Autonomy now needs a filed decision policy
Agent decision rights written into law, and the plumbing that makes answering for them possible.
How we assure
China’s implementation opinions on intelligent agents
Every agent decision has to be sorted into three tiers before deployment: decisions only a person may take, decisions that need approval first, and decisions the agent may take alone. An agent used in healthcare, transport, media or public safety must be filed and pass a compliance test before it goes live.
We tell a client that the rights an agent holds to decide are not a design choice discovered in production. They are a policy written down before it runs. A three-tier split of authority is something a board can inspect. A vague assurance that a human is in the loop somewhere is not.
How we build
One finds vulnerabilities across an environment and proves which could actually be exploited, then drives the fix through the team’s own process rather than merging a patch itself. The other builds a graph of what a firm already knows, so an agent can look up the rules of the business instead of guessing. Neither is a model.
Our position is that this layer decides whether an agent is safe to give real access to. Read next to the Chinese rules, the pattern is one thing. Autonomy is becoming a question of paperwork rather than capability, answered as what tier this decision sat in, who approved it, and what the agent knew when it acted.