Runtime authority for AI agents.

Alethesis AI puts every high-risk AI agent action in front of the accountable human, before it runs.

Where runtime authority fits.

Today's stack governs the whole agentic AI system.
Runtime authority governs each consequential action.

Scope · The whole AI-agent system

AI governance

Governs the system before it runs

Registers systems, checks framework alignment, writes documentation.

AI inspection

Sees what the system is doing

System-level context, controls and behavioral monitoring.

Runtime enforcement

What the agent can do

Guardrails inside the system, applied to every call.

  • Policies + regulatory regimes
  • Evidence of every decision
  • Violations + context
The missing layer

Scope · One consequential action

Runtime authority

Who is authorized and accountable for this action?

Deterministic logic, outside the agent, with evidence of every decision.

  1. Before it runs

    AI governance

    Governs the system before it runs.

    AI inspection

    Sees what the system is doing.

  2. While it runs

    Runtime enforcement

    Decides what the agent can do.

  3. The missing layer · one action at a time

    Runtime authority

    Decides who is accountable for each action.

Three ways to oversee AI agents.

Guardrails

“Is this allowed?”

Unit of governance
The whole system
Risk logic
Internal to the system, probabilistic
Effect
Allow or block

Human-in-the-loop

“Did a human approve it?”

Unit of governance
Every action
Risk logic
Manual human review
Effect
Everything waits

Alethesis AI

Runtime authority

“Who is accountable for this action?”

Unit of governance
A single consequential action
Risk logic
External to the system, deterministicEncodes your process logic
Effect
Only critical actions pause, until the accountable human decides

Runtime authority and EU AI Act oversight.

Read the FAQ
Art. 14

Oversight while in use

High-risk AI must be effectively overseeable while it runs, not only at deployment.

Art. 26

Competent people

Deployers assign oversight to people with the competence, training and authority.

How runtime authority helps

High-risk actions reach an accountable person, and every decision is recorded. It supports your legal assessment; it doesn't replace it.

Runtime authority, explained.

What is runtime authority for AI agents?

Runtime authority determines who is authorized and accountable for each consequential action an AI agent takes. Before execution, it scores the action's risk, routes it to the accountable human when it matters and records the decision as evidence. Runtime enforcement decides what an agent can do. Runtime authority decides who answers for it.

What's the difference between AI guardrails and runtime authority?

Guardrails answer "is this action allowed?" Runtime authority answers "who is accountable for this action, and should they decide before it executes?" Guardrails govern the whole system from inside it, with probabilistic logic. Runtime authority governs a single consequential action from outside the system, with deterministic logic. An action can be permitted and still need human judgment because of its severity, scope or reversibility. Runtime authority works alongside guardrails, so consequential actions reach the right person at the right moment.

What's the difference between human-in-the-loop, human-on-the-loop and human-out-of-the-loop?

The terms describe how involved a human is when an AI system acts.

  • Human-in-the-loop (HITL): a person approves each action before it executes. Maximum control, minimum scale.
  • Human-on-the-loop (HOTL): the AI acts on its own while a person monitors and can intervene. Oversight depends on noticing problems in time.
  • Human-out-of-the-loop (HOOTL): the AI acts with no real-time human involvement. Maximum scale, no live oversight.

Is human-in-the-loop enough to oversee AI agents?

Not on its own. Classic human-in-the-loop asks a person to approve every consequential action. That doesn't scale once agents run multi-step workflows at machine speed. Agentic AI needs three things classic HITL doesn't deliver:

  • Risk-proportional routing.
  • Assignment to the right accountable human, based on context.
  • A tamper-proof record linking each human decision to the action it governed.

The shift is from "a human approves everything" to "the right human approves what matters."

Does the EU AI Act require human oversight at runtime?

For high-risk AI systems, yes. Article 14 requires them to be designed so people can oversee them effectively while they are in use, not only at deployment. Article 26 requires deployers to assign that oversight to people with the necessary competence, training and authority.

The Act does not require a human to review every decision in real time. Runtime authority helps deployers evidence effective oversight: consequential agent actions reach an accountable person, and each decision is recorded.

Close the runtime authority gap.

See runtime authority on your own agent workflows.

Request a Meeting