banezglobal

The Republic of Paper Warrants

Published: 2026-07-24

Abstract

Authorization, attestation, and agentic AI in the Philippine National Anti-Corruption Strategy.

Authorization, attestation, and agentic AI in the Philippine National Anti-Corruption Strategy

Zen Banez · Banez Global · banezglobal.com · July 2026 · Working paper


1. Context and the question

On 1 July 2026, the government launched the development of the Philippine National Anti-Corruption Strategy (PNACS) — a whole-of-government framework fulfilling the country's commitment under the UN Convention against Corruption, structured around five pillars: prevention, enforcement, information sharing, international cooperation, and asset recovery. The Presidential UNCAC Inter-Agency Committee leads the effort, with UP NCPAG supporting the consolidation of stakeholder inputs, and consultations open to civil society, the private sector, and academe.

This paper contributes one structural argument to that consultation. It begins from an observation that is easy to state and uncomfortable to sit with: the Philippines does not suffer from a shortage of anti-corruption controls. It suffers from controls whose evidence refers to other controls. The question PNACS must answer is not “how do we add oversight?” but “how do we make the oversight we already have touch reality?”

2. The paper republic already runs on warrants

Consider what the bureaucracy already is. A notarized Special Power of Attorney is a capability token: a named principal, a named agent, enumerated powers, third-party attestation, revocability, and — through the doctrine of ultra vires — an enforcement layer that voids acts outside the instrument's scope. “A valid credential is not consent” is not a novel principle of computer security; it is centuries-old agency law.

The disbursement chain is even richer. A purchase request begets an obligation request; a budget officer certifies that funds exist; an accountant certifies the appropriation; an approving authority signs; the Commission on Audit maintains what is, in effect, an append-only log. Each signature is a narrow attestation of one specific fact — not general approval. In the vocabulary of capability systems, this is caveat-based attenuation of authority. The paper republic is, on its face, one of the most warrant-dense administrative systems ever built.

Which sharpens the puzzle. If the architecture is sound, why do ghost projects clear it with perfect paperwork?

3. Four failure modes of paper

Verification cost. Checking that a document is authentic, unrevoked, and current is expensive on paper, so downstream parties skip the check. An entire fixer economy exists in the gap left by skipped verification.

No freshness. A signed document is “valid” forever. Revocation does not propagate. Once ink dries, the capability is immortal; there is no mechanism demanding that authority be shown to be currently alive.

Attestation decay. The signature ritual persists while the inspection behind it dies. A certifying officer signing forty obligation requests a day is not certifying; the act has become theater. This is the bureaucratic form of approval fatigue, and it is a design problem, not a personnel problem.

Self-attestation — the deniability engine. The deepest failure: every attestation in the chain references another document, never the world. The inspector's certificate cites the contractor's completion report; the accountant certifies against the certificate; COA audits the file. The chain is closed under paperwork. In a ghost project, every warrant in the chain is genuine, every signature real, every caveat satisfied — and the road does not exist.

Self-attestation is what manufactures plausible deniability as a structural product. Each signer can truthfully say “I attested to what was before me.” Colluders need only corrupt the single point where documents were supposed to touch reality; everyone downstream is structurally innocent, and blame diffuses until no one carries it. The 2025 flood-control anomalies are the canonical recent instance: immaculate files, absent works, surfaced by physical inspection and citizen reports rather than by any property of the document chain.

4. The deniability inversion

Prevention has one governing principle: force the chain open — anchor it to reality at points the beneficiaries do not control. The deepest instrument for this is changing what a signature is.

Today an attestation is a vague act of diligence: “I certify that the project is complete.” Vagueness is what makes it deniable — poor judgment is not a crime. Replace it with a narrow, falsifiable, evidence-carrying claim: “segment km 4.2–7.8 paved as of this date; geotagged photographs with these reference hashes; drone orthomosaic attached.” Now, if reality diverges, the signer did not exercise poor judgment — the signer fabricated evidence, a discrete, provable, prosecutable act.

Call this the deniability inversion. Vague attestations diffuse blame across the whole chain; specific falsifiable attestations localize it to exactly one claim and one signer. Present chains are engines of collective innocence. Falsifiable chains are engines of individual accountability. The scope boundary is what makes the violation legible — the same property that makes a well-drawn warrant enforceable.

5. Design principles for an open chain

Separate benefit from attestation. The party who gains from “complete” must never be the sole source of the “complete” signal. Verification belongs to oracles with independent — ideally adversarial — incentives. Three exist already in embryonic form: (a) machine observation — satellite and drone differencing of claimed progress against imagery, the approach piloted under Project DIME; (b) community monitoring — the CCAGG tradition of citizens physically walking the roads their taxes built, the Bayanihan form of verification; and (c) adversarial inspection — losing bidders, the best-incentivized free auditors in existence, given standing and access to the evidence bundle.

Gate disbursement on freshness. A useful pattern from modern capability systems splits authority into a long-lived capability plus a short-lived “freshness” proof issued by a powerless third party — one that cannot initiate anything, only confirm observation. The fiscal translation: the appropriation is the long-lived warrant, but no milestone payment is honorable without a fresh, short-lived reality-attestation from a no-stake oracle — a current satellite differential, a community confirmation quorum. Money becomes physically unable to move on documents alone. Where presidential site visits have caught ghost works, the president was acting as an ad hoc freshness oracle; the point is to make that check protocol-mandatory rather than dependent on anyone's attention.

Randomize, rotate, and attach liability. Collusion requires durable relationships — the inspector who knows which contractor to accommodate. Random assignment of verifiers, unpredictable selection of projects for deep physical audit, and rotation break those relationships, converting corruption from a stable arrangement into repeated risky negotiations with strangers. Exhaustive verification is unnecessary: what is required is that any given attestation face a real, unpredictable probability of being checked against its own attached evidence, with personal liability when the claim proves false.

Reduce attestation volume; increase attestation depth. Decay comes from load. Forty rubber stamps a day protect nothing; a small number of deep, meaningful certifications protect a great deal. Risk-based tiering — automated checks for routine low-value transactions, genuine human verification for large ones — restores meaning to the signature by rationing it.

6. Honest limits

Services are harder than structures. Reality-anchoring is tractable for infrastructure because roads and flood-control works are visible from orbit. Ghost trainings, consultancies, and software deliverables require a weaker anchor — quorums of supposed beneficiaries — which is itself more corruptible.

Delivery is not value. This apparatus verifies that the dike exists, not that it was needed or fairly priced. Specification- and procurement-level corruption lives upstream and needs different instruments — open contracting and beneficial-ownership disclosure, which the New Government Procurement Act already mandates on paper.

The oracle problem is priced, never solved. Any single oracle can be bought. The design objective is raising the number of independent, non-colluding, randomly assigned parties who must all be corrupted — across incentive domains that do not share interests — above the payoff of any given theft. The paper republic fails because that number is currently one.

7. Where AI genuinely fits — and where it endangers

Corruption is chiefly an incentive problem, and no model fixes a prosecutor who will not prosecute. But three bottlenecks in the design above are genuine capability bottlenecks — humans cannot read, watch, or match at the required scale — and those are the legitimate applications.

Collapsing time-to-understanding. The paper republic's data is largely public — COA reports, procurement records, asset declarations, beneficial-ownership registries — and goes unread because reading is expensive. Large language models make full-population analysis affordable for the first time: cross-referencing bidders who share addresses and incorporators, detecting bid rotation, flagging price outliers, matching budget insertions to contractor networks. Ukraine's Prozorro/DOZORRO ecosystem is the existence proof. The shift from audit-by-sampling to audit-by-population changes the fraud calculus directly: the probability that any false attestation gets examined moves from approximately zero to something an accomplice must price in.

Processing reality anchors. Satellite-and-drone verification dies at human review capacity; no inspectorate can eyeball ten thousand sites quarterly. Computer vision differencing claimed progress against imagery, with humans reviewing only the divergences, is the correct division of labor — with one discipline held absolute: AI never attests; AI routes attention. The attestation remains a human or instrumented act with liability attached.

Democratizing adversarial verification. Losing bidders and citizen monitors are the best-incentivized auditors, but querying procurement data currently requires a data scientist. Natural-language interfaces over open contracting data turn every provincial journalist into a capable forensic analyst — verification that actually distributes.

Against these stand four dangers. AI is a better forger than detector: immaculate completion reports, inspection narratives, and plausible imagery are now nearly free to fabricate, which finishes documents-as-evidence as a category and converts reality-anchoring from an improvement into a requirement. Attestation laundering: “the AI reviewed it” is the rubber stamp reborn at machine speed; if approvers wave through whatever a model summarizes, decay returns with better throughput. Weaponized detection: everyone's paperwork contains anomalies, so whoever sets a flagging model's thresholds chooses the defendants; the detector itself needs open methodology, logged queries, and no single institutional owner. And ungoverned agents: addressed next, because it is the forward-looking core of this paper.

8. The coming agentic government and the warrant

Within the PNACS implementation horizon, government agencies will deploy AI agents inside fiscal workflows — processing obligations, drafting certifications, reconciling accounts, initiating routine disbursements. This is not speculative; it is the trajectory of every large administrative system currently adopting the technology.

An agent operating on broad standing credentials inside a disbursement chain is a corruption instrument awaiting an operator. The failure mode is precisely the one this paper began with, at machine speed: the credential is valid, therefore the action proceeds — but a valid credential is not consent. Detection-centric governance answers this too late; the money has moved, and the mean time to understanding is measured in budget cycles.

The alternative is an authorization architecture with four properties. Narrow: agent authority is scoped to enumerated actions, not granted as standing access. Expiring: authority carries a lifespan and must be re-established, so revocation propagates by default. Intent-bearing: the purpose of the delegation is captured in the instrument itself, so drift from intent is detectable, not merely regrettable. Logged: every exercised authority appends to an audit trail that records not just what was done but under which authorization and toward which stated intent.

The striking consequence: an agentic government built on such instruments produces a richer accountability record than the paper republic ever generated. Every automated action arrives with its authorization context attached. Corruption conducted through such agents is legible by default — the inversion of the present situation, where corruption conducted through paper is deniable by default. And because government is the domain where the words warrant, obligation, and certification already mean what this architecture means — where ultra vires has enforced the principle for centuries — the conceptual translation cost is the lowest of any sector.

The recommendation to PNACS is therefore modest and timely: as agencies institutionalize their own anti-corruption planning and map the vulnerabilities in their operations, the authorization architecture of any AI they deploy should be named as a vulnerability class now, and open standards for warrant-style agent authority should be referenced in implementation guidance — before the deployments arrive rather than after. Standards adopted at design time cost signatures; standards retrofitted after an incident cost scandals.

9. Mapping to the five pillars

Prevention: falsifiable attestations, benefit/attestation separation, freshness-gated disbursement, and attestation-load reform are all preventive controls in the strict sense — they remove the structural conditions of deniability rather than punishing its exploitation.

Enforcement: the deniability inversion is an enforcement multiplier; it converts diffuse negligence into localized, provable fabrication, which is what prosecutors can actually carry.

Information sharing: population-scale analysis of already-public records, open flagging methodologies, and natural-language access to procurement data are this pillar's concrete form.

International cooperation: open authorization standards and open-contracting data formats make Philippine records interoperable with the cross-border asset-tracing this pillar contemplates.

Asset recovery: intent-bearing, logged authorization chains shorten the path from anomaly to traced beneficiary — recovery begins at the moment of understanding, and understanding is the quantity these designs compress.

10. Provenance and author

Zen Banez is a systems developer and founder based in Tacloban City, with over a decade of systems work for the Department of Education, Save the Children Philippines, and international aid programs. The capability-warrant line of thinking documented here dates in his work to 2007, under the working name “Bayanihan Network,” and continues as ongoing research and published writing at banezglobal.com — including “A Valid Credential Is Not Consent” (2026), “The Front Desk and the Warrant,” and “The Tower and the Warrant.” He builds Pulse, a human-in-the-loop platform for agentic communication, and leads Project AIgnite, a volunteer AI-literacy initiative at Leyte National High School. He writes from Eastern Visayas, where the distance between a flood-control line item and a family's survival is not a metaphor.