Governance, Control, Autonomy — Who Gets to Decide What?
Published on 7/2/2026 · André Hellmann
The agent sent the email. Was it allowed to? Good AI governance does not answer that question with yes or no, but with a dial: adjustable per workflow — what AI may do alone, what needs approval, and what it may never do. This article shows why decision rights are a design question and who should hold the dial.
Discuss the next step in a free diagnostic call. Book a call →
Contents
- The agent sent the email. Was it allowed to?
- Ungoverned autonomy is already here
- The autonomy dial: three settings
- The dial per function: content, sales, workflow
- Designing decision rights: three steps
- The link to compliance: GDPR and the EU AI Act
- The netzstrategen approach to AI governance
- Frequently Asked Questions about AI Governance
- Sources
The agent sent the email. Was it allowed to?
An agent answers a customer request. On its own, in seconds, with no second pair of eyes. The reply is polite, fast, and factually wrong.
Now the question is no longer technical. It is a question of decision rights. Somewhere — deliberately or by default — it was decided that this agent could communicate externally on its own.
That is exactly the point. The question is not what AI can do. The question is who holds the dial — and which setting it is on for each task. Control, in this view, is not a brake. It is an adjustable component of every workflow.
Ungoverned autonomy is already here
The debate about AI autonomy often pretends the decision is still ahead. It is not. In most organizations, AI is already acting — just without a defined dial.
The numbers prove it. 63% of breached organizations lack an AI governance policy (Source: IBM Cost of a Data Breach, 2025). Where shadow AI is widespread, a data breach costs an average of $670K more (Source: IBM Cost of a Data Breach, 2025). And 48.6% of German companies have not seriously prepared for the EU AI Act (Source: Deloitte Legal, 2024).
This means the choice is not between autonomy and control. It is between governed and ungoverned autonomy. Ungoverned means employees set the dial themselves — each one differently, none of it documented.
Responding with a total ban only pushes the problem into the shadows. Allowing everything gives up the steering instrument. Both hand the dial away. Good AI governance takes it back — as a deliberately designed system of autonomy with control.
The autonomy dial: three settings
Decision rights cannot be assigned in bulk. They are set task by task — like a dial with three settings. The setting follows the risk, not the hype: the greater the external impact and the potential damage, the tighter the control.
The dial turns the big question “Do we trust AI?” into a design decision: which setting fits this task? Three levels are enough for that.
Level 1 — Full autonomy
The agent acts alone, with no human sign-off. This is only acceptable where errors are cheap and reversible. Examples include internal research, drafts, and sorting data.
Level 2 — Autonomy with review
The agent works independently, but a human checks the result before it takes effect. This setting fits most productive tasks. Speed is preserved, and the human keeps the final word.
Level 3 — Approval required
The agent may trigger nothing until a human has actively agreed. This setting applies to anything high-risk: external communication, money, contracts, personal data.
All or nothing
Unchecked autonomy → unnoticed errors → damage at the customer (or total ban → wasted value)
Three autonomy levels
Assess task by risk → assign the matching level → autonomy with control as a system
The dial settings add up to a matrix: function times autonomy level. Each function gets a documented setting per task type. That makes decision rights visible, traceable, and steerable — the foundation of solid AI Operations.
AI governance is not a technical configuration. It is a leadership decision about who the company entrusts with which responsibility.
The dial per function: content, sales, workflow
The dial is set per workflow, not per technology. The same model, the same agent — and still different settings, depending on the task at hand. Three examples make this tangible.
Content agent
A content agent researches, structures, and writes drafts. Research and the first draft run at Level 1 — internal work, easy to correct.
But the moment a text is meant to be published, the dial jumps to Level 3. No agent publishes on its own. This rule is non-negotiable at netzstrategen, because anything external-facing needs a human approver.
Sales agent
A sales agent qualifies leads, prepares data, and proposes replies. The analysis and the suggested reply run at Level 2 — fast, but with review.
Binding offers, discounts, or contract commitments sit at Level 3. This is about money and legal obligation. These decision rights stay with a human.
Workflow agent
A workflow agent moves data, creates tickets, and kicks off internal processes. Pure routine steps with no external impact often run at Level 1.
But when a workflow touches customer data or external systems, the dial moves up. For more on why such gaps between capability and action appear, read the analysis of the Implementation Gap. The task determines the setting — not the tool.
Designing decision rights: three steps
The autonomy dial is not a document you write once. It is a design process inside live operations. Three steps get it reliably started.
Step 1 — Map the tasks
First comes a list of what the AI agents actually do. Not what they could do, but which concrete actions they trigger. Without this map, every dial setting hangs in the air.
Step 2 — Assign risk and dial setting
Every action is assessed by external impact and potential damage, then assigned one of the three levels. The decision is documented — decision rights that are written down nowhere do not exist.
Step 3 — Enforce control in the system
A dial setting without enforcement is just a wish. The approval logic belongs in the system: review steps, approval gates, logs. Whoever steers this centrally is effectively running an Admin Layer for AI governance.
Governance without technical enforcement stays theory. Only review steps, approval gates, and logs make autonomy levels effective in daily work.
These three steps are not a one-off project. New agents, new tasks, and new risks demand new dial settings all the time. Holding the dial is therefore a standing leadership duty — closely tied to the dual challenge of AI leadership.
The link to compliance: GDPR and the EU AI Act
The autonomy dial is not just good practice. It is increasingly a requirement. Documenting decision rights cleanly also satisfies regulatory demands.
The GDPR requires that personal data be processed lawfully and traceably. An agent handling customer data on its own is a risk here. Level 3 for personal data is therefore not caution, it is compliance.
The EU AI Act goes further. It sorts AI applications into risk classes and ties obligations of transparency and human oversight to them (Source: European Commission, EU AI Act). Human oversight, in practice, means a documented, enforced dial. That is exactly what the three autonomy levels encode.
How accountability, oversight, and documentation fit together is covered in the glossary entry on Responsible AI & AI Act Compliance. Good governance and compliance are not separate projects. They are the same discipline from two angles.
The netzstrategen approach to AI governance
netzstrategen does not build governance as a glossy policy, but as part of the operating model teams use every day. The dial should enable work, not block it.
The base rule is clear: no agent publishes or commits on its own. Anything external-facing runs through a human approver. Internally, where errors are cheap, the dial is deliberately set to plenty of freedom.
This only works when the people are on board. Dial settings no one understands get bypassed — much like the People-Process Gap. So the rules are developed with the teams, anchored in Operating Systems and lived in operation.
As a practical head start, a governance template brings tasks, risk, and autonomy level together in one matrix. It is the fastest way to move the dial from concept into governed everyday practice.
Frequently Asked Questions about AI Governance
What is the difference between governance and control?
Governance is the rulebook: it defines who is allowed to make which decision and who is accountable for it. Control is the enforcement of those rules in live operation — through reviews, approvals, and logs. Governance without control stays theory, and control without governance stays arbitrary.
How do I define autonomy levels for my AI agents?
Every action is assessed with two questions: how large is the external impact, and how hard would an error be to reverse? Internal, reversible tasks get full autonomy, while anything involving money, contracts, or external communication needs approval. Autonomy with human review sits in between.
What happens if an agent breaks the rules?
A good governance setup prevents most violations technically, because risky actions simply cannot run without approval. If an incident still occurs, the log makes it traceable, reviewable, and correctable. In the free diagnosis call we show how to build this protective layer for a company’s agents.
Sources
- McKinsey: The state of AI in 2024, McKinsey Global Survey on AI, 2024
- Gartner: Hype Cycle for Artificial Intelligence, 2024, Gartner, 2024
- BCG: The Widening AI Value Gap, 2025
- European Commission: Regulation on Artificial Intelligence (EU AI Act), 2024
- IBM: Cost of a Data Breach Report, 2025
- Deloitte Legal: Umfrage EU AI Act, 2024