Automation-Control Matrix
Increase machine capability without forcing people to surrender control.
- Difficulty
- Moderate
- Time to result
- ~weeks to results
- Steps
- 5
- Confidence
- 95%
The Automation-Control Matrix treats machine autonomy and human agency as two independent design dimensions. First map how much of a task the system can perform, from assistance to full execution. Separately map the controls a person may need: setting direction, changing pace, making exceptions, pausing, or taking over. Build modes that combine these dimensions rather than assuming that every increase in automation requires an equal loss of control. A user may want full automation in one moment and active direction in another, even with the same capable system. Make overrides clear, preserve status visibility, and test whether people understand and can change the division of labor. The result is technology that expands choice instead of using human disappearance as its maturity model.
Origin
Norvig challenges the one-dimensional self-driving scale whose highest level visually removes the person, arguing that automation and user control should instead be designed on separate axes.
Core principles
- 01Automation and human control are independent dimensions.
- 02More automation should not make the person disappear.
- 03Users need different control levels in different contexts.
- 04Capability should expand choice rather than remove agency.
How to run it
- 1
Map automation levels
Define the bounded levels of assistance and execution the system can reliably provide.
Pro tip Base levels on tested capability, not marketing labels.
- 2
Map control needs
List the choices users may need before, during, and after automated action.
Pro tip Include redirection and unscheduled exceptions.
Watch out Do not reduce control to a single emergency stop.
- 3
Create mode combinations
Offer useful pairings of automation and control instead of forcing one linear progression.
Watch out Avoid modes whose names conceal what the machine will actually do.
- 4
Build overrides
Let the person pause, redirect, adjust, or take over with minimal friction.
Pro tip Keep current system intent visible before an override is needed.
- 5
Test agency
Observe whether users can predict, choose, and change the machine-human split in realistic scenarios.
Watch out Completion speed alone will not reveal loss of control.
In the wild
Norvig may want a trusted car to take over completely while he sleeps. At another time, he may want it to handle difficult driving while he chooses a different street, changes speed, or adds an unscheduled stop.
→ The same automation capability supports both delegation and active human direction.
A founder lets an agent draft and organize research automatically but requires approval before it contacts anyone or changes a live system. The founder can interrupt and redirect the research at any point.
→ Automation saves effort while consequential control remains human.
Common mistakes
Using a one-way autonomy ladder
A linear scale implies that progress requires steadily removing the person from the system.
Offering only on or off
Binary automation ignores legitimate differences between contexts and user preferences.
Hiding the override
Control that is slow, unclear, or inaccessible during operation is not meaningful control.
Is it for you?
Best for
Designers of AI agents, vehicles, and automated workflows where users may want different levels of involvement.
Not ideal for
Invisible low-stakes background processes where intervention has no practical value.
From the transcript
“I don't want this trade-off to be one-dimensional of if I get more automation then I disappear more.”
“I'd rather have it be two two-dimensional and let me choose.”
“So I don't want to say just because I have automation that I've given up control.”
From the episode
Peter Norvig: Transforming AI Into the Ultimate Human Advantage
Peter Norvig