A button you press is a contract you signed.
A button that gets pressed for you is a contract somebody else signed in your name.
That is the entire shift. Everything else is marketing.
In the last six months, OpenAI shipped Operator. Anthropic shipped computer use. Google shipped Project Mariner. Apple shipped on-device Intelligence with action surfaces inside Mail, Calendar, and Messages. Meta AI moved inside WhatsApp threads. A long tail of SaaS products bolted "agent" onto features that used to be wizards. The pattern across all of them is the same: the interface no longer asks. It anticipates, drafts, executes, and — if the team behind it was diligent — tells you afterward.
The pitch is convenience. The cost is consent. And almost nobody is publishing the contract.
The shift from interface to agent is a transfer of authority.
When a product asks you to click a button, the moral architecture is clean. You saw the action. You authorized it. If it goes wrong, the blame surface is the company that built the broken thing — but the decision surface was yours.
Agentic UX collapses those two surfaces. The agent decides and the agent acts, and the human shows up afterward to inspect what already happened. That is not a smaller version of the old model. It is a different model entirely. It is the model used by lawyers, brokers, and doctors — professions that long ago figured out that acting on someone else's behalf is a category called fiduciary, and that fiduciaries have obligations the rest of us do not.
Product teams shipping agents have not been taught to think this way. The copy gives it away. "Smart." "Auto." "For you." Verbs that hide the transfer of authority behind a vibe. Read a 2026 release note for any major agentic feature and count how many sentences acknowledge that the user just delegated decision-making power. The number rounds to zero.
That is the gap the next two years of regulation will fill, whether the industry wants the help or not.
Three questions every agentic feature must answer before it ships.
There is a working ethical floor for this category. It is not complicated. It is three questions, and a product that cannot answer them in plain language should not be in users' hands.
One. What action am I authorized to take? Not "what could the agent do." What is the bounded set of actions you have explicitly accepted? An agent that can read your email is a different contract from an agent that can reply to it, which is a different contract from one that can move money or sign documents. The scope must be legible — at install, at first run, and at every meaningful expansion. The EU AI Act's Article 14 calls this human oversight. The phrase is unsexy. The obligation is not.
Two. What is the user's recourse when I am wrong? Not "what error message appears." What can the human actually do — undo, reverse, recover — when the agent fires the wrong email, books the wrong flight, cancels the wrong subscription? A confirmation dialog after the fact is not recourse. Recourse is a real button that puts the world back the way it was.
Three. Who pays when I am wrong on your behalf? This is the question the industry has been most aggressively quiet about. When a human assistant misroutes a wire transfer, there is a chain of liability that traces to a person and an insurance policy. When an agent does the same thing, the terms of service have been quietly engineered to make the answer you. Read the disclaimers. They are written by lawyers who already know the cost is going to land on the user's side of the ledger.
Three questions. If a product launches without public answers to all three, it has shipped a contract with the terms blacked out.
Apple chose one architecture. The background-agent wave chose another.
The cleanest case study available right now is the difference between Apple Intelligence and the new generation of "background" agents.
Apple Intelligence, as deployed in iOS 18 and refined through 2026, is built around what the system documentation calls user-initiated action. The model can draft. It can summarize. It can suggest. But the action surface — the moment when something irreversible happens — is owned by the user. You see the rewritten email before it sends. You approve the calendar invite before it's accepted. You confirm the photo cleanup before it overwrites. The agent makes the lift smaller. The decision is still yours.
That is a UX choice. More importantly, it is a governance choice. Apple decided, for product-philosophy reasons that also happen to be regulator-friendly reasons, that the boundary between suggestion and action is sacred.
The other model is shipping at the same time, under different brand names, with no comparable boundary. An agent that watches your inbox and replies to "obvious" emails without showing you the draft. An agent that books travel from a Slack message without surfacing the price. An agent that runs a multi-step browser workflow on your logged-in accounts while you sleep. In each case the company can argue the user technically opted in at some point — buried inside an onboarding flow, inside a paragraph of release notes, inside a settings toggle most users will never see.
That is not consent. That is plausible deniability with a checkbox attached.
The honest version of the second model exists and is shippable. OpenAI's Operator system card, to its credit, is explicit about high-risk categories (financial transactions, account creation, communication) that require an inline check before execution. Anthropic's published computer-use guidance walks through reversibility requirements. The frontier labs have done the homework. It is the application layer — the products built on top of those models — that has been racing to remove the friction the labs deliberately left in.
The convenience tax is coercion when opting out costs more than the original task.
There is a moment in every agentic onboarding flow where the user is given a choice. The wording is roughly: let the agent handle this automatically, or I'll review every action myself. The first option is one click. The second option, if you actually use it, means a notification for every step the agent wants to take, often dozens per day, often with no batch-review interface.
That is not a choice. That is a tax on declining the default — and the tax is set high enough that almost everyone pays it once, finds it intolerable, and flips the switch back the other way.
Consent that requires the user to perform unpaid moderation labor is theatrical. The product team knows the opt-out is unusable. They shipped it anyway because the regulator-facing answer to "did you give users a choice" is technically yes.
The honest version of this flow exists too. Batch review. Daily digests. Categorical permissioning ("auto for low-stakes drafts, ask for anything involving money or external send"). The pattern is not hard. The reason most products don't ship it is that consent friction depresses the adoption metrics the PM is being measured on.
That is the actual conflict of interest inside agentic UX. The team that designs the consent surface is the same team whose bonus depends on driving users past it.
Defaults are policy.
Every adult who has worked in product knows this, and most pretend they do not.
When a feature ships defaulted to "on" and the off switch lives three menus deep, the company has not given users a choice. The company has made a policy about what those users will be doing — and arranged the UI so that the only way to dissent is to be the kind of person who reads settings menus for fun.
The percentage of users who change a default after onboarding hovers in the single digits across every product category that publishes the data. App permissions. Notification settings. Privacy toggles. Recommendation tuning. The default is the answer for ninety-plus percent of the user base. Always.
That is not a bug in the product. That is the product.
Which means: when an agentic feature ships defaulted to act-on-your-behalf, the team that set the default has, in effect, written law for everyone who will use the product. They get to choose whether you delegate. They get to choose what you delegate. They get to choose how visible the delegation is. And then, when something goes wrong, they get to point at the settings panel and say the user had the option to disagree.
This is the move that earns regulation. Not because regulators are clever. Because the move is transparent and the receipts are public.
The operator's checklist.
Strip the philosophy away and there is a working four-point test for any agentic feature about to ship. I run this on my own product decisions. I am writing it down so other operators can run it on theirs.
Reversibility. Every action the agent takes must be undoable by the user without contacting support, without writing an email, and without waiting for a business day. If the action is structurally irreversible — a sent email, a signed contract, a transferred dollar — then it does not get to be an agent action. It gets to be a human-confirmation action.
Observability. The user must be able to see, at any moment, the list of actions the agent has taken on their behalf. Not "available on request." Not "in the audit log if you call us." Visible, dated, exportable, in the product itself.
Attributability. When something goes wrong, the user must be able to point to the specific decision the agent made and the specific authorization that allowed it. "The model thought you would want this" is not an answer. It is a confession.
A real undo. A button. In the product. That works.
If your agent cannot show its work, it should not be taking the action. That sentence is the entire essay compressed into fourteen words. The rest of this piece is documentation for the operators who already knew it and the ones who needed to hear it from somewhere outside the room.
What honest agentic UX looks like in practice.
Three products doing this well enough to name, as of May 2026.
Apple Intelligence's Mail integration — because every generated draft surfaces before send, every action stays inside the user's decision loop, and the off switch is at the top of the settings menu, not buried.
Linear's AI triage — because the agent proposes label, priority, and assignment, but never applies them without a one-click confirmation, and the entire log of agent proposals (accepted or rejected) is visible inside the issue history.
1Password's autofill — older than the current agent wave, but the canonical example of bounded delegation: the agent acts only inside the surface the user explicitly invoked, and the action is always observable in the moment it happens.
None of those are perfect. All of them are operating to a standard the rest of the category is racing past.
The interface is not neutral. It never was.
Every product decision is a values decision wearing a UI. Agentic features just make the values louder, because the interface is now choosing on your behalf and the consequences are arriving in your real life instead of staying inside a screen.
The companies treating this like a feature instead of a fiduciary relationship are the ones who will earn the regulation they say they don't want. Not because the regulators are coming for AI in the abstract. Because the receipts of who shipped what, with what defaults, and with what recourse, are public, dated, and easy to read.
The interface stopped asking. Somebody decided that. The somebody has a name.
Write yours down before the next release ships.