# The Legibility Gap: Why the Algorithmic Systems Affecting You Stay Invisible

There is a particular kind of uncertainty that modern technology creates. It is not simply the uncertainty of not knowing how software works. It is the harder feeling of not knowing whether software is working *on you* at all.

You may drive through a city without seeing the systems that record vehicle movements. You may use an ordinary app without seeing which parts of its advertising software handle location data. You may read a confident-sounding public claim without having a dependable signal that it is misleading. You may encounter a generated image without being able to reconstruct where its material came from. And you may be shown an unusually clear visualisation of an AI system without being able to tell whether that display explains why the system produced an answer.

These are different technical and political problems. They should not be collapsed into one grand claim that all technology is secretly watching or deceiving us. The connection between them is an editorial interpretation: in each example, the people affected may be unable to inspect the relevant process, evaluate its boundaries, or meaningfully contest it in the moment. That shared condition does not establish a shared motive, technology, or legal remedy.

Call this the legibility gap. A system is legible when a person can reasonably tell what it is doing, what information it is using, what its output means, and where its account stops. The gap opens when those questions are unavailable, buried, or answered only after harm has already become difficult to trace.

Privacy is part of this picture, but it is not the whole of it. An invisible data flow is a privacy concern. An untraceable image is a provenance concern. A persuasive but misleading statement is an information-integrity concern. A beautiful explanatory interface that cannot establish causation is an accountability concern. Looking at them together does not erase their differences. It shows why reacting to each case as a separate surprise can leave people permanently behind the systems shaping their choices.

When systems are hard to inspect

“Invisible” here is an editorial description of a person’s practical vantage point, not a claim about designers’ intentions. Some systems are hard to inspect because they operate in the background, through networks of vendors, sensors, databases, models, and policies. Some offer an ordinary interface with few places to look. Some produce effects that are easier to notice than their causes.

That distinction matters. It avoids imputing intent while still taking the consequences seriously. A person does not need to establish a motive before asking a basic question: can I tell what is happening to me here?

Legibility is also not the same as being handed a long privacy notice, a technical diagram, or a dashboard full of activity. Information can be available in theory and unusable in practice. A useful account has to match the decision a person faces. If a driver cannot know whether a journey is entering a networked surveillance system, or an app user cannot tell what location-related behaviour its ad software is prompting, then a formal disclosure elsewhere may not provide practical visibility.

The same applies to information. Reading more material does not automatically reveal whether a claim is misleading. Seeing more of an AI system does not automatically show which internal activity caused an answer. What people need is not maximum data. It is an intelligible connection between an action, a consequence, and a possible response.

That is why the legibility gap is partly psychological. When causes are hard to locate, people can end up blaming themselves for not being sufficiently alert, technical, or sceptical. Yet a person cannot make an informed choice about a process they have no realistic way to observe. The burden should not rest entirely on the individual to infer an invisible system from its outcomes.

A U.S. surveillance-policy example: ALPRs in public

Automated license plate reader (ALPR) systems make the problem concrete, but this example has clear limits. It draws on a U.S.-based civil-liberties organisation’s policy position; it does not describe every ALPR deployment, legal regime, or jurisdiction. In an August policy position, the Electronic Frontier Foundation argues for eliminating ALPR surveillance and reducing its harms. Its concern is not merely a camera on one corner. It is the capacity for plate-reader systems to turn sightings of a vehicle into a record of movement, including in contexts where a person is not individually suspected of wrongdoing.

For an affected driver, the defining feature is often ambient collection. A camera may not announce what database will receive a plate number, how long a record will remain available, whether it will be shared, or what later query may connect it to other records. The system is visible only in the thin sense that a camera might be physically present. Its operational life is mostly elsewhere.

This does not mean every camera creates the same risk or that every use has the same legal basis. It means that visibility has to be assessed at the level that matters: the collection, retention, access, and downstream use of the record. A sign saying “cameras in use” cannot by itself answer those questions.

The EFF’s position is an advocacy position, not a neutral inventory of all ALPR policy. That is worth stating plainly. Its value here is to name a real design and governance problem: systems that assemble movement records can be difficult for the people represented in those records to see, assess, or challenge.

ALPRs are not facial recognition, although the two can sit in the same wider landscape of public-space surveillance. For a related discussion, see Age of Algorithms’ “Live Facial Recognition in Public Spaces”. The point of the comparison is not to make all surveillance technologies interchangeable. It is to recognise that public visibility — being out on a street — does not necessarily make data collection legible.

Some advertising SDKs collect and share location by default

The same mismatch can appear in the phone in a person’s hand, but the evidence is limited and specific. The EFF’s 4 August release, *Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds*, says its review identified four named advertising SDKs — InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads — that collected and shared a user’s location by default for ad targeting when the user had given the app location permission. That finding is not evidence that every reader’s phone, every app, or every SDK shares location in this way. It identifies a documented risk in particular embedded advertising software that an app user may not see.

A permission prompt can create the impression that the whole decision has been made. But the more important question may be what happens after permission is granted: which software components are involved, what signals are requested or encouraged, and what sharing practices follow. Those are not questions that most people can answer by looking at an app’s home screen.

This is where legibility becomes more demanding than consent. Consent can be meaningful only if a person understands the decision at a useful level of detail and can revisit it when circumstances change. A binary permission setting may be necessary, but it is not a complete map of a commercial data flow. Nor should people be expected to reverse-engineer the software supply chain of every app before deciding whether to use it.

That does not make personal settings pointless. It changes what they are for. Reviewing location permissions, choosing not to grant access that an app does not seem to need, and removing apps that no longer serve a purpose are reasonable forms of hygiene. But individual settings cannot substitute for clearer product design, meaningful limits on collection and sharing, and rules that make consequential flows inspectable.

The practical test is modest: if an app wants access to where you are, can you tell why, when, and through which part of the service that access is used? If the answer is unclear, the problem is not that you failed a technical exam. It is that the system has not made an important relationship legible.

When the information you see is misleading, and you cannot tell

Legibility is also about what reaches a reader’s attention. The recent arXiv preprint *RCMN: Understanding Misleadingness in Influential Public Discourse* examines misleadingness in influential public discourse. As a preprint posted on 27 August, it should be treated as active research rather than settled evidence. It does not establish a universal prevalence of misleading content, and it should not be used as a shortcut to declare public discourse broadly untrustworthy.

Its relevance lies in the problem it takes seriously. Misleadingness is not always marked with a warning label. A claim may be framed selectively, omit a crucial context, use an apparently authoritative source, or be placed within a narrative that makes its limitations hard to notice. The reader’s task is then not simply to retrieve a fact. It is to detect what is absent, distorted, or overconfident.

That task has collective consequences. When influential discourse is difficult to assess, the cost is not confined to one person being fooled. Shared decisions depend on a shared capacity to distinguish evidence, uncertainty, advocacy, and assertion. The difficulty is compounded when attention is scarce and the surrounding systems reward speed, certainty, or engagement more readily than careful qualification.

None of this requires treating readers as helpless. A useful habit is to slow down at the point where a claim creates a strong emotional or political conclusion. What is the original source? What exactly does it say? Is the conclusion stronger than the evidence described? What would change the interpretation? These questions will not solve every case, and they should not become a ritual of endless suspicion. They are ways to restore some visibility to the path between a statement and the confidence it asks of us.

Algorithmic systems can shape that path through ranking, recommendation, moderation, and presentation. For adjacent context, see “The Quiet Referee: How Automated Moderation Shapes What You See and Say”. The legibility question remains the same: can a reader tell why this material is prominent, what supports it, and what would count against it?

Can transparency tools actually make AI legible?

It would be a mistake to conclude that the answer is simply more transparency. More transparent design can be valuable. MIT News’ July interview, *3 Questions: Neural transparency and the future of AI design*, describes work on an interface intended to let users inspect aspects of a personalised AI system’s neural activity. The directly relevant conference paper is *Neural Transparency: Mechanistic Interpretability Interfaces for Anticipating Model Behaviors for Personalized AI*. Its reported interface and study concern that personalised-AI setting; they are not evidence that transparency interfaces generally explain the behaviour of AI systems.

That ambition deserves more than a cynical dismissal. An interface that exposes activity may give a person a better starting point than a black box that offers nothing at all. It can make questions possible that were otherwise out of reach.

But showing activity and demonstrating causation are different achievements. This is an editorial caution rather than a finding that the paper’s interface is deceptive or unhelpful. A colourful or comprehensible display can give a viewer a starting point without, by itself, establishing that a particular internal pattern caused a particular output. The viewer may be able to see *something* happening and still need evidence about whether the display is a faithful explanation, a useful approximation, or an attractive proxy.

This is not a reason to reject neural transparency. It is a reason to give transparency claims their own scrutiny. What precisely does the interface show? What does it omit? Has the relationship between the display and the output been validated? Can a user distinguish a descriptive visualisation from a causal account? And, crucially, can they act on what they learn?

Age of Algorithms has explored this distinction in “The Explanation Gap: When the AI That Decides About You Can’t Show Its Work”. The larger point here is that transparency is not a decorative property. It is a relationship between an account and a decision. A system becomes more legible when its explanation helps a person understand, question, and, where appropriate, contest a meaningful outcome.

When synthetic media cannot be traced to its source

Synthetic media adds another layer. MIT News reported in August on *Outputs of generative diffusion models are often unattributable*, a Nature Communications study. The study tests a defined attribution question in experiments with generative diffusion models: whether an output can be attributed to individual training images. Its finding that outputs were often unattributable is not a claim that every generated image lacks provenance information, that every generative model works the same way, or that it settles every question about authorship or rights. It identifies a limit within the study’s experimental scope: after the fact, the route from output back to particular training material may be unavailable.

That limit matters because provenance is not just a technical curiosity. It is how a person asks where something came from, whether it has a known history, and what claims can responsibly be made about it. When that chain is broken at the data layer, some questions about origin and consent cannot simply be answered later by inspecting the finished image.

The result is a different kind of invisibility from data collection. Here, the missing object can be a history. An image can be vivid and fully visible while the conditions of its production remain obscure. The connection to the wider legibility gap is editorial: visibility of an output does not necessarily provide a viewer with a usable account of its origin.

For a fuller treatment, see “When an Image Has No Author: The Erosion of Provenance in the Age of AI”. The useful lesson for the wider legibility gap is not that every image must be rejected. It is that visibility of an output should not be confused with visibility of its origin.

What an ordinary person should ask

No individual can audit every street camera, app library, public claim, model interface, or image they encounter. A humane response to the legibility gap is not permanent vigilance. It is to build a few questions into the moments where a system asks for trust.

  • **Am I being tracked here, and what would make that visible?** Look beyond the immediate device or sign to the likely data flow, retention, and access questions.
  • **What is this app asking to know, and is that access necessary for the job I want it to do?** Treat a permission as the beginning of a question, not the end of one.
  • **Can I trace the important claim I am reading to evidence that actually supports it?** Check whether confidence, context, and source strength line up.
  • **Does this transparency feature prove anything, or does it merely show activity?** A display may be useful without being a complete explanation.
  • **Can this image or media item be connected to a reliable account of its origin?** If not, narrow the claims you make about how it was produced.

These questions will sometimes produce an incomplete answer. That is not failure. An incomplete answer is itself information: it can reveal where a product, institution, or information environment has left people without a way to understand a consequential process.

The goal is not to make every system perfectly transparent or to imply that uncertainty can be eliminated. It is to stop treating invisibility as normal. When tracking, persuasion, and automated judgment happen outside a person’s view, the first form of defence is to recognise the pattern. The next is to insist that systems affecting people provide accounts that are not merely available somewhere, but usable by the people asked to live with their consequences.