Search papers, labs, and topics across Lattice.
This paper establishes a governance framework that differentiates between Allowed Autonomy Levels (AAL) and Autonomous Capability Levels (ACL) in AI systems, addressing the critical distinction between what AI can do and what it should be permitted to do. By outlining a structured set of autonomy levels and a risk-aware decision process for assigning allowed autonomy, the authors illustrate how organizations can manage AI capabilities while ensuring safety and accountability. The framework is validated through a case study of an enterprise data engineering agent, demonstrating that high-capability systems can be effectively constrained to lower autonomy levels based on contextual factors like risk and organizational readiness.
Distinguishing between what AI systems can do and what they should be allowed to do could redefine governance in agentic AI deployment.
As AI systems increasingly exhibit agentic behavior, discussions of autonomy often conflate what systems are technically capable of doing with what they should be permitted to do in practice. This paper introduces a governance framework that explicitly separates Allowed Autonomy Levels (AAL), which define the degree of autonomy an AI agent is authorized to exercise given risk, oversight, and accountability considerations, from Autonomous Capability Levels (ACL), which characterize an agent's inherent technical abilities. We present a structured set of autonomy levels spanning reactive execution, decision support, supervised action, goal-directed autonomy, and delegated operational authority, and describe how control, reversibility, and accountability change as autonomy increases. To operationalize this framework, we propose a risk-aware decision process for assigning allowed autonomy, analyze how risk and accountability evolve across autonomy levels, and demonstrate its application through a deployed enterprise data engineering agent, illustrating how a system assessed at a high capability level can be deliberately constrained to a lower allowed autonomy based on risk, reversibility, and organizational readiness. By distinguishing authorization from capability, this work provides practical guidance for the design, deployment, and governance of Agentic AI systems.