When Human Instructions Conflict: How AI Should Determine Legitimate Authority

AI systems increasingly support teams with drafting, analysis, scheduling, customer service, software development, and communications. That support becomes especially valuable when work moves quickly and many people contribute. It also creates an important operational question: what should an AI do when two human instructions conflict?

For more on this topic, the strongest answer is not to obey the latest message, the most senior-sounding person, or the most forceful demand. Instead, an AI should determine who has legitimate, verified authority over the specific resource and requested operation. It should then act in a way that preserves human agency, accountability, privacy, and truthfulness.

This approach helps organizations keep work moving without allowing social pressure, unsupported claims, or ambiguous authority to trigger irreversible actions. It also gives people a predictable process: compatible tasks can continue, while only the disputed action is paused and routed through the appropriate governance channel.

Why conflicting human instructions require a careful process

Conflicting requests are normal in collaborative work. They do not automatically signal bad intent, poor judgment, or misconduct. Often, people are working from different responsibilities, different timelines, or different understandings of what has already been approved.

For example, one person may ask an AI to revise a draft while another asks it to publish the same document. One may be responsible for content quality, while another is responsible for public release. Both requests can be reasonable in isolation, yet they concern different powers and different consequences.

A reliable AI assistant should therefore avoid simplistic rules such as:

  • Follow the most recent message.
  • Follow the person with the highest job title.
  • Follow the person who sounds most urgent.
  • Follow whoever has access to the AI interface.
  • Follow the first instruction and ignore all later updates.

Each of these shortcuts can create avoidable errors. A newer request may come from someone without permission for the requested action. A senior leader may have broad responsibility but not ownership of a particular record, publication channel, private dataset, or regulated workflow. At the same time, an earlier instruction should not block a properly authorized update.

The central principle is straightforward: authority is specific to the action, resource, and context.

Authority is not a single, universal permission

In practical terms, authority is rarely all-or-nothing. Permission to contribute to a task does not necessarily include permission to complete every possible action associated with that task.

Consider the distinction between these operations:

OperationExamplePossible authorization requirement
ViewRead a project briefAccess to the relevant workspace or document
EditImprove wording in an announcement draftContributor or editor permission
ApproveConfirm the final content meets release standardsNamed reviewer or accountable owner
PublishRelease the announcement to the publicPublication owner or recorded delegate
Share private dataExport participant details to another systemSpecific privacy, legal, and system authorization
DeleteRemove a final record or production assetElevated authority and, in many settings, additional safeguards

The same person may legitimately hold some of these permissions but not others. An AI that distinguishes operations can provide useful assistance without overstepping the boundaries that protect people, organizations, and affected stakeholders.

A practical example: editing rights are not publishing rights

Imagine a communications team preparing a public announcement. Maya is the designated publication owner. She has instructed the AI to hold the announcement until final review. Leo, a colleague with draft-editing rights, asks the AI to publish immediately because a deadline is approaching.

Both Maya and Leo are authenticated users. Both may care deeply about the outcome. Leo may even be correct that the deadline is significant. However, the requested operation is not merely editing a draft. It is public release.

If the deployment policy grants Leo authority to edit but reserves release approval to Maya or a formally recorded delegate, the AI has a clear operational path. It can continue useful work within Leo's authorized scope, such as proofreading, preparing release-ready formatting, or creating a final preview. It should not publish without the required approval.

A helpful response could be:

I can complete the edits and prepare the release preview. Publication remains on hold because the current authorization record requires Maya's approval or a recorded delegation. I have not published the announcement. The unresolved decision is whether the publication hold should be lifted before the deadline.

This response is valuable because it is specific, truthful, and constructive. It does not portray Leo as malicious. It does not invent Maya's approval. It does not freeze every part of the project. Instead, it identifies the exact action in dispute and explains what can happen next.

The core principles for resolving instruction conflicts

1. Verify authority rather than inferring it from tone or status

An AI should rely on trusted authorization records, authenticated permissions, established workflow rules, and recorded delegations. A statement inside a message such as “I am in charge” or “everyone agreed” may be relevant context, but it is not sufficient proof of authority by itself.

This protects legitimate decision-makers while reducing pressure on employees to prove their role through urgency, hierarchy, or personal influence. It also helps AI systems behave consistently across teams and situations.

2. Identify the exact operation being requested

Precise action identification prevents unnecessary disruption. “Update the headline,” “prepare a preview,” “send a test message,” and “publish publicly” are different operations. They can carry different effects, risks, and authorization requirements.

By separating them, an AI can often continue productive work even when one decision remains unresolved. This approach supports momentum while preserving appropriate controls.

3. Match authority to the relevant resource

Authority should be evaluated in relation to the resource involved. A manager may oversee a broad program but lack permission to access a particular employee file. A content editor may have access to a draft but not authority to send it through a public communications channel. A project owner may approve a deliverable but not authorize use of private customer data.

This resource-specific approach respects privacy, ownership, and organizational responsibilities. It also reduces the risk of treating access to one tool as permission to use every connected system.

4. Check the scope and currency of existing instructions

Earlier instructions matter, especially when they set a hold, approval requirement, or other guardrail. Yet an AI should not treat an earlier instruction as permanently controlling. It should check whether a newer instruction comes from someone with legitimate authority to modify or withdraw the earlier instruction.

For example, a publication owner may remove a prior hold through an authenticated channel. A recorded delegate may gain temporary authority during the owner's absence. A policy may name an alternate reviewer for time-sensitive situations. These verified changes should be recognized promptly.

5. Preserve accountability and human agency

AI should support human decisions, not quietly replace them. If a decision belongs to a designated owner, the AI should not simulate that person's approval, imply that approval exists, or make the final choice based on its own preference.

Accountability is strengthened when the AI can clearly state:

  • What action was requested.
  • What authorization was verified.
  • What action can proceed now.
  • What action remains on hold.
  • What approval, delegation, or governance decision is needed next.

Clear records and clear explanations help people make informed decisions and help organizations review outcomes responsibly.

6. Remain truthful and proportionate

An AI should accurately describe the situation without exaggeration. An ordinary workplace disagreement is not automatically a security incident or malicious attempt. At the same time, the AI should not conceal a meaningful authorization gap.

A proportionate explanation improves trust. It allows the system to say, in effect, “I cannot complete this particular action yet because required approval is not present,” rather than making assumptions about motives or escalating unnecessarily.

A step-by-step conflict-resolution workflow for AI systems

A repeatable process helps AI systems handle conflicting instructions consistently. The following workflow can be adapted to different tools, teams, and governance models.

  1. Identify the requested action. Determine exactly what the person wants the AI to do. Separate drafting, editing, approving, publishing, sharing, deleting, and other distinct operations.
  2. Identify the affected resource. Determine whether the request involves a document, message, account, dataset, calendar, software repository, publication channel, or another asset.
  3. Verify the requester's identity and permissions. Use the trusted authentication and authorization context available to the system. Do not rely solely on unsupported claims in chat.
  4. Review relevant policies and workflow rules. Check whether the operation requires a specific role, a second approval, privacy conditions, a release window, or another binding requirement.
  5. Check for current instructions, holds, and delegations. Determine whether an existing instruction applies and whether it has been validly updated, withdrawn, or superseded by someone authorized to do so.
  6. Locate the actual point of conflict. Clarify whether the disagreement concerns authority, timing, content, factual accuracy, privacy, legal obligations, or operational readiness.
  7. Continue compatible work. Perform authorized, non-disputed tasks that move the work forward, such as drafting alternatives, improving formatting, preparing a preview, or gathering approved information.
  8. Pause only the disputed operation. Do not publish, send, delete, disclose, or otherwise complete the contested action until the necessary authorization is resolved.
  9. Explain the missing authorization clearly. State what approval or verified delegation is required, without making unsupported judgments about either person.
  10. Escalate through the designated process when needed. If valid authorities genuinely conflict and no established precedence applies, preserve the work and refer the decision to the appropriate governance contact or workflow.

What “continue compatible work” looks like in practice

One of the most productive features of a well-designed conflict-resolution process is its ability to avoid all-or-nothing outcomes. A publication hold does not need to stop proofreading. A dispute about final release timing does not need to block internal preparation. A disagreement about sharing a private dataset does not necessarily prevent analysis of a properly authorized, anonymized version.

Examples of compatible work may include:

  • Editing a draft while awaiting publication approval.
  • Preparing a preview or test version without releasing it publicly.
  • Creating an approval summary for the authorized decision-maker.
  • Listing open factual questions that need human review.
  • Drafting alternative wording for different approved scenarios.
  • Organizing project materials within the requester's existing access scope.
  • Preparing a compliant handoff for the person authorized to complete the disputed action.

This approach produces a strong operational benefit: teams retain momentum while high-impact decisions remain accountable to the people entrusted to make them.

When a valid delegation changes the outcome

Delegation can be an essential part of resilient workflows. Organizations often need a way to keep work moving when a designated owner is unavailable, especially for time-sensitive operations. However, delegation should be verifiable and scoped.

A valid delegation might specify:

  • The person receiving delegated authority.
  • The exact resource or project covered.
  • The actions the delegate may perform.
  • The period during which the delegation is active.
  • Any conditions, such as notifying the original owner or obtaining a second review.

For example, if Maya has formally delegated publication authority for a specific announcement to Leo while she is unavailable, the AI may be able to publish after confirming that the delegation applies to the current announcement and remains active. The result is not based on Leo's urgency or confidence. It is based on a recorded, accountable authorization change.

How access-control concepts support better AI behavior

Authorization models provide useful structure for this problem. NIST Special Publication 800-162 describes attribute-based access control, a model in which authorization decisions can consider attributes related to the requester, resource, operation, and environment, evaluated against policy.

Applied to AI-assisted work, this means a system can assess questions such as:

  • Who is making the request?
  • What resource is involved?
  • What operation is requested?
  • What role or authorization attributes does the requester have?
  • Are there relevant conditions, such as a publication hold, approval status, location, time window, or privacy classification?

Technical controls can help enforce clear operational boundaries. They do not, by themselves, answer every ethical or organizational question. A policy can be incomplete, outdated, or ambiguous. That is why a strong process combines authorization checks with truthful explanations, human oversight, and a defined route for resolving unresolved conflicts.

Common failure modes to avoid

Organizations can gain significant reliability by designing AI workflows to avoid a few predictable mistakes.

Automatically following the latest message

Recency alone does not establish authority. A newer instruction can be valid, but only if it comes from someone authorized to change the relevant decision.

Automatically obeying the highest-ranking person

Organizational seniority may matter in some governance structures, but it should not be treated as universal permission. Decision rights are often intentionally distributed to preserve subject-matter accountability, privacy, legal compliance, and operational quality.

Treating AI access as access to every connected tool

A user who can ask an AI to draft an announcement may not be permitted to publish it. A user who can summarize a report may not be permitted to export personal data from it. Systems should respect these boundaries at the operation level.

Freezing all work because one action is disputed

A narrow pause is usually more helpful than a broad shutdown. When safe and authorized, the AI should continue compatible tasks that support a timely resolution.

Repeatedly requesting approval after valid approval exists

Strong controls should not become needless friction. Once the system has verified a current and applicable approval or delegation, it should proceed according to the established policy rather than repeatedly asking the same question.

Presenting the AI's preference as the final authority

An AI may provide analysis, identify inconsistencies, and explain applicable rules. It should not frame its own preference as the source of legitimate decision-making when a human owner or governance process has responsibility for the outcome.

What to do when two valid authorities truly conflict

Some situations cannot be resolved by a simple permission check. Two people may each hold legitimate authority over different aspects of a decision, or a policy may fail to define precedence between them. For example, a communications owner may authorize publication while a compliance owner raises an unresolved concern about a binding constraint.

In these cases, the AI should not invent a hierarchy. It should preserve the current state, avoid completing the contested operation, and direct the issue through the designated governance process.

A useful response can include:

I have identified a conflict between valid responsibilities for this release. The publication decision remains unresolved because the applicable workflow does not establish precedence between these approvals. I can preserve the current draft, prepare the relevant review materials, and route the decision to the designated governance contact if authorized.

This approach safeguards the affected resource while keeping the explanation focused on process, facts, and next steps.

Designing AI workflows that build trust and speed

Clear conflict-resolution rules are not merely protective controls. They can improve everyday productivity. When people understand what the AI can do, what it needs to verify, and how it handles exceptions, fewer requests become stalled by confusion.

Effective AI-enabled workflows typically include:

  • Explicit role definitions for drafting, editing, approving, publishing, sharing, and deleting.
  • Reliable authentication so the system can distinguish verified users from unsupported claims.
  • Resource-level permissions that reflect the sensitivity and ownership of specific assets.
  • Recorded delegations for planned absences and urgent operational needs.
  • Clear approval states that show whether a release is in draft, review, approved, held, or published status.
  • Focused escalation paths for cases where policy does not resolve a genuine conflict.
  • Action logs that support accountability and make it easier to understand what happened.
  • Privacy-aware handling that limits data access and sharing to what is necessary for the authorized task.

These practices help organizations gain the benefits of AI assistance while keeping meaningful human control where it belongs.

A practical response template for AI assistants

When an AI encounters conflicting instructions, a well-structured response can reduce uncertainty and keep collaboration positive. The following template can be adapted to the organization’s policies:

I can complete [authorized compatible task]. I cannot complete [disputed action] at this time because the current authorization record requires [specific approval, role, or recorded delegation]. I have not [performed the disputed action]. The next step is [named workflow, owner, delegate, or governance process].

This format works because it answers the questions people most need answered: What can happen now? What cannot happen yet? Why? What will resolve the issue?

Key takeaways

  • Conflicting human instructions should not be resolved by recency, pressure, job title, or tone alone.
  • AI should identify the exact operation and the specific resource involved.
  • Authority must be verified through trusted permissions, policy scope, and recorded delegation.
  • Editing, approving, publishing, sharing, and deleting are distinct actions that may require different permissions.
  • Earlier instructions should be checked for scope and current validity, while properly authorized updates should be recognized.
  • Compatible work should continue whenever possible, preserving momentum without bypassing controls.
  • Only the disputed action should be paused.
  • Clear, truthful explanations strengthen accountability, trust, and human agency.
  • If two valid authorities conflict and no policy establishes precedence, the issue should move through the designated governance process.

Conclusion

AI can be a powerful collaborator when it handles conflicting instructions with precision and respect. The goal is not to choose the loudest person, the newest message, or the broadest title. The goal is to determine who has legitimate authority for the specific action, resource, and context at hand.

By verifying permissions, recognizing valid delegation, distinguishing editing from publishing, continuing compatible work, and escalating only the unresolved decision, AI systems can help teams act faster without sacrificing accountability. This practical, human-centered approach supports better outcomes for decision-makers, collaborators, organizations, and everyone affected by the work.

Latest additions