Should AI agents earn more autonomy over time?
A comment on my last thread made me rethink how confirmation should work in AI agents.
Someone asked:
If I’ve approved the same action 20 times, why should the agent keep asking?
That feels obvious at first.
If I repeatedly approve the same low-risk action, asking me again and again eventually stops feeling like safety.
It starts feeling like friction.
But I also don’t think the answer is simply:
“The more you approve, the more freedom the agent gets.”
Because repetition alone doesn’t mean two actions are actually equivalent.
For example:
I might approve:
“Create a reminder for me at 3 PM.”
20 times without thinking.
But that doesn’t necessarily mean I want the agent to assume it can:
move an important calendar event,
send a message on my behalf,
or create the same reminder in a very different context.
So I’m starting to think agent autonomy may need to be earned — but scoped.
Right now, the model in my head looks something like this:
1. Repetition builds trust
If a user repeatedly approves the same kind of low-risk action, the agent should probably reduce unnecessary confirmations.
2. Trust should be context-specific
“Create reminders without asking” shouldn’t automatically become “send messages without asking.”
And approving an action for one person, app, or workflow may not imply permission everywhere else.
3. Trust should decay
Something I approved every day six months ago may no longer reflect how I work today.
Past behavior matters, but maybe recent behavior should matter more.
4. Consequence should still override familiarity
Even if I’ve approved something many times, an unusually expensive, public, destructive, or hard-to-reverse version of that action should probably trigger confirmation again.
That leads me to a concept I’ve been thinking about as progressive trust:
An agent starts cautious, learns repeated patterns, earns more autonomy in specific contexts — and knows when that trust no longer applies.
To me, that feels more natural than either extreme:
Ask me about everything → safe, but exhausting.
Ask me about nothing → convenient, but terrifying.
The harder question is how an agent should decide that it has “earned” enough trust.
Is it:
number of approvals?
recency?
similarity of context?
reversibility?
confidence?
some combination of all of them?
I’m curious how other people building or using agents would want this to work.
Would you prefer to explicitly grant autonomy yourself, or would you be comfortable with an agent gradually learning when it no longer needs to ask?
And what’s one action you’d never want an agent to learn to do without confirmation?
Replies