Human gates for AI: which decisions an AI should never take alone
An AI should never take alone any move that touches law, health, money, safety, rights, jobs, education, public policy or reputation; in the Of One method, each of those moves sits behind a human gate, a point where a named person must approve before anything happens.
That rule does not mean an AI cannot help with those decisions. It can gather facts, draft options, and point out risks. It means the AI stops at the gate and a person decides. This guide gives the gate list, explains why reversibility matters so much, shows how to accept a risk without losing track of it, and ends with an illustrative gate table for a small business that uses AI agents.
This guide is education, not legal advice. If a law applies to your use of AI, ask a lawyer who knows it.
The gate list
Of One’s skill file lists the moves that need a human reviewer. In plain words, a person must sign off on anything involving:
- Law and compliance: legal and compliance matters.
- Health and medicine: medical and health decisions.
- Money: financial decisions and anything that moves money.
- Safety: safety and physical safety.
- Rights: anything that affects people’s rights.
- Jobs and education: employment and education decisions about people.
- Public policy.
- Reputation: anything that could damage how others see you.
The skill file adds gates for the method’s own work: a trunk rewrite, releasing a research pack outside, high-severity dissent, low-provenance evidence behind a high-stakes claim, overriding the adapter, and deleting or backfilling audit records.
Two patterns sit under the whole list. The first is stakes for other people: health, rights, jobs and safety land on someone other than the person pressing the button. The second is reversibility: once the money leaves, the email is sent, or the person is let go, you cannot take it back.
Reversible versus one-way moves
Jeff Bezos drew this line in Amazon’s 2015 letter to shareholders. He described consequential, irreversible decisions as “one-way doors” that must be made carefully and slowly, and wrote that most decisions are not like that: they are changeable, reversible, “two-way doors.”
Of One builds the same line into every map. Each option records its tradeoffs and whether it can be undone. The repo’s example map states the rule as a standard: prefer moves that resolve rendering-blocking unknowns before irreversible action. In plain words, take the reversible step first, and let the exposures named on the gate wait for a named person to sign.
For AI, this line decides a lot. A reversible move made by an AI is a draft. A one-way move made by an AI is a decision no human made. The repo’s own example map shows the pattern. Its recommendation is a reversible diligence sprint, not a launch, and its gate, G1, requires a human regulatory and business owner to “approve, block, or narrow” the move before any customer commitment, permit filing, compliance or reputation exposure, or launch.
What a gate needs to work
A gate that anyone can wave through is not a gate. The repo even names this failure in its example map: “review treated as paperwork instead of a decision gate.” A gate works when it has:
- A named owner. A person with a role and the authority to decide, not “the team” or “a reviewer.”
- A clear decision. Approve, block or narrow. Not “looks fine.”
- What they saw. The owner signs off on the map: the facts, the unknowns, the options. Not only the AI’s summary.
- A record. Who decided, when, and why. High-stakes maps in Of One keep a review log for exactly this.
Accepting a risk without losing it
Sometimes you have to move while something is still unknown. Of One allows that, but not quietly. An accepted risk needs:
| Field | What it means |
|---|---|
| Named owner | The person who accepts it, their role, and their authority to do so |
| Scope | Exactly what is being accepted, and nothing more |
| Reason | Why moving now beats waiting |
| Accepted on, expires on | A start date and an end date |
| Evidence | What the owner looked at |
| Reopening conditions | The facts that would bring it back for a new decision |
The repo’s engine rejects accepted risks that are anonymous, expired, dated in the future, too broad, or missing evidence. The expiry matters most. Without it, “we accepted that risk for now” turns into “we stopped thinking about that risk” without anyone deciding so.
What public frameworks say
Human oversight is not only an Of One idea. Two public frameworks are worth knowing.
The EU AI Act, Article 14. For AI systems the Act classes as high-risk, Article 14 requires that they be designed so that people can effectively oversee them while they are in use. Among other things, the people overseeing must be able to stay aware of automation bias (the tendency to over-rely on the machine’s output), to decide not to use the system or to “disregard, override or reverse the output,” and to stop the system safely. Whether your use is high-risk under the Act is a legal question; this is a summary, not advice.
The NIST AI Risk Management Framework (AI RMF 1.0). NIST’s voluntary framework, released in January 2023, is organized around four functions: Govern, Map, Measure and Manage. One of its Map outcomes is that processes for human oversight are defined, assessed and documented. It also notes that human-AI setups can span from fully autonomous to fully manual, and that human roles in decision making and oversight need to be clearly defined and differentiated.
Both frameworks point to the same practical habit as Of One’s gates: decide in advance where a person stays in charge, write it down, and make sure that person can actually stop the machine.
A gate table for a small business (illustrative)
This table is invented for a made-up eight-person marketing agency that uses AI agents for email, bookkeeping, scheduling and client work. It is a starting point, not a standard. Adjust the owners, limits and review dates to your business.
| Move an AI agent might make | Reversible? | Gate category | AI may do alone | Human gate (owner by role) | Review or expiry |
|---|---|---|---|---|---|
| Draft a reply to a client email | Yes, until sent | Reputation | Draft and queue | Account lead approves before sending to clients | Review the rule quarterly |
| Send a routine appointment reminder from an approved template | Mostly | Reputation | Send | Standing approval: the account lead approved the template | Recheck the template every 6 months |
| Publish a social post for a client | Partly (it can be deleted, but people may have seen it) | Reputation | Draft and schedule as a draft | Account lead approves each post | Per post |
| Pay a vendor invoice | No | Money | Match invoice to purchase order and flag mismatches | Owner approves any payment | Per payment |
| Issue a refund to a client | No | Money, reputation | Prepare the refund and the reason | Owner approves; a standing approval under a set amount can be granted with an expiry | Standing approval expires in 90 days |
| Change a client’s contract terms | No | Law | Compare versions and flag changes | Owner signs; a lawyer reviews anything unusual | Per contract |
| Screen or reject job applicants | No, for the applicant | Jobs, rights | Summarize applications against the written criteria | Hiring manager reads every application the AI would reject | Per hiring round |
| Delete client data | No | Law, rights | List what would be deleted and why | Owner approves after checking the client agreement | Per request |
| Change prices on the website | Yes, but customers may already have bought | Money, reputation | Propose new prices with reasons | Owner approves | Per change |
| Reorder office supplies under a small set limit | Mostly (returns possible) | Money | Order | Standing approval by the owner, under a set monthly limit | Limit expires at year end |
A few things to notice:
- The AI does real work at every row. The gate sits at the moment of commitment, not at the start.
- Standing approvals expire. “The AI can refund small amounts” is a standing approval: a named owner grants it in advance, with a limit and an end date, just as Of One requires for an accepted risk. When it expires, someone has to decide again.
- Reputation catches more than people expect. A message that goes out under your name cannot be unsent.
- Jobs get a gate even when the AI only filters. Rejecting a candidate is a one-way move for that person.
Do it today
- List every action your AI tools can take without asking anyone.
- Mark each one: can you undo it? Does it touch law, health, money, safety, rights, jobs, education, policy or reputation?
- Put a named owner on every row that gets a yes.
- For anything you let the AI do alone, write a limit and an expiry date.
- Check that each owner can actually stop the tool, not just read its output.
Gates are one part of the map; see What goes on a decision map. To make an AI assistant respect gates in its answers, see How to give an AI a decision harness. The method page covers the move step in full.
If you want help drawing gates for your own team, Utlyze offers Consult at $400 an hour in 5-hour blocks, and Build, from $15,000 a month, for a dedicated team that builds with you and is on call 24/7.
Sources
- ofone-skillchain/SKILL.md at main · CryptoJym/ofone-skillchain · GitHub · Utlyze (GitHub) · 2026-05-21
- ofone-skillchain/docs/question-geometry-engine.md at main · CryptoJym/ofone-skillchain · GitHub · Utlyze (GitHub) · 2026-08-01
- ofone-skillchain/examples/strategy-micro.json at main · CryptoJym/ofone-skillchain · GitHub · Utlyze (GitHub) · 2026-05-17
- Article 14: Human Oversight | EU Artificial Intelligence Act · EU Artificial Intelligence Act (artificialintelligenceact.eu) · 2026-09-01
- Artificial Intelligence Risk Management Framework (AI RMF 1.0) · National Institute of Standards and Technology · 2023-01-26
- EX-99.1 · Amazon.com, Inc. (SEC EDGAR filing) · 2016-04-05
Researched and drafted with AI assistance, checked against the sources above.
Run it as a business of one.
Begin →