← Insights · September 2, 2026

Minimum viable autonomy: how much agency should an AI agent get?

Article card on a dark navy background reading The AI agent question is not what it can do. It's what you'd let it, with the last line highlighted in green.

Somewhere in a sales deck near you, an AI agent is booking meetings, answering customers, updating the CRM and filing its own expenses. The demo is genuinely impressive. The question the demo never answers is the one that decides whether the thing belongs in production: which of those actions would you let it take on a bad day, at speed, with nobody watching?

The security establishment has now answered that question in public. In May, the UK’s National Cyber Security Centre and its Five Eyes counterparts published joint guidance, Careful adoption of agentic AI services (hosted, as joint Five Eyes documents usually are, by the Australian Signals Directorate), and the NCSC summarised it in a blog post of 15 May 2026. The advice is unusually plain for a security document: start small, use agents for low-risk tasks first and apply the security controls you already know. One sentence in the NCSC’s summary does most of the work, and it is worth pinning above every agent project in your organisation:

“If you cannot understand, monitor or contain an agent’s actions, it is not ready for deployment.”

Notice what that sentence is not. It is not “agents are dangerous, wait”. Five national security agencies are telling you to adopt this technology. They are telling you to adopt it the way you would let a new driver into a car: capable of more than you are currently permitting, permitted more as trust is earned.

Autonomy is a design decision, not a dial

The industry framing of agents treats autonomy as the product. More autonomous is more advanced is more valuable. Buy the roadmap and the agent that drafts your emails today will be running your renewals next quarter.

The problem with that framing is that autonomy is where all the risk lives. The NCSC’s list of what makes agents riskier than ordinary AI tools is short and specific: broader access to systems and data, behaviour that is harder to predict, actions that happen faster than humans can review them and decisions that are harder to explain afterwards. Every one of those risks scales with how much the agent is allowed to do on its own.

So the useful question is never “how autonomous is the technology?” It is “how much autonomy does this task need?” Those produce very different answers.

Drafting a reply is a different risk from sending one. Recommending a decision is a different risk from making it. Reading your systems is a different risk from writing to them. The capability gap between those pairs is small. The consequence gap is enormous, because one of each pair is reversible and the other is not.

Minimum viable autonomy

We run a method for taking processes from idea to production, APEX, and the design principle it applies to agents is the one in this article’s title: minimum viable autonomy. The smallest amount of independent action that still delivers the benefit. The declared interest is obvious, we sell this. The principle is worth having whether you buy it from us or build your own.

In practice it means putting every candidate task on a ladder and starting each one on the lowest rung that produces value.

Rung one: the agent observes and reports. It reads, summarises, extracts and flags. It touches nothing. A lot of organisations are sitting on years of value at this rung alone, in inboxes, documents and systems nobody has time to read. If an agent fails here, you get a bad summary. You have survived bad summaries before.

Rung two: the agent drafts, a person sends. Replies, quotes, reports, code. The work happens at machine speed, the commitment happens at human speed. This is the rung where most of the commercial value sits, which is convenient, because it is also the rung that legal and security will actually sign off.

Rung three: the agent acts inside hard limits. It sends the routine acknowledgement, files the record, routes the enquiry, but only within boundaries set in advance: these systems, these actions, these amounts, nothing else. The limits are enforced by permissions, not by the prompt. Asking an agent nicely to stay in scope is not a control.

Rung four: the agent operates, people supervise. Full autonomy over a task, with monitoring that would actually notice misbehaviour and a person who can stop it. The NCSC’s guidance describes what qualifies you to be here: least privilege, tightly limited scope, short-lived credentials, behavioural monitoring, a threat model for the deployment and an incident plan that covers the agent going wrong. If reading that list feels heavy for your use case, that is the ladder telling you the use case belongs on a lower rung.

Climbing a rung should be boring. It happens when the evidence from the current rung says the agent is reliable, the failure modes are understood and the monitoring works. It should never happen because the vendor shipped a new feature.

Someone has to own it

The sharpest section of the joint guidance is not technical at all. It is about accountability, and it says the quiet part plainly: a system may take an action, but humans remain accountable for the decision to deploy it, the access it was granted, the safeguards around it and the consequences of its operation.

Before an agent touches real systems or data, the guidance expects named answers to five questions. Who owns this system? Who approves what it can access? Who monitors what it does? Who reviews incidents? Who can switch it off? If any of those questions produces a job title rather than a person, or the person named does not know they hold the role, the deployment is not governed. It is merely running.

The pressure running against this discipline is real. Retool’s State of AI Governance 2026, a vendor survey of 307 technology leaders (CTOs, CIOs and CISOs), published in 2026, found only 5% very confident they have full visibility of what is running in production, while 90% report pressure to ship AI faster. Treat the numbers with the caution any vendor survey deserves. The shape they describe, more speed with less visibility, is exactly the combination the NCSC guidance exists to interrupt.

How this looks when you actually do it

We run our own business on this ladder, so a concrete example. Our inbound email routing operates at rung three: an agent reads what arrives in five mailboxes and files it, sales enquiries into the CRM as leads, support into cases. It acts without asking because the blast radius is small, the actions are reversible and every one of them is logged. Misfiled email is a recoverable failure.

Our published content operates at rung two and stays there. An agent researches and drafts. A person reviews every word before anything is published, priced or promised. Nothing goes out on the agent’s say-so. The capability to publish autonomously exists and is deliberately not used, because a wrong claim in public is not a recoverable failure in the way a misfiled email is.

Same business, same technology, different rungs, chosen by consequence rather than by capability. That is the whole principle. Where a task sits on the ladder is a decision with reasons attached, written down, which brings us to the regulator.

Write the reasons down

The Information Commissioner’s Office has agentic AI guidance in drafting, due in final form in Winter 2026, alongside its updated guidance on automated decision-making under the Data (Use and Access) Act, also due Winter 2026. Both dates checked against the ICO’s published guidance plans on 17 August 2026.

Nobody outside the ICO knows exactly what the final guidance will say. You do not need to know. An organisation that can show which tasks its agents perform, how much autonomy each was given, why that amount, what limits enforce it and who is accountable for it will be able to answer whatever the guidance asks. That paper trail is not compliance overhead. It is the same set of decisions the NCSC already expects you to have made, written down as you made them.

The agent vendors will keep selling the top of the ladder, because the top of the ladder is the best demo. Buy the capability by all means. Grant the autonomy one rung at a time, for reasons you can show someone.

The smallest amount of independent action that still delivers the benefit. It is not the exciting answer. It is the one that gets you an agent estate you can defend, to a board now and to a regulator in the winter.

Insights

Occasional, useful notes on applied AI.

What's actually working, what to ignore, and what the new regulation means for UK businesses. No spam.

We’ll only use your email address to send you these Insights notes. We never share it, and you can unsubscribe from any email. See our Privacy Policy.

AI Services

Where we work

Company

Latest writing

AI Applied Ltd, Technology House, 9 Newton Place, Glasgow G3 7PR. Registered in Scotland SC806963. support@aiapplied.uk · +44 141 465 5233