Issue 014 organizations name it2026 evidence
Risk to people rises with autonomy, and the trade is almost never stated
The more control is ceded to the system, the broader its action surface and the weaker the oversight. That relationship is documented, and it appears in almost no deployment decision.
The academic argument here is unusually blunt for this research. It holds that risks to people increase with the autonomy of a system, that increased autonomy brings broader action surfaces together with reduced oversight, and that even small miscalibrations of trust at a given level of autonomy multiply into much larger harm surfaces. Its recommendation is not prohibition but a spectrum: name the level, and accept the risk that goes with it deliberately. That is the same conclusion Anthropic reaches from operating experience, arrived at independently.
How to fix it — 1 approach, 3 steps
Write the autonomy level and the risk accepted with it
Record, per system, the autonomy level chosen and the specific harms that level makes possible. An unstated trade is an unmanaged one.
Done when Each production agent records its autonomy level on a fixed scale and the specific harms that level admits, including to people outside the organization, with a re-approval date within the last twelve months.
- Name the autonomy level for each production agent using a fixed scale.
- Document the harms that level admits, including to people outside the organization.
- Re-approve the level annually rather than treating it as permanent.
The evidence — 6 documents
| Organization | Document | Position |
|---|---|---|
| arXiv (research)Academic | Fully autonomous AI agents should not be developedOur reading Argues risks to people increase with the autonomy of a system - the more control a user cedes, the more risks arise - with safety, privacy and security risks growing together, and small miscalibrations of trust at a given level multiplying into larger harm surfaces.Risk characterisation across levels of autonomy | names it |
| CISAOther · April 2026 | Careful adoption of agentic AI servicesOur reading Names both halves of the trade in one place: more independence means more the system can reach, and simultaneously less that an operator can see, because agents initiate their own follow-on work, spawn sub-agents and extend delegation chains in ways not surfaced to whoever is nominally supervising. The oversight does not merely fail to keep pace, it loses sight of what there is to oversee.Autonomy widens the surface and dims the light at the same time | names it |
| Cloud Security AllianceInstitution · July 2026 | Defining non-human identityOur reading Gives the mechanism behind the curve: an autonomous identity executing thousands of operations a second removes the pauses in human work where a mistake would have been caught, so a misconfiguration compounds rather than surfacing.Why NHI risks differ from human identity risks | names it |
| IBMHyperscaler | Agentic AI risk and opportunityOur reading Names the autonomy trade directly - a system acting without approval at each step can reach unintended or harmful outcomes - and answers it with a staged framework that widens autonomy only as performance and quality measurements justify it, rather than setting a level once.Autonomous action | names it |
| AnthropicFrontier lab · July 2026 | Anthropic’s CISO guide to agentic AIOur reading Reaches the same conclusion from operating practice: make agentic risk legible and bounded so exposure is deliberately accepted at a known scope.The principle of least agency | proposes a fix |
| arXiv (research)Academic | Fully autonomous AI agents should not be developedOur reading Recommends adopting an explicit spectrum of autonomy levels rather than a binary, so that trade-offs between benefit and risk are documented at each level.Adoption of a spectrum of AI agent autonomy | proposes a fix |