arXiv:2607.23438cs.AIcs.CY2026-07

区分AI能力与权限,实现可控自治。

Separating Capability from Permission: A Governance Framework for Agentic AI Autonomy Levels

  • 将AI自主能力与允许权限分离,明确授权边界。
  • 提出五级自主层级,随权限提升控制变难、可逆性降低。
  • 适合企业部署AI时做风险管控,保障安全合规。

随着AI系统展现出越来越多的自主行为,对其自主性的讨论常常混淆了技术能力与实际授权范围。本文提出一种治理框架,将‘允许的自主水平’(AAL)——即在风险、监督和问责考量下被授权行使的自主程度——与‘自主能力水平’(ACL)——即智能体固有的技术能力——明确区分开来。我们构建了一个从反应式执行、决策支持、受控操作、目标驱动自主到委托运营权的五级自主层级体系,并说明随着自主性上升,控制难度、可逆性和问责机制的变化规律。为落地该框架,我们提出基于风险的决策流程以分配允许的自主水平,分析风险与问责在不同层级间的演变关系,并通过一个已部署的企业级数据工程代理案例进行验证:即使某系统具备高能力等级,也可因风险、可逆性或组织准备度不足而被限制在较低的允许自主水平。通过厘清授权与能力的关系,本研究为智能体AI系统的设计、部署与治理提供实用指导。

原文摘要 · Abstract (English)

As AI systems increasingly exhibit agentic behavior, discussions of autonomy often conflate what systems are technically capable of doing with what they should be permitted to do in practice. This paper introduces a governance framework that explicitly separates Allowed Autonomy Levels (AAL), which define the degree of autonomy an AI agent is authorized to exercise given risk, oversight, and accountability considerations, from Autonomous Capability Levels (ACL), which characterize an agent's inherent technical abilities. We present a structured set of autonomy levels spanning reactive execution, decision support, supervised action, goal-directed autonomy, and delegated operational authority, and describe how control, reversibility, and accountability change as autonomy increases. To operationalize this framework, we propose a risk-aware decision process for assigning allowed autonomy, analyze how risk and accountability evolve across autonomy levels, and demonstrate its application through a deployed enterprise data engineering agent, illustrating how a system assessed at a high capability level can be deliberately constrained to a lower allowed autonomy based on risk, reversibility, and organizational readiness. By distinguishing authorization from capability, this work provides practical guidance for the design, deployment, and governance of Agentic AI systems.

AI治理自主性风险控制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。