Skip to main content
Back to BlogAnalyse IA

An AI Agent Acting in Your Systems: Who Approves What?

October 3, 2026

An AI Agent Acting in Your Systems: Who Approves What?

On September 10, 2026, Anthropic added a permissions policy to its Claude agents that evaluates every action the agent takes and pauses it for human approval when it is sensitive. This is not a technical footnote: it is exactly the mechanism Law 25 requires you to have when an automated decision touches your clients' personal information.

The Short Answer

A modern AI agent no longer just drafts content: it acts (it creates an account, sends an email, modifies a file). The right question for an executive is therefore not "is the AI good enough?", but "which actions happen on their own, which require a human hand, and where is that written down?" Since September 10, 2026, the Claude platform knows how to draw that line on the server side: every tool call is evaluated and then executed, refused, or held for your approval. And since September 22, 2023, Law 25 has already required you to be able to answer that question in Quebec.

What Changed on September 10, 2026?

Two additions, in the official Claude platform release notes:

  • An auto permissions policy for managed agents (Claude Managed Agents): the server evaluates every tool call made by the agent (including tools connected via MCP), then executes it, refuses it, or suspends it pending approval. Every evaluation is logged in agent.tool_use and agent.mcp_tool_use events.
  • An ant beta:sessions connect command that lets you connect live to an active agent session: follow what it is doing, interact with it, and authorize or refuse pending actions.

(Source: Claude platform release notes, September 10, 2026 entry: platform.claude.com/docs/en/release-notes/api.)

The distinction that matters: the guardrail is no longer a written instruction that the AI is kindly asked to follow. It lives in the platform, beyond the model's reach. A rule that exists only in a prompt is not a rule; it is a wish.

Why This Concerns an Executive, Not Just the IT Team

Because Quebec law has already settled the question.

Section 12.1 of the Act Respecting the Protection of Personal Information in the Private Sector (CQLR, c. P-39.1), in force since September 22, 2023, applies to any decision based exclusively on automated processing of personal information. Such a decision is defined as one made without any natural person having exercised meaningful control.

When that is the case, the organization must:

  • inform the individual of the automated nature of the decision, no later than the time it is communicated;
  • on request, disclose the information used, the reasons and principal factors behind the decision, and the individual's right to have them corrected;
  • give the individual an opportunity to present observations to a staff member who is in a position to review the decision.

(Source: Gouvernement du Québec, "Décision fondée exclusivement sur un traitement automatisé," quebec.ca; Commission d'accès à l'information du Québec, "Principaux changements apportés par la Loi 25.")

Two very concrete consequences:

✦ A real human approval point takes you out of the "exclusively automated" category. But it has to be real: named, traceable, actually exercised, and not a checkbox in a policy nobody reads.

✦ Even outside that category, you must be able to explain. "The AI decided" is not an answer. A per-action evaluation log, like the one Anthropic has just made native, is precisely what makes a decision explainable twelve months later.

How Do You Decide What an Agent Does on Its Own?

In our practice, the rule is not set by agent or by trust level. It is set by cost of error:

  • Near-zero cost and reversible → autonomous. Reading a mailbox, sending an acknowledgment, serving a procedure that has already been verified. Requiring approval for this protects no one and exhausts everyone.
  • Reputational cost → human review. Anything that commits the organization on substance: a solution, a deadline, an amount, published content.
  • Irreversible cost → explicit approval. Creating or revoking an identity, resetting a password, wiping a device, sending something externally.

The classic trap is tightening controls across the board "to be safe." This produces two effects, both bad: zero-cost actions get blocked, so the service goes silent; and approval fatigue sets in. Past a certain volume, the tenth request gets skimmed and the twentieth approved by reflex. A guardrail nobody reads guards nothing.

Where Do You Start?

This is the logic behind our CAPE method:

  • Conceive: inventory the actions the AI would take, and rank them by cost of error. That inventory is also your Law 25 compliance document.
  • Activate: start with a narrow scope, with the approval point connected from day one, not bolted on afterward.
  • Propel: expand autonomy where measurement justifies it, action by action.
  • Evolve: review the log: what was approved and never refused can become autonomous; what was refused must stay gated.

FAQ

Does Law 25 prohibit using an AI agent in my organization? No. It prohibits nothing. It requires transparency, an explanation available on request, and a reachable human capable of reviewing the decision.

Does this apply to a small business, or only to large enterprises? Section 12.1 applies to organizations regardless of size. A small business that makes an automated decision about a client is subject to it just as a large one is.

If an agent sorts my emails, is that an "automated decision"? Classifying an email is generally not a decision within the meaning of section 12.1. Declining an application, setting a condition, or cutting off a client's access is. The line is documented case by case: that is the work of the Conceive step.

Does every AI action require a human behind it? No, and that would be counterproductive. A human is needed at the points where an error is costly or cannot be undone. Everything else should run.

How do you prove that a human exercised meaningful control? Through the audit trail: who approved, what, when, and on what basis. That is precisely what a per-action evaluation log provides.


If you are considering letting an AI take actions in your systems, the "who approves what" inventory takes a single meeting. Reach out: we start from your actual actions, not a template.

Article written September 12, 2026.

LinkedIn Version

Which actions is your AI allowed to take without asking your permission?

On September 10, Anthropic made that control native: Claude agents now evaluate every action (execute, refuse, or pause for human approval). Every evaluation is logged.

This sounds technical. It is an executive issue.

Because in Quebec, section 12.1 of Law 25 has been in force since September 22, 2023. It targets decisions made without any person having exercised meaningful control: it then requires you to inform the individual, explain the factors on request, and offer them a human capable of reviewing the decision.

What we see in practice: the right question is not "how far can the AI go?", but "what does the error cost?"

✦ Zero cost and reversible → autonomous. ✦ Reputational cost → review. ✦ Irreversible cost → approval.

Locking everything down "out of caution" causes two problems: the service goes silent, and approval fatigue sets in. A guardrail nobody reads guards nothing.

No prohibition. No window dressing. A written boundary.

Loi25 PMEduQuébec IAQuébec DirigeantsPME GouvernanceIA

Sources Cited

  1. Claude platform release notes, September 10, 2026 entry: https://platform.claude.com/docs/en/release-notes/api (verified 2026-09-12; the former docs.anthropic.com address redirects 301 to this one)
  2. Gouvernement du Québec, "Décision fondée exclusivement sur un traitement automatisé": https://www.quebec.ca/gouvernement/travailler-gouvernement/normes-gouvernance-pratiques-internes/protection-des-renseignements-personnels/technologie-et-droit-a-la-protection-des-renseignements-personnels/decision-traitement-automatise
  3. Commission d'accès à l'information du Québec, "Principaux changements apportés par la Loi 25": https://www.cai.gouv.qc.ca/protection-renseignements-personnels/sujets-et-domaines-dinteret/principaux-changements-loi-25
  4. Act Respecting the Protection of Personal Information in the Private Sector, CQLR c. P-39.1, s. 12.1: https://www.legisquebec.gouv.qc.ca/fr/document/lc/P-39.1 (verbatim wording not re-read: legisquebec blocked automated access, HTTP 403. The content of section 12.1 above is drawn from official sources 2 and 3; confirm against the legislative text before publishing.)