A Human Approval Button Does Not Tell You Who Decided

A human approval click does not establish who made an AI agent's underlying decisions. Accountable approval requires organizations to separate the judgments inside an action and define the evidence, authority, refusal rights, escalation, and records attached to each one.

A Human Approval Button Does Not Tell You Who Decided

An AI agent at a Japanese company is ready to send personalized marketing emails to 12,418 customers. It selected the recipients from the customer relationship management system, generated the copy, optimized the timing, and prepared the campaign for execution. The marketing director's screen says “Approved.”

What did the director approve? The wording, the recipient list, the use of personal data, the campaign's scale, or the inclusion of customers who would normally be excluded? The interface does not say.

This is a hypothetical scene, not a documented incident. It isolates a problem that appears whenever an AI agent turns one visible action into a chain of hidden judgments. A human click can confirm that a workflow passed through a person. It cannot establish which decision that person made or had the authority to make.

The governing question is therefore precise: whose judgment does a human approval button represent?

AI Agents Turn Instructions into External Action

IBM defines an AI agent as a system that autonomously performs tasks by designing workflows with available tools. Unlike a chatbot that waits for another prompt, an agent can decompose a goal, call external tools, interact with other agents, revise its plan, and act in an external environment.

IBM's explanation is vendor-authored guidance, not an independent standard. It nevertheless identifies an important operating structure. Three groups influence an agent's behavior: the developers who design and train it, the team that deploys it and provides access, and the user who supplies its goal and available tools. Each group shapes what the agent can do. None automatically becomes the final authority for every resulting business judgment.

This distribution matters because the email campaign is not one decision. Recipient eligibility, permitted data, copy, price or offer, scale, timing, exceptions, and response to an anomaly are different judgments. The agent may perform all of them in one workflow, while the organization has assigned authority for only some of them.

Safety Controls Support Judgment but Do Not Allocate Authority

IBM recommends activity logs, interruption, unique agent identifiers, and human supervision. It specifically presents human confirmation as a best practice before high-impact actions such as mass email or financial trading. These controls address real operational risks.

Their limits are equally important. An activity log can show what happened without identifying who had authority to accept the outcome. An identifier can trace an agent to its developers, deployers, and user without defining how responsibility is divided among them. An interrupt control can stop a process without deciding who may stop it, under which conditions, or when interruption would create greater harm. A confirmation step can place a person in the workflow without giving that person a meaningful decision.

These are tools for control and evidence. They do not, by themselves, allocate legitimate decision authority.

Japan's Policy Has Shifted from Human Presence to Human Responsibility

Japan's Ministry of Internal Affairs and Communications and Ministry of Economy, Trade and Industry published AI Guidelines for Business, Version 1.2 on 31 March 2026. The guidelines describe an AI agent as an AI system that perceives its environment and acts autonomously to achieve a specified goal. Their supporting material recognizes that an agent may place an unintended order or delete a file and that human monitoring alone may struggle with high-speed interaction among AI systems.

The guidelines are risk-based, non-binding guidance. They do not impose a universal legal requirement for human approval before every agent action. Their treatment of human involvement includes concerns such as fairness, over-reliance, traceability, and control. It should not be presented as a complete allocation of authority for a particular workflow.

The policy context developed further during 2026. An April working paper from the Cabinet Office raised the concern that a person could be placed in a human-in-the-loop process only to bear responsibility. A June draft of Japan's next AI Basic Plan distinguished three approaches: human-in-the-loop, where a person directly participates in task execution; human-on-the-loop, where AI executes while a person designs and monitors the overall process; and human-in-the-lead, where people retain control of decisions and value creation.

That draft is no longer the latest policy status. On 14 July 2026, the Cabinet approved the Second-Phase AI Basic Plan. The final plan retains those three approaches as concepts under discussion. It states that people should hold responsibility for decisions, places human agency at the center of judgment responsibility, calls for continued examination of responsibility boundaries when autonomous AI causes harm, and asks what judgments people should perform in their relationship with AI.

The plan is national policy, not a rule that assigns the marketing director's authority. It does establish the direction of travel: the relevant question is no longer whether a human appears somewhere in the process. The question is whether human involvement carries real judgment, responsibility, and control.

Approval Requires More Than Visibility

Human approval becomes substantive only when the approver has five things.

First, the organization must define the object of judgment. The marketing director should know whether the request concerns campaign scale, copy, recipient eligibility, data use, exceptions, or all of them.

Second, the approver must receive relevant evidence. For the campaign, that evidence may include the recipient count, inclusion and exclusion rules, data fields used, changes from approved copy, detected anomalies, historical complaint rates, and the reversibility of the proposed action.

Third, the approver must have enough time and skill to evaluate that evidence. Presenting 12,418 generated messages moments before dispatch does not create effective oversight.

Fourth, the role must carry authority to approve, reject, narrow, delay, or return the proposal. A screen that permits only confirmation turns approval into ratification.

Fifth, the process needs an escalation route. A marketing director may own campaign strategy while a privacy officer decides whether a new use of sensitive customer data is permitted and legal counsel evaluates a potentially misleading claim. “Ask a human” is not an authority model.

One Approval Must Be Decomposed into Distinct Judgments

The campaign should be designed as several linked decisions rather than a single send action.

Recipient eligibility

The organization must decide which customer segments may be contacted and which exclusions are mandatory. The agent can apply approved eligibility and suppression rules. A new segment, an unclear consent record, or an exception customer should trigger review by the role authorized to change eligibility.

Permitted data use

The agent should use only approved data fields for approved purposes. A proposed use of sensitive attributes, inferred characteristics, or data collected for another purpose should stop the workflow and route the question to the designated privacy authority.

Message and offer

The agent can personalize language within an approved template and apply prohibited-expression checks. A new claim, special price, difficult-to-reverse offer, or potentially misleading formulation requires the business or legal authority assigned to that judgment.

Scale and timing

The organization can pre-authorize routine campaigns within a defined scope. An unusually large audience, an abnormal sending window, or a mismatch between customer and delivery systems should trigger a stop or a higher level of approval.

Exceptions and response

Unverified consent, suppression-list conflicts, abnormal complaint indicators, external-tool failures, and policy-check failures need predefined responses. The safe action may be to stop, reduce the audience, switch to manual handling, or proceed with a constrained subset. The workflow must name who can choose among those responses.

Breaking the send action into these judgments reveals that one executive may not legitimately approve all of them. The interface should reflect the allocation of authority instead of collapsing it.

Decision Design Makes Approval Institutionally Legible

Decision Design is a judgment architecture framework for structuring authority, accountability, and decision boundaries in AI-augmented organizations. Decision Design is not about improving decisions alone; it is about designing the authority structure within which decisions become institutionally legitimate.

For each recurring judgment, Decision Design asks who holds legitimate authority, what role AI may perform, which evidence and data may inform the judgment, when the process must stop or escalate, who owns the outcome and explanation, which record preserves accountability, and which event triggers review.

Decision Design complements law, governance, ethics, risk management, organizational design, automation, and technical controls. It does not replace them or establish legal compliance. It is a framework proposed by the author, not a law, public standard, or settled academic concept.

Decision Boundaries Define the Scope of Legitimate Delegation

A Decision Boundary is the institutional line between judgments delegated to AI and judgments retained or accepted by a human or organization. Decision Boundaries are not operational thresholds; they are institutional demarcations of legitimate authority.

An operational threshold can enforce part of a boundary. A maximum recipient count can block execution, for example. The institutional boundary also records who authorized that limit, what class of campaign it covers, who may approve an exception, and who owns the resulting action.

Within the hypothetical campaign, the AI agent might be authorized to select customers under approved criteria, use approved data fields, personalize an approved template, check suppression lists, optimize sending time within a defined window, and execute a campaign within a pre-approved scale. Human review of every message could add delay without adding meaningful judgment.

The retained boundary might cover new customer segments, sensitive attributes, changed processing purposes, campaigns above the approved scale, new pricing, hard-to-reverse offers, legally sensitive claims, and customers subject to complaint or exception handling. The organization should assign each category to a role with the relevant authority. Marketing, privacy, legal, and information security leaders need not share a single undifferentiated approval.

The boundary must also define who may change it. A new model, CRM integration, data source, legal requirement, complaint pattern, or material incident can change what delegation is supportable. A vendor update should not silently expand the agent's authority.

A Decision Log Connects Technical Events to Institutional Authority

A Decision Log is a structured record of who made or authorized a judgment, what evidence supported it, which conditions applied, and how the organization reached the outcome. Decision Logs do not merely record outputs; they preserve accountability continuity across distributed judgment processes.

For the campaign, the Decision Log should connect the data version, recipient rules, generated content, policy checks, tool calls, agent identifiers, anomalies, approval object, approver, authority basis, reasons, exceptions, stops, and delivery result. Access and retention rules must protect the record because it may contain personal data and commercially sensitive judgments.

This is more than an activity log. The technical log might show that an agent called an email-delivery API. The Decision Log shows why that action fell within an approved boundary, who authorized the boundary, whether an exception occurred, and who remains responsible for explaining the result.

The distinction is especially important when no one clicks immediately before execution. A named owner can authorize a bounded class of routine campaigns in advance. If the Decision Log shows that all authorized conditions were satisfied and no stopping event occurred, automation represents a prior placement of authority rather than an absence of responsibility.

Replace “Approved” with a Decision That Can Be Refused

Return to the director's screen. A credible interface would not display one unexplained approval state. It would show the judgments requiring that director's authority, the relevant evidence, unresolved exceptions, and the consequences of proceeding. It would permit rejection, narrowing, revision, and escalation.

The problem with the 12,418-recipient campaign is not the number itself. The problem is that no one can tell whether “Approved” applies to the audience, data, message, scale, timing, exceptions, or the entire bundle. A visible human has absorbed responsibility without a legible judgment.

Organizations do not solve that problem by adding another confirmation dialog. They solve it by decomposing the action, assigning authority, enforcing boundaries, and preserving the connection between each judgment and its owner.

FAQ

Does Japan require human approval before every AI agent action?

No. AI Guidelines for Business, Version 1.2 are non-binding, risk-based guidance, and the Second-Phase AI Basic Plan is national policy rather than a universal approval rule. Both support meaningful human involvement and responsibility, but neither requires a human click before every action in every use case.

What makes human approval substantive rather than ceremonial?

Substantive approval has a defined object, relevant evidence, enough time and skill for review, authority to refuse or modify the proposal, and an escalation route. A person who can only confirm an AI recommendation is not exercising full approval authority.

Must a human inspect every AI-generated email?

No. An organization can authorize an AI agent to personalize and send messages within approved templates, data uses, recipient rules, scale, and stopping conditions. Human authority should focus on judgments outside that boundary and on authorized review of the boundary itself.

What is the difference between an activity log and a Decision Log?

An activity log records system events such as tool calls and message delivery. A Decision Log connects those events to authority by recording the governing boundary, decision owner, evidence, reasons, exceptions, and outcome.

Is Decision Design a legal or regulatory requirement?

No. Decision Design is a judgment architecture framework proposed by Ryoji Morii. It helps organizations translate law, policy, governance, ethics, risk management, and technical controls into the authority structure of a recurring judgment, but it does not replace those disciplines.

References

Decision Design is a judgment architecture framework proposed by Ryoji Morii, founder of Insynergy Inc., for structuring authority, accountability, and decision boundaries in AI-augmented organizations.

Japanese version is available on note.

Open Japanese version →
日本語版を読む (Japanese) →