Central finding

Instrument novelty is less important than whether the institutional chain completes.

This paper develops Protection Reach: the operational capacity of a governance arrangement to place an affected person or representative inside an actionable pathway - from notice and legal coverage, to usable evidence, to authoritative review, to timely remedy. It is the distance between visible AI-governance commitment and lived protection.

The diagnostic assesses six dimensions - visibility; legal and institutional coverage; evidence accessibility; contestability; institutional authority and independence; and remedy effectiveness - treating participation timing and responsibility allocation as cross-cutting conditions. The dimensions are partly sequential: a missing record, an inaccessible forum, or a delayed remedy can nullify strength built elsewhere in the chain.

Six comparative cases

A structured comparison applies the diagnostic to six algorithmic or automated-decision cases, with a seventh bounded institutional analogue:

Australia — Robodebt Netherlands — SyRI Kenya — NIIMS / Huduma Namba India — Aadhaar Spain — Platform-work regime Canada — Automated decisions South Africa — Black Sash (analogue)

The cases show that collective representation is conditional on evidence and authority, that digital exclusion can be both the harm and a barrier to remedy, and that imported or distributed systems create cross-border evidence problems.

Six executive findings

No.
Proposition
Implication
1
Institutional inheritance can outperform instrument novelty.
Constitutional, administrative and labour institutions may protect people better than dedicated AI instruments when they already connect standing, evidence, authority and remedy.
2
Framework presence is an unreliable proxy for protection.
The real test is whether an affected person can activate a pathway from notice to timely remedy - not whether a policy document exists.
3
Protection Reach is a chain with bottlenecks.
Visibility without evidence, appeal without suspensive effect, or oversight without corrective authority can each make a formally complete regime operationally weak.
4
Collective contestability is conditional, not self-executing.
SyRI shows representation linked to evidence and an authoritative court works; Kenya, Aadhaar and Spain show mobilisation alone can leave proof and remedy incomplete.
5
Public-sector systems create accountability and exclusion asymmetries.
The state may demand identity, data and proof from people while withholding system records; authentication failures can exclude a person before any appealable decision is even recorded.
6
Timeliness is constitutive of remedy.
A review that succeeds after benefits are lost, work is terminated, or an identity system becomes entrenched may produce legal correction without full lived protection.

Policy architecture

The paper concludes with an institutional implementation package: dual notice, exception logging, evidence preservation and export, proportionate suspensive review, representative standing, independent authority, regional cooperation, and sustained funding for public-interest intermediaries.

Why this matters for telecom governance

This research paper complements the four ITS Issues Papers on telecom AI governance. Where the Issues Papers ask whether an operator controls the data, authority, compliance evidence and inventory behind its AI systems, From Promise to Protection asks the question from the other side of the chain: when an AI-influenced decision harms a person, can that person actually reach notice, evidence, review and remedy - or does the chain break first?

Download full paper Discuss this research

Citation: Arora, G. (2026). From Promise to Protection: The Institutional Reach of AI Governance - Oversight, Contestability and Redress for People Affected by AI Systems. Institute for Technology Stewardship, Research Paper No. 2, Version 1.5.
© 2026 Institute for Technology Stewardship. Licensed under CC BY-NC 4.0.