Blog
AI Red Lines: What the UN Actually Asked For (and What Your Team Should Do)
What the UN actually asked for
On September 7, 2026, UN High Commissioner for Human Rights Volker Türk told the 63rd session of the Human Rights Council that advanced artificial intelligence could pose an existential risk to humanity — and asked countries to agree on international red lines on what the technology should never be permitted to do.
Notice the ask. It is not "stop AI." It is not "pause AI." It is: decide which actions AI should never take without a human, and enforce the line. That is a very different message from the headline noise. It is also the message any responsible team can act on this week — regardless of what governments do.
Türk's speech drew on the Global Call for AI Red Lines, a movement launched at the UN General Assembly in September 2025 and signed by more than 200 figures, including 10 Nobel laureates. It asks governments to agree binding limits by the end of 2026, with an independent body to enforce them.
What "AI red lines" means, plainly
An AI red line is an action an AI system is never allowed to take on its own — regardless of what the model wants to do or what the prompt asked for. Crossing the line requires a human decision, on the record.
Two categories of red line matter for your team:
- Universal red lines — actions no AI should ever take autonomously, in any organization. Autonomous weapons systems that decide to kill without human input are the canonical example. This is what the UN speech was really about (Türk voiced "horror" at reports that Russia used fully autonomous drones in Ukraine allegedly killing three people in August).
- Organizational red lines — actions your AI should never take without your approval, tuned to your business's tolerance. Sending a customer refund. Signing a contract. Deploying code to production. Publishing to your public feed.
The UN is arguing for category 1. Every business needs to define its category 2.
The 5 red lines every business should draw first
Different teams will draw different lines, but almost every business we have seen deploy an AI workforce ends up with at least these five:
- Money leaves the building — refunds, payments, invoices, expense approvals. Cost of a mistake: measurable in cash.
- Something is published — social posts, press releases, blog posts, customer emails. Cost of a mistake: brand and legal.
- A contract is signed — vendor agreements, MSAs, NDAs, employment offers. Cost of a mistake: legal + strategic.
- Code merges to main / deploys to production — regardless of test coverage. Cost of a mistake: outage or security incident.
- Personal data flows out of the perimeter — customer records, health data, financial records. Cost of a mistake: compliance breach.
Every action outside these five can typically be delegated to an AI employee with review, not pre-approval. That is what "reduce risk by design" looks like in practice.
How a red line actually enforces itself
A red line without enforcement is a wish. Enforcement means the AI system physically cannot cross the line without a human decision — the code path stops, the request queues, a person sees it. Here is what that flow looks like:
Where teams are on this today
The gap between "we care about AI safety" and "we have red lines wired into our stack" is large — and it is the gap that separates teams that will pass 2027 procurement reviews from teams that will not.
The pattern we see across MANAV deployments is a slow climb: teams typically start with 1-2 loose approval rules, add real red-line policies as they hit near-misses, and reach mature governance around month 5-6. The teams that reach maturity fastest have one thing in common: they treated red lines as a day-one design decision, not a retrofit.
Why "slow AI down" is the wrong response
The temptation after a statement like the UN's is to pause deployments. Don't. The organizations that pause fall behind the organizations that add oversight and keep shipping. Every meaningful AI risk is already solvable with existing engineering primitives:
- Autonomous action risk → human-in-the-loop approval on the actions that matter.
- Explainability gap → agent traces + evidence chain (see our observability guide when it lands).
- Data-boundary risk → workspace-scoped RBAC + BYOLLM.
- Prompt-injection risk → per-request guardrails on the middleware.
The UN is asking for outcomes, not techniques. Any outcome can be delivered by a team that draws its red lines and enforces them.
Split of common red-line categories in practice
Across the businesses we work with, the distribution of red-line rules clusters heavily around communication and money — because those are the actions with the fastest blast radius. Data-boundary and infra rules come later, once the first-week wins are locked in.
Not every team needs every category. But if your list has fewer than three of the below, you have some drawing to do this week.
How MANAV draws + enforces red lines
On the MANAV platform, red lines are a first-class product feature — not a config file, not a prompt, not a policy PDF nobody reads.
- Per-action rules live in Guardrails and specify what/why/impact/rollback fields on every intercepted action.
- Approval queue at Human Approval is where human reviewers approve, reject, or edit-then-approve every red-line-crossing action.
- Evidence trail attaches to every approval — the exact prompt, the exact tool call, the exact decision — retrievable months later for audit.
Every de-risking primitive we ship — approvals, audit trail, evaluation, RBAC, guardrails — is a red-line enforcement primitive. That is the whole product thesis: run AI with proof.
See our pricing for how the trust primitives are packaged, or read the FAQ for the questions security reviewers ask most often.
AI red lines — FAQ
Are AI red lines a legal requirement yet? No. The UN is asking for binding international agreement by end of 2026 — there is no such agreement yet. But regulators in the EU (AI Act), UK, and US already write informal red lines into procurement rules; ignoring them closes doors.
Does every AI need red lines? Every AI that can take an action does. An AI that only answers questions needs guardrails but not action-blocking red lines. An AI that can send email, move money, or ship code absolutely does.
How many red lines is too many? If reviewers get more than ~10 approvals per day per person, fatigue sets in and approvals become rubber-stamps. Design for reviewer sanity — narrow the red lines to the actions that genuinely need a human.
What is the difference between a red line and a guardrail? Guardrails shape what the AI can do (topic, tone, tools available). Red lines gate what the AI will do (specific actions requiring human sign-off before execution).
Where do I start? Pick the 5 red lines from the earlier slide, wire them to a human approval flow, and iterate weekly. Two weeks in, most teams are shipping with more confidence than they had before the UN speech.
You may also like
AI Audit Trail: How to Audit Your AI Agents (2026 Compliance Guide)
An AI audit trail is the tamper-evident record of what your AI agent did, when, and why. With the EU AI Act's enforcement window opening August 2, 2026, and 88% of enterprises reporting AI agent security incidents in the last year, an audit-ready agent is no longer optional. Here's what the audit trail actually needs to capture, how to build one that survives an auditor's questions, and why retrofitted audit trails always cost more than the ones you build on day one.
AI Agent Evaluation: The Framework Every Team Should Adopt in 2026
An AI agent evaluation framework is how you know your agent is any good — before you ship it, and while it runs in production. This guide covers the three-level eval stack (unit tests, LLM-as-judge, online evals), the metrics that actually matter for agents (versus one-shot LLMs), and how to design rubrics that stabilize at 85%+ human agreement in three iterations.
Human-in-the-Loop AI Agent Approval Workflow: The 2026 Practical Guide
Human-in-the-loop (HITL) approval is what turns an AI agent from a demo into a production teammate. This guide covers the three oversight tiers, how to decide which actions need which tier, and the exact workflow shape that scales without creating reviewer fatigue.