Implicit rate-limiting controls removed by agentic Artificial Intelligence (AI)
Implicit rate-limiting controls removed by agentic Artificial Intelligence (AI): blast radius amplification and the operational risk literature gap
- Confidence: high. The reviewed frameworks require explicit governance, monitoring, change control, resilience, and risk-management processes, but none of the reviewed texts explicitly classify human speed, attention, fatigue, or working hours as controls whose removal must be replaced with engineered controlsBasel (n.d.)APRA (n.d.)Regulation (2022)NIST (n.d.)NIST (n.d.)ISO (2018)
- Confidence: medium. DORA comes closest to the missing mechanism because it mandates continuous monitoring, automatic alerting, automated isolation, controlled change management, and interdependency-aware continuity planning, yet it still frames those as explicit ICT controls rather than as substitutes for removed human rate limitsRegulation (2022)
- Confidence: high. Basel Committee operational-risk principles and APRA CPS 230 clearly require strong control environments, oversight controls for change, monitoring, remediation, and ICT risk management, but they do not name pre-existing human operational friction as a distinct mitigant categoryBasel (n.d.)APRA (n.d.)
- Confidence: medium. NIST AI RMF 1.0 explicitly requires documented roles for human-AI configurations and oversight, ongoing monitoring, risk-tolerance setting, and safe decommissioning, but it does not instruct organizations to identify which human operating characteristics disappear when work shifts to continuous autonomous executionNIST (n.d.)NIST (n.d.)
- Confidence: medium. The SEC and CFTC Flash Crash report shows that a volume-driven automated sell program compressed execution into 20 minutes, many liquidity providers paused simultaneously to reassess conditions, and exchanges then implemented circuit breakers to recreate assessment time explicitlySec (n.d.)
- Confidence: high. The RPA literature shows that humans had been serving as the glue across disconnected systems, that automation moves more of that long-tail work into software agents, and that reliable scaling then depends on explicit exception handling, monitoring, privileged-access control, and change managementDoi (n.d.)Springer (n.d.)ISACA (n.d.)
- Confidence: medium. Perrow's normal accident theory provides the clearest first-principles explanation for the gap because tighter coupling and interactive complexity make consequence propagation faster and harder to interrupt once human slack is removedPrinceton (n.d.)Sec (n.d.)Doi (n.d.)
- Confidence: medium. A framework provision that closed the gap would need to require organizations to inventory human-derived friction before autonomy increases and to prove that rate limits, approval thresholds, segmentation, monitoring, exception routing, and shutoff mechanisms replace the lost mitigationBasel (n.d.)Regulation (2022)NIST (n.d.)ISO (2018)
Research Question
Prior to agentic Artificial Intelligence (AI), the blast radius of ungoverned citizen development was implicitly bounded by human speed, attention, fatigue, and working hours, controls that are not documented in any risk framework but function as real operational constraints. Agentic AI removes these implicit rate-limiting controls without replacing them with engineered controls. Does any operational risk framework, automation risk framework, or AI governance framework explicitly account for the removal of these implicit controls, or does this represent a gap in current frameworks that must be constructed from the operational risk literature on automation and speed of consequence?
Findings
(Populated from Section 6 Synthesis above.)
Executive Summary
- The reviewed operational-risk, resilience, and AI-governance frameworks do not explicitly account for the removal of human speed, attention, fatigue, or working-hour constraints as a named control-substitution problem; that mechanism is a genuine conceptual gap in explicit framework language.
- Those frameworks do, however, require explicit governance, monitoring, change control, resilience planning, and risk review, so unmanaged autonomy can still be criticised under existing duties even though the narrower mechanism is not named.
- The analogue evidence from high-frequency trading and RPA shows that once automation compresses time or extends operating windows, organizations add engineered pauses, monitoring, exception routing, and access controls to recreate the friction humans had been supplying implicitly.
- Perrow's normal accident theory is the strongest first-principles foundation for the missing mechanism because tighter coupling and faster consequence propagation explain why blast radius increases when human slack disappears.
Key Findings
- Confidence: high. The reviewed frameworks require explicit governance, monitoring, change control, resilience, and risk-management processes, but none of the reviewed texts explicitly classify human speed, attention, fatigue, or working hours as controls whose removal must be replaced with engineered controls.
- Confidence: medium. DORA comes closest to the missing mechanism because it mandates continuous monitoring, automatic alerting, automated isolation, controlled change management, and interdependency-aware continuity planning, yet it still frames those as explicit ICT controls rather than as substitutes for removed human rate limits.
- Confidence: high. Basel Committee operational-risk principles and APRA CPS 230 clearly require strong control environments, oversight controls for change, monitoring, remediation, and ICT risk management, but they do not name pre-existing human operational friction as a distinct mitigant category.
- Confidence: medium. NIST AI RMF 1.0 explicitly requires documented roles for human-AI configurations and oversight, ongoing monitoring, risk-tolerance setting, and safe decommissioning, but it does not instruct organizations to identify which human operating characteristics disappear when work shifts to continuous autonomous execution.
- Confidence: medium. The SEC and CFTC Flash Crash report shows that a volume-driven automated sell program compressed execution into 20 minutes, many liquidity providers paused simultaneously to reassess conditions, and exchanges then implemented circuit breakers to recreate assessment time explicitly.
- Confidence: high. The RPA literature shows that humans had been serving as the glue across disconnected systems, that automation moves more of that long-tail work into software agents, and that reliable scaling then depends on explicit exception handling, monitoring, privileged-access control, and change management.
- Confidence: medium. Perrow's normal accident theory provides the clearest first-principles explanation for the gap because tighter coupling and interactive complexity make consequence propagation faster and harder to interrupt once human slack is removed.
- Confidence: medium. A framework provision that closed the gap would need to require organizations to inventory human-derived friction before autonomy increases and to prove that rate limits, approval thresholds, segmentation, monitoring, exception routing, and shutoff mechanisms replace the lost mitigation.
Assumptions
- Assumption: Human speed, attention, fatigue, and working hours historically bounded citizen-development blast radius even though the reviewed corpus did not contain a direct pre-agentic measurement study. Justification: The claim is inferred from shadow-information-technology and automation analogues rather than from a direct quantitative historical study of citizen development specifically.
- Assumption: The explicit-gap conclusion is limited to the reviewed accessible framework texts and public summaries. Justification: Several seeded or granular sources were paywalled or inaccessible in this runtime, although no reviewed evidence suggested that those missing texts explicitly close the gap.
Analysis
- I weighted primary framework texts and official summaries more heavily than vendor or practitioner commentary when determining whether explicit coverage exists, so the explicit-gap conclusion is driven by regulator and standards documents rather than by later commentary.
- I used analogue evidence from high-frequency trading and RPA not to prove that the frameworks already contain the mechanism, but to test whether consequence speed, exception routing, and control substitution behave in practice the way the implicit-controls hypothesis predicts.
- Perrow's coupling model and DORA's explicit interdependency and continuity language align strongly enough that the first-principles argument is more credible than a pure novelty claim detached from operational-risk theory.
- The most important trade-off in the evidence is between directness and relevance: the shadow-information-technology and RPA sources are highly relevant to workaround estates but indirect on the exact phrase "implicit controls," while the framework texts are direct on explicit controls but silent on the narrower mechanism.
Risks, Gaps, and Uncertainties
- Direct empirical studies that quantify human pace, attention, fatigue, or working hours as a measured blast-radius cap for citizen development were not found in the reviewed corpus.
- The inaccessible Oxford and Gartner sources may contain additional supporting detail for the technology-analogue section, but they do not change the reviewed-framework conclusion because the explicit-gap claim is grounded in accessible primary framework texts.
- ISO 31000 and NIST SP 800-53 were only accessible at public-summary level in this runtime, so claims about their silence on the mechanism are lower precision than the DORA, Basel, APRA, NIST AI RMF, SEC, and RPA claims.
Open Questions
- Which concrete control patterns best replace lost human friction in enterprise agent deployments, for example rate limits, mandatory approval thresholds, segmentation, exception-routing thresholds, or time-bounded credentials?
- How should boards and risk committees quantify blast-radius change when a workflow moves from human execution to continuous agent execution under otherwise unchanged permissions and process maps?
sources
- [x] Basel Committee on Banking Supervision, Principles for operational resilience — - primary resilience framework text.
- [x] Basel Committee on Banking Supervision, Principles for the Sound Management of Operational Risk, Executive Summary — - primary operational-risk summary used for pinpointable principle language.
- [x] APRA CPS 230, Operational Risk Management — - primary prudential text.
- [x] Regulation (EU) 2022/2554, Digital Operational Resilience Act (DORA) Portable Document Format (PDF) — - primary legal text; the web reader path was unreliable in this runtime, so the PDF text extraction was used.
- [x] NIST AI RMF 1.0 publication page — - official framework publication page.
- [x] NIST AI RMF Core — - official categories and subcategories used for human-AI oversight and monitoring language.
- [x] NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations — - official publication page and control-family summary; granular control pages were not directly accessible in this runtime.
- [x] ISO 31000:2018, Risk management - Guidelines — - official public summary page; full text is paywalled.
- [x] Princeton University Press, Normal Accidents: Living with High-Risk Technologies — - accessible publisher summary used in place of the unstable Amazon listing.
- [x] U.S. Securities and Exchange Commission (SEC) and Commodity Futures Trading Commission (CFTC), Findings Regarding the Market Events of May 6, 2010 — - primary Flash Crash report; the originally seeded SEC URL returned 404 in this runtime and was replaced by the current official PDF.
- [x] Oxford Review of Financial Studies Flash Crash article — - checked, returned 403 in this runtime, and was not used for downstream factual support.
- [x] van der Aalst, Bichler, and Heinzl, Robotic Process Automation — - peer-reviewed RPA overview with explicit discussion of humans as the glue across systems, handoff of exceptional cases, and unnoticed automated failure.
- [x] Herm et al., A framework for implementing robotic process automation projects — - peer-reviewed RPA implementation literature, including high failure-rate discussion and methodological challenges.
- [x] ISACA Journal, RPA Is Evolving but Risk Still Exists — - practitioner guidance on command-and-control centers, continuous operation, privileged access, monitoring, and change control.
- [x] From Shadow IT to Business-managed IT — - peer-reviewed shadow-IT study showing business units adopt local systems when central information technology cannot deliver suitable solutions quickly enough.
- [x] On the Emergence of Shadow IT, A Transaction Cost-Based Approach — - checked, but the accessible view exposed references only in this runtime, so it was not used for downstream factual support.
- [x] Gartner RPA document — - checked, returned 403 in this runtime, and was not used for downstream factual support.