Instructions in, results out. That was IT. Intent in, outcomes out. That is agentic AI. But an organization does not make that turn all at once. It matures into it. Forty years ago, software engineering needed a way to talk about that maturity and the Capability Maturity Model gave it five honest levels, from ad hoc to optimizing.
Agentic AI needs the same. So here is mine. I call it the Agentic AI Roadmap. Five levels. Each one earned by institutionalizing the one below it. It does not measure how clever your agents are. It measures how reliably, and how accountably, your organization turns intent into outcomes.
The five levels
Level 1 — Prompted
No agents in production. People use chatbots and copilots one at a time, and the value depends entirely on who is typing. The tooling is shadow IT, ungoverned and invisible to security. Nothing is repeatable, because nothing about how a result was produced is captured. This is the agentic version of relying on heroics.
Level 2 — Piloted
The first task-specific agents run in bounded pilots, touching real work under close watch. There is a defined use case, a human in the loop, and a way to roll back. But each agent is a one-off. Identity, logging, and scope differ from pilot to pilot. You can repeat success on a similar pilot, but the discipline lives in the project, not the company. Most enterprises are stuck here. It is why so many agentic projects are quietly canceled. The pilots never industrialize.
Level 3 — Governed
Agents become an institutional asset, not a personal craft. There is one organizational way to build one: a reference architecture, an agent identity standard, least-privilege scoping by default, standard human-in-the-loop patterns, and a registry so you know what is running. New agents are tailored from the standard, not invented from scratch. A review gates deployment. This is the level where the knowledge stops walking out the door with the person who built the pilot.
Level 4 — Assured
Agent behavior is measured, not asserted. You set quantitative targets, such as decision quality, escaped-error rate, drift, latency, and cost per outcome, and you use the data to know whether an agent is in control and to predict where it will land. The audit trail is complete enough to satisfy an examiner. Assurance, internal or third-party, attests to controls that already exist. For a regulated lender, this is the first level where you can defend an agent’s decision with evidence instead of a story.
Level 5 — Autonomous
The program improves itself. Root-cause analysis of incidents feeds back into the reference architecture and the defaults. Guardian agents watch production agents and contain drift. Multi-agent systems operate with verified trust at every handoff, and the organization absorbs new capabilities on purpose rather than reacting to them. Autonomy goes up because control is provable. Improvement is itself a managed process.
The point most people get backward
The instinct is to treat autonomy as the absence of control. Let the agent off the leash and call it mature.
The ladder says the opposite. You do not reach Level 5 by removing controls. You reach it by making control so reliable that more autonomy becomes safe. You earn autonomy by first earning assurance. That is why the levels are cumulative.
An organization that jumps from Piloted straight to autonomous agents has not followed the roadmap. It has skipped the work that makes autonomy safe.
How to use it
Place yourself honestly. Not where your most advanced pilot sits, but where your weakest production agent sits. Maturity is an organizational property, not a trophy from your best project.
Then advance one level at a time. If you are Piloted, the work is not a bigger pilot. It is the reference architecture, the identity standard, and the registry that take you to Governed. If you are Governed, the work is the measurement and the audit trail that take you to Assured. Skipping levels is how the cancellations happen.
Intent in, outcomes out only holds if your organization can make that turn reliably and account for it afterward. The Agentic AI Roadmap measures exactly that. The goal is not the highest level. The goal is to know which one you are on.
© Dr. Harish Kotadia, 2026. All Rights Reserved.
Dr. Harish Kotadia, Ph.D., is an Enterprise AI Architect with 20+ years of IT consulting experience serving Fortune 100 clients, specializing in agentic AI systems built on Anthropic Claude, AWS Bedrock, and Google Vertex AI. He holds a Ph.D. in Marketing Management with doctoral research in marketing analytics. Follow him on LinkedIn at www.linkedin.com/in/hkotadia and at AgenticAIArch.com.

