Sudden handoff is the most dangerous form
Aliases: surprise takeover · unannounced transfer · startle handoff
What it is
Control dumped on a person who did not expect it is sudden handoff. No preview, no transition in which “the system is still holding,” the person is rewritten from bystander to actor in an instant. The danger is not the passing of control; it is that with zero expectation the first reaction is startle and grabbing the most salient control, not entering the situation.
“Please take over immediately” from a car that was playing a film a second earlier is this form. An agent that ran twenty silent steps and then pops “failed, your turn” is this form too.
Why it happens
Startle clears a piece of working memory; attention is captured by the sound and light, landing on the alarm itself rather than the world the alarm points at. Endsley’s three layers do not get to run: perception is eaten by the alarm, comprehension has no material, projection is replaced by “do something.” Suddenness is a timing property — whether the transfer had a lead relative to the person’s expectation. It is not the same as “the system only hands over at maximum complexity”: that is a coupling of reason-for-handoff with situational difficulty; this is whether the person was aligned in advance.
Products default to sudden handoff because internal failure detection is instantaneous, and the instant is mapped straight onto an instant for the person. The machine’s detection moment is not the person’s ready moment.
Studying it
Compare three timings: no-preview sudden transfer, preview without a brief, preview with the system holding during the preview. Dependent variables: startle ratings, whether the first act hits the alarm control rather than the task object, how long post-takeover error lasts. Independent variables: presence of preview, alarm channel (sound / modal / log only), whether the person’s current activity is interrupted at transfer.
The variable to isolate is “sudden,” so preview can be short; what matters is whether the person formed an expectation of “I am about to take it.”
Where it stops holding
When the world is already falling toward the irreversible and one more second costs more, a sudden stop of the machine may be right — that is an emergency stop, whose goal is freeze first, not let the person keep driving. If the person has been holding control all along, nothing is suddenly passed over. This entry does not prescribe what a brief contains, nor how much rebuild time a person minimally needs.
Applying it
- Forbid jumping from “person not on post” to “person must execute.” Put at least one perceptible preview beat in between, and in that beat the system continues to hold on a safe default.
- Do not make “take over now” the only large button on the alarm. The first act should be “open the situation”; takeover is the second.
- Check: trigger a transfer while the person is doing something else. If the first hit is always on the alarm, and a wrong task act follows, that is sudden handoff — add preview, rather than making the alarm louder.
Related
- Same group: L4.04.1 Handoff needs enough time to rebuild the situation · L4.04.2 The system state at handoff must be fully briefed · L4.04.4 Handoff quality depends on whether the giver explains how the situation was reached · L4.04.5 Time to rebuild the situation is a hard constraint and cannot be squeezed to zero · L4.04.6 The system hands off when it loses its grip, which is when the situation is most complex · L4.04.7 Responsibility transfers immediately after handoff; the transfer must be confirmed by the taker, not assumed · L4.04.8 Reverse handoff needs design too; when a person hands back, they must say what they changed
- Nearby: L4.13 Agent Failure Reporting and Escalation · L1.06 Graceful Degradation of AI Failure · L4.03 Automation Complacency
- Search terms:
surprise takeover·sudden handoff·startle
Cards in the same group
- L4.04.1Handoff needs enough time to rebuild the situation
- L4.04.2The system state at handoff must be fully briefed
- L4.04.4Handoff quality depends on whether the giver explains how the situation was reached
- L4.04.5Time to rebuild the situation is a hard constraint and cannot be squeezed to zero
- L4.04.6The system hands off when it loses its grip, which is when the situation is most complex
- L4.04.7Responsibility transfers immediately after handoff; the transfer must be confirmed by the taker, not assumed
- L4.04.8Reverse handoff needs design too; when a person hands back, they must say what they changed