← Latest papers
💻 computer science

From Democracies to Autocracies: How AI Systems Enable Authoritarianism by Design

This paper argues that AI-enabled authoritarianism is not exclusive to autocratic regimes but is a distributed phenomenon arising from specific design and operational choices—such as data centralization, regulatory gaps, and weak oversight—that allow AI systems to facilitate political punishment and erode accountability across both democratic and authoritarian political contexts.

Original authors: Jeba Sania, Marta Ziosi, Fazl Barez

Published 2026-06-17
📖 7 min read🧠 Deep dive

Original authors: Jeba Sania, Marta Ziosi, Fazl Barez

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine you have a toolbox. Inside, there are power tools like drills and saws. Usually, we think of these tools as neutral; a drill can build a house or break down a door, depending on who holds it and how they use it.

This paper argues that with Artificial Intelligence (AI), the "drill" itself is being built with a specific design that makes it much easier to break down doors and harder to stop, regardless of who is holding it. The authors, researchers from Harvard and Oxford, looked at six different AI systems used in countries ranging from the United States and the UK to China and Russia. They wanted to see if these tools were only dangerous in "bad" countries (autocracies) or if they could turn a "good" country (democracy) into a place where people are watched and controlled, too.

Here is the breakdown of their findings using simple analogies:

1. The Core Discovery: It's Not Just About the "Bad Guys"

The biggest surprise in the paper is that authoritarianism (the practice of controlling people through fear and surveillance) isn't just a feature of "evil" dictatorships.

Think of it like a speeding car. You might think only a reckless driver in a dangerous neighborhood speeds. But this paper shows that even a careful driver in a safe, wealthy suburb can end up speeding if the car's cruise control is set too high, the brakes are weak, and the speed limit signs are ignored. The design of the car (the AI system) matters just as much as the driver (the government).

The authors found that the same "dangerous features" appear in both democracies (like the US and UK) and autocracies (like China and Russia).

2. The Six "Danger Zones" (How AI Enables Control)

The researchers identified six ways these AI systems act like a "control toolkit." Here is how they work, with analogies:

  • Coercive Capacity (The Big Stick):
    • What it is: The ability to use force or the threat of force easily.
    • The Analogy: Imagine a security guard who can call a SWAT team with a single button press. In the case of the Lavender system (used by the Israeli military), the AI helps identify targets for airstrikes. Because the system is integrated with weapons and has a high error margin, it lowers the "threshold" for using lethal force. It makes violence easier to trigger.
  • Accountability Erosion (The Invisible Hand):
    • What it is: Making it hard to know who is responsible when things go wrong.
    • The Analogy: Imagine a game of "Hot Potato" where the potato is a mistake. If a police officer in the UK uses a Live Facial Recognition Van and wrongly stops someone, the officer can say, "The computer told me to," and the company can say, "We just sold the software." No one takes the blame. The system is designed so that responsibility gets lost in the shuffle.
  • Symbolic Safeguards (The Fake Seatbelt):
    • What it is: Having rules that look good on paper but don't actually work.
    • The Analogy: It's like a car that has a seatbelt, but the buckle is broken. The Lavender system has a rule that a human must check the target before an attack. But reports show humans spend only 20 seconds checking, just enough to tick a box. The "safeguard" exists, but it's a sham.
  • Information Control (The One-Way Mirror):
    • What it is: The government knowing everything about you, while you know nothing about them.
    • The Analogy: Imagine a giant library where the librarian can read every book you've ever checked out, every note you've written, and every time you visited the bathroom, but you can't see what the librarian is writing in their log. The IJOP system in China does this by combining police data with medical records, utility bills, and even second-hand car sales data to build a total picture of a person's life.
  • Anticipatory Repression (The Crystal Ball):
    • What it is: Punishing people before they do anything wrong, just because the AI thinks they might.
    • The Analogy: Imagine a bouncer at a club who kicks you out because you look "suspicious" or because you changed your phone number recently, even though you haven't broken any rules yet. The Sfera system in Russia uses facial recognition to arrest people before they even plan a protest, based on the idea that they might protest.
  • Boundary Control (The "Us vs. Them" Wall):
    • What it is: Creating digital categories that treat certain groups of people as less human or less safe.
    • The Analogy: Imagine a filter on a photo app that automatically blurs out people with a specific accent or skin tone, labeling them as "risky." The IJOP system specifically targets Uyghur Muslims, and the SlimmeCheck system in the Netherlands was found to flag non-Dutch citizens for welfare fraud much more often than locals. The AI learns to see certain groups as "the enemy."

3. The Two Ways the System Breaks: Centralized vs. Fragmented

The paper makes a very important point about how these systems are organized.

  • Centralized Systems (The Big Boss):
    • Example: The IJOP in China or Sfera in Russia.
    • How it works: One big authority controls everything.
    • The Risk: It's like a single, massive dam. If the dam breaks, the whole valley floods. Because one group holds all the power, there are fewer people to say "Stop."
  • Fragmented Systems (The Swarm):
    • Example: FlockSafety in the US.
    • How it works: This is a network of license plate cameras owned by thousands of different neighborhoods, businesses, and police departments.
    • The Risk: This is like a swarm of bees. You can't just kill one bee to stop the swarm. Because the system is spread out, no single person is in charge. If a neighborhood association abuses the camera, it's hard to regulate because there is no central "boss" to fire. The paper argues this "swarm" is actually harder to control than the "Big Boss" because the responsibility is so diluted.

4. The "Lifecycle" Problem

The authors say we usually look at AI and ask, "Is the math smart enough?" (The Model). They say we should be asking, "How was this tool built, sold, and used?" (The Lifecycle).

They compared the systems across 10 stages, from the initial idea to the current day. They found that the danger isn't just in the final product; it's in the choices made along the way:

  • Who bought it? (Often private companies partnering with governments).
  • How was it tested? (Often poorly or not at all).
  • Who is watching the watchers? (Often no one).

5. The Takeaway

The paper concludes that AI-enabled authoritarianism is a design choice, not an inevitable result of technology.

It's not that the AI is "evil" by nature. It's that developers, governments, and users have made choices to:

  1. Connect the AI to too much data.
  2. Ignore the rules that are supposed to protect people.
  3. Build systems that are hard to stop once they start.

The authors warn that this isn't just a problem for "bad" countries. Democracies are at risk too, especially when they use these tools for "efficiency" or "safety" without realizing they are slowly building a cage. They urge developers to build "brakes" into the system and for governments to make sure the "seatbelts" actually work before letting the car drive.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →