Draw the AI Line by Blast Radius and Reversibility

TV
Thiago Victorino
7 min read
Draw the AI Line by Blast Radius and Reversibility

IBM’s own 1979 training manual settled this: “A computer can never be held accountable, therefore a computer must never make a management decision.” Forty-six years later, IBM Think reopened the question and gave a softer answer. Where does AI decision-making end and human judgment begin? A moving target, the piece concludes, decided case by case through ethics, risk, and trust, with “no hard-and-fast line” because legislation “hasn’t kept pace.”

The 1979 rule was right. It just lacked an engineering definition of “management decision.” That definition exists now, and it makes the line drawable.

IBM’s Three Soft Criteria

The framework in the IBM Think piece, written by Doug Bonderud and built on quotes from Guy Pearce of DEGI and ISACA, rests on three tests. Ethics is where AI “can’t do it,” in Pearce’s words, because a model seeks the most efficient path rather than the most ethical one. Risk is “an AI specialty,” measurable through standard error and variability. Trust is the human comfort layer on top.

Each test is real. Each is also a judgment call rendered per decision, per topic, by a committee. That is what keeps the line blurry, and Pearce names the cost of the blur directly: “shared accountability often leads to no accountability.” When three departments co-own a decision, none of them owns it. The blurry line and the vanishing accountability are the same problem wearing two faces.

Adoption has already outrun the deliberation. IBM’s Global AI Adoption Index reports 42% of enterprises have actively deployed AI and another 40% are experimenting, with 59% of those using or exploring it accelerating investment over the prior two years. IBM’s AI in Action report adds that two-thirds of leaders credit AI with more than a 25% improvement in revenue growth rates. Systems are making decisions at scale while the governance question stays open. A blurry line at that volume is a standing liability.

Two Properties Replace Three Judgments

Ethics, risk, and trust are properties of a decision’s content, and content is infinite. You cannot pre-adjudicate every topic an agent will touch. So stop drawing the line by topic. Draw it by the two properties of the action itself, both knowable before the agent runs.

Reversibility. Can this action be undone, and at what cost? Reading a record is fully reversible. Drafting a message is reversible until it sends. Deleting a production table, wiring a payment, or steering a vehicle is not reversible at all. Reversibility is a property of the action class, not the topic. A delete is irreversible whether it hits a marketing list or a patient record.

Blast radius. If this action is wrong, how far does the damage travel and how fast? One customer or the whole book. One inbox or the press. A rounding error or a solvency threat. We defined blast radius as the core autonomy-scoping variable in Three Autonomy Failures, Three Blast Radii, and the point holds: the shape of the worst case tells you the containment you need.

These two axes are mechanical. They do not require a committee to convene. They can be attached to an action class in code, once, and enforced in the harness rather than argued in a meeting.

The 8% Is the Whole Argument

IBM presents Consult Venture Partners’ AIda concierge, built on watsonx Assistant, as a success: it answered 92% of queries correctly. Turn the number over. It was wrong 8% of the time. For a lead-generation concierge, an 8% error rate is fine. The blast radius of a wrong answer about opening hours is a mildly annoyed prospect, and the action is fully reversible with a follow-up. Put that same 8% behind a loan approval, a medical triage, or a wire transfer and it is catastrophic, because the blast radius is a person’s finances or health and the action does not reverse.

Same model, same accuracy, opposite verdict. The acceptable error rate is not a property of the model. It is a property of the action’s blast radius and reversibility. That is precisely why a per-tool or per-topic line fails and a per-action-class line works. Tesla’s “full self-driving” mode was accurate the vast majority of the time; the motorcyclist it struck and killed in July 2024, as reported by CNN, fell in the fraction where an irreversible, maximum-radius action met a wrong call.

Singular Accountability Is a Design Choice

Pearce treats shared accountability as an inherent feature of AI decisions. It is a design default, and defaults can be changed. Accountability collapses into nothing when a scope has no owner. Attach an owner to the scope and it stops collapsing.

Four mechanisms make accountability singular and auditable. A named human owner for each high-radius or irreversible action class, one signature, not a committee. A scoped permission in the harness so the agent physically cannot execute outside its class, which is where the enforcement lives because the in-model instruction layer is unreliable under depth. An audit trail that logs every autonomous action with its class, its inputs, and its owner. And one scoreboard where every action rolls up, so the owner sees drift before it compounds. We described this control substrate in The Governance Substrate for Autonomous Operations and framed governed autonomy as the convergence point in Governed Autonomy Is the Convergence Point.

Run those four and “keep a human in the loop” stops being a slogan. IBM’s advice to retain human oversight is correct and underspecified. A human in the loop with no defined scope, no enforced permission, and no scoreboard is a bystander with plausible deniability. A human who owns a named action class, sees every action against one board, and holds the only key to the irreversible ones is accountable in the sense the 1979 manual demanded. Guardrails are the mechanism that makes oversight real, a point we develop in Hallucination Guardrails Are Governance.

Do This Now

Take your highest-autonomy agent and inventory its action classes, not its topics. For each class, mark two things: is it reversible, and what is the worst blast radius if it fires wrong. Auto-approve the reversible, low-radius classes and let the agent run. Gate every irreversible or high-radius class behind one named owner with a scoped permission and an audit line. Point all of it at a single scoreboard. You will have drawn the line IBM says cannot be drawn, and you will have done it once, in code, instead of a thousand times, in meetings.

No legal line yet does not mean no operational line. The operational line is buildable today, and the firms that build it will be the ones still standing when the legislation finally arrives.


This analysis synthesizes AI decision-making: Where do businesses draw the line? (IBM Think, January 2025), IBM Global AI Adoption Index 2023 (IBM Newsroom, January 2024), the AI in Action report (IBM, 2024), and CNN’s reporting on a Tesla full self-driving fatality (July 2024). Framework quotes are attributed to Guy Pearce (DEGI, ISACA); adoption and revenue figures are IBM-reported.

Victorino Group helps CTOs and risk officers turn “keep a human in the loop” into scoped permissions, named owners, and one scoreboard. Let’s talk.

All articles on The Thinking Wire are written with the assistance of Anthropic's Opus LLM. Each piece goes through multi-agent research to verify facts and surface contradictions, followed by human review and approval before publication. If you find any inaccurate information or wish to contact our editorial team, please reach out at editorial@victorinollc.com . About The Thinking Wire →

If this resonates, let's talk

We help companies implement AI without losing control.

Schedule a Conversation