risk vocabulary

The AI Automation Ladder

'Human in the loop' is a slogan. This is the actual question.

The AI Automation Ladder: five rungs rising left to rightA ladder of five rungs rising diagonally from lower left to upper right, labeled in order Assist, Analyze, Recommend, Act with approval, Act autonomously. Beneath the ladder, six full width horizontal bands represent the overlay dimensions that must be specified at every level, each band shaded progressively darker moving right to show increasing control requirements as authority increases. The fourth rung, Act with approval, is marked in the accent color.L1 ASSISTL2 ANALYZEL3 RECOMMENDL4 ACT WITH APPROVALL5 ACT AUTONOMOUSLYRISK TOLERANCEIDENTITYPERMISSIONSAUDITABILITYOVERSIGHT DESIGNROLLBACKthe Laddererikcaldwell.com
the Ladder

Structure

L1: Assist
AI helps a person do the work. The human does everything.
L2: Analyze
AI interprets data or documents. The human decides.
L3: Recommend
AI proposes a specific action. The human chooses.
L4: Act with approval
AI executes after authorization. The human authorizes.
L5: Act autonomously
AI executes within a defined scope. The human sets scope and audits the result.

"Human in the loop" describes a posture, not a design. It does not say which step the human is in, what they see when they get there, or what happens if they are wrong. This ladder replaces the slogan with five levels, and at every level, six things have to be specified in the same breath: risk tolerance, identity (what the agent is and how it authenticates), permissions (read, write, or never touch), auditability, the design of human oversight (which step, with what information), and rollback (what happens when it is wrong, and how fast).

Most organizational arguments happen at the wrong level. People debate whether AI should ever act autonomously while a level two capability, AI interpreting documents for a human to decide on, is still unreliable in production. The useful question is never "are we comfortable with autonomy." It is: what level of authority can this specific workflow support today, and what would have to become true, in identity, permissions, auditability, oversight, and rollback, for it to move up one rung.

The line to use in a room“You do not have an autonomy problem. You have an L2 problem that you are discussing as though it were an L5 problem.”