AI Agent Autonomy Levels: What Exists, What to Ask

One supervised-or-autonomous setting treats a comment fix and a payments change alike. Researchers and governments have proposed scales, and we found no standards body that has published one.

By Harinderpal Hanspal on July 2026. Updated October 2026

We found no standards body that has published autonomy levels for AI agents. What exists is a five-level research proposal (June 2025), a NIST initiative (February 2026) and Singapore's voluntary framework (January 2026). Ask a vendor where its own scale is defined and who can change it.

One supervised-or-autonomous switch treats every task alike; one workable scale has four stepsSketch comparing a single on-off switch, which gives a typo fix and a setpoint change the same answer, with one possible four-step scale: read only, propose and a person confirms, act within limits and report, act with no gate. A note says no standard scale exists.one switchontypo fixsetpoint changesame answerfor bothone workable reading1 read only2 propose, a person confirms3 act within limits, then report4 act, no gatecost of a wrong action picks the stepno standard scale exists
One supervised-or-autonomous switch treats every task alike; one workable scale has four steps

An agent handles two jobs on the same afternoon: a typo in a maintenance report template, and a change to the setpoints a scheduler sends to a line. A single toggle, supervised or autonomous, gives both the same answer. Supervised sends the typo to a queue for a person to confirm something with no risk in it. Autonomous lets the setpoint change through unreviewed.

What has been proposed, and what has not

For AI agents the picture is thin.

Three researchers proposed five levels in June 2025, defined by the role the user plays: operator, collaborator, consultant, approver and observer. They treat autonomy as a deliberate design choice, separate from the agent's capability and from its environment (Feng, McDonald and Zhang, arXiv 2506.12469). It is an essay, not a standard.

On 17 February 2026 NIST announced an AI Agent Standards Initiative with three pillars: industry-led standards, open-source protocols, and research on agent security and identity (NIST). It is an initiative. It does not define levels.

Singapore's IMDA launched a Model AI Governance Framework for Agentic AI on 22 January 2026 (IMDA). Law-firm summaries say it is voluntary, asks organizations to set limits on an agent's autonomy and its access to tools and data, and leaves them legally accountable. We have not read the framework text.

Anthropic's own framework, from August 2025, says the right balance between autonomy and oversight "varies dramatically across scenarios" (Anthropic, 4 August 2025). That is a vendor's position, and it supports the case for a scale set per task.

Where one setting fails in practice

The supervised end fails quietly. Anthropic reported in March 2026 that Claude Code users approve 93% of permission prompts, and built classifiers partly to reduce approval fatigue (Anthropic Engineering, 25 March 2026). That is an approval rate for one product, not a measure of safety. A person asked about everything stops reading.

The autonomous end fails loudly, and in a plant the consequences differ. CISA and eight partner agencies advise that where AI is actively updating control logic, systems should add human-in-the-loop intervention points, because problems can escalate before operators notice. The same document says humans remain responsible for functional safety (CISA, 3 December 2025). It is guidance, not a regulation.

So a useful scale is tied to consequence rather than to a mood. One workable reading has four steps: read only; propose, and a person confirms; act within stated limits and report afterward; act with no gate. Which step a task gets depends on what a wrong action costs, and that differs between two jobs the same agent does five minutes apart.

A scale also needs rules around it. Who may raise a level? If the agent can raise its own, the scale is decoration. Where is the limit enforced? A limit written into the agent's instructions can be argued past, while a limit applied below the agent cannot. What happens after repeated failures? And is each decision, allowed or refused, written to a log?

Ask the vendor to show the scale

  1. Where is the list of levels defined, and is it the same list in every screen and report you use?
  2. Can the level differ per task, or only per agent?
  3. Who can raise it, and can the agent itself?
  4. Is the limit enforced outside the agent, or requested in its prompt?
  5. What lowers a level automatically, and has that rule ever fired?
  6. Does the log show which level applied to each action?

A vendor who answers the first question by showing a settings page with two options has not answered the other five.

Drawn from Feng, McDonald and Zhang (arXiv, June 2025), NIST's AI Agent Standards Initiative (17 February 2026), Singapore IMDA's announcement (22 January 2026) with law-firm summaries of the framework, Anthropic (4 August 2025 and 25 March 2026) and CISA's AI-in-OT principles (3 December 2025), all read on 6 October 2026. The IMDA framework itself was not read. No figure here is a measurement.

Related notes

Related insights

Related paper: Governing agents in production: what to ask before an agent acts