Arguments about machine autonomy usually fail because they are conducted at the wrong grain. Asking whether a decontamination system should be autonomous produces a values debate with no exit. Asking whether this specific decision may be taken without a human, given this specific evidence, within this specific time budget, produces an answer you can write into a specification.
Decompose the mission into decisions, not into modes
The mode vocabulary — manual, supervised, autonomous — describes the operator interface. It does not describe accountability, and accountability is what the argument is actually about. Replace modes with a decision inventory: list every point in the mission where an outcome branches, and treat each one separately.
For a decontamination task the inventory is short and unglamorous. Where to position. Whether conditions permit starting. Which surface class is in front of the effector. Whether to apply. Whether the pass met its own quality condition. Whether to repeat, move on, or stop. Whether to declare the task finished.
Written out this way, the disagreement resolves fast. Almost nobody objects to a machine deciding its own station-keeping. Almost everybody objects to a machine declaring a task finished. The interesting work is in the middle, and the middle is where a rule is worth writing.
The gate test: three questions per decision
For each decision in the inventory, ask three things in order. The order matters, because a no at any step ends the enquiry.
- Is the decision reversible within the time it takes to detect the error? A reversible decision tolerates automation because a wrong answer costs a retry. An irreversible one — releasing a site, discharging into a drain, declaring completion — does not, regardless of how good the classifier is.
- Can the machine produce, at decision time, the evidence a human would have been required to have? Not similar evidence. The same evidence, in a form that can be inspected afterwards. If a human would have needed a reading against a written criterion, an inference from a camera is not a substitute.
- Does anyone remain accountable if the machine is wrong, and do they have a means to intervene? Accountability without an intervention channel is a signature on someone else decision.
Evidence sufficiency is the hard gate
Gate two is where most proposals fail, and the failure is usually disguised as a performance claim. A classifier reported at high accuracy on a curated dataset is being offered as a substitute for a measurement taken against a written criterion. Those are not the same kind of statement. The classifier reports a probability over a distribution it was trained on; the criterion is a threshold with a legal or doctrinal source. Substituting one for the other silently changes what the record means.
The workable test is a document test rather than a technical one: take the evidence the machine will log, hand it to someone who was not present, and ask whether they can reconstruct why the decision was correct. If they cannot, the machine has not met the gate, however well it performs.
The human gate has to be real
A human in the loop who has three seconds, no independent information, and a strong default to concur is not a gate. They are a signature-collection mechanism, and the accountability they appear to supply is fictitious. Three conditions make the gate real: the human sees evidence the machine did not itself select, has enough time that declining is practical, and faces no penalty for declining that exceeds the penalty for wrongly concurring.
The last condition is organisational, not technical, and it is the one most often left unaddressed. Where concurrence is fast and refusal is slow and awkward, the system will produce concurrence at whatever rate the interface allows.
What to write into a specification
The output of this exercise is short: a table with one row per decision, and four columns — decision, reversible yes or no, evidence artefact, and deciding party. Where the deciding party is the machine, the row also names the log record that makes it reviewable. That table is worth more to a reviewer than any amount of prose about autonomy philosophy, and it is producible in an afternoon.
Boundary
This column concerns decision allocation and evidence, not system design. It does not describe any specific control architecture, sensor suite, algorithm, or performance figure, and it makes no claim that any particular system meets any gate. Discussion of airborne dry decontamination remains at concept and role level. This is not doctrinal, legal, or safety-certification guidance; autonomy in safety-related functions is governed by national regulation and applicable standards, which readers must confirm for their own jurisdiction.
Source frame. The autonomy-level and human-gate structure is the question structure from BLIS-D: Autonomous AI Decision-Making — Where a Machine May Decide and Where It May Not (Kindle, ASIN B0H3DMTTDT). The three-gate sequence, the decision inventory and the document test were written for this column. View on Amazon
Verification. The gate framework is author analysis (L3). No autonomy standard is cited as endorsing this specific sequence, and no system is assessed against it. Falsification. If a decision is irreversible yet routinely and safely automated with a reviewable evidence record, gate one is too strict and should be replaced by a cost-of-error test.
Leave a Reply