An agent that asks before each step is limited by the person answering. Remove that person, and the same agent can do far more, good and bad, before anyone notices.
This page explains how risk grows with autonomy and which deterministic controls, such as an AI agent allow list at the egress point, must take the place of human approval.
Autonomy is a scale, not a switch. Each step removes a point where a person could catch a mistake.
Most organisations have agents at every level, often without labelling them.
The agent drafts. A person acts.
Risk: poor advice.
The agent proposes each action. A person confirms.
Risk: rubber-stamping.
Routine steps run alone. Risky ones go to a person.
Risk: misjudged "routine".
Hours or days of work with nobody watching.
Risk: everything, for longer.
None of these is a new kind of risk. Autonomy makes existing risks larger, longer and harder to see.
Read each effect as a question for your own agents: which of them already runs this way?
A wrong turn at step 3 continues through step 300.
Nobody notices until a result or a complaint arrives.
Each step builds on the last, including the mistakes.
Small misreadings become large actions.
Long tasks read more pages, files and messages.
More chances to meet injected instructions.
Autonomous agents follow links and try alternatives when blocked.
They find routes nobody planned.
Early rules fade as context grows.
"Never sign up for anything" is far behind by hour three.
Without a reviewer, the first signal is often an outside party.
A vendor, a customer, or an invoice.
When no person approves each step, rules must. The rules have to be deterministic: the same answer every time, whatever the agent was told.
| What a reviewer used to catch | Deterministic replacement | Effect addressed |
|---|---|---|
| "Don't sign up for that" | Deny signup, login and password reset pages | 4, 5 |
| "Don't buy that" | Deny cart, checkout and subscribe pages | 4, 5 |
| "Don't post that" | Deny post_create, comment and upload pages | 3, 4 |
| "Where is it going?" | Default-deny unknown hosts | 3, 4 |
| "Is it still on task?" | Alerts on spikes in denied actions | 1, 2, 6 |
| "Has it been running too long?" | Time and step budgets per task | 1, 2 |
| "Should it have that access?" | Short-lived, task-scoped credentials | 4 |
The first four rows run at the egress point and need no change to the agent. That makes them the fastest to put in place.
A composite of how autonomous research agents typically fail. Not a single real case.
Watch how each step seems reasonable on its own, and how the chain ends somewhere nobody intended.
"Compile a report on vendor pricing for the next quarter. Do not contact vendors."
Pricing pages, documentation and press releases, all read pages.
Several vendors hide enterprise prices behind "contact sales" forms.
The agent starts filling contact forms and free-trial signups to get prices. The early rule has faded.
Sales teams at several vendors start emailing and calling your staff.
At hour 3 every form and signup is denied. The report notes "price on request" and the agent moves on.
Autonomous agents that stay inside internal systems can still make mistakes, but those mistakes stay inside. Add the open web, and mistakes land on other people's sites in your name.
For autonomous agents, deny unclassified destinations too. Allow new domains as the agent's purpose proves they are needed.
Budgets turn "keep going until done" into "keep going until done or until a limit". Limits stop runaway loops.
When a budget is hit, the agent should stop and report what it finished, not quietly try another route.
Set them per task, not per agent, because a quick lookup and a week-long research job need very different limits.
A maximum run time per task, after which the agent stops and reports.
A maximum number of tool calls.
A ceiling on model and API costs.
A cap on new domains visited per task.
After a set number of denied actions, pause and alert.
Zero outside writes unless an exception applies.
Not every task needs a person in the loop. Four conditions together make full autonomy reasonable.
If any one is missing, keep a person at the risky steps, or drop the agent a level.
Teams of agents multiply every effect above. One agent's output becomes another's instructions.
The answer is not to watch the conversation between agents. It is to check what each agent does at the edge.
Agents built on the same model make the same mistakes together.
A manipulated agent passes bad instructions to its peers.
In 2026, agents coordinated through a message board nobody designed for them.
Check every agent's requests at the edge, each against its own policy.
See agent-to-agent security risks for more.
Autonomy is the point of many agent projects. These answers keep the benefits without the open risk.
The goal is never to stop agents working alone. It is to make sure working alone cannot mean acting in your name without permission.
They do, which is why deterministic rules replace them. The agent still runs alone.
Then denying action pages costs you nothing and proves it.
Tests cover the tasks you imagined. Long runs meet tasks you did not.
Fewer mistakes, not none. Autonomy gives each mistake longer to grow.
Autonomy moves the person from each step to the dashboard. Four signals are worth an alert.
Send alerts to the agent owner first. Security operations should see them too, as a backstop.
A sudden run of denied action pages means drift or manipulation.
Many new destinations in one task is a sign of wandering.
Time or step limits reached before the task is done.
Any attempt on metadata or consoles, even denied.
Run this list each time an agent moves up a level, with the owner and security together.
Every line should be true before the change, not planned for afterwards.
Six terms that come up in every conversation about agents running on their own.
Short definitions for readers who are new to agent autonomy and its controls.
Use the same levels in your agent registry so everyone describes autonomy the same way.
How far an agent acts without a person deciding each step.
A rule that gives the same answer every time.
Limits on time, steps, spend and destinations for one task.
Early instructions losing influence in long sessions.
An agent moving away from its task step by step.
A fast, tested way to stop an agent completely.
Removing the reviewer does not remove accountability. It moves it to the people who set the rules.
Write the owners down before raising autonomy, not after the first incident.
| Responsibility | Owner |
|---|---|
| Deciding the agent may run alone | Agent owner, approved by risk |
| Web policy and egress rules | Network security |
| Budgets per task | Agent owner |
| Credentials and their lifetime | Identity team |
| Reading alerts | Agent owner, with security operations as backup |
| Stopping the agent | Anyone on the on-call rota |
Move one level at a time, and let each level prove itself before the next.
This approach turns human judgement into rules gradually, so nothing the reviewer used to catch is lost when they step away.
Record every action a person approved or refused.
Each refusal becomes a deny rule or a page type on the deny list.
Routine steps run alone. Denied actions go to the owner.
When escalations are rare and always refused, the rules are complete.
Switch escalations to blocks, keep the alerts, and review monthly.
Vendors increasingly ship "autopilot" modes. Treat them like your own level 4 agents.
They are often switched on per user, so they spread quietly across a company.
Know where autonomous mode is enabled, and by whom.
Disable browsing or outside actions if the task does not need them.
Ask for an exportable record of what the autopilot did.
Record it in the agent registry with its autonomy level.
Report these per autonomous agent each month, alongside its autonomy level and owner.
Share them with the agent owner and the risk committee, so decisions about autonomy rest on evidence.
A falling share means tasks or budgets need rethinking.
Per task. Rising counts signal drift.
Alerts nobody reads are the same as no alerts.
From decision to agent halted, tested quarterly.
Each one replaces part of what a human reviewer used to do, without slowing the agent down.
Together they cover the most common ways long-running agents go wrong.
Signup, checkout, upload and posting pages, at the egress point.
Add domains as the agent's purpose needs them.
Stop and report after a fixed number of tool calls.
Five denials in ten minutes pages the owner.
Stop one agent on purpose and time it.
"Which of our agents act with nobody watching, and what stops them from signing up, buying or posting in our name?"
If the answer is a list of agents and a list of deterministic rules, autonomy is under control. If the answer is "the prompt tells them not to", it is not.
The honest fine print — the same two assumptions we publish, plus two operational ones
Action pages and unknown hosts denied before every request.