Every vendor calls their product an “agent.” But a read-only search tool, an API caller that waits for approval, and an autonomous system that can touch production are fundamentally different risk profiles—even when the marketing pages look identical. Without a shared vocabulary for autonomy, security teams end up applying Assistant-level controls to Agent-level capabilities, and boards end up approving deployments nobody fully understands.
The 4A Framework maps AI capabilities to four distinct autonomy levels—Assistant, Adjuvant, Augmentor, and Agent—each with its own risk profile and control requirements. Between Adjuvant and Augmentor sits the DANGER CLOSE boundary: the point where AI stops suggesting and starts acting, and where most organizations are deploying faster than their governance can keep up.
This session walks through the model, shows how to use it to cut through vendor terminology, and offers honest guidance on where most organizations should actually be operating today versus where the pitch decks say they should be.