The hardest problem wasn't the calculation — it was the permission model. In a market where trust in any app touching your money starts from a lower baseline, an AI feature is a liability unless permission is core product, not a settings-page afterthought. I built a six-level AI interaction ladder — Inform, Explain, Recommend, Prepare, Confirm, Automate — and every AI-initiated action in MOVA sits at exactly one level, visibly. Nothing touching real money moves without an explicit tap anywhere in V1 or V2; automation is opt-in per rule, never on by default, and fully reversible.