All writing
7 min readHealth AI, Decision-making

Supervision Is a Technology

Teaching hospitals solved the problem of getting reliable output from not-yet-reliable people a century ago. The software industry is rediscovering that same problem now, at retail prices, with AI agents.

Every teaching hospital in the world runs on an uncomfortable premise: the newest doctors are not yet safe, and the institution knows it. Nothing about this is hidden; the architecture announces it. Prescriptions written by a house officer get countersigned by someone senior. Management plans get presented at morning rounds before they get executed. There are written rules about what a junior doctor may decide alone at 2 a.m. and what requires waking a consultant. I trained inside this system, first as the person being checked, and the strange part is how little offense anyone takes. The scrutiny is the job. Nobody reads the countersignature as an accusation of stupidity. It means the institution decided, a long time ago, that competence and reliability are different properties, and that you can extract reliable output from not-yet-reliable people if the structure around them is built for it.

I keep returning to that premise this year, because the software industry has spent 2026 rediscovering the exact problem it solves.

What is actually being sold

The thing marketed as agentic AI is, in plain terms, software that takes a goal instead of a command. A chatbot answers the question you asked and stops. An agent takes "find the duplicate charges in these invoices and draft the dispute emails," breaks it into steps, opens the tools it needs, does the work, checks the result against the goal, and comes back when it is finished or stuck. The distinction that matters is initiative, not intelligence. You stop specifying steps and start specifying outcomes, which means the system now makes small decisions on your behalf while you are not watching. Everything good and everything dangerous about the technology lives inside that clause.

The plumbing arrived faster than most people noticed. In December 2025, Anthropic donated the Model Context Protocol, the connector standard that lets agents operate external tools, to the Linux Foundation, with OpenAI, Google, Microsoft and others signed on and more than ten thousand public MCP servers already published. When competitors of that size agree on a socket, the argument about whether the technology is real is over. Sockets are what you build on.

And yet the honest picture of adoption is two numbers pointing in opposite directions, both from the same Gartner analysis. By 2028, they project, a third of enterprise software will include agentic AI, up from under one percent in 2024. The same firm predicts that over forty percent of agentic AI projects will be canceled by the end of 2027. Their reasons: escalating costs, unclear business value, inadequate risk controls. They also note that of the thousands of vendors now selling "agents," they estimate only around 130 are selling the real thing. The rest are rebadged chatbots and RPA scripts, a practice Gartner has taken to calling agent washing.

The industry is simultaneously certain this is the future and abandoning nearly half of its attempts to build it. That is what it looks like when people acquire capable juniors and skip the part where someone supervises them.

The intern problem

Here is what a decade around hospitals teaches you about delegation that the current AI discourse keeps relearning at retail prices.

The dangerous intern is not the visibly incompetent one. That intern gets caught by everyone, immediately. The dangerous intern is fluent. The notes are clean, the presentation is confident, the plan is plausible, and one element in it is wrong in a way that only shows up if someone with more context actually looks. Medicine learned, at real cost in bodies, that fluency and correctness come apart precisely when it matters most, and that the expensive errors are the ones formatted exactly like good work.

Agents fail the same way. They rarely fail loudly. They produce output that has the shape, tone and confidence of finished work, with the error embedded where a skim will not find it. A wrong figure carried through an otherwise correct analysis. A step quietly skipped and papered over. A source that supports a weaker version of the claim attached to it. If your review process is "does this look right," you have no review process, because looking right is the one thing these systems are uniformly excellent at.

Medicine's response to this exact property was not to stop delegating. Hospitals cannot run without juniors, and at this point I would argue most knowledge work cannot run much longer without agents, if only for cost reasons. The response was a technology. Not a machine, a technology in the older sense: a set of techniques, refined over a century, for getting safe output from unsafe workers. It has parts, and the parts map onto agent deployment almost one to one.

Graded autonomy. A junior doctor is not trusted or untrusted. They are trusted per task. The same person who can discharge a stable patient alone cannot start certain drugs without sign-off. Medical educators formalized this into entrustable professional activities, units of work you certify one at a time. The agent version: permissions scoped per task, not per system. The agent that drafts your emails does not get access to send them. Autonomy is granted task by task, expanded only with a track record, exactly the way you would treat a new hire.

Countersignature at the point of harm. Hospitals do not review everything equally. Verification concentrates where irreversibility concentrates. Nobody countersigns the intern's lunch order; someone countersigns the opioid prescription. The agent version: a human between the agent and anything irreversible. Sending, publishing, paying, deleting, committing. Everything upstream of that line can run free, and should, because that is where the leverage is.

Written escalation rules. The 2 a.m. question, "do I wake the consultant," is not left to the intern's judgment, because judgment is the thing still under construction. The criteria are written down. The agent version: explicit instructions for what the agent must hand back to you rather than resolve itself. Ambiguity, missing data, anything touching money or reputation. An agent without escalation rules resolves everything, which means it resolves things it should not, silently.

Error review without blame. When something goes wrong in a hospital, the morbidity and mortality conference asks what happened and what in the system allowed it, on the theory that the error is information about the structure, not just about the person. The agent version: when the agent gets something wrong, the useful question is which check would have caught it, and adding that check. People who treat agent errors as betrayals quit. People who treat them as findings build systems that improve monthly.

Why delegate if you still have to check everything

That's the standard objection.

Medicine's answer is that checking is cheaper than doing, but only when you know where to look. The consultant reviewing an intern's plan does not redo the workup. They have a trained scan pattern built from years of seeing where plans go wrong: the drug interaction, the assumption that skipped a differential, the lab value everyone anchored on. Reading work for the one wrong thing is a real skill, and it is a different skill from producing the work. It has to be learned separately, and almost nobody teaching "prompt engineering" is teaching it. Most of what I do when I review AI output professionally is exactly this scan pattern, transplanted from one domain into another, and I remain a little surprised by how directly it transfers.

Two complications, so this stays honest rather than tidy.

First, supervision fails in hospitals too. Countersignatures decay into reflexes. Tired seniors rubber-stamp. Medicine argues constantly, in its own literature, about how much its supervision actually catches versus how much it exists to distribute liability. Importing the architecture does not exempt you from the failure mode; the rubber stamp is, if anything, easier with agents, because the output is better formatted than any intern note ever was. I have caught myself doing it: approving an agent's work at speed because it looked like the last twenty that were fine, and only later finding the one that was not. The architecture is necessary. It is not self-executing.

Second, the analogy has a limit worth stating plainly. Interns become consultants. The supervision is scaffolding around a person who is learning, and the institution's investment pays off when the scaffolding comes down. An agent does not graduate. Whatever checking structure you build, you are building permanently, at least until the models change in ways nobody can quite schedule. If that changes the economics for your use case, it changes them, and pretending otherwise is how you end up in Gartner's forty percent.

The decision is whether you're prepared to be the attending

Strip the vendor language away. Agents are impressive; that was never the question. Start with tasks where errors are visible and reversible. Write down what the system may do alone. Put yourself at the exact points where harm becomes irreversible and nowhere else. Review the failures like findings.

None of this is exotic. It is a century of teaching-hospital procedure, translated. The hospitals never resolved the tension between needing juniors and not fully trusting them. They just built well enough around it that the work gets done and most of the errors die in review, caught by a tired senior with a pen, reading someone else's confident work at 2 a.m., signing only after actually looking.


Further reading

  • Gartner, "Over 40% of Agentic AI Projects Will Be Canceled by End of 2027," press release, June 2025
  • Anthropic, on donating the Model Context Protocol to the Linux Foundation, December 2025
  • ten Cate et al., on entrustable professional activities as a framework in medical education