Sign in for free: Preamble (PDF, ebook & audiobook) + Forum access + Direct purchases Sign In

Unscarcity Research

Human-in-the-Loop: Where AI Agents Must Stop

Microsoft just put AI agents on a leash. The real design question isn't whether to constrain them — it's where humans must stay in the loop, and why.

10 min read 2164 words Updated June 2026 /a/human-in-the-loop-agentic-checkpoints

Note: This is a research note supplementing the book Unscarcity, now available for purchase. These notes expand on concepts from the main text. Start here or get the book.

Where the Machine Stops: Human Checkpoints for Autonomous AI Agents

In 1909, E.M. Forster wrote a story about a civilization that handed every decision to a Machine and slowly forgot how to take any of them back. He called it The Machine Stops, and he meant it as a warning. In June 2026, Microsoft turned the title into a product roadmap.

At Build 2026 on June 2, Microsoft introduced a layer of the operating system designed to do one thing: tell an autonomous AI agent where it has to stop. One trade outlet described the effort as putting AI agents on a short leash. The centerpiece, Microsoft Execution Containers (MXC), is a policy-driven wrapper that lets a developer declare exactly what an agent may touch — which files, which networks, which credentials — and then enforces those walls at runtime. Alongside it came ASSERT, a scoring system for grading agent behavior against the rules, and Agent Control Specifications, a portable rulebook meant to travel with an agent across platforms.

Translation: the most valuable software company on Earth has decided that the governing question of enterprise AI is how much autonomy to give an agent, and where to draw the line it cannot cross alone. Deployment is assumed. The whole argument has moved to restraint.

That’s the right question. The book has an answer for where the line goes.


The Quiet Inversion: From Answering to Acting

For three years, the risk of a language model was that it might say something wrong. Embarrassing, occasionally defamatory, rarely catastrophic. You read the output, you caught the mistake, you hit delete.

Agentic AI breaks that safety net. An autonomous agent doesn’t hand you a draft and wait. It books the flight, moves the money, ships the code, closes the ticket, sends the email under your name. The 2023 chatbot produced text. The 2026 agent produces consequences. The moment software can take an action in the world, the cost of a wrong decision stops being “awkward” and starts being “irreversible.”

This is the inversion almost nobody priced in. We spent the chatbot era worrying about hallucinated facts. We’re entering an era where the danger isn’t that the agent says something false — it’s that the agent does something true to its instructions and disastrous in effect. A perfectly obedient agent told to “clean up the stale records” can empty a production database exactly as asked. Containment doesn’t save you there. The agent never left its box. It did precisely what it was permitted to do.

That’s why a leash, by itself, isn’t governance. Microsoft’s containers answer what an agent can reach. They don’t answer the harder question: which actions should a human have to sign off on, no matter how capable the agent gets?


The Real Design Question: Where, Not Whether

Strip away the vendor announcements and the enterprise debate reduces to a single axis: reversibility.

Most of what an agent does all day is reversible. A bad draft gets rewritten. A mis-sorted inbox gets re-sorted. A wrong recommendation gets ignored. For that vast majority, you want the agent running flat-out, with a human watching the dashboard rather than approving each move — what the industry calls human-on-the-loop. Demanding a signature for every reversible step would throw away the entire productivity case for agents in the first place.

But a thin slice of actions are different in kind. Wiring a payment. Deleting data. Pushing a change to a live system. Signing a contract. Sending a message the world will read as coming from a named human being. These share a property: once done, they cannot be quietly undone. For those, you want human-in-the-loop — the agent prepares the action, but a person has to approve it before it executes.

The design principle falls out cleanly: place the checkpoint at the irreversible-action threshold. Gate human approval wherever the cost of a wrong autonomous decision materially exceeds the cost of waiting for a human. Everywhere else, let the machine run. The skill is knowing which doors get a lock and which stay open.

Get this calibration wrong in either direction and you lose. Lock everything, and your “autonomous” agent is a glorified macro that pings a human every four seconds — all the oversight cost, none of the leverage. Lock nothing, and you’ve handed a tireless, literal-minded optimizer the keys to actions it can’t take back. The whole art of agent governance lives in that one judgment: which thresholds are non-delegable.


“But Checkpoints Kill the Whole Point”

Here’s the objection a good engineer raises immediately: if you make humans approve things, you’ve reintroduced the bottleneck the agent was supposed to remove. Why automate at all?

Because the checkpoint fires on a few actions, not all of them. In a well-designed system, an agent executes ten thousand reversible steps autonomously and pauses on the three that touch money or production. The human’s attention gets spent where it’s scarce and decisive: on the irreversible, the regulated, the high-consequence. That is triage — human judgment rationed to the decisions that can’t be walked back.

And the threshold isn’t fixed forever. The mature pattern is a spectrum of oversight that moves: an agent earns more autonomy as it accumulates a track record, the way a new hire graduates from “check everything with me” to “just handle it.” You start with tight checkpoints, watch the agent’s decisions against the rules, and widen the gates as confidence is earned rather than assumed. The whole discipline is calibration.

The companies that lose are the ones treating this as binary — fully manual or fully autonomous — when the real system is a dial, set per action class, adjusted over time.


The Regulators Already Decided This Is Mandatory

If the business case weren’t enough, the law is arriving to make human checkpoints non-optional for high-stakes systems. The EU AI Act reaches a major enforcement milestone in August 2026, and its high-risk provisions make demonstrable human oversight a legal requirement — you must be able to show a human can review, approve, or override the system at defined points. California’s SB-833 adds state-level oversight requirements landing July 1, 2026. “We trusted the agent” will not be a defense.

Yet the readiness gap is enormous. Deloitte’s 2026 State of AI survey found only about one in five organizations has a mature governance model for autonomous agents — even as deployment accelerates. Gartner projects that by 2029 roughly 70% of enterprises will run agentic AI inside their core operations, up from under 5% in 2025. The agents are scaling faster than the checkpoints. That gap, between what agents can do and what humans have actually agreed they may do alone, is precisely where the next decade’s worst automation failures will live.


Why This Is the Book’s Whole Argument, in Miniature

Unscarcity makes a claim that sounds abstract until a moment like this makes it concrete: governance is the rate-limiter on abundance. The machines can deliver staggering productivity. Whether that productivity becomes shared prosperity or a slow-motion loss of human agency depends entirely on which decisions we keep for ourselves. The irreversible-action checkpoint is that abstract principle compiled down to a runtime setting.

Three pieces of the framework map directly onto the agent-checkpoint problem.

AI as Referee, Humans as Conscience. The book’s governing maxim for machine authority is that AI enforces the rules; humans decide which rules exist. An agent is a superb referee — fast, consistent, untiring. But a referee should never get to rewrite the rulebook mid-game, and it should never get to make the calls that can’t be reviewed. The human checkpoint is the exact point where conscience overrides the referee. Microsoft is shipping the referee’s whistle. The book supplies the part that says some calls belong to the conscience alone.

The Right to Govern is non-delegable by design. Unscarcity splits personhood into two tiers: the Right to Exist, which everyone holds unconditionally, and the Right to Govern, which is earned and kept by humans through service. You can hand the machine your labor. You cannot hand it your accountability. An irreversible-action threshold is the engineering expression of that split — it’s the line below which a human must remain answerable for what happens next. When an agent can spend money or end a contract without a person owning the outcome, the Right to Govern has quietly been delegated to a process that cannot be held responsible. That’s the failure mode the two-tier system exists to prevent.

Power Must Decay, and truth must be seen. The book’s foundational axioms demand that no actor accumulate unchecked authority and that decisions remain auditable. Applied to agents, that’s an accountability architecture the industry is converging on independently: a named human owner for every agent, a traceable log of every consequential decision, and circuit breakers that halt a misbehaving fleet. No agent should quietly accrue more reach than the human who answers for it. Every irreversible action should leave a record a person can inspect. This is the MOSAIC pattern — distributed authority, transparent logs, the standing right to pull the plug — pushed down to the level of a single software agent.

The checkpoint, in other words, isn’t a security feature bolted onto a product. It’s a constitutional question wearing an engineer’s hard hat: which decisions must a human always own? Microsoft built the plumbing — the containers, the identities, the policy specs. Plumbing decides what’s possible. It doesn’t decide what’s right. The framework is the part that tells you where the valve goes.


The Stakes Get Higher When Agents Get Hands

So far the consequential agent lives inside enterprise software, where the worst case is a wrecked database or a wired payment. That ceiling is about to rise. The same autonomy is moving into humanoid robots — agents with bodies, operating in warehouses, hospitals, and eventually homes. When an agent’s “irreversible action” stops being a deleted record and starts being a physical act in a room with a person in it, the checkpoint stops being an IT-governance nicety and becomes a safety architecture for civilization.

This is why the question can’t wait for the labor cliff to arrive in full. The instinct to delegate everything to a capable machine is exactly the instinct Forster warned about. Abundance that nobody governs isn’t abundance — it’s just a very efficient machine running open-loop, with no one left who remembers how to stop it.

Forster’s civilization died because it forgot the Machine had an off switch, and forgot that someone had to be willing to throw it. The lesson for 2026 is to be deliberate, now, while the thresholds are still ours to set, about the decisions we refuse to automate. The machine should stop wherever a human must answer for what happens next.

Design the checkpoints on purpose, and autonomous agents become the engine of the Foundation — running the routine work of an abundant world while humans keep the decisions that define it. Skip the design, and we’ll have built Forster’s Machine on schedule, leash and all.

That choice — which decisions stay human — is the book’s entire argument, arriving early, in a runtime policy file. Read the blueprint.


Sources


Share this article: