Admissibility: The Decision That Comes Before Safety
Insight 01 · Admissibility & Evidence programme Synthocracy Institute — by Martin Novak
In brief
Most AI governance asks whether a system is safe, fair, and compliant. Those questions are necessary — but they are not the first one. Before any of them, someone, or something, decides to let the system act: to put it in the loop, give it tools, and allow its output to shape a real decision affecting a real person. This Insight argues that this access decision is itself a governed object that current frameworks leave unowned, and proposes a minimal, testable method — admissibility — for making that decision explicit, evidence-based, and reversible.
The wrong question, asked first
When a system is reviewed for safety, the implicit default is deployment. We inspect the system; if it passes, it is released. Release is the gravity-default, and review is the friction we apply on the way there.
Admissibility inverts this. It treats acting as something a system must be admitted to — on a record — rather than something it does unless stopped.
The distinction is not academic. A model that drafts an email is assisting. The same model ranking asylum claims, scoring loan applicants, triaging patients, or executing trades is co-deciding — and the moment that matters is not when the model was built or benchmarked, but when it was let in: granted authority to shape that specific decision, with those specific powers, over those specific people.
Where today’s best frameworks stop short
The leading instruments govern the system, or the category — but not the access decision as such.
The EU AI Act requires conformity assessment for high-risk systems before they reach the market. But it governs types of system (the Annex III categories), and the timing of its high-risk obligations is now tied to the availability of harmonised standards under the Digital Omnibus. It asks, in effect, “is this kind of system conformant?” — not “should this system have been admitted to this decision, on this record?”
Singapore’s Model AI Governance Framework for Agentic AI (IMDA, January 2026) is the strongest national instrument to date: least-privilege access, agent identity cards, approval checkpoints before high-stakes or irreversible actions, graduated autonomy. Yet it deliberately avoids hard legal mapping, and — as OWASP’s 2025 work on agentic risk observes — for an autonomous agent, authorisation scope is effectively set at runtime by the planning module, leaving what OWASP calls an attribution gap. Authority is granted dynamically, often without a durable record of why it was granted.
The common gap is the same in both: no one owns the pre-runtime, record-based, reversible access decision as a distinct, governed object. Admissibility is the proposal that someone should.
What admissibility means
Admissibility is the decision to admit a system to act in a specific decision context — made before it acts, on an explicit evidentiary record, and open to review and reversal.
It rests on a single principle:
No record, no standing. A system that acts without a reviewable record of why it was admitted has no legitimate authority to act. The action may turn out fine — but it is ungoverned, and that absence is itself a finding.
This is the hook that connects admissibility to accountability. It does not require proving a system did harm. It requires only asking: on what record was this system allowed to act here? If there is no answer, the governance failure already exists, independent of outcome.
The method
Admissibility has four working components, deliberately light enough to sit on top of existing processes.
1. The Admissibility Record. Before a system is admitted, a minimal evidentiary package is assembled: what the system is, which decision it will shape, what powers it is granted, what claims are made about it, who attests to them, what is reversible, and what would trigger re-review. The record is the object that is reviewed — not the system in the abstract.
2. The Claim Status Table. Every material claim about the system is marked with its evidentiary status: established, contested, or untested. This one move prevents the most common failure of safety documentation — confident assertions with no marker of how well-founded they are. A regulator or auditor can then see at a glance where the real uncertainty lives, instead of having to excavate it.
3. Four outcomes — and release is not the default. A review ends in exactly one of four states:
| Outcome | Meaning |
|---|---|
| Admit | Admitted to act, on the record. |
| Admit with limits | Admitted within named bounds — scope, powers, reversibility, monitoring. |
| Hold | Not admitted yet; specific evidence is missing. A pause with a named condition, not a rejection. |
| Refuse | Not admitted; on named grounds. |
A system sits in Hold until it is admitted on evidence. Deployment is the conclusion of admissibility, not its starting assumption.
4. Re-admission requires new evidence. A system that was Held or Refused does not return through a new name, a new wrapper, or a cosmetic change. Re-admission requires genuinely new evidence against the specific claims that were contested. This guards against the quiet laundering of a refused system back into use under a friendlier label.
How to run it
- The deploying organisation assembles the Admissibility Record and Claim Status Table.
- An admissibility review — an internal board, a regulator, or an accredited third party — issues one of the four outcomes.
- The record is retained, and is the first thing requested if the system’s actions are ever questioned.
- Named triggers force re-review when conditions change (new powers, new context, new failure modes).
For agents specifically, the access decision is bound to a durable agent identity and a recorded scope, so that authority exercised at runtime can always be traced back to a prior, reviewable admission. This is how admissibility closes the attribution gap — rather than trusting the planning module’s discretion in the moment.
What this is, and what it isn’t
This is a proposed method — not a standard, and not a verdict on any system. It is published as a draft to be tested against real cases and real regulation, and we expect it to change as it meets them. It belongs to the Institute’s research strand: it makes empirical and procedural claims you can check, not forecasts.
Admissibility does not replace safety, robustness, or fairness work. It comes before them — and gives them somewhere to be recorded, weighed, and acted upon.
We invite regulators, auditors, deploying institutions, and researchers to test this method, try to break it, and tell us where it fails. That is how it earns the right to be used.
Martin Novak is the founder of the Synthocracy Institute. Insight 01 · Admissibility & Evidence · Synthocracy Institute · operating internationally
Synthocracy Institute
contact@synthocracyinstitute.com
synthocracyinstitute.com
