Graduated delegation
How much autonomy a user grants an agent over their affairs, growing only as trust is earned rather than handed over all at once. At every point, the user decides how far it goes.
The impact of agents
Agents capable of acting across a whole government service, not just answering questions, are now widely available. As they take on more of a service, government has to decide how much autonomy to grant one over a user's affairs, and how a user earns or contracts that autonomy.
Granting the full range at once overwhelms cautious users and exposes everyone to high-consequence actions before trust is established, while granting too little under-serves confident ones.
What must be verified
Government needs an agent's autonomy over a user's affairs to be bounded and earned rather than granted wholesale: a user should be able to start with minimal involvement and expand it on demonstrated use. The agency's agent-platform operator enforces the capability boundaries at the platform layer, rather than leaving them to each deployment.
Protecting access
Cautious users, and those who distrust automation, are deterred if the dial pressures them toward automated action. They will reach a worse outcome at equal effort if the conservative level they chose gets constrained service.
Keeping the path open
- Default every user to the most conservative level, rather than requiring them to opt down.
- Offer a 'just do it the normal way' escape hatch at every level, routing to existing non-agent channels at equal standing.
- Refuse gamification, which would dress delegation up as achievement and pressure people into more automation than they want.
- Announce the dial's current level, and the consequence of changing it, to assistive technology.
Response surface
The risk of a service action sets the delegation level offered, and that level defaults to the most conservative option.
At any level: “stop and hand back to me” takes one tap and applies immediately. This cap is fixed by the service. Your assistant cannot raise it on its own. Only low-consequence actions reach the delegated rung.
Moving up a rung is always the user’s explicit act. The system may suggest it after demonstrated use; it may never perform it.
Maturity
- Established
For the theory of graduated, non-binary delegation, fully established via Parasuraman, Sheridan & Wickens; no primary source here documents an enterprise-grade AI-agent autonomy framework already in production.
- Frontier Headline
As a user-facing response in government services: no government has yet put a production-grade, user-controlled autonomy dial in front of the public for AI agents.
Precedents
Parasuraman, Sheridan and Wickens. The model identifies four classes of automatable function: information acquisition, analysis, decision selection, and action implementation. It establishes that automation is 'not all or none, but can vary across a continuum of levels', and that one system can automate each class to a different degree. That is the theoretical basis for granular delegation.
CSA Agentic Trust Framework. The specification applies zero-trust principles through a four-level maturity model with one operating mode each: Intern observes and reports, Junior recommends and gets approval, Senior acts and notifies, Principal runs autonomously. Its stated rule is that 'Agents earn autonomy through demonstrated trustworthiness. They do not receive it by default.'
Nielsen Norman Group on progressive disclosure, adapted to agents. Revealing complexity incrementally, whether step by step, conditionally, or contextually, has been carried into agent interfaces with each step reaffirming trust before the person proceeds. Yocco's autonomy dial lets a person trust an agent for low-stakes tasks while demanding confirmation for high-stakes ones.
Five Eyes joint guidance on agentic AI services. Six national cyber authorities recommend phased deployment, in which an agent's access and autonomy rise progressively while human oversight is maintained. Graduated autonomy carries government security backing, and not only the industry frameworks above it.
What carries over to agent use
High transferability; among the most directly applicable patterns here. Government services naturally decompose into risk tiers: checking a payment date is low-stakes, updating bank details is medium, lodging an appeal is high. A graduated delegation model maps cleanly onto this existing risk architecture.
Proposed government adaptation:
| Level | Agent capability | Human involvement | Example |
|---|---|---|---|
| Level 0: Informational | Answer factual questions from published guidance | None required | "When is the next payment date?" |
| Level 1: Guided | Pre-fill forms, suggest next steps | User reviews and confirms every action | "You may be eligible for X. Shall I start the application?" |
| Level 2: Supervised | Execute multi-step workflows | User approves at defined checkpoints | Change-of-address across linked services, confirming each service |
| Level 3: Delegated | Act within defined parameters without per-action approval | Exception-based review; audit trail | Adjust payment schedule within legislated parameters |
| Level 4: Autonomous | Initiate and complete complex transactions | Post-hoc audit; override available | Not recommended for government services at current maturity |
Critical constraint: full delegation remains feasible for only a small minority of tasks. Most government AI-agent interactions should operate at Levels 0–2.
Where things go wrong
The failure to prevent is unsupervised, fully automated issuance of high-consequence decisions. When public-facing agents are capped at supervised levels, the technical boundary keeps a human in the loop where it matters. The level itself can be pushed past what a user chose: a provider can silently default a returning user to a higher level after a period of inactivity, or treat non-response at a checkpoint as consent to proceed at the next level up.
Sources
10 references
The instrument, the operating deployment, or the official record itself.
- SAE J3016 — Taxonomy and Definitions for Terms Related to Driving Automation Systems
- Parasuraman, Sheridan & Wickens — A model for types and levels of human interaction with automation
- Careful adoption of agentic AI services — Five Eyes joint cybersecurity guidance (ASD ACSC, CISA, NSA, CCCS, NCSC-NZ, NCSC-UK)
- CAISI — evaluation of DeepSeek AI models (agent hijacking)
Writing about the subject rather than the framework itself, including vendor commentary.
- CSA — Autonomy Levels for Agentic AI
- The Agentic Trust Framework: Zero Trust Governance for AI Agents (Woodruff, via CSA blog)
- Agentic Trust Framework specification (GitHub)
- Nielsen Norman Group — Progressive Disclosure (Jakob Nielsen)
- Yocco, V. — Designing For Agentic AI: Practical UX Patterns (Smashing Magazine)
-
DRCF — The Future of Agentic AI (foresight paper)
A joint paper from the UK's four digital regulators (CMA, FCA, ICO, Ofcom) setting out five levels of agent autonomy (Tool, Assistant, Operator, Collaborator, Autonomous Actor), with the top two rungs described as largely theoretical. An official cross-regulator articulation of the level-based model, but a foresight document by its own admission, not policy; do not read it as evidence that any deployment sits at a given rung.