A boundary you can trust is made of four things, and making them explicit is not a documentation task but a change to the work that produces them. The rate at which you turn intent into checked boundaries, not the model or the seat count, caps how much you can safely automate.
A boundary splits into four parts, and the last three are not mechanical. Each handoff carries a judgement. So “can AI make the decision” is the wrong question: judgement runs the whole line.
An invariant is what others rely on, and you author only half of it. Your consumers mint the rest by depending on you (Hyrum’s Law). A check enforces only the half you declared; the undeclared half is found by exploration, not enforcement.
An autonomous agent stays green while every undeclared obligation it disturbs breaks in silence. Velocity widens the gap, it does not close it. A generator can run the bench but not the floor: discovery, ownership, and who owes what to whom is not a check.
AI cannot take the four judgements behind a boundary. It can assemble the menu of decisions you choose from. So the thing you audit moves up a level: from whether the decision is right to whether the support behind it was complete.
The loop can write correct code unattended. What it can’t do is grant itself permission — and in a regulated estate that gap is a gate, not a better checker.