In March 2018, an Uber test vehicle was driving itself through Tempe, Arizona. Its sensors picked up Elaine Herzberg crossing the road 5.6 seconds before it hit her. In those seconds the software cycled through classifications, bicycle, vehicle, other, never settling on a person walking into its path.
Then it decided something was wrong. And here the system fell into the cracks between design intent and execution. On detecting a possible emergency, the system entered a one-second window that Uber called action suppression: it held off braking while it either re-checked the hazard or waited for the human behind the wheel to take over.
The safety driver was the fallback. Uber's own document says so: "The primary countermeasure in an emergency situation was the vehicle operator, who was expected to recognize the hazard, to take control of the vehicle, and to intervene appropriately."
The investigators found that during that one-second window, no alert was given to the operator.
The whole safety case rested on a person taking over. It's just that nobody had designed the bit where they were told.
The seam
I've started calling these moments "seams". The points where the machine stops and a person starts, or the other way round.
You know them from the customer side. You're deep in a chat with some company's bot, explaining the problem for the third time, and it gives up and passes you to a human. Who says: "Hi, how can I help?" Everything you typed is gone. The bot had it. The person doesn't. You start again.
That is the same failure as Tempe, with the stakes turned down to almost nothing. Somebody built the bot. Somebody else staffed the support desk. The gap between them was left to whatever the software did by default.
Seams are everywhere once you look. A mortgage application declined in under a second, and the first human to see the case is the officer being asked to explain it, holding a score and a threshold and no reasoning at all. A complaint that mentions a bereavement, sorted into a queue by tone and topic, landing in front of someone with thirty seconds a case. An expense claim auto-approved at £49 and pushed to a manager at £51, whilst nobody can remember who chose either number.
Most organisations have dozens. Very few could tell you where theirs are, let alone show you the design work behind them.
The person is not a safety feature
The Uber example above is the extreme version of a pattern that turns up wherever people put a human at the end of an automated process and call it safe.
The Robodebt scheme did it in Australia. Before it, an officer assessed each mismatch between tax and welfare records, chased payslips from employers, and established whether a debt was real. The scheme removed that officer and handed the job to the person receiving the letter: prove it yourself, through a web form, in 21 days, using payslips from up to seven years ago. The Royal Commission found human checking had been progressively stripped out until notices were going out unreviewed. The human was still in the process. They were just the one person in the chain with no access to the evidence.
The Post Office did it in Britain. Subpostmasters who spotted a shortfall rang the Horizon helpline, which was the designated human intervention point, and were told they were the only one having the problem, while the actual known bugs sat in Fujitsu's logs. Later, the same output went to investigators and courts, protected by a legal presumption that a computer is working properly unless somebody can prove otherwise. People were nominally in control at every step. What they lacked was any means of exercising it.
In all three, the design is the same shape. The human is written into the safety case as the thing that catches the failure, and no one checks whether they are in a position to catch anything.
We argue about how much, not about where
The conversation about AI at work is nearly always about volume. How much can we automate? How many hours does it save? What share of tickets can it close?
That hides the question that matters. Not how much, but where. Where exactly does the machine stop? What happens in the second after it stops? Who arrives, and what do they know?
Our vocabulary doesn't help. "Human in the loop" and "human on the loop" have been around for over a decade, and both describe an arrangement: is a person in the chain, or watching it, able to step in? Useful. But they describe the setup, not the moment. They tell you a person is somewhere in the system. They say nothing about what happens when you meet them.
There's a line in the Knight First Amendment Institute's "Levels of Autonomy for AI Agents" that quietly does a lot of damage: autonomy is "a property that can be designed independently of capability."
Which means, in plain terms, that how much a machine does on its own is a choice somebody makes, not a level it reaches. A very capable system can be kept on a short leash deliberately. So when a machine ends up making a call it shouldn't have, nobody gets to say it took over because it got good enough. Someone let it, or nobody stopped it.
What you automate says what you think people are for
A company that automates ninety per cent of its customer service decisions has said something about where it thinks a person is worth having. So has the company that kept a human on every refund over a certain size, or on any complaint mentioning a death. These aren't cost decisions dressed up as values. They're statements about what the organisation believes, and cost is one input.
The uncomfortable part is how few were made deliberately. Most were inherited. The pattern of what's automated and what isn't grew on its own, shaped by whatever the tools could handle that quarter, not by anyone asking where they wanted people to stay in the room.
Gartner expects at least fifteen per cent of everyday work decisions to be made autonomously by AI by 2028, up from essentially none in 2024. That shift happens one seam at a time, and the default is drift: the machine takes each piece it can, unless somebody decides otherwise on purpose.
Deloitte's 2026 Human Capital Trends found sixty per cent of executives now use AI to help them decide things, and five per cent say they manage it well. Deloitte calls the gap "culture debt": what you run up when you scale AI faster than the accountability around it.
Three arguments about the same moment
The seam is where three conversations turn out to be the same conversation.
It's an ethics question. At this exact point, is a person accountable, or has accountability quietly evaporated into a threshold nobody set?
It's a design question. What does the handover feel like? Does the person arrive knowing everything already said, or do you start again?
And it's a brand question. That moment, repeated across every interaction you have, is one of the truest things a company does. Automate the point where someone grieving needs a person, and you've told them exactly what you are, whatever the values page says.
Most organisations treat these as three meetings with three owners. They're one argument about a handful of moments, and those moments can be designed.
Where to start
You don't need a philosophy of machine autonomy. You need to find your seams. And you need to apply some simple service design thinking.
Take one journey that matters. Mark every point where control passes between a person and the system. At each one, ask two questions. Did we choose this, or inherit it? And what does it feel like from the other side?
Most teams can't answer the first for the majority of their seams. That's the finding. The points where a person enters your customer's experience were set by software defaults and nobody's second thoughts.
The Uber system was eventually changed. Action suppression was removed before the investigators published. It took someone's death to design one second of handover that should have been designed in at the start.
Yours are likely lower stakes than these. They're also unexamined. Finding them takes about an afternoon.
Sideways is a behavioural design practice for regulated businesses. We design the moments where judgement, accountability and trust are decided, rather than leaving them to the defaults.