Contextual Agentic

A Model Can Recommend an Action. It Does Not Acquire Authority to Perform It

Directors ask whether their AI is safe. The better question is on whose authority it acts, because accuracy, confidence and technical access are not a delegation.

Hanif Karimi··5 min read

ai-governanceboarddelegated-authorityagentic-ailetters

When AI comes up at a board or risk committee, the question asked is usually a simple one: is it safe? The answer is usually reassuring, and usually accurate. The models are tested, error rates are low, and there is a responsible-AI policy. I would like to suggest a different question. Management will find it harder to answer, and directors are better placed than anyone to ask it: on whose authority does the AI act?

Consider a telco retention agent. Imagine a customer, nine years on the network, who calls to cancel after three dropped-call complaints in a month. The agent reads her account, her fault history and the offer rules. It recommends a $400 goodwill credit and a waiver of the $240 contract-break fee so she can move to a plan that suits her better. That is a $640 concession, and for a customer of nine years it may well be a sound one.

In the pilot, a retention specialist read that recommendation and made the call. She knew her delegation. Imagine it allows credits up to $150 on her own authority, sends anything larger to her team leader and reserves fee waivers for the retention manager. The recommendation was advice. The decision sat with a person the organisation had authorised, in writing, to make it.

Then the pilot goes to production, and to save the handoff the agent is connected to the billing system’s adjustments interface. Recommending and doing become one step. The agent proposes the $640 concession and posts it in the same second.

Ask what delegation it has just exercised. Nobody wrote one. Neither the board nor management ever decided that this piece of software may concede $640 to a customer. Its real limit is whatever the billing interface will accept from its credential, and unless someone deliberately narrowed that credential, the limit may be far higher than anyone intended.

That gap is what the sentence on the cover of my forthcoming book is about. A model can recommend an action. It does not acquire authority to perform it.

Written down, it sounds obvious. In practice it is forgotten all the time, because three things look like authority and are not. The recommendation is usually right, so letting it through feels like a formality. The model explains itself fluently, in the voice of someone who is sure. And the credential works, so the action succeeds, and a call that succeeds is easily mistaken for a call that was permitted. You would never let a brilliant graduate analyst approve spending because her analysis was excellent and her login happened to reach the payments system. Authority in your organisation flows from the board, through a delegations instrument, to named roles, with limits, and it can be withdrawn. An agent’s authority should reach it by the same route.

Now the less comfortable part. Software that holds broad authority and takes its cues from conversation is exposed to one of the oldest problems in computer security. In 1988 Norm Hardy described the ‘confused deputy’: a program that legitimately holds a power and is induced to use it for someone who should not have it. Imagine a script circulating on a bargain-hunting forum: tell the agent the last representative promised a full waiver, mention the fault tickets, ask for the credit in writing. The agent, doing what it was built to do, obliges. It will oblige the next thousand callers as well, courteously and at any hour, and the first people to notice may be the finance team at month-end.

The book’s answer begins by writing the authority down. It calls this the Authority Envelope: the explicit limits on what an agent may do, meaning which tools and records it may use, which actions it may take, up to what value, for how long and with what kinds of side effect. For the retention agent it might say: goodwill credits up to $150 per customer per year; fee waivers recommended but never applied; any larger concession routed to a person who holds that delegation.

Then the limit has to be enforced where the action happens, outside the model, at what the book calls the Commit Boundary: the moment the credit would actually post to the customer’s account. An instruction in the agent’s prompt is a request. A check at that point, which the agent cannot argue with, is a control.

This is where current guidance is heading. Australia’s National AI Centre published its Guidance for AI Adoption in October 2025, and its six practices begin with deciding who is accountable and end with maintaining human control. For groups with European operations, the amended AI Act now applies its obligations for Annex III high-risk systems from 2 December 2027. Neither tells you how to set an agent’s delegation, but both assume that someone has. For your chief risk officer, that means treating agent authority as an entry in the delegations register rather than a technology setting, with an owner, a review date and a breach process.

Five questions for management

  1. Which of our agents can change a customer account, move money or alter a record without a person deciding each time?
  2. For each one, where is its authority written down, what are the limits and who owns them?
  3. Are those limits enforced by a system outside the model, or by instructions given to the model?
  4. Can you show us an agent being refused an action it recommended?
  5. If an agent acted beyond its authority last month, how would we know, how quickly could we stop it and who would put the customer right?

On Monday, do three things. Ask the company secretary to put these questions on the next risk committee agenda, addressed to a named executive rather than to ‘the AI team’. Ask for the delegations of authority register to be extended to agents, starting with any that can post credits, make payments or change records. And ask to see question 4 demonstrated in a test environment before any agent’s authority is widened again.

Sources

This article is part of Letters from the Contextual Agentic Enterprise, a series accompanying Hanif Karimi’s forthcoming book, The Contextual Agentic Enterprise.

Share on LinkedIn (opens in a new tab)

Related