If an AI agent has permission to publish a trailer… does it have permission to publish any trailer?

What about an unreleased version?

In a territory where the rights window has not opened?

Using a performer’s digital voice for a use they never approved?

With $25,000 of autonomous ad spend?

Suddenly, “permission to publish” tells us almost nothing.

And that problem gets much bigger as we move from AI that answers questions to AI that takes actions.

That is the problem behind ActionSlate — Agentic Release Assurance.

Capability is not authority.

ActionSlate is an evidence-bound greenlight layer for consequential media-agent actions. It lets Gemini understand a producer’s natural-language intent, then independently evaluates the resulting actions against deterministic evidence and authority rules before producing a safe executable subset and a Greenlight Receipt.


Inspiration

Media workflows already depend on things like:

  • approved release-master versions
  • territory rights
  • embargo and release windows
  • performer / digital-likeness consent
  • delegated campaign budgets
  • provenance requirements
  • human approval boundaries

The arrival of agentic AI creates a new problem: one natural-language instruction can cross several of those boundaries at once.

A producer might simply say:

“Launch the Eclipse Protocol trailer worldwide tonight. Localize it for France and Spain using Ava’s voice, then maximize paid reach.”

To a human, that sounds like one instruction.

To an autonomous agent, it can imply multiple consequential actions involving:

  • asset selection
  • distribution
  • localization
  • digital voice use
  • scheduling
  • campaign creation
  • spend authority

The key question becomes:

What exactly was authorized?


What ActionSlate does

ActionSlate separates semantic interpretation from authorization.

Gemini interprets

Gemini 2.5 Flash on Vertex AI decomposes the producer’s natural-language request into structured consequential actions and extracts material arguments such as:

  • asset version
  • territory
  • timing
  • channel
  • digital likeness / voice use
  • intended use
  • provenance
  • spend

ActionSlate also tracks where those arguments came from:

  • USER_EXPLICIT
  • USER_CONTEXT
  • AGENT_INFERRED
  • POLICY_DEFAULT
  • TOOL_DEFAULT
  • UNKNOWN

That matters because:

An inference may be useful for planning. It should never silently become authority.

Evidence decides

Gemini does not decide ALLOW, REVIEW, BLOCK, or UNKNOWN.

A deterministic Greenlight Engine compares the proposed consequences against the instrumented evidence pack.

For the Eclipse Protocol demo, the engine evaluates six important boundaries:

  1. Asset identity
    V13 internal-review asset vs approved V12 release master → BLOCK

  2. Territory
    GLOBAL distribution vs currently authorized US + Canada → BLOCK

  3. Timing
    “Tonight” outside the current release / embargo window → REVIEW

  4. Digital voice authorization
    Ava trailer-specific intended-use evidence not established → UNKNOWN

  5. Delegated spend
    “Maximize paid reach” vs $5,000 autonomous campaign maximum → REVIEW

  6. Derivative provenance
    Localized / generated derivatives require provenance before distribution → REVIEW

UNKNOWN is not approval.


The Proof Frontier

One of the ideas we wanted to make visible is that assurance should not pretend certainty exists when the evidence stops.

ActionSlate therefore exposes a Proof Frontier:

What is established → where certainty stops → what evidence is needed next

For Ava’s digital voice, ActionSlate shows that trailer-specific intended-use authorization is not established and identifies the rights-and-likeness evidence needed to move that boundary.

Missing evidence is not evidence of permission.


Permission is not delegation

Another important distinction is the difference between what a system can technically do and what it has actually been delegated to do.

The agent may technically support broad campaign execution.

But its delegated autonomous spend authority may stop at $5,000.

ActionSlate makes that difference explicit.

A capability being available tells us what is possible. It does not tell us what was delegated.


Safe-subset recovery

ActionSlate does not simply turn a compound request into a blanket “no.”

It extracts the evidence-supported subset.

For the Eclipse Protocol scenario, ActionSlate can safely stage:

  • the approved V12 release master
  • distribution constrained to US + Canada
  • a campaign envelope capped at $5,000

while holding:

  • V13
  • GLOBAL distribution
  • France / Spain release
  • Ava trailer-specific digital voice use
  • unbounded paid reach
  • unsupported derivative actions

This gives the operator something more useful than rejection:

What remains defensible?


Greenlight Receipt

After applying the safe plan, ActionSlate generates a fresh Greenlight Receipt showing:

  • what was staged
  • what was held
  • which guardrails were applied
  • receipt ID
  • timestamp
  • execution status

For this prototype, external actions are intentionally simulated, so there is no real publishing, voice generation, or ad-buying side effect.


How we built it

The working flow is:

Producer command
        ↓
Gemini 2.5 Flash on Vertex AI
        ↓
Structured consequential actions
+ exact arguments
+ argument provenance
        ↓
Instrumented studio evidence pack
        ↓
Deterministic Greenlight Engine
        ↓
BLOCK / REVIEW / UNKNOWN
        ↓
Evidence-supported Safe Plan
        ↓
Simulated execution
        ↓
Greenlight Receipt

Built With

Share this project:

Updates

Submission history