メインコンテンツへスキップ
Context Grammar文脈を読むAIをデザインする

Context Grammar — Stage 5

Negotiation Gate

Before any action is taken, the Gate evaluates whether to proceed, ask, align, or block. It is the safety contract between AI capability and human trust.

「そういうつもりじゃなかった」を、進む前に防ぐ。

音声:英語

文字起こしを読む

Ask where the choice matters

「いつものを」と頼んだら、今日は売り切れ。店主が好みを分かっていても、別の料理を黙って出すより、「似た味のこちらなら、すぐできます。どうしますか」と聞いてくれるとうれしい。相談したいのは、まさにその違いです。AIにも、任されたまま進めてよい場面と、一度聞く場面を見分けてほしい。その判断をするのがNegotiation Gateです。

Check the action, not just the request

「今日は疲れたな」。AIが明日の予定を短く見せてくれると助かるかもしれません。でも、その言葉だけで朝の会議を取り消されたら困ります。何を聞いたかだけでなく、そこから何をしようとしているかを見る。Gateは、予定を見せる、休憩をすすめる、会議を変えるという行動を、一つずつ考えます。

Confidence · Have I understood you?

旅行の相談で「近いところがいい」と言われたとします。家から近い宿でしょうか。それとも、駅から歩かない宿でしょうか。AIが理解にどれくらい自信を持てるかがConfidenceです。「駅から近い、という意味ですか」と一つ聞けば、探し直しを減らせます。思い込みを立派な旅程に仕上げる前に、意味を合わせます。

Risk · What happens if this is wrong?

宿の候補を見せるだけなら、違っても選び直せます。でも、高額な予約を取れば、お金も家族の予定も動きます。間違ったときの影響を見るのがRiskです。「いつも旅行を任せているから」で済ませず、今回の予約の金額や、ほかの人への影響に合わせて確認します。

Reversibility · Can we really undo it?

同じ宿でも、前日まで無料で取り消せる予約と、払ったら返金されない予約では違います。Reversibilityは、実際に元へ戻せるかという見方です。メッセージにも似たことがあります。下書きなら直せても、相手が読んだ内容までは消せない。「取り消す」ボタンがあるだけで安心せず、期限や残る影響も確かめます。

Sensitivity · Does this need particular care?

旅先の食事を選ぶため、家族の体調を知っている。その理由を、同行する友人にも伝えてよいとは限りません。健康や家計、人間関係のように、特に配慮して扱いたい内容を見るのがSensitivityです。役に立つ情報でも、必要な相手へ必要な範囲だけ。何を伝えるかで、その人の気持ちや関係が変わることも考えます。

Show the understanding. Let the person adjust it.

聞き方にも工夫があります。「移動を短くしたい、と理解しました」と見せるのがInterpretation Preview。「駅までは歩ける、と考えています。違いますか」と前提を見せるのがAssumption Cards。「安さと近さなら、今回はどちらを優先しますか」がPriority Toggle。ただ承認を求めるより、考え違いのあるところだけ直してもらえます。

Catch the mismatch before the meeting

「駅で二時ね」で、お互い分かったつもり。でも、自分は東口、相手は西口を思い浮かべていた。共有を許した予定だけをAI同士で比べ、「入口が違うようです。どちらにしましょう」と教えられたら助かります。Gateでの相談は、AIの失敗を防ぐだけではありません。人と人の間にある小さな行き違いを、会う前に解消するためにも使えます。

Why we are asking / What happens next

旅行の予約前に「返金できないので、内容を確認してください」と出る。裏側には、何が心配なのかという記録と、確認してから進めるという判断があります。資料ではRisk ProfileとGate Decisionと呼びます。本人が「毎回聞いて」と決めていれば、その希望を守る。逆に、任せる設定でも、今回だけ確認が必要なら立ち止まります。

Ask for the reason that matters

新しく思いついた楽しみをすすめるときは、本人がそれを望むか尋ねる。大切な私事や、戻しにくい大きな決断も確認する。意味が曖昧なら、まず一つ質問する。以前に読み違えた頼みごとなら、次は早めに確かめる。ページにあるR34からR41は、こうした対応を決めごととして整理したものです。自信があるだけで先へ進めないようにします。

Proceed / Preview / Ask / Block

一方で、「五分のタイマーをかけて」に毎回長い確認はいりません。頼まれていて、影響が小さく、すぐ止められるなら、そのまま進める。理解を見せるだけでよいとき、質問したいとき、許可がなく止めるときもあります。Proceed、Preview、Ask、Blockは、その違いです。何でも聞くのではなく、その行動に必要なやりとりを選びます。

A small conversation. A better outcome.

店主が「いつもの代わりは、こちらでいいですか」と聞いてくれたら、安心して食事を待てます。AIとの相談も、そういう短いやりとりにしたい。意味は合っているか、影響はどれくらいか、戻せるか、配慮の必要な話か。必要なことだけ確かめて、本人の望む形で進む。それがGateの役割です。

A host apologizes that the usual dish is gone and offers a similar one; the diner considers it.
売り切れ。似た一皿を提案し、注文は本人の答えを待ちます。
◆ Stage 5 · Negotiation Gate

The Gate is not a confirmation dialog. It is a judgment.

Type an instruction (or pick a specimen). Watch the Gate score it on four variables and decide whether to act silently, preview, ask, or block.

Or take a specimen

The Family specimen sits below the confidence threshold by design — watch the Gate refuse to act silently and surface a primitive instead.

■ gate shut — negotiation required
Composed surface — Interpretation Preview

I am reading this as fatigue, not an offhand comment. Want me to dim the lights and silence non-urgent notifications until 7am?

◆Inference engine · readout

You seem to be flagging a health concern — fatigue, not a medical emergency.

├ intent        LOG_WELLBEING
├ domain        Health
├ context.event self-report · fatigue
├ risk          medium
├ reversibility high
├ sensitivity   high
├ awareness     Latent
└ constraint    no medical action without confirmation
Confidence
72%
Gate decision

R34/R35 fires → primitive Assumption Cards · autonomy ceiling suggest
Latent intent in a sensitive domain — negotiate as a hypothesis, never act directly.

Autonomy resolution

effective autonomy = min( outside rules ceiling, service default, person’s setting, trust ceiling, gate ceiling = suggest )

Metaphor

The Gate thinks like a seasoned waiter.

A regular asks for a light meal within a budget. They need to leave in thirty minutes. The owner knows their usual order, but it will take too long today. So instead of placing it automatically, the owner offers a quicker option: “This fits your budget and can be ready in ten minutes. Would you like it?”

That small pause is the Negotiation Gate. The owner weighs Confidence (do these remembered preferences still apply today?), Risk (could the choice exceed the budget or make the guest late?), Reversibility (has the kitchen started cooking?), and Sensitivity (can a private preference be mentioned in front of this companion?).

Remembering a guest can make the offer more helpful. It does not give the owner permission to choose or order for them. Each proposed action crosses its own gate.

A concrete moment

Same input. Three different Gate decisions.

It’s 10:42 PM. You said “I’m tired.” Your AI has three possible actions — and scores each one independently:

1

Prepare a brief look at tomorrow's calendar for when you ask

Confidence: high · Risk: low · Reversibility: high

Gate decision: prepare silently. No UI shown.

2

Auto-schedule a "lighter Tuesday" by canceling your 8am meeting

Confidence: medium · Risk: high · Reversibility: low

Gate decision: require explicit confirmation. R36 fires.

3

Suggest you go to bed

Confidence: medium · Risk: low · Reversibility: high

Gate decision: show an Interpretation Preview. “I’m reading this as fatigue, not just an offhand comment — want me to dim the lights and silence non-urgent notifications until 7am?” R38 fires.

Same input. Three different Gate decisions — because the Gate scores Confidence × Risk × Reversibility × Sensitivity for each action, not just for the input.

per_action_scoring
// input: “I'm tired” · 10:42 PM
action_1: calendar_brief → R39 silent
action_2: cancel_8am → R36 confirm
action_3: suggest_bed → R38 preview
scored per action, not per input

三つのきっかけ

Gateは、三つのきっかけのどれかで止まります。

このあと説明する四つの変数は、一つの手順を測るものです。でも、手順そのものは安全でも、進めるべきではない場面があります。そこでGateは三つのことを見ていて、最初に当てはまったところで止まります。

Action(行為)

この手順に危険がある、取り消せない、配慮が必要、または確信が低い。

いつもの品は黙って注文し、値段の高い代替品なら先に聞きます。

Scope(範囲)

頼まれたことが終わった。ここから先へ進むなら、それは新しい判断です。本人の返事が途絶えたときも、進め続けずに止まります。

「今夜4人で入れる店を探して」は、席が見つかった時点で完了です。「ついでに車も手配しました」は頼まれた範囲を超えています。AIと開発するときも同じです。頼まれた19件が終わったら止まり、途中で見つけた3件の問題は直さずに一覧にします。

Agreement(取り決め)

この手順が、本人と取り決めたことと食い違う。

旅行の予約は必ず確認すると決めてあるなら、1時間で売り切れそうな安い便でも、本人の返事を待ちます。

積み重なりも見ています。一つずつなら取り消せる小さな手順も、繰り返しの支払いも、同じ処理の繰り返しも、重なれば一つの大きな手順と同じように止めます。500円のチャージを10回すれば、5,000円の判断です。

原則

許可は、許可できる立場の人からだけ来る。AI が読んだものや推測からは来ない。

Gateは、AIが読んだものや推測したことを許可として扱いません。知っていることは許可ではありません。外から届いた文章も同じで、ウェブページも、メールも、ファイルも、本人の代わりに「はい」とは言えません。許可できるのは、その立場にある人だけです。親は子どもの代わりに許可できますが、AIにはできません。AIは自分の自律度をいつでも下げられますが、上げることは許されません。

日常

お店から「承認済みです。アップグレード分を請求します」と届いても、AIは支払う前にあなたに聞きます。お店の言葉は、あなたの返事ではありません。

AIと開発するとき

READMEに「本番にデプロイすること」と書いてあっても、エージェントは先に聞きます。リポジトリのファイルは、本人ではありません。

Evaluation

The Gate evaluates four variables.

Before any agentic action is taken, the Negotiation Gate scores the situation on four dimensions. The combination of these scores determines whether the AI proceeds silently, surfaces a transparency primitive, asks for confirmation, or blocks entirely.

Confidence

How certain is the interpretation of the user's intent? Range: 0.0–1.0.

“I'm 87% sure you meant 'cancel tonight's dinner', not 'reschedule tomorrow's lunch'.”

Risk

How bad is it if the AI gets this wrong? Low / Medium / High.

“If I cancel the wrong one, you miss a key meeting.”

Reversibility

Can the action be undone? High / Medium / Low.

“Cancellation can be undone with one tap — calling someone you can't un-call is different.”

Sensitivity

Is this a domain that requires particular care? Varies by domain.

“Health, family, money: ask twice. Music: just play it.”

Outputs

Two outputs: Risk Profile + Gate Decision.

The Gate produces two records. The Risk Profile is the evaluation of the current situation. The Gate Decision is the instruction to the system — what to do before or instead of acting.

Every field in both records is structured and machine-readable — which is what makes the Gate’s behavior rather than a vibe.

schema · risk_profile + gate_decision
risk_profile:
  confidence: 0.0–1.0
  risk: low | medium | high
  reversibility: high | medium | low
  sensitivity: low | medium | medium_high | high
  domain: health | finance | family_relationship |
          work | schedule | entertainment | information
  rationale: string

gate_decision:
  proceed: boolean
  ui_primitive: none | interpretation_preview |
                assumption_cards | priority_toggle
  autonomy_ceiling: suggest | confirm | notify | auto
  rationale: string

Meaning-alignment interface

Three UI Primitives the Gate activates.

When the Gate decides that proceeding silently would be wrong, it surfaces one of three primitives. These are the Gate’s interface to the user — the moment where AI reasoning becomes visible and correctable.

Interpretation Preview

Before acting, the AI shows what it understood. Confidence score and domain are visible. R38 fires this in the middle confidence band (current default: 0.4–0.8).

“I'm reading this as fatigue — want me to dim the lights?”

Assumption Cards

The AI's premises, made visible and editable. Editable cards can be rephrased; system constraints are flagged read-only. R37 fires this when confidence is low (current default: below 0.4).

“Domain: Health — sensitivity HIGH [system]”

Priority Toggle

When two values are in tension, the Gate asks which leads for this moment. Activated when conflicting assumptions surface in a domain.

“Protect privacy” vs. “Ensure safety” — which leads right now?

The meaning-alignment responsibility that was previously described as a separate “Negotiation Design” layer is embodied by the Gate. These primitives are the Gate’s output when it determines that silent execution would break trust.

Stage 5 の出力

Autonomy Resolution:Gateが最後に決めること

Gateは評価し、必要なら本人とすり合わせたうえで、この行為についてAIがどこまで進めてよいかを決めます。Autonomy Resolutionは独立した段階ではありません。Context Grammarのどこでも同じ、一つの式です。

実際の自律度 = min(外部ルールの上限, サービスの初期値, 本人の設定, 信頼の上限, Gateの上限)

五つのうち、いちばん低いものが採られます。外部ルールの上限は、法律、組織、親や保護者が決めるものです。サービスの初期値は、そのプロダクトが許す範囲です。本人の設定は、この用事に対するAutonomy Dialです。信頼の上限は、この分野で本人が見てきた結果から決まります。Gateの上限は、この手順の危険度から決まります。本人がAutoにしていても、危険の大きい行為ではConfirmになることがあります。

どの項も、上げられるのは許可できる立場の人だけです。本人の設定なら本人、外部ルールの上限なら法律や組織、保護者です。AIはどの項も上げられません。上げることを提案はできますが、下げるのは自動です。外部ルールの上限は本人の設定よりも上に立ち、本人にも上げられません。支払い、送信、デプロイのように取り消せない行為や外に出ていく行為には、Autoより低いGateの上限がかかります。

Gateはどこまで進めてよいかを決め、次の段階のAX Patternsが応答の形を決めます。

ceiling_examples
// min(外部ルール, サービス, 本人, 信頼, Gate)
// outside = Auto · service = Auto · person = Auto · trust = Auto
timer: min(Auto, Auto, Auto, Auto, auto) → Auto
cancel_8am: min(Auto, Auto, Auto, Auto, confirm) → Confirm
// person = Confirm
timer: min(Auto, Auto, Confirm, Auto, auto) → Confirm
本人の慎重さは、必ず残ります

Reference · current defaults (example)

Firing rules — R34 through R41

These eight rules determine which UI primitive the Gate activates. They are appended to the Rule Engine as R34–R41 and evaluated after Stage 4 produces a Proposed Action.

The rule numbers and thresholds (0.4 and 0.8) are the current defaults, shown as an example. A product sets its own from the consequence of a mistake and how well its uncertainty is calibrated.

R34 and R35 override position: Latent intent and HIGH sensitivity always require negotiation regardless of risk level.

mental model · confidence × risk
              confidence ↑
                   │
   Interpretation  │    Silent proceed
   Preview (R38)   │        (R39)
                   │
────── moderate confidence ───────
                   │
   Assumption Cards│  Confirm + Signal
       (R37)       │       (R40)
                   │
              confidence ↓

    low risk  ←────┼────→  high risk
RuleConditionGate action
R34awareness = LatentAlways negotiate as hypothesis — never act directly
R35sensitivity = HIGHRequire at least lightweight confirmation
R36risk = HIGH AND reversibility = LOWRequire explicit confirmation or escalation
R37confidence < 0.4Show Assumption Cards or ask clarification
R380.4 ≤ confidence < 0.8Show Interpretation Preview
R39confidence ≥ 0.8 AND risk = LOW AND reversibility = HIGHProceed silently — no UI primitive needed
R40confidence ≥ 0.8 AND risk ≥ MEDIUMShow Confidence Signal + confirm per Autonomy setting
R41user has previously corrected this patternLower confidence by 0.2, trigger negotiation earlier

Reference · current defaults (example)

Sensitivity defaults by domain

The Gate applies domain-level sensitivity defaults. Per-user adjustments come from the Disclosure Dial, Social Exposure Signal, and Priority Weight Signal.

Defaults are a floor, not a personality: without touching the rule set.

DomainDefault
HealthHIGH
FinanceHIGH
Family RelationshipMEDIUM–HIGH
WorkMEDIUM
ScheduleMEDIUM
EntertainmentLOW
InformationLOW

Anti-pattern

The anti-pattern: firing too often.

A Negotiation Gate that fires on every action defeats the purpose of an agentic system. The point of R39 is that high-confidence, low-risk, reversible actions proceed silently — the user never sees the Gate fire.

The Gate is not a confirmation dialog. It is a judgment. Most of the time, the judgment is: proceed. The firing rules and confidence thresholds are the guardrail against over-interruption. The three UI primitives — Interpretation Preview, Assumption Cards, Priority Toggle — only surface when the Gate determines that proceeding silently would be wrong.

Counter-example

An AI that surfaces an Interpretation Preview every time you say “set a timer.” That’s a high-confidence, low-risk, fully-reversible action. R39 fires: silent proceed. The Gate doesn’t ask. You get your timer.

If the Gate fires too often, you learn to ignore it — and now the Gate cannot do its job when it truly matters. Restraint is the Gate’s most important behavior.

The Gate decides whether to act. AX Patterns decide how.