№ 07·0407 · AI Agent System3 min read · Section 4 of 5

7.4 Boundaries of Agent

Literacy, approval, funding and legal red lines; the risk matrix of illusion and overreach; human-machine division of labor and brakeable design.

Updated
7.4 · Agent boundaries

Only controlled Agents can enter the settlement and reputation system.

The stronger the capability, the more hard boundaries are needed: which outputs can only be drafted, which actions must be HITL, and which data will never leave the domain. The boundary is not to restrict innovation, but to turn LLM from an “unaccountable black box” into a “defensible component” - unlike Copilot, which only recommends and the user is fully responsible for, WCN must explicitly divide responsibilities at the network layer.

What this page doesAllowed set/Prohibited set/Risk and control measures
core themesThe person retains the final commitment and funding rights
Reading highlightsLegal, funding, PoB, external commitments, logs

What the Agent can do (allowed set)

Research and organizeAbstract, comparison matrix, preliminary due diligence screening, bullet citation with source; suitable for GPT-4 / Claude long article + RAG. The output default label is "not legally verified".
Process and MinutesMeeting minutes draft, action items, follow-up email templates; Execution class core scenarios. Timeline and speaker attribution errors need to be corrected manually.
Growth and MonitoringNarrative descriptions of copywriting variations, channel highlights, and indicator anomalies; natural language alerts after Liquidity-like read-only quotes.
Low risk automationFill out forms, label, synchronize status fields within explicit permissions; similar to RPA, but with LLM parsing unstructured input.

What the Agent cannot do (forbidden set)

Not a substitute for signing a contractElectronic signatures, binding terms, and exclusive/gambling conclusions require human and legal processes.
Cannot drive funds aloneTransfers, appropriations, on-chain authorizations, escrow instructions—even wallet-connecting tools require multiple human approvals and limits.
Cannot issue legal/tax/audit opinionsSummaries of regulations can be searched, and final conclusions such as "legal for you" are not allowed.
Unable to finalize PoBProof Desk and governance rules determine adoption; Agents can be pre-examined and sorted, but cannot "pass by self-certification".
Do not make external commitments beyond your authorityIncome, regulatory status, time on the firm, endorsement relationships - law firm-level statements are prohibited from automatically being generated and sent.
Logging and takeover cannot be bypassedThe critical path must be interruptible and rollable; silent invocation of unregistered tools is prohibited.

Risk matrix (simplified)

RiskPerformanceControl Ideas
IllusionFabricated cases, wrong laws, wrong company namesMandatory quotation; output "unknown" if unsure; key field rule verification
Prompt injectionMalicious web pages/PDFs inducing leaks or unauthorized accessTool isolation; untrusted content sandbox; outbound actions HITL
Data leakageTraining or logs take away confidentialityData classification; log desensitization; clearing keys after Retired
Excessive autonomyAutoGPT-style infinite loops and feesTask-level budget and step limit; no task means no running
Ambiguous responsibilitiesI don’t know who approved it if something went wrongAdoption record + approval chain + model/prompt version number

Without boundaries, AI is not a stronger execution layer, but a lever that amplifies mistakes—especially in high-stakes copywriting and funding-related processes.

Demarcation of responsibilities with Microsoft Copilot/Universal Assistant

Copilot's general terms and conditions stipulate: It is recommended that the user be responsible for verification. The WCN network side also needs to serve multi-party attribution: Therefore, the Agent boundary must be written in type policies and task contracts, rather than relying solely on end-user self-discipline.

What WCN needs is an agent that can be explained, accountable, and can enter PoB; "the model says it" cannot be regarded as the node saying it.

TradFi revelation: Automation stops before the decision-making chain

COIN-type systems handle large amounts of document analysis, and credit decisions are still subject to bank policy and human review; Aladdin emphasizes that risk calibers are consistent, and portfolio managers still bear investment responsibilities. WCN aligns with the same principle: **Agent compresses friction and does not replace signature authority. **

One sentence for product acceptance: If you delete the Agent, the business process is still legal and can be run, but it will be slower - the boundary is roughly correct. If the process of deleting the Agent cannot close the loop, it means that the human link has been excessively eroded.