Until recently, we haven’t had language precise enough to make that choice. You were either “using AI” or you weren’t. Then a better vocabulary turned up in an unexpected place - the Mills Review, the FCA’s new report on AI and the future of retail financial services.


The framework it uses describes five roles for the human as more of a task is handed over to a machine. As an operator, you use AI as a tool. As a collaborator, you and the machine plan and act together. As a consultant, you guide while it compares options and recommends. As an approver, it prepares the action and you authorise it. As an observer, it acts continuously within limits you have set, while you monitor the outcomes.  Five positions on a spectrum, where before there were two.


The framework isn’t the FCA’s. The report borrows it, with credit, from three researchers - Kevin Feng, David McDonald and Amy Zhang - whose paper, Levels of Autonomy for AI Agents, was published through Columbia’s Knight First Amendment Institute in mid-2025.


That short journey - from a human-computer-interaction paper to a financial regulator’s flagship review in under a year - is itself part of the point. A framework this useful doesn’t stay in its home field. It spreads, because everyone is suddenly facing the same question and nobody has had the words for it.


Their central argument travels with it, and it’s the one that matters most: autonomy is a design decision, separate from how capable the underlying model might be.


Just because a system can operate at the far end of the spectrum doesn’t mean it should. You don’t move towards maximum autonomy because the technology allows it. You choose the level that fits the job.


If the shape feels familiar, it should. It echoes the scale the car industry has used for years to talk about driving automation - a shared language for calibrating who does what, and under which conditions.


We worked out, collectively, that “how autonomous?” is something you judge against the situation, not a switch you throw. We did it for cars. We are now having the same conversation about every knowledge task in every office, and only now finding the words.


Because the choice the framework forces is the whole skill.


A hospital might want AI at consultant level for a diagnosis - recommend, and let the clinician decide - while happily allowing it to operate at observer level when reordering supplies. A law firm might use it as a collaborator when drafting, but would be reckless to allow a court filing to proceed without explicit human approval.


Same organisation, different tasks, different levels - each chosen for the outcome required, not for how advanced it looks in a board presentation.


Some researchers go further and argue that fully autonomous agents shouldn’t be built at all - a warning that becomes particularly difficult to dismiss when the consequences are serious. You don’t have to go that far to take the point. Pushing everything towards the right-hand end of the spectrum doesn’t automatically give you a better service. Sometimes it simply gives you a riskier one, faster.


The people receiving the service have levels too.


Take my commute. I'd happily let an agent choose the route home: get me there as quickly and painlessly as possible, I don't care how. But the motorcycle tour I'm planning? I'd want my hands all over those decisions, because there the route is the trip. The value isn't arriving; it's the road I took to get there.


Same person, same act - choosing a route - but two completely different levels. When only the outcome matters, I'll hand it over. When the doing is the point, I want to stay in the saddle.


That's one of two forces deciding where I sit. The other I wrote about last week: trust is the moat, and friction drains it. How much I care sets how far I want the machine to go; trust sets how far I'll let it.


The autonomy spectrum shows the machinery beneath both. Nobody hands a machine the keys to something they care about on day one. You earn the right to move someone further along through one good experience after another - and one bad experience can send them backwards far faster.


Autonomy isn't a setting you switch on. It's permission: granted slowly, withdrawn fast.

That is another reason maximum autonomy is the wrong default. You don't get to assume you can start there, however much you might like to. Trust has to be earned, and the amount of autonomy someone grants will rise or fall alongside it.


None of this is really a finance idea, or a car idea, or an academic one.


It is portable precisely because it describes the relationship between a person and a machine acting on their behalf - now every industry’s problem, and every industry’s opportunity. A bank in the City, a startup in Halifax: the same five levels, entirely different work, one shared conversation.


So take the framework and use it. Map your service onto the five roles. Argue about where each task belongs. Decide what the machine should do, what the human must retain and where permission should be earned rather than assumed.


Make the choice out loud and on purpose - instead of drifting towards greater autonomy simply because the technology allows it.


The goal was never maximum autonomy.  It’s the right autonomy, chosen deliberately and earned.