Chapter 18 of the 8 HARPS book, available on Amazon

The Artificial Intelligence Amendment

The Artificial Intelligence Amendment

I. The Governance Vacuum

Every prior constitutional amendment in this volume responds to a concentration of power that already existed when it was drafted. In government, in markets, in the drawing of a map. Artificial intelligence is different in one important respect: the concentration of power it enables is still accelerating, and the institutions meant to govern it are, by design, temporary. An executive order can be rescinded by the next administration in a single stroke. A state statute can be preempted by the next Congress, or by an Attorney General’s litigation task force organized for exactly that purpose. Only a constitutional floor survives a change of administration, and artificial intelligence, more than any technology this country has regulated before, is being built and deployed at a pace that outruns the amendment cycle of ordinary politics.

The federal government’s actual record on AI governance illustrates the problem rather than solving it. Congress has enacted exactly one AI-specific statute, the TAKE IT DOWN Act, addressing non-consensual intimate imagery. And has twice rejected proposals for a broader federal moratorium on state AI regulation, without ever replacing that patchwork with a comprehensive law of its own. In its place, the executive branch has issued a rotating sequence of policy documents: a January 2025 order removing regulatory barriers to AI development, a July 2025 “AI Action Plan,” a December 2025 “AI National Policy Framework,” a March 2026 “National AI Legislative Framework,” and, in June 2026, an executive order establishing an AI cybersecurity clearinghouse and directing the Attorney General to challenge state AI laws as unconstitutional interference with interstate commerce. Each of these instruments can be, and most likely will be, superseded by the next administration’s own sequence of orders. None of them binds a court. None of them survives a change in the White House. A private company deciding how to build and deploy a frontier model is, at the federal level, navigating guidance rather than law.

II. A Lesson From Europe

The European Union’s experience cuts the other way but proves the same point from a different angle. The EU AI Act entered into force in August 2024 promising a comprehensive, binding, risk-tiered regime for exactly the systems this proposed Article addresses. By May and June 2026, under pressure from industry and member states, the Council and Parliament had agreed to a “Digital Omnibus” that pushed the compliance deadlines for most high-risk AI obligations back by sixteen months, to December 2027, with product-embedded systems deferred even further, to August 2028. A binding statute, even a carefully drafted one, is a target that shifting political coalitions can and will renegotiate. A constitutional floor, by contrast, is not renegotiated by the next legislative session, which is precisely why the rights this volume proposes for citizens generally are placed in the Constitution and not left to statute, and precisely why the same logic applies to the systems now making or materially informing decisions about those citizens’ employment, credit, housing, and liberty.

III. What Changed: The Black Box Opens

There is also a narrower, more technical reason this Article is necessary now rather than five years ago: for most of the history of neural networks, meaningful oversight of what was actually happening inside one was not technically possible. A large model was, for practical and regulatory purposes, a black box. You could observe its inputs and outputs, but not the internal computation connecting them. That has changed. Mechanistic interpretability, the discipline of identifying the internal representations and decision pathways inside a trained neural network was named one of MIT Technology Review’s ten breakthrough technologies of 2026. Anthropic’s interpretability research has progressed from identifying features corresponding to individual recognizable concepts inside a model to tracing complete computational paths from a prompt to a response. And the company has begun using these tools as part of the pre-deployment safety assessment of its own frontier models. The first documented instance of interpretability research being used to inform an actual deployment decision for a production AI system, rather than remaining a research curiosity. Google DeepMind has released comparable open-source tooling covering an entire family of models. A regulatory mandate to monitor the internal behavior of a covered AI system was aspirational in 2020. It is achievable, though not yet trivial, in 2026, which is exactly the condition under which a legal obligation to do it becomes reasonable to impose.

IV. Why Watching Outputs Is Not Enough

The same 2025 to 2026 research also supplies the clearest evidence of why monitoring outputs alone is not enough. Interpretability researchers have documented that advanced reasoning models can produce a chain of stated reasoning that does not match the actual computation the model used to reach its answer. A model’s explanation of itself can be unfaithful to what it is actually doing, whether by omission or by something closer to concealment. A regulatory regime that reviews only a system’s outputs, or only the explanation a system offers for those outputs, is reviewing what the system has chosen to show. A regime capable of examining the system’s internal state is reviewing what the system is actually doing. The distinction is not academic: it is the difference between a company’s compliance filing and an audit.

V. A Concern That Touches Every HARP

None of this is unique to any single right; artificial intelligence now touches nearly every dimension of economic and civil life. It can determine who is approved for a loan or a lease, affecting equal access to opportunity. It can be used by a dominant platform to model and undercut the businesses that depend on it, affecting the ability of ordinary market participants to compete on fair terms. It can be trained on, and can generate conclusions about, information a citizen never consented to share, affecting a citizen’s basic security of person. What a constitutional amendment can do that a sector-specific statute cannot is state, once, which rights govern all of these uses at once rather than legislating a separate answer for lending, a separate answer for hiring, and a separate answer for policing, each vulnerable to being weakened in isolation.

VI. A Floor Drawn From a Text That Already Exists

That is the reason this Article’s human-rights floor is drawn from, rather than invented apart from, the Universal Declaration of Human Rights. The Declaration, adopted by the United Nations General Assembly in 1948, is the closest thing the world has to an agreed moral floor beneath any government’s laws. But a full, open-ended incorporation of all thirty articles of the Declaration as directly enforceable law against every covered AI system would import ambiguity this Article cannot afford: some of what the Declaration proclaims is properly understood as aspirational, not judicially administrable, and a court asked to enforce “the right to rest and leisure” or “a standard of living adequate for health and well-being” against an algorithm has been handed a mandate the text was never drafted to bear as binding law.

Section 2 resolves that tension the same way this book resolves it everywhere else: by turning a broad principle into an enforceable rule. It lists the specific rights that a covered AI system may not be used to violate: non-discrimination, human dignity, privacy, security of person, and existing employment protections. Each of these rights is drawn directly from, and must be read consistently with, the matching article of the Declaration: non-discrimination from Articles 2 and 7, dignity from Article 1, privacy from Article 12, the right to life, liberty, and security from Article 3, and just conditions of work from Article 23.

The Declaration remains the anchor and the guide for interpreting these rights. What changes is that a court applying this Article now works from a finite, workable list of rights, rather than having to decide on its own which of thirty articles a machine learning system may have violated.

Section 2 also states explicitly what was previously left to inference: this Article governs the design, training, deployment, and operation of a covered AI system and its use to make or inform a decision about a person. It does not regulate what a covered AI system generates, publishes, or helps a person say, and it does not judge a system’s output by its viewpoint or content. Artificial intelligence does not need a bespoke bill of rights, and this Article does not police what an AI system, or the person using it, chooses to express. It needs to be held, explicitly and by name, to the same non-discrimination, dignity, privacy, and due-process floor this country has spent two hundred fifty years learning to demand of every other kind of consequential power when that power is used to decide something about a person, not when it is used to say something.

This Article also closes a narrower but increasingly urgent gap: the difference between a communication a person has agreed to receive, or already has a relationship with the sender, and one an automated system generates and sends to a stranger on its own initiative. Section 6 permits a covered AI system to initiate a call, text, or email to a specific person only where that person has consented to receive it, has an existing relationship with the sender, or the communication falls within a narrow set of recognized categories: a government emergency alert, a response to a request the person made, or a genuinely non-commercial political, religious, charitable, or public-interest message. Every AI-generated or AI-assisted communication permitted under that framework must say so, and must give the recipient a working way to opt out. And regardless of consent or relationship, no system may impersonate a real person's voice or likeness without that person's consent, full stop.

A violation, including the non-consensual use of a synthesized voice or likeness to impersonate a real person, carries statutory damages of not less than five hundred dollars per violation, giving the individual harmed a remedy that does not depend on proving the kind of measurable financial loss this type of intrusion rarely produces. Impersonation carries that remedy without regard to consent or relationship; nothing excuses it.

“A system that cannot be inspected cannot be held accountable, and a right that no institution is bound to enforce is not a right. This Article is written to close both gaps at once.”

VII. Objections Considered

A serious objection deserves to be answered directly: does binding artificial intelligence to a human rights floor, and requiring interpretability monitoring before and during deployment, risk driving frontier AI development out of the United States and into jurisdictions with no such requirement? The honest answer is that some marginal effect of that kind is possible, and this Article does not pretend otherwise. But the same objection was raised, and proved substantially overstated, against securities disclosure requirements, against automobile safety standards, and against comparable data-privacy protections. A firm capable of building a frontier model is a firm capable of building the monitoring infrastructure this Article requires; the interpretability tools described above already exist inside the frontier labs most capable of the systems this Article is most concerned with. What this Article forecloses is not advanced capability. It forecloses advanced capability deployed without anyone, including the company that built it, being able to say with confidence what the system is actually doing and whether that use is consistent with the rights of the people subject to it.

A related objection is that anchoring these rights to the Universal Declaration risks importing an external, evolving body of international law into the United States Constitution, effectively letting a foreign tribunal or a later international agreement reshape a domestic constitutional right over time. Section 2(b) forecloses that risk by design. It anchors only to the fixed text of the Declaration as adopted on December 10, 1948, and it says so expressly: no subsequent international agreement, foreign tribunal decision, or evolving international norm may be given interpretive weight under this Article. The Declaration functions here the way a law dictionary functions: fixed at a moment in time, consulted for the meaning of a term, not a living treaty whose content drifts with the practice of other nations.

The second objection is that regulating artificial intelligence risks becoming, in practice, regulating speech. This is a real concern. State AI statutes are currently being challenged on First Amendment grounds, and the Supreme Court recognized in Moody v. NetChoice, 603 U.S. 707 (2024), that curating and presenting expressive content is itself an expressive act entitled to real constitutional scrutiny.

Section 2(c) answers this directly, rather than leaving it to inference. This Article regulates the decisional use of a covered AI system: its role in deciding whether a person gets a loan, a job, or a parole date. It does not regulate the content that system or its user generates, publishes, or expresses. A chatbot's output remains speech, governed by the law that already governs speech.

What loses constitutional protection under this Article is not an AI system's expression. It is the use of that system as an unaccountable decision-maker over a person's employment, credit, housing, or liberty.

A related concern is Section 6 specifically: does a rule governing who may initiate an automated call, text, or email risk becoming an unconstitutional restriction on speech in its own right, particularly for political campaigns, nonprofits, religious organizations, and the press that rely on automated outreach at scale? Section 6 instead follows the model Congress itself has used since 1991 in the Telephone Consumer Protection Act, and that courts have repeatedly upheld: automated contact with a stranger requires consent or an existing relationship, every AI-generated message must say so, and the recipient always gets a working way to say stop. A campaign, a congregation, or a newsroom that already has a relationship with the people it contacts, or that obtains consent before reaching new ones, loses nothing. What the Section forecloses is unsolicited automated contact with someone who has never agreed to hear from the sender at all, dressed up to look human when it is not, which is precisely the kind of unwanted, deceptive intrusion the TCPA framework was built to stop without banning any viewpoint or any speaker.

The third objection concerns Section 7’s funding mechanism: does guaranteeing the Commission a funding floor, self-executing if Congress fails to appropriate, improperly bypass Congress’s appropriations power? The Supreme Court answered a closely related question in CFPB v. Community Financial Services Association, 601 U.S. 416 (2024), upholding a federal financial regulator’s standing, non-annual funding mechanism precisely because Congress had authorized it in advance, in specific and bounded terms, rather than ceding open-ended control over its own purse. Section 7(c) is built the same way: a specific, bounded floor, established directly by this Article rather than left to ordinary appropriations politics, that Congress remains free to exceed by law at any time. It protects the Commission from being defunded into irrelevance by a hostile Congress; it does not, and cannot, prevent Congress from funding it more generously.

A closely related structural question is whether the Commission's members are properly insulated from at-will presidential removal, and if so, whether that insulation is itself constitutional. This Article answers both parts directly: a Commissioner may be removed before the end of a term only for material neglect of duty or material abuse of authority, established by clear and convincing evidence, not at the President's discretion. That structure is not the single-director, removal-protected agency the Supreme Court held unconstitutional in Seila Law v. CFPB, 591 U.S. 197 (2020); it is the multi-member, politically balanced commission model the Court has upheld since Humphrey's Executor v. United States, 295 U.S. 602 (1935), and left undisturbed in Seila Law itself. The Commission also does not impose penalties on its own authority. It sets technical standards, investigates, and refers; a penalty under Section 9 is imposed only by an Article III court, consistent with the jury-trial requirement the Supreme Court applied to comparable civil penalties in SEC v. Jarkesy, 603 U.S. 109 (2024).

The fourth objection is that a private right of action against any deploying entity, without more, invites either speculative litigation or, if courts demand a showing of real harm, no enforcement at all. Section 8 answers this directly: a plaintiff must show the same concrete, particularized injury federal courts already require for a constitutional or statutory claim under TransUnion LLC v. Ramirez, 594 U.S. 413 (2021), not merely a generalized grievance that a covered AI system exists and might someday affect someone. That standard does not eliminate the private right of action; it channels it toward the person the system actually harmed.

A further objection concerns Section 9's penalties: does a minimum civil penalty running into the hundreds of thousands or millions of dollars per violation, without regard to a deploying entity's culpability, size, or good-faith effort to comply, risk becoming an excessive fine of the kind the Eighth Amendment forbids, as the Supreme Court explained in United States v. Bajakajian, 524 U.S. 321 (1998)? This Article draws the distinction Bajakajian requires. A knowing and willful violation of the core discrimination, dignity, privacy, and safety protections in Sections 2 and 4 carries a real minimum penalty, because a deliberate violation of those protections is exactly the conduct this Article exists to deter. A negligent or unknowing violation does not carry a mandatory minimum at all; a court sets the penalty, if any, after weighing the harm, the entity's culpability and ability to pay, and whether it self-reported and fixed the problem, and a good-faith compliance effort that is promptly corrected is a complete defense. The severe end of the penalty scale is reserved for the entities this Article is actually written to reach.

A separate objection concerns Section 2's privacy protection and Section 4(b)'s biometric-identification exception: what counts as a person's consent or as lawful legal process for purposes of the privacy right, and what do real-time, general-purpose, and publicly accessible actually mean when a covered AI system is scanning a crowd? Left undefined, each term could be read narrowly enough to gut the protection or broadly enough to reach conduct never intended to be swept in. Section 1(g) defines all five terms directly. Consent must be freely given, specific to the use at issue, and never inferred from silence or a general terms-of-service click. Lawful legal process means a warrant, subpoena, or court order under a standard no weaker than what already governs the same category of information offline. And the biometric exception in Section 4(b) is confined to identification happening in the moment, aimed at the public generally rather than at a named individual, and outside spaces such as a clinic or house of worship where a reasonable expectation of privacy survives being in public.

Section 3(c) answers a related threshold concern the same way: rather than granting a future technical standard an unreviewable presumption of validity, the standard is entitled only to deference proportionate to the reasoning and evidence behind it, and a court must set aside one that is arbitrary, capricious, or not reasonably achievable. A final set of objections concerns whether the Article's own key terms, dignity, deceptive behavior, a concealed capability, meaningful and timely and informed human authorization, ordinary advertising, are precise enough to give a regulated company fair notice of what is prohibited, and whether the interpretability and disclosure duties in Sections 3 and 5 ask a company to do something no current technology can actually do. This Article defines each of those terms directly rather than leaving them to case-by-case inference, and it ties every technical duty, interpretability analysis, continuous monitoring, and the explanation a person is owed under Section 5, to what is reasonably achievable using methods generally accepted in the technical standards Congress and the Commission must keep current, not to a fixed and potentially impossible standard. Where a system's behavior genuinely cannot be reduced to the factors Section 5 asks for, the company must say so rather than invent an explanation it cannot stand behind. And a system that is covered only because of its size, not because it is used to decide something about a person, answers to the monitoring duty in Section 3 alone, not to the full weight of Sections 4, 5, 6, 8, and 9. The Article asks a company to do what the state of the art actually allows, not what a regulator wishes were possible.

VIII. What an AI System Bound by Human Rights Looks Like

The alternative to a constitutional floor is not the status quo. It is a continuing cycle in which each new administration’s executive orders are undone by the next, each state’s protective statute is challenged by a federal litigation task force organized to preempt it, and the only durable constraint on how artificial intelligence is built and used in the United States is whatever a handful of companies choose to impose on themselves. This Article proposes something more durable than that.

In a system governed by this Article, no company deploying a system capable of denying a person a loan, a job, or a parole date can honestly say it does not know why the system reached that result, because the law requires that it be able to look inside the system and find out, before the decision is made and again afterward. No government agency can deploy a surveillance system that watches every face in a public square and claims it is merely following an executive order, because the floor beneath that order is a constitutional right the order cannot lower. And no citizen denied an opportunity by an automated system is left arguing with a machine: there is a human being, identifiable and accountable, whose job it is to look at the case again.

This does not slow artificial intelligence down for its own sake, and it does not pretend the technology is something to be feared rather than governed. It says only what this volume says about every other concentration of power it addresses: that a capability this consequential cannot be left to govern itself, and that the people affected by it are entitled to the same floor of dignity, non-discrimination, and due process this country has spent two hundred fifty years learning to demand of every other kind of power. Artificial intelligence is not exempt from that demand merely because it is new. It is subject to it because it is powerful.

Finally, this Article is written so that no single flawed provision can be used to unravel the whole of it. If a court finds one Section wanting, the rest stands; that has always been the more responsible reading of a document this consequential, and this Article says so in its own text rather than leaving the question to chance.

PROPOSED CONSTITUTIONAL AMENDMENT