FIELD NOTE / INSTAGRAM
Ask who owns each AI gate.
The complete written thought and the evidence behind it. The video edition will follow its public release.
The written argument is here.
This approved Instagram edition is on the journal now. Its video player and original platform link will appear after each public release is verified.
Ask who owns each AI gate.
Video caption
Ask who owns each AI gate.
Availability is not delegated authority.
Record legal review, provider route and application decision.
An answer can inform; the tool must decide.
#EricFieldNotes
Full written post / accessibility read
Think of a case approval as three doors. Law determines whether a deployment or use is allowed. A provider decides whether to supply its model for a request. Your organization decides whether this user may approve this case. None of those doors substitutes for the others.
Imagine a support agent drafting a refund. The model writes a valid explanation, but the logged-in operator lacks refund authority. A prompt instruction to 'only approve authorized refunds' is not a permission check at the payment boundary.
For consequential actions, make the audit record show current policy owner, provider response category and user/tool permission result. Where law matters, record counsel's deployment decision rather than asking a model to pronounce legality.
Before the refund API runs, check the operator, target, amount and current policy in code. Do this because no model answer, refusal or grammar can grant authority the application did not give.
#EricFieldNotes
Four-beat scene transcript
1. Ask who owns each AI gate.
Think of a case approval as three doors. Law determines whether a deployment or use is allowed. A provider decides whether to supply its model for a request. Your organization decides whether this user may approve this case. None of those doors substitutes for the others.
Visual: One action can pass a model and fail your business rule.
2. The model can answer the wrong person's request.
Imagine a support agent drafting a refund. The model writes a valid explanation, but the logged-in operator lacks refund authority. A prompt instruction to 'only approve authorized refunds' is not a permission check at the payment boundary.
Visual: Availability is not delegated authority.
3. Separate the three receipts.
For consequential actions, make the audit record show current policy owner, provider response category and user/tool permission result. Where law matters, record counsel's deployment decision rather than asking a model to pronounce legality.
Visual: Record legal review, provider route and application decision.
4. Put permission at the effect boundary.
Before the refund API runs, check the operator, target, amount and current policy in code. Do this because no model answer, refusal or grammar can grant authority the application did not give.
Visual: An answer can inform; the tool must decide.
Research and claim limits
- OpenAI Usage Policies (S133)
- European Commission: AI Act enforcement (S135)
- Regulation (EU) 2024/1689, official text (S136)
The examples identified as illustrative or simulated are design probes, not reported incidents. Vendor specifications do not establish workload performance.