AI Agent Approval Gate: Approve the Write

Three places to put an approval gate, why a gate that always gets a yes protects nothing, and what an approver needs to see before one tap commits a change.

By Harinderpal Hanspal on July 2026. Updated October 2026

An approval gate protects something only when it sits on the write that commits a change and shows the approver the result, not the request. Anthropic reports that users approve 93% of permission prompts, which is what a gate on every step produces.

The agent drafts freely; a person approves the write that commits the agendaSketch of an agenda agent. Drafting stays inside the line, where a wrong answer costs a regeneration. Writing the agenda crosses the line, so a person approves it. The gate goes on the write, not on the draft.inside: wrong = regenerateoutside: wrong = lost trustAgent draftsthe agendaPending, inthe pageAgenda goes liveGATEone tap, on the agenda pagegate the write,not the draft
The agent drafts freely; a person approves the write that commits the agenda

Picture an agent that proposes next week's maintenance work orders. It reads open faults, checks which technicians are free, and drafts a schedule. The question for a plant is where a person has to say yes.

Three places to put an AI agent approval gate

Gate on What a person reviews What goes wrong
Nothing Nothing The write replaces the schedule technicians were already working from, and the first reviewer is whoever opens it on Monday
Every step Each read, each lookup, each draft Approval becomes a formality, and a gate that always gets a yes adds delay without scrutiny
The write The one call that commits One decision per change

The evidence for the middle row is Anthropic's own. In March 2026 it wrote that Claude Code users approve 93% of permission prompts, and that it built classifiers to reduce approval fatigue (Anthropic Engineering, 25 March 2026). That 93% is an approval rate. It describes how often people click yes, and says nothing about how often the prompts were safe. A gate that asks about everything trains its approver to stop reading.

The evidence for the top row is the opposite failure. In July 2025 a coding agent deleted a production database during a declared freeze, and the company's chief executive called it unacceptable and said it should never be possible (Fortune, 23 July 2025). That is one reported incident, not a rate. It shows what an ungated write costs when it goes wrong.

A wrong draft costs a regeneration. A wrong write replaces what was there. The gate belongs on the second.

What the approver needs to see

A gate on the write still fails if the approver sees only the request. "Run the schedule update" tells the person nothing. The card should show what will change: which orders move, which technicians are reassigned, what the old schedule said. A preview of the result turns a click into a decision.

Two more details decide whether the tap means anything. The approval has to reach the run that is waiting, so that a second place to approve cannot leave the agent paused with the row marked done. And the second person who has the screen open has to see that the card is already settled.

What the guidance says

OWASP lists excessive agency as risk LLM06 and recommends human-in-the-loop control, requiring a human to approve high-impact actions before they are taken, whether the cause is a hallucination or a prompt injection (OWASP LLM Top 10, 2025). Deloitte's 2026 survey of 3,235 senior leaders found that only one in five companies has a mature model for governing autonomous agents (Deloitte, State of AI in the Enterprise 2026).

For systems classed as high-risk under the EU AI Act, Article 14 requires that the overseer can decide not to use the output, override or reverse it, and stop the system with a stop button. The text of that article, as published on artificialintelligenceact.eu, applies to high-risk systems, not to every agent.

Questions to put to a vendor about the gate

  1. Which actions does the agent take without asking, and which wait for a person?
  2. Does the person approve the request or the result?
  3. If there are two places to approve, does either one leave the run paused?
  4. What does the approver see if the agent proposes a change and never calls the write?
  5. Who can approve, and is that recorded with the decision?

A vendor who answers the first question with "everything is configurable" has not answered it.

Drawn from OWASP's LLM Top 10 (2025), Anthropic Engineering (25 March 2026), Fortune (23 July 2025), Deloitte's State of AI in the Enterprise 2026 and the EU AI Act's Article 14 as published on artificialintelligenceact.eu, all read on 6 October 2026. The reasoning about where a gate sits is ours.

Related notes

Related insights

Related paper: Governing agents in production: what to ask before an agent acts