Volume I — Core Architecture · The People's Model — Manifesto v2026

Chapter 6 — Ethics, Oversight, Digital Rights, and Citizen-controlled Data: AI that Serves People

This chapter owns the principles and the institutions that govern the digital state — the Citizen Data Trust, the AI-Use Register, the Grievance Justice…

Read this chapter in the interactive reader, or download the full 601-page manifesto (PDF).


The People’s Model

Manifesto v2026

Volume I — Core Architecture

Chapter 6

Ethics, Oversight, Digital Rights, and Citizen-controlled Data: AI that Serves People

Where this chapter sits

This chapter owns the principles and the institutions that govern the digital state — the Citizen Data Trust, the AI-Use Register, the Grievance Justice Authority, the Citizen Consent Ledger, the Civil-society Independent Audit Board, and the Karnataka Cyber Security Operations Centre — together with the operating rule that binds every system the state runs or contracts. Service-design narrative and operational detail live elsewhere.

6.1 Problem Snapshot

Digital government without ethics becomes surveillance. AI without oversight becomes discrimination. Automation without appeal becomes injustice. India already has visible examples of digital exclusion: residents without documents, without connectivity, or without the right format of identity get punished for system gaps that are not their fault. A welfare benefit denied by an unexplainable algorithm is still a denial. A bank-account change executed without notice is still a theft of subsistence.

Karnataka cannot build a high-trust state by trading dignity for efficiency. The People’s Model commits to the opposite: every digital and AI-enabled system in government has to pass the same four tests before it is allowed to make a decision about a resident — and the resident has to have a fast, no-cost route to challenge the decision when it goes wrong.

Power without accountability becomes tyranny — whether it is held by a person or by a system.

6.2 People’s Model Blueprint

Chapter 6 commits to six statutory institutions, one operating rule that binds every government AI and decision system, two supporting rules on how state software is built, and three citizen-data rights that hold across them all. The institutions are statutory — established by Act and independent of the executive whose systems they govern. The rule is binding on every system the state runs, contracts, or procures.

The operating rule — four tests for every AI / decision system

A system that cannot pass all four tests is not deployed. A system that loses any of the four is paused until it can pass again. The tests apply to first-party government systems, to contracted systems, and to vendor-supplied systems alike — the state cannot outsource its accountability to a procurement contract.

Institution 1 — Citizen Data Trust

A statutory body that holds the governance authority over how the operating spine collects, uses, shares, and disposes of resident data. The Trust publishes the consent framework, certifies the integrity of dashboard data on the spine, names the independent auditors, sets the breach-disclosure rules, and adjudicates complaints about data misuse. The Trust’s council is independent of the executive — its composition is statutory, its budget is direct, and its findings are published.

Institution 2 — AI-Use Register

A public, machine-readable register of every AI-enabled system operated by the Karnataka state — direct or contracted. Each entry carries the system’s purpose, owning department, named accountable official, training-data scope, evaluation metrics disaggregated by district, caste, gender, language, and age, known limitations, the latest fairness-test result, the annual independent algorithmic audit summary, and the appeal pathway. New systems are added before deployment; material changes are added before rollout. Citizens have a Right-to-Contest: any AI-driven decision affecting a citizen can be challenged through a published mechanism, with human review within a published SLA. The Register is the operating implementation of the four tests above.

Sectoral AI is registered on the same terms. The Karnataka Health Records Authority (KHRA) — see Vol II Ch 8 Sec. 8.8 Universal Medical Record System — registers its two AI uses on this Register: (1) population analytics, default-on, de-identified aggregate analysis to fine-tune preventive-care programmes; (2) individual risk scoring, opt-in via JANATA, identified-record analysis with derived score storage. Both carry full model description, training-data scope, performance metrics, and annual independent algorithmic audit. Other sector AI — KFDA forecast models, AI traffic management, AI live monitoring of CCTV, content-moderation AI — registers on the same terms; no state AI operates without a Register entry.

Institution 3 — Grievance Justice Authority

A statutory authority with binding adjudicatory power over grievances that escalate beyond the operating spine’s own engine (Vol I Ch 2 — Grievance & Ombuds engine). The Authority hears appeals against adverse decisions — welfare denial, contract dispute, service refusal, data misuse — and issues binding remedies. Its case management runs on the operating spine, with full publication of decisions and remedies (without exposing individual personal data). Members are appointed through a transparent shortlist process; budget is statutory and ring-fenced from executive interference.

Institution 4 — Citizen Consent Ledger

Every data flow through KSSL (Vol I Ch 2) that touches a citizen’s record requires a consent token issued by the citizen. The Citizen Consent Ledger is the citizen’s view of every token issued, every access made, and the right to revoke any token in real time. Citizens see on JANATA: which party (sector authority, treating officer, empanelled firm, civil-society auditor) accessed which class of their data, when, why, for how long, and under which consent token. Revoke any token; any subsequent attempted access fails closed. Emergency overrides (break-glass for medical emergencies, active investigations under judicial authorisation) bypass consent at the moment of access but trigger immediate citizen notification, twenty-four-hour formal notice, and quarterly review-panel audit. Every data class carries a published retention schedule; citizens hold a statutory deletion right for personal records not under legal hold, and deletion events are themselves logged and verifiable. From a Year-3 pilot onward, the Ledger targets zero-knowledge eligibility proofs — a citizen proves entitlement to a scheme without revealing the underlying records to the requesting department. The Citizen Consent Ledger is a statutory right, established by the Karnataka Cyber Security & Citizen Consent Act (Vol III App I).

Institution 5 — Civil-society Independent Audit Board

New statutory body with civilian + technical + retired-judiciary members. Statutory budget protected from executive interference. Power to compel disclosure of system documentation, source code, audit logs, and access records for audit purposes (with privacy-preservation rules for personal data). Annual public report. The Board oversees CSOC (Institution 6 below), names the independent auditors for state AI systems on the Register, and can refer findings to the Grievance Justice Authority, the Lokayukta, or the courts. Members serve fixed terms; selection through a transparent shortlist process with public input.

Institution 6 — Karnataka Cyber Security Operations Centre (CSOC)

Statutory body, twenty-four / seven monitoring across state systems. Holds compel-patching authority — the power to require a department to apply a published patch, to mandate a vendor change, or to isolate a non-compliant system pending remediation. Runs the bug-bounty programme, the annual external red-team exercise, and the cryptographic-incident response protocol. Reports to the Civil-society Independent Audit Board (Institution 5 above), not to the executive whose systems it audits; funding ring-fenced from departmental control. The operational details of CSOC’s programme live in Vol II Ch 15 (Cybersecurity baseline) and App H sheet H.231.

The supporting rules — how state software is built

Open-source mandate for state software. Every state-built or state-procured citizen-facing software system is open-source. Source code is published in a public repository; builds are reproducible; official releases are signed with hardware-attested keys. Civil-society organisations can audit the code, run their own builds, and run their own verifier nodes. This is the difference between trust-the-state and verify-the-state. The mandate covers the four front doors, the operating-spine systems, the AI systems registered above, and KSSL itself.

Threshold cryptography for sensitive operations. Sensitive state operations require multi-party authorisation — no single officer can authorise alone. This includes bulk data exports beyond a published threshold, AI model retraining or redeployment, contract awards above a published value threshold, CCTV footage release beyond the Right-to-Self-Footage (Sec. 6.7.1), KFDA forecast model updates, and KSSL governance changes. The number of required signers is published per category; signing keys are held in Hardware Security Modules under independent custody.

The accompanying rights — three citizen-data rights

Three citizen-data rights complete the frame. (1) The receipt right — every state transaction returns a signed, independently verifiable receipt proving the transaction is recorded and untampered (anchored through KSSL, Vol I Ch 2). (2) The deletion right — citizens may have personal records deleted where no legal hold applies, with the deletion itself logged and verifiable through the Consent Ledger. (3) The Right-to-Contest — any AI-driven decision affecting a citizen can be challenged through the AI-Use Register’s published appeal mechanism, with human review within a published SLA. These three rights operate across all six institutions above.

Six institutions, one operating rule, two supporting rules, three citizen-data rights, one outcome: a digital state that residents have meaningful rights against.

6.3 How it Works (Operational Flow)

System rules — for every government AI / decision system

Resident protections

Officer protections

Mandatory algorithmic impact assessment

Before any new AI-enabled system goes into production, an impact assessment is filed against the Register: intended use, classes of residents affected, predicted error rates by group, deployment safeguards, exit criteria if performance degrades. The Citizen Data Trust reviews and signs off; deployment without a signed assessment is itself an actionable offence under the Trust’s code.

6.4 Finance & Accountability

Ethical AI and rights infrastructure save money by preventing avoidable harm and avoidable litigation.

Fiscal logic

Budget items

6.5 KPIs & Public Dashboards

The operational dashboards that measure cybersecurity, DPI delivery, and citizen-tech performance live in Vol II Chapter 15 — they are the “how” to this chapter’s “what”.

Six headline rights-coverage KPIs for the six institutions and the operating rule, each measurable from the AI-Use Register, the Citizen Consent Ledger, the Audit Board’s annual reports, and the operating spine itself. Each KPI’s definition, unit, source dataset, and audit frequency is published in Vol III Appendix A (Sector KPI Dictionary).

6.6 Implementation Roadmap

Foundations — 0 to 100 days

Foundations — Year 1

Build-out — Years 2 to 5

Consolidation — Years 5 to 10

6.7 Anti-capture Safeguards

The eight Chapter 1 safeguards apply. Three additional rights-specific safeguards apply, and silent automation is forbidden by design.

6.7.1 AI live monitoring and electronic-evidence custody-transfer

The 100% CCTV Coverage commitment (Vol II Ch 9 Sec. 9.6.8) introduces large-scale state-operated camera infrastructure. The civil-liberties rails around it are committed in this chapter — Vol I Ch 6 is the canonical source for AI-Use Register, Citizen Data Trust governance, and consent rules. Two specific commitments in the CCTV programme sit on top of this chapter’s framework.

AI live monitoring — incident-detection only, never identification or tracking

AI systems that watch live CCTV feeds and raise tickets when they detect incidents (accidents, fights, falls, fire) are governed by this chapter’s AI-Use Register. Permitted AI categories are a closed published list. New categories require approval from the Citizen Data Trust ombudsperson plus the statutory CCTV Authority. Facial recognition is explicitly banned for ordinary CCTV operations (the three narrow exceptions named in Vol II Ch 9 Sec. 9.6.8 require magistrate authorisation and are individually logged on the AI-Use Register). Person-tracking, predictive policing, and behavioural profiling are banned under any framing.

Electronic-evidence custody-transfer vault

The moment a court formally accepts a piece of digital evidence (CCTV footage, body-camera footage, electronic communication record), custody transfers from the producing agency to the Justice Department-maintained Electronic Evidence Vault (Vol II Ch 12). This is a structural protection against tampering — the agency that produced the footage (police, CCTV operator) does not retain the original once it becomes evidence. Chain of custody is documented in the court order, the vault intake log, and the KSSL-anchored custody record.

Citizen Data Trust ombudsperson — joint jurisdiction

The Citizen Data Trust ombudsperson has joint complaint jurisdiction with the statutory CCTV Authority over any breach in CCTV operations — privacy breach, unauthorised access, retention beyond rule, AI-Use Register violation. A citizen has one address to complain to; jurisdiction is allocated between the two bodies on receipt.

6.8 Citations & Further Reading

Full bibliography for this chapter and the wider manifesto is in Vol III Appendix G (Research References).

Cross-references inside this manifesto


← Chapter 5 — From Contractor Raj to State Capacity: Government Works & Manufacturing Ecosystem · Chapter 7 — Learning State Without Barriers →

This is a chapter of The People's Model manifesto for Karnataka — published in full for public review. Every claim may be challenged: write to [email protected].