Authorize or certify the level of autonomy and its controls
Draft
Authorize or certify the level of autonomy and its controls
Layer 4. Control AUTAuthorization
Allocation
| L4-AUT-03 | |
|---|---|
| Decides | CAIO, or the AI Risk function |
| Consulted | CISO, Head of Risk and Model Owner |
| Executes | Model Owner |
| Evidence | Autonomy certification with control set and review cycle. An increase removing a human step triggers L5-12 work reallocation. |
| Delegated band | Delegated |
In plain terms
Decide how independently the agent operates and under what controls. L4-AUT-02 says what it may do; this says how much of it happens without a human.
What is being judged
Where the human sits relative to the action, and whether that placement is real.
Four positions, and the difference between the middle two is where most of the judgment lives. Proposes, a human acts. Acts on confirmation, a human approves each action. Acts with notification, a human can intervene after the fact within a window. Acts autonomously, no human in the path.
Acts on confirmation degrades into acts autonomously through volume. A person confirming four hundred actions a day is not a control, and the certification should state the volume at which the confirmation stops being one.
Autonomy drifts upward. It is granted narrowly, works well, gets extended informally and is never re-certified. The review cycle exists for this rather than for control failure.
What this decision does not cover
It does not decide the permitted actions. It does not authorize the model itself.
When it fires
On event. Alongside L4-AUT-02. On any increase in autonomy level. When confirmation volume crosses the rate stated in the certification. On a control failure in the autonomy path.
On cycle. The certification’s stated cycle, which should be shorter than the model’s.
What you need before deciding
The authorized action set. The proposed autonomy position per action class, since one agent may hold different positions for different actions. The confirmation volume a human would face at expected throughput. The intervention window and whether anyone monitors it.
How this goes wrong
Confirmation theater: the position says acts on confirmation and the volume makes confirmation a keystroke. One level for all actions: uniform autonomy across an action set that mixes reversible and irreversible. Certification without a cycle: granted once, extended by practice, never revisited.
Related decisions
Paired L4-AUT-02.
Upstream L4-CLS-04.
Downstream L5-10 AI literacy, since a person exercising oversight must be competent to exercise it.
Related the EU AI Act Article 14 human oversight requirements implemented at Layer 3.
Instrument references
EU AI Act Article 14 requires human oversight and Article 26(2) requires competence and authority in the person exercising it. Neither specifies who certifies the autonomy level. ISO/IEC 42001 and NIST AI RMF do not address the question.
Correction
The maintainer answers corrections. There is no service level. Responses are best-effort and opportunistic within a reasonable time: a correction raised on a Monday is answered that week or sooner.