Autonomy certificates are a governance mechanism proposed in the Feng–McDonald–Zhang essay "Levels of Autonomy for AI Agents" (Levels of Autonomy for AI Agents (Feng + McDonald + Zhang, Knight Columbia, 2026)). Under the proposal, a third-party governing body would issue a certificate to an agent developer communicating the behavioral and autonomy characteristics of an agent to other developers, to other agents, and to regulators, making an agent's designed level of independence legible without requiring inspection of its internals.
Background: autonomy as a design choice
The certificates rest on the essay's argument that autonomy can be a deliberate design decision, separable from capability. Given a fixed capability set and operational environment, a developer chooses how much the agent acts without user involvement. The authors distinguish agency (the capacity to form and carry out an intention) from autonomy (the extent to which an agent is designed to operate without user involvement). On this account an agent can have high agency but low autonomy (many tools, but it seeks user feedback), or low agency but high autonomy (a single API, but it runs unsupervised in the background).
The framework defines five user-centered autonomy levels, keyed to the role a user (human or AI) plays:
| Level | User role | Description |
|---|---|---|
| L1 | Operator | User in charge throughout; agent provides on-demand support ("copilot") |
| L2 | Collaborator | User and agent jointly drive the workflow |
| L3 | Consultant | Agent drives execution; user consulted on key decisions |
| L4 | Approver | Agent drives execution and decisions; user approves at gates (e.g. plan-mode) |
| L5 | Observer | Agent operates autonomously; user observes, intervenes only on failure |
Because autonomy and capability are treated as independent dimensions, the authors argue a certificate captures information that benchmark scores do not: a highly capable model deliberately deployed at L1, and a weak model run at L5 on a narrow task, are different governance objects.
Applications
The essay identifies three applications for autonomy certificates. For risk assessment, third-party visibility into an agent's autonomy level is intended to enable ex ante harm estimation, before deployment and across agent-to-agent interactions. For safety-framework design, RSP-style policies could condition deployment thresholds on certified autonomy levels rather than on capability alone. For multi-agent legibility, in agent-to-agent ecosystems one agent could read another's certificate to decide how much to trust or defer to it, addressing the principal–agent opacity that arises when agents transact with agents.
Relation to other governance mechanisms
Autonomy certificates are framed as a disclosure or typed-credential mechanism, complementary to capability-threshold regimes. They operationalize the levels-of-autonomy framework for governance, in the way system cards operationalize capability disclosure. They sit alongside Post-Deployment AI System Monitoring and Meaningful Human Review as ways to keep a human, or accountable party, in the loop at a designed level rather than an ad hoc one. They also connect to AI Autonomy Risk and Agent Autonomy Spectrum (5 Levels) by making the autonomy axis a declared, auditable property.
Relationships
- depends-on: Levels of Autonomy for AI Agents (Feng-McDonald-Zhang framework)
- related: Agent Autonomy Spectrum (5 Levels), AI Autonomy Risk, Agentic Economy, Responsible Scaling Policy (RSP), Meaningful Human Review, Post-Deployment AI System Monitoring, Kevin Feng
- instance-of: AI Governance (umbrella)
Source: the Levels of Autonomy for AI Agents (Feng + McDonald + Zhang, Knight Columbia, 2026) essay (Feng, McDonald, Zhang, UW / Knight Columbia; July 2025, republished in the May 2026 symposium). Confidence is medium because the page rests on a single source.