Skip to content

The consequence boundary

What are consequential AI actions?

A consequential AI action is an action by an AI agent that changes something outside the model and matters if it is wrong, such as moving money, changing a record or contacting a customer. These actions need a decision before they execute. Everyday read-only work, such as looking up information, usually does not.

AI Acts. Crelis Decides. · Runtime authorization for AI agents

The blue clay Crelis robot rests one hand on a lever and raises the other in a wait gesture as a cream clay agent reaches for it; behind them another agent reads a book undisturbed.
What it changes
Money, records, customer contact
When it is decided
Before the action executes
Outcome
Allow, require human approval, escalate, or block
Everyday reads
Usually no decision needed

Why the line matters

Reading is not the same as changing

When an AI agent looks something up, the enterprise is left as it was. When it moves money, changes a record or sends a message in your name, something outside the model is now different.

That difference is the consequence boundary. On one side is everyday read-only work. On the other side are the actions that change something outside the model and matter if they are wrong. Those actions need a decision before they execute.

Each enterprise draws the line in its own policy. A simple test helps: ask how hard the action would be to put right if it were wrong.

A read leaves things as they were; a consequential action does not.

Where the line falls

Not every action carries the same weight

An AI agent can read, draft or change something. The consequential action is the kind that is decided before it executes.

Reading information

Looks something up and leaves things as they were

Usually none

Drafting or suggesting

Prepares something for a person to review

The person who reviews it decides

Routine change

Changes something small that is easy to put right

When your policy says so

Consequential action

Moves money, changes a record or contacts a customer, and matters if it is wrong

Before the action executes

Actions that matter, not every action.

What counts

What a consequential action looks like

Each of these changes something outside the model, and each one matters if it is wrong.

  1. Move money

    A payment, a transfer, a refund.

  2. Change a record

    An account, a limit, a customer file.

  3. Contact a customer

    A message sent in your name.

What regulators point to

Controls at the moment an agent acts

We publish an independent, primary-sourced reference mapping SAFR, NIST AI RMF and EU AI Act requirements to controls at AI-agent execution time. It cites the source documents and implies no endorsement.

If you are mapping your agents

Questions to ask about your agents' actions

A short list for the teams that run your AI agents. These are questions, not answers.

  1. 01Which of our agents' actions change a system of record, and which just read?
  2. 02Has anyone written down which of those actions are consequential?
  3. 03If a given action were wrong, who would have to put it right?
  4. 04Which consequential actions should wait for a person?
  5. 05What happens to a consequential action if the authority cannot be reached?
  6. 06After a consequential action, can we show what was decided?

FAQ

Consequential actions, in short answers

The questions people ask about which AI agent actions need a decision.

What is a consequential AI action?

A consequential AI action is an action by an AI agent that changes something outside the model and matters if it is wrong, such as moving money, changing a record or contacting a customer. These actions need a decision before they execute. Everyday read-only work, such as looking up information, usually does not.

Which AI agent actions need approval?

The consequential actions that your policy says should wait for a person. Policy decides the outcome: allow, require human approval, escalate, or block. How an approval is decided and recorded is explained on the runtime authorization page.

Why do AI agent writes differ from reads?

A read retrieves information and leaves things as they were. A write changes something outside the model: a payment is sent, a record is altered, a customer is contacted. The two carry different risk, so the decision is placed where an agent does something consequential.

Does every AI agent action need a decision before it executes?

No. The decision is for the moment an AI agent does something that matters, not for every step it takes. Everyday read-only work is untouched. The decision itself is explained on the runtime authorization page of this site.

Are all AI agent actions that change systems consequential?

No. Consequential actions are a subset of the actions that change something. A change is consequential when it matters if it is wrong: it moves money, alters a record people rely on, or reaches a customer. Each enterprise sets that line in its own policy.

Can reading data be a consequential action?

Usually not. A read retrieves information and leaves things as they were, so nothing outside the model changes. Each enterprise draws the line in its own policy, and that policy can name any action the enterprise decides matters.

What does GREENLIGHT decide about a consequential action?

Before an AI agent does something that matters, GREENLIGHT decides whether it should happen: allow, require human approval, escalate, or block. Every allowed action earns an execution visa, and every decision is recorded as proof. Crelis authorizes or routes the action; your own system executes it.

Give your agents a green light — safely.

Start in shadow mode on non-production traffic. See every decision GREENLIGHT would have made — before you let it make one.