29 Sep 2026 · 5 min read
How to set the right boundaries for an AI buyer without killing its effectiveness
Every organisation deploying an AI buyer faces a design question that no vendor will fully answer for them: how much should the system be allowed to do on its own, and where should it stop and ask? Get this wrong in one direction and the buyer is so constrained it offers no meaningful advantage over a human doing the same tasks manually. Get it wrong in the other direction and the buyer is operating beyond its mandate, making commitments the organisation did not sanction and incurring liabilities it did not anticipate.
What is the earned autonomy model?
Earned autonomy is a structured approach to expanding the scope of what an AI buyer does without human sign-off, based on demonstrated performance within progressively narrower constraints. The model runs in five stages: observe, recommend, draft, human-approved action, and bounded automatic action.
At the observe stage, the buyer has read access only. It reviews market data, pricing trends, and available inventory but takes no actions. At the recommend stage, it produces recommendations for a human to act on. At the draft stage, it prepares full deal proposals for human review before any commitment is made. At the human-approved action stage, it negotiates and commits, but every commitment requires explicit human sign-off at the gate. At the bounded automatic action stage, it commits within defined parameters without stopping for sign-off each time.
Most buyers in production today are operating at the human-approved action stage. The question of how to set the right boundaries is really a question of how to define the parameters that would eventually allow a shift toward bounded automatic action, and how to structure the human-approved action stage in the meantime so it adds genuine governance value rather than just friction.
Which decisions should always require human sign-off?
Some decisions should not be delegated to autonomous action regardless of how well the buyer has performed historically. These include: any commitment that creates a financial obligation above a defined threshold, any deal involving inventory sources not previously approved, any amendment to an existing deal that changes material terms such as price, volume, or placement, and any deal that the harness flags as containing unusual terms or potential brand safety risk.
These are not arbitrary categories. They represent the decision types where the cost of an error is high enough that the efficiency benefit of autonomous action does not justify the risk. Human sign-off on these decisions is not a concession to technology scepticism. It is the appropriate allocation of accountability for high-stakes choices.
Which decisions are safe candidates for bounded automatic action?
Decisions that are repeatable, low-variance, and within tightly defined parameters are the best candidates for bounded automatic action. These include: renewals of existing deals on unchanged terms, within a buyer that has demonstrated consistent brief compliance across many similar deals; price adjustments within a defined floor-to-ceiling range for inventory from approved sources; and volume adjustments within a defined range where the budget headroom is confirmed and the brief allows flexible volume.
The common characteristic of these candidates is that the decision space is small and well-understood. There are few ways for the buyer to get it wrong, and the harness can verify compliance with the defined parameters before the action executes. Bounded automatic action is not open-ended autonomy. It is autonomy within a box the organisation has defined, tested, and agreed to trust.
How is the boundary defined and enforced at the harness level?
The boundary between autonomous and human-approved action is a configuration in the harness, not a setting in the model. The model does not decide how much autonomy it has. The harness enforces the boundary by validating every proposed action against the defined parameters before executing. If the action falls within the parameters, it executes. If it falls outside, the harness stops it and routes it to the approval gate.
This enforcement needs to be strict. A harness that enforces the boundary approximately, treating the defined parameters as guidelines rather than hard limits, will drift over time. Actions that are marginally outside the parameters get through. The boundary shifts without anyone explicitly approving the shift. The first time this matters is when a commitment is made that the organisation did not intend to sanction, and by then the boundary has been meaningless for some time.
How do you set boundaries without killing effectiveness?
The risk of over-constraining the buyer is real. A buyer that requires human sign-off on every action, with no parameters defined for autonomous operation, is not an AI buyer in any meaningful sense. It is a recommendation engine that a human must manually execute. The efficiency case for deploying it is weak.
The way to preserve effectiveness while maintaining governance is to invest in defining the parameters well, not to loosen the enforcement. The more precisely an organisation can specify which inventory sources, which price ranges, which volume bands, and which brief types it is comfortable with the buyer handling autonomously, the more confidently it can allow autonomous action within those boundaries. Vague boundaries require more human oversight to compensate for the imprecision. Precise boundaries allow genuine autonomy within a trustworthy scope.
How does the buyer earn expanded boundaries over time?
Expanded autonomy is granted based on evidence of reliable performance within the existing boundary, not on the basis of time elapsed or vendor assurance. The evidence base is the deal record: a complete log of every action taken, every brief compliance check passed, every commitment made and whether it was delivered against. An organisation that reviews this record systematically, at defined intervals, has the information it needs to decide whether the buyer has earned a wider boundary.
This is the earned in earned autonomy. The boundary does not expand automatically. It expands because a human organisation reviewed the evidence, made a judgement, and explicitly updated the harness configuration to reflect a wider trust scope. The buyer did not grant itself more autonomy. The organisation decided the buyer had earned it.