Law 44 · Humans & Autonomy

Match the Level to the Stakes

Full autonomy is a setting, not a default.

Diagram explaining Match the Level to the Stakes

The principle

Autonomy is a spectrum, from 'the computer suggests' to 'the computer acts and then tells you' to 'the computer acts and decides whether to tell you at all'. The highest levels are a bad idea for consequential actions, because no aid is perfectly reliable and the cost of a confident error has no ceiling. Autonomy isn't one switch. It's a dial you set per action, based on how reversible and costly that action is.

Why it happens

Autonomy is not one switch. A system can gather information, analyze it, recommend an action, act after approval, or act alone. The right level depends on reliability, reversibility, and cost of error. A receipt resend and a large refund should not share the same autonomy setting. Too much autonomy causes costly silent mistakes; too little creates approval fatigue and rubber-stamping. Set the level per action. Let cheap reversible actions run, and require confirmation where the blast radius or irreversibility justifies human attention.

Watch for

In practice

Your support agent has one autonomy setting: act and report. That is fine when it is resending a receipt, but the same dial lets it issue a $4,000 refund and cancel an enterprise subscription before anyone sees it. The fix is not a global require-approval flag that buries humans in confirmations for trivial actions, it is gating per action by reversibility and blast radius. Let it resend receipts and reset passwords autonomously, route refunds over a threshold and any cancellation to propose-and-confirm, and you spend human attention only where a confident error actually costs you.

Apply it

  1. Classify each action by reversibility and blast radius before deciding its autonomy level.
  2. Let cheap, reversible actions run fully autonomously and gate costly or irreversible ones to propose-and-confirm.
  3. Tune the dial per action rather than flipping one global approval flag for the whole agent.

The takeaway

Don't pick one autonomy level for the whole agent. Gate irreversible or high-impact actions behind propose-and-confirm, and let the cheap, reversible ones run fully on their own.

Sources and further reading

Related laws

Get the audit kit Access the buyer edition Back to all 50 laws