AI Product Architecture & Operations10 min read

AI UX Is the Contract Between Human and Machine

How to design AI work surfaces, shared control, uncertainty, provenance, authenticity, and recovery across different levels of autonomy.

A shared AI workspace exposes sources, state, uncertainty, undo and handoff controls.
On this page
  1. 1.Start with the job and control model
  2. 2.Measure the AI detour
  3. 3.Design for comprehension and emotional outcome
  4. 4.Replace the blank page with affordances
  5. 5.Design a shared human-agent workspace
  6. 6.Match UX to autonomy
  7. 7.Communicate uncertainty without fake precision
  8. 8.Provenance and authenticity
  9. 9.Generative UI needs a bounded vocabulary
  10. 10.Recovery is part of the primary flow
  11. 11.Voice and multimodal work
  12. 12.Measure the relationship
  13. 13.Anti-pattern: the invisible boundary

TL;DR

  • AI UX defines who holds context, who chooses the next action, what the system may do, and how people recover when it is wrong.
  • Inline assistance, open workspaces, delegated agents, and generative interfaces serve different jobs. Choose the surface from the workflow and autonomy level.
  • Trust comes from calibrated control, visible provenance, honest disclosure, and reliable recovery, not a confidence badge or human-sounding prose.
  • Good AI UX reduces uncertainty and emotional effort as well as clicks. Comprehension, reassurance, and recovery can create more value than decorative delight.

AI UX is not the chat box wrapped around a model. It is the contract between a person and a probabilistic system.

The interface tells the user what the system knows, what it can do, what it is doing now, and who remains accountable. When that contract is vague, users either under-trust a useful system or over-trust a dangerous one.

Design the relationship before designing the screen.

Start with the job and control model

Four surface patterns cover most AI product work.

Inline assistance

AI appears inside an existing task: suggesting text, classifying a record, explaining a metric, or pre-filling a field.

Use when context is already present and the user remains the primary actor. Inline AI reduces detours and can earn adoption without teaching a new destination.

Risk: frequent suggestions can become noise or quietly steer decisions.

Open workspace

The user explores, researches, creates, or analyses across several steps. The interface may combine conversation, files, tools, previews, and editable artefacts.

Use when the job is genuinely open-ended and the user needs to direct the path. Do not reduce a rich workspace to one empty prompt.

Risk: capability is broad, so boundaries and state become difficult to understand.

Delegated agent

The user assigns a bounded job and the agent works asynchronously or in the background.

Use when the outcome and permissions can be specified, progress can be observed, and escalation is available.

Risk: users lose situational awareness while the system acts.

Generative interface

The system assembles forms, tables, summaries, controls, or visualisations around the current task.

Use when the right presentation depends on the request and data, but interactions can still be constrained to trusted components.

Risk: dynamic layouts become unpredictable or hide important state.

No pattern is the default for every product. Choose based on the user's job, existing workflow, required context, and acceptable autonomy.

Measure the AI detour

Destination AI often asks users to leave their workflow, restate context, formulate a request, interpret a response, and manually carry the result back.

Count those steps. Remove them where the job is known.

Inline actions and contextual triggers work well when the task is repeated and bounded. Open workspaces remain valuable for research, creation, troubleshooting, and other work where the user must shape the path.

The decision is not inline good, destination bad. The decision is whether the surface matches the structure of the job.

Design for comprehension and emotional outcome

Removing a click does not improve an experience when the user becomes less certain about what happened.

AI products introduce emotional work: deciding whether to trust an answer, wondering whether an action occurred, checking for fabricated detail, and recovering when the system fails. Design should reduce that burden.

Start with two outcomes:

  1. Functional outcome: what the user needs to complete, decide, create, or change.
  2. Emotional outcome: how the user needs to feel to proceed, such as informed, confident, in control, reassured, or appropriately cautious.

Delight is not confetti around a generated answer. It can be the relief of a clean recovery, a clear explanation of missing evidence, a handoff that preserves context, or an agent that remembers the agreed boundary without pretending to be human.

Friction can support comprehension. Reviewing an editable plan before execution, confirming a high-consequence action, or selecting the relevant source may add steps while improving control. Remove avoidable effort. Keep the interaction that helps the user form an accurate mental model.

Test comprehension directly:

  • Can the user explain what the system did?
  • Do they know which information it used?
  • Can they distinguish a draft, recommendation, and completed action?
  • Do they understand what requires verification?
  • Can they predict what will happen after the next control?

A fast workflow with a false mental model is not usable.

Replace the blank page with affordances

“Ask anything” transfers capability discovery and prompt design to the user.

Offer structure:

  • Suggested actions based on the current context
  • Examples that reveal scope and expected inputs
  • Forms for known constraints
  • Editable plans before multi-step execution
  • Visible files, sources, tools, and selected data
  • Progressive access to advanced capability

Structure improves usability and can also improve reliability by narrowing inputs. Preserve free-form control where users need it, but do not make free-form prompting the price of entry.

Design a shared human-agent workspace

When a person and agent work on the same artefact, the interface must show more than another cursor.

Users need to see:

  • What the agent is changing
  • Which context and sources it used
  • Which actions are proposed, active, complete, or blocked
  • What requires approval
  • How to interrupt, edit, undo, or retry
  • Which changes came from a human and which came from an agent

Use diffs, plans, activity history, checkpoints, and reversible actions. Avoid streaming every internal step. Visibility should support control, not create operational noise.

For software products, design for both human and agent access. Stable APIs, tool schemas, permissions, and machine-readable state matter alongside the human interface. A browser-only workflow can force agents into brittle imitation of clicks.

Match UX to autonomy

Four workspaces show different interaction patterns for increasing levels of AI autonomy.

Autonomy changes the contract.

ModeUser roleEssential UX
SuggestionChooses every actionClear accept, edit, dismiss, and source access
Plan and approveReviews intent before executionEditable plan, action scope, cost or consequence preview
Supervised delegationReviews exceptions and sampled workProgress, escalation queue, audit trail, pause and rollback
Bounded autonomyMonitors outcomes and controlsAggregate health, alerts, permission management, incident recovery

Do not treat movement toward full autonomy as inevitable progress. Some high-judgement workflows should remain assisted even when the model improves.

The agentic patterns chapter covers architecture. Every Agent Needs an Owner covers operation after release.

Communicate uncertainty without fake precision

Confidence scores are useful only when they are calibrated to the task and understandable to the user. A green badge can create more over-trust than no score at all.

Prefer evidence the user can act on:

  • Show sources and the exact passages used
  • Distinguish observation from inference
  • Highlight missing or conflicting information
  • Explain which part of a result is uncertain
  • Offer a verification path
  • Abstain when the system lacks required context

Use numeric confidence when it has been validated against real outcomes and the user knows how it should change their behaviour. Otherwise communicate uncertainty directly through the work.

Provenance and authenticity

Synthetic abundance changes what users need to know.

For generated or materially transformed content, design clear answers to:

  • Was AI used?
  • Which parts were generated, edited, or approved by a person?
  • What source material informed the result?
  • Can the user inspect or verify it?
  • Who is accountable for publishing or acting on it?

Disclosure should be proportionate. An autocomplete suggestion does not need a warning banner on every word. A synthetic spokesperson, customer communication, professional recommendation, or altered image may need prominent disclosure and provenance.

Do not rely on unreliable AI-content detection as the only mechanism. Capture provenance during creation: model and tool use, source references, human edits, approval, and publication history.

Authenticity is not the absence of AI. It is an honest relationship between origin, intent, and representation. A human can use AI extensively and still create authentic work when they exercise judgement and accept ownership. A synthetic persona designed to appear human without disclosure violates that contract.

Generative UI needs a bounded vocabulary

Agents can render tables, forms, charts, cards, and confirmation controls rather than returning walls of text.

The design system becomes a trusted vocabulary. Each component should define:

  • Allowed data and states
  • Interaction and accessibility behaviour
  • Permission implications
  • Empty, loading, uncertain, and error states
  • How the user confirms consequential actions

The agent can select and populate components. It should not invent arbitrary interaction patterns for high-impact work.

Dynamic layout also needs consistency. Preserve location, hierarchy, and state so the user can form a mental model across runs.

Recovery is part of the primary flow

AI systems fail through wrong answers, missing context, tool errors, timeouts, permission denials, and partial execution.

Design recovery for each:

  • Preserve the user's input and completed work
  • Explain what failed in useful language
  • Show whether any external action occurred
  • Offer retry only when retry is appropriate
  • Provide a non-AI path where one exists
  • Transfer full context during human handoff
  • Make undo or compensation visible for reversible actions

“Something went wrong” is insufficient when the system may have sent an email, changed a record, or charged a customer.

Voice and multimodal work

Voice, image, and video change interaction constraints.

Voice requires low perceived latency, confirmation of critical details, conversational repair, and a human handoff that preserves context. Images and video require provenance, selection tools, and clarity about what was observed versus inferred.

Multimodal input can reduce user effort. It can also collect more sensitive context than the task requires. Make capture, retention, and use visible.

The Voice Agents in Production playbook covers the operational detail.

Measure the relationship

Track whether users are getting value and calibrating trust:

  • Adoption by job, not feature visit
  • Suggestion acceptance and later reversal
  • Override and correction rate
  • Escalation and abandonment
  • Time to recover from failure
  • Source inspection before consequential action
  • Repeat delegation for the same job
  • User-reported control and understanding
  • Comprehension of state, source, and next action
  • Confidence and continuation after recovery

High acceptance is not always success. It may indicate excellent assistance or uncritical automation bias. Pair behaviour with outcome quality.

Anti-pattern: the invisible boundary

A product lets an agent research, edit records, and send messages from one conversational surface. The user cannot tell when the system moves from drafting to acting. Sources disappear inside the summary. The confirmation button looks the same for a local edit and an external action.

The interface is simple because the boundaries are hidden.

Good AI UX makes complexity manageable. It does not conceal consequence. The user should always understand the current state, the next action, and who owns what happens.

v3.1 · Updated July 2026