This regulatory application note operationalizes the impossibility result established in On the Impossibility of Observability-Based Authorization (Meyman, 2026; Technical Note v1.4.0; DOI 10.5281/zenodo.19647542) for requirements that call for authorization before execution. It introduces the Authorization Artifact Test, a two-prong, regime-neutral instrument for determining whether a candidate governance architecture can, in principle, satisfy a pre-execution authorization requirement. The test asks whether a verdict exists before execution and whether an independent third party can reconstruct that verdict from the authorization artifact, governing policy, context, and proposed action specification, without access to the governed system. If either condition fails, the architecture cannot satisfy such a requirement, regardless of latency, automation, sophistication, or vendor description. Passing both prongs establishes a threshold, not complete conformance: non-bypassability, fail-closed enforcement, ownership of authority, governed escalation, and input provenance are assessed separately, including under the Five Tests Standard (5TS). The note applies the test, in conditional form, to contexts arising under the EU AI Act (Article 14), the General Data Protection Regulation (Article 22), the HIPAA Security Rule technical safeguards (45 C.F.R. § 164.312), DFARS 252.204-7012, and the NIST AI Risk Management Framework's GOVERN function. It does not interpret those instruments and does not assert that any of them expressly requires the artifact defined here. Whether pre-execution authorization is required is determined by the applicable authority or organization; the test determines whether the architecture can produce the corresponding authorization artifact. Where such a requirement has been established, the note derives the consequences of the impossibility result for architectures commonly described as guardrails, monitoring systems, observability platforms, and human review of system outputs. The dividing line is structural: a model-generated candidate held pending at a non-bypassable runtime authorization boundary may be the subject of a conforming pre-execution verdict; a verdict rendered only after release, or dependent on unreconstructable observation of the governed system, is not authorization. The contribution is classificatory rather than prescriptive. The note is an architectural analysis, not legal advice, a legal opinion, or a compliance determination, and it does not introduce new doctrine or prescribe implementation. It supplies an operational instrument for applying the formal result in regulatory hearings, conformity assessments, audits, supervisory reviews, and standards-body work, distinguishing architectures that produce pre-execution, independently reconstructable verdicts from those that do not. Version 1.1 clarifies the analytical status of the regulatory mappings, distinguishes proposed-action generation from effect-bearing execution, and situates the Authorization Artifact Test as a necessary threshold rather than a complete compliance determination. Intended audience: regulators, regulatory counsel, standards-body participants, and conformity-assessment bodies. This note is part of the FERZ research program on deterministic AI governance. The full corpus is available at https://zenodo.org/communities/ferz/.
Meyman et al. (Sun,) studied this question.