Runtime Authority Control verifies machine-initiated actions before they execute, moving enterprise AI from detection after the fact to authorization before the fact.
The first wave of artificial intelligence changed how people create. The second wave is changing what systems are allowed to do.
AI is no longer confined to drafting emails, summarizing documents, and answering questions. Intelligent systems now trigger workflows, reach into enterprise software, update customer records, call APIs, and start processes that used to require a person. As that autonomy spreads across finance, operations, customer service, and internal business systems, one question sits in front of every operator: before an AI system acts, who decides what it is allowed to do?
For technology founder Emily Hartstone, that question was never theoretical. It became an operating problem when AI agents inside her own business began taking actions she had never authorized. Nothing on the market could stop them before execution, so she built the layer that could.
In 2022, Hartstone created Runtime Authority Control (RAC), an enterprise authorization layer that verifies machine-initiated actions before they execute. Hartstone Institute LLC owns the technology and the intellectual property behind it. Runtime Authority Control LLC is the operating company.
“The real shift is not AI generating content. The real shift is AI taking action: triggering workflows, calling APIs, modifying records, moving money,” Hartstone said. “Once machines act, the question stops being what did the system say and becomes what is this system allowed to do. That is the question Runtime Authority Control answers, before execution, not after.”
The distinction separates two different disciplines. Most organizations have invested in monitoring that flags problems after they occur. RAC sits earlier in the sequence. It evaluates whether an action is permitted at all, and it returns that decision before the action runs.
Timing is the entire point. A single unauthorized machine action can touch sensitive records, move money, or reroute a workflow long before a compliance alert ever reaches a human.
“I did not build RAC because I read a trend report. I built it in 2022 because my own AI agents started taking actions I never authorized, and there was nothing on the market that could stop them before the fact,” Hartstone said. “The market caught up to the problem. I had already built for it.”
Building ahead of demand is a habit Hartstone traces to her late father, Joel Martin Hartstone, whose career spanned broadcasting, entertainment law, and investment banking. She does not wait for an industry to name a problem before solving the one in front of her.
Hartstone Institute LLC is the home for her technology research and enterprise infrastructure work, including Runtime Authority Control. Separately, she runs From the Hart Management LLC, a client services firm advising founders and growing companies on strategy and operational execution; Soul Systems Studio, which builds digital products for entrepreneurs; and EmPOWERthePATIENTS, her advocacy initiative for people living with rare and chronic illness. Different industries, one principle: systems should strengthen human decision making, not replace it.
That principle is getting harder to ignore. Business leaders are no longer evaluating AI only as a productivity tool. They are evaluating it as an active participant in operations, which turns accountability, authority, and trust into engineering questions rather than policy questions.
Hartstone’s position is that the work starts by naming who holds the authority to approve a machine action, then enforcing that answer inside the system itself rather than in a document nobody reads at runtime.
“Detection tells you what went wrong. Authorization decides what is allowed to happen,” Hartstone said. “Those are different disciplines, and the future of enterprise AI depends on the second one.”
Enterprise AI will keep getting faster and more capable. The question underneath it does not change. Before a machine acts, someone has to decide what it is allowed to do.
About Hartstone Institute LLC
Hartstone Institute LLC holds the patents, trademarks, and copyrights across the Runtime Authority portfolio and is the home for founder Emily Hartstone’s technology research and enterprise infrastructure work. More at hartstoneinstitute.com.
About Runtime Authority Control
Runtime Authority Control is an enterprise authorization layer that verifies machine-initiated actions before they execute. Runtime Authority Control LLC is the operating company. More at runtimeauthoritycontrol.ai.
Media Contact
Chuansea Keller
media@hartstoneinstitute.com
emilyhartstone.com | Instagram @empromo_hart
Runtime Authority Control, RAC, Runtime Authority Fabric, CORTHEM, and UNANIMOS are trademarks of Hartstone Institute LLC, and the technologies they describe are the subject of pending patent applications.