// blog · analysis · policy2026-08-17source: Regulatory texts

Autonomy becomes a permission level

Every regime so far has regulated what a model is. One has started regulating what it is allowed to decide by itself — and that turns out to be the easier thing to write down.

Before deployment, each of an agent's decisions must be assigned to one of three tiers: human-only, user-approval-required, or agent-autonomous. That is the operative mechanism of the first national framework to treat agents as their own regulated category.

Regulating the action, not the artifact

Almost every AI rule written to date regulates the model. What data it saw. What it may output. What must be disclosed about how it was built. This one regulates the act — and specifically, who is on the hook for it.

A tier assignment is a table. That is why it will spread.

Compare the compliance cost honestly. Characterising a training corpus is expensive because nobody agrees what a sufficient characterisation is. Demonstrating the absence of a capability is expensive because absence is not observable. Enumerating which decisions your agent makes alone is a spreadsheet, and any team that cannot produce it does not understand its own system.

The boundary already exists, undocumented

Anyone who has shipped an agent has drawn this line. It lives in a prompt instruction, a few conditionals, and a confirmation dialog somebody added after an incident. It was written by whoever was on the ticket, it is documented nowhere, and it gets loosened whenever it becomes inconvenient.

The rule does not create the boundary. It makes the existing one legible — which is a different and much more uncomfortable requirement, because the current answer for most deployments is we would have to go and look.

Meanwhile, the older seam

California is advancing audits, call-centre oversight and limits on AI-aided employment decisions — worthwhile, and aimed at the model-and-outcome layer that every Western regime is still working. The real fight there is preemption, not substance.

The convergence to watch is with the other end of the stack. The integration layer just standardised on an open protocol. Tooling is commoditising; authority is being regulated. Differentiation is getting squeezed into the narrow band between them.

What to do about it

Produce the table. Not because a Chinese regulation binds you — for most readers it does not — but because the exercise is diagnostic. If you cannot say which of your agent's decisions are autonomous, you do not have a governance gap, you have a comprehension gap, and the regulation arriving in your jurisdiction will find it.

Autonomy stopped being a property of the model this year. It became a permission you grant, and permissions get audited.

EveAI Core — AI Regulation in 2026: What Just Changed → · Inside AI Policy — AI regulation coverage, August 2026 →