When AI Can Act, Who Decides What It Can Do?

Abstract AI workflow passing through defined permission boundaries

Written by

AI agents become useful when they can reach real systems. Leadership needs to decide where that authority starts and stops.

AI tools are moving beyond drafting and summarizing. They can read inboxes, retrieve files, update records, and trigger steps in other applications.

That makes them useful. It also changes the risk.

A model may follow the goal it was given and still take a route nobody expected. Recent frontier model research has shown that clearly. The research environments were specialized. The business question is ordinary.

What was the AI allowed to do?

Access creates authority

Every system connected to an AI agent gives it more scope.

An agent that can only draft a response has limited authority. An agent that can send the response can affect a client relationship. If it can update the customer record or trigger the next step, it is now acting inside the business.

Many firms treat those permissions as technical setup. They are management decisions.

If an agent can change an official record, contact a client, stop a workflow, or move information between systems, leadership has delegated authority. That remains true even when nobody formally described it that way.

The risk grows with the access.

Prompts are not controls

A prompt tells the model how it should behave. The model still has to interpret that instruction.

Access controls determine what the agent can reach. Tool permissions determine what it can change. Approval rules determine when a person must make the decision.

Those boundaries should live in the workflow itself.

Leadership should be able to answer four questions before an AI agent starts taking action.

  1. What information can the AI access?
  2. What records or systems can it change?
  3. Which actions require a deliberate human decision?
  4. Who owns the result when something goes wrong?

The AI should not have to infer its authority from a broad objective.

Human review has to mean something

A human review step sounds reassuring. It can become meaningless when people are asked to approve routine actions all day.

Review should sit where judgment matters.

Sending information outside the company deserves more scrutiny than summarizing an internal document. Changing an official record carries more risk than drafting a suggested update. Moving money or accepting a legal commitment should require a clear decision from an accountable person.

The review point should make the decision obvious. The person should know what the AI is proposing, which information is involved, and what will happen after approval.

Otherwise the review becomes another button everyone clicks.

Start with one workflow

A company does not need to solve every governance question before it begins.

Start with one workflow where employees already use AI or where manual work creates a clear bottleneck.

Map how the work happens today. Identify the result worth improving. Define the information involved and who owns the outcome.

Then decide what the AI can do on its own.

Some workflows may only need drafting support. Others may allow the AI to update an internal system within strict limits. Actions involving clients, money, legal commitments, or sensitive information may need a clear approval point.

Test the workflow against a result the business can see.

Did it create capacity the business could use? Did quality hold up? Can another employee follow the same process? Does leadership know who is accountable?

AI agents will keep getting better at finding paths to an objective. Businesses need to become more precise about which paths are allowed.

Further reading

Idea Pursuit helps Canadian firms define practical boundaries around AI one workflow at a time.