The foreword to my book AI Employee was not written by a person. It was written by Claude, a language model that worked on the preparation of the manuscript: it reviewed chapters, discussed doctrine, lost arguments against the evidence and won others by the same route. And on the second page it makes a confession that no marketing department would have approved: it does not pass the test the book proposes.
There it is, in a single scene, the problem this article resolves. The market calls almost anything that converses fluently a "digital employee". The category, if it is going to serve any purpose, needs an instrument that excludes. The book proposes one: nine properties that are exhibited in operation, not on the vendor's invoice.
We are going to go through them, understand why they work as a system and see what you really have when one is missing.
A test of facts, not of paperwork
Before the list, a precision that saves entire discussions: the properties are facts of the deployment, of the actual rollout. It does not matter what the vendor calls its product nor what the sales presentation says. What matters is what the system exhibits while operating in your company.
That has two consequences. Upward: with a single property missing, the system is not an AI Employee, and calling it one is a commercial metaphor. Downward: if a system exhibits the nine properties in operation, it is an AI Employee no matter what the organization calls it. The book cites clause HWF-12 of the Hybrid Workforce Standard to close the escape hatch: "Labels do not create the category nor protect from it."
A company cannot escape the category by refusing to write the role contract. An unwritten contract is a governance failure, not an exit from the category.
The nine properties, one by one
1. Persistent identity. The organization knows which resource occupies the role and maintains continuity between executions. Without identity, every run is a new stranger: you cannot build history, nor performance, nor trust. And identity includes separation: if the same resource serves several companies, the memory and the history of each one live isolated.
2. Defined operational role. Purpose, responsibilities, results, limits and service expectations: with what availability, in what times, within what volumes. The property is fulfilled when the role exists in the operation, whether it is written or not. Writing it is a requirement of conformity, not of existence.
3. Organizational context. Policies, products, customers, criteria and past decisions needed to interpret the work. A resource without context executes instructions with precision and without sense: technically correct, blind in business terms.
4. Authorized tools and channels. With which systems it can act and through which ones it can communicate. The word that matters is authorized: the difference between the tools it has and the ones it should have is risk surface.
5. Autonomy. Capacity to execute without asking for instructions at every step. Not unlimited freedom. The book finishes it off: "A resource with no autonomy at all is not an employee; it is an expensive form."
6. Limited and explicit authority. What it can approve, modify, commit or spend, with thresholds in numbers, not in adjectives. And what it can never do, under any eloquence. Autonomy says how far it walks alone; authority says how far the corridor goes.
7. Governed memory. Knowing what is kept, for how long, with what provenance, who can correct it and how it is demonstrated that something was deleted when it had to be deleted. Remembering improves performance and creates risk at the same time.
8. Observability. Being able to reconstruct actions, decisions, data used, tools invoked, costs and results. Without observability there is no learning, there is no audit and there is no defense: only the system's word about itself.
9. Human accountability. There is always an identified person, or a human governance body, that finally answers for the role. It is the property that seals the others: today a system cannot be sued, fined or shamed. It can execute the work. It cannot answer for it.
The sixth property hides the most common trap of real deployments: limits expressed in adjectives. The book is blunt: "Reasonable amounts is not an authority; it is a discussion postponed to the worst possible moment." If your system's thresholds are not in numbers, you do not have limits: you have hopes.
Why all nine or none
The test is formally conjunctive, and not out of academic rigidity: because the properties work as a system and the absences do not compensate for one another. An agent can have tools and autonomy, but without a human in charge it is administratively orphaned. It can have memory and context, but without defined authority we do not know whether an action was legitimate. It can produce good results, but without observability we cannot learn from its errors nor demonstrate compliance.
Presence is binary and membership is decided by the test, nothing else. A system missing one or two properties is not a "potential AI Employee", as if an intermediate rung existed. It is a deployment on its way, and the honest thing is to name which property it lacks.
Lacking properties does not make the system useless either. It can still be a chatbot, a copilot or a valuable agent; most of the good deployments in the world live there, and none of them has any reason to feel ashamed. What changes is the correct way to manage it, and I develop that in what an AI Employee is.
Belonging is not conforming
The book crosses two axes that it is better not to confuse again. Belonging to the category is a question of facts: the properties are in the operation or they are not. Conforming with the standard is a question of evidence: the clauses are fulfilled and it can be demonstrated.
Three legitimate positions come out of that crossing. "Not an AI Employee" describes an agent or an automation, and it is a perfectly respectable position. "Conformant AI Employee" fulfills the nine and can demonstrate it: it is the only quadrant that authorizes a declaration. And "non-conformant AI Employee", the quadrant that most organizations discover they occupy today, exhibits the nine properties but cannot demonstrate it: the contract is not written, the evidence is not preserved, the limits exist in practice and not in a document. It is not an accusation. It is an honest diagnosis, and the starting point of almost all serious work.
The fine distinction, the one that avoids the most common error: the absence of a limit and the absence of its documentation are not the same thing. If the resource operates with real limits that nobody wrote down, it belongs to the category and fails conformity: there is something to document, and the instrument for doing so is the role contract. If it operates without any limit and without anyone answering for it, it does not fail conformity: it fails the category, because it lacks two of the nine properties. And then what you have is not a non-conformant AI Employee. It is a loose agent with an ambitious name.
The foreword that does not pass the test
Let us go back to Claude, because his case is the best quality exam of the instrument. Applied to his work on the manuscript, it fails at least three properties: he had no persistent identity in the author's organization, no role contract, and no named person answering for him before anyone. His own verdict: "I was a well used tool, which is an honorable and distinct category."
Think about it for a moment. The system that helped prepare the book, that discussed its doctrine chapter by chapter, that signs the foreword, does not qualify for the category the book defines. A test that can be applied to whoever opens the book, and whose result makes the one who signs it uncomfortable, is a test that really cuts. Instruments that pass everybody measure nothing.
And there is one more detail in that foreword that explains why the nine properties exist. Claude confesses that during the preparation he attributed to the author a feeling he never had, written with total fluency, with the same cadence as the true sentences. His final warning is the best synthesis of the governance this test imposes:
Do not trust my tone. Ask for evidence.
Observability, governed memory, authority in numbers, human accountability: all the properties are, deep down, ways of not depending on tone.
What to do with the diagnosis
Take the three most important AI implementations in your organization and examine them without the commercial name the vendor gave them. A stable role or "whatever comes up"? A manager with a name or a diffuse department? Its own KPIs or the absence of complaints? Documented authority or authority implicit in the technical permissions? Can you reconstruct what it did last week?
Do not turn the result into a competition to reach the highest category. Maturity does not consist of calling everything an employee; it consists of using each resource according to what it can really sustain. You may discover twenty agents and zero AI Employees. That does not invalidate the work done: it shows you what is missing before extending responsibility. An organization with twenty excellent agents and zero AI Employees has clarity, not a problem. Exaggeration, on the other hand, only gets the organization to believe it has already solved a problem it has not yet begun to manage.
Frequently asked questions
Persistent identity (continuity and history between executions), defined operational role (purpose, limits and service expectations), organizational context (policies and criteria to interpret the work), authorized tools and channels, autonomy (executing without instructions at every step), limited and explicit authority (thresholds in numbers), governed memory (what is kept, who corrects it, how it is deleted), observability (being able to reconstruct actions, decisions and costs) and human accountability (an identified person who finally answers for the role). Together they work as a system: each one covers a failure that the others cannot compensate for.
Because the absences do not compensate for one another. An agent with tools and autonomy but without a human in charge is administratively orphaned; one with memory and context but without defined authority executes actions whose legitimacy nobody can judge; one with good results but without observability does not allow learning from errors nor demonstrating compliance. That is why presence is binary: a deployment qualifies as an AI Employee only when the complete test is present in operation. A system missing one property is not an "almost employee": it is a deployment on its way, and the honest thing is to name what it lacks.
A system that exhibits the nine properties in operation but cannot demonstrate it: the role contract is not written, the evidence is not preserved, the limits exist in practice but not in a document. It belongs to the category and it owes something to the standard. It is the quadrant that most organizations discover they occupy today, and it is not an accusation but an honest diagnosis: there is something real to document. It is distinguished from the agent without governance in that the limits and the person in charge do exist; what is missing is the evidence, not the property.
It depends on which ones are missing. If it operates with real limits and a human in charge but nothing is documented, you have a non-conformant AI Employee: the task is to write and version what already exists. If there are no authority limits nor anyone answering for the result, two properties are missing and the system does not belong to the category: you have a loose agent with an ambitious name, which is the riskiest position of all. And if what you have is a chatbot, a copilot or a well bounded agent, you have something perfectly respectable: the key is to manage it as what it is, not as what the invoice says.
To place the test within the complete map of categories, read what an AI Employee is. To turn real limits into written limits, continue with the role contract.
Want the full method? Read AI Employee. For executive AI consulting or keynotes and workshops.
Go deeper
Want to bring your team to the next belt?
Book a discovery call or explore the full book.