We cannot decide where agents should act
The organisation has no shared method for selecting appropriate autonomy by capability. This becomes most visible when pilots move from assisting individuals to making or executing decisions inside operational workflows.
Debate becomes binary: automate everything or block it. The underlying weakness is the absence of an operating model that defines purpose, authority, constraints, evidence, escalation and revocation for human, agentic and hybrid actors.
Low-risk value is delayed while high-risk deployment may advance without adequate safeguards. At enterprise scale, experiments remain isolated or scale without consistent accountability, producing unclear value and unacceptable governance exposure.
The AEOM 1–5 maturity dial sets a justified target per capability. In practical terms, each capability can progress to the autonomy level justified by its value, risk and human-oversight requirements under Human Sovereignty.
- Faster agreement on appropriate autonomy; value released in lower-risk work without overexposing high-judgement capabilities
- Clear autonomy and authority boundaries
- More credible AI value cases
- Continuous evidence and oversight
- Controlled progression from assistance to autonomy
- Which capabilities are high-volume and low-judgement?
- Which decisions demand human review or accountability?
- What evidence would justify moving a capability up one stage?
- What evidence must an agent produce before its action is accepted?
- Under what condition must authority return immediately to a human decision-maker?
NIST promotes context-and risk-based AI governance rather than a single undifferentiated control approach.
NIST: AI Risk Management Framework
The official EU AI Act establishes a risk-based legal framework covering governance, documentation, transparency, monitoring and human oversight for relevant AI roles and systems.
EUR-Lex: Regulation (EU) 2024/1689