Executive summary
Debates about AI in permitting usually collapse three things: rules that execute identically every time, models that assist with reading and retrieval, and people who interpret and decide.
Deterministic rules are precise, repeatable, versioned and testable. AI is useful for extraction, classification, retrieval, comparison and drafting, and it is probabilistic. Professionals handle ambiguity, exceptions, accountability and the decision. Keeping the three distinct is what makes a system auditable.
The three roles
Deterministic rules apply where a requirement can be expressed as conditions over known facts: a dimension against a threshold, a document present or absent, a classification permitted or not for an occupancy. Because the logic is explicit, it can be tested, versioned against an edition, and explained without reference to model behaviour.
AI assistance applies where information must be found before any rule can run: locating a title block, classifying a discipline, extracting a schedule, matching a note to a referenced standard, identifying what changed between revisions. These are reading tasks and they are probabilistic; output carries a validation status and stays inspectable against the source.
Human judgment applies wherever the requirement calls for interpretation — performance-based provisions, alternative solutions, unusual configurations — and at the point of decision. Federal guidance treats human oversight of automated decision support as a control requirement scaled to impact [1][2].
| Deterministic rules | AI assistance | Human judgment | |
|---|---|---|---|
| Best at | Threshold and presence checks | Reading, classifying, retrieving, comparing | Interpretation, exceptions, decisions |
| Behaviour | Identical output for identical input | Probabilistic, confidence-bearing | Accountable and contextual |
| Explanation | Rule statement and citation | Source evidence and confidence | Recorded reasons |
| Failure mode | Consistent misinterpretation | Extraction and classification error | Time pressure and automation bias |
| Control | Test cases and expert validation | Evidence links and validation status | Workload design and recorded overrides |
How work is routed
Rule outcomes are reported with words and icons rather than colour alone — Pass, Potential Issue, Requires Review, Not Applicable — and anything a rule cannot resolve is escalated rather than guessed [3].
Governance expectations
The NIST AI Risk Management Framework organises practice around governing, mapping, measuring and managing risk across the lifecycle, with accompanying playbook material [4][5]. Canada’s Directive on Automated Decision-Making requires impact assessment, transparency, quality assurance and human intervention proportionate to impact [1], supported by the Algorithmic Impact Assessment [2]. Guidance on generative AI adds caution on accuracy and provenance in public services [6].
None of these prescribe a permitting architecture. They do make clear that explicit logic where logic suffices, validated assistance where reading is required, and human authority at the decision is a structure that can be assessed.
Implications for authorities having jurisdiction
Ask any vendor which specific checks are deterministic, which depend on AI extraction, and where a person is required. The answer should be a list per permit type, not a claim about the system as a whole.
Design oversight with time in it. Meaningful review of a finding requires the reviewer to be able to open the evidence, which requires workload planning as much as interface design.
Implications for applicants and professionals
Deterministic checks are predictable, so where a rule statement is published a submission can be prepared against it. For any finding, the useful question is not whether the system is accurate in general but what this finding rests on: which sheet, which fact, which requirement, which edition, what validation status.
Risks, limitations and safeguards
- Deterministic rules can encode a misinterpretation; expert validation and test cases are the control.
- Extraction errors propagate into rule evaluation, producing confidently wrong results.
- Automation bias is real; oversight needs designed intervention points, evidence access and review time.
- Rule coverage is partial by design and must be stated; silence must never read as compliance.
- Model and platform updates change behaviour; re-evaluation belongs in change control.
PermitAssure perspective
PermitAssure separates the three capabilities deliberately. Configured deterministic rules evaluate facts against jurisdictional requirements for a stated edition; AI assistance handles extraction, classification, retrieval and comparison, carried forward as evidence rather than conclusions; reviewer actions — accept, modify, reject, escalate — are recorded with reasons. Capabilities are labelled per feature as Available, Configurable, Pilot Capability, Planned, Future Roadmap, Integration Dependent or Jurisdiction Dependent.
Five key takeaways
- Deterministic, AI-assisted and human work are three responsibilities, not three settings.
- AI output belongs upstream of a rule or a person, never at the point of a regulatory outcome.
- Coverage, rule versions and validation status must be visible to reviewers and applicants.
- Oversight requires designed intervention points, evidence access and review time.
- Status labels must not rely on colour alone.
References
- Directive on Automated Decision-Making. Treasury Board of Canada Secretariat. www.tbs-sct.canada.ca. Accessed 3 August 2026.
- Algorithmic Impact Assessment. Government of Canada. www.canada.ca. Accessed 3 August 2026.
- Web Content Accessibility Guidelines (WCAG) 2.2. W3C. www.w3.org. Accessed 3 August 2026.
- AI Risk Management Framework. National Institute of Standards and Technology. www.nist.gov. Accessed 3 August 2026.
- AI RMF Playbook. NIST AI Resource Center. airc.nist.gov. Accessed 3 August 2026.
- Guide on the Use of Generative AI. Government of Canada. www.canada.ca. Accessed 3 August 2026.
Cited statements follow the sources above. Frameworks, diagrams and interpretation in this article are PermitAssure's own.
Related resources
Next step
Ask for a per-permit-type list of which checks are deterministic, which are AI-assisted, and where a reviewer is required.
See the technology approachPermitAssure provides digital review, workflow and decision-support capabilities. This resource is educational and does not constitute regulatory, legal, architectural or engineering advice. Final interpretations, approvals and regulatory decisions remain the responsibility of the applicable Authority Having Jurisdiction and its authorized professionals.