Content material filters can block unsafe output. They can’t inform you whether or not an agent was approved to difficulty that refund, contact that manufacturing system, or commit the corporate to an exterior motion. These are completely different issues, and most enterprises are solely fixing the primary one.
An AI agent can comply with its directions completely and nonetheless take an motion the enterprise by no means sanctioned.
In commerce environments, I’ve seen this sample emerge in sensible methods. A service workflow calculates the right refund quantity however lacks a boundary stopping credit above what the enterprise accepted for autonomous motion. An order agent accurately applies a requested change however overlooks a financing or achievement situation. A procurement agent identifies the lowest-cost provider, however no one has outlined whether or not it may possibly settle for contractual phrases or solely advocate the choice.
The agent retains working. The issue might not floor till one thing downstream breaks.
These aren’t essentially AI reasoning failures. They’re failures to separate technical functionality from enterprise authority.
As enterprises transfer from copilots that advocate to brokers that decision instruments and set off workflows, each manufacturing agent wants specific determination rights: What it might execute, what requires approval, what it might solely advocate, and what it must not ever contact.
Guardrails stay obligatory. However a guardrail just isn’t an authority mannequin.
Security controls and determination rights clear up completely different issues
Early gen AI controls display screen dangerous content material, defend delicate data, validate responses, and constrain software conduct. That work issues.
Choice rights reply a distinct query: Even when an motion is secure and technically legitimate, is that this agent approved to take it on behalf of the enterprise?
That governance hole is turning into more durable to disregard. In April 2026, a Cloud Security Alliance survey discovered that 65% of respondents had skilled an AI-agent-related incident within the prior yr, whereas 82% had found beforehand unknown brokers working of their environments. The survey concerned 418 IT and safety professionals and was sponsored by Token Safety.
The findings illustrate how rapidly agent exercise can outpace the visibility and possession constructions constructed for standard software program.
The World Economic Forum’s May 2026 playbook displays this shift. It introduces an Agent Functionality and Authorization Profile designed to make delegated actions auditable, enforceable and accountable.
Guardrails constrain conduct. Choice rights outline respectable authority.
Give each manufacturing agent an authority contract
Earlier than an agent receives entry to enterprise instruments, it wants a machine-enforceable report of precisely what authority the enterprise has chosen to delegate. Name it an Agent Authority Contract.
At minimal, that contract ought to reply seven questions:
-
Who owns the end result? Title a human or enterprise function, not one other system.
-
What might the agent do? Learn, advocate, write, or commit?
-
Which methods and information might it attain?
-
What materiality limits apply? Outline greenback thresholds, report counts, buyer scope, and operational impression.
-
What triggers escalation? Uncertainty, anomaly, delicate information, or potential impression?
-
Can the motion be reversed, and who can reverse it?
-
When does the authority expire, and the way is it withdrawn?
Entry management determines whether or not an agent can attain a system. The authority contract determines whether or not it might take a selected motion within the present context.
These aren’t the identical verify.
Singapore’s up to date Model AI Governance Framework for Agentic AI attracts the same distinction. It treats entry controls, behavioral guardrails, and human approvals as separate controls and ties oversight necessities to motion scope, reversibility and potential impression.
Resolve each consequential motion into 4 outcomes
A working decision-rights mannequin ought to map each consequential agent motion to certainly one of 4 outcomes.
Permit
Low-risk, bounded, and reversible actions run autonomously.
Examples embrace retrieving accepted data, classifying an inbound request, or updating a non-material discipline. The agent acts with out prior assessment as a result of the potential impression is proscribed and the motion might be reversed.
Approve
The agent prepares or initiates the motion, however execution waits for authorization from a human or deterministic coverage service.
This class covers funds, manufacturing modifications, and actions that materially have an effect on a buyer, worker, or third get together.
Advocate
The agent analyzes, ranks, drafts, or proposes. A named human makes the ultimate determination.
Use this consequence when contextual judgment issues or when the authorized, monetary, or particular person impression makes automated execution unacceptable.
Deny
The motion stays exterior the agent’s authority no matter its confidence.
Deleting crucial manufacturing information, making a remaining employment determination or overriding a compulsory compliance management ought to stay within the Deny class even when the agent’s underlying reasoning seems right.
One level will get missed constantly: Deny should be enforced exterior the system immediate.
A natural-language instruction telling an agent to not do one thing just isn’t a technical boundary. It’s a suggestion.
Make authority selections at runtime
Static configuration can’t cowl each state of affairs.
A small service credit score is likely to be allowed beneath regular situations however require approval when the quantity crosses a threshold, the account is beneath investigation, or the request includes a regulated buyer.
A sensible runtime sequence seems to be like this:
-
The agent proposes an motion.
-
A coverage layer evaluates the agent’s identification, delegated principal, requested software, information concerned, transaction context, and potential impression.
-
The coverage returns Permit, Approve, Advocate, or Deny.
-
The system information the authority determination, ensuing motion and consequence.
-
Operational telemetry expands, narrows, or revokes the agent’s authority over time.
In enterprise commerce, probably the most harmful AI mistake just isn’t all the time a false reply. It may be a technically right motion the agent had no enterprise taking.
A refund could also be correct however exceed an approval restrict. An order change might match the client’s request however invalidate a financing situation. A supply promise might mirror accessible stock whereas overlooking a provider constraint utilized an hour earlier.
The agent might not have did not purpose. The enterprise did not outline the place its authority stopped.
Human oversight ought to goal exceptions, not every thing
Requiring human approval for each agent motion seems to be conservative. At scale, it may possibly rapidly degrade into rubber-stamping.
When reviewers approve hundreds of routine actions, consideration declines and real exceptions grow to be more durable to establish. Singapore’s framework acknowledges that steady human oversight of each agent workflow turns into impractical at scale and recommends significant checkpoints for higher-risk or irreversible actions.
Proportional authorization is the extra workable mannequin.
Low-risk actions run inside slender boundaries. Excessive-risk or irreversible actions require approval. Surprising conduct triggers escalation. Any consequential motion with no outlined authorization coverage is denied by default.
The target just isn’t most autonomy. It’s the highest degree of autonomy the enterprise can observe, govern and reverse responsibly.
Measure whether or not authority is calibrated
As soon as brokers are in manufacturing, response accuracy turns into too slender a hit metric.
Enterprises must also monitor:
-
Override price: How usually do people reject or materially change what the agent determined?
-
Escalation precision: Does the agent floor genuinely dangerous circumstances, or does it return routine work to folks?
-
Unauthorized-action makes an attempt: How usually does the agent attempt to exceed its system, information, or motion scope?
-
Enterprise-impacting error price: How usually do approved actions produce monetary, compliance, operational, or buyer hurt?
-
Choice latency: Are approval necessities managing danger, or slowing down automation that was already secure?
These measures flip authority right into a ruled working variable.
Constantly dependable efficiency might justify increasing bounded authority. Frequent overrides, escalation failures, or coverage violations ought to slender it.
The governance hole just isn’t within the mannequin
Mannequin security, output controls, and safe software use all matter. Enterprises ought to proceed investing in them.
However none of these controls can reply who delegated authority, how a lot was transferred, beneath what situations it applies, or who owns the consequence when one thing goes improper.
An Agent Authority Contract can.
Earlier than asking how autonomous an AI agent can grow to be, the extra helpful query is: What’s the enterprise truly ready to delegate, and the way will that delegation be enforced, noticed, and withdrawn?
The agent demo works. That isn’t the arduous half anymore.
Nixal Patel is a product chief. The views expressed are his personal
