AI Agent Readiness Checklist: The Decision Rights Test You Now Have to Pass

AI agent readiness checklist decision rights framework by Elevates.AI

Most AI agent readiness checklist templates in circulation ask about data quality, model choice, and integration surface. Those are fair questions. They skip the one a regulator has now made mandatory, which is what your agent is allowed to decide when no human is watching.

On July 15, 2026, that stopped being a matter of internal preference.

What Article 6 actually requires

The Cyberspace Administration of China, the National Development and Reform Commission, and the Ministry of Industry and Information Technology jointly issued the Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents on May 8, 2026. The rules became enforceable on July 15. They are the first national framework anywhere to treat AI agents as their own regulated category rather than as an extension of model rules.

Article 6 is the part that matters for readiness. Before an agent is deployed, its decision authority has to be documented and sorted into three tiers. Decisions only a human may make. Decisions the agent may propose but may execute only after user approval. Decisions the agent may handle alone inside a delegated scope. The user keeps the right to be informed and the final say.

Article 7 adds the harder half. Those tiers have to be verifiable and traceable after the fact. The outcome, the rationale, and the approval record for every action need to survive somewhere an auditor can reach them.

Article 11 sets oversight by sector. Healthcare, transportation, media, and public safety carry registration, compliance testing, and product recall provisions. Lower-risk sectors such as lifestyle and entertainment run on self-assessment and industry self-regulation. Full coverage of the enforcement timeline is available from the AI Governance Institute.

Legal commentary inside China compresses the liability principle into a phrase that translates as look at control, not code. Responsibility falls on whoever actually controlled the agent’s behavior, which in practice is the company that deployed and operated it rather than the company that wrote the model.

This is a readiness requirement, not a legal one

Read Article 6 again with the legal framing stripped out. It asks you to produce a map of which decisions in your business belong to a person, which need a person’s sign-off, and which can be delegated to software. That map is an operating model artifact. Legal can review it. Legal cannot author it.

Most companies have never drawn it. The Kyndryl 2026 People Readiness Report, a survey of 1,100 senior business and technology leaders across eight countries published June 25, 2026, found that 33 percent of organizations claim clear policies on which decisions AI can and cannot make. In the same study, 81 percent expect AI agents to make impactful decisions for their organizations within the next year.

Eighty-one percent are preparing to hand over consequential decisions. Thirty-three percent can name which ones.

If you want to see where your decision rights actually sit before you write a tiering document, the free 60-second assessment scores governance and oversight as a named dimension and returns the gaps in plain language.

That gap is the readiness gap, and it does not close with a policy memo. You cannot tier decision authority you have never mapped, and you cannot map decision authority without first knowing where those decisions sit today.

The AI agent readiness checklist, in five parts

Treat each part as pass or fail. Partial credit is how organizations end up believing they are ready.

One. Decision inventory. List every decision the agent will touch in its intended workflow, not every task it will perform. A decision has an owner, a consequence, and a reversal cost. Pass test: a person outside the project team can read the list and identify the three most expensive decisions on it.

Two. Tier assignment. Sort each decision into human-only, approval-required, or autonomous. Sensitivity and reversibility drive the sort. Moving money and signing commitments sit high. Summarizing a document and drafting a reply sit low. Pass test: every decision on the inventory carries exactly one tier and a named accountable owner.

Three. Approval mechanics. For every approval-required decision, define who approves, inside what time window, and what happens when nobody responds. Pass test: the default behavior on timeout is written down, and it is not silent execution.

Four. Evidence trail. For every executed action, capture what the agent did, what it consulted to decide, and who approved it. Pass test: pick an agent decision from last week at random and reconstruct all three in under an hour.

Five. Override and shutdown. Define how a human interrupts an agent mid-task, how an agent gets pulled from production, and who holds that authority. Pass test: someone has actually done it outside of a drill.

Four of the five are organizational. Only the evidence trail is primarily technical, and even that one fails for organizational reasons more often than technical ones. We covered the control side of this work in the Elevates.AI AI agent governance checklist.

Our gap analysis maps decision ownership across functions before any agent goes live, then ranks what to fix by cost to close and by what it unblocks. Start with the assessment and the inventory arrives as an output rather than as homework.

Where the AI agent readiness checklist usually breaks

Part one. Almost always part one.

Teams jump straight to tier assignment because it looks like the regulated step and it produces a document. Tiering an incomplete inventory gives you a tidy artifact covering the decisions you already thought about, and no coverage at all for the decisions the agent will actually encounter in production.

The second failure is treating this as a data problem. In IDC survey data cited in analysis of the Chinese rules, 62 percent of enterprises named data rights and security compliance as the biggest obstacle to agents executing across systems, and 58.7 percent named governance and compliance as their top goal in adopting an agent platform. Those numbers usually get read as a case for better infrastructure. They are better read as evidence that the organizational work was skipped and the tooling is absorbing the blame.

The third failure is scope. Kyndryl found that only 27 percent of organizations use a registry and monitoring across all of their AI systems. A checklist applied to the agent launching next quarter, while eleven others run unregistered, does not produce readiness. It produces a compliant island.

The fourth failure is timing. Teams run this exercise after the vendor contract is signed, which turns it into a justification exercise rather than a decision. By that point the tiering conversation has an obvious right answer, because anything that slows the rollout looks like an obstacle to a purchase the company already made. Run the inventory while you can still walk away from the deal and you will get honest answers about reversal cost.

China is the first mover, not the last

Illinois signed the AI Safety Measures Act on July 6, 2026, becoming the third United States state with a frontier AI safety law after California and New York. Its distinguishing clause is a mandatory annual independent audit by a disinterested third party. The developer pays for the audit, and that payment cannot be tied to the findings.

Under the EU AI Act, transparency obligations apply from August 2, 2026, while the Digital Omnibus agreement endorsed by the European Parliament in June 2026 defers stand-alone high-risk obligations to December 2, 2027.

The mechanisms differ. China documents authority in advance and traces it afterward. Illinois brings in an auditor. The EU classifies systems and requires disclosure. All three demand the same thing underneath, which is proof rather than declaration.

Gartner’s 2026 CIO and Technology Executive Survey found that 17 percent of organizations have deployed AI agents, while more than 60 percent expect to within two years. Gartner also forecasts that more than 40 percent of agentic AI projects will be canceled by the end of 2027 on cost, unclear business value, or inadequate risk controls. Those cancellations will not be evenly distributed. They will concentrate in the organizations that deployed before they could answer part one.

What to build first

If you are starting from nothing, run the inventory before you buy anything else.

Take one workflow you intend to hand to an agent. Sit down with the person who owns that workflow today and write out every decision inside it. Mark each one with its reversal cost. That single exercise usually surfaces two or three decisions nobody realized were being made at all, which is exactly the category that produces incidents.

Then tier them, name the owners, and define the timeout behavior. You will have satisfied the substance of Article 6 for that workflow in an afternoon, and you will have done it because it is sound operating practice rather than because a regulator asked.

Two habits keep the work from decaying. Rescore the tiers every quarter, because agent capability and vendor defaults both change faster than an annual review catches. And log the near misses, meaning the decisions an agent was about to make autonomously before a human intervened. Those near misses are the cheapest signal you will ever get about where the tiering is wrong, and almost nobody captures them.

Do this once per workflow, not once per company. An AI agent readiness checklist is not a certificate you earn and file. Readiness is a per-decision property, and it has to be re-established every time the scope of delegation changes.

Most agent programs stall for a reason nobody writes into the postmortem. The team could not say, on paper, which decisions the agent was allowed to make. Map that before your next deployment rather than after the first incident. The free 60-second assessment returns your readiness baseline and the gap list in less time than it takes to schedule the meeting where you would otherwise debate it.

Frequently Asked Questions

What is an AI agent readiness checklist?

An AI agent readiness checklist is a structured test of whether an organization can safely delegate decisions to autonomous software. It covers the decision inventory, the tiering of decision authority, approval mechanics, the evidence trail, and override and shutdown authority. It is an operating model exercise rather than a technical one.

Does China’s AI agent regulation apply to companies outside China?

The Implementation Opinions apply to agents deployed in the Chinese market, so a company with no Chinese operations is not directly bound by them. The requirement matters anyway because Illinois, the European Union, and enterprise procurement teams are converging on the same demand, which is documented decision authority that can be proven after the fact.

What are the three tiers of AI agent decision authority?

Article 6 defines decisions only a human may make, decisions the agent may execute only after user approval, and decisions the agent may handle alone inside a delegated scope. Sensitivity and reversibility determine which tier a decision belongs to. The user retains the right to be informed and to override at any point.

How is agent readiness different from general AI readiness?

General AI readiness asks whether the organization can adopt and sustain AI tools. Agent readiness asks a narrower and harder question, which is whether the organization has defined and can enforce the boundaries of delegated authority. An organization can be ready for AI assistance and completely unready for AI autonomy.

How long does it take to define AI agent decision rights?

For a single workflow, a focused session with the current process owner usually produces a first-pass decision inventory and tier assignment in a few hours. Doing it across every workflow in the enterprise takes months, which is why most teams start with the highest-consequence workflow and expand from there.

About the Author

Tomer Mann is the founder of Elevates.AI, an AI readiness platform that helps organizations assess maturity, identify gaps, and build prioritized 90-day implementation roadmaps. He also builds Levos.ai, a workforce intelligence platform that aggregates data across the HR technology stack.

His perspective is grounded in more than a decade as Chief Revenue Officer at 22Miles, where he has led enterprise SaaS deployments for Fortune 500 brands across financial services, defense, pharmaceuticals, and professional services. That experience shapes how he thinks about enterprise data, AI adoption, measurable outcomes, and why many implementation efforts fall short.

LinkedIn: linkedin.com/in/tomermann22m

Be the First to Discover New AI Insights

Follow Elevates.AI on Google to stay updated with the latest AI readiness assessments, governance frameworks, implementation guides, buyer's guides, and enterprise AI best practices.

GoogleFollow Elevates.AI on Google
FREE WEEKLY NEWSLETTER

The AI Readiness Brief

Every Week, receive practical enterprise AI strategies, implementation frameworks, governance updates, and expert insights—all delivered in a 5-minute read.

✓ Enterprise AI Strategy✓ AI Readiness Frameworks
✓ Governance & Compliance✓ Exclusive Guides & Resources
 

Join 500+ AI Professionals

Enter your work email below to receive one high-value email every week. No spam. Unsubscribe anytime.

×