The lecture opens with the question any practicing lawyer would ask first: if an election commission deploys a cryptographically verifiable system and something goes wrong, who answers for it in court — and does existing law have any real capacity to handle that at all, or does the entire project first require a constitutional rewrite? The answer, stated upfront, is reassuring: embedding verifiability within existing legal systems does not require a constitutional revolution. Three classes of legal mechanism, already tested and functioning in adjacent fields, apply to this series' subject without requiring an entirely new body of law.
The first mechanism is soft law, examined through a twenty-year-old precedent: the Council of Europe's Recommendation Rec(2004)11 on electronic voting. Carrying no binding treaty status and no judicial enforcement mechanism, its non-binding character is exactly what gives it practical strength — it functions as a living, continuously updated reference that courts, regulators, and observer missions can cite without anyone undergoing the slow, costly procedure of treaty ratification. Strikingly, the recommendation remains the single authoritative source on electronic voting even in domestic jurisprudence of non-member countries, and its roughly biennial revision cycle lets it adapt as technology moves — something a constitutional amendment process, built for stability rather than speed, cannot do.
The second mechanism is the regulatory sandbox — an experimental legal regime bounded by participant count and time, and paired not with reduced but with increased transparency and monitoring. The lecture traces its structural lineage back to the 1934 federal Rules Enabling Act's pilot-project procedure, showing the underlying logic — a temporary, bounded departure from a general rule to accumulate practical experience — is nearly a century old. Applied to this series' subject, a Pol.is-style sense-making platform or a cryptographically verifiable voting system need not launch at full national scale; it can begin with consultative votes or municipal jurisdictions under heightened monitoring. The lecture draws a direct parallel to Lecture 8: both Estonia and Switzerland effectively operated by this sandbox logic even without naming it, and Switzerland's monitored withdrawal is exactly the case for why the mechanism matters — the problem was caught before irreversible full-scale deployment.
The third mechanism, and the lecture's central question, is liability for automated systems. Courts have consistently held that a computer system is not itself a legal actor bearing responsibility — liability falls on whoever controls and operates the system. The lecture illustrates this through the Air Canada chatbot case, where a court held the airline, not the chatbot's developer, liable for incorrect refund information, because it was the airline that controlled the system and owed the duty of care. Applied directly: liability for a failed verifiable procedure should fall on the controlling institution — an election commission, a government body — not the technology vendor, absent a specific contractual breach. The lecture is honest about the complication of establishing causation in complex, evolving systems, and ties this directly back to the reproducibility criterion from Lecture 4 and Kerckhoffs's principle: correctly assigned liability gives the controlling body its own built-in legal incentive to demand architectural transparency, with no separate regulatory mandate required.
The lecture closes by sequencing all three mechanisms into a single evolutionary path rather than three alternatives: form a soft-law standard, pilot specific implementations through sandbox-style controlled rollout, and rely throughout on existing liability doctrine correctly assigned to the controlling institution. None of the three, the lecture stresses, requires a constitutional revolution or an invented legal vocabulary — only the deliberate work of adapting already-familiar legal mechanisms to a new subject matter. The lecture ends by looking back across the whole series — diagnosis, principles, technology, institutions, and now law — and forward to the final lecture, framed not as a closing manifesto but as a program of open questions still worth pursuing.