Guarded Automation: Agents That Run Operations Module 4 · Approval and Revocation

Which Oversight Rules Reach Meridian

Last reviewed · content updated

Advanced

What you'll learn

~18 min
  • Read one rule at a time and say whether it binds Meridian, and by what mechanism, rather than assuming guidance equals obligation
  • Name the contract mechanism that could carry a federal oversight duty onto a commercial vendor's agent, and state that it applies only if the clause is in the contract
  • State plainly which regulators have published nothing on agent actions, and why that gap is not an opening
ℹLeadership brief

What it is: one table, one row per named rule, stating who it binds, how it reaches Meridian if at all, and what it would require of a single agent action.

What it buys: the difference between “a document mentions agents” and “our contract requires this” — the gap most oversight overclaiming lives in.

What to fund: one legal review of the interconnect contract’s flow-down language, once, rather than a compliance program built against guidance nobody signed.

Before the detail — Artifact: the applicability table below, accepted when every row states a binding party and a path to Meridian, or plainly states there is none. Status of what follows: guidance and contract terms, named precisely — never “requires” where the document itself does not say so.

Prompt first: build the table, not the compliance program

List every oversight rule your team has heard cited about AI agents -
guidance documents, agency memos, sector regulator statements,
standards drafts. For each one, fill four columns:
binding party - who does this actually bind, by name?
modality - guidance / binding rule / contract term /
vocabulary only / not published
path to us - how, if at all, does it reach our agent?
(direct regulation, contract flow-down,
sector rule, or "it doesn't")
what it requires - stated in the document's own words, not a
paraphrase that sounds stricter
Flag any row where "requires" appears in your notes but the source
document only says "should," "recommends," or nothing at all. That
gap is the finding, not a detail to smooth over.

The prompt asks for four columns instead of a summary paragraph because overclaiming survives in a summary and dies in a column: a rule that “requires human oversight” reads differently once “binding party” says “federal civilian agencies,” and Meridian is neither.

This is not the applicability method — it is one filled table

Operating in Production 4.2 (a separate training in this series) already built the general method for deciding which reporting clock reaches Meridian at all: by contract, by sector, by vendor. This lesson does not re-derive that method. It applies it once, to the specific rules that name agent actions, and stops at the table.

The applicability table

RuleBinding partyModalityPath to MeridianWhat it says or requires
”Careful adoption of agentic AI services” (2026-04-30)NobodyVoluntary joint guidanceNone by default; Meridian may adopt it voluntarilyCalls for system designers or operators — not the agent — to decide approval points; calls for quarantining log-deletion requests and for enclaves with no write access to logs
NCSC-UK, managing the cyber risk of agentic AI (2026-08-20)NobodyGuidanceNone; informative onlyAdvises organizations to remain able to “pull the plug” immediately and says logs should be immutable
OMB M-25-21 §4(b)(v) (2025-04-03)Federal agencies as defined at 44 U.S.C. §3502(1), which reaches the military departments; national security systems carved outBinding federal memo within that scopeMeridian has a duty only if the interconnect contract incorporates it”Provide Additional Human Oversight, Intervention, and Accountability. Agencies must ensure human oversight, intervention, and accountability suitable for high-impact use cases. When practicable and consistent with existing agency practices, agencies must ensure that the AI functionality has an appropriate fail-safe that minimizes the risk of significant harm.” Footnote 31’s exception: some safety mechanisms must act without waiting for human approval, and the agency must instead determine the appropriate oversight and accountability processes
M-25-22 (2025-04-03)Federal agencies; vendors only under a contract containing the termsBinding memo, but these three provisions are encouraged rather than mandatedOnly if Meridian’s task order contains the relevant termRollback, version-performance standards, and advance notice of new capabilities — §F has agencies “encouraged to require” the first two, §G that they “should consider, where relevant, requiring” the third
FINRA 2026 Annual Regulatory Oversight Report (published 2025-12-09)FINRA member broker-dealersSector guidance/reportNone; Meridian is not a securities firmAdvises considering “guardrails or control mechanisms to limit or restrict agent behaviors, actions or decisions,” prompt-and-output logging, and “tracking which model version was used and when”
National Institute of Standards and TechnologyNobodyNot publishedNoneNo agent standard or artificial-intelligence control overlay published as of 2026-08-29
Department of Defense / Chief Digital and Artificial Intelligence OfficeN/ANot publishedNoneNo agent-action guidance identified
NERC CIP-010-4 R1.2Registered entities with applicable High- and Medium-Impact Bulk Electric System Cyber Systems and associated systemsBinding reliability standard within that populationNone for MU-AI-011; its actions are fenced to the information-technology/data zoneRequires covered baseline deviations to be authorized and documented by an individual or group with authority to authorize the change
European Union Artificial Intelligence Act, Article 14Covered high-risk systems in its jurisdictionVocabulary only hereNone for this US-only exampleAbility to “disregard, override or reverse the output” and “interrupt the system through a ‘stop’ button”

Two rows deserve a plain caveat. No FERC or NERC instrument governs agent actions. CIP-010-4 R1.2 reaches only its applicable High- and Medium-Impact Bulk Electric System Cyber Systems and associated systems; MU-AI-011 never crosses into that population. NIST has published no agent standard and no artificial-intelligence control overlay — writing “NIST requires” here would invent an obligation that does not exist yet.

A table with an honest “none” in half its rows beats a summary that makes every row sound the same weight.

Footnote 31 is not a loophole — it is the exception 1.3’s table already decided

The temptation reading M-25-21’s fail-safe clause is to assume it always means “a human approves first.” Footnote 31 says otherwise, in the document’s own words: “an AI-enabled safety mechanism may require an immediate and automated action to prevent a harm from occurring. It would not be practicable in this case to require human intervention to approve the activation of the safety mechanism. However, agencies must still determine the appropriate oversight and accountability processes for such a use of AI.” A mechanism whose entire job is stopping harm faster than a human can be reached is not a violation of oversight. For a covered agency — or for Meridian only if its contract carries the requirement — this is a case the oversight obligation must plan around, not forbid.

1.3’s action-class register is where that case gets its determination — signed, named, and bounded in advance by the same owner who signs every other row, not invented on the spot to skip an approval. Footnote 31 names why such a row can exist; 1.3 is where it already gets decided.

A footnote that anticipates the case for acting without a human is a design constraint the action register has to hold a row for, not a general license to skip approval whenever it feels urgent.

The seam: a commercial agent, a federal seat, and what actually crosses

The commercial starting practice is what this module already builds: a per-action envelope enforced at a gateway, expiring approvals, and a receipt chain the guarded agent path cannot write and whose later alteration is detectable against an anchor — none of it required by any regulator, built because it is the right control regardless. The federal delta could reach Meridian only if the interconnect contract contains the relevant M-25-21 or M-25-22 clause; Meridian does not become a federal agency merely because its data crosses the interconnect. The handoff artifact is the exact task-order or interconnection language, not guidance that binds nobody by itself.

What is not equivalent: guidance’s “should” is not a contract’s “shall.” 3.4’s rule: agent approval is not change authorization. Nothing in this table gives Guarded Automation standing on a Bulk Electric System Cyber System.

Stop and escalate when someone treats guidance as a requirement without a contract clause behind it, or extends a sector rule (FINRA, NERC CIP) past the population it binds. Both are legal-review questions — route them to whoever owns the interconnect contract, before a control gets built against an obligation that was never there.

KNOWLEDGE CHECK

A vendor's marketing page states that Meridian's crew-dispatch agent 'follows CISA's Five Eyes guidance on agentic AI oversight.' What does this table say about that claim?

Practice status — oversight practices that could apply to an agent action at a commercial utility with a federal interconnect

PracticeStatusAlso called
human approval for high-impact, hard-to-reverse actionsstrong optionalhuman-in-the-loop checkpoint
quarantine of agent requests to delete logsemerginglog-deletion hold
performance of a federal oversight or rollback clause that appears in the task orderrequiredcontract clause; flow-down term
action register naming a pre-authorized fail-safe exceptionstrong optionaldocumented automated-response exception
sector applicability checked against the population the rule bindscommon baselineapplicability check; sector-scope check

Scale: required | common baseline | strong optional | reference-shop (seen only at organizations that publish their own practice) | emerging

Key takeaway

Guidance is not obligation until a contract, sector rule, or binding federal instrument says so, and this table exists so that distinction survives contact with a vendor’s marketing language. Only two rows could reach Meridian’s agent through this route — the fail-safe duty and the rollback, performance, and notice terms — and only if the interconnect contract actually contains them. Module 5 turns from who authorizes an action to what gets written down once it happens: the receipt chain that makes every row here checkable at all.

LEADERSHIP DECISION no oversight rule is treated as binding on
Meridian's agent unless a named contract clause
or an applicable sector rule says so; voluntary
guidance and agency-only instruments do not
PRACTITIONER ACTION get the interconnect contract's flow-down
language reviewed once, in writing, and keep the
applicability table current against it
SUCCESS MEASURE zero claims in any audit or vendor document that
cite guidance as if it were a requirement -
audit finding avoided
Search lessons