Executive Decision · AI and Enterprise Control

Before You Approve an AI Agent

Before approving an AI agent, define the boundary.

Devendra KumarOctober 20263 min read

An AI agent can recommend an action.

It can also take the action.

The second changes the decision.

Once an agent can act inside a real business process, leadership is no longer approving an AI capability alone.

Leadership is approving a level of authority.

Before approving an AI agent, define the boundary.

Start with the action

Ask what the agent is actually being authorised to do.

Observe information?

Recommend an action?

Prepare a transaction?

Execute after approval?

Execute independently within defined limits?

The answer should depend on the consequences of failure, not the sophistication of the technology.

Assess the consequence

Ask:

What happens if the agent is wrong?

Consider:

Financial impact

Customer impact

Employee impact

Regulatory exposure

Security consequences

Reputational impact

Reversibility

An incorrect draft is different from an incorrect payment.

An incorrect recommendation is different from an irreversible transaction.

The higher the consequence, the stronger the required control.

Define the operating boundary

Before approval, specify:

Systems the agent may access

Data the agent may use

Actions the agent may take

Transaction limits

Frequency limits

Approval requirements

Conditions requiring escalation

Conditions requiring shutdown

Least privilege should apply.

The agent should receive only the authority required for the defined process.

Test failure before deployment

Do not test only whether the agent performs the intended task.

Test what happens when conditions are wrong.

What happens when:

Data is incomplete?

Instructions conflict?

A request is duplicated?

A downstream system fails?

An unexpected input arrives?

A transaction times out?

Someone attempts to bypass the controls?

The organisation needs a defined response for each material failure mode.

Establish accountability

Before approval, identify:

Business owner

Process owner

Technology owner

Data owner

Security responsibility

Support responsibility

Authority to stop the agent

The agent does not own the outcome.

A named person or function does.

Prove reversibility

Ask:

Can the agent's action be reversed?

If the answer is no, stronger controls are required.

Low-risk and reversible activities are stronger candidates for higher autonomy.

Irreversible actions need greater human involvement.

Define the evidence

Approval should include measurable conditions for continued operation.

Define:

Expected performance

Failure thresholds

Monitoring frequency

Exception levels

Incident triggers

Review points

Conditions for reducing autonomy

Conditions for stopping the agent

Autonomy should increase only when evidence supports the change.

Warning signs

Pause approval when:

The proposed authority is broader than the process requires.

No business owner accepts accountability.

Failure is difficult to detect.

Actions are difficult to reverse.

Exception handling is undefined.

Audit records are incomplete.

Shutdown authority is unclear.

Operating costs are not understood.

The business case depends on maximum autonomy.

The decision

Do not ask:

Can we deploy this agent?

Ask:

What authority are we prepared to give it, and why?

Then decide the appropriate level:

Observe → Recommend → Draft → Execute with approval → Execute within limits → Fully autonomous

Start with the lowest level that creates meaningful value.

Increase autonomy only when evidence supports the change.

Five questions before approval

  1. 01What action is the agent authorised to take?
  2. 02What is the consequence if the agent is wrong?
  3. 03What must remain human-controlled?
  4. 04How will failure be detected, contained and reversed?
  5. 05Who has authority to stop the agent?

An AI agent should not receive authority because the technology makes autonomy possible.

Authority should follow the risk of the action.

Before you approve an AI agent, approve its boundary.

Related frameworks

TopicsAIGovernanceExecutive Decision-Making

Related

Read next.

Explore more perspectives →