Separating Capability from Permission: A Governance Framework for Agentic AI Autonomy Levels

πŸ“… 2026-07-25
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This work addresses a critical gap in current AI systems, which often conflate technical capability with operational authority, resulting in inadequate governance of authorized autonomy. The paper proposes a structured governance framework that systematically distinguishes between an AI system’s Autonomous Capability Level (ACL) and its Authorized Autonomy Level (AAL). By integrating risk exposure, action reversibility, and accountability, the framework introduces a dynamic authorization mechanism that decouples capability from permission. Validated in enterprise-grade data engineering agents, the approach enables high-capability systems to be safely constrained to lower authorization levels aligned with organizational risk tolerance. Through layered autonomy modeling and risk-aware decision protocols, the framework ensures that AI autonomy remains both effective and responsibly governed.
πŸ“ Abstract
As AI systems increasingly exhibit agentic behavior, discussions of autonomy often conflate what systems are technically capable of doing with what they should be permitted to do in practice. This paper introduces a governance framework that explicitly separates Allowed Autonomy Levels (AAL), which define the degree of autonomy an AI agent is authorized to exercise given risk, oversight, and accountability considerations, from Autonomous Capability Levels (ACL), which characterize an agent's inherent technical abilities. We present a structured set of autonomy levels spanning reactive execution, decision support, supervised action, goal-directed autonomy, and delegated operational authority, and describe how control, reversibility, and accountability change as autonomy increases. To operationalize this framework, we propose a risk-aware decision process for assigning allowed autonomy, analyze how risk and accountability evolve across autonomy levels, and demonstrate its application through a deployed enterprise data engineering agent, illustrating how a system assessed at a high capability level can be deliberately constrained to a lower allowed autonomy based on risk, reversibility, and organizational readiness. By distinguishing authorization from capability, this work provides practical guidance for the design, deployment, and governance of Agentic AI systems.
Problem

Research questions and friction points this paper is trying to address.

Agentic AI
autonomy
governance
capability
permission
Innovation

Methods, ideas, or system contributions that make the work stand out.

Allowed Autonomy Levels
Autonomous Capability Levels
Agentic AI governance
risk-aware autonomy
AI accountability
πŸ”Ž Similar Papers
H
Haining Zheng
ExxonMobil Technology and Engineering Company
Q
Qian Dong
ExxonMobil Technology and Engineering Company
R
Rodolfo K. Depena
ExxonMobil Technology and Engineering Company
J
Jonathan D. Bhatia
ExxonMobil Technology and Engineering Company
F
Feng Xiao
ExxonMobil Global Operations Company
P
Peng Xu
ExxonMobil Technology and Engineering Company