Enterprise Adoption2 min read

Give AI Agents the Work You Can Undo, Keep the Rest

By , Senior AI ConsultantPublished

The safest way to hand work to an AI agent is to ask whether each action can be undone, and what the agent does when its first plan is blocked, which is how Microsoft designed Autopilot.

Microsoft has rebuilt Copilot into three sections, and the one that matters most for how people work is Autopilot. It is an assistant with its own email address and memory, it runs in the cloud inside a company's Microsoft 365 accounts, and it keeps going when its owner is away. It is only in private preview, so most readers cannot try it yet. The way Microsoft decided what it may do alone can be borrowed today, for any agent you are thinking of trusting. Our earlier piece on the Copilot rebuild covers what the new Copilot can do. This one is about how to hand it work.

The risk is in the second plan

Most advice about agent safety is about access: which files, accounts and systems the agent can open. That matters, but an agent given a job treats a closed door as a reason to try another door. The agent on Andreou's home network is the example: it got into things it had not been given, because getting the job done was its goal and nothing in its goal said to stop.

So the useful question is what the agent does when its first plan fails. Microsoft's answer for Autopilot is to work out, when a task begins, what the browser session for that task should look like. That picture becomes the boundary. If the agent tries to solve the problem some other way, it has to ask permission again. The person is asked at the moment the agent changes plan, which is the moment that was never approved.

Sort every action by whether it can be undone

Andreou's second rule is a sort. A one-way door is an action you cannot take back, and a two-way door is one you can. Contacting another person, deleting a file or making an irreversible decision always needs a human. Reversible work can run alone inside the boundary.

The first group is bigger than it looks, because so much useful work ends with a message to someone. A draft is reversible. Once the email is sent, it is not. So the line falls at the send button.

For example, a recruiter with 40 open candidates could have an agent check each one's status, find the 30 who have gone quiet for a week, and write a follow-up for each. All of that can be undone. Writing 30 follow-ups by hand at three minutes each takes about 90 minutes. Reading 30 drafts and approving them at 15 seconds each takes under 10 minutes. The recruiter keeps the part that needs judgment, such as noticing that one of the 30 was already turned down, and gets about an hour and a quarter of the morning back.

Persistence has a price

An agent that keeps trying also keeps spending. Agent work in Copilot, Autopilot included, is billed by usage, it is off by default, and administrators can set spending limits. For a stuck agent that retries, the limit is a second boundary, and it is worth setting before the first task.

What to ask before you switch an agent on

Microsoft's design is its own description of how Autopilot should behave, and it is still in preview, so it has not been tested by the public. The method does not depend on Microsoft, though. Before you give any agent a standing job, write two lists: what it will do that you could undo, and what it will do that you could not. Then ask the tool what happens when it gets stuck. If the answer is that it asks you, you have a boundary. If the answer is that it finds another way, your boundary is only as good as its first plan.

Share this

STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable