AI Policy Wiki
Dashboard

Autonomy Certificates

medium confidence · updated 2026-06-06

A proposed governance mechanism, introduced by Feng, McDonald, and Zhang (Knight Columbia, 2025/2026), in which a third-party body issues certificates communicating an AI agent's designed level of autonomy to other developers, agents, and regulators. Builds on the authors' five-level user-centered autonomy framework and the claim that autonomy is a deliberate design choice separable from capability.

Autonomy certificates are a governance mechanism proposed in the Feng–McDonald–Zhang essay "Levels of Autonomy for AI Agents" (Levels of Autonomy for AI Agents (Feng + McDonald + Zhang, Knight Columbia, 2026)). Under the proposal, a third-party governing body would issue a certificate to an agent developer communicating the behavioral and autonomy characteristics of an agent to other developers, to other agents, and to regulators, making an agent's designed level of independence legible without requiring inspection of its internals.

Background: autonomy as a design choice

The certificates rest on the essay's argument that autonomy can be a deliberate design decision, separable from capability. Given a fixed capability set and operational environment, a developer chooses how much the agent acts without user involvement. The authors distinguish agency (the capacity to form and carry out an intention) from autonomy (the extent to which an agent is designed to operate without user involvement). On this account an agent can have high agency but low autonomy (many tools, but it seeks user feedback), or low agency but high autonomy (a single API, but it runs unsupervised in the background).

The framework defines five user-centered autonomy levels, keyed to the role a user (human or AI) plays:

LevelUser roleDescription
L1OperatorUser in charge throughout; agent provides on-demand support ("copilot")
L2CollaboratorUser and agent jointly drive the workflow
L3ConsultantAgent drives execution; user consulted on key decisions
L4ApproverAgent drives execution and decisions; user approves at gates (e.g. plan-mode)
L5ObserverAgent operates autonomously; user observes, intervenes only on failure

Because autonomy and capability are treated as independent dimensions, the authors argue a certificate captures information that benchmark scores do not: a highly capable model deliberately deployed at L1, and a weak model run at L5 on a narrow task, are different governance objects.

Applications

The essay identifies three applications for autonomy certificates. For risk assessment, third-party visibility into an agent's autonomy level is intended to enable ex ante harm estimation, before deployment and across agent-to-agent interactions. For safety-framework design, RSP-style policies could condition deployment thresholds on certified autonomy levels rather than on capability alone. For multi-agent legibility, in agent-to-agent ecosystems one agent could read another's certificate to decide how much to trust or defer to it, addressing the principal–agent opacity that arises when agents transact with agents.

Relation to other governance mechanisms

Autonomy certificates are framed as a disclosure or typed-credential mechanism, complementary to capability-threshold regimes. They operationalize the levels-of-autonomy framework for governance, in the way system cards operationalize capability disclosure. They sit alongside Post-Deployment AI System Monitoring and Meaningful Human Review as ways to keep a human, or accountable party, in the loop at a designed level rather than an ad hoc one. They also connect to AI Autonomy Risk and Agent Autonomy Spectrum (5 Levels) by making the autonomy axis a declared, auditable property.

Relationships

Source: the Levels of Autonomy for AI Agents (Feng + McDonald + Zhang, Knight Columbia, 2026) essay (Feng, McDonald, Zhang, UW / Knight Columbia; July 2025, republished in the May 2026 symposium). Confidence is medium because the page rests on a single source.