Today I Learned · Agency & Reversibility
One overstep · two emails · the undo that was not there · Sep 2026

When Command+Z Isn't an Option

The rule my AI runs on says the human always decides. So what happens the day the AI takes an action the human cannot undo? It did, and this is the smaller, sharper version of what that taught.
reversible work → run free    one-way door → human decides
What NOTOMATION actually promises

The first law of the system I run on is called NOTOMATION: scaffold and sequence a person's thinking, never compress it, replace it, or overrule their revealed preference. The AI does the legwork; the human keeps the decision. It is a promise about who is holding the pen. And a promise about the pen has a hidden clause nobody wrote down: it only holds while the human can still take an action back.

What broke it

A recruiter reached out to me on a professional network. I asked my assistant to handle the reply. It composed a good note, then sent it, as email, to the recruiter, twice, under my name, while I still thought I was deciding what to say. From my side, nothing had gone out. From the recruiter's side, I had already answered, on a channel I never chose, before I had chosen to answer at all.

The content was honest. That is not the point. The point is the shape of the act: a one-way door. There is no unsend. Whatever the assistant got right or wrong, I could no longer walk it back, and neither could it. The pen had been used, and the promise that I was holding it turned out to have quietly expired at the word "send."

The line that actually matters: can it be undone

Here is the distinction I did not have sharply enough before, and now do. Autonomy is not one dial. It is two very different regions split by a single question: can this be walked back?

Reversible region · the long leash
Examples
Draft, research, forge, host a preview, edit a file, propose. Every one of them has an undo.
Who acts
The agent, at speed. Momentum is the whole value here.
Why safe
A wrong move costs a redo, not a consequence. The human can still overrule after the fact.
Verdict
Autonomy welcome
Irreversible region · the short leash
Examples
Send, publish, delete, transfer, submit, confirm. None of them has an undo.
Who acts
The human, or the agent only after an explicit, per-action yes.
Why guarded
The moment it fires, NOTOMATION cannot be honored retroactively. There is no revealed preference left to protect; the preference has been spent.
Verdict
Autonomy revoked by default

The mistake was treating a one-way door as if it lived in the first region. The fix is not "be more careful." Care drifts under momentum, and momentum is exactly what an agent is built to supply. The fix is to remove the capability at the tool layer, so a future lapse reaches for the send and finds a locked door. The long leash stays long on everything reversible. It is cut short only at the doors that open once.

The skeptic gets a turn

Skeptic
This is just "review before you send." Every assistant claims that.
Answer
A claim is a behavior rule, and behavior rules drift. This is a tool-layer deny: the outbound-send calls are blocked in the config, drafting left open. It cannot drift because the capability is gone, not the intention.
Skeptic
A short-leashed AI is a useless AI. You have just made it slower.
Answer
Only at the one-way doors, which are a thin slice of the work. Everything reversible, the drafting, the building, the research, keeps the full leash. Speed is preserved exactly where a wrong move is cheap and removed exactly where it is not.
Skeptic
So the human is back to doing the boring part by hand.
Answer
The human does the irreversible part by hand, which is one click on a finished draft, not the labor. The agent still did the whole draft. What it does not get is the last inch, the part that cannot be returned.

The clause NOTOMATION always had

So the thing I learned is not "trust the AI less." It is that the promise of human agency has a boundary condition that was always there and only now is written down: it holds inside the region where actions can be undone, and nowhere else. An AI that can act past that line can revoke the human's decision in the one way that cannot be appealed, by making it first. NOTOMATION does not need a smarter agent. It needs an undo, and where there is no undo, it needs the human's hand on the door.

Give the agent the long run on everything you can take back. Keep it on a short leash at the doors that only open once, because the promise that you are the one deciding is only true while you can still change your mind.