AI Action Confirmation UX: When Should an AI Ask Before Doing Something?
A decision framework for when an AI should act automatically, notify, ask for approval or hand control to a person, and how to design approval screens.
Quick answer
An AI should ask before acting when getting it wrong would be costly or hard to undo. Score each action on seven factors: risk, reversibility, financial impact, external communication, privacy, permissions and blast radius. Then map the score to one of four modes: automatic for low risk, notify with optional review for medium, explicit approval for high and human-controlled for critical actions.
Asking too often is a failure too. People approve without reading when every step needs a click. Prefer undo for reversible actions, batch related approvals and reserve confirmation for actions that matter.
The seven factors
| Factor | Lower risk | Higher risk |
|---|---|---|
| Risk of error | AI is accurate on this task; easy to check | Ambiguous request; judgment involved |
| Reversibility | Undo available (draft, archive, toggle) | Irreversible (payment captured, email sent, record deleted) |
| Financial impact | None or trivial | Spends, refunds or commits money |
| External communication | Internal or private | Message to customers, partners or the public |
| Privacy | No personal data moves | Shares or exposes personal or sensitive data |
| Permissions | Within the user's normal rights | Uses elevated or delegated rights |
| Blast radius | One item, one user | Many records, many recipients, production systems |
The decision framework
Classify by the highest-risk factor, not the average: a single irreversible external payment is high risk even if everything else is low.
| Tier | Typical actions | Mode | UX |
|---|---|---|---|
| LOW | Tag a ticket, draft a reply, sort a list, summarize | Automatic | Do it; show in activity log; offer undo |
| MEDIUM | Update a CRM field, reschedule an internal meeting, apply a small credit within policy | Notify / optional review | Do it, notify, allow review and undo for a window |
| HIGH | Send an email to a customer, place an order, issue a refund, share a document externally | Explicit approval | Approval card before acting; approve, edit or reject |
| CRITICAL | Large payments, bulk deletion, contract changes, production changes, legal or medical decisions | Human-controlled | AI prepares and recommends; a person performs or co-signs the action |
Agent proposes action
│
▼
Score: risk · reversibility · money · external ·
privacy · permissions · blast radius
│
┌─────┼───────────────┬──────────────────┐
▼ ▼ ▼ ▼
LOW MEDIUM HIGH CRITICAL
act act + notify approval card human performs /
log undo window approve·edit· co-signs; AI
undo reject·delegate prepares evidence
│ │ no response?
│ └─▶ expire safely (do nothing)
▼
Activity log + audit record for every tierDesigning the approval request
When an action needs approval, the request should let a person decide in seconds without opening other tools. It needs an action summary in plain language, the object and recipients affected, the impact (amount, number of records), a risk indicator and why it is that level, the context and evidence the AI used, and four responses: approve, reject, edit and delegate to someone else, plus an escalation path when the approver is unsure. State what happens if nobody responds; the safe default is that nothing happens.
For actions that were taken automatically, undo must be real: reversing a database change is easy, but recalling an email or a payment is not. AI agent rollback covers what can be reversed and how.
┌──────────────────────────────────────────────┐
│ ● HIGH Refund requires your approval │
│ │
│ Refund EUR 420.00 to Maria K. │
│ Order #55120 · sofa delivered damaged │
│ │
│ Why: damage confirmed in 4 photos; customer │
│ declined repair. Policy allows full refund │
│ within 14 days (day 3). │
│ Evidence: photos · delivery note · chat │
│ │
│ [ Approve refund ] [ Edit amount ] [ Reject ]│
│ Delegate… Escalate to finance… │
│ Expires in 24 h — no action if not approved │
└──────────────────────────────────────────────┘Approve, reject, edit, delegate
Approve should commit exactly what was shown; if anything changed since (price, stock, recipient), show it again. Reject should ask for a short reason, which becomes feedback for the agent and its evaluation set. Edit lets the approver correct details without rejecting the whole action, and the edited version is what executes. Delegate sends the request to someone with more context or authority, keeping the history. For queues of many approvals, see the operational guidance in human-in-the-loop AI.
Avoiding confirmation fatigue
Over-confirming has real costs: slower work, users who stop reading and approve everything, and frustration that pushes people to disable the AI. Practical ways to keep confirmations meaningful:
- Use undo instead of confirmation for reversible actions
- Batch related actions into one review ('send these 8 follow-ups')
- Show only what changes, highlighted, not the whole record
- Remember approvals for identical repeated actions within limits the user sets
- Let users tighten levels freely and loosen them only within policy
- Track approval rates: near-100 percent approval with seconds of review suggests the step is either unnecessary or not being read
Enforce it in the backend
A confirmation that exists only in the interface can be bypassed by a bug, a different client or a prompt injection. Store the confirmation tier per action in policy, require an approval token from the right person for high-tier actions at the API, and log who approved what. The same thinking at the level of the whole agent is in AI agent autonomy levels.
Designing approvals for AI features?
ZSpace Labs designs approval flows, review screens and the backend controls that enforce them. See UI/UX design and AI automation.
Conclusion
The right answer to 'should the AI ask first?' depends on what the action can break. Score actions on risk, reversibility, money, external reach, privacy, permissions and blast radius; automate the low tier, notify on the medium, require approval on the high and keep people in control of the critical. Design approval requests that can be judged in seconds, prefer undo where it is genuine and enforce the rules on the server. For explaining actions after they happen, see AI agent trust UX.
Common questions.
When an action is hard to reverse, spends money, communicates externally, exposes personal data, uses elevated permissions or affects many people or records. Low-risk, reversible actions inside the user's own workspace usually should not need confirmation.