28 Aug 2026 · LinkedIn · 6 min read
The permission gap
Models can already do the work. The product is whether anyone will let them.

Here’s a question I keep coming back to: the models are good enough to plan a trip better than most travel agents, so why hasn’t an AI travel company disrupted Booking or Expedia yet?
Partially I don’t think it’s because the technology isn’t ready. I think the answer is more interesting than that — namely that some workflows contain their own utility. Browsing hotels and fantasizing the trip is part of the experience.
But the bigger reason is that just because an agent can, doesn’t mean we’ll give permission. The fact that an AI can book my whole vacation, unsupervised, with stored credentials and credit card details, doesn’t mean I’ve decided to let it. And here’s the thing about permission — it doesn’t move at the speed of the models. Permission moves at the speed of culture, identity, and human preference.
Different categories, different gaps
Spam filtering: I’ll let an AI kill my spam email and reroute me around traffic without a second thought. Investing: here I hesitate, even though the capability already exists. I could wire an agent to Robinhood with set parameters and have it send market updates and ask before it re-weights or cycles positions. Instead I still read the equity research myself and stay concentrated in a few AI-infra, pharma, and consumer internet names. I prefer to keep my hand on the wheel. Moving money: assuming it is reversible, and the transaction is executed by an institution I trust, I would happily delegate.
Whilst activities we’re uncomfortable outsourcing today, norms shift and trust can be earned. History says the stickiest behaviours and markets are often the most disruptable: online credit-card entry looked insane in the ’90s, Uber with strangers’ cars, Airbnb with strangers’ homes. Each was unlocked by a specific mechanism — Airbnb provided guarantees, insurance, ratings; online credit cards, reversibility with chargebacks. More recently, coding agents and support bots earned permission quickly because the downside was low, verification was easy, and actions were reversible.
That permission gap is where the real opportunity lives. A great startup’s job isn’t to respect the gap; it’s to manufacture permission faster than culture would grant it on its own. Incumbents like Booking are trapped by the permission their brand already has, and that’s the attack surface. Other big gaps today exist within health, money, kids, eldercare — and are also the biggest markets.
A rough model
Permission Gap ≈ (downside severity × irreversibility × error rate) ÷ trust
The short-term goal shouldn’t be more autonomy. It’s earning your way across the gap. A few things I’d design around:
- Earned delegation: start with small, reversible tasks and widen the mandate as trust is proven. Trust has become the make-or-break attribute because these apps are data-hungry and ask for real access — calendar, email, payments, preferences, credit cards — up front in a way earlier consumer software never did.
- Paid exploration: let people pay the AI to explore options. The searching itself has value, even when they make the final call.
- Persistent taste models: remember what this person likes, over years, not sessions. Travel agents that win won’t just recall that you like boutique hotels with good coffee. The agent should anticipate the version of the trip that makes you feel most like the person you want to be.
- Collaborative workspaces: a place to work with the AI, not a black box that acts for you. Leave the user feeling more capable and more themselves.
- Outcome verification: show your work, and make the result easy to check.
- Final-choice influence: inform the decision, but leave the last click to the human.
The winners won’t be the most capable agents. They’ll be the ones that earn the most permission from consumers.
Early adopters — power users, the AI-curious — may tolerate more autonomy and data asks. The mass market will not. You have to work your way there.