The Override Asymmetry: Why ABSTAIN-Plus-Human-Override Is Not Guardrails-Plus-Human-in-the-Loop

Review-only human-in-the-loop and ABSTAIN with authorized resolution look alike in a workflow diagram. Both place a human near the moment an AI system might act, and both interrupt the action's path to execution. This technical note states the architectural rule that separates the two. A human decision becomes part of authorization only when a non-bypassable, fail-closed runtime authorization boundary materially consumes the human's authority-bound input to emit the action-bound verdict on which execution depends, and that verdict is represented in an independently reconstructable authorization artifact. This is the note's operational reading of the Authorization Non-Substitution Principle for human participation. A human supplies input; the boundary emits the verdict; the authorization artifact represents the verdict. Participation that does not meet the rule may support an authorization process, but it does not itself constitute authorization. The two stipulated arrangements differ on three axes: the basis on which the human is invoked, how the human's determination enters the architecture, and the properties of the record it leaves. The second axis carries the argument and separates into two consumption events. First-order consumption, the boundary's consumption of the human's authority-bound input, is required for authorized resolution of the held action. Second-order consumption is optional: where a separately authorized policy-amending pathway exists, it may consume the resulting authorization artifact to change the policy governing later actions in a covered class. That second act changes future policy. It is not what authorized the held action. The note states workload functions over fixed-policy intervals for both arrangements, makes no claim that either is cheaper, and restricts its only rate claim to a covered recurring action class under declared conditions. Reserved action classes, in which every action returns to a human by design, fit the model without qualification. The note examines what evidence each arrangement preserves under sustained volume. Authorized resolution produces a record reconstructable with respect to policy, authority, and verdict; those properties do not establish decision quality. Whether accumulated resolutions and amendments constitute drift remains a separate analytical judgment over the record. The note provides an operational reading of Criterion 6 of the Enforcement Test Protocol, Authorized Resolution and Override Governance, defined in Observability Is Not Enforcement Version 2.0.0: what it means for an override to occur within the runtime authorization boundary rather than around it. Its relationship to On the Impossibility of Observability-Based Authorization follows Version 2.0.0 of that paper. The paper states an ex-ante authorization model and establishes a conditional information-sufficiency result: observation-only evaluation cannot guarantee correct permission resolution across states that present identical available information but require different permission outcomes for the same proposed action. Review-only HITL, as stipulated in this note, fails the model's release condition because it produces no action-bound authorization verdict on which execution depends. That failure follows from the stipulated arrangement and the model's requirements, not from a class-wide impossibility of human review. The note draws on the Authorization Artifact Test, the Authorization Boundary Integrity Model, the ABIM Evidence Requirements, the Five Tests Standard, Authority versus Authorization, and The Closed-World Bargain. It includes a doctrinal mapping to the five tests and the Composition Test. Independent reconstruction, Input Integrity, material consumption, and non-bypassability require separate demonstrations. The mapping is not a conformance claim about any implementation. The argument is structural and uses a stipulated comparator. It makes no empirical claim about deployment economics or policy maturation, and no claim about any particular implementation, including any FERZ implementation. The note also states what its properties do not reach. Where authorized resolution supplies material input, the boundary can bind what was presented to the resolver, the resolver's identity and authority, the applicable policy and decision time, the resolution input, and the resulting verdict. Presentation sufficiency, whether the system presented the resolver with the evidence policy requires, in a usable form and within any applicable time constraint, may be declared, traced to policy and authority, and evaluated. Deliberative adequacy, whether the resolver considered that evidence with adequate attention and judgment, does not become established by declaration. Reconstruction cannot recover a distinction the boundary did not bind. Files on this record. Override_Asymmetry_v2.3_FERZ.pdf is the note. Override_Asymmetry_v2.3_FERZ_academic.pdf is the same note on a plain shell. Override_Asymmetry_Companion_v1.1_FERZ.pdf is the companion document, The Override Asymmetry: Questions About Human Review and Authorized Resolution, Companion Version 1.1, issued with parent Version 2.3; Companion Version 1.0 was issued with parent Version 2.2. The companion answers nine questions the note attracts, each from published instruments and each with the bound on that answer stated alongside it. It introduces no doctrine and does not amend the note. The companion has no identifier of its own: cite it by title and internal version, together with the concept DOI and the version DOI of the record containing the cited copy. Version history. v2.3 (September 2026): aligns the note with On the Impossibility of Observability-Based Authorization Version 2.0.0 and the Authorization Artifact Test Version 1.3. Attributes Enforcement Test Protocol Criteria 3, 5, and 6 to Observability Is Not Enforcement Version 2.0.0, where they are defined. Replaces the former class-wide impossibility characterization with application of the ex-ante model's release condition. Distinguishes ABSTAIN from failure to produce a verdict: both block execution, but an evaluator that cannot run need not emit ABSTAIN. Separates bypassability as an enforcement finding from the Authorization Artifact Test's two prongs. Clarifies that the boundary materially consumes the human's authority-bound input, while the authorization artifact represents the resulting verdict. The three axes, workload functions, limitations analysis, and conclusions remain unchanged. Reissues the companion as Companion Version 1.1: its entries are reviewed against the Authorization Artifact Test Version 1.3, and four answers (Questions 5, 6, 7, and 9) are corrected where they stated more than the argument establishes. v2.2 (September 2026): corrects two definitions in Section 2, with conforming edits to Section 3.3 and Appendices A and B. The authorization-artifact definition no longer treats established input origin as a defining property; the artifact and its authenticated bound materials preserve the evidence against which origin and applicable admissibility conditions are assessed, and that assessment is a separate determination under Input Integrity. The override definition distinguishes the human's authority-bound input from the separate resulting verdict emitted by the boundary; the held ABSTAIN remains unresolved until that verdict exists. Both corrections align the note with the Authorization Boundary Integrity Model, the ABIM Evidence Requirements, and the Governance Taxonomy. Pins Observability Is Not Enforcement to Version 2.0.0 and the Governance Taxonomy to Version 1.7.1. Adds the companion document. The argument, workload functions, and Section 8 limitations passage are unchanged. v2.1 (September 2026): adds the Section 8 limitations passage separating presentation sufficiency from deliberative adequacy and clarifies what the workload functions do not establish. No other substantive claim changed. Citation maintenance, recorded separately in the note, adds the ABIM Evidence Requirements and updates the Authorization Artifact Test and Authorization Boundary Integrity Model edition pins. v2.0 (August 2026): supersedes the April 2026 formulation. Treats codification into policy as optional rather than definitional; separates action-scoped authorized resolution from separately authorized policy amendment; states that an unresolved ABSTAIN remains ABSTAIN and is not converted to DENY; restates the workload comparison as interval functions with a restricted rate claim; distinguishes input, verdict, and artifact throughout; aligns terminology to the authorization-artifact class term and independent reconstructability; and updates corpus references. v1.4 (April 2026): added Appendix A, Boundary Conditions. The April formulation remains available in the record's version history. Citation and license. Copyright © 2026 FERZ, Inc. This work is licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0). Cite the concept DOI 10.5281/zenodo.19772248 for the work and the version DOI 10.5281/zenodo.22943421 for this edition. Canonical page: ferz.ai. Full corpus: the FERZ community on Zenodo.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-24
DOI
https://doi.org/10.5281/zenodo.22943421
Primary Topic
Ethics and Social Impacts of AI
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

The Override Asymmetry: Why ABSTAIN-Plus-Human-Override Is Not Guardrails-Plus-Human-in-the-Loop

Edward Meyman
Zenodo (CERN European Organization for Nuclear Research)
Ethics and Social Impacts of AI
article

The Override Asymmetry: Why ABSTAIN-Plus-Human-Override Is Not Guardrails-Plus-Human-in-the-Loop

Edward Meyman
article en

Abstract

Review-only human-in-the-loop and ABSTAIN with authorized resolution look alike in a workflow diagram. Both place a human near the moment an AI system might act, and both interrupt the action's path to execution. This technical note states the architectural rule that separates the two. A human decision becomes part of authorization only when a non-bypassable, fail-closed runtime authorization boundary materially consumes the human's authority-bound input to emit the action-bound verdict on which execution depends, and that verdict is represented in an independently reconstructable authorization artifact. This is the note's operational reading of the Authorization Non-Substitution Principle for human participation. A human supplies input; the boundary emits the verdict; the authorization artifact represents the verdict. Participation that does not meet the rule may support an authorization process, but it does not itself constitute authorization. The two stipulated arrangements differ on three axes: the basis on which the human is invoked, how the human's determination enters the architecture, and the properties of the record it leaves. The second axis carries the argument and separates into two consumption events. First-order consumption, the boundary's consumption of the human's authority-bound input, is required for authorized resolution of the held action. Second-order consumption is optional: where a separately authorized policy-amending pathway exists, it may consume the resulting authorization artifact to change the policy governing later actions in a covered class. That second act changes future policy. It is not what authorized the held action. The note states workload functions over fixed-policy intervals for both arrangements, makes no claim that either is cheaper, and restricts its only rate claim to a covered recurring action class under declared conditions. Reserved action classes, in which every action returns to a human by design, fit the model without qualification. The note examines what evidence each arrangement preserves under sustained volume. Authorized resolution produces a record reconstructable with respect to policy, authority, and verdict; those properties do not establish decision quality. Whether accumulated resolutions and amendments constitute drift remains a separate analytical judgment over the record. The note provides an operational reading of Criterion 6 of the Enforcement Test Protocol, Authorized Resolution and Override Governance, defined in Observability Is Not Enforcement Version 2.0.0: what it means for an override to occur within the runtime authorization boundary rather than around it. Its relationship to On the Impossibility of Observability-Based Authorization follows Version 2.0.0 of that paper. The paper states an ex-ante authorization model and establishes a conditional information-sufficiency result: observation-only evaluation cannot guarantee correct permission resolution across states that present identical available information but require different permission outcomes for the same proposed action. Review-only HITL, as stipulated in this note, fails the model's release condition because it produces no action-bound authorization verdict on which execution depends. That failure follows from the stipulated arrangement and the model's requirements, not from a class-wide impossibility of human review. The note draws on the Authorization Artifact Test, the Authorization Boundary Integrity Model, the ABIM Evidence Requirements, the Five Tests Standard, Authority versus Authorization, and The Closed-World Bargain. It includes a doctrinal mapping to the five tests and the Composition Test. Independent reconstruction, Input Integrity, material consumption, and non-bypassability require separate demonstrations. The mapping is not a conformance claim about any implementation. The argument is structural and uses a stipulated comparator. It makes no empirical claim about deployment economics or policy maturation, and no claim about any particular implementation, including any FERZ implementation. The note also states what its properties do not reach. Where authorized resolution supplies material input, the boundary can bind what was presented to the resolver, the resolver's identity and authority, the applicable policy and decision time, the resolution input, and the resulting verdict. Presentation sufficiency, whether the system presented the resolver with the evidence policy requires, in a usable form and within any applicable time constraint, may be declared, traced to policy and authority, and evaluated. Deliberative adequacy, whether the resolver considered that evidence with adequate attention and judgment, does not become established by declaration. Reconstruction cannot recover a distinction the boundary did not bind. Files on this record. Override_Asymmetry_v2.3_FERZ.pdf is the note. Override_Asymmetry_v2.3_FERZ_academic.pdf is the same note on a plain shell. Override_Asymmetry_Companion_v1.1_FERZ.pdf is the companion document, The Override Asymmetry: Questions About Human Review and Authorized Resolution, Companion Version 1.1, issued with parent Version 2.3; Companion Version 1.0 was issued with parent Version 2.2. The companion answers nine questions the note attracts, each from published instruments and each with the bound on that answer stated alongside it. It introduces no doctrine and does not amend the note. The companion has no identifier of its own: cite it by title and internal version, together with the concept DOI and the version DOI of the record containing the cited copy. Version history. v2.3 (September 2026): aligns the note with On the Impossibility of Observability-Based Authorization Version 2.0.0 and the Authorization Artifact Test Version 1.3. Attributes Enforcement Test Protocol Criteria 3, 5, and 6 to Observability Is Not Enforcement Version 2.0.0, where they are defined. Replaces the former class-wide impossibility characterization with application of the ex-ante model's release condition. Distinguishes ABSTAIN from failure to produce a verdict: both block execution, but an evaluator that cannot run need not emit ABSTAIN. Separates bypassability as an enforcement finding from the Authorization Artifact Test's two prongs. Clarifies that the boundary materially consumes the human's authority-bound input, while the authorization artifact represents the resulting verdict. The three axes, workload functions, limitations analysis, and conclusions remain unchanged. Reissues the companion as Companion Version 1.1: its entries are reviewed against the Authorization Artifact Test Version 1.3, and four answers (Questions 5, 6, 7, and 9) are corrected where they stated more than the argument establishes. v2.2 (September 2026): corrects two definitions in Section 2, with conforming edits to Section 3.3 and Appendices A and B. The authorization-artifact definition no longer treats established input origin as a defining property; the artifact and its authenticated bound materials preserve the evidence against which origin and applicable admissibility conditions are assessed, and that assessment is a separate determination under Input Integrity. The override definition distinguishes the human's authority-bound input from the separate resulting verdict emitted by the boundary; the held ABSTAIN remains unresolved until that verdict exists. Both corrections align the note with the Authorization Boundary Integrity Model, the ABIM Evidence Requirements, and the Governance Taxonomy. Pins Observability Is Not Enforcement to Version 2.0.0 and the Governance Taxonomy to Version 1.7.1. Adds the companion document. The argument, workload functions, and Section 8 limitations passage are unchanged. v2.1 (September 2026): adds the Section 8 limitations passage separating presentation sufficiency from deliberative adequacy and clarifies what the workload functions do not establish. No other substantive claim changed. Citation maintenance, recorded separately in the note, adds the ABIM Evidence Requirements and updates the Authorization Artifact Test and Authorization Boundary Integrity Model edition pins. v2.0 (August 2026): supersedes the April 2026 formulation. Treats codification into policy as optional rather than definitional; separates action-scoped authorized resolution from separately authorized policy amendment; states that an unresolved ABSTAIN remains ABSTAIN and is not converted to DENY; restates the workload comparison as interval functions with a restricted rate claim; distinguishes input, verdict, and artifact throughout; aligns terminology to the authorization-artifact class term and independent reconstructability; and updates corpus references. v1.4 (April 2026): added Appendix A, Boundary Conditions. The April formulation remains available in the record's version history. Citation and license. Copyright © 2026 FERZ, Inc. This work is licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0). Cite the concept DOI 10.5281/zenodo.19772248 for the work and the version DOI 10.5281/zenodo.22943421 for this edition. Canonical page: ferz.ai. Full corpus: the FERZ community on Zenodo.

Zenodo (CERN European Organization for Nuclear Research)
Ferghana Polytechnical Institute (UZ), Ferro (United States) (US)
Peace, Justice and strong institutions
Openalex Percentile: Top 7%
Ethics and Social Impacts of AI
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.