Congratulations. You have your first AI agent.
Maybe it monitors inventory and recommends purchases. Maybe it handles customer requests, reviews invoices, follows up on sales leads, or analyzes financial information. Whatever its job is, you’ve crossed an important line: AI is no longer just answering questions for you. It’s beginning to participate in the work of the company.
That’s exciting, but it creates a question that I don’t think businesses have spent enough time considering. How much authority are you willing to give your new AI agent?
Why AI Agent Governance Matters
As AI agents gain the ability to act, AI agent governance becomes more than a technology issue. Companies need to decide what an agent can do, when it needs approval, and when it must escalate to a person.
I recently received a comment from Paul Malott on one of my LinkedIn posts that made me think much more deeply about this question. He wrote:
“The key transition is from AI as a tool to AI as a participant in the operating model. Once agents can recommend and execute, organizations need to rethink decision rights, authority, escalation & governance not just technology.”
I think Paul has identified one of the most important issues companies will face as we move toward an agentic world. Building an agent is only part of the challenge. We also have to decide what we’re going to allow that agent to do.
Your New Employee Wants to Place an Order
Imagine that your first agent works in purchasing. It monitors inventory, reviews demand, and determines that your company needs another 100 cases of an item.
Should it be allowed to create the purchase order? That seems reasonable. Should it also be allowed to send the purchase order to the vendor?
Now things get more interesting. Sending the purchase order may create an actual financial commitment for the company. Your AI agent has moved from recommending an action to taking one on your behalf.
Suppose this is an item you’ve purchased every month for the last five years. It’s coming from a trusted vendor, the price hasn’t changed, the quantity is normal, and the entire purchase is $2,000. Do you really need an employee to review and approve it?
Maybe not.
But suppose the price suddenly increases by 20 percent. Or the agent wants to order five times the normal quantity. Or instead of your normal supplier, it wants to purchase from a company you’ve never done business with before.
And what if the purchase isn’t $2,000?
What if it’s $200,000?
Suddenly, the question isn’t whether AI is capable of creating a purchase order. The question is whether the AI agent has the authority to commit your company to that purchase.
We’ve Already Solved Part of This Problem
The interesting thing is that this isn’t an entirely new business problem. Companies have been deciding how much authority to give employees for a very long time.
A buyer might be authorized to place orders up to $5,000 without approval. A purchasing manager might have a $50,000 limit. Larger purchases might require approval from a CFO or another executive.
Companies also establish rules around vendors, contracts, pricing, credit, payments, and other areas of the business. We don’t normally hire someone on Monday and give that person unlimited authority over the company on Tuesday.
Why should an AI agent be any different?
Perhaps we should think about agent authority in much the same way we think about employee authority. The agent receives enough authority to do its job, but that authority exists within clearly defined boundaries.
The Answer Isn’t Human Approval of Everything
My first reaction to concerns about AI agents was that we should simply keep humans in the loop. Let the agent do the work, but require a person to approve important actions.
I’m starting to believe that answer is incomplete.
If every action an AI agent takes requires someone to click an Approve button, we haven’t really created an autonomous process. We’ve created a very efficient recommendation system followed by a human approval queue.
That might work when an agent handles five transactions a day. What happens when it handles 500? What happens when a manager is presented with hundreds of routine transactions that are almost always correct?
We already know what humans tend to do with repetitive approval processes.
Approve. Approve. Approve.
Eventually the approval itself can become routine. Instead of creating meaningful oversight, we’ve created a human rubber stamp.
The Risk Should Determine the Authority
I recently came across a useful way of thinking about this in AWS guidance for AI agents. Rather than routing every agent action through human review or giving agents unlimited freedom, the idea is to use risk-tiered approvals.
That makes sense to me because it’s already how well-run businesses operate.
Our purchasing agent might be allowed to automatically place an order when the vendor is trusted, the item is approved, the price is within a reasonable range, the quantity is normal, and the total purchase falls below a defined limit. Those conditions create a boundary around the agent’s authority.
Change one of those conditions and the process changes.
A new vendor might require review. A large price increase might require review. An unusual quantity might require review. A purchase above the agent’s spending limit might require review.
The agent doesn’t need to stop working. It needs to recognize that the decision has moved outside its authority and escalate it to someone who has the authority to make it.
This Is Bounded Autonomy
I think we’re going to hear much more about this idea as agents become common in business.
I call it bounded autonomy.
The idea is straightforward. Give an agent enough freedom to perform useful work on its own, but establish clear boundaries around that freedom. When the agent encounters something outside those boundaries, it stops, validates, asks for help, or escalates the decision.
This means the goal isn’t maximum autonomy. The goal is appropriate autonomy.
A routine $500 transaction with a trusted supplier might happen automatically. A $500,000 transaction probably shouldn’t. The technology may be perfectly capable of executing both transactions, but technological capability and business authority are two very different things.
AI Is Becoming a Participant in the Company
This is why Paul’s comment struck me.
We’ve spent the last several years thinking about AI primarily as a tool. A tool doesn’t need decision rights because a human is using it and remains responsible for the action.
A spreadsheet can calculate how much inventory we should buy. A dashboard can tell us we’re running low. An AI assistant can even recommend that we place an order.
But an AI agent can potentially take the next step.
It can act.
Once it does, AI begins moving from being a tool used by the operating model to becoming a participant in the operating model.
And participants need rules.
The AI-Native Company Needs an Authority Architecture
I’ve been spending a lot of time thinking about what an AI-native company might eventually look like. Much of that thinking has naturally focused on technology.
I believe ERP systems may become an important operational foundation for these companies because so much business data is already structured inside them. A canonical business model and semantic layer could help agents understand customers, vendors, products, orders, inventory, costs, and other business concepts.
But access to information isn’t enough.
Just because an agent knows that inventory is low doesn’t mean it should be allowed to buy more. Just because it knows a customer normally receives a certain price doesn’t necessarily mean it should be allowed to change that customer’s contract.
The AI-native company therefore needs something beyond a data architecture.
It needs an authority architecture.
That architecture defines what an agent can do, what it cannot do, what it must validate, when it needs approval, when it must escalate, and who is ultimately accountable for its actions.
These aren’t simply technical settings.
They’re management decisions.
Governance Can’t Be Added Later
This is one of the areas where I think businesses need to be careful as AI moves so quickly.
It’s easy to become excited about what an agent can do. The demos are impressive, and the technology is improving at an incredible pace.
But capability is moving faster than many companies’ operating models.
We shouldn’t wait until an agent makes a bad decision to determine who was supposed to approve it. We shouldn’t wait until an agent places an inappropriate order to decide what its purchasing limit should have been.
Decision rights, authority, validation, escalation, and accountability need to be part of the design from the beginning.
These are the guardrails that allow us to give agents more freedom safely.
This Isn’t About Slowing AI Down
I don’t see these questions as arguments against AI agents.
I see them as requirements for using agents successfully.
If we create good boundaries, companies may eventually become comfortable giving agents considerably more authority than they have today. A purchasing agent might handle thousands of routine transactions without human involvement while escalating the handful that genuinely require judgment.
That would be a better outcome than forcing humans to approve everything.
People could spend their time on exceptions, relationships, negotiations, strategy, and the decisions where human judgment actually creates value. Agents could handle much of the routine work inside the boundaries we’ve established for them.
That’s not removing humans from the operating model.
It’s changing where humans add value within it.
Your Agent Is Ready. Is Your Company?
We’re getting surprisingly good at building AI agents.
I suspect the harder challenge will be redesigning companies so those agents can safely participate in them.
That will require technology, but it will also require management, governance, trust, accountability, and good business judgment. Companies will need to think carefully about the relationship between human authority and machine authority.
So congratulations. You have your first AI agent.
Now comes the more interesting question.
What are you going to let it do?
