Capability is not permission

Most public argument about AI runs together four things that come apart cleanly, and separating them makes almost every question easier to think about.

Capability. What the system can do. Can it write the code, draft the letter, spot the tumour?

Autonomy. How many steps it takes without a person checking. One reply, or an hour of unsupervised work?

Access. What it is actually connected to. Your calendar? Your bank? A factory floor?

Accountability. Who answers for the result when it goes wrong.

These are set independently, and mostly not by the model.

An extremely capable model with no autonomy and no access is a very good typewriter. A mediocre model with broad autonomy and access to your money is a serious hazard. Capability is what people argue about. The other three are what determine consequences, and all three are decided by whoever deploys the system.

That should be reassuring in one way and much less so in another.

Reassuring, because the frightening scenarios almost all require someone to grant autonomy and access. The model does not acquire the ability to move money by becoming cleverer. Somebody hands it a key.

Less reassuring, because those keys are being handed over constantly, by ordinary people under ordinary commercial pressure to move faster. Nobody decides to be reckless. Someone decides to skip the approval step because the approval step is slow and the system has been right for months.

And accountability is the one that lags. When an agent acting for a company makes a costly mistake, the question of who is responsible, the operator, the deployer, the model provider, is genuinely unsettled in most places. The capability arrived first. Everything that governs it is still being worked out.