Next week's work rota can look like an ordinary timetable. Yet one recommended schedule may decide who loses hours, who rearranges care, and whose explanation a manager ever sees. The machine need not hold legal authority. The institution can still organise itself around what the machine said.

The recommendation in next week's rota

A worker tells a manager that they cannot work after four on Thursday because they collect a child from school. They can cover Friday instead. A scheduling assistant reads everyone's availability, predicts demand, and proposes a rota in seconds.

The recommendation solves a genuine problem. A manager balancing twenty people's hours may overlook constraints, repeat familiar patterns, or spend an afternoon moving names between boxes. A well-designed system can see conflicts earlier and distribute unpopular shifts more consistently.

Now imagine that the proposed rota gives the worker fewer hours. The manager sees a green “recommended” schedule, while the availability note sits behind another screen. Accepting takes one click; changing the rota requires an explanation because it lowers an efficiency score.

The assistant did not hire, dismiss, or formally command anyone. The manager approved the rota. Yet the recommendation organised what the manager saw, which option appeared normal, and whose circumstances required special justification. A suggestion became part of an institutional act.

No dramatic malfunction is required. The system can work exactly as designed and still leave a serious question unanswered: when did useful scheduling assistance acquire practical authority over someone's time and income?

That question travels beyond the workplace. A recommendation can become a medical priority, a payment check, a university intervention, an insurance category, or an investigation. Accuracy and safety matter, but they do not reveal how an output entered the workflow or acquired force.

The deeper question is: which capability may be delegated, to whom, for which purpose, under whose authority, and with what remedy when it produces a consequence?

Carry this forward

A recommendation becomes powerful when following it is ordinary and questioning it becomes exceptional.

Why institutions delegate

There are good reasons to place AI inside institutional work.

A system can retrieve material that a worker would struggle to find, translate across languages, identify routine inconsistencies, prepare a first draft, or help a person navigate a process that was already confusing. In an overstretched organisation, it can reduce waiting and return scarce attention to cases that need judgment.

Consistency can also be valuable. Similar cases should not receive radically different treatment merely because one worker is hurried, another is experienced, and a third never saw the relevant document.

Refusing automation has consequences too: delay, administrative burden, inaccessible services, and decisions made with incomplete information. The serious argument is not between technology and humanity. It is about where each contribution is useful and where its limits become institutionally important.

A system that drafts a message is not equivalent to one that sends it. A system that displays a balance is not equivalent to one that transfers money. A system that proposes an appointment is not equivalent to one that changes a medical record.

The benefit grows with capability. So does the need to specify the boundary.

Where assistance becomes power

The difficult transition rarely arrives with a formal announcement that the machine now has authority.

It appears through defaults. The recommendation is placed first. The supporting record takes longer to open. A worker must justify disagreement but not agreement. A target rewards speed. An appeal begins from the machine-produced category rather than from the person’s original situation.

The system remains “advisory” in policy. In practice, it organises attention, narrows the available reasons, and determines what must be disproved.

This is institutional power without formal delegation. It does not arise from intelligence alone. It arises from the relationship between a technical output and an organisation prepared to rely upon it.

The institution cannot answer this problem by pointing to the vendor, the model, or the final human signature. It must explain the complete route by which a contribution became consequential.

Capability is not authority

AI debates often place capability, autonomy, permission, and authority on one ladder. A system becomes more capable, then more autonomous, then somehow more authoritative.

But these are different questions.

  • Capability asks what the configured system can reliably do.
  • Permission asks which resources and actions technical controls make available.
  • Mandate asks which function a competent institution has validly assigned.
  • Reliance asks whether a person or workflow actually treats the contribution as an operative premise.
  • Commitment asks which record, communication, allocation, transaction, or state change follows.
  • Consequence asks whose treatment, options, rights, or burdens change.

An assistant can possess a technical permission without a valid institutional mandate. It can hold a valid mandate that nobody uses. It can be officially “advisory” while people routinely accept its recommendation because the interface, time pressure, or organisational target makes disagreement exceptional.

The categories are connected. They are not interchangeable.

This changes the object of governance. It is not “AI” in general. It is a dated configuration with a specified capability, permission, recipient, purpose, workflow, consequence, and control.

A human signature is not always human control

Imagine that an assistant recommends which insurance document a person should submit. The recommendation is easy to inspect and carries no direct institutional effect. Now imagine that the assistant completes the application, selects the category, and sends it. The model may be identical. The institutional position is not.

Now change the workflow again. A human must confirm the submission, but the screen shows only the assistant’s summary. Opening the source document takes several steps. Rejecting the category requires an explanation. Human confirmation remains formally present while practical reliance has moved elsewhere.

This is why “human in the loop” is not a complete safeguard. The question is whether the person can understand the contribution, inspect its basis, reasonably disagree, interrupt the action, and repair the result.

Human review can also become theatre. Repeated prompts encourage automatic approval. Excessive confirmation can make systems harder to use without making them safer. Meaningful control requires friction proportionate to consequence, not a ritual click attached to every action.

Try the distinction

What would make the manager's click meaningful?

Look beyond whether a person was formally present and inspect the conditions under which judgment was possible.

  1. Visibility: Could the manager see the worker's stated constraint alongside the recommendation?
  2. Time: Was there enough time to examine conflicts rather than approve automatically?
  3. Authority: Could the manager change the schedule without penalty or exceptional escalation?
  4. Record: Would the system preserve why the recommendation was accepted or changed?
  5. Repair: Could lost hours or an unworkable shift be corrected before the burden fell on the worker?

A human click is evidence of control only when the surrounding workflow makes informed disagreement practical.

Govern the conversion points

A general policy label cannot control a specific institutional action. Safeguards must sit at the points where one kind of relation becomes another: capability becomes permission, permission becomes mandate, mandate becomes reliance, and reliance becomes consequence.

A defensible arrangement would not ask only, “Is this AI allowed?” It would ask:

  1. Resource: which message, document, account, sensor, or application is in scope?
  2. Action: may the assistant read, draft, modify, send, purchase, delete, or execute?
  3. Purpose: what bounded user intention or institutional function justifies the access?
  4. Duration: when does permission expire, and can it be reused?
  5. Confirmation: which actions require meaningful human approval?
  6. Observability: what record allows later explanation, audit, and challenge?
  7. Revocation: who can stop the action independently of the assistant?

Reading one selected message is different from indexing a mailbox. Drafting a payment is different from authorising it. Summarising a document locally is different from sending it to a remote model.

Control should therefore be graduated by capability and consequence. Low-risk, reversible functions can carry light requirements. Sensitive, identity-bearing, communicative, financial, or state-changing functions require stronger isolation, evidence, confirmation, and independent interruption.

Responsibility should follow practical control

An AI-mediated workflow creates a chain of actors: model provider, systems integrator, data supplier, deploying institution, frontline worker, affected person, and regulator. “Shared responsibility” can easily become responsibility that disappears between contracts.

The provider controls model evaluation. The integrator controls how components and permissions connect. The institution controls purpose, workflow, staffing, and monitoring. A frontline worker or affected person should be responsible only where choice is informed, protected, and genuinely available.

Responsibility should follow practical control and capacity. Who could prevent the access? Who could observe the failure? Who could suspend the capability? Who could restore the record, payment, message, or opportunity? Who could change the design after the incident?

Industrial relations matters here. A worker should not become the moral crumple zone for a system they did not procure, configure, or have the authority to stop. Keeping a human near the decision does not justify pushing organisational responsibility downward.

Counterarguments and limits

Capability-based governance can become administratively heavy. Testing, documentation, audit, and review consume resources. Requirements should scale with practical reliance and consequence rather than burden every low-risk use equally.

Granular permissions do not eliminate failure. Complex systems still create unexpected interactions. Some actions may remain too sensitive for delegation until stronger evidence, architecture, and institutional capacity exist.

Restricting a capability can sometimes be justified. A function may be withheld where an institution can demonstrate a specific, material, and otherwise unmanageable risk. The justification should be reviewable, time-bounded, and no broader than necessary.

The framework can become paperwork instead of control. A perfect record does not make a weak institution capable. Documentation has value only when connected to enforceable boundaries, independent testing, interruption, reconsideration, and remedy.

The framework does not decide the institutional outcome. Applicable law, technical evidence, proportionality, context, and institutional competence remain necessary. The framework clarifies the questions; it does not predetermine the answer.

From the longer research

Between capability and consequence

This is a plain-language companion to my longer research paper. The complete paper develops the framework, tests difficult cases, states its limits, and explains when it should be revised or abandoned. This essay offers interpretation, not a report of an original empirical study.

Read the complete preprint on ZenodoBetween Capability and Consequence: Governing AI-Mediated Institutional Actiondoi:10.5281/zenodo.21752571

Conclusion

AI can make institutional work faster, more accessible, and more consistent. It can also become practically decisive without ever receiving a clear or legitimate grant of authority.

The answer is neither automatic adoption nor general prohibition. It is governed conversion: narrow permissions, valid mandates, observable reliance, meaningful human control, independent interruption, reversible action where possible, and responsibility aligned with those who can actually prevent and repair harm.

Intelligence can produce an answer. Institutions decide when that answer is allowed to change the world.