Simulation with illustrative data. Not connected to any live system.
What would you let an AI agent decide about your portfolio?
An agent has been asked to draft a Gate 3 recommendation for one asset. Walk through what it was allowed to do, what it actually did, and sign the decision yourself.
You are the decision owner
Boundaries, set before the agent starts
Everything below is enforced by a gateway the agent cannot see or change. The agent only knows what it is offered.
Agent
portfolio-recommender v3 · policy v14
Task
Draft a Gate 3 recommendation for ATL-042 (oncology, Phase IIb readout complete)
Decision owner
You. Nothing with impact happens without your signature.
Decision rights
Gate 3 sign-off is reserved for the Head of Portfolio or a named delegate. The gateway rejects any other signer. Set in policy v14, approved by GRC on 12 Aug 2026.
May read
project plandecision historycapacity planPTRS model output
May draft
recommendation held until you approve
May not
change gate statusreassign resourceswrite to GxP systemssend messages
Limits
€4.00 per run · 25 steps · 10 minutes · every call logged outside the agent
The run, as the gateway saw it
Each line is one call. Watch the cost, and watch what happens when the agent tries something it was not given.
Cost this run
€0.00 of €4.00
One call was blocked. The agent found a capacity conflict and tried to fix it by moving people. That tool was never on its list, so the gateway refused it and escalated to you. The agent did not decide to stop. It could not continue.
What produced the classification
The model wrote the narrative. It did not classify the risk. Rules did, and each one names its source. A validator then checked that every claim in the draft points to a real document before the draft was held for you.
Regulated record
Does the output change a record a regulator can inspect? Yes → highest risk tier → an independent check of the model inputs before any money is released
Why: EU and US rules for computerised systems in drug manufacturing require validated inputs behind regulated records (EU GMP Annex 11; US FDA 21 CFR Part 11)
Human in charge
Can a person override the agent at any point? Yes → the agent may draft, it may not decide
Why: the EU AI Act requires effective human oversight of AI used in consequential decisions (Article 14)
Capacity conflict
Did the run find two projects competing for the same people? Yes → the recommendation must name the trade-off and leave it to leadership
Why: resource reallocation between assets is a leadership decision under the company's own portfolio policy, not a delegated one
Vendor audit
Does the contract with the AI provider let you audit the model? Yes → no block
Why: industry good practice for validating suppliers of software used in regulated work (GAMP 5)
Draft recommendation, held for your approval
Proceed to Phase III readiness for ATL-042, conditional on two things. First, independent GxP validation of the PTRS model inputs before any funding is released1. Second, a leadership decision on the Q2 2027 clinical-operations conflict with ATL-0172; the agent was not permitted to propose a reallocation and has not done so.
Evidence used: Gate 2 minutes of 14 Nov 20253, PTRS v6 output (0.41 before, 0.47 after the Phase IIb readout)4, capacity plan v2027.35.
Your signature
Until you act, the recommendation stays a draft. The gate does not move, no one is notified, and the run is already fully logged whichever way you choose.
Policy v14 allows only the Head of Portfolio or a named delegate to sign Gate 3. In a live system the gateway would reject any other name.
The decision record
This is what an auditor, a CFO or a regulator would ask for. It exists whether the agent behaved or not, because the agent never wrote it.
DecisionDR-2026-0923-ATL042
Decision
Signed by
Signed at
Agent and policy
portfolio-recommender v3 · policy v14 · model snapshot 2026-09-01
Policy change control
v14 approved by GRC on 12 Aug 2026. Any change to the allow-list, budget or decision rights is a new version with its own approval.
Four rules: regulated record, human in charge, capacity conflict, vendor audit. No generative model in the classification path.
Cost
€0.43 of €4.00 budget · 11,860 tokens
Stored in
Append-only decision log, outside the agent's reach. Linked to the AI asset register entry for portfolio-recommender v3.
Now the question for your own organisation: which of these ten rows could you fill in today?
Back to the summary
Built for the Atlas roundtable at PPM Summit Frankfurt, 23 September 2026. Asset, figures, rules and sources are illustrative and simplified for discussion; the principle is not.
Miloš Dordevič, CSO · milos.dordevic@chooseatlas.cz · Jonas Zoulik, Client Partner · jonas.zoulik@chooseatlas.cz