risk vocabulary
The AI Automation Ladder
'Human in the loop' is a slogan. This is the actual question.
Structure
- L1: Assist
- AI helps a person do the work. The human does everything.
- L2: Analyze
- AI interprets data or documents. The human decides.
- L3: Recommend
- AI proposes a specific action. The human chooses.
- L4: Act with approval
- AI executes after authorization. The human authorizes.
- L5: Act autonomously
- AI executes within a defined scope. The human sets scope and audits the result.
"Human in the loop" describes a posture, not a design. It does not say which step the human is in, what they see when they get there, or what happens if they are wrong. This ladder replaces the slogan with five levels, and at every level, six things have to be specified in the same breath: risk tolerance, identity (what the agent is and how it authenticates), permissions (read, write, or never touch), auditability, the design of human oversight (which step, with what information), and rollback (what happens when it is wrong, and how fast).
Most organizational arguments happen at the wrong level. People debate whether AI should ever act autonomously while a level two capability, AI interpreting documents for a human to decide on, is still unreliable in production. The useful question is never "are we comfortable with autonomy." It is: what level of authority can this specific workflow support today, and what would have to become true, in identity, permissions, auditability, oversight, and rollback, for it to move up one rung.
The line to use in a room“You do not have an autonomy problem. You have an L2 problem that you are discussing as though it were an L5 problem.”