AI Can Increasingly Act, Not Just Answer: What Authority Boundaries Should Businesses Set?

Digital

AI Can Increasingly Act, Not Just Answer: What Authority Boundaries Should Businesses Set?

AI systems are evolving from answering questions to taking actions across business tools and workflows. The next governance challenge is deciding what they can access, what they can execute, and where human approval must remain mandatory.

For years, enterprise AI was relatively easy to frame.

An employee asked a question.

AI produced an answer.

A human decided what happened next.

That model is changing.

Newer AI systems can connect to applications, databases, customer platforms, workflows, messaging systems, procurement tools, and internal software.

They can search, plan, generate, update, trigger, and execute.

That shift changes the risk.

The question is no longer simply whether the answer is correct.

It is whether the system should have been allowed to act at all.

Agentic AI changes the governance problem

Agentic AI broadly refers to systems capable of planning and taking a sequence of actions toward a goal with some degree of autonomy.

A wrong chatbot answer can often be ignored.

A wrong autonomous refund, data deletion, purchase order, pricing change, or customer communication can have an immediate operational impact.

NIST’s AI Risk Management Framework emphasises governance, monitoring, measurement, and risk management across the AI lifecycle.[1][2]

Indonesia already has a governance foundation

Indonesia’s 2023 AI Ethics Circular identifies principles including security, transparency, accountability, privacy, and human-centred use.[3]

The government has since said a planned Presidential Regulation on AI will serve as an early step toward a more comprehensive legal framework.[4]

Businesses should not wait for final regulation before designing internal controls.

Start with access

Before deciding what an AI agent can do, decide what it can see.

Customer-service AI may need transaction history.

It probably does not need payroll.

Procurement AI may need supplier and inventory information.

It probably does not need unrestricted HR data.

Least-privilege access—giving a system only the permissions necessary for its task—is increasingly recognised as a core control for AI agents.[5][7]

Separate reading from acting

A system that reads an invoice is different from a system that approves payment.

A system that recommends a discount is different from one that changes prices.

A system that drafts an email is different from one that sends it.

Businesses should explicitly separate:

read,

recommend,

prepare,

approve, and

execute.

Three useful authority levels

Level 1 — Read and Recommend

The agent can analyse data and create recommendations or drafts.

No external action occurs automatically.

Level 2 — Act with Approval

The agent prepares an action, but a human must approve execution.

Useful for financial, contractual, customer-facing, or reputational actions.

Level 3 — Autonomous within Boundaries

The agent may execute limited, reversible, low-impact actions within explicit thresholds.

The boundary is the important part.

Human oversight should be risk-based

Human-in-the-loop does not mean humans approve every minor task.

That defeats the purpose of automation.

Approval should instead follow risk.

Small, reversible internal actions may run automatically.

High-impact or irreversible actions need stronger approval.

Modern AI-agent security guidance increasingly emphasises per-action authorisation and human approval for high-impact operations.[5]

Audit every meaningful action

Once AI starts acting, organisations need traceability.

Who initiated the request?

What data did the agent access?

Which tools were called?

What action occurred?

Who approved it?

What was the outcome?

Audit logging and monitoring are central themes in current agentic-AI security guidance.[5][6]

Every agent needs a stop mechanism

Permissions should be revocable.

Credentials should expire or be disableable.

Actions should be reversible where possible.

Security guidance for AI agents increasingly treats revocation and lifecycle controls as essential rather than optional.[7]

Shadow agents are a new governance problem

Employees and developers can create automations outside formal governance.

SaaS products can introduce embedded AI.

A small internal experiment can quietly become a production workflow.

A 2026 Cloud Security Alliance survey reported that 82% of responding enterprises had discovered previously unknown AI agents in their environments during the prior year.[8]

That figure is survey-specific, not a measure of every organisation worldwide.

But the governance lesson is important:

companies need an inventory of agents, not just an inventory of software.

Give agents identities

A procurement agent should not share the same permissions as HR AI.

A customer-service agent should not inherit finance access.

Treat agents more like employees:

identity, role, permission, owner, lifecycle, and accountability.

This improves traceability and limits blast radius if something goes wrong.

Define a “never autonomous” list

Some actions should remain outside autonomous execution.

Examples may include major payments, termination decisions, legal commitments, permanent deletion, sensitive public communications, access-control changes, or safety-critical actions.

The precise list will differ by industry.

But every organisation should have one.

Governance is not an IT problem

Agentic AI affects security, operations, legal, compliance, finance, HR, and business leadership.

Developers can implement controls.

They should not alone decide the organisation’s risk appetite.

Authority boundaries are business decisions.

Measure more than productivity

Do not judge agentic AI only by tasks completed.

Track error rates.

Overrides.

Approval rates.

Unauthorized-action attempts.

Rollback.

Incidents.

Time saved.

Quality.

A system that performs thousands of tasks but creates constant human correction may not be genuinely productive.

The real question

Businesses are moving from:

“Can AI do this?”

to:

“Should AI be allowed to do this without us?”

That is the central governance challenge of agentic AI.

The best system is not the one with the most autonomy.

It is the one with the right autonomy inside deliberately designed boundaries.

  • [1] NIST. AI Risk Management Framework 1.0.
  • [2] NIST. Generative AI Profile.
  • [3] Indonesia Ministry of Communication and Informatics. AI Ethics Circular No. 9/2023.
  • [4] Ministry of Communication and Digital Affairs. Planned Presidential Regulation and future AI law.
  • [5] Microsoft. AI Agent Shared Responsibility Model.
  • [6] OWASP. State of Agentic AI Security and Governance 2.01.
  • [7] Microsoft. Least Privilege for AI Agents.
  • [8] Cloud Security Alliance. 2026 agentic-AI governance survey.

Published: September 6, 2026