Compliance Theatre
Quality mechanisms exist on paper and in UI — but do not change judgment or accountability
Commitment-quality mechanisms must do what they claim — or they provide false assurance while consuming the resources genuine mechanisms require.
Controls are present. Auditors see checkboxes, second signatures, stress-test jobs, and vote records. Operationally, outcomes would be identical if the mechanisms were removed — because nothing in the mechanism actually constrains judgment. That is compliance theatre: the organisation buys the appearance of strengthened commitment boundaries without paying the cost of independent assessment, disclosure, or pre-committed rules. See theatre for the general pattern; credential theatre and vote on physics for legitimacy-side instances.
Strengthening the Commitment Boundary names concrete instances.
Common forms
Rubber-stamp approval
Human review that never changes outcomes. Article 19 Rule 3: rubber-stamp review is not review.
Undisclosed stress testing
An AI generates challenges to a tentative conclusion, but results are not shared with all reviewers and auditors. That is not a stress test — it is invisible influence with no accountability. Genuine pattern: AI stress testing with full disclosure in the commit record.
Post-hoc threshold manipulation
Democratic or meritocratic panels where the supermajority threshold or voter weights are set after votes are visible. Pre-commitment is the mechanism; adjusting rules after seeing outcomes is manipulation regardless of framing.
Visible anchors on “independent” review
Second reviewer sees the first conclusion or merged model score before assessing — anchoring bias preserved by workflow design. See blind peer review.
Collapsed model disagreement
Ensemble scores that hide which models agreed, disagreed, and why — destroying the epistemic signal the human needed to escalate.
In software systems
Workflow engines require secondReviewerId but pass the first decision in the payload. Stress-test microservices run asynchronously; only a boolean stressTestPassed reaches the commit event. Fraud panels store a single riskScore aggregated from three models. Audit exports show mechanisms executed; they do not show mechanisms changing the path to bind.
In human organisations
Committees exist; dissent is not recorded. Certification is cited while scope is ignored. GCP/SOC/ISO badges cover process folders, not whether anyone read the counter-evidence before signing.
Counter direction
Apply quality mechanisms from art. 20 and legitimacy mechanisms from art. 35 as designed: blind review, disclosed stress tests, separate model outputs, pre-committed calibration weights, certification with scope, authorized process with deviation events, recorded delegation, contestability. Measure override rates, disagreement flags, and unresolved challenges — not merely that a step ran.
Related dark pattern (consent-specific): consent theatre — different domain, same structural hollowed bind.