The Director's Brief · Companion to the AEF Working Paper

Letting AI do the work without losing control of the company

The Autonomous Employee Framework, explained in plain language. Ten minutes, no jargon.

The problem in one paragraph

Companies are starting to run real operations with autonomous AI agents — software that reads email, updates systems, and contacts customers on its own. The instinctive safety plan is "a human approves everything." That plan fails at scale: nobody can genuinely review ten thousand AI decisions a day. Either the approval queue strangles the value of automation, or — far more often — approvals quietly become rubber-stamps and the "human oversight" becomes theater. The Autonomous Employee Framework (AEF) is our answer: a set of operating rules, like financial controls but for AI decision-making, under which the AI workforce runs mostly on its own while humans stay genuinely in charge of what matters.

The one-line version: the levels of self-driving, applied to office work — a graduated ladder of AI autonomy where every promotion needs a human signature, every failure automatically costs a rung, and every chain of command ends at a person.

Where this sits in the AI era

The AI era has three steps, defined by what the technology actually delivers:

StepDeliversWhat that means
1 · LLMsAnswersYou ask, it responds — and you still do all the work. Nothing to govern, because it can't act.
2 · AI agentsTasksIt plans, uses tools, and acts — then vanishes when the task ends. Safety exists, but it's bolted on app by app: permission pop-ups and sandboxes, not management.
3 · AI employeesRolesIt holds a job over time, builds a track record, and can be promoted, demoted, audited, and held accountable — managed like a workforce.

The key insight: step 3 isn't step 2 plus rules — it requires something today's agents don't have: permanence. You cannot give a performance review to something that forgets it exists after every task. There is no track record to reward, no identity to hold accountable. That's why real governance can't simply be patched onto today's agents; it needs agents built to persist. It's the difference between a merchant keeping cash in a strongbox and an actual banking system with audits and examiners — one is a feature, the other is an institution. This framework is the institution. And it points somewhere: once AI employees exist, the next step is the AI organization — AI teams with AI team leads, still answering to humans. The rules that make step 3 safe are the same rules step 4 will inherit.

The six rules that matter

  1. AI agents earn trust like new hires.Every agent starts on probation with tiny limits, then works "in shadow" — doing the job for real while its output goes into a drawer for checking, not out the door. Authority grows only with a proven record, and drops automatically the moment the agent materially fails. Raising trust always needs a human signature; lowering it never does. The system can only fail toward less freedom.
  2. AI team leads absorb the routine approvals — inside hard guardrails.Senior agents ("deputies") approve routine work within a spending limit, like a shift supervisor. They can never change the rules, never fire anyone, and humans spot-check their decisions — checking more often when the stakes are higher. Crucially, reporting lines can never form a circle: every chain of supervision must end at a human, and a computer verifies that continuously. "Are we still in control?" has a checkable answer.
  3. Review effort matches the stakes.Every action passes a rules-based check that can't be sweet-talked. Beyond that, cheap and reversible actions get light review; expensive or irreversible ones face a full panel of independent reviewers — including an AI from a different vendor, so the checker doesn't share the doer's blind spots. Governance never costs more than the risk it manages.
  4. The outside world is treated as hostile.Emails and documents can carry hidden instructions designed to hijack an AI — this is the most common real-world breach. We don't rely on the AI to resist manipulation. A locked "mailroom" sits between the AI and the world: everything leaving the company is checked against rules the AI cannot change. Even a fully tricked AI can't send anything the mailroom won't allow.
  5. Every decision leaves a sealed paper trail.Each decision is written to a logbook where every page is mathematically sealed to the one before — edit or remove a page and every later seal visibly breaks. One warning that trips up many teams: re-running a past AI decision can give a different answer, so a re-run is a diagnostic, never evidence. The sealed original is what you show a regulator.
  6. Whose side the AI is on is written down in advance.When the law, the customer, and the company want different things, the agent resolves it against a declared ranking — the law first, then safety, then the person on the receiving end, then the customer, then the company, and the agent's own survival dead last. Conflicts it can't resolve get escalated to a human, never guessed at.

The questions you should ask — answered honestly

"Has this actually run anywhere?"
The framework grew out of building agent infrastructure in production, and every rule traces to a failure we've seen or can name. But the paper is an architecture proposal, not a results paper — the tuned numbers (how many good actions earn a promotion, how often deputies get spot-checked) still need validation across real deployments. We say this in the paper rather than hiding it.
"What does all this checking cost?"
Review depth scales with stakes. Routine actions get a fast rules check; only high-stakes, irreversible actions pay for the full review panel. The expensive human attention is spent on a small audited sample — the same logic as a financial audit, which doesn't re-examine every transaction either.
"Can the AI be hacked?"
The honest answer: the AI itself can be manipulated by malicious content — today, every AI can. That's why the guarantee doesn't live in the AI. It lives in the mailroom outside it: hard limits on what can leave, enforced by ordinary deterministic software the AI can't influence. A manipulated agent is contained, not trusted.
"Who's accountable when something goes wrong?"
A human, always. Deputies approve; they never own. Charters — the rules themselves — can only be changed by a human. Incidents land on a named human supervisor, and one person can pause the entire AI organization with a single verified action.
"Is this compatible with regulation?"
It's designed for it. The EU AI Act requires "effective human oversight" without saying how; AEF is a concrete mechanism for it. For regulated data (health, payments, market-sensitive), the framework requires independent third-party attestation — companies handling that data don't get to grade their own homework.

Jargon translator

When you hear…It means…
CharterThe agent's signed job description plus its hard limits. No charter, no work.
Blast radiusThe maximum damage one action can do — in money, people contacted, things that can't be undone.
Shadow modeDoing the job for real, but output goes into a drawer for checking instead of out the door.
DeputyAn AI team lead with a signature limit. Approves routine work; can't change rules or fire anyone.
Canary taskA secret-shopper test: a fake task with a known right answer, slipped in among real work to catch quality slips.
EgressAnything leaving the building: every email sent, file shared, or byte of data going to an outside service.
Audit record vs. replayThe sealed original logbook entry vs. a re-run for debugging. Only the first counts as evidence.
Goodhart's lawWhen a measurement becomes a target, it gets gamed — like teaching to the test. AEF measures quality two independent ways so neither can be gamed alone.

What we're still working on

Stated plainly, because credibility beats polish

Deployment numbers. The exact thresholds — how much track record earns a promotion, how often deputies are sampled — need tuning against production data. The architecture is fixed; the dials are not.

Quality measurement at scale. Our defense against "blandly acceptable" AI work asks humans to occasionally write their own version for comparison. Keeping that affordable while keeping it honest is the hardest open problem, and we say so.

Physical-world actions. Deliberately out of scope. Governing AI that moves atoms (manufacturing, healthcare delivery) is a functional-safety discipline, and we'll author that chapter with people who've shipped safety-critical systems.

AEF-1.1 · DIRECTOR'S BRIEF Read the full working paper →