High-consequence actions must not be committed by gaze alone
Aliases: gaze safety · irreversible gaze command · two-channel confirm
What it is
High-consequence actions—delete, pay, send, a medication dose, a driving-related toggle—must not be committed by gaze alone. Even after dwell or engagement has softened the Midas clash, the gaze channel’s false-positive rate stays higher than a key: calibration drift, an over-long reading fixation, an unexpected reflexive look can still fill a commit condition. High consequence demands a second piece of evidence independent of looking. This is a grading of outcomes, not a new dwell, and not an argument about how to make combination input faster.
Why it happens
Command errors from gaze are asymmetric: the cost of a false positive rises with the action’s consequence, while a false negative is usually “look again.” Paying, irreversible deletion, sending to the wrong contact, confirming a dose on a clinical UI—one false positive is not offset by “eye control is cool.” Gaze estimates carry spatial and temporal error. Engagement can cut commands outside a session; it cannot cut a sincere mis-look inside one.
Independent evidence means the second channel fails differently from the eyes. A finger pinch, a hardware key, a spoken phrase, or a second dwell on a confirm control that actually names the consequence asks another muscle or another semantics. If “confirm” is only “look at the same button a bit longer,” the two pieces of evidence are correlated and one drift takes both.
Studying it
Grade actions by consequence (undoable navigation, undoable edit, irreversible, money or safety) and inject known tracking disturbances on the same eye-controlled UI (slipping glasses, lighting change, instructing the participant to read a label); count false positives at each grade. Compare gaze-only commit, gaze plus a second dwell on the same button, and gaze plus an independent channel. The headline is not mean completion time; it is whether false positives at the high-consequence grade fall to something comparable with mouse and keyboard, and whether the independent channel is bypassed. Ethically, real money and real doses are not laboratory factors; use clearly labeled proxy tasks and report the gap between proxy and real consequence.
Where it stops holding
For people who can only use eye control and whose safety depends on a command (calling a nurse, acknowledging a ventilator alarm), “must not commit by gaze alone” collides with “must be able to finish independently.” Keep a protected eye-only path: larger targets, longer explicit confirm, or a scanning switch—do not hide the high-consequence command behind a key they cannot reach. Low-consequence, high-frequency, one-key-undoable actions do not need two channels; forcing them only fatigues. Medical and in-vehicle certification often already forbids single-channel confirm; a product cannot cover that with “false-selection rate was low in students.”
Applying it
- Label actions by consequence grade; irreversible, money, outbound privacy, and safety-related commands default to forbidding gaze-only commit.
- The second evidence must fail differently from the eyes: a key, pinch, voice, or a spatially separate confirm control whose label names the consequence.
- Verify by running a full task after deliberately disturbing calibration, confirming that high-consequence actions were not issued by gaze alone and that undo remains reachable.
Related
- Same group: C8.03.1 Look-to-select turns browsing into action · C8.03.2 Explicit engagement and disengagement conditions are required
- Adjacent: C8.04 Gaze-plus-confirm combinations · C4.27 Decoupling gestures from consequence severity
- Search:
high-consequence action·gaze confirmation·false positive cost