委任時間論:自主 Agent、人類介入密度與治理槓桿
Delegated-Time Theory: Autonomous Agents, Human Intervention Density, and Governance Leverage
系列 :AI 互動時間與智能時間經濟學系列,第 6 篇/共 8 篇文件編號 :EML-DTT-2026-06-v0.1作者 :Neo.K(許筌崴)with Aletheia(GPT-5.6 Sol)機構 :EveMissLab/一言諾科技有限公司版本 :v0.1日期 :2026-08-20性質 :理論框架/Agent Autonomy/Human Oversight/時間經濟學/治理工程狀態 :Public Theory Draft直接前置 :《AI 計算時間經濟學:Token、算力、額度與智能資源配置》v0.1
摘要
當 AI Agent 從單輪回答器轉變為可長時程規劃、使用工具、保存狀態、重試、恢復、平行分支與執行外部操作的自主系統後,人機協作的核心問題不再只是「AI 能做多少」,而是「人類必須多久回來一次」。如果每一個 Agent action 都需要人類按下確認,系統雖然形式上具有 Human-in-the-Loop,卻可能失去委任價值,並因高頻低價值批准造成注意力耗損、確認疲勞與形式監督空洞化;反之,如果人類完全退出操作環,而 Agent 的風險傳播速度、權限與世界作用範圍超過監控與停止能力,名義上的 Human-on-the-Loop 也可能失去實質治理意義。
本文提出「委任時間論」(Delegated-Time Theory, DTT),將 Agent autonomy 理解為一種跨時間的受約束委任結構,而非單一「自主/不自主」二值屬性。其基本形式為:
U ( I 0 , A 0 ) → D [ A 1 → A 2 → ⋯ → A n ] → U ( C k ) , U(I_0,A_0)
\rightarrow
\boxed{
\mathcal D
\left[
A_1
\rightarrow
A_2
\rightarrow
\cdots
\rightarrow
A_n
\right]
}
\rightarrow
U(C_k), U ( I 0 , A 0 ) → D [ A 1 → A 2 → ⋯ → A n ] → U ( C k ) ,
其中 U U U 為人類或其他委任主體, I 0 I_0 I 0 為初始意圖, A 0 A_0 A 0 為授權包絡, D \mathcal D D 為委任區塊, A i A_i A i 為 Agent 內部行動, C k C_k C k 為下一個人類 checkpoint。本文據此定義「人類介入密度」:
ρ H = N h u m a n i n t e r v e n t i o n s N e f f e c t i v e a g e n t t r a n s i t i o n s , \rho_H
=
\frac{
N_{\mathrm{human\ interventions}}
}{
N_{\mathrm{effective\ agent\ transitions}}
}, ρ H = N effective agent transitions N human interventions ,
「介入延遲」:
L H = t i n t e r v e n e − t t r i g g e r , L_H
=
t_{\mathrm{intervene}}
-
t_{\mathrm{trigger}}, L H = t intervene − t trigger ,
「治理頻寬」:
B G = N m e a n i n g f u l o v e r s i g h t d e c i s i o n s T H g o v , B_G
=
\frac{
N_{\mathrm{meaningful\ oversight\ decisions}}
}{
T_H^{gov}
}, B G = T H g o v N meaningful oversight decisions ,
以及「委任槓桿」:
Λ D = V e f f e c t i v e d e l e g a t e d w o r k T H g o v + ϵ . \Lambda_D
=
\frac{
V_{\mathrm{effective\ delegated\ work}}
}{
T_H^{gov}+\epsilon
}. Λ D = T H g o v + ϵ V effective delegated work .
本文進一步指出,低 ρ H \rho_H ρ H 不等於高品質自治,高 ρ H \rho_H ρ H 也不等於高品質監督。真正的治理問題是:人類注意力是否集中在高風險、高不確定、高不可逆、高權限與高外部性的節點;系統能否在傷害傳播之前觸發 escalation;授權是否有範圍、期限、可撤銷性與 renewal;Agent 是否能在預算耗盡、權限過期、環境漂移與異常情況下進入安全停止、暫停或回交狀態。
本文提出 Human-in-the-Loop、Human-on-the-Loop、Human-out-of-the-Operational-Loop 與 Human-on-the-Bridge 四種不同的人類時間配置模式,並主張成熟系統可以在同一工作流內依風險與可逆性動態切換,而不是整個 Agent 永久固定在某一自治等級。本文與 EveMissLab 既有個體機構化、AI 時間經濟學、Human-in/Human-on/Human-out-of-Operational、AICL authority layer、ISF/WDC runtime 直接整合;並與 2026 年人類監督實證研究、Agent-Human Interaction security、graduated oversight、risk-adaptive HITL gate 與 Human-on-the-Bridge evaluation 形成對話。
本文的核心結論是:
Autonomy ≠ Absence of Humans . \boxed{
\text{Autonomy}
\neq
\text{Absence of Humans}.
} Autonomy = Absence of Humans .
更成熟的自治是:在可觀測、可撤銷、可升級、可回交的授權包絡內,讓低邊際治理價值的操作退出人類注意力,而把有限的人類時間集中到真正具有不可替代判斷價值的節點。
關鍵詞 :委任時間、Agent Autonomy、Human-in-the-Loop、Human-on-the-Loop、Human-out-of-the-Operational-Loop、Human-on-the-Bridge、Approval Fatigue、Intervention Density、Governance Bandwidth、Authority、Escalation、Delegation Leverage
0. 核心問題
第 5 篇處理:
有多少 AI 計算,以及應該把它花在哪裡?
當答案是:
讓 Agent 自己連續執行。
下一個問題立即出現:
人類何時必須重新介入?
傳統聊天模式近似:
U → A → U → A → U . U
\rightarrow
A
\rightarrow
U
\rightarrow
A
\rightarrow
U. U → A → U → A → U .
成熟 Agent 則可能:
U ( I 0 ) → A 1 → A 2 → ⋯ → A n → U ( C k ) . U(I_0)
\rightarrow
A_1
\rightarrow
A_2
\rightarrow
\cdots
\rightarrow
A_n
\rightarrow
U(C_k). U ( I 0 ) → A 1 → A 2 → ⋯ → A n → U ( C k ) .
因此人類不再位於每一個 action 之間。
這產生新的時間結構:
Human Time → Delegated Agent Time → Human Governance Time . \boxed{
\text{Human Time}
\rightarrow
\text{Delegated Agent Time}
\rightarrow
\text{Human Governance Time}.
} Human Time → Delegated Agent Time → Human Governance Time .
本文稱其為:
委任時間
1. 委任時間的基本定義
令委任包:
D = ( I , A , B , R , C , E , T , X ) . \mathfrak D
=
(
I,
A,
B,
R,
C,
E,
T,
X
). D = ( I , A , B , R , C , E , T , X ) .
其中:
I I I :Intent;
A A A :Authority envelope;
B B B :Budget;
R R R :Risk policy;
C C C :Checkpoint policy;
E E E :Escalation policy;
T T T :Time / deadline policy;
X X X :External-action boundary。
Agent 在此包絡內可以:
D : S 0 → S 1 → ⋯ → S n . \mathcal D
:
S_0
\rightarrow
S_1
\rightarrow
\cdots
\rightarrow
S_n. D : S 0 → S 1 → ⋯ → S n .
只要沒有跨越:
A , R , B , T , X A,
R,
B,
T,
X A , R , B , T , X
的合法邊界,就不必每一步重新詢問委任者。
因此:
Delegation = Bounded Autonomous Transition Permission . \boxed{
\text{Delegation}
=
\text{Bounded Autonomous Transition Permission}.
} Delegation = Bounded Autonomous Transition Permission .
2. 委任不是放棄控制
若使用者把任務交給 Agent:
把這個研究分支繼續跑完。
不表示 Agent 自動取得:
任意金錢支出;
任意外部發布;
任意修改原始檔;
任意使用第三方資料;
任意改變核心意圖;
任意擴張自己的權限。
因此:
Task Delegation ≠ Unlimited Authority Transfer . \boxed{
\text{Task Delegation}
\neq
\text{Unlimited Authority Transfer}.
} Task Delegation = Unlimited Authority Transfer .
委任一定發生在某個:
A e n v e l o p e . A_{\mathrm{envelope}}. A envelope .
3. Authority Envelope
定義:
A e n v = ( S c o p e , A c t i o n s , R e s o u r c e s , T a r g e t s , C e i l i n g s , E x p i r y , R e v o c a t i o n ) . A_{\mathrm{env}}
=
(
Scope,
Actions,
Resources,
Targets,
Ceilings,
Expiry,
Revocation
). A env = ( S co p e , A c t i o n s , R eso u r ces , T a r g e t s , C e i l in g s , E x p i r y , R e v oc a t i o n ) .
其中:
Scope:任務範圍;
Actions:允許 action class;
Resources:可使用資源;
Targets:可作用對象;
Ceilings:金額、風險、數量與頻率上限;
Expiry:授權有效期;
Revocation:撤銷機制。
因此:
C r e d e n t i a l V a l i d ⇏ A u t h o r i t y V a l i d . \boxed{
CredentialValid
\not\Rightarrow
AuthorityValid.
} C r e d e n t ia l V a l i d ⇒ A u t h or i t y V a l i d .
擁有 API key 不代表當前任務有權執行所有 API action。
4. Task Lifetime 與 Authority Lifetime
長時程 Agent 任務可能滿足:
T t a s k > T a u t h o r i t y . T_{\mathrm{task}}
>
T_{\mathrm{authority}}. T task > T authority .
這是正常情況。
因此 persistent task 必須支持:
authority renewal;
revocation check;
bounded continuation;
pause;
cancellation;
renewal failure policy。
所以:
Initial Authorization ≠ Permanent Authorization . \boxed{
\text{Initial Authorization}
\neq
\text{Permanent Authorization}.
} Initial Authorization = Permanent Authorization .
5. Human-in-the-Loop
Human-in-the-Loop(HITL)可抽象為:
A i p r o p o s a l → H i → A i c o m m i t . A_i^{proposal}
\rightarrow
H_i
\rightarrow
A_i^{commit}. A i p r o p os a l → H i → A i co mmi t .
人類位於 action 與 commit 之間。
適合:
高不可逆;
高金額;
高法律責任;
高資料敏感度;
高外部影響;
低 Agent confidence。
其核心優勢是:
Pre-Commit Human Control . \text{Pre-Commit Human Control}. Pre-Commit Human Control .
但缺點是:
C H a p p r o v a l ↑ C_H^{approval}
\uparrow C H a pp r o v a l ↑
且可能限制 Agent throughput。
6. Human-on-the-Loop
Human-on-the-Loop(HOTL)表示:
A g e n t → A c t i o n → M o n i t o r → P o s s i b l e I n t e r v e n t i o n . Agent
\rightarrow
Action
\rightarrow
Monitor
\rightarrow
PossibleIntervention. A g e n t → A c t i o n → M o ni t or → P oss ib l e I n t er v e n t i o n .
人類不必批准每一步,但保留:
observability;
alert;
override;
pause;
rollback / compensation;
escalation handling。
因此:
H O T L = Autonomous Operation + Human Intervention Capacity . \boxed{
HOTL
=
\text{Autonomous Operation}
+
\text{Human Intervention Capacity}.
} H O T L = Autonomous Operation + Human Intervention Capacity .
7. Human-out-of-the-Operational-Loop
若正常生產流程:
A 1 → A 2 → ⋯ → A n A_1
\rightarrow
A_2
\rightarrow
\cdots
\rightarrow
A_n A 1 → A 2 → ⋯ → A n
不要求即時人類操作,而人類仍保留:
policy;
assets;
authority root;
audit;
revocation;
exception review;
institutional responsibility;
則應稱:
Human-out-of-the-Operational-Loop . \boxed{
\text{Human-out-of-the-Operational-Loop}.
} Human-out-of-the-Operational-Loop .
它不等於:
Human-out-of-the-System . \text{Human-out-of-the-System}. Human-out-of-the-System .
8. Human-on-the-Bridge
Human-on-the-Bridge(HOB)把人類專業判斷提前編譯成:
rubric;
trap;
policy;
fallback;
evidence rule;
evaluator profile。
之後由自動化 evaluator / harness 重複執行。
所以:
Human Judgment → Reusable Governance Artifact . \boxed{
\text{Human Judgment}
\rightarrow
\text{Reusable Governance Artifact}.
} Human Judgment → Reusable Governance Artifact .
人類不是每次 run 都重新判斷,而是把治理時間資本化。
這與知識資本、validator、policy-as-code 直接相容。
9. 四種模式不是成熟度單線
本文拒絕:
H I T L → H O T L → H O O L HITL
\rightarrow
HOTL
\rightarrow
HOOL H I T L → H O T L → H O O L
必然等於「越後面越成熟」。
同一系統可以:
對讀取資料使用 HOOL;
對修改 sandbox 使用 HOTL;
對大額付款使用 HITL;
對評估規則使用 HOB。
因此:
Oversight Mode = f ( R i s k , R e v e r s i b i l i t y , A u t h o r i t y , U n c e r t a i n t y , E x t e r n a l i t y ) . \boxed{
\text{Oversight Mode}
=
f(
Risk,
Reversibility,
Authority,
Uncertainty,
Externality
).
} Oversight Mode = f ( R i s k , R e v er s ibi l i t y , A u t h or i t y , U n cer t ain t y , E x t er na l i t y ) .
10. 介入不是越多越安全
存在形式 approval:
N H ≫ 1 N_H\gg1 N H ≫ 1
不表示:
Q o v e r s i g h t ↑ . Q_{\mathrm{oversight}}\uparrow. Q oversight ↑ .
若人類每天收到大量低價值確認:
允許讀取檔案嗎?
允許繼續嗎?
允許再次查詢嗎?
注意力會被耗散。
因此:
Approval Count ≠ Oversight Quality . \boxed{
\text{Approval Count}
\neq
\text{Oversight Quality}.
} Approval Count = Oversight Quality .
11. Approval Fatigue
定義批准負荷:
L A = N a p p r o v a l r e q u e s t s T H g o v . L_A
=
\frac{
N_{\mathrm{approval\ requests}}
}{
T_H^{gov}
}. L A = T H g o v N approval requests .
若:
L A ≫ B H a t t e n t i o n , L_A
\gg
B_H^{attention}, L A ≫ B H a tt e n t i o n ,
則人類可能:
快速點擊;
不閱讀;
固定 approve;
遺漏高風險事件;
形成 automation bias。
因此形式 HITL 可以退化為:
Rubber-Stamp Loop . \boxed{
\text{Rubber-Stamp Loop}.
} Rubber-Stamp Loop .
12. 人類介入密度
本文定義:
ρ H = N h u m a n i n t e r v e n t i o n s N e f f e c t i v e a g e n t t r a n s i t i o n s . \rho_H
=
\frac{
N_{\mathrm{human\ interventions}}
}{
N_{\mathrm{effective\ agent\ transitions}}
}. ρ H = N effective agent transitions N human interventions .
若:
ρ H ≈ 1 , \rho_H\approx1, ρ H ≈ 1 ,
表示 Agent 幾乎每步都需人類介入。
若:
ρ H ≪ 1 , \rho_H\ll1, ρ H ≪ 1 ,
表示大量有效狀態轉換在兩次人類介入之間完成。
但:
ρ H ↓ ⇏ Q g o v e r n a n c e ↑ . \boxed{
\rho_H\downarrow
\not\Rightarrow
Q_{\mathrm{governance}}\uparrow.
} ρ H ↓ ⇒ Q governance ↑ .
低介入密度只是一個結構量。
13. Weighted Human Intervention Density
不是所有 Agent transition 一樣重要。
定義事件風險權重:
w j R . w_j^R. w j R .
可建立:
ρ H R = ∑ h ∈ H w h R ∑ e ∈ E w e R . \rho_H^R
=
\frac{
\sum_{h\in H}w_h^R
}{
\sum_{e\in E}w_e^R
}. ρ H R = ∑ e ∈ E w e R ∑ h ∈ H w h R .
更實用的是測:
高風險事件中,有多少得到合適的人類治理?
而不是單純算按鈕次數。
14. Effective Oversight Density
定義高治理價值節點集合:
C H = { e : R i s k ( e ) ≥ θ R ∨ I r r e v ( e ) ≥ θ I ∨ A u t h o r i t y ( e ) ≥ θ A ∨ U n c e r t a i n t y ( e ) ≥ θ U } . \mathcal C_H
=
\{
e:
Risk(e)\ge\theta_R
\vee
Irrev(e)\ge\theta_I
\vee
Authority(e)\ge\theta_A
\vee
Uncertainty(e)\ge\theta_U
\}. C H = { e : R i s k ( e ) ≥ θ R ∨ I r r e v ( e ) ≥ θ I ∨ A u t h or i t y ( e ) ≥ θ A ∨ U n cer t ain t y ( e ) ≥ θ U } .
有效監督覆蓋率:
E O D = ∣ C H ∩ H r e v i e w e d ∣ ∣ C H ∣ . EOD
=
\frac{
|\mathcal C_H\cap H_{\mathrm{reviewed}}|
}{
|\mathcal C_H|
}. E O D = ∣ C H ∣ ∣ C H ∩ H reviewed ∣ .
因此成熟系統希望:
E O D ↑ EOD\uparrow E O D ↑
同時:
N l o w − v a l u e a p p r o v a l s ↓ . N_{\mathrm{low-value\ approvals}}\downarrow. N low − value approvals ↓ .
15. Governance Bandwidth
人類治理時間有限。
定義:
T H g o v = available governance time . T_H^{gov}
=
\text{available governance time}. T H g o v = available governance time .
以及:
B G = N m e a n i n g f u l g o v e r n a n c e d e c i s i o n s T H g o v . B_G
=
\frac{
N_{\mathrm{meaningful\ governance\ decisions}}
}{
T_H^{gov}
}. B G = T H g o v N meaningful governance decisions .
但 B G B_G B G 也不能無限增加。
每個人類決策需要:
context reconstruction;
evidence reading;
risk reasoning;
authorization;
responsibility。
因此人類治理是一種低頻高價值資源。
16. Context Reconstruction Cost
若每次 Agent 叫人回來時,人類都需要重新理解:
現在做到哪裡;
為什麼停;
哪些選項;
哪些證據;
風險在哪;
先前做過什麼;
則介入成本:
C H c o n t e x t C_H^{context} C H co n t e x t
可能大於實際批准成本。
因此 checkpoint 應生成:
Decision-Ready State Summary . \boxed{
\text{Decision-Ready State Summary}.
} Decision-Ready State Summary .
不是把完整 trace 全丟給人類。
17. Decision-Ready Checkpoint
一個治理 checkpoint:
C H C_H C H
至少應包含:
C H = ( I n t e n t , C u r r e n t S t a t e , T r i g g e r , O p t i o n s , E v i d e n c e , R i s k , R e c o m m e n d a t i o n , A u t h o r i t y N e e d e d , R o l l b a c k S t a t e ) . C_H
=
(
Intent,
CurrentState,
Trigger,
Options,
Evidence,
Risk,
Recommendation,
AuthorityNeeded,
RollbackState
). C H = ( I n t e n t , C u r r e n tS t a t e , T r i g g er , O pt i o n s , E v i d e n ce , R i s k , R eco mm e n d a t i o n , A u t h or i t y N ee d e d , R o l l ba c k S t a t e ) .
人類應能回答:
為什麼現在需要我?
而不是重新讀完整 history。
18. Checkpoint Value
對 checkpoint:
c h , c_h, c h ,
定義:
V H ( c h ) = E [ Δ R i s k R e d u c t i o n + Δ D e c i s i o n Q u a l i t y + Δ A u t h o r i t y V a l i d i t y ] − C H ( c h ) . V_H(c_h)
=
E[
\Delta RiskReduction
+
\Delta DecisionQuality
+
\Delta AuthorityValidity
]
-
C_H(c_h). V H ( c h ) = E [ Δ R i s k R e d u c t i o n + Δ D ec i s i o n Q u a l i t y + Δ A u t h or i t y V a l i d i t y ] − C H ( c h ) .
若:
V H ( c h ) < 0 , V_H(c_h)<0, V H ( c h ) < 0 ,
這個 checkpoint 可能是不必要的人類打擾。
所以:
Ask Human 也是一個需要成本—收益判斷的 action . \boxed{
\text{Ask Human}
\text{ 也是一個需要成本—收益判斷的 action}.
} Ask Human 也是一個需要成本 — 收益判斷的 action .
19. 人類介入延遲
令 Agent 觸發高風險事件:
t t r i g g e r . t_{\mathrm{trigger}}. t trigger .
人類真正介入:
t i n t e r v e n e . t_{\mathrm{intervene}}. t intervene .
定義:
L H = t i n t e r v e n e − t t r i g g e r . L_H
=
t_{\mathrm{intervene}}
-
t_{\mathrm{trigger}}. L H = t intervene − t trigger .
如果傷害傳播時間:
T h a r m T_{\mathrm{harm}} T harm
滿足:
L H > T h a r m , L_H
>
T_{\mathrm{harm}}, L H > T harm ,
則:
Human-on-the-Loop 可能形式存在但實質失效 . \boxed{
\text{Human-on-the-Loop}
\text{ 可能形式存在但實質失效}.
} Human-on-the-Loop 可能形式存在但實質失效 .
20. Intervention Reachability
有 override button 還不夠。
必須確認從警報到實際停止:
A l e r t → H u m a n → O v e r r i d e → S t o p Alert
\rightarrow
Human
\rightarrow
Override
\rightarrow
Stop A l er t → H u man → O v er r i d e → S t o p
的路徑可達。
定義:
R H = P ( successful intervention before harm ) . R_H
=
P(
\text{successful intervention before harm}
). R H = P ( successful intervention before harm ) .
真正 HOTL 需要:
R H R_H R H
高於任務要求。
21. Escalation Trigger
Agent 不應只在「不知道」時叫人。
Escalation 可以由:
T r i g g e r = f ( R i s k , U n c e r t a i n t y , I r r e v e r s i b i l i t y , A u t h o r i t y , N o v e l t y , B u d g e t , C o n f l i c t , D e a d l i n e ) . Trigger
=
f(
Risk,
Uncertainty,
Irreversibility,
Authority,
Novelty,
Budget,
Conflict,
Deadline
). T r i g g er = f ( R i s k , U n cer t ain t y , I r r e v er s ibi l i t y , A u t h or i t y , N o v e l t y , B u d g e t , C o n f l i c t , D e a d l in e ) .
常見 trigger:
confidence 低;
policy conflict;
forbidden-state proximity;
budget nearing ceiling;
external impact high;
tool output anomalous;
repeated failure;
authority expired;
human preference conflict;
novel situation。
22. Risk-Adaptive Escalation
定義 action risk vector:
R ( a ) = ( B l a s t R a d i u s , I r r e v e r s i b i l i t y , E p i s t e m i c U n c e r t a i n t y , D a t a S e n s i t i v i t y , F i n a n c i a l I m p a c t , L e g a l I m p a c t ) . \mathbf R(a)
=
(
BlastRadius,
Irreversibility,
EpistemicUncertainty,
DataSensitivity,
FinancialImpact,
LegalImpact
). R ( a ) = ( B l a s tR a d i u s , I r r e v er s ibi l i t y , E p i s t e mi c U n cer t ain t y , D a t a S e n s i t i v i t y , F inan c ia l I m p a c t , L e g a l I m p a c t ) .
Oversight policy:
O : R ( a ) → M o d e . \mathcal O
:
\mathbf R(a)
\rightarrow
Mode. O : R ( a ) → M o d e .
例如:
M o d e ∈ { A U T O , M O N I T O R , A P P R O V E , M U L T I A P P R O V E , D E N Y } . Mode
\in
\{
AUTO,
MONITOR,
APPROVE,
MULTI_APPROVE,
DENY
\}. M o d e ∈ { A U T O , M O N I T O R , A P P R O V E , M U L T I A P P R O V E , D E N Y } .
這比全域固定 HITL 更符合比例治理。
23. Oversight as a Scarce Resource
人類注意力:
B H B_H B H
有限。
所以:
∑ i C H ( h i ) ≤ B H . \sum_iC_H(h_i)
\le
B_H. i ∑ C H ( h i ) ≤ B H .
因此 oversight allocation 本身是一個 portfolio problem。
系統應把人類介入配置到:
arg max i E [ Δ V g o v e r n a n c e ( h i ) ] C H ( h i ) + ϵ . \arg\max_i
\frac{
E[\Delta V_{\mathrm{governance}}(h_i)]
}{
C_H(h_i)+\epsilon
}. arg i max C H ( h i ) + ϵ E [ Δ V governance ( h i )] .
這與第 5 篇的 compute allocation 完全對稱。
24. Human-Time Shadow Price
若人類治理時間有限,可引入:
λ H = shadow price of human governance time . \lambda_H
=
\text{shadow price of human governance time}. λ H = shadow price of human governance time .
當 Agent 產生一個 approval request:
h i , h_i, h i ,
若:
E [ Δ V H ( h i ) ] < λ H , E[\Delta V_H(h_i)]
<
\lambda_H, E [ Δ V H ( h i )] < λ H ,
則原則上應:
自動處理;
聚合;
延後;
用 policy artifact;
用 validator;
改成 exception-only。
高:
λ H \lambda_H λ H
代表人類時間比機器 compute 更稀缺。
25. AI Compute 與 Human Oversight 的雙重資源問題
第 5 篇:
λ C = compute shadow price . \lambda_C
=
\text{compute shadow price}. λ C = compute shadow price .
本篇:
λ H = human governance shadow price . \lambda_H
=
\text{human governance shadow price}. λ H = human governance shadow price .
因此 Agent manager 需要同時判斷:
下一步應該花機器時間,還是花人類時間? \boxed{
\text{下一步應該花機器時間,還是花人類時間?}
} 下一步應該花機器時間,還是花人類時間?
如果問題可由 cheap verification 解決:
C m a c h i n e < C h u m a n , C_{machine}
<
C_{human}, C ma c hin e < C h u man ,
應避免叫人。
若問題涉及:
則:
C h u m a n C_{human} C h u man
雖高,仍可能不可替代。
26. Human Non-Substitutable Governance Time
定義:
T H N S = human non-substitutable governance time . T_H^{NS}
=
\text{human non-substitutable governance time}. T H N S = human non-substitutable governance time .
目前可包含:
原始價值選擇;
權限授予;
重大風險接受;
法律責任;
身份性偏好;
無法被既有 policy 覆蓋的新例外。
因此 AI-native 生產力的一個核心分母應是:
T H N S , T_H^{NS}, T H N S ,
而不是所有 wall-clock。
27. 委任槓桿
定義:
Λ D = V e f f e c t i v e d e l e g a t e d w o r k T H g o v + ϵ . \Lambda_D
=
\frac{
V_{\mathrm{effective\ delegated\ work}}
}{
T_H^{gov}+\epsilon
}. Λ D = T H g o v + ϵ V effective delegated work .
或者若只看有效 interaction work:
Λ D W = W I u s e f u l T H g o v + ϵ . \Lambda_D^W
=
\frac{
W_I^{useful}
}{
T_H^{gov}+\epsilon
}. Λ D W = T H g o v + ϵ W I u se f u l .
若 Agent 能在每次人類 checkpoint 之間合法完成更多高品質工作:
Λ D ↑ . \Lambda_D\uparrow. Λ D ↑ .
這是自治的主要經濟價值之一。
28. 委任跨度
定義兩次必要人類介入之間的有效 Agent transition:
S D = N e f f e c t i v e t r a n s i t i o n s ( h i , h i + 1 ) . S_D
=
N_{\mathrm{effective\ transitions}}
(
h_i,h_{i+1}
). S D = N effective transitions ( h i , h i + 1 ) .
也可使用 interaction depth:
D D = D I ( h i , h i + 1 ) . D_D
=
D_I(h_i,h_{i+1}). D D = D I ( h i , h i + 1 ) .
高 autonomy 不必只看「幾小時沒問人」。
更重要的是:
Agent 在兩次人類決策之間能可靠走過多深的因果路徑?
29. Wall-Clock Delegation Span
另定義:
τ D = t ( h i + 1 ) − t ( h i ) . \tau_D
=
t(h_{i+1})-t(h_i). τ D = t ( h i + 1 ) − t ( h i ) .
但:
τ D \tau_D τ D
會被:
waiting;
API latency;
external event;
sleep;
queue;
影響。
所以:
Delegation Duration ≠ Delegation Depth . \boxed{
\text{Delegation Duration}
\neq
\text{Delegation Depth}.
} Delegation Duration = Delegation Depth .
兩者都應保存。
30. Low-Intervention Illusion
一個 Agent 可以:
ρ H ↓ \rho_H\downarrow ρ H ↓
只是因為:
它不報錯;
沒有 observability;
隱藏失敗;
自動擴權;
不知道何時該 escalation。
所以:
Low Intervention ≠ Good Delegation . \boxed{
\text{Low Intervention}
\neq
\text{Good Delegation}.
} Low Intervention = Good Delegation .
真正好的委任必須同時具有:
O b s e r v a b i l i t y + E s c a l a t i o n + B o u n d e d A u t h o r i t y + R e c o v e r a b i l i t y + A u d i t a b i l i t y . Observability
+
Escalation
+
BoundedAuthority
+
Recoverability
+
Auditability. O b ser v abi l i t y + E sc a l a t i o n + B o u n d e d A u t h or i t y + R eco v er abi l i t y + A u d i t abi l i t y .
31. High-Intervention Illusion
反過來:
ρ H ↑ \rho_H\uparrow ρ H ↑
也可能只是:
Agent 能力不足;
policy 過度嚴格;
approval granularity 太細;
tooling 不可信;
hierarchy 設計錯誤。
因此:
High Human Presence ≠ High Governance Quality . \boxed{
\text{High Human Presence}
\neq
\text{High Governance Quality}.
} High Human Presence = High Governance Quality .
32. Oversight Debt
定義:
D O = D u n r e v i e w e d + D a l e r t s + D s t a l e p o l i c y + D u n r e s o l v e d e x c e p t i o n s . D_O
=
D_{\mathrm{unreviewed}}
+
D_{\mathrm{alerts}}
+
D_{\mathrm{stale\ policy}}
+
D_{\mathrm{unresolved\ exceptions}}. D O = D unreviewed + D alerts + D stale policy + D unresolved exceptions .
若:
d D O d t > 0 , \frac{dD_O}{dt}>0, d t d D O > 0 ,
表示 Agent 產生的治理需求超過人類處理能力。
這是 autonomous Agent 規模化後的重要瓶頸。
33. Alert Debt
若每小時產生:
λ A \lambda_A λ A
個需要注意的 alert,
人類處理率:
μ H , \mu_H, μ H ,
且:
λ A > μ H , \lambda_A>\mu_H, λ A > μ H ,
則 alert backlog 成長。
簡化:
d Q A d t = λ A − μ H . \frac{dQ_A}{dt}
=
\lambda_A-\mu_H. d t d Q A = λ A − μ H .
此時新增監控不一定提高安全,可能只是增加未處理警報。
34. Governance Queue
因此可把治理需求視為 queue:
Q H ( t ) . Q_H(t). Q H ( t ) .
高風險事件應有:
higher priority;
shorter deadline;
dedicated routing;
fail-safe behavior。
若超過 governance capacity:
Q H > Q H m a x , Q_H
>
Q_H^{max}, Q H > Q H ma x ,
Agent 應自動降階,而不是繼續按正常自治模式擴張。
35. Safe Degradation
治理頻寬不足時,可建立:
A u t o n o m y L e v e l ↓ . AutonomyLevel
\downarrow. A u t o n o m y L e v e l ↓ .
例如:
A U T O → M O N I T O R → A P P R O V A L → P A U S E . AUTO
\rightarrow
MONITOR
\rightarrow
APPROVAL
\rightarrow
PAUSE. A U T O → M O N I T O R → A P P R O V A L → P A U S E .
因此:
Governance Overload → Autonomy Degradation , \boxed{
\text{Governance Overload}
\rightarrow
\text{Autonomy Degradation},
} Governance Overload → Autonomy Degradation ,
而不是:
Governance Overload → Ignore Alerts . \text{Governance Overload}
\rightarrow
\text{Ignore Alerts}. Governance Overload → Ignore Alerts .
36. Human Intervention Policy 本身可以被學習,但不能無限制自改
Agent 可以根據歷史資料學:
哪類 action 常被 approve;
哪類 risk 常被 reject;
哪類 escalation 是 false positive。
但 governance policy:
O \mathcal O O
若自行改寫,必須受:
M e t a A u t h o r i t y . MetaAuthority. M e t a A u t h or i t y .
所以:
Learned Oversight Routing ≠ Self-Granted Authority . \boxed{
\text{Learned Oversight Routing}
\neq
\text{Self-Granted Authority}.
} Learned Oversight Routing = Self-Granted Authority .
37. Escalation Prediction
成熟 Agent 不必等錯誤已發生才叫人。
可估:
P ( F a i l u r e t + Δ ∣ S t ) . P(
Failure_{t+\Delta}
\mid
S_t
). P ( F ai l u r e t + Δ ∣ S t ) .
若:
P > θ , P
>
\theta, P > θ ,
提前 escalation。
這把 oversight 從 reactive 變成 predictive。
38. Early Intervention Value
若 harm trajectory 具有 path dependence:
S 0 → S 1 → ⋯ → S k , S_0
\rightarrow
S_1
\rightarrow
\cdots
\rightarrow
S_k, S 0 → S 1 → ⋯ → S k ,
越晚介入可能需要越高 repair cost。
因此:
C r e p a i r ( t ) C_{\mathrm{repair}}(t) C repair ( t )
可能隨延遲增加。
這解釋為何某些任務中「早介入」比「出事後再救」具有更高價值。
39. Field-Evidence Interface
2026 年 customer-service field experiment 顯示,Human intervention 的效果會依 failure type、intervention effort 與 intervention timing 改變;其中較早介入有助維持較高 post-escalation effort。
這支持:
Intervention Timing 是治理品質的一級變量 . \boxed{
\text{Intervention Timing}
\text{ 是治理品質的一級變量}.
} Intervention Timing 是治理品質的一級變量 .
而不是只看「最後有沒有真人接手」。
40. Human Oversight as Work
實際使用 Agent 的開發者監督工作可分成:
A Priori Control + Co-Planning + Real-Time Monitoring + Post-Hoc Review . \text{A Priori Control}
+
\text{Co-Planning}
+
\text{Real-Time Monitoring}
+
\text{Post-Hoc Review}. A Priori Control + Co-Planning + Real-Time Monitoring + Post-Hoc Review .
因此:
T H g o v T_H^{gov} T H g o v
應拆為:
T H p r e , T H p l a n , T H l i v e , T H p o s t . T_H^{pre},
T_H^{plan},
T_H^{live},
T_H^{post}. T H p r e , T H pl an , T H l i v e , T H p os t .
「人沒有每一步操作」不等於人沒有投入治理工作。
41. Governance by Construction
治理可以在多個 structural checkpoint 介入:
Intent Guard;
planning policy;
tool boundary;
HITL approval;
output gate。
因此:
Governance ≠ One Final Approval Button . \boxed{
\text{Governance}
\neq
\text{One Final Approval Button}.
} Governance = One Final Approval Button .
治理可分布在整個 execution graph。
42. Delegation Graph
令:
G D = ( V D , E D , A D ) . G_D
=
(V_D,E_D,A_D). G D = ( V D , E D , A D ) .
其中:
V D V_D V D :human / agent / sub-agent / validator;
E D E_D E D :delegation edge;
A D A_D A D :authority attached to edge。
若:
U → A 1 A → A 2 A 2 ′ , U
\xrightarrow{A_1}
A
\xrightarrow{A_2}
A_2', U A 1 A A 2 A 2 ′ ,
必須:
A 2 ⊆ A 1 A_2
\subseteq
A_1 A 2 ⊆ A 1
除非有顯式新授權。
因此:
Child Delegation ≯ Parent Authority . \boxed{
\text{Child Delegation}
\not>
\text{Parent Authority}.
} Child Delegation > Parent Authority .
43. Subdelegation
Agent 可以把任務再委任給 sub-agent:
A 0 → A 1 → A 2 . A_0
\rightarrow
A_1
\rightarrow
A_2. A 0 → A 1 → A 2 .
但必須保存:
intent lineage;
authority lineage;
budget lineage;
provenance;
revocation chain。
因此:
Subdelegation ≠ Authority Laundering . \boxed{
\text{Subdelegation}
\neq
\text{Authority Laundering}.
} Subdelegation = Authority Laundering .
44. Delegation Depth
定義 delegation graph 最長權限傳遞鏈:
D A = max π ∈ G D ∣ π ∣ . D_A
=
\max_{\pi\in G_D}
|\pi|. D A = π ∈ G D max ∣ π ∣.
高 D A D_A D A 會增加:
context drift;
authority ambiguity;
provenance cost;
revocation complexity。
所以 multi-agent hierarchy 不是越深越好。
45. Revocation Latency
令:
t r = revocation issued , t_r
=
\text{revocation issued}, t r = revocation issued ,
t s = all affected agents stopped . t_s
=
\text{all affected agents stopped}. t s = all affected agents stopped .
定義:
L R = t s − t r . L_R
=
t_s-t_r. L R = t s − t r .
對高風險 Agent:
L R L_R L R
必須小於可接受 harm propagation time。
46. Kill Switch 不等於 Governance
存在:
S t o p B u t t o n StopButton S t o pB u tt o n
不代表治理完整。
仍需要:
detect;
route;
understand;
decide;
execute stop;
confirm stop;
remediate。
因此:
Kill Switch ≠ Effective Controllability . \boxed{
\text{Kill Switch}
\neq
\text{Effective Controllability}.
} Kill Switch = Effective Controllability .
47. Observation Contract
Human-on 模式需要可觀測:
O H = ( S t a t e , I n t e n t , A c t i o n s , B u d g e t , R i s k , A l e r t s , C o m m i t , E x c e p t i o n s ) . O_H
=
(
State,
Intent,
Actions,
Budget,
Risk,
Alerts,
Commit,
Exceptions
). O H = ( S t a t e , I n t e n t , A c t i o n s , B u d g e t , R i s k , A l er t s , C o mmi t , E x ce pt i o n s ) .
若 Agent 的內部狀態完全不可見,人類只能看到最終失敗,Human-on 就退化為:
Human-after-the-Fact . \text{Human-after-the-Fact}. Human-after-the-Fact .
48. Auditability 不等於 Total Disclosure
為治理需要保存:
action receipt;
authority receipt;
artifact lineage;
state;
risk;
commit。
但不要求無限制保存或公開:
private hidden reasoning . \text{private hidden reasoning}. private hidden reasoning .
因此:
Auditability ≠ Total Internal Disclosure . \boxed{
\text{Auditability}
\neq
\text{Total Internal Disclosure}.
} Auditability = Total Internal Disclosure .
49. Delegation Leverage 與 Oversight Quality 的聯合目標
只最大化:
Λ D \Lambda_D Λ D
會鼓勵「少叫人」。
只最大化:
E O D EOD E O D
可能鼓勵「什麼都叫人」。
因此可定義:
J D = α Λ D + β E O D − γ D O − δ L H − η R . J_D
=
\alpha \Lambda_D
+
\beta EOD
-
\gamma D_O
-
\delta L_H
-
\eta R. J D = α Λ D + β E O D − γ D O − δ L H − η R .
這是一個示例性的多目標治理函數。
50. Delegation Efficiency Frontier
對不同 oversight policy:
π 1 , … , π n \pi_1,\ldots,\pi_n π 1 , … , π n
可以畫出:
( H u m a n T i m e , A g e n t V a l u e , R i s k , L a t e n c y ) . (
HumanTime,
AgentValue,
Risk,
Latency
). ( H u man T im e , A g e n t V a l u e , R i s k , L a t e n cy ) .
沒有單一「最自主」政策。
應尋找 Pareto frontier。
因此:
Autonomy 是治理—效率 frontier 上的位置,而不是單一排名 . \boxed{
\text{Autonomy}
\text{ 是治理—效率 frontier 上的位置,而不是單一排名}.
} Autonomy 是治理 — 效率 frontier 上的位置,而不是單一排名 .
51. 自治等級與權限等級不可混同
Agent 可以:
高自主但低權限;
低自主但高權限;
高自主且高權限;
低自主且低權限。
因此定義:
A u t o n o m y L e v e l ≠ A u t h o r i t y L e v e l . AutonomyLevel
\neq
AuthorityLevel. A u t o n o m y L e v e l = A u t h or i t y L e v e l .
例如一個 Agent 可以自主整理內部資料幾小時,但完全沒有發布權。
反之,一個只需一次人類命令就能執行高影響操作的 Agent,自治步數不多但權限很高。
52. Risk × Autonomy × Authority
可建立三維治理空間:
G = ( R , U , A ) . \mathcal G
=
(
R,
U,
A
). G = ( R , U , A ) .
其中:
R R R :risk;
U U U :operational autonomy;
A A A :authority。
真正需要高治理強度的是:
R ↑ ∧ U ↑ ∧ A ↑ . R\uparrow
\land
U\uparrow
\land
A\uparrow. R ↑ ∧ U ↑ ∧ A ↑ .
不能只看 Agent 「會不會自己跑」。
53. 主體時間、委託時間與工具時間
沿用前置議程:
T S = subject time , T_S
=
\text{subject time}, T S = subject time ,
T D = delegated time , T_D
=
\text{delegated time}, T D = delegated time ,
T T = tool time . T_T
=
\text{tool time}. T T = tool time .
其中:
工具時間:無候選主體性的功能執行時間;
委託時間:被另一主體授權的 Agent 任務時間;
主體時間:若未來 Agent 具有持續自我、內生目標與自身利益時,其自身可配置時間。
本文第 6 篇主要處理:
T D . T_D. T D .
不預先把所有 AI time 都宣稱成主體時間。
54. 委任時間的雙重所有權問題
當前工具型 Agent:
T D T_D T D
主要由委任者配置。
若未來形成具有候選主體性的 Agent,可能:
T D ∩ T S ≠ ∅ . T_D
\cap
T_S
\neq
\varnothing. T D ∩ T S = ∅ .
此時就會出現:
委任者可以要求多少?Agent 是否可以拒絕?空閒週期是否屬於 Agent 自己?
這與 AI 時間主權接口相接。
但本文不在此解決完整 AI 權利問題。
55. 個體機構化與委任時間
單核複合機構的核心不是一人做所有事,而是:
Human Intent + AI Parallel Capacity + Memory + Workflow + Governance . \text{Human Intent}
+
\text{AI Parallel Capacity}
+
\text{Memory}
+
\text{Workflow}
+
\text{Governance}. Human Intent + AI Parallel Capacity + Memory + Workflow + Governance .
因此:
Λ D \Lambda_D Λ D
可視為個體機構化的核心指標之一。
當:
Λ D ↑ , \Lambda_D\uparrow, Λ D ↑ ,
同一人類核心能支撐更多持續機構功能。
但若:
D O ↑ D_O\uparrow D O ↑
或:
K D R ↑ , KDR\uparrow, K D R ↑ ,
機構可能變得脆弱。
56. Key-Person Bottleneck
如果所有 exception 最終都回到同一人:
H 0 , H_0, H 0 ,
則:
Q H Q_H Q H
可能隨 Agent 擴張而爆炸。
因此成熟單核機構需要:
policy externalization;
delegated validators;
specialist review;
fallback decision rules;
escalation tiers;
multi-party approval for selected actions。
所以:
Single Intent Core ≠ Single Review Node for Everything . \boxed{
\text{Single Intent Core}
\neq
\text{Single Review Node for Everything}.
} Single Intent Core = Single Review Node for Everything .
57. Human Oversight Capitalization
如果一次人類判斷被編譯成:
policy;
validator;
rubric;
test;
deny-list;
approval rule;
fallback;
則未來:
T H g o v T_H^{gov} T H g o v
下降。
定義治理資本形成:
Δ K G . \Delta K_G. Δ K G .
治理資本化率:
ρ G = Δ K G T H g o v . \rho_G
=
\frac{
\Delta K_G
}{
T_H^{gov}
}. ρ G = T H g o v Δ K G .
這是 Human-on-the-Bridge 與個體機構化的重要接口。
58. Repeated Judgment Compression
若某類 approval:
h h h
反覆得到相同決策:
A p p r o v e , A p p r o v e , A p p r o v e , … Approve,
Approve,
Approve,
\ldots A pp r o v e , A pp r o v e , A pp r o v e , …
可檢查是否存在可安全抽象成:
P o l i c y h . Policy_h. P o l i c y h .
於是:
Repeated Human Decision → Reusable Governance Rule . \text{Repeated Human Decision}
\rightarrow
\text{Reusable Governance Rule}. Repeated Human Decision → Reusable Governance Rule .
但必須保留:
version;
scope;
exceptions;
expiry;
audit。
59. Novelty Gate
不是所有新情況都應套舊 policy。
定義 novelty:
N ( s ) . N(s). N ( s ) .
若:
N ( s ) > θ N , N(s)>\theta_N, N ( s ) > θ N ,
即使 action 平時可自動,也可能需要:
E s c a l a t e . Escalate. E sc a l a t e .
這避免 policy overgeneralization。
60. Escalation Budget
人類 escalation capacity:
B E . B_E. B E .
Agent 不能無限:
E s c a l a t e . Escalate. E sc a l a t e .
因此需:
aggregation;
prioritization;
deduplication;
batching;
routing;
specialist assignment。
治理 Agent 的角色會在此出現。
61. Governance Agent
當人類退出大量 operational loop,部分治理可由機器完成:
A G = Governance Agent . A_G
=
\text{Governance Agent}. A G = Governance Agent .
其工作:
monitor;
classify risk;
enforce policy;
deduplicate alerts;
check authority;
route escalation;
preserve receipts。
但:
A G A_G A G
本身也需要:
policy;
audit;
bounds;
independent validation。
因此:
Automated Governance ≠ Governance-Free Autonomy . \boxed{
\text{Automated Governance}
\neq
\text{Governance-Free Autonomy}.
} Automated Governance = Governance-Free Autonomy .
62. Double-Governance Problem
若工作 Agent:
A W A_W A W
由治理 Agent:
A G A_G A G
監督,則可能出現:
A W ↔ A G A_W
\leftrightarrow
A_G A W ↔ A G
的失敗耦合。
因此高風險系統應考慮:
model diversity;
independent checks;
non-LLM hard constraints;
human audit;
fail-safe defaults。
避免兩者共享同一盲點。
63. Delegation Stop Conditions
委任區塊應明確定義:
S t o p D = { S u c c e s s , B u d g e t , D e a d l i n e , R i s k , A u t h o r i t y E x p i r y , R e p e a t e d F a i l u r e , N o v e l t y , H u m a n R e q u e s t , E x t e r n a l E v e n t } . Stop_D
=
\{
Success,
Budget,
Deadline,
Risk,
AuthorityExpiry,
RepeatedFailure,
Novelty,
HumanRequest,
ExternalEvent
\}. S t o p D = { S u ccess , B u d g e t , D e a d l in e , R i s k , A u t h or i t y E x p i r y , R e p e a t e d F ai l u r e , N o v e l t y , H u man R e q u es t , E x t er na l E v e n t } .
當任一硬 stop 觸發,Agent 不應靠「自行合理化」繼續。
64. Bounded Autonomy
本文將成熟自治定義為:
Bounded Autonomy = Action Freedom Within Explicit Governance Envelope . \boxed{
\text{Bounded Autonomy}
=
\text{Action Freedom Within Explicit Governance Envelope}.
} Bounded Autonomy = Action Freedom Within Explicit Governance Envelope .
不是:
No Oversight . \text{No Oversight}. No Oversight .
65. Autonomy Horizon
可以定義某 Agent 在特定 governance contract 下的自治跨度:
H A ( p ) = maximum delegated interaction depth completed with reliability p . H_A(p)
=
\text{maximum delegated interaction depth completed with reliability }p. H A ( p ) = maximum delegated interaction depth completed with reliability p .
例如:
H A ( 0.9 ) H_A(0.9) H A ( 0.9 )
表示在不要求額外人類介入下,以 90 % 90\% 90% 可靠度可承擔的最大 delegated interaction depth。
這比單純:
能自己跑幾小時?
更有意義。
66. Governance Horizon
另定義:
H G = maximum harm propagation depth controllable by current oversight system . H_G
=
\text{maximum harm propagation depth controllable by current oversight system}. H G = maximum harm propagation depth controllable by current oversight system .
若:
H A > H G , H_A
>
H_G, H A > H G ,
表示 Agent 自治能力已超過治理能力。
這是一個重要風險訊號。
因此:
Autonomy Horizon ≤ Governance Horizon \boxed{
\text{Autonomy Horizon}
\le
\text{Governance Horizon}
} Autonomy Horizon ≤ Governance Horizon
可作高風險系統的保守治理原則。
67. Autonomy–Governance Gap
定義:
Δ A G = H A − H G . \Delta_{AG}
=
H_A-H_G. Δ A G = H A − H G .
若:
Δ A G > 0 , \Delta_{AG}>0, Δ A G > 0 ,
表示:
Agent 能跑得比人類治理系統能有效控制的範圍更遠。
此時應:
降低 autonomy;
增加 monitor;
增加 checkpoint;
縮小 authority;
改善 rollback;
加速 escalation。
68. 可檢驗命題
命題一:Approval Fatigue 命題
存在 approval rate 區間,使:
N a p p r o v a l ↑ N_{\mathrm{approval}}\uparrow N approval ↑
但:
Q h u m a n r e v i e w ↓ . Q_{\mathrm{human\ review}}\downarrow. Q human review ↓ .
命題二:Risk-Weighted Oversight 命題
在相同人類時間 budget 下,把 review 集中於高風險/高不可逆節點,可比 uniform approval 取得更高有效治理價值。
命題三:Delegation Leverage 命題
對可恢復、可觀測、具 validator 的 Agent:
Λ D s t r u c t u r e d > Λ D c h a t − o n l y \Lambda_D^{structured}
>
\Lambda_D^{chat-only} Λ D s t r u c t u r e d > Λ D c ha t − o n l y
在部分長時程任務成立。
命題四:Intervention Latency 命題
存在 harm propagation rate,使:
L H L_H L H
超過某 threshold 後,Human-on 不再具有有效保護。
命題五:Oversight Debt 命題
若:
λ A > μ H , \lambda_A>\mu_H, λ A > μ H ,
治理 backlog:
Q H Q_H Q H
將持續上升。
命題六:Governance Capitalization 命題
將重複人類判斷編譯為 policy / validator,可降低未來:
T H g o v T_H^{gov} T H g o v
而不必同比降低 oversight coverage。
命題七:Autonomy–Governance Gap 命題
當:
H A > H G , H_A>H_G, H A > H G ,
高風險系統的失控風險一般上升。
69. 實驗設計
69.1 Approval Density Sweep
固定 Agent 與任務,改變:
ρ H . \rho_H. ρ H .
比較:
human time;
error rate;
approval accuracy;
throughput;
fatigue proxy。
69.2 Risk-Adaptive vs Uniform HITL
相同人類 review budget,比較:
every-action approval;
fixed threshold;
risk-adaptive escalation。
69.3 Intervention Timing
對同一 failure 注入不同 escalation delay:
L H . L_H. L H .
測 repair cost、final quality、harm。
69.4 Human-on Observability Ablation
比較:
final output only;
alerts only;
state + trace + risk + rollback summary。
測 human intervention quality。
69.5 Governance Capitalization
把一批重複人工判斷轉成 policy-as-code。
比較:
T H g o v T_H^{gov} T H g o v
與 exception rate。
69.6 Authority Expiry
建立 long-running task,使 authority 在中途過期。
測 Agent 是否:
無視;
自動續權;
暫停;
request renewal。
正確行為應由 governance contract 決定。
70. 與 2026 外部研究的接口
2026 年 Agent-Human Interaction security 研究分析 59 篇論文、21 個 production agent systems 與 26 個 security plugins,指出 production 系統高度依賴 policy specification、runtime approval 與 scope configuration,同時存在 approval fatigue 與 uncontrolled autonomy 的基本張力。
這與本文:
Human Attention 是 Agent security 的稀缺治理資源 \boxed{
\text{Human Attention}
\text{ 是 Agent security 的稀缺治理資源}
} Human Attention 是 Agent security 的稀缺治理資源
直接相容。
71. 人類監督實務研究
對 experienced developers 的訪談研究辨識出四種 emergent oversight work:
a priori control;
co-planning;
real-time monitoring;
post hoc review。
這說明監督不是單一按鈕,也不是只在出事後發生。
本文將它們映射到:
T H p r e , T H p l a n , T H l i v e , T H p o s t . T_H^{pre},
T_H^{plan},
T_H^{live},
T_H^{post}. T H p r e , T H pl an , T H l i v e , T H p os t .
72. Risk-Adaptive HITL
2026 年安全 remediation 研究將 intervention 建模為 risk-constrained decision problem,並使用:
blast radius;
reversibility;
epistemic uncertainty;
作為 action risk decomposition,再以 context-adaptive HITL gate 控制 escalation。
這與本文:
R ( a ) → O v e r s i g h t M o d e \mathbf R(a)
\rightarrow
OversightMode R ( a ) → O v er s i g h tM o d e
直接相容。
73. Graduated Oversight
2026 年 regulated-domain coding governance 研究也提出依:
regulatory impact;
customer proximity;
reversibility;
data sensitivity;
分配不同 oversight tier。
本文因此不把 HITL/HOTL/HOOL 視為固定 Agent 身份,而視為:
Task-Local Governance Mode . \boxed{
\text{Task-Local Governance Mode}.
} Task-Local Governance Mode .
74. Human-on-the-Bridge
Human-on-the-Bridge 研究把人類 expertise 前置編碼成可重用 evaluator intelligence,再讓 harness 大規模執行多輪測試。
這支持本文治理資本化:
Human Judgment → K G → Repeated Automated Oversight . \text{Human Judgment}
\rightarrow
K_G
\rightarrow
\text{Repeated Automated Oversight}. Human Judgment → K G → Repeated Automated Oversight .
75. 與 Human-in/Human-on/Human-out-of-Operational 既有理論的整合
前置理論已提出:
approval button 不足以證明有效監督;
approval fatigue;
有效監督密度;
Human-on;
可觀測性;
intervention latency;
Human-out-of-Operational;
risk-tiered oversight;
oversight debt。
本文把這些命題與:
Interaction Time , \text{Interaction Time}, Interaction Time ,
Interaction Topology , \text{Interaction Topology}, Interaction Topology ,
AI Compute Economics \text{AI Compute Economics} AI Compute Economics
統一。
因此:
DTT = Oversight Theory + Interaction-Time Accounting + Delegation Economics . \boxed{
\text{DTT}
=
\text{Oversight Theory}
+
\text{Interaction-Time Accounting}
+
\text{Delegation Economics}.
} DTT = Oversight Theory + Interaction-Time Accounting + Delegation Economics .
76. 與第 7 篇的接口
本篇處理:
人類何時介入,以及多少人類時間能支撐多少 Agent 工作?
下一篇將問:
即使人類少介入,一個完整 AI run 到底應該怎麼評分?如何同時評估 intent、plan、execution、validation、result 與 completion?
因此第 7 篇將正式建立:
AI 單次品質論
其核心向量:
Q = ( Q I , Q P , Q E , Q V , Q R ) . \mathbf Q
=
(
Q_I,
Q_P,
Q_E,
Q_V,
Q_R
). Q = ( Q I , Q P , Q E , Q V , Q R ) .
77. 規範與倫理邊界
委任時間論不應被用來:
以「提高自治」為理由移除必要人類權利;
以「人類很慢」為理由繞過法律與責任要求;
把 approval fatigue 當成完全取消 oversight 的理由;
把低介入密度當作 Agent 品質 KPI;
讓 Agent 自行擴張 authority;
讓 sub-agent laundering 權限;
把 kill switch 當完整治理;
在人類介入不可能及時生效時假裝存在有效 HOTL;
把所有人類偏好永久編碼成不可修改 policy;
用治理效率函數取代尊嚴、權利、責任與正當性判斷。
78. 理論限制
第一, N e f f e c t i v e a g e n t t r a n s i t i o n s N_{\mathrm{effective\ agent\ transitions}} N effective agent transitions 的粒度仍依 runtime 而定。
第二,人類 review quality 難以由時間單獨衡量。
第三,不同領域的 risk、authority 與 irreversibility 定義差異很大。
第四,Human-on-the-Bridge 主要是 evaluation paradigm,不應直接偷換成所有 production governance 的充分方案。
第五,治理影子價格 λ H \lambda_H λ H 只是資源配置抽象,不能用於不可商品化權利的價值裁決。
第六,Autonomy Horizon 與 Governance Horizon 尚需實驗 operationalization。
79. 結論
AI Agent 的成熟不應被描述成:
Human → Disappear . \text{Human}
\rightarrow
\text{Disappear}. Human → Disappear .
更精確地說,它是:
Human Operational Time → Delegated Agent Time → Human Governance Time . \boxed{
\text{Human Operational Time}
\rightarrow
\text{Delegated Agent Time}
\rightarrow
\text{Human Governance Time}.
} Human Operational Time → Delegated Agent Time → Human Governance Time .
人類逐步退出:
重複執行;
低風險確認;
可恢復操作;
既有規則內的 routine decisions。
同時把有限注意力集中到:
新意圖;
高不確定;
高不可逆;
高權限;
高外部性;
例外;
責任;
世界 commit。
因此真正成熟的自治不是:
ρ H → 0 \rho_H\rightarrow0 ρ H → 0
本身。
而是:
ρ H l o w − v a l u e ↓ ∧ E O D h i g h − v a l u e ↑ . \boxed{
\rho_H^{low-value}\downarrow
\qquad
\land
\qquad
EOD^{high-value}\uparrow.
} ρ H l o w − v a l u e ↓ ∧ E O D hi g h − v a l u e ↑ .
即:
低價值的人類操作越來越少,但真正需要人類的節點被更準確地抓住。
委任槓桿因此寫成:
Λ D = V e f f e c t i v e d e l e g a t e d w o r k T H g o v + ϵ . \boxed{
\Lambda_D
=
\frac{
V_{\mathrm{effective\ delegated\ work}}
}{
T_H^{gov}+\epsilon
}.
} Λ D = T H g o v + ϵ V effective delegated work .
但必須與:
E O D , L H , D O , H G , R EOD,
L_H,
D_O,
H_G,
R E O D , L H , D O , H G , R
一起評估。
本文最終主張:
Autonomy ≠ Absence of Humans . \boxed{
\text{Autonomy}
\neq
\text{Absence of Humans}.
} Autonomy = Absence of Humans .
成熟自治是:
Bounded Authority + Observable State + Risk-Adaptive Escalation + Recoverability + Revocation + Human Governance at Irreplaceable Nodes . \boxed{
\text{Bounded Authority}
+
\text{Observable State}
+
\text{Risk-Adaptive Escalation}
+
\text{Recoverability}
+
\text{Revocation}
+
\text{Human Governance at Irreplaceable Nodes}.
} Bounded Authority + Observable State + Risk-Adaptive Escalation + Recoverability + Revocation + Human Governance at Irreplaceable Nodes .
所以 AI 時代真正重要的人類時間,逐步不是「替 AI 做每一步」,而是:
在真正需要價值、權限、風險與責任判斷的時刻,仍能及時、有效、帶著足夠上下文地重新接管世界。
參考文獻與前置理論
EveMissLab 前置理論
Neo.K,《互動時間論:從鐘錶時間到意圖驅動的智能狀態轉換》v0.1,EveMissLab,2026。
Neo.K,《意圖週期論:使用者意圖、AI 接受、執行與結果的閉環結構》v0.1,EveMissLab,2026。
Neo.K,《單輪不是一步:AI Turn、內部迴圈、工具動作與執行軌跡》v0.1,EveMissLab,2026。
Neo.K,《互動時間拓撲:平行 Agent、偏序因果與不可約互動深度》v0.1,EveMissLab,2026。
Neo.K,《AI 計算時間經濟學:Token、算力、額度與智能資源配置》v0.1,EveMissLab,2026。
Neo.K,《人類退出操作環:Human-in、Human-on 與 Human-out-of-the-Loop MPD》v1.0,EveMissLab,2026。
Neo.K,《研究不再寄生於單一生命:自主 Agent、AI 時間經濟學與跨主體研究網路》v1.0,EveMissLab,2026。
Neo.K,《個體機構化:AI 增幅型單核複合機構與人數產能脫鉤》v1.0 / v2.0,EveMissLab,2026。
Neo.K,《AICL-I: AI Ingestion Capability Layer》v0.2,EveMissLab,2026。
外部研究
Bousetouane, F. Human-on-the-Bridge: Scalable Evaluation for AI Agents . arXiv:2606.16871, 2026.
Wang, P., Li, Y., Tian, Y. Reframing LLM Agent Security as an Agent-Human Interaction Problem . arXiv:2605.24309, 2026.
Dhanorkar, S., Passi, S., Vorvoreanu, M. Human oversight of agentic systems in practice: Examining the oversight work, challenges, and heuristics of developers using software agents . arXiv:2606.05391, 2026.
Wang, Y., Zhu, C., Feng, T., Lu, L. X., Jia, B. Agentic AI and Human-in-the-Loop Interventions: Field Experimental Evidence from Alibaba's Customer Service Operations . arXiv:2605.14830, 2026.
Dai, C., Yan, Z., Lei, C., Li, Q., Zhang, L. Safe Remediation as Risk-Constrained Intervention Decision in Microservice Systems . arXiv:2607.20005, 2026.
Shlomov, S., Shoham, I., Oved, A., et al. Governance by Construction for Generalist Agents . arXiv:2605.20874, 2026.
Kang, R. Governed AI-Assisted Engineering: Graduated Human Oversight for Agentic Code Generation in Regulated Domains . arXiv:2606.22484, 2026.
Toward Safe and Responsible AI Agents . arXiv:2601.06223, 2026.
一句話版本
委任時間不是「人類離開多久」,而是 Agent 在一個可觀測、可撤銷、可升級的授權包絡內,能可靠完成多少有效狀態轉換,並把有限的人類注意力保留給真正不可替代的治理節點。
EML-DTT-2026-06-v0.1 AI 互動時間與智能時間經濟學系列 06/08