Questions about running AI agents

Questions on how much work an AI agent takes on alone, and on how a person checks its work and stops it.

How much should an AI agent do without your approval?

At the start, an agent acts without asking only on actions that are cheap to undo, stay inside the company and move no money. Other actions wait for a person's approval until the agent's record on that exact task meets a rule written in advance, and anything that reaches outside the company tops out at act then notify. Four kinds of action stay at approval however long the record grows: moving money, agreeing to prices, terms or contracts, the first message to a person who has never heard from the company, and deleting records. The levels guide sets out the steps.

What are the levels of autonomy for an AI agent?

The guides here use four. Read only means the agent reads and reports and changes nothing. At draft it prepares work that a person carries out. Act after approval lets it carry out an item once someone approves it, and act then notify lets it act inside set limits and send a receipt at once. Academic work sets the levels differently: a 2025 paper proposes five, named for the role the user plays, from operator to observer. The levels guide compares the two and cites the paper.

When is an AI agent ready to send emails on its own?

When its record meets a rule written before it started. Invented for illustration: after 30 approved drafts in a row with at most a light edit, and no wrong recipient, wrong fact or promise nobody meant to make, sending moves from draft to act after approval. A second clean record at that level moves it to act then notify, where a person gets a receipt for each message. A first message to someone who has never heard from the company stays at approval. What an email says to a prospect is a sales question, and the guides leave it alone.

What should an approval request from an AI agent show me?

The approval card in the guides carries enough to decide without opening anything else: the action in one line, the exact content that goes out, what triggered it, links to the evidence it used, who it reaches, whether it can be undone and what it cost. The answers are approve, edit, or reject with a short reason, and those answers become the record that sets the task's level. A card that takes more than a minute to judge gets redesigned. The approvals guide lays out each part.

How do you stop an AI agent quickly when something goes wrong?

A stop switch works when it exists and has been tested before anyone needs it. The one in the guides only stops, comes in two sizes (one kind of action, or the whole agent), and sits outside anything the agent can change. A phone reaches it in about thirty seconds. A federal framework in the United States and the European Union's AI Act both describe a way for a person to halt an AI system, and the approvals guide cites them beside the switch's design and its monthly test.

What should an AI agent audit log record?

The federal catalog of security controls asks every audit record to establish what type of event occurred, when and where it occurred, its source, its outcome and who or what was involved. A receipt for an agent's action adds the instructions version and model it ran on, links to the evidence it read, who approved it and whether they edited, the agent's stated reason, and the tokens and price. The system that carried out the action writes the receipt at that moment, into a store the agent cannot change. The audit trail guide cites the catalog and lays out each field.

How much does it cost to run an AI agent?

The useful number is cost per completed action: a task's model and tool cost for a week divided by the actions that finished and were not rejected. The task and every number in this example are made up. A scheduling task runs up $6.00 of model and tool cost in a week and completes 111 actions, about 5.4 cents each. The owner spends 24 minutes in the approval queue that same week. The audit trail guide works through that week line by line.

How long should checking my agents take each week?

The time is a budget set in advance. Invented for illustration: fifteen minutes for a weekly summary that shows each task's actions and level, edits and rejections, any stop or failure, anything the agent has never done before, and the cost. When a week no longer fits in the fifteen minutes, promotions and new tasks pause until it does, so the read decides how many agents a company can take on. The audit trail guide shows the summary line by line.

Should one AI agent do everything or should you use several?

One agent on one narrow task is the easiest to govern, because its level, its access and its record all describe one job. When a single agent's work spreads across tasks with different risks, splitting it gives each task its own access and its own record, and so its own level. The Open Worldwide Application Security Project, a nonprofit, traces an agent's damaging actions typically to one or more of three causes: more functions, permissions or autonomy than the task needs. Narrow agents cut all three, and the levels guide cites that analysis.

Is a business responsible for what its AI agent tells a customer?

A tribunal in British Columbia held an airline responsible for what its website chatbot told a customer about a bereavement fare. In the February 2024 decision, known as Moffatt, the airline argued it could not be held liable for what its chatbot said; the tribunal described that as treating the chatbot as a separate legal entity, and rejected it. The decision is Canadian, and this answer is general information, not legal advice. The approvals guide tells the case with its source and covers routing each new kind of customer statement through approval.

Can AI agents run a small business on their own?

The guides here keep a person answerable for each agent: agents take over repeating tasks, and a person sets their limits, approves what is risky and reads what they did. In a 2023 sanctions order, a federal judge in New York wrote that using a reliable AI tool for help is not improper, while court rules still make lawyers answerable for the accuracy of what they file. Moving money, agreeing to prices, terms or contracts, the first message to a person who has never heard from the company, and deleting records stay with a person. The audit trail guide tells the court case.

Should you tell people when an AI agent wrote a message?

California's bot disclosure law makes it unlawful to use a bot online to knowingly mislead a person in California about its artificial identity to push a sale or sway a vote, and a clear, conspicuous disclosure avoids liability (Business and Professions Code, sections 17940 and 17941). The law defines a bot as an automated online account whose actions or posts are all or substantially all not a person's, so a message drafted with AI and checked by a person may fall outside it. Rules differ by state and channel, and this answer is general information, not legal advice.

Talk through one agent workflow

A 30-minute call about one agent workflow: what it may do alone and who approves the rest. Bring the step you most want to hand off.

Book a 30-minute callOpen the worksheet

Booking opens Google Calendar in a new tab.