π€ AI Summary
This work addresses a critical gap in current AI systems, which often conflate technical capability with operational authority, resulting in inadequate governance of authorized autonomy. The paper proposes a structured governance framework that systematically distinguishes between an AI systemβs Autonomous Capability Level (ACL) and its Authorized Autonomy Level (AAL). By integrating risk exposure, action reversibility, and accountability, the framework introduces a dynamic authorization mechanism that decouples capability from permission. Validated in enterprise-grade data engineering agents, the approach enables high-capability systems to be safely constrained to lower authorization levels aligned with organizational risk tolerance. Through layered autonomy modeling and risk-aware decision protocols, the framework ensures that AI autonomy remains both effective and responsibly governed.
π Abstract
As AI systems increasingly exhibit agentic behavior, discussions of autonomy often conflate what systems are technically capable of doing with what they should be permitted to do in practice. This paper introduces a governance framework that explicitly separates Allowed Autonomy Levels (AAL), which define the degree of autonomy an AI agent is authorized to exercise given risk, oversight, and accountability considerations, from Autonomous Capability Levels (ACL), which characterize an agent's inherent technical abilities. We present a structured set of autonomy levels spanning reactive execution, decision support, supervised action, goal-directed autonomy, and delegated operational authority, and describe how control, reversibility, and accountability change as autonomy increases. To operationalize this framework, we propose a risk-aware decision process for assigning allowed autonomy, analyze how risk and accountability evolve across autonomy levels, and demonstrate its application through a deployed enterprise data engineering agent, illustrating how a system assessed at a high capability level can be deliberately constrained to a lower allowed autonomy based on risk, reversibility, and organizational readiness. By distinguishing authorization from capability, this work provides practical guidance for the design, deployment, and governance of Agentic AI systems.