AI Agents · Guardrails · Cost Control

The autonomy budget: what to cap before an agent runs unsupervised

Published · Updated

Anthropic measures agents at about 4× the tokens of a chat, and multi-agent systems at about 15×. That multiplier is why stopping conditions, permissions and checkpoints get designed before capability.

Every agent conversation eventually reaches the same question: not what the thing can do, but what stops it. Anthropic's framing helps. Workflows are systems where models and tools are orchestrated through predefined code paths; agents are systems where models dynamically direct their own processes and tool usage, maintaining control over how they accomplish tasks. Cross that line and you hand over the step count and the spend. Here is the order in which the limits are worth setting.

Autonomy has a price you can quote

Anthropic published the multiplier from their own data: agents typically use about 4× more tokens than chat interactions, and multi-agent systems use about 15× more tokens than chats. Read that as a design constraint rather than a warning. A task worth 15× is one where parallel exploration genuinely beats a single pass. Many internal requests for an agent are really requests for a workflow with a predefined code path, and they should be priced that way.

The iteration ceiling comes first

Anthropic notes that it is common to include stopping conditions, such as a maximum number of iterations, to maintain control. That line belongs in the first version of a system, not in the patch that follows the first surprise. The same guidance pairs the higher costs of autonomy with the potential for compounding errors, and recommends extensive testing in sandboxed environments alongside appropriate guardrails. An agent with no iteration ceiling has no worst case anyone can state out loud.

Permissions are not the model's decision

OWASP's Excessive Agency entry names three root causes: excessive functionality, excessive permissions, excessive autonomy. An iteration cap addresses only the third. The other two are solved in the surrounding system. Implement authorisation in downstream systems rather than relying on an LLM to decide if an action is allowed. Apply rate limiting to reduce the number of undesirable actions that can take place within a given time period. Require human approval for high-impact actions before they are taken.

A tool catalogue is an attack surface

The Model Context Protocol is an open protocol enabling integration between LLM applications and external data sources and tools, and its specification is blunt about the risk: tools represent arbitrary code execution and must be treated with appropriate caution. It goes further on metadata, stating that descriptions of tool behaviour, such as annotations, should be considered untrusted unless obtained from a trusted server. A tool list is an attack surface before it is documentation.

Failure should cost one phase, not one run

Anthropic describes building systems that can resume from where the agent was when the errors occurred, combining the adaptability of AI agents with deterministic safeguards like retry logic and regular checkpoints. They also describe patterns where agents summarise completed work phases and store essential information in external memory before proceeding to new tasks. The MCP specification supports the same shape through Tasks: asynchronous execution of long-running operations, with polling, mid-flight input and durable handles.

The cost argument follows directly. Without checkpoints, a failure late in a long run means paying for the whole run again, at the multiplier rather than the chat baseline. With checkpoints and external memory, the same failure costs one phase and a retry. Recovery design and cost control are not two projects. They are the same engineering work described in two different vocabularies, and they share the same artefacts.

What bounded scope buys you

Our Tatano Energy build is a useful counterweight. A multilingual e-commerce platform runs across four country domains, with a daily SEO autoblog driven by search trends and multi-language generative video campaigns. Country domains indexed separately: 4. Languages served: 7. SEO articles published every day: 8. Manual intervention required: 0. The absence of manual intervention there is not a measure of how much freedom the system was given.

It is a measure of how precisely the job was bounded. The brief was concrete: a biomass boiler manufacturer present in four European markets with one generic site, no structured data and no localised content, against competitors established in every country. Publishing to seven languages on a daily cadence is a predefined code path with model calls inside it. Nothing in that system has to choose its own next step, so nothing in it can wander.

The practical sequence, then: decide whether the task needs dynamic direction at all, and keep it a workflow if it does not. If it does, set the iteration ceiling, move authorisation and rate limits into downstream systems, treat every tool description as untrusted input, and add checkpoints with external memory before you add capability. Those four controls are what make the token multiplier a budget you can quote instead of a number you discover afterwards.

Sources

Anthropic — Building effective agents — https://www.anthropic.com/engineering/building-effective-agents

Anthropic — How we built our multi-agent research system — https://www.anthropic.com/engineering/multi-agent-research-system

Model Context Protocol — Specification (version 2026-07-28) — https://modelcontextprotocol.io/specification/2026-07-28

OWASP Gen AI Security Project — LLM06:2025 Excessive Agency — https://genai.owasp.org/llmrisk/llm062025-excessive-agency/

Neurolinks case study — Four markets, one codebase — https://neurolinks.be/work/tatano-energy

Working on a project where these methods apply?