Should an AI agent need permission before spending money?
Imagine an assistant booking travel or replenishing groceries. The right boundary might depend on cost, reversibility, and how much you trust it.
Undo can lower the cost of a mistake. It cannot always erase consequences for other people.
Reversibility is a spectrum. Restoring an edited draft is different from recalling a published message or recovering disclosed private information. A claim that an action is reversible should identify what can be restored, by whom and within what time.
An agent posts an announcement and deletes it a minute later. The page is gone, but some people have read or copied it. Contrast that with reorganizing a private draft folder whose prior state can be restored.
Undo makes it easier to experiment and delegate.
An action may be technically reversible but still expose information or disrupt someone’s work.
Background reading for the tradeoff. Scenarios and discussion questions are editorial examples.
Practical guidance on tool permissions, memory isolation, oversight and agent failure handling.
A framework for identifying, measuring and managing generative AI risks across the system lifecycle.
Sources reviewed 13 September 2026. Product documentation can change. How we use evidence
Imagine an assistant booking travel or replenishing groceries. The right boundary might depend on cost, reversibility, and how much you trust it.
Drafting a message and sending it are different kinds of action. Sending can create commitments, share information, or affect a relationship.
Cleaning a workspace can be helpful. A mistaken deletion may be difficult to reverse.