Separating Capability from Permission: A Governance Framework for Agentic AI Autonomy Levels
Haining Zheng, Qian Dong, Rodolfo K. Depena, Jonathan D. Bhatia, Feng Xiao, Peng Xu
Why It Matters
What makes this one worth your time
Understanding and managing the distinction between what AI systems can do and what they are allowed to do is crucial for safe and effective deployment in real-world applications.
A framework to separate AI capabilities from permissions for better governance.
Summary
The paper proposes a governance framework that distinguishes between the technical capabilities of AI systems and the permissions granted to them based on risk and accountability. It introduces Allowed Autonomy Levels (AAL) and Autonomous Capability Levels (ACL) to manage AI autonomy, and provides a risk-aware decision process for assigning autonomy levels, demonstrated through an enterprise data engineering agent.
Key contributions
- Introduction of Allowed Autonomy Levels (AAL) and Autonomous Capability Levels (ACL).
- A risk-aware decision process for assigning autonomy levels.
- Application of the framework in a real-world enterprise data engineering agent.
Notable insights
- The separation of technical capability from allowed autonomy provides a structured approach to managing AI risks.
- The framework includes a risk-aware decision process for assigning autonomy levels.
Possible limitations
- Not stated in the abstract
Abstract
arXiv:2607.23438v1 Announce Type: new Abstract: As AI systems increasingly exhibit agentic behavior, discussions of autonomy often conflate what systems are technically capable of doing with what they should be permitted to do in practice. This paper introduces a governance framework that explicitly separates Allowed Autonomy Levels (AAL), which define the degree of autonomy an AI agent is authorized to exercise given risk, oversight, and accountability considerations, from Autonomous Capability Levels (ACL), which characterize an agent's inherent technical abilities. We present a structured set of autonomy levels spanning reactive execution, decision support, supervised action, goal-directed autonomy, and delegated operational authority, and describe how control, reversibility, and accountability change as autonomy increases. To operationalize this framework, we propose a risk-aware decision process for assigning allowed autonomy, analyze how risk and accountability evolve across autonomy levels, and demonstrate its application through a deployed enterprise data engineering agent, illustrating how a system assessed at a high capability level can be deliberately constrained to a lower allowed autonomy based on risk, reversibility, and organizational readiness. By distinguishing authorization from capability, this work provides practical guidance for the design, deployment, and governance of Agentic AI systems.