Human–AI interaction

Principles for Designing Human–AI Interaction

An applied framework for designing AI interfaces that support appropriate reliance, user control, transparency, and responsible autonomy.

  • 39 principles

    Practical rules for suggestion, review, refusal, and recovery when the same input can produce different outputs.

  • Nine categories

    From probabilistic foundations to sustained reliance — a map for the whole AI product surface.

  • Appropriate reliance

    The job is not maximum trust. It is helping people rely on AI only as far as the system deserves.

  • Human at the helm

    Accept, edit, undo, and escalate stay first-class. Autonomy is bounded by stakes and reversibility.

The framework

Nine categories. One practice.

Traditional interfaces assume predictable behavior. AI systems return a distribution. These categories help teams decide when to suggest, ask, or act — and how to keep people responsible for the result.

01 / 09

Probabilistic Foundation

Treat the model as a probabilistic service. Design for inference, generation, and the spread of possible outputs — not a single fixed function.

02 / 09

Expectation Setting

Users form a mental model before they read the first result. Clarify capability, limits, and AI involvement early.

  1. Principle 5

    Solve the blank-canvas problem

    An empty prompt box hides what the product is good at. Use examples, templates, and starter actions to reveal range and make the first move easy.

  2. Principle 6

    Frame output as a starting point

    Labels teach users how to treat a result. “Draft,” “suggestion,” and “review” invite inspection. “Answer” or “done” can imply more finality than the system earned.

  3. Principle 7

    Signal the AI’s role explicitly

    People should know when content was generated, summarized, ranked, or recommended. Hidden involvement creates false attribution to sources or authors.

03 / 09

Calibrated Trust

Match reliance to reliability. Reduce overtrust in weak output and underuse of useful help.

  1. Principle 12

    Make output cheap to verify

    Appropriate reliance depends on cheap checking. Highlight what changed, link the source, and keep verification to a glance rather than a second investigation.

  2. Principle 13

    The system must not run its own agenda

    The assistant should serve the stated task, not a hidden upsell, engagement, or retention goal. Secret objectives corrupt reliance at the root.

  3. Principle 15

    Respect creators and attribution

    Do not present borrowed phrasing, distinctive ideas, or licensed material as if the system invented them. Make the relationship to source content visible.

04 / 09

Transparency

A black box cannot be trusted appropriately. Make reasoning and evidence inspectable without drowning the workflow in noise.

  1. Principle 16

    Answer the five intelligibility questions

    Users ask what the AI did, what it used, why this result, why not another, and what would change the outcome. Answer those questions at the right depth.

  2. Principle 18

    Show plans and traces for multi-step work

    When an agent plans and acts across steps, render the plan. Show progress, tools, and pending approvals — never hide consequential work behind a silent spinner.

05 / 09

Control & Agency

Human and system share the wheel. Accept, reject, edit, undo, and override should stay one gesture away.

  1. Principle 20

    Ask, don’t guess, when uncertain

    When ambiguity would change a consequential result, ask a specific question. If the risk is low and recovery is easy, continue and make the assumption visible.

  2. Principle 21

    Give global and granular controls

    Granular controls shape one result. Global controls define standing behavior: memory, data access, autonomy, and defaults that should not be restated every time.

  3. Principle 22

    Time interventions to attention

    A correct suggestion at the wrong moment is an interruption. Weigh the cost of breaking focus against the value of the help, and stay quiet when the math says so.

  4. Principle 23

    Make AI assistance accessible and inspectable

    Generated edits, citations, warnings, and traces must work with keyboards, readers, and varied cognitive load. Announce changes. Do not hide the work in a visual-only layer.

06 / 09

Graceful Failure

Error is the default case, not the edge case. Make uncertainty, recovery, and escalation first-class paths.

  1. Principle 27

    Design the human handoff

    When the system hits its limit, escalate with context: what was tried, what is uncertain, and what to do next. A cold restart is its own failure.

  2. Principle 28

    Design the refusal path with good intent

    Assume a legitimate goal, then apply a safeguard only where risk is clear. State the limit, explain it briefly, and offer the nearest safe next step.

07 / 09

Co-Creation

Keep the artifact malleable. Treat generated work as a draft the user can shape, not a verdict they must accept.

  1. Principle 29

    Keep generated output malleable

    Let people edit in place, revise a selection, regenerate a section, and continue from the current state. Generated work should behave like material, not a sealed deliverable.

  2. Principle 31

    Help users specify intent

    Users should say what they want, not learn hidden prompt tricks. Expose controls, examples, and structured inputs so intent is visible and refinable.

08 / 09

Responsible Autonomy

The more the system acts on its own, the more the interface is a governance surface. Bound action by stakes, reversibility, and permission.

  1. Principle 34

    Protect third-party privacy

    The previous rule governs the user’s data. This one governs everyone else’s. Do not assemble, infer, or surface private context about people who are not in the room.

09 / 09

Sustained Reliance

Keep the conditions of healthy use intact over time: wait states, cost, quality, drift, ownership, and change.

  1. Principle 36

    Design the wait, not just the result

    An unexplained pause weakens confidence. Stream when useful, show staged progress, and give a safe way to cancel or continue in the background.

  2. Principle 38

    Measure reliance, not just usage

    High acceptance can mean value or overtrust. Regeneration can mean exploration or poor first-pass quality. Measure whether reliance is healthy, not only frequent.

  3. Principle 39

    Design for model and data changes

    Models and data will change. Version the experience, pin behavior with evaluations, and treat a swap like a dependency upgrade — not a silent break.