Once Fact, Evaluation, and Policy have been established, and the applicable Policies are managed through Authority, the next stage is to determine whether execution can be authorized in the present situation. In I2EA, this stage is defined as “Decision.”
At the Decision stage, the Decision Engine receives information related to an execution request and evaluates it against the Policies applicable at that point in time. For example, if an AI system seeks to use an image, the Decision Engine examines the relevant Fact Tags and Evaluation Tags, the requested Action, and the applicable Policies to determine whether the required conditions are satisfied.
Importantly, the Decision Engine does not make independent value judgments about whether something is “good” or “bad.” Its decision is grounded in the information structured in the preceding stages and the Policies recognized as valid by the relevant Authority. The role of the Decision Engine is to compare these elements and determine whether the current execution request satisfies the defined conditions.
If the required conditions are satisfied and execution is authorized, the Decision Engine issues an “Allow Key.” This Key is not simply a “Yes” response. It is machine-readable authorization information that communicates to the subsequent Execution Boundary that the required Policy Checks have been performed and the specific execution request has been authorized.
An Allow Key does not grant permanent authority to the AI system itself. It is issued on the basis of a specific Context, target, Action, Policy, and point in time. Accordingly, a new Decision may be required if the information being handled changes, the requested Action changes, or the applicable Policy is updated.
Conversely, if the required conditions are not satisfied, no Allow Key is issued. This makes it possible to distinguish between an AI system being able to reference a Policy and the system actually being granted authority to execute under that Policy.
The Decision can also record the Fact, Evaluation, Policy, Authority, Context, and Decision outcome that were referenced. This makes it possible to reconstruct later why a particular execution was authorized.
Accordingly, Decision is the stage in which an execution request is evaluated against the Policies and related information applicable at that point in time, and an authorization Key is issued when the required conditions are satisfied.
At this stage, rules previously defined as Policy are transformed into authorization for a specific execution request. However, the issuance of a Key is not yet equivalent to the ability to execute. In the next stage, Execution, the Key is validated at the Execution Boundary.