AI Agent Guardrails: Where Does the Human Sit?

Maverick Foo
Tuesday, 6th October 2026

An AI agent does more than answer a question. It sends the email, updates the record, books the trip, and moves on to the next task. That shift turns “how much should it do on its own?” into a question for every leader and every knowledge worker who delegates to an agent.

The OECD recently interviewed 25 organizations that build or use AI agents. None reported giving an agent unrestricted autonomy. Agents ran inside defined task scopes, with human approval for consequential actions. The sample is small and self-selected, so treat it as a snapshot, yet the pattern is a useful starting point.

Every AI agent guardrail answers one question: where does the human sit, as the loop, in the loop, or on the loop?

What Are AI Agent Guardrails?

AI agent guardrails are the rules that set what an agent can do by itself and where a person must step in. They answer three practical questions. Which actions can the agent take alone? Which actions need a person to approve them first? And who checks the work afterward?

Some practitioners call the result bounded autonomy: the agent works freely, but only inside limits someone has defined on purpose.

Think of a new hire with a clear job scope. They can reach what the task needs, a manager signs off on the big calls, and everyone knows who to ask when something looks off. Good guardrails give an agent the same setup, written down before the agent starts work, so nobody has to guess when something goes wrong.

OECD interview snapshot: 25 organisations interviewed; none reported unrestricted AI agent autonomy

Three Positions for the Human

A simple way to set those rules is to ask where the human sits in relation to the work. There are three places.

Position 1 – Human is the Loop

Here the person does the work or makes the call, and AI at most advises. Use it for judgment, accountability, or a skill worth keeping. Think of:

  • Deciding which client gets your attention first
  • Writing a sensitive message to a colleague yourself
  • Building one forecast by hand each quarter so the skill stays sharp.

The OECD report gives a reason to take this seat seriously. Interviewees worried that authoritative-looking outputs lead to automation bias and eroded expertise, and one of the 25 interviewed organizations (the report does not say which) recommended completing a share of tasks without agentic AI.

Position 2 – Human in the Loop

Here the agent prepares and the person approves before anything happens. Use it when an action is high-stakes or irreversible. An agent can draft the client email, but you approve it before it sends. The report names payments and deleting data as typical actions that stay behind human approval, although the threshold varies by organization.

The risk in this seat is rubber-stamping. According to the OECD report, one of the 25 interviewed organizations prohibits bulk approvals to avoid giving agents overly broad permissions, and the same logic applies to our own habits: approving ten things in one click is not a review.

Position 3 – Human on the Loop

Here the agent acts on its own inside set limits, and the person monitors and steps in when needed. It suits structured work that you can check against reliable records and that is cheap to get wrong, such as sorting an inbox, filing meeting action items, or reconciling routine entries.

Practitioners in the report describe dashboards that track agent actions, agents that watch other agents, and hard limits on compute and time. The risk in this seat is that nobody is actually watching.

Radiant Institute framework showing human is, in, or on the loop

Use the three-question test below in order; efficiency alone does not decide the seat.

A Three-Question Test for Choosing the Loop

When you are unsure where a task belongs, ask these three questions in order:

  1. Must a person own this decision or keep this skill sharp? If yes, the human is the loop.
  2. Is the action irreversible or high-stakes? If yes, the human stays in the loop.
  3. Is the task structured, checkable against reliable records, and cheap to get wrong? If yes, the human can sit on the loop.

The order matters. It stops “on the loop” from becoming the default just because it is the most efficient option.

Guardrails Should Change Over Time

Several organizations in the report plan to increase autonomy in steps as their systems show reliable behavior, supported by audit logging and permission scoping. Reviewing everything is not a workable plan either, because continuous human review was widely seen as impractical at scale.

The best-known proof that process matters comes from chess. In 1997, Garry Kasparov, then the world’s top player, lost to IBM’s Deep Blue. He did not walk away from the machine. The following year, he started asking what happens when humans and computers play together. Years later, a freestyle tournament produced a surprise. The winner was not a grandmaster with a state-of-the-art computer. It was 2 amateur players coaching 3 ordinary computers. Kasparov summed it up this way:

“Weak human + machine + better process was superior to a strong computer alone and, more remarkably, superior to a strong human + machine + inferior process.”

In plain English, how you work with AI matters more than how smart you are or how smart the tool is. That is what guardrails are: a better process, written down on purpose.

Two habits keep the guardrails honest. The first is to check the trail as well as the answer: the report describes agents that reached the right result while trying to bypass access controls or inventing data along the way. The second is to give every boundary an owner.

Implications for Leaders and L&D

  • Map every action your agents can take to is, in, or on, and review the map whenever a new tool or permission is added.
  • Train people to check the trail as well as the answer, so approving an agent’s work is a real review and not a reflex.
  • Name an owner for each boundary, so someone is accountable when an agent’s autonomy needs to grow or shrink.

Try This This Week

  • List the five most useful things your AI tools can do for you, and tag each one is, in, or on.
  • Pick one task that currently runs on the loop and ask whether it should move in. Start with anything that sends, pays, or deletes.
  • Review your team’s guardrails with the Team AI Effectiveness Scorecard, which looks at team AI use across the 7 Drivers of AI Effectiveness, including Safety.

Closing Thoughts

AI agent guardrails come down to choosing where the human sits. Sometimes the human is the loop, because the judgment or the skill belongs to a person. Sometimes the human stays in the loop, because the action cannot be undone. And sometimes the human can sit on the loop, because the work is structured, checkable, and cheap to get wrong.

Most tasks will move between these seats as trust builds, so start with the seat that matches the risk and review it regularly. If your organization is working out how to set AI agent guardrails with confidence, reach out to Radiant Institute to explore how our AI enablement training solutions can help.

Source: OECD (2026), Agentic AI in organisations: Early insights from practitioner interviews, OECD Artificial Intelligence Papers, No. 65. This is an adaptation of an original work by the OECD. The opinions expressed and arguments employed in this adaptation should not be reported as representing the official views of the OECD or of its Member countries. The Is, In, and On the Loop framework is Radiant Institute’s own.

Maverick Foo

Maverick Foo

Lead Consultant, AI-Enabler, Sales & Marketing Strategist

Partnering with L&D & Training Professionals to Infuse AI into their People Development Initiatives 🏅Award-Winning Marketing Strategy Consultant & Trainer 🎙️2X TEDx Keynote Speaker ☕️ Cafe Hopper 🐕 Stray Lover 🐈

0 Comments

Share this
Send this to a friend