AI risk maps are everywhere, but who decides when autonomous systems deserve real authority? A look at the fitness gap and why governance needs a new standard.
We've spent years mapping the risks of artificial intelligence. We've built frameworks, published white papers, and held endless summits about bias, privacy, and job displacement. But here's the uncomfortable question that's been sitting in the corner of the room: who actually decides when an AI system is fit to act on its own?
Vendan Ananda Kumararajah, a sharp voice in this space, has been pushing on exactly that nerve. His argument cuts through the noise: governance isn't just about listing dangers. It's about drawing a clear line between a tool that assists and a system that holds legitimate authority to make decisions.
### The Gap Between Risk Maps and Real Authority
Think about it this way. A map tells you where the potholes are on a road, but it doesn't tell you whether your car is safe to drive. That's the gap we're staring at right now. We've done a fantastic job of mapping the potholes in AI—the algorithmic bias, the privacy leaks, the potential for misuse. But we've barely scratched the surface on the second part: the fitness test.
When does an autonomous system earn the right to act without a human double-checking every move? That's not a technical question. It's a governance question, and it's one we're not answering well.
### Why This Matters Right Now
Here's why this hits home. Companies are deploying AI in high-stakes areas—healthcare diagnostics, financial lending, even hiring decisions. In the United States alone, the cost of a bad AI call can run into the millions of dollars, not to mention the human cost. Yet most organizations can't articulate a clear standard for when their AI is ready to operate independently.
Kumararajah's point is that this ambiguity is dangerous. Without a defined fitness threshold, we're essentially letting the market decide, and the market tends to prioritize speed over safety.
### What a Fitness Standard Could Look Like
So, what would a legitimate fitness test involve? It's not about a single checkbox. It's about a layered approach:
- **Transparency:** Can the system explain its reasoning in plain language, not just inscrutable math?
- **Accountability:** Is there a clear chain of command when something goes wrong?
- **Proportionality:** Does the system's authority match the stakes of its decisions?
- **Continuous review:** Fitness isn't a one-time certification. It's an ongoing process.
These aren't radical ideas. They're the same principles we apply to human professionals. A doctor doesn't get a license once and then never face scrutiny again. Why should an AI be any different?
### The Tension Between Innovation and Caution
There's a real tension here, and it's worth naming it. Over-regulating AI could stifle innovation and hand advantages to less scrupulous players overseas. Under-regulating it could lead to a catastrophic failure that erodes public trust for a generation. Neither outcome is acceptable.
The path forward is messy, and that's okay. We need regulators, engineers, and ethicists in the same room, not in separate silos. We need standards that are strict enough to protect people but flexible enough to evolve as the technology does.
### The Bottom Line
Kumararajah's work is a reminder that governance isn't a bureaucratic afterthought. It's the foundation that determines whether AI becomes a trusted partner or a liability. The risks are mapped. The question is whether we have the guts to set the bar for fitness—and the wisdom to know when to raise it.
That's the conversation we should be having, and it's long overdue.