26/08/2026
A pattern recurring across enterprise AI agent programmes: autonomy graded at the wrong level.
An agent approved for the incident process changed a customer-facing configuration at two in the morning. Nobody had approved that, and nobody had explicitly withheld approval either, because the decision itself was never in question. Only the agent was.
Most programmes answer "how autonomous is this agent?" per system, or per agent. Both are the wrong unit, and the wrongness is not cosmetic.
One agent, working on one system inside one process, can branch into three different decisions with three different risk profiles. Enriching an event is reversible, unregulated, and carries no blast radius, full autonomy is appropriate. Opening a case record is reversible with low blast radius, autonomous, but audited. Issuing an adverse determination is irreversible, regulated, and appealable, never autonomous.
Grade per agent, and one tier gets applied to all three. Two of them will be wrong, and the costly error sits on the highest-risk decision.
The Blog covers full framework including where the verification gate belongs and what a cross-process handoff needs to survive.
Read: https://www.bluedataconsulting.co/blog/who-is-accountable-when-the-ai-agent-acts/