The Limit Is the Unlock

By Anushka Appala and Dr. Janio Rosales

Most conversations about artificial intelligence in government begin with a question about capability: how much can the machine do? We want to begin somewhere else, with a claim that sounds like a retreat and is in fact the opposite. The single most powerful design decision we made in NaciluzIA was to draw a hard line the AI cannot cross. It never makes a binding decision. It never approves a benefit, suspends a right, or authorizes a payment. And that refusal — that deliberate limitation — is precisely what makes the system deployable, legal, and auditable.

This is counterintuitive, so it is worth stating plainly. The limit is not the price we pay to use AI in government. The limit is the reason we can.

What an auditor actually needs

Imagine the person who arrives after the fact: an auditor from the Contraloría, tracing a single social-benefit payment. They do not want to hear that a sophisticated model, trained on millions of examples, assigned the application a high confidence score. That answer is useless to them, because it cannot be checked. What they need is a chain they can follow. Which rule authorized which payment? What were the inputs? Who signed? When? Under what version of the policy?

A probabilistic system cannot supply that chain, because it is not how such a system works. A large language model predicts a likely output; asked to explain itself, it produces a plausible-sounding rationalization, not the actual cause. Point that system at a queue of benefit decisions and you have built something no auditor can audit — a machine that is right often enough to be trusted and opaque enough to be dangerous.

So NaciluzIA splits the work the way it must be split. The AI handles what is inherently probabilistic: understanding a request, translating it, drafting the paperwork, flagging an anomaly. The binding decision runs through a deterministic rules engine — "approve if the DPI is valid, the person is living, there is no duplicate benefit, and the socioeconomic threshold is met." That is not machine learning. It is published law, rendered as reproducible code, versioned so anyone can see which logic was in force on which day. A named official signs. Every step lands in a tamper-evident, hash-chained ledger. When the auditor arrives, the answer to which rule justified which payment is not reconstructed. It was recorded at the moment it happened.

The law was waiting for this

There is a common assumption that AI moves faster than the law and that regulation is always catching up. In this case the opposite is true. Guatemala already has the legal instrument that makes accountable automation possible: the electronic-signature law, Decreto 47-2008, which gives a properly recorded digital signature the same standing as a handwritten one. A system whose every binding action carries a named human signature, cryptographically fixed in an immutable record, is not straining against the law. It is exactly what the law anticipated.

This is the deeper meaning of the limit. Because the AI never signs, a human always does — and because a human always does, the entire transaction stands up under a statute that already exists. A design that let the model make the call would have to invent a new legal category to justify itself, and would fail the moment it was challenged in court. A design that keeps the human in the loop by construction inherits the legitimacy of an established law. The constraint is what connects the technology to the legal ground it must stand on.

Why a black box fails where trust is already thin

None of this would matter if citizens extended their governments the benefit of the doubt. They do not. In Latin America in 2024, trust in political parties stood at 17% and trust in congress at 24% (Latinobarómetro, 2024). Those are not the numbers of a public prepared to accept "the algorithm decided" as an answer. They are the numbers of a public that has learned to ask who decided, and can they prove it.

Drop an opaque decision engine into that environment and you do not solve the trust problem. You deepen it. Every denial becomes a grievance with no visible author. Every approval invites the suspicion that someone gamed the model. A black box asks citizens who already distrust their institutions to extend fresh trust to a machine they cannot see into — an extraordinary request, made precisely when the ground for it is thinnest.

The accountable design asks for the opposite. It says: here is the rule that applied to you, here is the official who signed, here is the record you or an auditor can inspect. It does not ask for trust. It offers proof. In a region where 17% is what confidence in parties has fallen to, proof is the only currency worth building on.

This is why we say the limit is the unlock. Refusing to let the AI decide is not a hedge against the technology's immaturity, to be relaxed once the models improve. It is the load-bearing decision that makes everything else — the legal standing, the audit trail, the citizen's ability to trust the result — possible at all. The most capable thing we could do with a government AI was to bound it. In the light, that is not a smaller system. It is the only one that can actually be deployed.

Cada decisión, a la luz.

Anushka Appala and Dr. Janio Rosales