When AI has permission to act, who gives it authority to decide?

Giving AI permission to take an action is different from letting it decide when that action should occur. CIOs need explicit boundaries for when AI can act autonomously.

As AI becomes embedded not only in ERP but across enterprise applications and workflows, CIOs face a crucial governance question: Even when an AI system has permission to perform an action, should it also have the authority to decide when that action should occur?

"Most conversations about this treat it as a capability question: Can the AI do the thing? It's not. It's about two separate questions: Who defined the boundaries before the system ever ran, and who has the final say once it's spoken?" said Rebekah Doran, head of AI product strategy at Ideagen, a U.K.-based software provider for highly regulated industries.

The risk is heightened as AI systems shift from merely analyzing information to recommending, initiating and executing business actions. AI decision authority is intended to control these processes by defining which decisions an AI system can make, under what conditions and limits, and when human approval is required. But intent and execution are entirely different things. Here's how to help close that gap.

Separating permission from decision authority

Permission and decision authority should be treated as separate product controls. Permission answers what an AI system is technically allowed to do. Decision authority answers which choices it can make on a person's or organization's behalf, under what conditions and when it must stop for review. In general, it is a means of preventing agent mishaps rather than addressing them after an agent runs off the rails.

"When organizations rush to embed AI into their workflows, the conversation too often defaults to post-deployment monitoring, trying to catch mistakes after they happen. But my experience is that if you are waiting until production to govern an AI's authority, you have already lost control," said Eshaan Jain, a senior enterprise technology product leader at IT services and consulting company Mphasis Silverline.

The temptation to put off establishing AI authority is understandable because it can be a complex exercise. Earlier forms of automation offer useful lessons.

"Network automation taught us that permission and authority are two different controls and that conflating them is how outages happen," said John Capobianco, head of AI and developer relations at Itential, a software company that provides an agentic operations platform.

Capobianco went on to explain that early on in network automation, the question "Is this automation allowed to push a configuration change?" was answered with credentials and role-based access control.

"What we couldn't answer was whether it was allowed to decide that the change should happen now, on this device, based on this signal," Capobianco added. "Our worst incidents were rarely unauthorized actions. They were authorized actions taken at the wrong moment or on a faulty premise: a correct remediation applied to the wrong device class, or a valid rollback fired during a change freeze."

Governing AI authority as a separate control measure is essential to ensure that automation does not quietly outrun accountability, expose the organization to unacceptable risk or leave leaders responsible for decisions they did not know AI was making.

For example, "an organization might tell an AI to 'resolve customer complaints' without deciding whether resolution means enforcing policy, retaining the customer or closing the case quickly. Those goals can produce very different actions. If the organization leaves that choice open, the AI is effectively writing policy one customer at a time," said Shikhar Mangla, who works in AI as product design lead at Sling TV.

Establishing decision boundaries

Setting the right boundaries is more important than many tend to think. Amir Baldiga, founder of ZOOQ, runs the company solo and lets agents handle most of the work of feeding live LinkedIn data to other agents via his API. "A boundary I get wrong shows up in my own numbers inside a week," Baldiga said. But even a delay of a few days to a week in learning that a boundary is wrong can come at a price. "My reply rate slid from about 30% to 21% before I caught it. Nothing was broken. The agent had permission for every message and sent them exactly as designed, at a target that had quietly drifted," he said.

Baldiga says he gives an agent authority over anything reversible and rate-capped, but he retains control over the timing of anything that cannot be undone. "At that volume, roughly 1% of messages go out wrong. That is the price of 10,000 of them [working] without [me] lifting a finger, but it is only a fair price if the wrong 1% is reversible," Baldiga added.

The obvious questions are what counts as a boundary and what makes one effective. Boundaries can include dollar or risk thresholds, required approvals, specific categories of transactions, escalation requirements, or circumstances in which autonomous decision-making should be paused, restricted or suspended.

"The boundary has to be a number before launch, not a dashboard after. In my stack, it is a send cap per sender profile per day. If a cap is the only thing between a drifted target and 10,000 people, then the cap is the governance," Baldiga said.

Ultimately, enterprise boundaries should be explicit enough that business leaders, technology teams and auditors can understand what the AI is authorized to decide and when human involvement is required.

"A useful boundary is to separate recommending, preparing, initiating and committing. Authority should narrow as uncertainty and consequence rise," said Priya Bhasin, group product manager at Microsoft AI, who also says these are her private takes on the subject and not necessarily the views of her employer. Bhasin advocates for teams to define the decision contract before agent launch -- specifically the objective, allowed inputs, prohibited actions, spending or scope limits, escalation triggers, expiration conditions and the evidence the system must surface to a reviewer.

A useful boundary is to separate recommending, preparing, initiating, and committing. Authority should narrow as uncertainty and consequence rise.
Priya BhasinGroup product manager, Microsoft AI

"If the system cannot explain which constraints it applied or cannot distinguish a material change from the original request, it should not have autonomous authority for that decision," Bhasin said.

The people who grant and own agent authority must be known and documented. That is essential to accountability, compliance and strong audit trails.

"The practical test is not simply whether the model can perform the task. It is whether the organization can state, in advance, who remains accountable, how a person can interrupt or reverse the action and which observable signals would cause authority to be reduced or revoked," said Bhasin.

Ultimately, humans -- not agents -- must remain accountable for machine decisions, whether executed by agents or other automated systems.

"'Human in the loop' is not enough. There needs to be a human on the hook," said Shama Hyder, professor of Practice at the Link School of Business in Miami.

The urgency is heightened because technology is moving faster than organizations can adapt. Hyder's own research, the September Hyder Index, found that industries are changing twice as fast as companies are responding, with a composite reading of 69 out of 100. "Better models will not solve that on their own. Leaders must decide where authority belongs before their teams hand it over by habit," Hyder added.

Others in academia and elsewhere agree that pinning responsibility to a specific person is crucial but that just appointing someone who ultimately ends up rubber-stamping AI approvals must be avoided, despite the speed at which these decisions tend to pop up in systems.

"Having someone approve an AI recommendation is not enough. People must have the knowledge and authority to define the problem, challenge the answer and decide when the technology should or shouldn't be used," said Vasileios Maroulas, Ph.D., executive director of the AI Tennessee Initiative at the University of Tennessee.

Maroulas points to Volkswagen's AI-enabled automobile inspection research and the University of Memphis' work in freight automation and logistics as examples. "These are real-world problems being solved by bringing together computational capabilities with the practical knowledge of people who understand production lines and supply chains," Maroulas said.

For CIOs, the goal is not to eliminate AI autonomy but to make decision authority explicit before deployment -- what an agent might decide, what narrows or revokes that authority and which human remains accountable when the system acts.

Pam Baker is a freelance journalist and the author of books including ChatGPT For Dummies and Generative AI For Dummies. Baker is also an instructor on AI topics for LinkedIn Learning and a member of the National Press Club, the Society of Professional Journalists and the Internet Press Guild.