Three questions before you let an agent send a message
The line between a useful automation and an incident runs exactly where the action leaves the company. These three questions are enough to decide whether a given action can go alone.
Who will see it?
An internal recipient is one thing, a client another, a regulator or a patient another still. The further from the company, the smaller the tolerance for error and the more a gate earns its place.
Write this down as a list of recipients rather than a feeling. An agent will not work out that this particular domain belongs to a client under a framework agreement unless somebody tells it.
Can it be undone?
A staging deploy can be rolled back. A sent message cannot. This is the sharpest dividing line and the easiest to implement, because it requires no judgement about content.
If an action cannot be undone, the question is not whether the agent will get it right, but what happens the one time in a hundred that it does not.
Reversibility is a better criterion than model confidence. It does not move with every model update.
Who signs for it?
There has to be a specific person, not a role and not a team. If the answer is the marketing department, then nobody signs.
The same rule runs the other way: whoever signs must see what they are approving and must be able to refuse. Blind approval is worse than none, because it manufactures the appearance of oversight.
What do you do with the answers?
Put them somewhere a machine reads. Three answers are enough to place an action in one of three tiers: it goes alone, it waits for a signature, or it never happens.
As long as those answers live in somebody's head, they apply only while that person is at work.
Sources
- Article 14: Human oversightEU Artificial Intelligence Act, accessed 2026-09-09