An employee uses AI to draft a proposal. Another uses it to classify incoming requests. A third lets an agent update customer records. All three may appear under the same heading in an AI inventory, although the authority they have delegated is very different.
If management has not decided where those boundaries belong, individual users and software defaults decide instead. The work continues, but the company has no consistent answer when someone asks why an automated action was allowed.
I would start with three levels: tasks AI may complete within a defined mandate, tasks that require substantive approval, and decisions a named person must retain. These are management categories, not legal classifications. They make responsibility explicit before a system acquires the ability to act.
Independent Action
1. Independent action within a bounded task
Independent operation is useful where the permitted task is clear, the consequences of an error are limited, and mistakes can be detected and corrected promptly. Classifying an internal document or routing a routine request may fit, provided the data and downstream actions stay within approved boundaries.
The boundary needs more detail than “low risk.” Specify which records the system can access, what it can change, how far it can proceed and what makes it stop. A classification tool that also closes a customer case has acquired a second authority. The permission to classify does not justify the permission to close.
Consider a hypothetical internal request-routing system. Assigning a request to the wrong queue may be tolerable if the request stays visible and can be reassigned quickly. Deleting the request after classifying it as irrelevant is a different decision. So is forwarding its contents to an external service. The same model can be acceptable for one action and unsuitable for another.
Independent operation still needs a human owner. That person reviews errors and changes in performance, maintains the mandate and can suspend the system. Autonomy describes how an individual task proceeds; it does not remove responsibility for the process.
Approval
2. Approval that can change the outcome
Approval is appropriate when AI can prepare useful work but a consequential output needs examination before release. A proposed quotation, a draft customer response or a suggested account adjustment may belong here.
For approval to work, the reviewer needs the relevant evidence, enough subject knowledge and time, and the authority to reject the output. The workflow must actually stop when approval is withheld.
A checkbox cannot supply any of those conditions. If a reviewer sees only the polished answer, they may have no practical way to detect that a contract term was omitted or an unsupported commitment was added. If the queue is too large to examine, approval becomes a way of attaching a person’s name to work they could not reasonably check.
The cost of this review belongs in the business case. A system that saves drafting time while creating a larger verification task may still be useful, but the claimed saving needs to survive both sides of the calculation.
The UK Government’s AI Playbook makes meaningful human control an explicit principle. My practical test is whether the reviewer can explain what would cause them to reject an output and demonstrate that rejection stops the action. If they cannot, redesign the approval step before increasing the volume.
Human Authority
3. Decisions a person must retain
Some decisions should remain with an authorized person even when AI is capable of preparing a persuasive recommendation. As a management rule, I would retain final authority over hiring and dismissal, material financial commitments, significant changes to access rights, and statements that create legal or public obligations.
The exact boundaries depend on the business and applicable law. They should be set deliberately, with specialist input where necessary, rather than inferred from what a product happens to automate.
AI can still do substantial work around these decisions: assemble evidence, identify inconsistencies, compare options and test assumptions. The person making the decision must have access to the underlying evidence and be able to reach a different conclusion.
There is also a difference between making a decision and executing it. A person may approve a payment within established financial controls while a system performs the subsequent administrative steps. The execution should remain tied to the approved amount, recipient and conditions. A later change requires a new decision, not an expansive interpretation of the original approval.
The Boundary
Classify actions, not entire tools
One system may operate at all three levels. It can categorize an inquiry independently, draft an answer for approval and prepare a contractual exception for a manager to decide.
Classifying the whole product as either “autonomous” or “human supervised” loses that distinction. Map the points at which the system reads, recommends, changes something or communicates externally. Assign the authority at each point, including the route taken when information is missing or a limit is reached.
THE THROUGH-LINE
Technology teams can enforce these boundaries through permissions and workflow design. Business owners must decide where the boundaries belong. Security, privacy and legal specialists then help determine which controls or restrictions apply.
The Call
Make the first inventory a decision document
Start with one consequential workflow. Include unofficial AI use if it touches that workflow; an inventory of purchased licenses will miss it.
For each AI action, record its level, permitted scope, owner, review requirement and stopping condition. Test an ordinary case, an ambiguous case and a case that must be refused. A successful demonstration of the ordinary case is insufficient evidence that the boundary holds.
Revisit the classification when the model, data, permissions or purpose changes. A system approved to summarize internal notes has not automatically been approved to send those summaries to customers.
The useful output of this exercise is a sentence the business can defend: this system may perform this action under these conditions, and this person is accountable for the boundary. Until that sentence exists, authority is being delegated without a clear mandate.