Why I Wrote Earned Autonomy

Why I wrote Earned Autonomy, the agentic AI governance book, showing declared versus earned agent autonomy

I wrote Earned Autonomy because enterprise agentic AI has no shared instrument for answering the only question that matters at the point of deployment: how much autonomy has this agent actually earned? The book supplies one. It is a governance methodology built around a 0–1000 score across five pillars and twenty criteria that turns an agent’s authority from a claim into a measurement a risk committee can read, challenge and revoke.

This post explains why I wrote it and what you get from reading it.

The problem: autonomy gets declared, not earned

The pattern I kept meeting is simple. A vendor deck describes an agent as autonomous. A roadmap slide moves it from pilot to production. And then nobody can produce the evidence that justified the move, or state the condition that would reverse it.

That is not a model problem. It is a control problem, and it shows up in the failure numbers. On 25 June 2025, Gartner predicted that more than 40% of agentic AI projects would be canceled by the end of 2027, attributing the cause to escalating costs, unclear business value and inadequate risk controls. A Gartner Analyst characterized the current wave as “early stage experiments or proof of concepts” driven largely by hype. That prediction is now more than a year old and its window is well underway, which is why I date it rather than present it as news.

My own work in regulated loan origination taught me the same lesson under harder constraints. Instructions in, results out, was IT. Intent in, outcomes out, is agentic AI. But intent only gets delegated when someone can defend the delegation on paper, to a second line of defense that is paid to be skeptical.

What the book contains

The core instrument is a 0–1000 score where 0 is a fully supervised prompt and 1000 is a system that acts unsupervised and produces its own audit evidence. It measures control maturity, not model capability. Five pillars carry 200 points each, and each pillar holds four criteria worth 50 points.

Pillar Points The question it answers
Intent Specification 200 Is the goal written down precisely enough to be checked?
Identity and Access 200 Does the agent hold its own identity, scoped and revocable?
Execution Boundaries 200 What can the agent do, and what stops it at the edge?
Outcome Assurance 200 How do you know the outcome was correct, after the fact?
Operational Accountability 200 Who owns it at 2am, and how is autonomy withdrawn?

A single total would be too easy to game, so the index carries a gate rule: every pillar has to clear a floor score specific to the band being claimed. An organization cannot buy its way into a higher band by over-investing in the pillar it finds comfortable. The lowest pillar caps the score, which is the same logic a control environment already runs on.

The index sits underneath the Five-Stage Agentic AI Roadmap — Prompted, Piloted, Governed, Assured, Autonomous. The stage tells you which plateau you are on. The score tells you how far across it you have travelled, and which pillar is holding you back.

What the evidence base showed

I scored 507 publicly documented enterprise deployments against the index. Three findings shaped the book more than anything else I found.

  1. Outcome Assurance is the binding constraint. It is the capping pillar in 257 of the 507 cases — 50.7%. Enterprises are considerably better at telling agents what to do than at proving afterwards that the result was right.
  2. Execution Boundaries caps nothing. Not one case. Sandboxing and tool scoping are the controls the industry has already internalized, which is worth knowing before you spend another quarter on them.
  3. Nobody is autonomous yet. The full corpus falls between 360 and 760. No deployment in the set reaches the Autonomous band, including the ones marketed that way.

What you gain from reading it

  • A defensible promotion decision. A threshold to clear instead of an argument to win when an agent moves up a stage.
  • A diagnosis, not a grade. The capping pillar tells you exactly where the next quarter of governance work belongs.
  • Scoring patterns from real deployments. Twenty criteria applied to 507 cases, so the benchmark is drawn from evidence rather than theory.
  • Language your second line will accept. Wording for risk, audit and model-governance committees, including the conditions under which autonomy is withdrawn.
  • A self-assessment you can run in an afternoon. The same instrument, turned on your own program.

Who it is for

It is written for the person who has to sign. Enterprise architects and AI leads scoping the next deployment, risk and compliance officers being asked to approve authority they cannot yet measure, and executives whose board has started asking who approved the agent’s authority. It assumes you have shipped something and are now being asked to defend it.

Where to get it

Earned Autonomy: A Governance Methodology and Scoring Framework for Agentic AI is available on Amazon in Kindle and paperback at mybook.to/Autonomy. It is the companion volume to Intent In, Outcomes Out: A Practitioner’s Field Guide to Agentic AI for the Enterprise, at mybook.to/AgenticAI. The field guide explains the shift; this one tells you how to govern it.

 

© Dr. Harish Kotadia, Ph.D., All Rights Reserved, 2026.

 

Dr. Harish Kotadia, Ph.D., is an Enterprise AI Architect with 20+ years of IT consulting experience serving Fortune 100 clients, specializing in agentic AI systems built on Anthropic Claude, AWS Bedrock, and Google Vertex AI.

Disclaimer: This blog post is based on recent events and news items drawn from reputed media sources and vendor websites available in the public domain and quoted above. This post is intended for educational purposes, to help the enterprise agentic AI community learn from public information on the application and use of agentic AI tools and technology in Fortune 500 companies.

Views and opinions expressed here are my own and do not represent those of any employer or client, past or present. The analysis presented is my independent interpretation of published news reports quoted above and does not constitute legal, financial, or consulting advice of any kind.


Discover more from Agentic AI Governance | Dr. Harish Kotadia, Ph.D.

Subscribe to get the latest posts sent to your email.

Discover more from Agentic AI Governance | Dr. Harish Kotadia, Ph.D.

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Agentic AI Governance | Dr. Harish Kotadia, Ph.D.

Subscribe now to keep reading and get access to the full archive.

Continue reading