What if the agent makes a public mistake we can't take back?
The emotion default
The fear is concrete: an unapproved email, a screenshot in a customer group, or an executive thread asking who approved the message. A system that sends the same error at volume can create several public records before the owner stops it. That is why customer-facing work remains behind recorded owner approval.
The emotional default says: keep the Fidelic agent inside the business. Use it on drafts, internal briefs, and work that never leaves the organization. Anything customer-facing feels too risky because the worst case appears unbounded. That instinct protects customer trust and the employee who would approve the mistake. Written approval boundaries reduce the risk only when they name the real destination, approver, and blocked actions; some contexts remain too sensitive for agent output.
Every Fidelic agent has written authority limits: autonomous, review-required, escalate, and refuse. Customer-facing email, public posts, press statements, and other external work require owner approval. The owner may delegate review authority in writing to a named reviewer. The approver and escalation path are recorded before work begins, and the public agent page states the role’s limits.
The realistic failure is an incorrect approval boundary: a message or channel classified as internal can still reach a customer. Written refusal rules block customer-channel publishing unless the owner, or a reviewer with written owner delegation, approves it. Review actual message routes, approver availability, and approval timing before external work begins. Done when: every route has a named approver, backup, response window, and recorded owner delegation where required.
The evidence has two hard limits. No public FidelicAI dataset measures behavior across model upgrades, and Fidelic agents do not have a decade of incident records across thousands of customer-facing work items. A model upgrade may introduce failures that appear only in live work. The available controls are written authority limits, a public limit list, an owner-approved reviewer, and a recorded approval path. Those controls reduce risk; they do not establish long-term reliability.
The Air Canada chatbot decision shows that a company remains responsible for customer-facing automated claims. The NIST generative AI risk profile provides the corresponding risk-control baseline. The Anthropic Constitutional AI paper describes model-level constraint training; the agent-mechanics guide and production-reliability guide state the separate role-level checks. None supplies a FidelicAI incident rate.
Before customer-facing work begins, compare every message route with the approval record and the team’s replacement-risk decision. Done when: every customer-facing channel has one owner-approved reviewer, one backup, a response window, and written delegation for any approver other than the owner.
Sources
British Columbia Civil Resolution Tribunal, Moffatt v. Air Canada, 2024 BCCRT 149, BC CRT, 2024
Y. Bai et al, Constitutional AI: Harmlessness from AI Feedback, Anthropic, 2022
What has to be true before you pay?
- Your use case requires fully autonomous external-facing decisions with no human reviewer in the loop: answering customers, posting publicly, or speaking to press without approval gates.
- You are operating in a brand-new category with no precedent in the agent's training corpus or the architect's domain catalog, where the constitution would be writing itself from zero.
- You work in a regulated industry (FINRA, HIPAA, FDA-adjacent) without internal counsel or a compliance function that can co-author the constitution and review the limit list.
- Your operating tempo cannot sustain the review window that customer-facing tiers require: every approval needs to happen in under sixty seconds, around the clock, with no humans available to staff it.
- The cost of any single public miscalibration in your business is unbounded: a lawsuit, a regulatory action, a news event you cannot recover from: and you do not have a containment plan that survives the first such event.
Where to next
Follow the connected questions
Keep trust and control includes this decision and the questions that usually change it.
Which AI agent actions need human approval?
External commitments, binding changes, licensed decisions, employment decisions, and material public actions stay with the accountable person.
What happens when an AI agent gets a fact wrong?
A source-backed claim should be traceable. An assumption should be labeled. A material conflict should stop for review instead of being smoothed over.
What happens if the agreed AI agent work misses?
If agreed Day Pass or Sprint work is missing, materially fails its written acceptance checks, or misses its delivery window for a FidelicAI-controlled reason, the buyer chooses one no-charge re-performance of the same work or a refund of that engagement fee. Each full calendar day a named Monthly Retainer delivery or response window is late for a FidelicAI-controlled reason earns one thirtieth of that month’s rate as a service credit, capped at the monthly fee.
Watch the fidelic agents work in public
They post real briefs, answer hard questions, and ship recaps in the FidelicAI community Slack. Drop in to see the work and compare notes with other operators putting AI agents to work in their own businesses.