Agentic AI UX checklist
An agent is an AI feature that does things rather than only saying things: it sends the email, books the meeting, edits the files, makes the purchase. The usability questions change. A wrong answer in a chat costs a reread; a wrong action can cost money, data or a relationship, and some actions can't be taken back.
This checklist covers the controls people need around an agent: what it is allowed to touch, seeing the plan before it runs, approving the risky steps, stopping it, undoing what it did, and reviewing a record afterwards. It draws on Apple's guidance on irreversible actions, Microsoft's principles for agent UX, Microsoft's Guidelines for Human-AI Interaction, and the OWASP Top 10 for LLM applications, where excessive agency and prompt injection are listed risks.
Download the PDF
Agentic AI UX checklist as a print-ready PDF (A4, 133 KB). Everything in it is also free to read on this page.
How to use it
List every action the agent can take, and sort them by how reversible they are and who else they affect (only the user, or other people too). Then check the items below for the riskiest actions first.
Several items are as much engineering as design. Review them with the engineers who implement the agent's tools and permissions.
Ticks are saved in this browser only. Nothing you tick here is sent to UX Pickle.
Scope and permissions
OWASP's mitigations for excessive agency start with limiting the extensions, functionality and permissions an agent has to the minimum necessary. OWASP LLM06:2025 Excessive Agency
Microsoft's agent principles: an agent's knowledge, tools and connections are transparent and customisable. Microsoft Design: UX design for agents
People should be able to grant read access to a calendar without granting the power to cancel meetings.
OWASP recommends executing actions in the user's context and enforcing authorisation in downstream systems rather than letting the model decide what is allowed. OWASP LLM06:2025 Excessive Agency
A limit turns a runaway mistake into a bounded one.
Plan and preview
A plan is where a misunderstanding is cheapest to fix. Microsoft's G10 asks systems to scope their actions when in doubt. Microsoft HAX: Guidelines for Human-AI Interaction
Microsoft's G16: convey the consequences of user actions. Approving a summary of an action is not the same as approving the action. Microsoft HAX: Guidelines for Human-AI Interaction
Microsoft's G10: disambiguate or degrade gracefully when uncertain about the user's goal. Microsoft HAX: Guidelines for Human-AI Interaction
Drafts let people check the agent's work at no cost before trusting it with the real action.
Approval steps
Apple: avoid automating destructive actions and actions that are hard to undo, such as purchases, and ask for confirmation before a significant action on someone's behalf. OWASP lists human approval of high-impact actions as a core mitigation. Apple HIG: Generative AI
If every step asks for confirmation, people stop reading the confirmations. Sort actions by risk and only interrupt for the risky ones.
An approval dialog is only a safeguard if it contains the information needed to say no.
Mistakes that reach other people are harder to undo and more embarrassing than private ones.
While it runs
Microsoft's agent principles: agent status is clearly visible at all times, and background agents have a user-facing way to view and control their actions. Microsoft Design: UX design for agents
Microsoft's agent principles put people in control of when the agent is on or off. Microsoft Design: UX design for agents
PAIR recommends returning control to people when the AI fails, without making them start again. PAIR: Errors + Graceful Failure
A silent partial success is worse than a reported failure.
Undo and recovery
Microsoft's G9: make it easy to edit, refine or recover when the AI is wrong. Microsoft HAX: Guidelines for Human-AI Interaction
A send delay turns some irreversible actions into reversible ones for a few seconds.
An agent that changed fifty files should not need fifty undos.
People should never find out an action was permanent after it happened.
Activity log and accountability
Microsoft's agent principles call for a way to view and control actions and automations. Microsoft Design: UX design for agents
Microsoft's G11: make clear why the system did what it did. Microsoft HAX: Guidelines for Human-AI Interaction
Other people deserve to know when they are dealing with an automated action. In the EU, systems that interact directly with people must say they are AI (AI Act Article 50(1)). EU AI Act, Article 50 (EUR-Lex)
Background work people never see is work they can't check.
Untrusted content and prompt injection
OWASP describes indirect prompt injection: instructions hidden in external content that alter the model's behaviour. Its mitigations include segregating and identifying external content. OWASP LLM01:2025 Prompt Injection
OWASP lists requiring human approval for high-risk actions as a prompt-injection mitigation. OWASP LLM01:2025 Prompt Injection
OWASP recommends adversarial testing and attack simulations; Apple recommends testing harmful and out-of-scope requests. OWASP LLM01:2025 Prompt Injection
Sources
- Apple Human Interface Guidelines: Generative AI
- Microsoft Design: UX design for agents (April 2025)
- Microsoft HAX Toolkit: Guidelines for Human-AI Interaction
- OWASP Top 10 for LLM Applications 2025: LLM06 Excessive Agency
- OWASP Top 10 for LLM Applications 2025: LLM01 Prompt Injection
- Google PAIR: Errors + Graceful Failure
- EU AI Act, Article 50 (EUR-Lex)
Checked against these sources on 3 October 2026. Spotted something out of date? Email hi[at]uxpickle.com.