Who Gave The AI Permission To Do That
- Aug 26
- 20 min read
Updated: Aug 28

For years, enterprise AI had a relatively comfortable job description: analyze information, generate an answer, and hand the result to a person. That boundary is disappearing. AI systems are beginning to retrieve records, modify systems, issue credits, initiate workflows, isolate endpoints, change software, and take other actions without waiting for a person to execute every step.
In each case, identity matters. The enterprise needs to know which human, machine, service, or agent is acting and what resources it can access. But identity does not answer the more consequential management question: Who gave the machine the authority to create that outcome?
The distinction is not merely semantic. In 2012, Knight Capital provided one of the clearest historical examples of what happens when machine execution outruns institutional control. A software deployment error caused its automated trading system to send more than four million orders into the market while attempting to fill just 212 customer orders. In approximately 45 minutes, Knight traded more than 397 million shares, accumulated billions of dollars in unwanted positions, and lost more than $460 million. The SEC later focused not only on the software failure but on inadequate controls designed to contain the risks created by automated market access.
Knight Capital was not using generative AI. That is precisely why the example matters. Enterprises have delegated consequential action to machines for decades. Agentic AI changes the combination of generality, adaptive reasoning, tool use, multi-step execution, machine speed, and the range of business activities over which machines can increasingly act.
The management problem is therefore larger than securing another class of machine identity. It is the governance of machine authority.
This argument also extends two ideas developed in earlier Alpha Decisions work. Where Does AI Value Actually Show Up? distinguished technological capability from realized economic value. Constraint Migration: The Next Challenge of Enterprise AI argued that when technology relaxes one constraint, another often becomes economically consequential. Governed machine authority is where those ideas converge: as intelligence and execution become cheaper and faster, authority, verification, intervention, and accountability can become the next scarce management capacities.
Autonomy is not a binary property of the agent. It is a distribution of decision rights across classes of consequence.
From Machine Identity to Institutional Authority
The technology market is already moving toward this problem. In February 2026, NIST published a concept paper specifically on software and AI-agent identity and authorization, addressing identification, authorization, auditing, non-repudiation, and the controls needed as autonomous agents gain access to enterprise tools, applications, and data.
Identity and security companies are moving quickly, too. Microsoft Entra Agent ID now provides purpose-built identities for autonomous and delegated agents. Okta is extending governance and runtime authorization to AI agents, including controls over individual connections and tool calls. SailPoint is bringing AI-agent identities into enterprise identity governance. BeyondTrust is moving privilege enforcement directly into agent execution, controlling what autonomous agents can do before they act. Palo Alto Networks is similarly extending dynamic privilege through Idira while Prisma AIRS moves from observing AI interactions toward authorizing autonomous execution.
Taken together, the direction is clear:
Identity → Access → Privilege → Authorization → Runtime Control
That is an important evolution, but it still leaves a management question that technical authorization alone cannot answer:
How much institutional authority should the enterprise economically want a machine to exercise?
Several concepts that are often collapsed together need to be separated. Capability asks whether the machine can perform an action. Identity establishes who or what is acting. Access determines which resources it can reach. Authority determines which institutional consequences it can create. Attribution connects an action back to the principal, delegation, policy, and actors that produced it. Accountability determines who is answerable for the outcome. Consequence determines what happens when that authority produces an undesirable result.
These distinctions matter because accountability is more than naming a responsible person or organization after the fact. Human institutions connect authority to consequences that can affect compensation, reputation, professional standing, wealth, freedom, organizational authority, or the ability to continue operating. As machines begin to exercise more consequential authority, preserving that connection between action, attribution, accountability, and consequence becomes increasingly important.
Those distinctions become important very quickly. A customer-service agent may legitimately access a customer's account without having authority to change contractual pricing. A cybersecurity agent may inspect an endpoint without having authority to revoke credentials across an enterprise. A finance agent may reconcile a payment without being authorized to execute it.
The authority chain is therefore broader than authentication:
Principal → Identity → Delegation → Purpose → Decision Rights → Action → Attribution → Consequence → Accountability
Decision rights can also be separated. A machine might be allowed to initiate, recommend, decide, execute, verify, or reverse an action without receiving all six rights. The meaningful question is no longer whether an agent is autonomous. It is autonomous to do what, on whose behalf, under which conditions, and with what potential consequence?
That gap is between securing an AI agent and governing an autonomous enterprise.

The Authority the Enterprise Never Formally Delegated
In 1997, economists Philippe Aghion and Jean Tirole distinguished between formal authority, the recognized right to make a decision, and real authority, effective control over what actually gets decided. Their work showed that the two can diverge when principals become overloaded, decisions become urgent, information is asymmetric, or the agent develops an informational advantage. (Duke People)
That distinction may prove unusually important in the age of AI.
Consider a manager who technically approves a decision. The AI collects the evidence, analyzes the alternatives, selects a preferred option, writes the rationale, presents the recommendation, and repeats the process hundreds of times. The human reviews the recommendation and approves almost every one.
Formally, authority remains with the human. Operationally, however, who is really making the decision?
A 2026 longitudinal study titled Habituation at the Gate examined 400 repeat reviewers and 11,429 reviews of AI-agent-generated code. As reviewers gained more exposure, approval rates rose from 30.1% to 36.8%. At the same time, inline comments declined 22% and review latency increased roughly 3.5 times. The researchers found the pattern more consistent with habituation under increasing workload than with rational trust calibration alone. (arXiv)
Meta has encountered a related systems problem at much larger scale. Its 2026 RADAR research reports that significant lines of code per human-landed diff increased 105.9% year over year and per-developer diff volume rose 51%, with agentic AI responsible for more than 80% of that growth. Meanwhile, timely human review became relatively scarcer. Meta responded not by placing more humans in every loop, but by building a risk-calibrated system that automatically lands qualifying low-risk changes after layered automated checks. (arXiv)

The Authority Alignment Gap
This creates what I call an Authority Alignment Gap. Formal authority, real authority, accountability, and intervention capacity can separate. A human may remain legally or organizationally responsible for an outcome while having diminishing practical influence over it.
That matters because organizations may reassure themselves that they have preserved human governance merely because a person remains somewhere in the workflow. Decades of automation research should make us skeptical of that assumption. Safety-critical domains have repeatedly found that humans are poorly suited to remaining attentive as passive monitors of highly reliable automation. The EU AI Act similarly requires human oversight for high-risk systems to include an ability to understand system limitations, recognize automation bias, disregard or override outputs, and interrupt operation—far more than simply placing a person nominally “in the loop.” (Eur-Lex)
The most dangerous machine authority may be the authority the enterprise never formally delegated but the machine already exercises in practice.
Human presence is not the same as effective human control.
Machine Authority Is a Form of Operating Leverage
Why would an enterprise delegate consequential authority to machines at all? Because authority has economics.
Organizations have always delegated decision rights because centralized coordination is expensive. Human approvals create handoffs. Handoffs create queues. Queues create latency. Supervision consumes scarce managerial attention. Monitoring, coordination, contracting, and review all impose economic costs on the enterprise.
Agency theory has long recognized the tradeoff. Delegating authority can improve economic efficiency, but delegation also creates monitoring costs, control costs, and the possibility that an agent's actions diverge from the principal's objectives. AI does not eliminate that old economic problem. It changes its scale, speed, and operating characteristics.
A capable AI agent can reduce approval latency, coordination effort, supervisory labor, transaction costs, and execution time while increasing throughput, availability, and organizational capacity. That is a form of operating leverage. The same enterprise can potentially execute many more decisions without proportional increases in human coordination.
But the same authority creates another economic effect. A machine that can execute one useful action at machine speed can potentially execute thousands of undesirable ones before people understand what is happening. The characteristics that make machine authority economically attractive—speed, scale, persistence, and automation—can also magnify value destruction.
Management therefore faces two very different ways of getting the economics wrong.
Under-delegation leaves economically useful AI trapped behind unnecessary human approval. The enterprise pays for machine capability but recreates the bottleneck immediately before execution. Capacity exists, but it cannot be converted into operating performance.
Over-delegation gives machines authority whose potential consequence exceeds the enterprise's ability to observe, contain, reverse, or absorb the outcome. The organization captures speed and scale but creates economic exposure beyond its control capacity.
The first leaves value unrealized. The second places value at risk.
Too little authority sacrifices value. Too much authority exposes it.
The management objective should therefore not be maximum autonomy. It should be economically productive governed autonomy.
Machine Authority Creates Value — and Exposes It
This two-sided economics deserves to be explicit.
On one side is Value Enabled. Greater machine authority can create faster execution, higher throughput, reduced coordination cost, lower supervisory burden, greater availability, more responsive customer interactions, better utilization of scarce expertise, and operating capacity that would otherwise require additional resources.
On the other side is Value Exposed. The same authority can create financial loss, customer harm, contractual commitments, operational disruption, regulatory consequences, cybersecurity events, intellectual-property exposure, or reputational damage.
The executive question therefore changes:
What incremental economic value does the next level of machine authority enable—and what incremental enterprise value does it expose?
That does not mean building another simplistic ROI calculator. As discussed in Where Does AI Value Actually Show Up?, arithmetic can estimate potential, but it cannot substitute for a causal model of how technological capability becomes economic value.
The point is to make the two economic effects visible and manage them together.
This is also where security enters the AI value case differently. If security is considered only through loss avoidance, the economic argument asks how much damage a control might prevent. But if stronger controls allow management to safely delegate authority that would otherwise be economically irrational, part of the value of security comes from economic activity that can now occur because the control exists.
Security can protect value.
It can also help unlock it.
The Governed Authority Frontier
It helps to think of machine authority as a frontier.
At low levels of delegation, additional authority can create considerable economic value. Routine approvals disappear, coordination costs decline, work moves faster, and scarce experts spend less time supervising repetitive actions. AI capability begins converting into operating leverage.
As authority expands, however, the economics change. Machines may begin affecting larger amounts of capital, more customers, broader operational systems, external commitments, or security infrastructure. At some point, the incremental value of additional autonomy can be overtaken by increasing agency costs, control costs, exception severity, and enterprise exposure.
That creates three broad regions.
In the under-delegated region, capable AI exists but human coordination remains the constraint. Value is left on the table.
In the governed-autonomy region, delegated authority creates more incremental economic value than the additional exposure and control burden it introduces.
In the over-delegated region, exposure, control complexity, exception severity, and potential losses rise faster than the incremental value of additional autonomy.
This is the Governed Authority Frontier.

The frontier is not fixed. Imagine two enterprises deploying equally capable AI agents. The first has weak identity controls, persistent privileges, little trajectory monitoring, poor observability, slow intervention, and limited ability to reverse consequential actions. Management rationally keeps substantial work behind human approval gates.
The second has strong identity, dynamic privilege, explicit delegation, runtime policy enforcement, state-aware authorization, effective monitoring, rapid intervention, and, where possible, reversible execution. That organization may rationally allow machines to execute more consequential work.
The difference is not AI capability.
It is governance capacity.
Controls that reduce the marginal exposure of delegated authority can move the Governed Authority Frontier outward.
That proposition has an important competitive implication. Two companies can have access to essentially the same AI capability yet extract different economic value from it because one has developed greater institutional capacity to govern consequential machine action.
Governance, in that sense, is not simply overhead imposed on autonomy. It can become a productive capability that allows the enterprise to use more autonomy.
The frontier also contains cliffs. Increasing a customer-service agent's authority from a $25 credit to a $50 credit may be incremental. Allowing a treasury agent to move from preparing a transfer to independently executing a $10 million payment crosses a qualitatively different boundary.
Legal obligations, fiduciary responsibility, fundamental rights, safety, and catastrophic-loss potential can create structural limits where conventional marginal economics is no longer enough. The objective is not to place every human and machine decision on one smooth ROI curve. It is to determine how far authority can rationally move within different classes of consequence—and where institutional boundaries should stop it.
Technical Permission Does Not Measure Economic Authority
Traditional access systems generally describe what an identity is technically permitted to do. That is necessary, but technical permission does not tell management how much enterprise value an action can create or destroy.
Consider two agents with similar write privileges. One corrects a customer address. Another changes contractual pricing across 50,000 customer accounts. Technically, both may be modifying records. Economically, they exercise radically different authority.
The same distinction applies in cybersecurity. An agent that isolates one suspicious laptop does not have the same economic authority as an agent that can change access policies or revoke credentials across an entire enterprise.
This suggests thinking about Economic Blast Radius rather than technical privilege alone.
Several dimensions determine that exposure: the consequence of one action, the scope of systems or people affected, the velocity at which actions can accumulate, the persistence of authority, the reversibility of the outcome, the degree of coupling to other systems or agents, how quickly undesirable behavior becomes observable, and how rapidly the organization can actually intervene.
Knight Capital remains a powerful example precisely because its error became catastrophic through the interaction of these factors. Machine-speed execution combined with broad authority and inadequate containment. The SEC also found that an internal system generated 97 automated emails related to the deployment problem before markets opened, but the organization did not act on them. Observation existed. Effective control did not.
Observation is not control if the enterprise cannot intervene before the consequence becomes irreversible.
A monitoring system can identify a problem accurately and still fail as a control mechanism if the machine acts faster than the enterprise can respond.
Accountability Is Also a Risk-Allocation Problem
Enterprises already have elaborate mechanisms for allocating the consequences of human decisions. Organization design assigns decision rights and responsibility. Legal entities, contracts, indemnities, insurance, financing structures, approval limits, governance bodies, and liability regimes can limit, allocate, or transfer portions of the resulting exposure. These mechanisms do not make risk disappear. They determine where consequences ultimately land.
Agentic systems complicate this because action can become distributed across models, agents, tools, vendors, policies, and human supervisors. An enterprise may know that an undesirable outcome occurred without being able to reconstruct which principal authorized the activity, which authority was delegated, which controls applied, when intervention remained possible, and who ultimately bore responsibility.
Governed authority therefore requires attribution to survive automation.
But attribution alone is not accountability. Accountability requires a credible connection between action and consequence. Human institutions rely on that connection because consequences influence behavior. Executives can be removed, employees disciplined, firms fined, directors sued, contracts terminated, licenses revoked, assets impaired, and in extreme cases individuals can face criminal penalties. Those mechanisms shape incentives before the failure occurs, not merely assign blame afterward.
AI creates an unusual asymmetry. A machine may increasingly exercise real authority while the economic, legal, and reputational consequences continue to fall on humans and institutions. The machine itself may not experience financial loss, reputational damage, imprisonment, or other forms of deterrence in the way accountable human actors do. That makes the design of external consequence mechanisms more important, not less.
The issue becomes harder when responsibility is distributed. A consequential outcome may involve an AI model supplied by one company, an agent configured by another, enterprise data and tools controlled by a third, policies established by management, and a human supervisor who nominally remains in the loop. If authority is distributed but consequences cannot be reliably attributed, accountability can become diffuse precisely when economic exposure is becoming more concentrated.
This also raises a deeper question around proposals to grant increasingly autonomous AI systems some form of legal personhood. Corporations already possess limited legal personhood, but their actions ultimately connect to owners, directors, officers, employees, creditors, insurers, regulators, and courts that can impose economic or personal consequences. If autonomous systems were granted institutional standing without an equivalent mechanism for consequence and deterrence, personhood could separate authority from meaningful accountability rather than solve the problem.
For corporate decision-making, the economically relevant issue is the residual exposure after controls and risk-transfer mechanisms are applied. A failure may first appear as customer remediation, operating loss, contractual liability, regulatory fines, litigation, an insurance claim, or asset impairment. Some of that exposure may be transferred or absorbed elsewhere. What remains can ultimately affect cash flow, enterprise value, the cost of capital, and equity value.
This is also a classic moral-hazard problem. When decision rights and consequences become separated—or responsibility becomes so diffuse that no actor expects to bear the consequences—risk-taking can increase.
Machine authority therefore cannot be governed through permission alone. It requires a credible chain from:
Authority → Action → Attribution → Consequence → Accountability
Attribution without enforceable consequence is not accountability.
An Authorized Action Is Not Necessarily an Authorized Trajectory
Agentic systems introduce another complication because they do not simply execute isolated requests. They pursue objectives through sequences of actions, use tools, inspect resulting states, revise plans, and continue.
An action that is acceptable in isolation may become unacceptable because of what happened earlier in the sequence.
A customer-service agent may be authorized to issue a $100 credit. Ten credits may remain entirely consistent with its delegated purpose. Ten thousand credits within an hour might indicate fraud, manipulation, system error, or an undesirable emergent strategy.
The technical authorization attached to the next $100 credit has not necessarily changed.
The state of the system has.
That means authorization increasingly needs to account for trajectory, accumulated exposure, changing conditions, and prior actions, rather than only asking whether an isolated transaction satisfies a static permission.
The broader management proposition is straightforward:
An authorized action is not necessarily an authorized trajectory.
Authority therefore needs to become state-dependent. Management should care not simply whether an agent is permitted to take the next action, but whether—given what has already happened, what is now known, how much exposure has accumulated, and what consequences may follow—the agent still possesses legitimate authority to continue.
Governed Authority Requires an Independent Control Plane
This has an architectural implication.
The mechanism that determines whether a machine may create a consequential institutional outcome should not depend solely on the same probabilistic reasoning process proposing the action.
An AI agent can reason, plan, and propose actions. But a separate Governed Authority Plane should evaluate different questions: Who is the principal? What mission was delegated? Which decision rights were granted? What is the current state? What trajectory has occurred? How much economic exposure already exists? Which policies apply? Is adequate evidence available? Can the action be reversed? Has an exception threshold been crossed?
This is more than another AI “guardrail.” It is an institutional control architecture.
The Governed Authority Plane should not be interpreted as a purely technical layer. It must connect to organizational design, legal structure, and economic consequence: who owns the decision, who may delegate authority, which entity is acting, who bears the risk, what consequences follow, and which mechanisms can limit or transfer those consequences.
Technology can enforce an authority boundary, but management still has to design it—and ensure consequential actions remain attributable to actors and institutions that can actually be held accountable.
Army Cyber Command provides a current example of the distinction. In August 2026, Lt. Gen. Christopher Eubank described AI agents being trained to the same job-qualification standards as people across cyber work roles and operating alongside them at machine speed. Yet Army Cyber has not simply transferred risk-bearing authority along with the work. Eubank said the command continually asks which risks humans should answer and which might eventually be delegated to agents, while emphasizing that agents have not yet been allowed to assume risk independently. (Breaking Defense)
The separation is important because work capability, decision authority, and risk ownership do not have to migrate together.
A machine may perform most of the operational work while people retain authority over a smaller number of consequential decisions. In another setting, a machine may receive authority to execute routine actions but not to change the policy governing those actions.
The architecture should make those boundaries explicit.
Authority Should Be Earned Through Evidence
The choice between human control and machine autonomy is often framed too crudely.
Financial economics provides a better lens.
Real Options theory addresses decisions made under uncertainty when commitments can be staged rather than made all at once. Instead of committing everything before uncertainty resolves, management can invest enough to learn while preserving the option to expand later, defer additional commitment, contract the investment, switch direction, or abandon it if evidence deteriorates.
Lenos Trigeorgis’ classic treatment of Real Options describes precisely this managerial flexibility: the ability to defer, expand, contract, abandon, switch use, or otherwise alter an investment as uncertainty resolves. Real Options has been applied to natural resources, R&D, new technologies, flexible manufacturing, and other settings where uncertainty and irreversibility make static capital-budgeting approaches incomplete. (MIT Press)
Machine authority can be managed in much the same way.
An enterprise does not have to decide on day one whether an AI agent should remain advisory forever or receive broad autonomy. It can grant a narrow authority envelope, observe actual performance, measure exceptions, verify the effectiveness of controls, and then expand, maintain, contract, switch, or revoke authority as evidence accumulates.
That produces a more rigorous principle than saying an organization should grant agents greater autonomy as it begins to “trust” them.
Authority should be earned through evidence, not inferred from capability.
Technical capability establishes what the machine can do. It does not establish what the institution should permit it to do.
A customer-service agent might initially recommend credits. After sufficient operating evidence, it could receive authority to issue credits below $50. Later, the threshold might rise. High-value exceptions may continue to require human decisions. The underlying model may not have changed dramatically between those stages; what changed is the enterprise’s evidence about the system, its operating environment, and the controls surrounding it.
Fixify’s 2026 analysis provides an early field example of this kind of progressive delegation. Its dataset covered 17,929 agentic plans and 147,351 plan actions across more than 40 companies. The report describes a developing division of labor in which AI agents increasingly execute routine work while analysts supervise, approve, reject, redirect, and take over when judgment is required. Fixify appropriately describes the data as an early-adopter snapshot rather than a settled enterprise pattern.
The Real Options interpretation matters because the enterprise does not need to expose itself today to capture all of tomorrow’s potential autonomous value.
It can buy information first.
The authority cycle becomes:
Delegate → Observe → Verify → Expand, Hold, Contract, Switch, or Revoke
The right to make the next authority decision later has economic value because it preserves upside while limiting irreversible downside.
In that sense, machine authority can be managed as a portfolio of staged institutional options.

Authority Should Be Earned Through Evidence
The right to make the next authority decision later has economic value of its own because it preserves upside while limiting irreversible downside.
In that sense, machine authority can be managed as a portfolio of staged institutional options.
When Execution Becomes Abundant, Authority Becomes Scarce
There is a larger systems implication.
AI can make intelligence and execution dramatically cheaper and more abundant, but enterprises do not become constraint-free. As I argued in Constraint Migration: The Next Challenge of Enterprise AI, the constraint moves.
Meta’s experience with AI-assisted software development illustrates the mechanism. Agentic AI dramatically increased the supply of code while reviewer bandwidth became relatively scarce. Instead of adding human reviewers indefinitely, Meta developed RADAR, a risk-calibrated system that automatically lands qualifying low-risk changes after layered automated checks. It has reviewed more than 535,000 diffs and automatically landed more than 331,000, illustrating how an organization can redesign the control system when human verification becomes a new bottleneck. (arXiv)
Army Cyber describes a similar mechanism in a different environment. Machine-speed cyber work is becoming possible, but institutional risk-bearing authority remains scarce and deliberately governed. (Breaking Defense)
The pattern is broader than either example. As machine execution expands, scarce resources can migrate toward verification, authorization, supervisory judgment, exception handling, accountability, and intervention capacity.
This matters because enterprises may assume that more capable AI necessarily requires less governance. The opposite can occur. More capable AI can increase the economic value of governance because the organization capable of governing machine action effectively can safely delegate more consequential work.
When execution becomes abundant, authority and control capacity become relatively scarce.
Security Can Become Part of the AI Growth Equation
This is where the implications for cybersecurity go beyond risk avoidance.
Security has traditionally justified much of its economic value by reducing the probability or severity of breaches, fraud, interruption, compliance failures, or other losses. Agentic AI introduces another possible source of value.
If an enterprise lacks confidence in its ability to control consequential machine action, restricting autonomy can be economically rational. More decisions remain behind human approval gates. Execution slows. Supervisory capacity becomes scarce. Some of AI's potential value remains inaccessible.
Controls that reduce the marginal exposure of delegated authority change that calculation. Strong identity, dynamic privilege, runtime enforcement, state-aware policy, trajectory monitoring, observability, rapid intervention, and reversibility can allow management to delegate authority it would otherwise rationally withhold.
The implication is significant:
Security can create value not only by reducing what AI might destroy, but by increasing how much economically productive autonomy the enterprise can safely use.
That changes the executive value proposition. The question is no longer only, “How much loss might this control prevent?” It can also become, “What economically useful autonomous activity can we safely permit because this control exists?”
The technology market is already assembling parts of the required infrastructure. Microsoft distinguishes autonomous agents operating with their own identities from agents acting on behalf of users and introduces explicit business sponsors alongside technical owners. Okta is extending controls into runtime agent connections and individual tool calls. SailPoint describes a continuous governance model spanning human, machine, and agent identities. BeyondTrust is enforcing privileged actions before agent execution. Palo Alto Networks describes Idira as a control plane for human, machine, and agentic identities and Prisma AIRS as enabling enterprises to safely authorize autonomous execution.
The industry may use different terminology, and no single vendor owns the whole problem. What matters is the direction of travel. The market is moving from controlling who can access a system toward controlling what autonomous actors can actually do once they get there.
This is also where trust enters the economic equation. Enterprises will delegate consequential authority only when executives, employees, customers, regulators, and counterparties have sufficient confidence that actions remain bounded, attributable, observable, and recoverable. Governance therefore does more than reduce risk. It can create the institutional confidence required to delegate more economically productive authority.
The management layer above that technical stack is still developing.
Enterprises will need a systematic way to decide what machine authority is economically valuable, how much value that authority exposes, where structural limits should apply, how authority should expand as evidence accumulates, and when it should contract or disappear.
One practical starting point is to map agentic operations and workflows against the enterprise mechanisms that already govern human action: decision rights, identity and access, delegated authority, attribution, intervention points, legal and contractual consequences, risk-transfer mechanisms, and residual economic exposure. The objective is not to invent an entirely new governance system for AI. It is to connect machine action to the control, consequence, and accountability structures enterprises already use—and identify where those structures stop working at machine speed.
The next market may therefore be larger than securing agent identities.
It may be enabling enterprises to operate safely at a higher level of machine authority.
Human Control Is Not Always the Answer
None of this means humans should remain in every loop.
Humans are slow, expensive, inconsistent, and subject to their own biases. Decades of automation research also show that people are not particularly effective when reduced to passive monitors of systems that perform most of the time reliably. Contemporary AI-code-review evidence suggests a similar problem: increasing machine output without redesigning human oversight can create larger queues and thinner scrutiny. (arXiv)
Nor should the goal be to remove humans from every consequential decision. The appropriate allocation depends on the nature of the task, the quality of available evidence, the consequence of failure, reversibility, legal obligations, institutional responsibility, and the comparative capabilities of humans and machines.
Human involvement therefore needs to be classified, not assumed.
Some human involvement is friction to eliminate because it introduces delay without meaningful risk reduction.
Some is capability to augment because humans and machines together outperform either independently.
Some is a control to preserve because ambiguity, consequence, rights, fiduciary responsibility, or institutional legitimacy justify explicit human authority.
Those classifications can change as evidence changes.
That is why “human in the loop” is not an architecture. It describes where decision rights currently sit.
Machine Authority Should Become an Explicitly Managed Enterprise Resource
Organizations have always governed authority. They use organizational structures, budgets, signing limits, approval matrices, professional standards, policies, contracts, audit systems, fiduciary duties, and law to determine who may act on the institution's behalf.
AI does not eliminate that management problem. It extends it to machines.
The transition will not happen all at once. Formal authority may remain human while real authority moves toward machines. Some agents will receive narrow execution rights. Others will operate across complex trajectories. Some authority will expand progressively as evidence accumulates. Other authority will encounter legal, fiduciary, operational, or catastrophic boundaries where delegation should remain constrained regardless of technical capability.
The management challenge is therefore not to prevent machine authority from emerging. The economics will make some delegation inevitable. The challenge is to make that authority explicit, bounded, observable, attributable, evidence-based, reversible where possible, and economically rational.
Six questions should increasingly become part of executive AI governance:
What economic value does additional machine authority enable?
What enterprise value does that authority expose?
Can consequential actions be attributed to the principal, delegation, policy, and control path that produced them?
Who is accountable for the outcome—and what consequence makes that accountability meaningful?
Who ultimately bears the legal and economic exposure after controls, contracts, insurance, and other risk-transfer mechanisms are applied?
Does the organization possess the governance capacity to operate safely at that level of autonomy?
Those questions bring AI strategy, organizational economics, operating-model design, cybersecurity, legal and risk architecture, value engineering, and capital allocation into the same management conversation.
Machine identity tells us who is acting. Machine capability tells us what is technically possible. Neither tells management how much institutional authority to delegate, how to attribute the resulting action, or who should ultimately bear the consequence.
That is a management decision.
Machine authority should become a deliberately managed enterprise resource—not an accidental byproduct of identity, access, and technical capability.
The competitive implication may ultimately be larger than the governance problem itself. Enterprises will not gain advantage simply by delegating the most authority to machines. Uncontrolled autonomy can magnify losses just as readily as it magnifies productivity. Equally, companies unable to govern machine authority may leave valuable capabilities trapped behind human coordination long after the technology can do more.
The strategic advantage lies between those extremes.
The winners in the agentic era will be the organizations that develop the institutional capacity to safely delegate more economically productive authority than their competitors.




Comments