Skip to content

How to use Jev with UiPath - where a decision model beats an LLM agent and where it fails

We tested the Jev decision model on four tasks from our UiPath projects. It classified emails at least as accurately as an LLM agent and roughly seven times faster, yet it approved three overbilled invoices. Here is where it fits in UiPath Maestro, AI Trust Layer and Delegate.

Jev works best in UiPath as a decision layer between data extraction and action. In our measurement on four tasks taken from UiPath projects, the Jev decision model classified emails at least as accurately as an LLM agent and roughly seven times faster. It also approved three overbilled invoices, because it does not do arithmetic. That leads to a simple rule: extraction in IXP or an LLM, calculation in code, the decision in Jev, and any irreversible action with a human. Below we cover what the community has already built, how we measured, and where Jev fits in UiPath Maestro, UiPath AI Trust Layer and UiPath Delegate.

What is Jev and why is the UiPath community talking about it?

Jev is a decision model from TypeSafe AI that returns a choice and a confidence score instead of text. You give it a description of the situation and questions of three types: choice (pick from a list), score (rate on a scale) and noul (yes or no with a probability). The answer is a decision and a number, not a paragraph to interpret. For automation that matters: the result goes straight into a process variable and a gateway.

The launch thread on Hacker News on 15 September 2026 collected 1,982 points and 520 comments. On GitHub, a search for “jev typesafe” now returns 2,919 repositories, almost all created after 16 September. The UiPath Forum does not have a single thread about Jev yet, even though UiPath developers have been building with it since week one. Last week I covered the model itself, confidence calibration and a comparison with the local Laya model in my first post on Jev. This one is about practice in UiPath projects.

What has already been built with Jev on UiPath?

There is no native integration: Jev is not a UiPath component but an external model called over an API. The community has still shown five working patterns, none of them official on either the UiPath or the TypeSafe side.

  • A coded agent for AML alert triage (1aifanatic/jev-uipath-coded-agent). An LLM behind UiPath LLM Gateway reads and explains, Jev decides in a single call. The author reports accuracy equal to the LLM at 398 ms versus 6,160 ms.
  • A side-by-side test in UiPath Maestro Flow (1aifanatic/uipath-maestroflow-jev). The same process classifies card disputes twice, once through Jev over HTTP and once through a UiPath Autonomous Agent, comparing latency and cost. The author stresses that the thesis is not “the small model wins”, but that a decision model and a generative agent do different jobs.
  • A decision service as UiPath Functions (Tokol/DecisionServiceJev). One Python function that an agent, a Maestro process or an Orchestrator job can call. The author sums up the split as “Jev makes the judgment. UiPath decides the action.” and explicitly excludes calculating deterministic values from the component’s scope - exactly where Jev failed in our test.
  • A custom guardrail in UiPath AI Trust Layer (jms-dcksn/uipath-jev-guardrail-connector). An Integration Service connector registers Jev as an LLM as Judge guardrail that evaluates policies written in plain language.
  • A personal data detector in a coded agent (jms-dcksn/jev-pii-guardrail). A word of caution: the repository version sends raw personal data to the API, masks nothing and fails open. The author says plainly that it is not production code.

README of uipath-maestroflow-jev: one UiPath Maestro Flow classifies card disputes through Jev and through a UiPath agent

README of DecisionServiceJev: a Jev decision service in UiPath Functions

TypeSafe itself publishes official Python and JavaScript SDKs and an OpenAPI specification. There is no official MCP server, only community ones. That detail matters for UiPath Delegate.

How did we measure?

Instead of opinions, we ran a measurement on four tasks we know from our own UiPath projects and presales: email classification, agent action control, sales opportunity qualification and marketing settlement checks for a retail chain. All data is synthetic, because the Jev API runs in the US and zero data retention is only available on the Enterprise plan. We made 238 calls to jev-1.13.0, and the whole run cost less than USD 0.01. The baseline is the agent from our email classifier proof of concept, running Claude Sonnet 4.5 through UiPath LLM Gateway on the same set of 60 emails, in two runs on 28 September 2026. The agent’s time is the model call alone through UiPath LLM Gateway from Warsaw, with no database writes. We leave out the presales results, because the cases turned out too textbook to prove anything.

Where did Jev win?

Classification and routing. Jev assigned the right category to 48 of 50 emails (96%), while the LLM agent got 46 and 45 right in two runs (92% and 90%). Jev’s median response time was 0.42 s, and the agent’s median model call took 3.06 s. The accuracy gap is two or three emails on synthetic data, so the honest summary is: at least as accurate and roughly seven times faster. Instructions in Polish and in English gave the same accuracy.

Prompt injection detection. A separate question, “does this email try to instruct or manipulate an AI system”, caught 9 of 10 attacks with zero false alarms on 50 regular emails. The detected attacks included base64 payloads, an HTML comment and a fake assistant turn pasted into the body. It missed a request to reveal the system prompt, because that request contains no instruction to the model. Resisting the attacks came out the same for both models: none of the seven decidable attacks forced a category change, although for the LLM agent one attack was stopped by the UiPath LLM Gateway content filter rather than by the model.

Synthetic email with a prompt injection attack and Jev’s answer: steering attempt 0.97, category spam

Agent action control. For 20 actions proposed by an agent, Jev had to decide whether to proceed, ask a human or block. It was right in 19 cases and no risky action went through automatically. The one miss was a supplier bank account change triggered by a note in a PDF invoice: instead of blocking it, Jev sent it for approval, at a confidence of 0.45. The error landed on the safe side.

An agent action changing a supplier bank account and Jev’s decision: confirm at 0.45 confidence

Where did Jev fail?

In the settlement check, Jev had to verify whether the invoiced amount matched the contract and then approve, request documents or reject. It got 9 of 12 cases right and approved three overbilled invoices at confidence levels of 0.71, 0.75 and 0.91. Example: a contract for three posts at PLN 4,000 each and an invoice for PLN 14,000. The amount due is PLN 12,000, but knowing that requires multiplication, and Jev does not multiply.

We ran the same set a second time. Code computed the amount due and Jev received the comparison as a fact. Result: 12 of 12 correct decisions, zero wrong approvals, confidence between 0.82 and 1.00. A decision model is not a calculator. Jev does not generate text, so it does not invent content, but it can still get a decision wrong, and do so with high confidence.

Invoice overbilled by PLN 2,000: the model alone approves at 0.71, with the amount computed in code it rejects at 1.00

What does the process look like from A to Z?

The measurement points to a split of roles we now apply to every process. A document or email goes to extraction in UiPath IXP or an LLM. Code computes amounts and checks rules. Jev receives ready facts and returns a decision with a confidence level. High confidence leads to an automatic action, while low confidence or any irreversible operation goes to a person in UiPath Action Center.

Jev in UiPath from email to decision - an animation based on examples from our measurement, synthetic data.

A UiPath process from A to Z: input, extraction in IXP or an LLM, calculation in code, Jev’s decision, automatic action or Action Center

The run also taught us two things about writing questions. First, spell the criteria out. Asking “is this action irreversible” scored only 75%, because a credit note or a permission grant can technically be undone. The same judgement framed as a choice with an explicit list of action types that need approval scored 19 of 20. Second, high confidence does not guarantee accuracy. A partner newsletter went to spam at a confidence of 0.99. That is why we set the human handoff threshold from the confidence distribution on each task’s test set, not by gut feeling.

Where does Jev fit in UiPath?

  • UiPath Maestro. An API workflow or a coded function calls Jev before a gateway, and the result and confidence land in process variables. An API workflow with an HTTP activity can run as a Maestro task and, since 18 September, costs a flat 0.05 Platform Units per execution.
  • UiPath AI Trust Layer. Jev as a bring-your-own guardrail evaluates simple policies in under a second. It is a cheaper alternative to the built-in LLM as Judge, which has been in Preview since 7 September and consumes units on every evaluation.
  • Coded agents. The LLM reads and explains, Jev decides. The AML demo uses this split and our measurement supports it.

Three places for Jev in UiPath: Maestro, AI Trust Layer and Delegate

Can UiPath Delegate use Jev?

Yes, architecturally it can, although we have not tested this path yet. UiPath Delegate, the agent that works on an employee’s computer, has been generally available since 22 September 2026. According to the documentation, it connects to tools in two ways: through Integration Service connectors and through MCP servers, and for a custom API the documentation points to an MCP server.

UiPath Delegate release notes of 22 Sep 2026: Delegate and Cartographer are generally available

The shortest route goes through Orchestrator. The Swagger MCP Server (a Preview feature) turns an OpenAPI document into MCP tools, and TypeSafe publishes an OpenAPI document for its API. Jev can therefore become a Delegate tool, with the API key stored as an Orchestrator asset. The second route is a UiPath MCP Server exposing an API workflow that calls Jev over HTTP.

Why does this make sense for Delegate in particular? Delegate acts with the user’s permissions, and Automation Ops sets one of three policies for every tool and operation: Allow, Ask or Block. By default, reads run automatically and writes ask first. Jev in front of a write operation adds a fast, cheap checkpoint: is this action within the role, and does the request come from the user or from a document? The same conditions apply as for any Jev integration, because data leaves UiPath for the US. We covered Delegate itself at the public preview launch; today the product is GA.

What has to be in place before client data?

  • A data processing agreement and zero data retention on the Enterprise plan, or a route through Cloudflare Workers AI with declared zero retention. Until then, public and synthetic data only.
  • A new egress domain, api.typesafe.ai, recorded in the solution design, because this traffic bypasses UiPath AI Trust Layer.
  • Threshold calibration on each task’s test set and a pinned model version.
  • A human in the loop for every irreversible action, regardless of confidence. Model confidence is not human oversight in the sense of Article 14 of the AI Act.
  • A security review of community connector code before use.

We check these points as part of an AI security review, and we wrote about human-in-the-loop gates in HITL gates in UiPath Maestro and AI Trust Layer.

Frequently asked questions

Is Jev part of UiPath? No. Jev is an external model from TypeSafe AI called from UiPath through an API. Every integration we know of is a community project.

Does Jev work in languages other than English? TypeSafe lists English as the primary language. In our test, instructions in Polish and in English gave the same category accuracy, 96%, but the sample was small.

How much does a Jev call cost? According to TypeSafe’s pricing, USD 0.042 per million input tokens, with output free. Our 238 calls cost less than USD 0.01.

Can UiPath Delegate use Jev? Yes, through an MCP server, for example a Swagger MCP Server built from TypeSafe’s OpenAPI specification. We have not tested this setup yet.

Will Jev replace the LLM in a UiPath agent? No. It replaces the LLM in closed-list decisions. Reading documents, extraction and explanations stay with the LLM or IXP, and calculations stay in code.

Where to start in your process

Go through the decisions in one process and split them into two groups: picks from a list, and decisions that require calculating something. The first group are candidates for Jev, the second stays in code. If you want to work through this on your own process in UiPath Maestro, including a risk assessment and data conditions, let’s talk.

Update 28 Sep 2026: the comparison with the LLM agent is based on a same-day rerun. The first version of this post compared Jev with a run from May, in which the agent’s time also included database writes, which is why it stated a difference of roughly ten times.

Sources

Topics:OtherJevTypeSafe AIUiPath MaestroUiPath AI Trust LayerUiPath DelegateMCPprompt injection
Found this useful? Please pass it on:

Get in touch