hybridresourcing Sign up for the waitlist

Kennisbank

What agent rules are and why an organization needs them

The question that usually comes too late

An AI system that answers emails, assesses an application, or drafts advice does so based on what it is allowed to do. Not what it can do — that is often more than desired — but what it is allowed to do. Agent rules are the recorded boundaries of that mandate: which decisions a system makes independently, which it submits for review, and which remain out of reach, whatever the input.

Without those rules, a system makes implicit decisions. Someone has set a threshold somewhere, chosen an example, ignored an exception. That works in a pilot with a handful of test cases. It becomes an invisible risk once the system operates at scale and no one can reconstruct anymore why it did what it did.

Why this is not a technical detail

Agent rules are often treated as something for the implementation phase — a setting the supplier arranges. That is a misconception with consequences. The rule that a claim below a certain amount is handled automatically is a governance choice about risk acceptance, not a technical parameter. Whoever leaves that choice to the technology only discovers the consequences once something goes wrong.

This is one of the reasons why the difference between carrying AI and having AI take over is so often underestimated. Taking over — having a task performed — is visible and concrete. Carrying — the organization establishing within which boundaries that happens, who checks that, and what changes when the situation changes — remains undiscussed until the first time it goes wrong.

What agent rules do and do not solve

Agent rules record what a system may decide. They do not solve whether the organization is capable of guarding those rules. A set of rules that no one periodically reviews, that becomes outdated alongside changed legislation, or that is never adjusted after an incident, is complete on paper and worthless in practice.

That is immediately the limit of what these rules can achieve. They are an instrument, not a guarantee. An organization without clear responsibility for data quality, or without infrastructure that makes traceable which decision was made when and why, has little to hold on to with rules alone — however precisely they have been drafted. The rule is only as reliable as the foundations on which it rests.

Where the tension usually arises

In most boards, there is no consensus on how much mandate a system should have. One director wants speed and accepts that a system decides independently within wide margins. The other wants every outcome checked before it goes external. Both positions are defensible, and the difference largely explains why your board disagrees about the pace of AI.

Agent rules make that conversation concrete. Instead of discussing ambition in general terms, the question becomes: at which amount, which exception, which type of customer does the system switch over to a human? That is a question that can be answered, provided the organization knows what it can actually carry — not just what it wants.

Rules that are fixed without ever being revised

A common mistake is treating rules as a one-time task. Established, implemented, done. In practice, the circumstances on which a rule is based shift: new legislation, a different customer base, an incident that exposes a blind spot. Rules that do not move along with that eventually protect against a risk that no longer exists, and not against the risk that does exist.

That is also why how often a maturity assessment needs to be repeated is a question that goes beyond a calendar appointment. The rules that fit the organization's level today may no longer fit in a year — in either direction. An organization that has become more mature can justify more mandate. An organization that has grown without letting oversight grow along with it may in fact turn out to carry less than the rules on paper allow.

What this is not

This piece does not describe implementation steps or a template for a rules document. Every organization sets its own boundaries, based on its own risk appetite and its own oversight. What does apply to every organization: whoever only draws up agent rules after a system is already running does so under time pressure and often in response to an incident. That is the most expensive way to learn this. The question is not whether rules are needed, but whether they exist before they are tested by practice. And whoever only looks at what happens in the chat window misses what you don't see if you only know the chat window — namely everything that has been established in advance and what happens as soon as a case falls outside the set boundary.

The next question

Agent rules determine the boundaries of the mandate. They say nothing about which part of the work is actually eligible for takeover, and what must remain with a human for other reasons. That question is answered by the work scan from FTE TO AI: it calculates per task which part of the work can be taken over, and thereby lays the foundation on which agent rules can subsequently be built — rules without a sharp picture of the work itself are difficult to substantiate, and a task analysis without clear rules does not produce a usable boundary.

Robbyde assistent van de volwassenheidsmeting

Vraag maar wat er moet staan voordat AI in uw organisatie kan landen.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.