Ask ten AI agent vendors whether their product is "autonomous" and all ten will say yes. Ask what that word actually means in their product, and you'll get ten different answers because "autonomous" has become one of those words that everyone uses and almost nobody defines. For a buyer trying to evaluate vendors, or a founder trying to describe their own product honestly, that ambiguity is a real problem. It's also, it turns out, avoidable the language itself gives it away, if you know what to read for.

Reading through the product pages, funding announcements, and customer case studies of more than 200 companies building AI agents, one pattern separated the agents that genuinely act from the agents that advise a human who then acts. It wasn't the pricing page. It wasn't the logo wall. It was the verb.

The Verb Test

Every product description eventually has to describe what the agent does. Two very different sets of verbs show up, and they tell you two very different things about who's actually pulling the trigger.

The agent commits: submits, files, issues, posts, books, pays, executes, negotiates, awards, binds, settles.

A human commits: recommends, flags, surfaces, suggests, identifies, assesses, analyses, drafts, prepares, scores, highlights.

The first list describes an action landing in the real world with no further step required. The second describes information handed to a person who then decides. Both are legitimate products. They are not the same product, and they don't carry the same risk. A tool that "flags" an anomaly for a human to review has a person as the last checkpoint before anything happens. A tool that "issues" a refund does not the action is already done by the time anyone finds out about it.

Read a vendor's homepage with this lens and the ambiguity mostly disappears. If every verb on the page comes from the second list, you're looking at an assistant, however much the word "autonomous" appears elsewhere on the site. If the verbs come from the first list, you're looking at something that commits actions on its own and that's the product category where checking the action actually matters.

The Phrase That Never Appears by Accident

There's one phrase worth watching for specifically: "without human intervention." Nobody puts that phrase in marketing copy by mistake. It's not vague, it's not aspirational language, and companies don't include it unless it's true and they want you to know it. When you see it, take it at face value it's a company telling you, plainly, that a real action happens with nobody checking it first.

The same goes for a published autonomy percentage. When a company advertises 93% resolution, 96% automation, or 84.5% auto-resolution, that's not a soft marketing number it's usually an internal metric the company is proud enough of to make public. Read it as exactly what it says: that share of the company's volume runs unattended, action and all.

What This Looks Like in the Wild

Reading actual product descriptions with this lens is more revealing than it sounds. A few examples, entirely in the companies' own published language:

A healthcare voice AI company describes refill requests as automatically processed for delivery and logged on a patient's prescription profile "without agent involvement" deployed across more than 45 health systems. That's list-one language, plus the phrase, plus real clinical infrastructure behind it. Read literally, not aspirationally.

A property-operations company describes a single guest message triggering an agent that files a damage claim, buys a replacement item, and issues a credit end to end, no human step described anywhere in the sequence. Their published automation rate: 84.5%. Again: verbs from the first list, a specific percentage, no hedge.

A billing and AR company describes tens of thousands of pieces of work completed in a 30-day window, with only genuine edge cases routed to a person. In their own words, the rest auto-approves. That's not an assistant drafting invoices for someone to send. That's the sending.

A patient-access company runs a live public counter on its homepage resolved actions against a small number flagged for review and states plainly that the agent itself decides what counts as sensitive enough to flag. That last detail matters as much as the percentage: the system, not a person, is making the judgment call about what needs a second look.

An insurance company reports over half of claims fully automated start to finish, the large majority of first notices of loss taken with no human intervention at all, and some settlements completed in two seconds. Every verb here is list-one. There's no ambiguity to read past.

None of this is a criticism of these companies this is exactly what a functioning autonomous agent is supposed to do, and the volume numbers are the product working as designed. The point of reading the language this closely isn't to catch anyone overselling. It's the opposite: these companies are being unusually precise about what their product actually does, and that precision is worth taking at face value rather than assuming it's marketing inflation.

Why This Matters More Than It Looks Like It Should

Once you can sort a vendor's language into "the agent commits" versus "a human commits," a second, more useful question follows naturally: for the vendors in the first category, what's actually checking the action before it lands? Not the model's training, not a permission scope set at the start of the session, not a dollar-threshold rule that only looks at amount. Those all matter, but none of them evaluate whether this specific action, on this specific record, is the right one which is exactly the gap that opens up the moment a vendor's own language tells you a human isn't in that path anymore.

This is the layer Salus is built for. Salus is a runtime control plane that sits between an agent and the tools it calls: every proposed action is checked against policy and evidence before it executes, whether the agent is filing a claim, issuing a refund, or moving money. Actions that don't hold up are blocked, clarified, or escalated with a decision receipt attached, and most actions ship untouched. In controlled testing on AgentDojo's banking environment with GPT-4o-mini, adding this kind of check brought mean prompt-injection attack success down from 47.7% to 0.69% across three repetitions the specific failure mode that opens up once "the agent commits" verbs are accurate and nobody's reviewing the individual action.

Reading a Vendor's Page Before You Buy

Next time you're evaluating an AI agent vendor, skip the adjectives and read the verbs. Look for "without human intervention" and take it literally rather than as a flourish. Treat a published autonomy percentage as an honest disclosure, not a boast. And once you've confirmed you're looking at a product where the agent genuinely commits actions, ask the one question the product page won't answer for you: what's checking this specific action before it fires?

"Autonomous" isn't a marketing word that needs decoding because vendors are being evasive. Most of them are being precise it's just precise language that most readers skim past. Read it literally, and the product tells you exactly what it does.