The Three Levels of AI Autonomy (and How to Choose the Right One)
AI autonomy isn't a switch, it's a dial. Here are the three levels that exist and how to choose the one your business actually needs.

What does it actually mean for an AI system to be "autonomous"?
When we talk about the autonomy of an AI system, we're talking about how much it can act without a person stepping in at every point. It isn't a yes/no label - "it has AI" or "it doesn't." It's a scale. And like any scale, it can creep up gradually, without anyone quite noticing how far it's gone.
The useful image here isn't a light switch, which only has on and off. It's a volume dial: every turn doesn't add a little more sound, it multiplies what you'd better be ready to hear. The same happens with AI autonomy: every level up doesn't add a bit more automatic work, it multiplies what you need to keep watching if something goes wrong.
There are three levels. Let's go through them one by one.
Level 1: HIL — human in the loop (someone approves every case)
At this level, the system proposes and a person decides. Nothing executes without someone reviewing and signing off on it first.
Think of the bank officer who has to sign off before a transfer above a certain amount goes through: the operation can be perfectly prepared, but it doesn't leave the desk without that signature.
It's the slowest level, but also the safest for processes where a mistake carries real consequences: legal decisions, financial ones, or anything that directly affects a person.
Level 2: HOL — human on the loop (someone watches and can stop it)
Here, the system already acts in real time, without waiting for prior approval. But there's a person in front of the panel, watching what happens, with the ability and the authority to step in or shut it down if something drifts off course.
Think of an air traffic controller: they don't decide the route of every single flight, but they're watching all of them at once and step in the moment something strays from the plan.
This level multiplies speed, because the system no longer waits its turn. But it demands something many companies assume without ever checking: that the person watching actually has the time, the information and the room to intervene in time - not just the job title of "supervisor."
Level 3: autonomous, or human out of the loop (the system runs on its own and escalates exceptions)
At the third level, the system acts on its own within the limits it's been given, and only alerts a person when it hits a case it doesn't know how to handle: an exception.
Think of an elevator. Nobody decides each trip or watches each ride up and down. But the moment something fails, an alarm goes off and a person steps in.
It's the most efficient level, and also the one that demands the most work upfront: defining precisely what counts as an exception, because anything you haven't anticipated, the system will resolve on its own - for better or for worse.
The typical mistake: choosing the level for convenience
The most common failure isn't technical, it's a matter of judgment. Companies pick the level of autonomy based on what's convenient - automating as much as possible, getting the work off their plate as soon as they can - rather than on what happens the day the system gets it wrong.
A product-recommendation chatbot can afford level 3 without much risk: if it gets it wrong, the customer just sees an odd suggestion and moves on. A system that approves contract terms, or decides who gets contacted first on a list of at-risk customers, shouldn't sit at that same level just because "it works fine most of the time."
The right level isn't the one that saves the most work this week. It's the one that matches the real cost of a mistake, multiplied by how often that mistake can happen.
This, in fact, isn't just common sense: the EU AI Act requires "effective human oversight" for high-risk AI systems - meaning people must be able to understand what the system does, decide not to use its output, and intervene in or stop it. The regulation doesn't mandate one specific level out of the three, but it does require companies to justify why the one they chose is right for that particular process.
What level is each piece of your process at today?
The question worth asking isn't "do we use AI or not?" It's this: for every piece of your operation that already runs on AI, what level is it at, and who is the actual person standing behind that level? Not a role on an org chart - a specific person, with the time and the real authority to step in when it matters.
Many companies discover, once they sit down and ask themselves this calmly, that they've been operating at a higher level than they thought - without the human role that level actually requires behind it.
If you want to know where your company stands on this, and on the other areas that determine your digital maturity, Digital Transformations' Digital Maturity Calculator gives you, in a few minutes, a breakdown by area - not a single score - of where you are and what's worth moving first.
Shall we talk? https://www.digitransformations.com/madurez-digital
Content developed with AI assistance and reviewed by the Digital Transformations editorial team
Frequently asked questions
What's the difference between human in the loop and human on the loop?
With human in the loop, someone approves every case before it runs. With human on the loop, the system already acts in real time, and the person watches with the ability to step in or stop it if something goes off course.
What's the safest level of AI autonomy to start with?
For processes where a mistake carries real consequences, the safest approach is starting at human in the loop and moving up a level as the system proves reliable and exceptions are clearly defined.
Does EU regulation require a specific level of AI autonomy?
The EU AI Act requires 'effective human oversight' for high-risk AI systems, but it doesn't mandate one of the three levels specifically - it requires companies to justify that the level they chose fits that process.
Can you change the level of AI autonomy after the system is already running?
Yes, and it's worth reviewing periodically. It's common to start at a more supervised level and move up as the system builds a track record of successes and well-controlled mistakes.
What happens if you choose the wrong level of AI autonomy?
The risk isn't that the system fails - that can happen at any level - it's that it fails without anyone having the time, information or authority needed to catch it and step in in time.
Related articles

Hiding is not blocking: why hiding a button does not protect your data
If a user cannot see something, that does not mean they cannot reach it. Three real cases of controls that looked in place and were not.

Who decides an AI agent can go to production?
Most AI agents reach production because someone tested them, they worked, and they stayed. There was no decision — there was drift.

How do you check that an AI agent withstands a manipulation attempt?
If an agent reads email or web pages, anyone can write to it. The usual defence, asking it in its prompt not to comply, is a request, not a control.
