Blog

Threshold values for AI decisions are becoming a legal design variable

China's agent rules and the AI Act make thresholds for AI-assisted decisions explicit. What does that mean for high-trust workflows?

· Victor Angelier

On 15 July 2026 the Implementation Opinions on Intelligent Agent Governance came into force in China. According to an analysis by AI Governance, this is the first jurisdiction with regulation aimed exclusively at AI agents. At the heart of the scheme is a three-tier decision-authorisation framework that classifies agent actions by consequentiality: routine, important and high-consequence. For the higher levels, prior human approval and stricter audit logs are mandatory, and organisations must document the autonomy and thresholds of their agents before they are deployed.

That is more than a detail. It anchors an idea that has so far mostly been treated as an internal best practice: the moment at which an AI system may act autonomously and the moment at which a human must be brought in is no longer a vague UX trade-off, but an explicit boundary value that you set in advance and can check afterwards.

The European line: oversight as a risk-bound threshold

Europe arrives at the same point via a different route. The consolidated redline of the AI Act with the Digital Omnibus on AI (version of 30 July 2026) confirms that the obligation to provide effective human oversight remains in place, and that this oversight must be commensurate with risk and autonomy. The AI Act does not prescribe fixed numerical thresholds, but it does require that high-risk systems are designed so that people can intervene at risk-based boundary values: deciding not to use the system, catching anomalies and countering automation bias.

The analysis by Casys.ai of Article 4 after the Digital Omnibus adds to this. AI literacy and human oversight remain mandatory, but organisations no longer have to meet an abstract 'sufficient' norm. They do, however, have to demonstrate that their oversight staff are appropriately trained, and that high-impact decisions receive a higher level of oversight than routine tasks. The message: threshold values may be context-dependent, but you must make them explicit and justify them.

From norm to concrete decision bands

What do those thresholds look like technically? The Art.14 developer guide by Sota.io translates the oversight obligation into a classification scheme for agent actions with four bands: allow, warn, require_approval and block. Which band an action falls into depends on a combination of factors: the authority of the action, the consequences, the reversibility, the data sensitivity, the model confidence and the downstream impact. Confidence and anomaly thresholds thereby determine when synchronous human review becomes mandatory.

The practical framework by Kla.digital makes this even more concrete in policy language. There, require_approval applies to material, hard-to-reverse, rights-affecting, sensitive, novel or low-confidence actions. block applies where mandatory evidence is missing, destinations are unknown or components are unauthorised. Organisations set their own authority and consequence thresholds and project these onto their agents.

For anyone working with high-trust information, this comes close to daily practice. In healthcare, a summary of a file might fall under warn, while a proposed medication change is always require_approval. In law, looking up case law can be autonomous, but filing a court document requires approval. In finance, a categorisation can be routine, while a transaction above a certain amount or to an unknown beneficiary is blocked.

Thresholds must be visible and verifiable

The common thread through all sources: it is not enough to define thresholds; you must also be able to demonstrate that AI-assisted decisions stayed within them. China requires audit logs, the AI Act requires demonstrably effective oversight, and the practical frameworks revolve around traceable decision rules. This shifts the question from which thresholds to how you enforce and verify them.

At that point, a verification layer such as IamVera.ai can play a role. Vera is not a chatbot and not its own language model, but a privacy-focused verification layer for professionals who work with confidential information. Vera can route a task through selected independent AI models and make the verification steps, corrections, disagreements and sources visible for inspection. That supports review and gives more insight into what happened; it is not a guarantee that every outcome is correct and does not remove all inaccuracies or fabrications.

That visibility ties in with the idea of threshold values as auditable decision rules. Vera does not define those thresholds itself, but makes it inspectable, per workflow, how models arrived at an outcome. For protecting sensitive content there is the Semantic Privacy Shield: sensitive document values can be replaced by synthetic, session-only equivalents on EU infrastructure before AI processing, after which the original values can be restored locally. The workflow is fail-closed: if the privacy check fails, the document is not sent onward. You can read more about this on the Privacy Shield page and the evidence page.

Responsibility for designing the threshold values — which action falls into which band, per risk category, confidence band and jurisdiction — remains with the organisation. And the professional final judgement always remains with the user. What the developments of July and August 2026 make clear is that these thresholds are no longer optional or implicit: they are becoming an explicit, documentable design variable in every AI landscape that works with sensitive or high-trust information.

← All articles