Blog post
The end state is not AI without people. It is judgement that moves up a level.
Every serious conversation about agent autonomy ends at a machine that does the standing work unwatched. Parts of that are nearer than the debate suggests. What is not reachable is an enterprise with nobody accountable for what the machine did.
Autonomy is not a measure of how capable an agent is. It is a measure of what it may do without asking.
The two get conflated constantly, and the confusion is expensive. A more capable model does not earn an agent more freedom, and a less capable one is not made safe by restriction. They are different axes: capability is what the agent can do, autonomy is what your organisation has permitted it to do unsupervised.
There is a structural reason this is hard, and it is worth stating precisely because it is the reason older governance tools do not transfer. A conventional application’s control flow is fully specified by whoever wrote it — you can read the code and know every external effect it may produce. An agent selects its own sequence of actions at runtime. The specific side effects it will attempt are not knowable until the moment of execution, because the risk of any given action depends on values that only exist at the decision point: an amount, a recipient, a data classification, a computed confidence score.
So an enterprise that wants to permit low-risk actions automatically while retaining control over high-risk ones cannot express that policy by inspecting the agent in advance. There is nothing to inspect. The policy has to be evaluated at the last possible moment, inline, with the runtime values in hand.
Four generations of automation, and the moment governance stopped working
Each generation of enterprise automation was governed by the method that suited its predictability. The methods worked because behaviour was knowable before the thing ran. The fourth generation broke that assumption, and the industry is still using the third generation’s tools on it.
every branch written down
Code review2010sRPArecorded paths, replayed exactly
Change control2023Copilotsit suggests, a person acts
The human2025Agentschooses its own actions at runtime
Agent’s codeNEXTGoverned autonomythe limit is enforced where the action happens
The runtimeThis is why the tools an enterprise already owns do not close the gap, and it is worth being specific about each, because every one of them is in somebody’s architecture diagram as the answer.
Audit and detection platforms record what happened and raise an alert for triage. They observe; they do not intercept. Where the side effect is irreversible — a payment sent, a production record deleted, generated code run against a live system — a log entry written afterwards cannot prevent the harm.
Policy engines evaluate a request against declarative rules and return permit or deny. Two problems. The vocabulary is binary — there is no outcome between yes and no. And as they are usually deployed they sit outside the runtime, in a policy service the application calls, so the value the step just produced is not in front of them and the decision cannot turn on it. They can be embedded instead; most enterprises have not embedded them.
Human approval steps do exist for agents — every serious agent framework offers a node that pauses and waits for a person, and plenty of teams use them. Two things are wrong with relying on them. They are placed by whoever wrote the agent, at build time, which puts the organisation’s control in the developer’s hands and leaves it invisible to everyone else. And they do not scale: an enterprise running thousands of agent actions an hour cannot route every borderline one to a person, and reviewer fatigue turns the control into a rubber stamp — worse than no control, because it looks like one.
Reviewer and critic patterns — a second model checking the first — answer a different question than the one being asked. They evaluate whether an output is good. Governance needs to know whether an action is safe to take without a human. Those are not the same question, and a system built for the first does not answer the second.
Governed autonomy, stated precisely
The end state is an agent that runs the standing work with no gate in its path — and every action it takes landing on a record, inside limits set in advance by people who are accountable for them. Not unsupervised. Supervised by construction rather than by interruption.
The distinction that matters, and the one most discussions of this drop: the end state removes the human from the run. It does not remove the human from the loop. Judgement does not disappear; it moves up a level — from approving each action to defining the envelope the actions must stay inside, and reading the record of what happened within it.
That reframing is not a softening of the ambition. It is what makes the ambition achievable, because it is the only version that survives contact with an auditor, a regulator, or a board asking who signed off. Accountability is not a technical property that can be engineered away. It is a legal one, and it attaches to a person.
Near for a narrow class of work. Far for the general case.
Anyone who answers this with a single date is selling something. Autonomy is not reached by the industry as a whole; it is reached one workload at a time, and the distance depends entirely on which workload.
Close, now
- Work that repeats, with a shape you can describe in a rule
- Actions that are reversible, or cheap to correct
- Outcomes with a measurable right answer
- Systems that already emit the evidence of what was done
- Decisions where a threshold captures most of the judgement
Still distant
- Novel situations with no precedent to threshold against
- Irreversible external effects — money out, data deleted, statements made publicly
- Actions a regulator requires a named person to attest
- Judgement calls where the right answer is contested, not merely unknown
- Anything whose failure is discovered months later
Most enterprise work is a mixture, which is the practical point: autonomy is not a setting for an organisation, or even for an agent. It is a setting for this agent, doing this thing, inside this process — and the same worker may sit at the top of the ladder for one step and the bottom for the next.
Five problems between here and there
None of these are model problems. Better models do not solve any of them, which is why the gap has not closed despite two years of rapidly better models.
Accountability does not delegate
An agent cannot be liable. Every regime that matters — financial, medical, data protection — ultimately requires a person or a legal entity to answer for a decision. Autonomy that obscures who that is does not reduce risk; it relocates it somewhere nobody is looking. The end state has to make the accountable party more legible, not less.
You cannot grant autonomy you cannot justify
Raising a worker’s autonomy is a decision someone has to defend. Defending it requires a record: what this worker did, how often it was right, what was escalated and why, what changed since. Almost nobody is keeping that record in a form an auditor would accept, which means most autonomy decisions today are made on impression. Impression does not survive an incident.
Yesterday’s pass is not tomorrow’s guarantee
Model behaviour is resampled every run, and the model underneath you changes on someone else’s release schedule. Certification — the mechanism every other regulated technology uses — assumes the thing you certified stays the thing you certified. That assumption does not hold here, so the control cannot be a one-time approval. It has to be live.
The failure mode is silent
An ungoverned agent does not crash. It quietly does a reasonable-looking wrong thing, at machine speed, until somebody notices — and the thing that would have made someone notice is the control you removed to get the throughput. No alarm is attached to this failure by default, which is what makes it the dangerous one.
The economics have no middle
Route every borderline action to a person and the model cannot pay for itself. Route none and you are gambling. The industry’s vocabulary offered only those two options, so the large and commercially important class of actions in between — past the line where automatic is comfortable, short of warranting a human interrupt — had nowhere to go.
Five levels, and what holds them up
aXentic governs a digital worker — a Xen — with an ordered ladder of five autonomy levels, each named for the kind of control it applies. The level is not advisory: it is evaluated inline, at each step, immediately before the action’s side effect would occur — including at the top of the ladder, where the evaluation runs and returns proceed.
The worker only suggests. A person takes every action; any attempt to write is refused outright, with no approval path.
Reads run on their own. Every write, external call or code execution pauses and waits for a named human to approve it.
Deterministic thresholds gate the work. A write inside the bounds proceeds untouched; one that breaches them stops for a person.
Same thresholds — but a breach escalates first to a Controller: a second AI agent whose only job is the risk call. It sees the value that breached and the history around it, and answers one bounded question — let this through, or hand it to a person.
No gate in the path. The worker acts, and the run is recorded for review after the fact — still bounded by the policies configured around it. This is the end state, reached per workload, on evidence.
Human-in-the-loop is not one of the levels. It is most of them.
It is tempting to read the ladder as a slide away from human control, with one rung labelled “human-in-the-loop” and the rest labelled something else. That is the wrong reading. A person is in the loop at every level, including the top one. What changes as you climb is not whether a human is involved, but what has to happen before one is interrupted.
Read that way, climbing the ladder does not remove human judgement. It raises the value of each interruption. At the bottom a person spends attention on everything; at the top they spend it only on what a deterministic limit and then a second agent both declined to settle. The scarce resource being governed here is not the machine’s freedom. It is human attention.
What makes it a control rather than a setting
Several vendors have a ladder. Three properties are what turn one into something an auditor can inspect rather than a preference someone set, and they are the subject of a pending patent.
The tightest setting wins. A level can be set in more than one place, and the level actually applied is the tightest of them. Caution set anywhere cannot be loosened elsewhere, so a worker trusted broadly is still held at arm’s length inside sensitive work, and a single dangerous action can be pinned tighter than everything around it. This is what makes autonomy a property of the work rather than of the worker.
Borderline cases do not have to wake anyone. Past the limit but short of warranting an interrupt, the decision goes to the Controller — an AI agent whose only job is the risk call, not the quality of the output — which either lets it through or hands it to a person. That tier is what gives Problem 05 an answer: the middle ground finally has somewhere to go, and the human tier is reached only for what genuinely needs it.
Ambiguity resolves toward caution. An action whose type cannot be recognised is treated as a write. An output that cannot be parsed fails to a pause rather than through it. The dull, ambiguous cases are where governance quietly leaks, so the ones the evaluator meets are settled in the cautious direction rather than waved through.
Does this solve it for the industry?
Partly, and it is worth being exact about which part. The ladder does not make an agent trustworthy. Nothing makes an agent trustworthy. What it does is make trust expressible, enforceable and revisable: you can state precisely what a worker may do unsupervised, the runtime holds that line whether or not the worker behaves, and you can move the line when the record justifies it.
Against the five problems, the honest scorecard is two answered and three narrowed. No vendor closes all five, including this one, and anyone claiming otherwise is describing a roadmap.
The control is evaluated at every action rather than granted once. A model that drifts does not quietly inherit wider permission, because permission was never granted to the model — it was granted to an action shape, and it is re-checked each time.
The borderline class now has somewhere to go that is neither an automatic pass nor a human interrupt. This is the one the ladder was built for.
Liability still lands on a person — nothing changes that. What changes is that the person is named, per worker and per level, instead of being reconstructed after an incident. The problem becomes legible rather than solved.
The runtime records what ran, what was escalated and what a person approved — the raw material a justification is built from. It cannot produce the track record instantly. You still have to run for a while before any of it is worth anything.
A breach of a limit is now an event with an owner, so one whole class of silent failure acquires an alarm. An action that stays inside its limits and is still wrong remains exactly as quiet as it was. This is the hardest of the five and it is not solved.
The industry will reach governed autonomy the way it reached every other kind of production trust — one workload at a time, each one earning it. The argument of this paper is simply that the ladder has to exist, and be enforced by the runtime, before the climb can start.
Working out where your agents sit on this ladder? Reach out to us at
info@axenticlabs.aiThe autonomy cascade described here is the subject of a filed provisional patent application. aXentic is not yet SOC 2 or ISO certified; nothing in this piece should be read as a certification claim.