cd /news/ai-agents/is-kasparov-still-right · home topics ai-agents article
[ARTICLE · art-136558] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Is Kasparov still right?

A developer has published a draft framework for governing AI agent autonomy, defining five autonomy levels, sixteen required controls mapped to OWASP Agentic and ISO/IEC 42001, a scoring worksheet that caps the permitted level, and promotion rules that require evidence before autonomy is granted and allow revocation on signals. The framework, released under CC BY 4.0 on GitHub, also includes a machine-readable certificate per use case and is framed around the question of who decides how much human involvement each use case needs and how to prove it is safe.

by read1 min views5 publishedSep 22, 2026

Kasparov's conclusion: "Weak human + machine + better process was superior to a strong computer alone and, more remarkably, superior to a strong human + machine + inferior process."

He wrote that after two amateurs with three chess engines beat grandmasters in 2005. I kept coming back to it while watching how companies roll out AI agents today.

Half of his thesis is dead. Engines stopped needing a human partner years ago. But the other half held: the process decides the outcome. A Harvard/BCG experiment with 758 consultants found the same thing with AI tools. Same tool, same people, 40% better inside the model's range, 19 points worse just outside it.

So the question for agents isn't "human or no human" anymore. It's: who decides how much human involvement each use case needs, and how do you prove it's safe?

I couldn't find a good answer, so I built one. Over the past weeks I worked out a framework with five autonomy levels, sixteen required controls mapped to OWASP Agentic and ISO/IEC 42001, a scoring worksheet that caps the level, and promotion rules so autonomy is earned with evidence and revoked on signals. Plus a machine-readable certificate per use case.

It's a draft, public under CC BY 4.0: [https://github.com/cjohannsen81/agent-autonomy-levels](https://github.com/cjohannsen81/agent-autonomy-levels)

If you run agents in production, I'd like to hear where it breaks. The thresholds need real deployments to calibrate.
── more in #ai-agents 4 stories · sorted by recency
── more on @owasp 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/is-kasparov-still-ri…] indexed:0 read:1min 2026-09-22 ·