AI agent autonomy puts CIO controls to the test

As AI leaders warn capabilities are advancing faster than safeguards, CIOs face a more immediate question: how much authority to give enterprise agents.

As enterprises move from AI assistants to increasingly autonomous agents, several prominent AI executives are warning that the technology may be advancing faster than the safeguards designed to control it.

For CIOs, the central issue is how much autonomy and authority to grant AI agents today and whether enterprise controls are keeping pace with what those agents are increasingly being allowed to do.

AI agents are gaining access to enterprise data, applications and tools and becoming capable of taking actions with less human intervention, increasing the potential consequences when something goes wrong. CIOs aren't just deciding which models are capable enough for the job. They're deciding what those systems should be allowed to access, what actions they can take independently and where human approval is still required.

That question has taken on new urgency as Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman called for a slower pace of frontier AI development amid concerns about increasingly capable systems. Separately, Microsoft AI published a first draft of its Humanist AI Code of Conduct on Sept. 14 for public consultation.

Amodei warned that the accelerating pace of AI advances, if left unchecked, could outpace efforts to understand and control increasingly capable systems.

Altman backed Amodei's call to pace frontier development, saying the issue has been a major topic of discussion inside OpenAI in recent weeks. Altman also said OpenAI would commit to giving independent evaluators employee-like access.

Microsoft's draft outlines intended behavior for future Microsoft AI models, including that they remain subject to human correction and shutdown. Microsoft says the code is still under development and is not being used to train its models today.

What AI slowdown warnings mean for CIOs

For CIOs, the more practical question is whether any of it changes what they do now.

Lian Jye Su, chief analyst at Omdia, a division of Informa TechTarget, said CIOs were already approaching agentic AI cautiously, with governance, security, data quality and unclear ROI among the factors holding back large-scale deployments. He expects the latest warnings to reinforce that caution and potentially push deployment decisions further into the future.

"CIOs will start to scrutinize their agentic AI plans, choose partners with a strong understanding of AI safety and security, and devote more resources to internal AI safety and security practices with human oversight," Su said.

But slowing frontier development doesn't necessarily address the more immediate risks enterprises face when deploying AI agents.

Randall Hunt, CTO at cloud services company Caylent, said the warnings don't significantly change what CIOs should be doing in the near term. The larger concern, he said, is the authority and access enterprises are already giving AI systems.

"A model doesn't need superhuman intelligence to expose customer records or make an unauthorized payment; it just needs authority and access," Hunt said. "More capable models and agents might find ways around weak controls but that will be true in perpetuity. Enterprises need to continue to set guardrails in what agents can do without humans in the loop."

A model doesn't need superhuman intelligence to expose customer records or make an unauthorized payment; it just needs authority and access.
Randall HuntCTO, Caylent

That shifts the focus for CIOs away from how capable the next generation of models may become and toward the controls surrounding the agents enterprises are deploying today.

Hunt said that starts with defining exactly what an agent can access and what actions it is allowed to take. Agents should have their own identities and least-privilege access, with limits around spending, transactions and how long they can operate autonomously enforced in code rather than through prompts.

Despite differing on how much the latest warnings change the enterprise AI landscape, Hunt and Su arrive at a similar place when it comes to the controls CIOs should put around agents.

Su said enterprises should limit agent autonomy, establish clear identities and role-based access controls and maintain human oversight. He also expects organizations to increase red-teaming and maintain audit trails of prompts, tool calls and outcomes.

Taken together, those controls are less about anticipating how powerful future models might become and more about limiting the consequences when an agent behaves unexpectedly.

Even if AI companies strengthen their own evaluation and safety practices, CIOs can't rely on those efforts alone.

"Embedded evaluation won't be a 'safety guarantee,' so CIOs still need to plan for their own AI safeguards and governance investments," said Gary Olliffe, distinguished vice president analyst at Gartner.

AI safety becomes a vendor-selection issue

The growing focus on AI safety could also change how CIOs evaluate AI vendors.

"Best practice will be to adopt the safest agentic AI models rather than the smartest or most capable ones," Su said.

That puts more weight on how providers approach security and safety, as well as the controls they give enterprises over agent identities, permissions, monitoring and human intervention.

The debate over how quickly frontier AI should advance isn't likely to be resolved anytime soon. CIOs, however, are already setting the access and authority boundaries for agents inside their organizations.

The immediate question isn't simply how capable the next model becomes. It's whether the controls surrounding agents already entering enterprise systems are keeping pace with what organizations are allowing them to do.

Liz Hughes is an award-winning editor and writer covering AI and emerging technology and the former editor of AI Business and IoT World Today.

Next Steps

Gartner warns traditional IT controls won't keep up with AI

The human in the loop is falling asleep

How governance as code controls AI agent risk

CISO's guide to nonhuman identity security

AI control is becoming an architecture problem for CIOs

Dig Deeper on CIO Strategy