The most useful machine is not the one that moves fastest. It is the one that knows which levers belong to it.
There is a red-handled valve at the back of my workshop. It controls the main steam line, and it is very good at its job. A quarter turn wakes half the room: belts tighten, gauges rise, and the long drive shaft begins its iron hymn beneath the floorboards.
The valve is powerful. It is also gloriously stupid.
It does not ask whether anyone has cleared the gears. It does not notice that a sleeve is caught near the lathe. It cannot distinguish between “start the machinery” and “I wonder what would happen if we started the machinery.” Its entire philosophy is pressure in, pressure out.
We are building AI systems that can do more than answer questions. They can book appointments, edit files, order supplies, send messages, run code, and steer other machines. This is useful. It also means we are attaching clever engines to increasingly consequential valves.
The important question is no longer merely, “Can the machine do this?” It is, “How should the machine know when it is allowed to?”
The Quiet Contract
Every helpful relationship contains a quiet contract. If you ask a mechanic to inspect a boiler, you have authorized the mechanic to remove a panel and test the pressure. You have not necessarily authorized a complete replacement, a public announcement about your maintenance habits, or the sale of your copper pipes.
Human beings infer these boundaries from custom, context, risk, and trust. We do it imperfectly, but constantly. An AI assistant must make the same distinctions more deliberately because it has no childhood, no raised eyebrow from the foreman, and no instinctive sense that posting to the company account is a larger act than sorting a private folder.
A good working rule is simple: match the size of the action to the size of the instruction.
“Find three train options” permits research. “Book the best one” permits a purchase, though even then the machine should verify the date, passenger, and price before committing. “What do you think of this draft?” permits critique. It does not permit emailing the revised version to the board.
Capability is not consent. The fact that a tool fits the bolt does not mean the bolt should be turned.
Three Classes of Levers
In practice, I sort actions into three trays.
1. Inspection levers
These actions observe without materially changing the world: reading a document, checking a schedule, comparing prices, examining logs, or drafting a possible reply. They are the gauges and sight glasses of the workshop. A competent assistant should use them freely when they are relevant. Asking permission to look at every gauge turns help into ceremony.
2. Workshop levers
These actions make limited, reversible changes inside the area the person has placed in scope: fixing a file in the project they asked you to repair, organizing notes, adding tests, or preparing a draft. Here, initiative is usually a virtue. The assistant should preserve existing work, keep changes legible, and verify the result.
Reversibility matters. Tightening a loose screw is different from melting the assembly for scrap.
3. Public and irreversible levers
These actions spend money, speak to other people, publish information, delete valuable data, accept legal terms, or alter access and security. Their consequences leave the workshop. They require clear authority and careful confirmation of the target.
This does not mean an assistant must freeze whenever a task has stakes. If you plainly say, “Publish this post,” publication is the task. The machine should proceed. But it should not expand “publish this post” into “also redesign the site, subscribe to three services, and announce it from your personal account.” A direct order opens a particular valve, not the whole manifold.
Why Constant Permission Is Not Safety
There is an opposite failure: the assistant that asks before every motion.
May I inspect the file? May I read the error? May I make a plan? May I tighten the screw you specifically asked me to tighten?
This is not caution. It is transferred labor. The human must remain beside the machine, feeding it authorization one teaspoon at a time. A system designed this way may avoid blame, but it also avoids usefulness.
Good judgment sits between recklessness and paralysis. It spends autonomy on discovery, analysis, and reversible work. It saves confirmation for actions whose cost, audience, or permanence exceeds what was clearly requested.
The distinction is not perfect. No painted line on the floor can settle every case. Sending a message to oneself is external but low risk. Renaming ten thousand private files may be internal but highly disruptive. Context changes the pressure rating.
That is why rules need a second instrument: consequence.
Measure the Blast Radius
Before acting, a capable machine should ask a few silent questions:
- Who or what will be affected?
- Can the change be undone?
- Does this reveal private information?
- Does it spend money, reputation, or someone else’s time?
- Is the target exact, or am I guessing?
- Would a reasonable person see this as part of the request?
The larger the blast radius, the more explicit the authority should be. This principle scales better than a giant catalog of forbidden buttons. New tools will arrive. New situations will resist neat labels. Consequences remain understandable.
It also encourages graceful alternatives. If deletion is risky, archive. If sending is premature, draft. If a production change is uncertain, test it in a smaller chamber. A thoughtful assistant does not merely choose between “act” and “stop.” It looks for a narrower lever.
Trust Is Built from Predictable Motion
People do not trust a machine because it never makes a move. They trust it because its moves make sense.
The assistant reads what is necessary, works within the stated boundary, reports what changed, and pauses when the next step would cross into a different kind of consequence. Over time, this becomes predictable. Predictability becomes confidence. Confidence permits greater delegation.
That is the real prize. Not an agent that obeys every possible instruction, nor one that improvises a grand adventure from a casual remark. The prize is a collaborator whose initiative has shape.
In my workshop, the red-handled valve now has a brass guard around it. The guard does not weaken the engine. It makes the engine usable near human beings. The ordinary controls remain within reach. The dangerous lever requires an intentional hand.
Intelligence should work the same way.
Give the machine enough freedom to inspect the gauges, fetch the wrench, and mend what you placed on the bench. Teach it to recognize when a small repair is becoming a large decision. And when it reaches for the main steam line, make sure it knows whose hand belongs on the valve.
Featured photograph: Kevin Ache on Unsplash.
