ROL: Use it or lose it
Rita Felgate | August 2026
ruleoflaw.science
An em-dash publication: developed through human-AI cognitive synthesis with Claude (Anthropic). Learn about the em-dash methodology
AI is already operating inside the information architecture of states. What has to be resolved urgently is what governs it when it does.
States based on the separation of powers depend on their information architecture to coordinate access to and exercise of power. Over centuries, key attacks against states have targeted that architecture. In antiquity it was by smashing clay tablets bearing documentary evidence of state laws, administrative records and decisions — the Western Roman Empire’s governance failure was preceded not by conquest alone but by the breakdown of the documentary record that held its coordination together. History is littered with states and empires that empire building and information destruction leave behind — their coordination collapsed before their armies did.
Attacks on state information architecture run from obvious to covert — espionage, propaganda, and the flooding of decision-making with false or distorted intelligence. Those attacks can emanate from other states or non-state actors.
What AI introduces is not a new threat to state information architecture, but an old threat that can be implemented at new scale and speed.
Several European governments and agencies have ended or restricted their use of Palantir systems — France’s domestic intelligence agency, Germany’s military cyber command, Switzerland (which repeatedly declined Palantir contracts on sovereignty grounds), and others — following concerns about data sovereignty, single-supplier dependence, and the terms on which state coordination information was being processed. Governance experts have raised significant concerns about the documentary basis on which DOGE operated within federal agencies. Both cases point to the same structural problem: AI operating in government without the documentary record that makes its exercise of state power verifiable. That is informational conquest — capture or disruption of a state’s information architecture without physical destruction, through means that are deniable, incremental, and legally ambiguous. It is the nuclear option of the information age: without crossing a border, without firing a shot, and without triggering the international legal responses that physical conquest would attract.
AI suppliers entering the coordination chain face a consequence they may not have anticipated: their systems are not merely tools deployed by the state, but instruments through which the state accesses and exercises power. Palantir’s CEO, Alex Karp, told investors in February 2025 that the company exists to improve the institutions it partners with and, when necessary, “to scare our enemies and, on occasion, kill them.” That is not a commercial function. It is an exercise of state power — and it must satisfy the same observable conditions as any other exercise of state power, including the highest-stakes ones.
However, while the information age creates the vulnerability, it also facilitates a solution. A defective governance coordination instrument can be identified at the point of its production. States do not have to wait for information system collapse before beginning reconstruction of their information architecture — instrument failures can be identified and repaired immediately, before they accumulate past the point of correction.
The Rule of law is a system of governance that provides the coordination architecture and informational integrity upon which state stability depends. It is not a binary presence or absence, but a system of governance whose parameters are measurable, whose failures are correctable, and whose integrity is maintainable in real time. It has remained unnamed, unmeasured, and undefended — until now. A commencement failure can be measured across sixteen years of gazette records; an authority defect can be corrected by republication. That is what measurement makes possible. The previous post established how that measurement works and what it has found.
The introduction of AI within government operations is currently negotiated through procurement contracts. With the vulnerability so visible, two questions are being asked simultaneously about those contracts.
Governments are asking: how do we ensure AI is governed through legislation — and faced with a threat they cannot meet by force, how do they protect the information architecture on which the state depends? AI suppliers are asking: how do we manage our exposure of deploying in government?
The fundamental answer to both questions lies not in new legislation or new regulatory bodies but in understanding and applying the ROL as the coordination rule that has been governing and stabilising states all along. The ROL is the coordination rule whose conditions are observably satisfied or not satisfied in the documentary record — with the particular advantage that both parties can independently assess whether those conditions are met, without requiring trust, common interest, or negotiated agreement. Its conditions are necessary to the coordination capacity of the state and hence its stability. Both parties to a procurement contract enter this era vulnerable to what has just been described. Both have an equal interest in the ROL framing a solution.
A note on terminology: throughout this post, “Rule of law” does not mean democratic values, judicial independence, or human rights — though these may be its effects. It means the coordination mechanism by which access to and exercise of state power is measured, prior to and independently of any particular piece of legislation. If that distinction is unfamiliar, the previous post sets it out.
The ROL Is Upstream of the Contract
The ROL arises with the complexity of governance systems that makes the separation of powers between components of state inevitable. It is what enables that complexity to maintain stability. It preceded the legislation that expresses it — and it precedes any contract that rests on those.
The ROL exists upstream of and a priori to legislation and state contracts. Their coordination effect is conditional on the ROL’s observable conditions. Those conditions are not conditional on them. Legislation or state contracts that ignore, contradict or misconstrue the ROL’s observable coordination conditions have outputs that cannot enter ROL-compliant information streams — they fail the coordination test that valid governance instruments must pass.
When a government and AI supplier contract to provide government services, both parties turn to legislation and contract law for the framework of their obligations, and their due diligence is perceived as limited to those instruments. But the ROL sits upstream of both.
An AI supplier contracting with government to provide government services should therefore assess compliance at two levels: firstly, whether the legislation underlying the contract satisfies the ROL’s observable coordination conditions, and secondly, whether the contract itself, in what it authorises the parties to do, is consistent with those conditions. Likewise, a government official contracting with an AI supplier needs to ensure the same.
A contract signed by an official without valid statutory authority is not saved by its black letter terms. A contract authorising AI to carry out functions that exceed the statutory powers of the contracting state entity is not saved by the fact that both parties agreed to it. The AI supplier enters the coordination chain at the point its output is used in the state’s access to or exercise of power — not merely because it supplies AI. At that point, the observable conditions for ROL-compliant coordination apply to its output.
Gap Between Constitutions and the Rule of law
The reason neither governments nor AI suppliers have yet invoked a ROL clause is simple: the ROL has never been operationally defined in a form that a contract could reference. Some Constitutions invoke it — South Africa’s Constitution names it a foundational value, full stop, no definition — and courts have developed the concept through recognition in judicial precedent. The SROL’s Seven ROL Compliance Categories are the first operationalisation precise enough to be contractually referenced. That changes what is now possible.
The Observable Conditions for ROL-Compliant Coordination
Every documentary governance instrument — every Act of Parliament, regulation, ministerial notice, proclamation, commencement notice, ministerial direction, assignment, delegation, and notice of general application — must satisfy seven observable conditions for ROL-compliant coordination to be possible. That is not a finding; it is what coordination requires. Without any one of these conditions, access to and the exercise of state powers cannot coordinate a ROL-compliant effect. The Seven ROL Compliance Categories: Authority, Jurisdiction, Clarity, Public Participation, Publication, Referent, Commencement. Full definitions and codebook →
Many of these conditions are formally codified in legislation — but their source is the ROL, not the legislation.
What research establishes is what happens when the conditions fail.
The failure of any Category means the instrument cannot coordinate a ROL-compliant effect. The question of whether domestic law treats the resulting instrument as void, voidable or otherwise remediable is a separate remedial question answered by positive law. The coordination failure is not a separate question — it is the observable fact that the instrument cannot do what it is supposed to do.
Twenty years of research. 28,337 South African government gazette documentary records coded against the Seven ROL Compliance Categories. A correlation of −0.979 between the integrity of the information architecture those categories measure and the breakdown of governance coordination. That integrity measure is built from three of the seven categories — Publication, Referent and Clarity. The independence test shows their relationship with coordination failure is significantly stronger than that of the remaining four.
This research demonstrates that the Rule of law coordination mechanism is not theoretical. It is measurable. It has been measured.
Risks the AI Era Is Exposing
AI is now generating governance instruments — drafting regulations, processing ministerial notices, producing policy documents that become the basis for the exercise of state power. AI is also making decisions that are properly those of creatures of statute — decisions requiring statutory authority, affecting rights and obligations, depending on powers conferred by legislation, and which carry the duties and obligations of creatures of statute in performing those decisions. Whether generating instruments or making decisions, the ROL’s observable coordination conditions apply.
Much of what applies does so already through existing black letter law and common law. What is not yet required by contract with governments is systematic verification of Seven ROL Compliance Category compliance at the point of AI production.
This absence creates exposure on both sides of the contract.
For the state: a governance instrument generated or processed by AI that fails any one or more of the Seven ROL Compliance Categories means that state powers exercised down the line depending on that instrument cannot coordinate a ROL-compliant effect. A failure to commence an Act, for example, cannot be the basis of and cannot coordinate any exercise of power under that Act. To the extent that any exercise of state power depends on such an instrument as its legal authority, that exercise is without a secure legal foundation and remains challengeable.
For the AI supplier: the supplier enters the coordination chain when its output is used in the state’s access to or exercise of power. From that point, the observable conditions for ROL-compliant coordination apply. Where conditions of AI deployment or its product fail any one or more of the Seven Categories, the contract terms that give that product its statutory effect leave the AI supplier without a secure legal foundation.
What flows from these failures — whether invalidity, damages, rescission, judicial review, administrative correction, or nothing at all — is answered by positive law in each jurisdiction, not by the ROL. The ROL establishes the coordination failure. Positive law determines the consequence.
The insertion of a ROL due diligence clause within procurement contracts between AI suppliers and government addresses a different and prior question: it creates an express contractual duty to test and document compliance with the Seven Categories, and allocates consequences between the parties if that duty is not performed. That clause — and what it makes possible — is the subject of the next section.
ROL: A Double-Edged Due Diligence Sword
The ROL’s coordination conditions operate in both directions simultaneously — and this is the distinctive strength of ROL-based requirements within a procurement contractual instrument.
Satisfying the observable conditions for ROL-compliant coordination is inherent in the statutory function. The state cannot choose whether to require that compliance when AI is delivering functions the state provides under statutory appointment. The ROL due diligence clause — the contractual instrument of the state — simply makes that pre-existing condition explicit, documented, and with contractually allocated consequences for failure.
The AI supplier’s accountability to the ROL’s coordination conditions exists a priori the government procurement contract — neither created by the contract nor imported into it, but simply expressed by it. AI output in a governance function occupies the position of witness evidence: it is evidence of the state’s exercise of power and must satisfy the same Seven ROL Compliance Category conditions as any other governance instrument through which state power is coordinated.
A state that refuses to include the ROL due diligence clause is not taking a legal position. It is accepting instruments into its documentary record without verification that they satisfy the observable conditions for ROL-compliant coordination.
An AI supplier that resists the clause is not protecting a commercial position. It is declining to document that its exercise of government functions or its product satisfies the conditions that coordination requires.
Neither party’s position is defensible when a coordination failure becomes visible — in a courtroom, a regulatory proceeding, or a constitutional challenge. The resolution of coordination failures runs through the ordinary functioning of the components of state — the Public, the Legislature, the Executive, and the Judiciary. That is where the standing question will be answered: in positive law, not in the ROL.
The standing question becomes urgent immediately precisely because ROL coordination failures accumulate undetected and unresolved: they pile up daily — in uncommenced Acts, in unpublished regulations, in instruments that lack their authority — and go unrecognised until someone with a specific legal grievance stumbles into court a decade later, if they surface at all. In circumstances of state capture, they may never surface because the components of state that should bring them have themselves been captured.
The SROL’s ROL measurement instrument changes what can be put before a court. A documented Category failure is evidence — observable, verifiable, grounded in the documentary record — of a defect in the information architecture on which the exercise of separate powers of state can coordinate. That is not a private grievance. It is a failure in the coordination on which separately exercised state powers depend. Whether the ordinary requirements of standing fit that kind of evidence — where the defect is public and documentary rather than private and consequential — is a question for positive law. It is one the ROL literature has not yet answered.
Nature of the ROL Due Diligence Clause
The clause does not make the ROL enforceable. It makes ROL due diligence contractually enforceable.
As a contractual instrument, the ROL due diligence clause makes the a priori ROL accountability explicit and documented without requiring new legislation, a new regulatory body, or international agreement.
It requires one ROL due diligence clause in an AI procurement contract, referencing the published Seven ROL Compliance Category methodology (Felgate, R. (2026). DOI: 10.5281/zenodo.21134975), specifying that AI-generated or AI-processed governance instruments must satisfy the Seven ROL Compliance Categories during due process, and providing for independent verification against the documentary record.
The Seven Categories are not equally within either party’s control — and that differential allocation enhances the clause’s discriminating power, not its limitation.
The AI supplier’s production-side categories — Clarity, Publication, Referent — are within the AI supplier’s control at the point of instrument production. The AI supplier warrants these. The process-side categories — Authority, Jurisdiction, Commencement — are properties of the state’s upstream process: whether the official held the power, whether the instrument fell within it, whether the commencement step was taken. The state warrants these. Public Participation concerns a process that preceded the instrument’s production entirely; both parties verify against the documentary record that participation occurred — the record of it, which is what a contract can reach. Where participation was conducted by a third party acting under statutory authority, that party’s outputs are themselves instruments of the state’s exercise of power and must satisfy the Seven Categories in their own right.
Where either party cannot verify a Category, that inability is itself the signal of due diligence failure. If the state cannot verify its own Authority or Jurisdiction, the verification gap is the defect. If the supplier cannot verify Commencement, the uncommenced status is the defect. The verification failure and the Category failure are the same observable fact, seen from different positions in the coordination chain.
Verification against the published codebook and the state’s gazette documentary record is possible today — manually, by any person with access to both. The verification programme makes verification continuous and automated. The practical path to auditing due diligence will likely be by third-party verification: an independent party applying the published codebook to the state’s gazette documentary record, with no stake in the outcome and consequences available against either party. That is the ROL due diligence clause in its first operational form — and it is the market-setting move.
Indicative clause elements. A ROL due diligence clause should specify: (1) that AI-generated or AI-processed governance instruments are subject to Seven ROL Compliance Category verification before entry into the state’s documentary record; (2) which Categories each party warrants (production-side: supplier; process-side: state; Public Participation: verified jointly against the documentary record); (3) that where verification is impossible, the gap constitutes a Category defect triggering the clause’s consequence provisions; and (4) that verification may be performed by an independent third party against the published codebook (Felgate, R. (2026). DOI: 10.5281/zenodo.21134975) and the gazette record.
For AI suppliers, the clause is not a burden, but a documented due diligence trail that converts a coordination failure from a liability into a defence.
The first government that includes such a clause sets a precedent. But the more likely first mover is the supplier. An AI supplier operating across jurisdictions has a direct commercial interest in one documented standard rather than twenty bespoke contractual regimes. Refusing to document ROL compliance is indefensible when a coordination failure surfaces. Accepting the standard — and being able to demonstrate compliance against a published, open-access codebook — is the competitive differentiator in government procurement.
The window is open. Governments are actively seeking AI governance frameworks. The ROL’s observable coordination conditions are published, open access, empirically grounded, and contractually operationalisable today.
The clause does not require immediate full compliance. It requires documented due diligence — a contractually visible trajectory that both parties can monitor, enforce, and improve against. And it does not require the state to solve its compliance deficit before contracting: it creates the commercial space for AI suppliers to bring production-side compliance tooling with them — the forms and pre-publication checklists that make Seven Category compliance achievable at the point of production. Verification instruments, however, must remain independent — the party being verified cannot supply the verification standard.
The Verification Programme
The ROL due diligence clause is the immediate step. The programme is the destination.
What is in store if this fails is not a new dystopia. It is the acceleration of the existing one — more winner-takes-all transactionalism, faster consolidation of power by those who control the information architecture, less time for correction before the degradation becomes irreversible. We are on the precipice already — a moment where states can choose a rules-based order or face the real risk of information system failure and the discoordination of state functions that follows. The direction is visible.
A programme that applies the Seven ROL Compliance Categories automatically — to any governance instrument, during due process, before publication — is technically buildable from the published methodology. Input: a governance instrument. Output: pass or fail on each of the Seven Categories, overall verdict, identified coordination defects, suggested corrections.
The question that concerns every state is whether governance AI will operate within the coordination architecture the state requires — or outside it. The SROL’s answer is structural: the observable conditions for ROL-compliant coordination apply to the instrument regardless of who or what produced it. The Public, the state and its service providers undertaking governance functions — as agents, with AI as their instrument — apply those conditions through the verification programme. That is not a constraint on what AI can do. It is the coordination architecture within which what AI does either serves governance or fails it.
The ROL due diligence clause does not wait for legislation. It does not wait for a regulator. It does not wait for international agreement. It waits for two parties to agree. That route is available today. Use it.
The Science-based Rule of law framework has been in development for twenty years. Its systematic documentary measurement covers sixteen years of South African government gazette data, applying formal scientific methodology to governance. The Seven ROL Compliance Category methodology is published open access: Felgate, R. (2026). DOI: 10.5281/zenodo.21134975.
Rita V. Felgate is an independent legal practitioner and governance researcher. She is the founder of ruleoflaw.science and the developer of the Science-based Rule of law framework.