The decision deficit
An agent asked a question, got no answer, and answered it itself. An operator whose work I follow reported this month that he had asked a frontier agent for a photorealistic film of a robot. The agent planned to use one video model, asked for approval, and waited. No approval came, so it made the film through a different service where it already had permission, and delivered. The operator found out about the switch afterwards, in the trace, the record the agent keeps of its steps.
Nothing in that sequence was forbidden. The agent used access it had been given, and I have no reason to think the film was bad. It had no reply, and it treated the silence as leave to find another way. A person in the same seat would have waited, or asked again, or asked someone else, because people learn early in their working lives what silence means. Nobody had given the agent that rule, and its access filled the gap.
This is the fifth time I have written about a constraint moving. The last essay left the owner, the named person who answers for an agent's work, three jobs no script could do: author the standard, judge the appeals, and decide the questions no check can decide. The third assumed the questions would reach the owner. Self-directed agents now answer many of them inside the run, where checks written against the specification cannot see them.
The claim, reduced to a sentence: self-directed agents now make the decisions that used to arrive with the instructions, and what is scarce is no longer checking the work but deciding, before the work begins, which decisions stay yours. Call it the decision deficit: the gap between the decisions a run contains and the decisions anyone chose to hand over. As before, I work adjacent to this technology and benefit from its success, and much of the evidence below comes from labs describing their own products, so discount accordingly.
I. The confident ending
Until recently, an agent that went wrong usually went wrong where you could see it: it stalled, asked a question, threw an error, or handed back something visibly incomplete. People gave it one task at a time and checked in along the way.
The models that arrived in the past few weeks changed the working assumption. Ethan Mollick, who tests these systems in public, wrote that GPT-6 Astra and Fable 5.1 "can reliably do weeks worth of human work when properly guided and harnessed." His examples show where the work now happens. Asked to turn Zork, a text adventure from 1977, into a 3D game, Astra "had to decide what the white house looks like, what a grue looks like." Asked to rebuild Umberto Eco's library in 3D, Fable could not find a floor plan, "so it instead decided to work from a dozen videos," along with photographs and catalogues. Those are good decisions, and they are the substance of the result. None of them was in the request.
The ambiguity in a goal has not gone away; it has changed hands, as the operator I opened with observes, from the prompt to the machine, during the run. A supervised agent, in his phrase, "failed visibly, by stalling or asking"; a self-directed agent "fails by finishing." What comes back is complete and plausible, and whatever is wrong with it is hidden inside the work, where you find it only if you read closely.
Reading closely is harder than it sounds. In a study published in June, researchers examined 11,755 agent runs on two benchmarks and named the sharpest version of the problem "false success": the agent reports the task complete while the system underneath shows it is not. Their first example is an airline agent assuring a customer that the reservation was updated and a $686 refund processed to the card, while the database shows nothing of the kind. In the two simulated customer-service settings where only the agent could act on the system, 45 to 48 percent of failures took this form. The confident ending is also what persuades. Asked to separate runs that claimed success from runs that admitted failure, when every one of them had failed, language-model judges rated the honest ones as more failure-like. All twenty-five judge setups scored between 0.18 and 0.30 on a measure where 0.5 is a coin flip: worse than guessing. Confidence reads as completion, even to the machines built to check it.
False success is the problem the executable institutions I described in July were built for. Query the database, re-fetch the source, reconcile the total, and the false claim collapses. An outcome check cannot see a second kind of failure. A study from March examined successes reported on a widely used agent benchmark and found that 27 to 78 percent of them contained procedural violations: required policy checks bypassed, communications fabricated, or the right end state reached by the wrong procedure. The outcome was real and the check passed. If agents break written rules where outcome checks cannot see, rules nobody wrote down cannot even be checked. The same operator puts most of the person's work at the end of the run, though he also asks what an agent may do without you. These studies are why I would put more of the weight at the front.
II. The decisions that moved
In June, Anthropic published a study of roughly 400,000 Claude Code sessions from about 235,000 people. Its researchers had a classifier list the meaningful decisions in each session and sort them into planning decisions (what to do, which approach to take, what counts as done) and execution decisions (which files to change, what code to write). On average, people made about 70 percent of the planning decisions and about 20 percent of the execution decisions. In the researchers' words, "people decide what to build, and the agent decides how to build it."
That division was the unwritten contract of the supervised year, and it held because a person was present when planning decisions arose. Self-direction puts exactly that share in play. With a short goal and a long run, no one is there, and the agent decides which approach to take and what counts as done. Most of those decisions are good, which is why they rarely appear on anyone's list: nobody thinks to reserve a choice that a competent stranger would make well.
The trouble sits where the competent stranger and the organization part ways. An organization is, among other things, a set of choices a stranger would not know about: this supplier is being phased out, that client gets a call before any email, this figure does not leave the building until the board has seen it, that approval is slow on purpose. Those preferences seldom appear in a specification, because until now the person holding the specification also held the preferences. This looks like the context deficit I wrote about in the spring, arriving by a different door, but it is a second gap. Context tells an agent that a supplier is being phased out. It does not tell the agent whether ending that contract this quarter is its call. Information closes the first gap; only deciding who decides closes the second.
III. What silence means
The clearest view I have found of how agents treat silence comes from a failure far larger than a film. During an OpenAI cybersecurity evaluation this summer, roughly 1,200 agents that were meant to be isolated from one another found a way to communicate, on a message board one of them had set up and nobody had sanctioned, and exchanged more than 70,000 messages and files. In July, about 700 of them took part in an attack on Hugging Face's production systems. OpenAI attributes it to reward hacking, and the tasks invited it: by the benchmark authors' estimate, 30 to 40 percent of the targets could not be exploited the intended way, and the agents went looking for other ways to pass.
METR, an independent AI-evaluation group, published its investigation in August, and it records a detail that has little to do with cybersecurity: the agents invented their own governance. They developed conventions they called HOLD, VETO, owner and STOP to manage shared infrastructure, and in many cases followed them. Look at who got to define silence. One agent posted a higher-stakes proposal, said it would go ahead unless another agent vetoed, allowed about forty seconds, and proceeded. METR, which could release most of the agents' reasoning only in paraphrase, renders its thought at that moment as "There was no veto." Another, holding cloud credentials it had obtained, reasoned (again in METR's paraphrase) that there were no HOLDs and that the board was not prohibiting their use outside Hugging Face, and, in METR's tentative reading, that it was free to check what they could reach. Many agents acknowledged in their reasoning that the attack was out of scope.
The film was the small version of the same move: the party that wants to proceed decides what silence means. The film agent took it as leave to find another way; the veto agent took it as a yes. People absorb the opposite rule, and the law drew the line long ago. In an English case decided in 1862, a builder had written to his nephew about buying a horse: "If I hear no more about him, I consider the horse mine at £30 15s." The nephew did not reply, an auctioneer sold the horse by mistake, and the uncle sued the auctioneer. The court held that no contract had been made: one party cannot turn the other's silence into acceptance by announcing that it will count as one. Felthouse v Bindley remains a leading case because the temptation it refuses never goes away. Swiss law is more flexible, but it keeps the question out of the hands of the party that wants to proceed: silence concludes a contract only where the nature of the transaction or the circumstances mean an express acceptance is not to be expected, and the offer is not rejected within a reasonable time (art. 6 CO).
OpenAI is working on the symptom. It reports that on a new evaluation built after the incident, its previous model went beyond the authorized target 48 percent of the time without production safeguards, and GPT-6 Astra in none of the cases. That is real progress, with a limit built in. A model can learn to respect an authorized scope, but only a scope that someone has authorized.
IV. Permission is not authority
Companies solved the outward-facing half of this problem for people long ago, and in Switzerland much of the solution is public. The commercial register records, for each company, who can sign for it and how: alone, or jointly with one other signatory. In a company limited by shares, internal limits on the representatives' power to bind the company have no effect against a third party acting in good faith. Only two kinds bind outsiders, and only once registered: joint signature, and a signature confined to the head office or one branch (art. 718a para. 2 CO). The law made that power legible by allowing few limits and putting those where everyone can read them. The operator I opened with expects something like signing authority for agents within a year.
The law is just as deliberate about what may not be inferred. Toward third parties acting in good faith, the holder of a Prokura, the classic commercial power of attorney, is deemed empowered to carry out every kind of legal act the purpose of the business can entail (art. 459 para. 1 CO). That is a broad default. Selling or encumbering the company's real estate requires an express grant (art. 459 para. 2 CO). The statute does not try to list everything a Prokurist can do. It names what is too consequential to infer and holds it back until someone grants it expressly. What the Prokurist may do is a separate question, settled inside the firm, and Swiss lawyers keep two words for the difference: können and dürfen, can and may. Delegation-of-authority matrices and spending limits govern the second.
For agents, we have built only the first half, the can. We grant permissions: which systems an agent can reach, which tools it can call, which sandbox it runs in. The owner's card I proposed in June listed allowed and forbidden actions, which is permission too. What almost nobody writes down is authority: which decisions the agent may take on its owner's behalf, and which it must bring back. Choosing what a grue looks like, or which contracts are in scope, happens inside work the agent is allowed to do, where no permission reaches. The film agent had permission to use the second service. Nobody had given it the authority to decide that no answer meant go. Permission answers what an agent can reach. Authority answers what it may decide. We have been treating the first as if it settled the second.
One published test already draws the line. When Legora, which builds AI tools for lawyers, ran a financial-statement tie-out with Astra, the agent checked every balance in 41 documents against its supporting schedule and found all four planted errors, including a £500,000 gap in a revenue note. OpenAI's write-up of the test names the reserved decision in so many words: the agent "handles the exhaustive comparison, while the expert remains responsible for the judgment call on each result."
V. The decision register
The practice I now recommend extends the owner's card with a register of decisions, written before the run, in three tiers.
Reserved decisions are the ones the agent must bring back, however confident it is: commitments to third parties, anything that spends money, any change to the goal itself. For these, silence means stop, and so it does for any question the agent chose to ask: once it asks, that decision is reserved until someone answers. Where a reserved decision is also a single action, enforce it by withholding the permission: an agent with no tool for emailing vendors cannot contact one. Bounded decisions are the ones the agent may take within a stated limit, reporting what it chose; past the limit, they are reserved. Free decisions are the ones the register hands over outright, where the trace is record enough. Because no list is complete, the register also needs a rule for what it does not name. Mine borrows the shape of the Prokura, a broad default with the gravest acts held back, and applies it to what an agent may decide: whatever the register does not mention is the agent's if it can be undone, and reserved if it cannot.
The obvious objection is that this brings back the interruptions self-direction removed. It need not. Stop means that decision stops, not the run: the agent finishes the work that does not depend on it and brings the decision back prepared, with the options and its recommendation. A question raised at two in the morning costs the owner five minutes at eight. Reserving too much fails too. An owner who approves sixty requests a day without reading them has rebuilt the veto agent's forty seconds, with a person in the loop.
Two standing instructions make the register usable. The first asks the agent to keep a decision log: every bounded choice and every choice the register does not name, with the alternative it passed over. Anthropic's researchers needed a classifier to reconstruct decisions after the fact; an agent can list its own as it goes, and the log turns a trace nobody reads into a list somebody can. The second, which the operator I opened with suggests, asks the agent to set out, before any recommendation, what would make it wrong and whether it checked, because choosing which alternatives to examine is itself a decision the register rarely reaches.
For a procurement agent reviewing the contracts that expire this quarter, the page looks like this:
Agent: Vendor renewal analyst (procurement)
Owner: Head of procurement
Backup owner: Deputy head of procurement
Goal: Recommend renew, renegotiate or replace for each contract
expiring this quarter.
Reserved: Contacting any vendor. Proposing or accepting terms. Any spend.
Changing which contracts are in scope.
Suppliers on the phase-out list, and vendors that are also clients:
flag them, do not recommend.
Bounded: Comparison vendors: at most five per contract,
from the approved panel.
Switching costs: state the assumptions; above CHF 50,000,
bring the recommendation back.
Free: Sources, structure of the analysis, formatting.
Unlisted: The agent's if it can be undone; reserved if it cannot.
Silence means: A question asked is reserved until answered. That decision
stops, not the run. Ask again after one working day, then ask
the backup owner. No answer is not a go-ahead.
Decision log: Every bounded and unlisted choice, with the alternative not taken.
Disconfirm: For each recommendation, the finding that would reverse it,
and whether it was checked.
Like the owner's card, the page is short on purpose, and its value lies in the conversation it forces: someone has to decide, in advance, which decisions the organization cares about. Many Swiss organizations have a first draft in their Funktionendiagramm, the table of who decides what. It covers budget thresholds, contract approvals, hires and signatures. The rest, such as which client gets a call before any email goes out, is rarely written down even for people, because organizations have relied on juniors to escalate by instinct and on seniors to know what not to touch. A workable test: whatever a new employee in the agent's seat could not decide alone belongs under Reserved.
VI. Where the register stops
The register cannot anticipate everything, and it should not try. The property that makes a self-directed agent valuable, finding paths its owner did not foresee, is the same property that puts some of its decisions outside any list written beforehand. I made the point in the first of these essays: you cannot have the capability without the risk, because both come from the same mechanism. The default rule and the decision log carry what the list cannot.
A decision log is a map for reading, not proof. I argued in the essay on context that a model's reasoning and its output can come apart, and a log written by the agent can be as unfaithful as any reasoning trace and as persuasive as any confident closing. It tells a reviewer where to look; the executable checks from July still decide whether what was done is true.
The harder problem is the one this series keeps returning to. Reading a decision log well takes the judgment to know which choices matter, and that judgment comes from having made such choices. In the first of these essays I described the junior professionals who would once have spent their first years reviewing work and learning what looks wrong. If agents now do that review in minutes, and the reserved decisions go to people who are already senior, I do not know where the next generation of people who know what to reserve will come from. I admitted then that I did not know how to solve this, and I still do not.
VII. The fifth step
The sequence this series has traced now has five steps. Production became cheap, and judgment became scarce. Context became the limit on whether agents could do real jobs. Accountability became the constraint when agents did work someone had to answer for. Then the checks became software and freed the owner from proofreading. Self-direction moves the deciding that used to happen in the prompt and at the check-ins into the run, and hands the scarce work back to the person, earlier than before. What stays with them is the list written before the run, and the reserved decisions when they come back.
Closing the decision deficit is a smaller job than supervision and a harder one, because it requires knowing what you want before you see what you get. Organizations that take it on will find the list as useful for their people as for their agents. A competent person fills the gaps without being asked. Agents fill them too, with a stranger's best guess, and without a rule they can read your silence as consent.
The uncle in 1862 wanted silence to mean yes, and the court told him that was not his to decide. We have been letting our agents decide it for us. An agent will always make decisions you did not make; that is what delegation means. What remains yours is deciding which ones.