After AI Enters the Workflow · Season Three: “When AI Starts Acting for the Organisation” · Article Four
A customer misses the deadline for cancelling a service. The standard policy is clear: notice must be given seven days in advance or the next monthly charge applies. AI checks the dates, calculates six days and refuses a refund.
The customer explains that she was admitted to hospital before the deadline and could not manage the account until discharge. She uploads evidence and requests review. The AI replies again: “Under the terms, your request is outside the required period.” She selects “review”, which sends the same material into another automated process and returns the same result in slightly different words.
In this hypothetical case, AI may have read every rule and calculated every date correctly. The problem is that the rule was designed to manage ordinary cancellation, not necessarily to exhaust every exceptional circumstance. The organisation automated the standard judgement without identifying who could interpret the purpose of policy, weigh an exception and accept responsibility for departing from the rule.
AI can apply a rule. An exception should not depend on whether AI happens to notice it. It needs an institutional entrance and a person with actual discretion.
One customer request conceals two organisational queues
Most service workflows design one standard queue: collect fixed fields, compare conditions and produce a result. That queue suits large numbers of similar cases and is easiest to automate.
Exceptions require a second queue:
Standard request
→ complete data
→ rule match
→ automated result
Exceptional request
→ identify the reason for departure
→ collect proportionate additional evidence
→ authorised judgement
→ explain reasons and create a reusable record
The second queue cannot be the same model with a different prompt. It needs different powers: access to fuller facts, ability to interpret policy purpose, permission to depart, responsibility to record reasons and authority to change the original outcome.
If a “human reviewer” cannot alter the result and may only select a prepared explanation, the organisation still has one queue. The case moves from machine to person without gaining a new capacity for judgement.
Exceptions do not necessarily weaken a rule
Organisations reasonably worry that exceptions can create inconsistency, favouritism and uncontrolled cost. Clear rules improve predictability, support similar treatment and protect frontline staff from improper pressure.
But rules express policy purposes through limited variables. Seven days’ notice may exist to allow resource planning, not to punish a customer incapable of acting while in hospital. Identity verification may prevent fraud, not permanently exclude someone unable to use one form of document. When the institution preserves literal conditions but loses purpose, the rule becomes mechanical rather than reasonable.
The role of an exception mechanism is not to let anyone avoid a rule. It handles three kinds of situation that the standard process cannot reliably resolve:
- available fields fail to represent the real circumstances;
- multiple rules conflict or produce a plainly disproportionate outcome; and
- a new situation has not yet entered policy.
A well-designed exception mechanism can protect the rule. It confines departure to stated reasons, appropriate authority and an auditable record rather than forcing employees to create informal workarounds outside the system.
AI may detect anomalies without being suited to approve them
AI can compare many cases, identify unusual combinations, organise a customer’s account and point to facts that differ from standard conditions. These are valuable forms of assistance.
Approval involves a different judgement: whether evidence is credible, whether the purpose applies, whether treatment is fair to others, whether loss is proportionate, what precedent the outcome creates and whether the institution accepts the consequence. A model may provide relevant information, but similarity to previously approved cases does not confer new authority.
Historical data are particularly difficult. Past exceptions may already be inconsistent. Some customers reached a senior employee while others, because of language, time or communication capacity, never entered the exception process. Learning from recorded outcomes can convert old differences in access into a new risk prediction.
Australia’s AI Ethics Principles connect fairness, contestability and accountability and say that significant effects should have an effective challenge process with appropriate use of human judgement. Department of Industry, Science and Resources, “Australia’s AI Ethics Principles” Exception design must therefore examine not only average model performance but who reaches review, whether the reviewer can change the result and whether reasons are available.
The nature of the exception should determine who decides
“Send it to a manager” is not a complete system. Exceptions should reach a role with the required knowledge and authority.
| Exception type | Suitable decision-maker | Appropriate AI assistance |
|---|---|---|
| Missing or malformed information | Business processing officer | Identify gaps and check consistency |
| Low-value, reversible service remedy | Frontline supervisor | Summarise history and calculate impact |
| Discrimination, accessibility or vulnerability issue | Specialist policy or risk role | Flag relevant obligations, not decide |
| Contract change, admission or material value | Formally authorised manager or professional | Prepare evidence and options |
| New and repeated exception | Policy owner | Cluster cases and reveal rule gaps |
Role authority must match consequence. The fact that an AI interface can route a case to someone does not give that person permission to approve it. The system should know who may see sensitive material, who decides, who advises and who owns policy change.
An exception request needs an evidence channel, not a free-text trap
Inviting a customer to “explain” in a blank box and asking AI to judge credibility can turn expressive skill into case merit. People familiar with institutional language may trigger the right concepts. A customer who writes briefly, uses translation or cannot organise a detailed narrative may be overlooked.
The interface should offer structured but proportionate evidence choices for the type of exception—dates, event, available documentation and requested remedy—while allowing facts not covered by standard fields. It should not demand sensitive information irrelevant to the outcome or equate incomplete material with an invalid reason.
Telephone, representative and accessible channels are also needed for people unable to use the online route. An exception mechanism available only to digitally fluent customers creates a new eligibility threshold beneath formal equality.
Review must gain independence from the original result
A genuine review changes at least one thing: uses additional facts, applies a different rule, reaches a higher authority or obtains independent judgement. Asking the same model to answer again, or asking an employee only whether the system followed procedure, checks consistency rather than whether an exception is justified.
Reviewers should see the basis of the original decision without being bound by its conclusion. An interface can show facts and policy before separately revealing the AI recommendation, reducing anchoring. For consequential matters, reviewers can be required to record their own reasons rather than choose only “agree” or “disagree with model”.
The NIST AI Risk Management Framework treats governance, mapping, measurement and management as a continuing cycle and places roles, feedback and risk response across the lifecycle. NIST AI Resource Center, “AI RMF Core” Exception review is important feedback: it should correct one customer outcome and tell the policy owner where automated rules repeatedly fail.
Do not measure approval alone; observe how exceptions change policy
Exception data can reveal flaws, but a single approval rate is ambiguous. A low rate may show a sound rule or an inaccessible application route. A high rate may show generous review or repeated wrongful refusal by the automated system.
More useful measures include:
- which rules produce most exceptions;
- which customer groups enter review;
- time from request to an authorised decision;
- main reasons the original outcome changes;
- whether information must be submitted repeatedly; and
- when repeated exceptions become formal policy updates.
If the same “exception” occurs hundreds of times each week, it is no longer marginal. Continuing case-by-case treatment wastes customer and staff time. The policy owner should revise the standard rule, add graduated treatment or establish a new formal category.
ISO/IEC 42001 includes continual improvement within an AI management system. ISO, “ISO/IEC 42001—Artificial intelligence management systems” For a service organisation, improvement should apply not only to model performance but to rules, authority and workflows changed by appeals and exception evidence.
Exception authority must not become another black box
Human discretion can also be inconsistent, favour familiar customers or respond to performance pressure. Retaining a person does not guarantee fairness. An exception decision should record applicable policy, material facts, reasons, approver and remedy, with samples compared across cases.
Audit should not force every special circumstance into a fixed code. Its purpose is to see whether similar facts receive explainable treatment, whether a group is repeatedly refused and whether exceptions are creating an unapproved new policy.
Limits and conflicts also matter. A supervisor authorised for small service remedies may not be able to vary a contract. A salesperson should not decide alone a material complaint affecting their own performance. Discretion is necessary, but it remains constrained institutional power.
Conclusion: standard processing can be automated; exception responsibility cannot be ownerless
AI can apply rules quickly and consistently. The issue is not that rules are inherently cold or that every special request should succeed. It is whether the organisation recognises that any limited rule will encounter a reality it cannot fully express.
The final principle is:
Every consequential rule applied by AI should have an accessible exception path. That path must reach someone with fuller facts, a different capacity for judgement and genuine authority to change the result, and repeated exceptions must feed back into the policy itself.
Customers do not need unlimited indulgence. They need one opportunity for an authorised person to hear facts that do not fit standard fields and provide reasons. An organisation that automates a rule without designing its exceptions leaves part of policy—purpose, proportionality and responsibility—outside the system.
Primary sources and further reading
- Department of Industry, Science and Resources: Australia’s AI Ethics Principles
- NIST AI Resource Center: AI RMF Core
- ISO: ISO/IEC 42001—Artificial intelligence management systems
- Australian Government: Policy for the responsible use of AI in government
Continue reading: Explore the After AI Enters the Workflow series.
Discover more from Geoffrey Chen
Subscribe to get the latest posts sent to your email.