Implicit rate-limiting controls removed by agentic Artificial Intelligence (AI)

Implicit rate-limiting controls removed by agentic Artificial Intelligence (AI): blast radius amplification and the operational risk literature gap

2026-04-26 · agentic-ai security-risk governance-policy tools-infrastructure · medium · source → · wiki →
key claims
  1. Confidence: high. The reviewed frameworks require explicit governance, monitoring, change control, resilience, and risk-management processes, but none of the reviewed texts explicitly classify human speed, attention, fatigue, or working hours as controls whose removal must be replaced with engineered controlsBasel (n.d.)APRA (n.d.)Regulation (2022)NIST (n.d.)NIST (n.d.)ISO (2018)
  2. Confidence: medium. DORA comes closest to the missing mechanism because it mandates continuous monitoring, automatic alerting, automated isolation, controlled change management, and interdependency-aware continuity planning, yet it still frames those as explicit ICT controls rather than as substitutes for removed human rate limitsRegulation (2022)
  3. Confidence: high. Basel Committee operational-risk principles and APRA CPS 230 clearly require strong control environments, oversight controls for change, monitoring, remediation, and ICT risk management, but they do not name pre-existing human operational friction as a distinct mitigant categoryBasel (n.d.)APRA (n.d.)
  4. Confidence: medium. NIST AI RMF 1.0 explicitly requires documented roles for human-AI configurations and oversight, ongoing monitoring, risk-tolerance setting, and safe decommissioning, but it does not instruct organizations to identify which human operating characteristics disappear when work shifts to continuous autonomous executionNIST (n.d.)NIST (n.d.)
  5. Confidence: medium. The SEC and CFTC Flash Crash report shows that a volume-driven automated sell program compressed execution into 20 minutes, many liquidity providers paused simultaneously to reassess conditions, and exchanges then implemented circuit breakers to recreate assessment time explicitlySec (n.d.)
  6. Confidence: high. The RPA literature shows that humans had been serving as the glue across disconnected systems, that automation moves more of that long-tail work into software agents, and that reliable scaling then depends on explicit exception handling, monitoring, privileged-access control, and change managementDoi (n.d.)Springer (n.d.)ISACA (n.d.)
  7. Confidence: medium. Perrow's normal accident theory provides the clearest first-principles explanation for the gap because tighter coupling and interactive complexity make consequence propagation faster and harder to interrupt once human slack is removedPrinceton (n.d.)Sec (n.d.)Doi (n.d.)
  8. Confidence: medium. A framework provision that closed the gap would need to require organizations to inventory human-derived friction before autonomy increases and to prove that rate limits, approval thresholds, segmentation, monitoring, exception routing, and shutoff mechanisms replace the lost mitigationBasel (n.d.)Regulation (2022)NIST (n.d.)ISO (2018)

Research Question

Prior to agentic Artificial Intelligence (AI), the blast radius of ungoverned citizen development was implicitly bounded by human speed, attention, fatigue, and working hours, controls that are not documented in any risk framework but function as real operational constraints. Agentic AI removes these implicit rate-limiting controls without replacing them with engineered controls. Does any operational risk framework, automation risk framework, or AI governance framework explicitly account for the removal of these implicit controls, or does this represent a gap in current frameworks that must be constructed from the operational risk literature on automation and speed of consequence?

Findings

(Populated from Section 6 Synthesis above.)

Executive Summary

Key Findings

  1. Confidence: high. The reviewed frameworks require explicit governance, monitoring, change control, resilience, and risk-management processes, but none of the reviewed texts explicitly classify human speed, attention, fatigue, or working hours as controls whose removal must be replaced with engineered controls.
  2. Confidence: medium. DORA comes closest to the missing mechanism because it mandates continuous monitoring, automatic alerting, automated isolation, controlled change management, and interdependency-aware continuity planning, yet it still frames those as explicit ICT controls rather than as substitutes for removed human rate limits.
  3. Confidence: high. Basel Committee operational-risk principles and APRA CPS 230 clearly require strong control environments, oversight controls for change, monitoring, remediation, and ICT risk management, but they do not name pre-existing human operational friction as a distinct mitigant category.
  4. Confidence: medium. NIST AI RMF 1.0 explicitly requires documented roles for human-AI configurations and oversight, ongoing monitoring, risk-tolerance setting, and safe decommissioning, but it does not instruct organizations to identify which human operating characteristics disappear when work shifts to continuous autonomous execution.
  5. Confidence: medium. The SEC and CFTC Flash Crash report shows that a volume-driven automated sell program compressed execution into 20 minutes, many liquidity providers paused simultaneously to reassess conditions, and exchanges then implemented circuit breakers to recreate assessment time explicitly.
  6. Confidence: high. The RPA literature shows that humans had been serving as the glue across disconnected systems, that automation moves more of that long-tail work into software agents, and that reliable scaling then depends on explicit exception handling, monitoring, privileged-access control, and change management.
  7. Confidence: medium. Perrow's normal accident theory provides the clearest first-principles explanation for the gap because tighter coupling and interactive complexity make consequence propagation faster and harder to interrupt once human slack is removed.
  8. Confidence: medium. A framework provision that closed the gap would need to require organizations to inventory human-derived friction before autonomy increases and to prove that rate limits, approval thresholds, segmentation, monitoring, exception routing, and shutoff mechanisms replace the lost mitigation.

Assumptions

Analysis

Risks, Gaps, and Uncertainties

Open Questions


sources

Connected items

Loading…

View full knowledge graph →