Factor
All stories
article

Put the Model Behind a Gate

AI should propose and deterministic systems should commit. Here is the architecture I'd hold every team to, the patterns that have held up, and what it changes for engineering leaders through 2028.

NNijelOct 2, 20265 min read21 reads
Put the Model Behind a Gate

The next three years won't belong to the teams with the best prompts. They'll belong to the teams that put probabilistic intelligence behind deterministic control, and rethink how leaders decide.

I keep seeing the same pattern in AI rollouts. Someone wires a chatbot into a workflow, the demo goes well, and the team calls it transformation. Then the model gets write access to something that matters, and we find out about the gaps after the incident.

The shift that matters is architectural, not conversational.

AI is becoming the proposal engine. Deterministic systems remain the commitment engine. Leadership is the work of deciding where the line between the two sits.


The trap: treating intelligence like software

We've spent decades building on software that behaves the same way every time. Same input, same output. That's why tests, SLAs, audits and contracts mean anything.

Foundation models don't work like that. They are:

  • Probabilistic: you get a useful distribution over outputs, not a guarantee
  • Context-sensitive: change the prompt, the memory or the available tools and the behavior changes
  • Non-stationary: a model update moves the behavior under your feet
  • Uncalibrated: confident language is not a calibrated probability

None of that makes them weak. They're very good at drafting, ranking, exploring options and making sense of messy input. They're a bad fit for owning irreversible state like money, identity, inventory, medical dosing, production deploys or legal commitments.

Hand a model that job and you haven't automated judgment. You've automated risk and put a friendly UI on it.

Fig 1 — Hybrid control loop
live
REQUESTInAI LAYERpropose · rank · draftDETERMINISTICvalidate · constrain · auditCommitProbabilistic work stays upstream of irreversible state.

AI proposes. Deterministic systems verify. Only verified actions commit. The commit path is the product.


Hybrid architecture, defined

A hybrid architecture separates three planes:

PlaneJobMust be
Perception / generationUnderstand, draft, rank, exploreProbabilistic (AI)
Control / policyAuthorize, constrain, verifyDeterministic
State / commitPersist irreversible factsDeterministic + auditable

The rule I'd hold every team to:

No AI output becomes world-state without a deterministic gate.

The gate can be code, a schema, a policy engine, a human approval, a dual-control workflow, or several of those together. It cannot be "the model seemed sure."

A concrete shape

ts
type Proposal = {
  intent: string;
  actions: ActionDraft[];
  rationale: string;
  evidenceRefs: string[];
};

type GateResult =
  | { ok: true; actions: VerifiedAction[] }
  | { ok: false; violations: string[]; escalate?: "human" | "reject" };

async function handle(request: Request) {
  const proposal = await ai.propose(request);          // probabilistic
  const gate = await policy.verify(proposal);          // deterministic
  if (!gate.ok) return escalate(gate);
  const receipt = await ledger.commit(gate.actions);   // deterministic
  await audit.record({ proposal, gate, receipt });     // deterministic
  return receipt;
}

This isn't an anti-AI position. It's how you let the model move quickly without letting it own the truth.


What must stay deterministic

If you only keep one list from this piece, keep this one:

  1. Identity & authZ: who can do what
  2. Money movement: amounts, FX, fees, refunds
  3. Inventory / capacity: physical or logical scarcity
  4. Compliance constraints: hard regulatory limits
  5. Schema & invariants: data shapes that keep systems coherent
  6. Audit trail: what happened, who or what decided, and on what evidence

The model can recommend inside all of these areas. It shouldn't be the source of truth for any of them.

decision stack blog


Design patterns that have held up

1. Propose → Verify → Commit

The control loop in Fig 1. The model explores, policy verifies, the ledger commits. Keeping those three apart is the difference between a clever assistant and a system you can operate.

2. Typed tool contracts

Don't give models free-form side effects. Give them tools with:

  • strict input schemas
  • idempotency keys
  • explicit side-effect classes (read, draft, mutate, irreversible)
  • rate and blast-radius limits
ts
const transfer = tool({
  name: "transfer_funds",
  sideEffect: "irreversible",
  input: z.object({
    from: AccountId,
    to: AccountId,
    amount: Money.positive().max(limits.perTxn),
    idempotencyKey: z.string().uuid(),
  }),
  // model may *request* this; policy + ledger execute it
});

3. Dual-model is not dual-control

Having one LLM check another helps draft quality, but you still have two probabilistic systems agreeing with each other. That's not enough for safety. Pair the model with deterministic checkers: unit invariants, policy engines, range checks, reconciliations, and shadow reads against the source system.

4. Eval harness as architecture, not ceremony

If you can't measure a change, you can't govern it.

  • Golden cases for critical workflows
  • Regression suites on every prompt, model or tool change
  • Online monitors for distribution shift, not just latency
  • Incident → new eval case, same day

5. Human escalation as a first-class path

Hybrid systems assume uncertainty. When confidence is low, the case is new, or the blast radius is large, escalate. Design the escalation experience as carefully as the happy path. Teams that skip it end up handling it in a panicked Slack thread.


How this changes decision-making

Classic leadership decision:

Collect inputs → form judgment → decide → communicate → execute.

Hybrid-era leadership decision:

Define the decision system → set boundaries → decide which cases are automatic vs escalated → review the system's failure modes → improve the gates.

The unit of leadership work shifts from individual decisions to decision infrastructure.

Some managers will read that as a loss of status. For the ones who adapt, it's more leverage than they had before.

What good leaders will own by 2028

  • Boundary maps: which decisions are AI-eligible, which are human-locked
  • Proof standards: what evidence is required before anything commits
  • Risk budgets: how much automated error each domain can absorb
  • Escalation quality: whether humans get real context, not a data dump
  • Taste: what "good" looks like when AI drafts most of the options

Taste doesn't disappear. It concentrates. When first drafts are free, the scarce skill is selecting and shaping, not producing.


The next three years

three year shift blog

2026: Pilot chaos

Every team adopts its own tool and almost nobody shares a control plane. Shadow IT turns into shadow cognition. Wins stay local. Failures are embarrassing and mostly survivable.

Leadership move: stop collecting demos. Start collecting commit paths: what can the AI actually change, and through which gate?

2027: Hybrid becomes the default for serious systems

Regulated industries and high-stakes product teams settle on propose, verify, commit. "Agent" stops meaning a chatbot with tools and starts meaning a workflow with a probabilistic planner and a deterministic executor.

Leadership move: fund policy-as-code and auditability with the same urgency as model access. Grow engineers who can build gates, not only prompt chains.

2028: A decision OS emerges

The strongest organizations won't be the ones with the flashiest copilots. They'll have a coherent decision operating system:

  • a shared policy registry
  • shared eval suites
  • common audit and escalation tooling
  • clear ownership of the boundary between what AI may propose and what the company will commit to

That's the real moat, because it's hard to copy and slow to build.

N

Written by

Nijel

2 stories on 10x Factor

Discussion

No comments yet

Sign in as a member to join the discussion.

Keep reading

All stories