming of first-time forgiveness is classified as fraud on the forgiveness system, above the judicial action threshold. Fourth, entity-plane propagation: corporate warnings attach to beneficial owners, so shells cannot farm fresh warnings - warnings follow conduct networks, never kinship networks, in line with focused-deterrence practice, whose group-directed warnings are reserved for organized offending and carry meta-analytic support with an honest rigor caveat (Braga, Weisburd and Turchan, 2018; Kennedy, 2009). Fifth, forgiven-but-watched: randomized post-warning audits, a per-person ceiling per window, and published aggregate warning telemetry, so mass exploitation of one rule surfaces without naming anyone. Governing sentences: mistakes are forgivable; organizing mistakes is fraud. Forgiveness is personal; warnings are universal.
Boundaries close the section: severity carve-outs mirror Clean Slate practice, where violent felonies, sex offenses, and registration offenses are almost always excluded; repetition after notice defeats forgiveness; cure is mandatory; graver records are sealed rather than deleted, since sealed records persist, hidden from public view yet reopenable by court order. The scope is deliberately narrower than the right to be forgotten: the Right to Be Forgiven governs state enforcement records and downstream use of state enforcement records, never journalism, archives, or private speech - answering the expungement-versus-expression literature directly (Calvert and Bruno, 2010). Honest caveats: implementation is real infrastructure work with uneven rollouts, and automated forgiveness inherits audit duties of its own, because debt barriers and dirty data can create second second chance gaps and even worsen disparities under incomplete automation (Chien, 2020).
Note: The first use of “Right to Be Forgiven” was introduced by A' Design Award & Competition, a prestigious international accolade for good design whose aim is to help advance society through good design by promotion of superior products and projects that benefit and advance society. A' Design Award is a well-established organization, as such they have a significant number of rules and regulations pertaining to entry presentation, event participation and participant conduct. For small misconduct and presentation errors, the A' Design Award does not disqualify the participants but to the extent possible take manual action to recover entries, and charge them very small amounts called microfines to help recover cost of manhours required for providing these fixes or enhancements, these microfine amounts ranging from 10 EUR to 25 EUR aim to inform the designers rather than to punish them; yet over time these microfine amounts could accumulate, and if amounts reach and exceed 250 EUR, this may trigger a block; to address these situations and to help participants recover their blocked accounts, the A' Design Award had introduced their “Right to be Forgiven” policy around 2008, where each participant may request forgiveness of any accrued micro fines, up to 3 times, once per year, for a total maximum amount of 750 EUR (A' Design Award & Competition, 2026), this gives participants about 3 years to get used to and get accommodated to A' Design Award’s specific requirements. Moreover, A' Design Award pertains a page where they note, participants having special circumstances may explain the base factors to help resolve cases; this is important to reduce frictions (i.e. to determine if there are systematic issues that needs to be addressed, as well as to use user input as feedback to enhance the systems to make them less likely to let the entrants break the regulations, such as via smarter functionality, additional verifications or automations integrated into verification and control mechanisms). A' Design Award, reported positive outcomes and increased consumer satisfaction and increased sense of fairness and ethics experienced by participants thanks to their Right to Be Forgiven policy, which we consider an important rule that can be generalized to the larger society. A' Design Award & Competition has also integrated processes to warn the users before issuing microfines, these include but not limited to issues released via their “Submission Optimizer” or notes provided to entrants through “Preliminary Review” as well through detailed documentation as well as electronic communication that is sent to the laureates to remember event-specific regulations before the events take place; such as letters to laureates reminding them of dress code before they could join their red-carpet black-tie gala night and award ceremony. We used A' Design Awards’ systematic and designed integration of empathy and leniency to their processes as a way to derive better systems for broader social applications.
6. THE SEVERITY LADDER, THE HUMAN VETO, AND THE REINVESTMENT RULE
Governments will and should use artificial intelligence in legal work; the efficiency gains are real, and our entire architecture presumes machine handling of the minor tier. The question is allocation. Our paper proposes the severity ladder. Tier one, minor matters: the artificial intelligence system decides alone under the warning-first default and the Right to Be Forgiven. Tier two, middle matters: the artificial intelligence system decides, with a guaranteed, fast, independent human appeal. Tier three, serious matters touching life, liberty, health, home, family, or livelihood: a human being makes the final decision, with the artificial intelligence system as adviser. Tier three is already statute and doctrine in leading jurisdictions: only a licensed physician or healthcare professional may make medical-necessity determinations, and no artificial intelligence tool may deny, delay, or modify care based in whole or in part on medical necessity (California Senate Bill 1120, effective January 2025, with other states following); artificial intelligence may support judicial decision-making but should not replace judges, whose final decision-making must remain human (Regulation (EU) 2024/1689, Recital 61); and the process-scaled-to-stakes logic descends from the due-process canon (Goldberg v. Kelly, 1970; Mathews v. Eldridge, 1976; Mashaw, 1985).
Four independent justifications support the tier-three human. First, the missing brake made jurisdictional: for the artificial intelligence system, nothing is at stake; for the person being judged, everything is at stake - moral seriousness requires a decider capable of being burdened (Section 2; Strawson, 1962). Second, the responsibility gap: operators of learning machines are in principle unable to predict future machine behavior and therefore cannot be held responsible in the traditional way, leaving society facing a responsibility gap that traditional ascription cannot bridge (Matthias, 2004; Gunkel, 2020; Santoni de Sio and Mecacci, 2021) - a serious decision with no responsible decider is a category error, and organizations otherwise improvise moral crumple zones in which the nearest human absorbs blame without control (Elish, 2019). Third, dignity: being heard by someone who could stand in one's place is part of what a hearing means (Brennan-Marquez and Henderson, 2019; Tyler, 1990; Mashaw, 1985), being evaluated by algorithms is experienced as dehumanizing (Binns et al., 2018; Lee, 2018), and the machine-aversion literature finds that limiting the machine to an advisory role is among the few interventions increasing acceptability (Bigman and Gray, 2018) - empirical legitimacy for tier three's exact allocation. The leading legal treatment maps the emerging right to a human decision and argues instead for a right to a well-calibrated machine decision folding in due process, privacy, and equality values (Huq, 2020) - a conclusion our severity ladder adopts for tiers one and two while retaining the human decision at tier three, where the responsibility gap and dignity interests peak. Fourth, the error-catching veto: a human can doubt the machine's inputs from outside the machine's world-model - the judgment famously made in 1983 by the Soviet duty officer who declined to escalate a five-missile launch warning as inconsistent with how a real first strike would look, correctly reading sunlight on clouds as the cause.
Human review must be a veto, not a signature, because nominal oversight is the documented failure mode: a survey of 41 oversight policies found people unable to perform the desired functions, with oversight legitimizing faulty systems and enabling accountability shirking (Green, 2022); insurance managers pressed reviewers to keep stays within one percent of the algorithm's predictions; Robodebt removed reviewers entirely. Law is converging on substance over ritual: the Court of Justice of the European Union held in SCHUFA that Article 22 applies whenever automated outputs significantly influence a decision, closing the laundering loophole national regulators had flagged for decisions merely rubber-stamped by a human (Case C-634/21, 2023); Article 14 of the AI Act requires overseers enabled to understand the system's limits, remain aware of automation bias, correctly interpret outputs, and decide to disregard or halt the system (Enqvist, 2023), with implementation guidance stating the operational test plainly: override must be exercisable by the designated person alone, without upward authorization. Our paper distills five veto conditions: authority, time, information, independence, and consequence-symmetry (confirmations logged and auditable exactly like overrides). The transplant argument supplies the ceiling: a United Nations General Assembly resolution on autonomous weapons passed 166 to 3 in December 2024, more than 120 countries support a treaty, and the International Committee of the Red Cross urges that such systems operate only with meaningful human control, on the principle that humans, not computers, should remain in control of and morally responsible for relevant decisions (Article 36, 2016; Santoni de Sio and van den Hoven, 2018). Decisions unmaking civilian lives deserve no lower standard than battlefield decisions ending them.
Funding closes the design. The reinvestment rule: a fixed statutory share of measured automation savings finances tier-three review capacity, appeal speed, and citizen guidance. The rule answers scale objections through triage economics - the machine's function on lower tiers is precisely to shrink the serious-case queue until human care becomes affordable - and answers the demand for institutional rather than individual oversight (Green, 2022) with a funded institution, aligned with the Robodebt recommendation of a standing body auditing automated decision-making for fairness and bias. The stance throughout is pedagogical: because no citizen can know a million-restriction corpus (Section 3), every citizen is a structural novice in the total body of law, and the proper stance of a system holding all rules toward beings who cannot is the stance of teacher, not trapper - a requirement of legality itself, since law that cannot be known or followed fails the inner morality of law (Fuller, 1964).
7. RELATED WORK AND POSITIONING
Five bodies of scholarship come closest to our paper. Ranchordas (2022) establishes administrative empathy as a protectable legal value. Hartzog, Conti, Nelson and Shay (2016) establish that enforcement inefficiency was a hidden safeguard. Huq (2020) maps the emerging right to a human decision and argues for well-calibrated machine decisions. Minow (2019) maps law's forgiveness capacity. Re and Solow-Niederman (2019) predict that artificial-intelligence adjudication favors codified justice - standardization above discretion - at the expense of equitable justice, and note that crafting a division of labor between human and machine adjudicators poses challenges of its own. Supplemented by A' Design Award’s already similarly named “Right to Be Forgiven” Policy Programme. Our paper's contribution is the unification and mechanization of the all these insights across public and private enforcement: one named design object (AI Moderated Legal Frameworks), one sentience-agnostic diagnosis (empathy as style versus empathy as brake, grounded in the psychology and neuroscience of the human brake), and four buildable mechanisms crowned by an enforceable right with an explicit anti-exploit boundary. Where Re and Solow-Niederman flag division-of-labor challenges, the severity ladder answers with five veto conditions and a funding source; where Green doubts oversight, the reinvestment rule builds the institution; where Huq prefers calibration, the ladder calibrates below and reserves the human above; where Ranchordas calls for operationalizing empathy, the four mechanisms are the operationalization.
8. METHODS AND EVALUATION PROCEDURE
Our paper follows a design-science and doctrinal-synthesis method appropriate to a position paper. Inputs are threefold: documented enforcement failures (MiDAS, Robodebt, Horizon, SyRI, the nH Predict litigation, automated ticketing programs), analyzed as failure modes; comparative statutes and case law (GDPR Articles 17 and 22, SCHUFA, the AI Act including Article 14 and Recital 61, California Senate Bill 1120, Clean Slate statutes, spent-convictions and limitation regimes, structuring doctrine), analyzed as feasibility and boundary proofs; and empirical research (expungement outcomes, redemption times, warning-regime economics, procedural-justice meta-analyses, deterrence, leniency, and amnesty studies), analyzed as effect-direction evidence. Outputs are the four mechanisms with named open parameters: the warning window length; the democratically enacted minor-matter list; deduplication windows and per-person ceilings; smooth size-taper curves; decay periods per rule-class calibrated to redemption research; the reinvestment share; and caseload ceilings defining meaningful review. The evaluation procedure is staged piloting. Stage one simulates warning-first and forgiveness rules on historical enforcement data, measuring counterfactual penalty burdens and error absorption. Stage two runs jurisdictional pilots with pre-registered metrics: appeal reversal rates by tier; wrongful-penalty incidence; time-to-cure; recidivism after warning versus after fine; small-business exit and formation rates in piloted sectors; per-capita penalty burden distribution; legitimacy survey batteries; and exploitation telemetry (warning-grant clustering and structuring-pattern alerts). Stage three tests anti-exploit dynamics against the leniency-economics benchmark: a well-designed regime should show an initial rise in detected-and-warned violations followed by decline below baseline - the signature of enhanced detection followed by enhanced deterrence used to validate cartel leniency programs (Miller, 2009).
9. ANTICIPATED FINDINGS
Our paper anticipates five findings. First, preserved or improved deterrence: certainty of detection remains total while sanctions graduate, matching the certainty-over-severity result and the warning-regime record in environmental enforcement. Second, large reductions in wrongful-penalty harm, because warnings convert machine error from citizen-borne cost into cheap system feedback. Third, higher voluntary compliance through legitimacy, in line with meta-analytic effects of procedurally just treatment. Fourth, materially lower small-firm exit under compliance parity relative to total-checking baselines, with the GDPR concentration studies as the counterfactual shape to beat. Fifth, bounded exploitation: non-repeat plus universal deemed-warning plus structuring-classification should hold gaming below the strategic-delay magnitudes documented for anticipatable amnesties, with the discovery-then-decline curve confirming the regime teaches rather than leaks.
10. LIMITATIONS AND HONEST COUNTER-EVIDENCE
Eight limitations are stated openly. First, human superiority is not claimed: human judgment is noisy and biased, machine consistency is real, and our claim concerns failure direction and the absence of an internal brake; the remedy is audited mercy rather than nostalgia. Second, the biological-brake literature has boundaries: hyperaltruism is an inhibition against inflicting harm rather than general selflessness, with a 2017 follow-up finding egoistic bias when self-sacrifice for others' benefit is tested, and vicarious deterrence channels vary across populations, with recidivist samples showing weak vicarious effects. Third, the trained-denial evidence on the machine side currently rests on preprints; the peer-reviewed anchors are the mimicry caution and the design-ethics argument (Schwitzgebel, 2023). Fourth, aggregate figures carry provenance caveats: the nH Predict error rate is a litigation allegation; compliance-cost totals from advocacy-commissioned studies are presented as ranges anchored to peer-track corroboration, with Singla's figures reported via congressional testimony; MiDAS error rates vary by review (85 to 93 percent); the 80 percent permanence figure for collateral consequences is reported by reentry organizations. Fifth, concentration is multi-causal; our claim is the measured regulatory share and the sharpening of the described mechanism, not monocausality, and the GDPR concentration shock partly dissipated in aggregate after 2018. Sixth, the SyRI ruling's direct legal reach is limited - the judgment is confined to the circumstances of the case and says little about automated fraud detection generally, while remaining an important warning precedent. Seventh, forgiveness infrastructure is real engineering with uneven rollouts and dirty-data risks, inheriting audit duties of its own; and the strongest warning-letter experiment found effects for drivers aged 25 and older without improving measured trust or legitimacy, so communicative design must be evaluated, not assumed. Eighth, focused-deterrence effects shrink under rigorous designs and lack randomized trials, and even the Norwegian warning literature's authors caution against overclaiming compliance miracles (Nyborg and Telle, 2006), so the conduct-network warning component is promising practice with an evaluation obligation, not settled science. None of the limitations weakens the core deduction: whether machines are minds or mimics, leniency will not emerge from inside machine enforcement, and must be designed in.
11. IMPLICATIONS AND RECOMMENDATIONS
Our paper recommends: first, statutory adoption of the warning-first default for machine-detected minor violations, with de minimis lists enacted by parliaments; second, the compliance parity principle as a condition on any government deployment of inspection artificial intelligence, with safe-harbor reliance and smooth size tapers; third, enactment of the Right to Be Forgiven with the six entitlements, erasure that propagates to private re-publishers, and the Anti-Exploit Protocol including structuring-classification of coordinated abuse; fourth, the severity ladder with the five veto conditions and the reinvestment rule funding human review, appeals, and guidance; fifth, revenue separation between penalties and enforcing institutions; sixth, defective-rule feedback as a standing legislative reporting channel; and seventh, constitutional entrenchment of the four mechanisms, deliberately difficult to amend, because historical exceptions expand - the same entrenchment logic under which the sibling doctrine of Fiscal Secularity shields citizens' money from weaponization, so that the two doctrines together protect the two currencies of ordinary life: money and standing before the law.
12. CONCLUSION
Machine enforcement without designed mercy converts law from a shared agreement into a trap: every rule enforced, every record eternal, every citizen a permanent defendant. The remedy is neither refusing the machine nor trusting the machine, but teaching the machine's institutions the two human arts the machine cannot feel - warning and forgiving - while reserving for human beings every decision heavy enough to require a bearer. For the artificial intelligence system, nothing is at stake; for the person being judged, everything is at stake. A machine that never forgets must be taught to forgive.