Admissibility Without Standing: What a Working Gate Shows About Gates

Admissibility Without Standing: What a Working Gate Shows About Gates

METHODS · WORKING PAPER — Governance. Programme: Admissibility & Evidence. Anchored to dated, citable law as of July 2026.

DISCIPLINE NOTICE. This paper analyses a legal architecture, not a political system. It takes no position on any state’s constitutional order and applies the same test to the European Union and to the Institute’s own method. Our reading of the Chinese registry’s contents rests on published external analysis rather than our own examination of the filings, and we mark that limit where it bites. Per our Correction to the Synthocracy Thesis (July 2026), no case discussed here is offered as evidence for that thesis.

The Institute has argued that AI capabilities should pass through a pre-runtime, record-based gate before entering a consequential decision — a reversible access decision with terminal outcomes, resting on the rule no record, no standing. That gate exists. It has operated at national scale for four years. It refuses applications and gives reasons. Over five thousand algorithms have passed through it.

And a person in China subject to a decision made by one of those algorithms can do nothing with any of it.

Both sentences are true, and together they identify a hole in our method that four years of argument did not reach. A gate is not a protection. A gate is an accountability relation, and every accountability relation has a direction: someone must answer to someone. The architecture of the gate — pre-runtime, record-based, reversible, terminal — determines none of that. The direction is set by a single question the architecture never asks: to whom is the record legible, and to whom are the reasons owed? Change the answer and the identical gate becomes an instrument of citizen protection, of market administration, or of state control, without a line of its design being altered.

We did not ask that question. This paper asks it, and answers it against ourselves.

The gate exists

China’s Administrative Provisions on Algorithm Recommendation for Internet Information Services came into force on 1 March 2022. Providers of recommendation algorithms bearing public-opinion attributes or social-mobilisation capability must file with the Cyberspace Administration. The administration has thirty working days to grant the filing and issue a filing number; where the materials are incomplete, the filing is refused and the applicant is notified with reasons stated, within the same thirty working days. A provider that has completed filing must then display its filing number prominently on the service and link to the published information. Providers with public-opinion attributes must additionally undergo security assessment.

What must be filed is not thin, on its face: a description of the algorithm’s mechanism covering input, logic and output; the application scenarios and user scale; a security self-assessment; the data sources and processing methods; a description of training data; and an assessment of potential risks with mitigation measures. For generative services with public-opinion attributes, security assessment and filing must precede public provision. Over five thousand algorithms had been filed through the national platform by November 2025. Enforcement includes service suspension, fines, and, in serious cases, criminal liability. In practice, observers disagree about what the system has become: whether providers merely register their assessments, or whether regulators effectively operate a licence by withholding acceptance until satisfied — two readings with, as one analysis notes, widely different implications.

Set the jurisdiction aside and check it against our own definition. Pre-runtime: yes — the decision is made before the system serves the public. Record-based: yes — admission turns on a documentary submission. Per-route and per-system rather than a blanket permission: yes. Terminal outcomes with reasoned refusal: yes. Reversible in principle, through required updates on change: yes, though re-filing practice appears inconsistent.

This is admissibility. It is the only working national implementation of it, it predates our first paper by four years, and we had not written a word about it. That should be said plainly before anything else.

What passes through the gate

Now the second finding, and its source matters. We have not examined the filings ourselves; what follows rests on published analysis, and we mark it as such.

Carnegie’s examination of the public filings found the descriptions pitched at so high a level as to be almost completely devoid of meaningful detail — the entry for Weibo’s trending-search feature characterises the algorithm as combining search popularity, discussion popularity and dissemination popularity, multiplied by an interaction-rate coefficient; accurate, perhaps, and something an observer with no knowledge of the system could substantially have guessed. The same analysis notes that the administration may lack the in-house technical expertise to interpret what it receives, recounting a meeting in which company representatives resorted to metaphor and simplified language to communicate with officials. The registry, on this reading, provides a skeletal understanding and scaffolding for later demands.

That is an envelope record: a complete, well-administered, publicly numbered account of the fact that an algorithm exists, from which no specific decision can be reconstructed. Our first signpost — the record — reads Ceremonial in the one place on earth where the gate itself is real.

This is not a failure of the gate. The gate did what it was built to do. It admitted what it was designed to admit.

The thread that runs the other way

Honesty requires the complication. The Chinese regime is not purely state-facing, and it would be convenient for our argument to pretend otherwise.

The Provisions state as their purposes the safeguarding of national security and the social public interest and the protection of the legitimate rights and interests of citizens, legal persons and other organisations. Providers must not deploy models that induce addiction or excessive consumption, must regularly review their mechanisms, models, data and outcomes, and must publish the rules of their recommendation services. Reporting notes that the regime obliges providers to give an explanation where an algorithm harms a user’s legitimate interests, and imposes user-facing duties: clear labelling of algorithm-driven content, explanation of recommendation logic in accessible language, controls to adjust or disable recommendations, and access to a non-personalised view.

Take that seriously. It is more than most jurisdictions give. A user learns that ranking is happening, learns roughly how, and can switch it off.

And now ask the two questions from our corrected definition. Can that user obtain a record from which an independent party could reconstruct the specific decision that ranked, priced, or suppressed them? No. Can they obtain a reconsideration capable of reversing it? No. What they have is disclosure of the machinery and a switch. What they lack is the decision.

(A reader will notice this is the shape our corrected thesis predicts. Per that correction, we may not cite it in the thesis’s support: China is one of the four cases from which the thesis was constructed, and a hypothesis fitted to a sample takes no confirmation from it. It is stated here as description, not evidence.)

The asymmetry of reasons

Here is the structural finding, and it is not about China.

Under the Provisions, when a filing is refused, the applicant is notified with reasons stated. When a filing is granted, a number is published. Nobody is owed reasons for an admission. Nobody outside the administration and the applicant sees the record on which the admission rested.

Reasons are owed for noes, to industry. Yeses are silent, to everyone.

That single asymmetry reveals the direction of the entire relation. The party to whom the gatekeeper must justify itself is the party the gate answers to. In this architecture, the gatekeeper must justify refusal to the applicant and justifies admission to no one. The public receives a number. The affected person receives a number.

This is not a Chinese peculiarity. Run the same test on the European Union. The AI Act’s high-risk regime is, in the relevant sense, a gate: pre-market, record-based — technical documentation, conformity assessment — with a terminal outcome and a public marker. To whom is that documentation legible? To notified bodies and to market-surveillance authorities. Whatever individual-facing rights the Act contains sit elsewhere in the instrument, and the high-risk obligations that would carry them stand deferred to December 2027. A CE mark, like a filing number, explains nothing and is owed to no one. Admission is silent there too.

Two gates. Two political systems with nothing in common. The same asymmetry, because it is a property of gates and not of regimes. Absent a deliberate design decision to the contrary, a gate answers upward — to the authority that operates it and the industry that petitions it — and not downward, to the people on whose behalf it was ostensibly built.

Where our own rule is silent

Now turn it on ourselves, which is the only reason this paper is worth writing.

No record, no standing. Read it again. It says that a capability with no reconstructable record has no standing to enter a consequential decision. It is a rule about the system’s standing. It says nothing whatsoever about the person’s.

We have written as if the two were the same rule — as if requiring a record on the way in would, by some unstated mechanism, make that record available to the person on the way out. Nothing in the method delivers that. Our four terminal outcomes specify what the gatekeeper decides, not to whom the decision is explained. Our reversibility requirement specifies that standing may be withdrawn, not who may ask that it be. Our foundational paper says admissibility is the decision that comes before safety. It does not say who makes it, to whom they answer, or who may compel them to look again.

China supplies each of those answers, coherently. The administration decides. It answers to the state. Nobody may compel it. The record is filed, not published; the number is published, not the record.

The Institute has spent four years arguing for a mechanism and treating its direction as self-evident. It is not self-evident. It is the whole of the matter. A method that specifies the architecture of a gate while leaving its beneficiary unstated is not a protective method. It is a template — and it will be filled in by whoever holds the pen.

What a citizen-facing gate would require

If the direction must be designed rather than assumed, it must be designed explicitly. Four conditions, and none of them concerns the architecture we have been arguing about.

1. Reasons for admission, not only for refusal. The asymmetry above is the load-bearing defect. A gate must state, publicly, on what basis a system was admitted, and to what limits — not merely that it was. A silent yes is an unaccountable yes, however rigorous the process behind it.

2. The record legible to the affected class. Not the weights, not the source, not the formula — the CJEU in SCHUFA confirmed that a scoring agency need not disclose its mathematical weighting. What is required is that the record admitted through the gate be sufficient for an independent party, acting for an affected person, to reconstruct a specific decision. A filing that describes an algorithm in terms an outsider could have guessed satisfies a gate and defeats a person.

3. Triggerable from below. Admission once granted is permanent in fact unless someone outside the operator and the gatekeeper can compel re-examination. Reversibility that only the gatekeeper may exercise is not reversibility; it is discretion. A person subject to a system’s decisions must be able to put that system’s standing back in question.

4. A gatekeeper independent of both operator and state. A gate is a concentration of power sufficient to refuse a frontier capability. That is exactly the power worth capturing. Where the gatekeeper is the state, the gate is an instrument of the state; where it is the industry, an instrument of the industry. This condition is the hardest, and we do not know how to satisfy it.

Notice that all four concern direction, and none concerns whether the gate is pre-runtime, record-based, or reversible. We had the architecture right and the politics unspecified.

The honest tension

Each condition has a price, and one of them may be unpayable.

Reasons for admission invite gaming: a published account of why a system was admitted is a specification of what an applicant must appear to be. Legibility to the affected class collides with trade secrets and with security, and SCHUFA shows a sympathetic court declining to breach the first. A gate triggerable from below can become a veto exercised by whoever is best organised, and a state facing continuous re-examination of every admitted system will stop admitting or stop examining. And condition four may be impossible: a body strong enough to refuse a frontier capability, independent of both the state that wants it and the firm that built it, does not obviously exist and may not be constructible.

There is also a harder point that we would rather not concede. A gate whose beneficiary is the state is not a corrupted gate. It is a functioning gate with a different beneficiary. There is no neutral gate whose politics can be read off its engineering. Every argument for admissibility — including every argument we have made — is an argument for constituting an authority, and the question of whose authority cannot be deferred to implementation. We deferred it.

What this paper does not settle

Four things, and the last is the worst.

First, whether a democratic state can build a pre-runtime gate that handles genuinely classified evidence without becoming a domain of sealed sovereignty. Our own Fable/Mythos commentary posed this and did not answer it; this paper does not either, and it is now the central unanswered question of the method.

Second, whether a gate triggerable from below is workable at scale, or collapses into either veto or theatre.

Third, our reading of what the Chinese registry actually contains rests on external published analysis, in translation, of the public portion of the filings. The non-public portion may be substantially more demanding. We do not know, and an institute that insists on evidence should say so rather than build on the convenient reading. Our structural argument does not depend on it — the asymmetry of reasons holds whether the filings are thin or thick, and it holds in Brussels too — but our characterisation of the record does.

Fourth: we did not find this hole. It was there in the first paper, and it took a working implementation in a jurisdiction we had ignored to make it visible. That is not a methodological triumph. It is what happens when a research programme examines only the cases that flatter it.

FAQ

Is this paper a criticism of China’s AI regulation?
No. It is an analysis of what gates do. China’s registry is the only working national implementation of the pre-deployment, record-based gate this Institute has advocated. The finding is structural and applies equally to the European Union’s conformity regime: gates owe reasons for refusal to applicants and reasons for admission to no one, so they answer upward unless deliberately designed otherwise.

Does this mean the Institute no longer supports admissibility gates?
It means a gate is not protective in itself. Admissibility is constitutive: it creates an accountability relation and does not determine its direction. Every admissibility proposal must state to whom the gatekeeper answers, who may compel re-examination, and to whom the record is legible. Ours did not.

What does “no record, no standing” actually establish?
That a system without a reconstructable record has no standing to enter a consequential decision. It is a rule about the system. It has never been a rule about the person, and we have written as though it were. Nothing in it gives an affected person access to the record, or a route to contest what the record shows.

What is the single most important design fix?
Reasons for admission. A gate that explains its refusals to industry and its approvals to nobody has already chosen whom it serves, whatever its architecture.


Synthocracy Institute — Power & Accountability When AI Co-Decides