Governance Without Surveillance
A new paper for the works council conversation that usually kills AI measurement

Most behavioral measurement tools die in the approval room, not the evaluation room.
Any tool that measures how employees work with AI invites one objection before any other: is this surveillance? In a European context, with a works council across the table, that objection is not a public-relations concern. It is a gate. A tool that holds identified behavioral records is squarely inside co-determination law, and the conversation is effectively over before the measurement is ever evaluated on its merits.
"Governance Without Surveillance" is a new paper from PAICE (People + AI Collaboration Effectiveness) that makes the case that the surveillance objection is answerable — but only by architecture, not by policy. The distinction determines whether a behavioral measurement programme is adoptable at all.
The Surveillance Test
The paper defines surveillance structurally rather than by intent, which is what makes the definition testable. Observation is not surveillance. Surveillance is observation that carries three additional properties:
- Identification — the observation is tied to a known individual
- Retention — a durable record of that individual's conduct is kept
- Repurposability — the retained, identified record can later be turned to a use the person did not agree to
A system with all three is surveillance whatever its stated purpose. Remove any one and the character changes; remove all three and what remains is measurement.
This distinction is useful because it lets a works council or DPO ask three architectural questions instead of arguing about intentions. Can the system attribute this record to a named person? Is the record kept? Could it be repurposed against them?
How PAICE Fails the Test by Design
PAICE is engineered to answer no to all three questions, and to do so structurally rather than by policy promise.
No identification. PAICE requires no user accounts, no registration, no persistent profile. A user is reduced to an irreversible SHA-256 hash. In enterprise deployments, participants are represented by opaque tokens whose mapping to real employees lives in the organization's own systems — never in PAICE.
No retention of the observed material. The conversation through which behavior is observed is not stored in the production environment. Turn-by-turn logging is disabled by code, not by configuration or promise. During a session the transcript exists in memory to drive scoring; once scores are computed, the raw material is not written to any persistent store.
No repurposability. Because there is no identified, retained record of individual conduct, there is nothing to repurpose. Organizational analytics are returned only as aggregates above an enforced floor of ten completed assessments. A score detached from identity and from the underlying conversation cannot be turned into a disciplinary exhibit.
The paper maps this architecture to the specific legal instruments that decide whether a programme is adoptable in Europe: German works-council co-determination under BetrVG § 87(1) no. 6, the EU AI Act workplace information duty under Article 26(7), and GDPR data minimisation under Article 5(1)(c).
Privacy as Adoption Enabler
Most vendors present privacy as risk reduction — encryption, access controls, retention limits. Those controls matter and PAICE implements them. But the paper argues something different: for measurement of people, privacy is not a defensive feature bolted on at the end. It is the precondition for the product existing in the workplace at all.
An organization cannot measure AI-collaboration behavior across its workforce if the measurement is surveillance, because the workforce's representatives will not permit it. By removing identity, retention, and repurposability at the architectural level, PAICE converts an un-approvable programme into an approvable one.
The architecture is the adoption strategy. That is the structural claim behind the title.
What the Employer Still Must Do
The paper names its boundaries honestly — because presenting the architecture as eliminating all employer obligations would cost credibility with exactly the audience it addresses. PAICE does retain some data (scores, metadata, timestamps, encrypted email where provided). A works-council consultation, an employee-information notice, and a data-protection assessment may all still be required. The architecture makes each of these easier to complete and likelier to succeed, because the honest description of the system is favorable. The employer must still do them.
Read the Paper
The full paper is available now at paice.work/papers/governance-without-surveillance — readable in-browser or as a PDF download. It includes an appendix mapping the European legal touchpoints — BetrVG, EU AI Act Article 26(7), GDPR Articles 5(1)(c) and 88 — to specific PAICE architectural features.
Ready to see what behavioral AI measurement looks like when it's built for approval? Take the PAICE assessment to experience the architecture firsthand, or contact us for a works-council or DPO review pack.
Get Involved:
- Take the assessment (free, always — ES, PT, FR available)
- Read the full paper (in-browser or PDF)
- Browse all papers (six papers in the library)
- Explore the AI Capability Baseline (cohort-level analytics for organizations)
- Contact us about your specific requirements
Recommended Reading
📖 Related Papers:
- The Cost of Invisible AI Risk — The board-level business case for measuring AI-collaboration reliability
- The People-Vector Evidence Layer — Mapping PAICE to NIST AI RMF, ISO/IEC 42001, and the EU AI Act
📖 Related Posts:
- Privacy-First Email Management — How PAICE handles contact information without linking it to scores
- Your Data, Your Privacy — What PAICE collects, what it doesn't, and why
- Transparency Tells You It's AI — EU Article 50 commentary on the gap between disclosure and judgment
متجسس لیکن وقت کم ہے؟
3 منٹ کا PAICE Pulse کریں — ایک فوری اعتماد چیک جو یہ ظاہر کرتا ہے کہ آپ اپنی AI تعاون کی پوزیشن کو کیسے دیکھتے ہیں۔ لاگ ان کی ضرورت نہیں۔