The map: who decides, who acts, and how far the system goes on its own
The first series drew an agent platform, layer by layer. It never said when you need one. This series answers the question a business reader asks first: which kind of AI system does this job call for? The names on the slides will not tell you. Two questions will: who decides, and who acts. Eight families then fall into place, and the gaps between them show.
HokonokenSeptember 2026Reading time: 14 minNot legal advice · Views are my own, not my employer's
Three things to take away
Sort systems by who decides and who acts, not by the word on the slide. A model that emits a score, a model that writes text a person reads, and a model that picks actions inside a system are three regimes of responsibility, whatever they are called that quarter.
"Agentic" is not a higher level, it is a different regime. Each step down the map moves the risk: from the quality of a prediction, to the content a person reads, to the sources a system may read, to the actions it takes. The controls change kind, not size.
The law reads the autonomy axis. The AI Act defines an AI system by its "varying levels of autonomy" and its output types; its oversight article asks for a person who can override or stop; Swiss data-protection law gives a right to a human review of a decision "based exclusively on automated processing". Where a job sits on the map decides which of those apply, and a logistic regression can sit higher than a frontier model.
Why not the names on the slide
Five names come up in every deck: predictive AI, generative AI, RAG, AI agent, agentic AI. They do not belong to the same list. One is a model class (generative), one is a technique (retrieval-augmented generation), two are deployment patterns (agent, agentic), and the first is everything that was called machine learning until 2022. Sorting a job by which of those five it "is" tells you what the vendor sells. It does not tell you what the job needs.
Two questions do. Who decides: what produces the output that matters? A trained model emitting a score. A language model emitting text. A language model choosing the next action. An orchestrator splitting a goal between agents. Who acts: who turns that output into an effect on the world? A person. A business rule. The system itself, inside a perimeter. Several systems, across a process.
The law already sorts this way. The AI Act's definition of an AI system, Article 3(1), is a machine-based system "designed to operate with varying levels of autonomy" that "infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments". Four output types and an autonomy dial: that is the map, in one sentence, written in 2024. The word "agent" does not appear in Article 3 at all.
Add three axes and the picture becomes usable. Autonomy, from a system that informs to one that delegates. Reversibility of the worst action: reading, writing a record, or committing something that cannot be quietly undone, like moving money, sending a letter, revoking a benefit. Freshness of the data the system reasons from: a training run, an index, or the live system. And, to tie this series to the first one, the layer of the platform that carries the risk for each family.
Eight families
no language modelcontent, a person readsyour sources, a person readsactions in systemsAutonomy 1 informs · 2 proposes · 3 acts under approval · 4 acts, reviewed after · 5 delegatesWorst action: read nothing changes · write a record changes, can be reversed · commit money, letters, rights; reversal is a new action
The map. Eight families, sorted by who decides and who acts. The autonomy cells show the range the later parts place jobs at: a predictive model wired to an automatic refusal sits at 4 with no language model in sight, and an agent that only reads, but chooses its reads, sits at 4 too. The last column names the layer of the platform from the first series that carries the risk, and the part where it is described. Levels are a working scale of mine, not a standard; see the note below. Colours group the families by what a failure damages first.
Two of the eight rows contain no language model. They run more of the world's AI than the other six combined, and they are the ones nobody calls AI at the budget meeting. Part 2 is theirs. The two content rows are where a person still reads everything before it leaves; the model writes, the human signs. The sources row is where the model reads what you own, and the risk becomes who was allowed to see which document. The three action rows are where the first series lives: the model, or a process around it, changes something in a system.
Three families from the usual lists are folded in rather than given a row. Small specialised models, fine-tuned for classification, extraction or routing, are a size choice, not a regime: they sit wherever the job they do sits, and they are often the right tool where a general model is used by reflex. Recommendation systems are the most deployed predictive case and share its row. Agentic RAG and graph RAG share the sources row, with one caveat the cell shows: once the model decides what to fetch, where and how many times, retrieval has become an action, and the governance changes with it. Part 4 takes that apart.
The autonomy scale, and why it is mine
There is no recognised standard for levels of autonomy in AI systems. The AI Act uses the phrase and does not grade it. So this series uses a working scale of five levels, borrowed in spirit from the way road vehicles are graded: SAE J3016 places a car at a level by asking who is driving, the person or the system, not by how good its sensors are. Same here. What places a system high is not the size of its model but who acts on the output.
1 · INFORMSEmits a score, a label, a rank. A person or a rule decides and acts.
2 · PROPOSESDrafts content, an answer or a proposal. A person reads it before anyone acts on it.
3 · ACTS UNDER APPROVALActs on its own, except that listed actions wait for a person.
4 · ACTS, REVIEWED AFTERActs on its own; a person can read the record, override it and stop it.
5 · DELEGATESSets sub-goals and hands them to other agents. People set the goal and the boundaries.
The scale says nothing about model quality, and that is the point. A credit-scoring model from 2015, wired so that a score below a threshold refuses the application without anyone looking, is at level 4. A frontier model drafting emails that a person sends is at level 2. If your governance effort follows the model's sophistication, it is on the wrong row.
Reading the map: three lines that matter
The autonomy line is the one the regulator reads. Article 14(4) of the AI Act asks that the person overseeing a high-risk system can "decide, in any particular situation, not to use" it, "disregard, override or reverse the output", and "intervene in the operation … or interrupt the system through a 'stop' button or a similar procedure". Every one of those verbs assumes a system that acts, or a decision that stands, without the person. At level 1 they are trivially met: the person is the one deciding. At level 4 they need a surface that exists, and the first series found that surface missing in every open component it read. The same article, 14(4)(b), names "automation bias", the "tendency of automatically relying or over-relying on the output". That clause is written for level 2: the copilot whose proposals get accepted by habit. Swiss law adds a third marker, Article 21 FADP: a decision "based exclusively on automated processing" with legal or considerable effect gives the person a right to have it reviewed by a natural person. "Exclusively" is a line between level 1 and level 4, and nothing in it mentions a language model.
The reversibility line fixes where the approval goes. A read changes nothing. A write changes a record that can be changed back. A commit moves money, sends a letter, revokes a right; reversal is a new action with its own consequences. The approval a person gives belongs at the commit, not at the family: a generative system that publishes directly is a commit, an agent that only reads is not. The Model Context Protocol, the interface through which most agents reach their tools, states it as a principle: "hosts must obtain explicit user consent before invoking any tool", and adds that "MCP itself cannot enforce these security principles at the protocol level". Part 4 of the first series showed one way to enforce them per action; this series will only ask, for each family, which actions are commits.
The freshness line decides which failure you will see. A system reasoning from a training run fails by drift: the world moved, the model did not, and the failure is silent until someone measures it. A system reasoning from an index fails by confidence: it answers about last quarter's policy in the present tense, with a citation. A system reasoning from live data fails in the system itself, immediately, and the record of the failure is the record of the action. The monitoring the first series described in part 5 is a different job on each line.
Three jobs on the map
The same job can be placed on several rows. That is the most useful thing the map does, because the placement, not the technology, is what the law and the platform respond to. Three organisations, none of them real, each with a job that moves.
Job
Family, level
Worst action
What the platform must provide
Regulatory line
A public agency assesses eligibility for a benefit. Placed as a score shown to a caseworker.
Predictive, 1
commit, by the caseworker
Model registry, drift monitoring, an inventory entry with a risk class (S1 part 3, 5).
Annex III 5(a) names systems used "to evaluate the eligibility of natural persons for essential public assistance benefits" as high-risk. Article 6(3) can lift that for a "narrow procedural task" or a "preparatory task", never where the system "performs profiling of natural persons". High-risk obligations apply from 2 December 2027.
The same agency. Placed as a copilot that drafts the decision letter from the case file.
Integrated copilot, 2
write; commit when the officer signs
The case-management tool's own permissions; a record of what the model proposed and what the officer changed (S1 part 5).
Same Annex III row: the text also covers systems used "to grant, reduce, revoke, or reclaim such benefits". Article 14(4)(b) on automation bias is the clause to design for. Article 50(1) if the letter is generated in a conversation with the applicant.
The same agency. Placed as an agent that grants, adjusts and notifies within rules.
AI agent, 4
commit
MCP gateway, agent identity, per-action policy, an approval surface, records kept six months (S1 parts 1, 4, 5).
Annex III 5(a), no exemption in reach. Article 14 in full: a person with authority to stop it. Article 21 FADP for a Swiss agency: a right to human review of the decision.
A bank scores credit applications. Placed as a score that decides automatically below a threshold.
Predictive, 4
commit
Model registry, performance and bias tests with metrics fixed in advance, an independent review, fallback (S1 part 3, FINMA 08/2024).
Annex III 5(b): "creditworthiness of natural persons", high-risk. The same point excludes systems "used for the purpose of detecting financial fraud": the fraud model next door, same technique, is not on the list.
The same bank answers customers about their own statements in a chat.
Answering on your documents, 2
read; a disclosure is the risk
Vector store access control tied to the customer's identity, citation of the passage used, an index refresh policy (S1 part 1, 5).
Not an Annex III row. Article 50(1), in force since 2 August 2026: the customer is told they are talking to an AI. FADP Articles 7 and 8 on protection by design and data security.
The same bank reconciles supplier invoices with an agent that posts matched entries.
AI agent, 3
write; commit at payment
Per-action policy with the payment step as the approval point, identity, records (S1 part 4).
Not an Annex III row. NIS2 Article 21(2) binds the bank as an entity: access control, supply chain, incident handling; the agent's tools and model are part of that supply chain.
A manufacturer predicts machine failures from sensor data. A planner schedules the maintenance.
Predictive, 1
read
Model registry, drift monitoring against live telemetry (S1 part 5, 6).
Outside Annex III. Annex I only if the model is a safety component of a regulated product, a definition Regulation 2026/1744 narrowed in July 2026.
The same manufacturer gives technicians an assistant over the maintenance manuals.
Answering on your documents, 2
read; a wrong procedure is the risk
Ingestion with document versions, citation of the manual page, index refresh on every revision (S1 part 5).
Outside Annex III. Product-safety and workplace rules apply to the procedure itself; the AI Act adds Article 50(1) disclosure.
The same manufacturer lets an agent order spare parts up to a ceiling.
AI agent, 4
commit
Per-action policy with the ceiling as a rule, approval above it, an audit record per order (S1 part 4).
Outside Annex III. NIS2 if the manufacturer is an essential or important entity. Contract law does the rest, which is why the ceiling is a rule and not a prompt.
Read the table by column and the pattern is plain. The regulatory line depends on the job and its placement, not on the family: the same benefit assessment is high-risk at level 1 and at level 4, and the same predictive technique is high-risk for credit and unlisted for fraud. The platform column, on the other hand, depends almost entirely on the family. That split is the reason this series exists: the business reader can find their job in the first column and the lawyer's answer in the last; the platform reader can find the family and the layer it needs.
What the map does not say
It does not say which family is better. A level 1 model that has run a factory's maintenance for six years is not a lesser thing than an agent demo. It does not say what a family costs, in money or in people; the first series had a part on that and this one will not repeat it. It does not place any product: a vendor's "agent" is wherever its answers to the two questions put it, and the same product is often sold at one row and deployed at another. And it does not say that jobs stay put. The realistic path for an administration or a bank is not to replace a process with an agent but to let a model into one step of it, keep the engine in control, and move the step to an agent when the records show it is safe. That path is the augmented workflow row, and part 5 is about it.
One question carries into the next part. Two rows of the map contain no language model, run at level 1 most of the time, and can still reach level 4 with nobody noticing, because the wiring, not the model, moved them there. If a model that only emits a score can already sit where the oversight article bites, what exactly does the platform owe it? That is part 2.
Next in the series
Part 2AI without a language model: prediction, recommendation, perception, optimisation. What already runs everywhere, and why it is not "less" than the rest.
Part 3Generating and assisting: generative AI, integrated copilots, small specialised models. The person reads, the risk is the content.
Part 4Answering on your own documents: RAG, agentic RAG, graph RAG. The risk becomes access to sources, and freshness.
Part 5Acting within a perimeter: the AI agent with its tools, and the augmented workflow as the migration path. The risk is the action; the perimeter is outside the model.
Part 6Pursuing a goal with several agents: agentic AI, delegation, intent. The most demanding regime, and the one sold first.
This article is an engineer's reading of public legal texts and public code, checked against the versions and dates given below. It is not legal advice. For a real deployment, read the texts with counsel and with your supervisor's guidance for your sector.
Read, not run. Everything in this series comes from reading public documents and public code at a stated date, not from running them in production. Treat it as a map to test, not a result to trust: the texts are amended, the projects move monthly, and a placement that is right for one organisation's wiring is wrong for another's. Place your own jobs on the map with the people who own them. When something here does not match what you find, tell me, or better, tell the project or the authority concerned: that is the only way a map like this one stays true.
Sources
Regulation (EU) 2024/1689 (AI Act), Article 3(1), Article 6(2) and (3), Article 14, Article 50, Annex III point 5; texts read on artificialintelligenceact.eu on 23 September 2026. Application dates as amended by Regulation (EU) 2026/1744, read in part 3 of the first series.
Federal Act on Data Protection (FADP, SR 235.1), Fedlex, English translation, Articles 7, 8 and 21; Directive (EU) 2022/2555 (NIS2), Article 21(2); FINMA Guidance 08/2024, sections 2.2 to 2.7. All as read for part 3 of the first series, 22 September 2026.
Building effective agents, Anthropic, 19 December 2024: the distinction between workflows, "where LLMs and tools are orchestrated through predefined code paths", and agents, "where LLMs dynamically direct their own processes and tool usage". The augmented-workflow and agent rows follow that line.
Model Context Protocol specification, revision 2025-06-18, section "Security and Trust & Safety", read 23 September 2026; the current revision, 2026-07-28, keeps the sentences quoted here unchanged (see part 5).
SAE J3016_202104, Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicles, April 2021, used as an analogy only; its level definitions are not reproduced here.
Agent stack blueprint, the first series, parts 1, 3, 4 and 5, for the platform layers named in the last column of the map.
Independent work, not affiliated with any regulator, court, standards body, foundation or vendor named. Not legal advice. Product names belong to their owners. Views are my own and do not represent the position of my employer. Text and diagrams: CC BY 4.0; quoted code and documents stay under their own licences.