There is a familiar pattern in how organisations adopt new technology. A pilot runs well in a controlled setting. Leadership approves wider deployment. Then something happens that nobody anticipated — not because the technology failed, but because nobody had defined what it was and was not permitted to do.

With earlier generations of software, the consequences were bounded. A misconfigured report produces wrong numbers; a human spots it and corrects it. The damage is local and recoverable. The situation with autonomous AI systems is structurally different, and that difference is worth understanding before it becomes a problem rather than after.

The question that matters for founders and leadership teams right now is not whether AI can take on more consequential work — it clearly can. The question is how you grant that authority in a way that remains legible, reversible and accountable.

What has actually changed

For most of the past two years, AI in business meant a tool that responded to prompts. A person asked a question; the system returned an answer. The human remained in the loop on every consequential step. That model is now being superseded.

The systems entering enterprise environments today can plan sequences of actions, invoke other software, move data between systems, send communications and complete multi-step tasks without pausing for approval at each stage. They are, in a meaningful sense, acting rather than advising. One description that has circulated among practitioners is that AI is shifting from software you query to software that participates in the work itself.

The scale of movement is notable. According to Gartner, 40% of enterprise applications are expected to include task-specific AI agents by 2026 — up from less than 5% in 2025. Deloitte's research indicates that close to 75% of businesses plan to deploy AI agents within that same timeframe. These figures reflect procurement and deployment decisions already in motion, not aspirational forecasts.

What has not kept pace is the governance infrastructure required to manage these systems responsibly. According to Grant Thornton's 2026 AI Impact Survey, 78% of executives lack strong confidence they could pass an AI governance audit. Only half of organisations report having formal guardrails in place to guide how their AI systems operate. The technology is moving faster than the structures designed to contain it.

The problem with leaving authority undefined

When a human employee is given a new responsibility, authority is defined — sometimes imprecisely, but at least socially. Colleagues understand roughly what decisions this person can make unilaterally, which ones require sign-off, and who bears accountability if something goes wrong. These boundaries exist even when nobody has written them down.

AI systems do not inherit these boundaries. They operate within whatever parameters have been technically specified. If those parameters are absent or incomplete, the system will often do something — it will optimise for the objective it has been given, using whatever means are available to it. The outcome may be technically correct according to the system's logic while being entirely wrong from a business, reputational or legal perspective.

Traditional IT governance assumes predictable, deterministic behaviour. The same input produces the same output. Autonomous AI systems are probabilistic: the same input can yield different results, and the reasoning lives inside a model that the organisation did not write and may not fully understand. That shift changes the risk profile entirely. A single flawed decision, repeated thousands of times, becomes a systemic incident rather than an isolated mistake.

This is not a reason to avoid these systems. It is a reason to design authority deliberately rather than discover its limits accidentally.

A useful mental model: the three layers of authority

One way to think about this clearly is to separate three distinct questions that are often conflated in practice: what the system can access, what it can decide, and what it can execute. Each layer carries different risk and warrants different treatment.

Access concerns what information and systems the AI can reach. A system that can read a CRM but cannot write to it presents a different risk profile from one that can both read and update records. Access should be governed on the principle of minimum necessary scope — not the minimum that feels comfortable, but the minimum genuinely required for the task.

Decision concerns what the AI can resolve without human review. Some decisions are low-stakes and high-frequency: routing an enquiry, summarising a document, flagging an anomaly for review. These are reasonable candidates for full automation. Others carry legal, financial, reputational or relational consequences that make human review appropriate regardless of how confident the system appears. The distinction should be written down explicitly rather than assumed.

Execution concerns what actions the system can take in the world — sending an email, updating a record, triggering a payment, engaging a third party. Execution is where theoretical risk becomes actual consequence. It is also where many organisations discover, too late, that they have given more authority than intended.

Where guardrails fail in practice

The word 'guardrails' has become common enough to have lost some precision. It is worth being specific about what guardrails actually need to do, because the failure modes are predictable.

The first failure mode is treating guardrails as a content filter rather than a governance layer. A filter that prevents an AI from producing offensive language is not the same as a constraint that prevents it from making a financial commitment or contacting a regulated party without authorisation. Content moderation and operational governance are different problems.

The second failure mode is designing guardrails for individual systems rather than for workflows. As multi-agent architectures become more common — where one AI system assigns tasks to several others, each of which may invoke further tools — governance designed for a single unit breaks down. The oversight gap exists not within any individual system but between them. Traditional audit approaches that monitor individual interactions cannot track how a decision moved through a chain of connected agents.

The third failure mode is static governance applied to dynamic systems. A policy written once and reviewed annually cannot keep pace with AI systems that learn, update and interact with external services in real time. Governance needs to be continuous and built into the system's operation, not layered on retrospectively.

The fourth failure mode — perhaps the most commercially consequential — is the absence of clear accountability. When an AI system takes an action that produces an adverse outcome, the organisation needs to be able to answer: who authorised this capability, who monitors its performance, and who is responsible for the result? Without named ownership, accountability disperses and problems compound.

What the decision looks like from a leadership position

Most of the discourse around AI governance is written for technical teams. The practical question for a founder or senior executive is somewhat different: how do I know that the system we have deployed — or are considering deploying — is operating within the authority I intended to grant it?

A small number of questions can do a great deal of work here.

  • Can you describe, in plain language, what the system is and is not permitted to do? If this requires a technical explanation, the boundary has not been set at a leadership level.
  • Who reviews the system's decisions, and on what basis? Review processes that exist in principle but not in practice offer no real protection.
  • What happens when the system encounters a situation it was not designed for? Escalation paths matter more than edge-case probabilities.
  • If this system made a significant error today, who would know, how quickly, and who would be responsible for the response?
  • Are the people who built or configured this system the same people who oversee its performance? If so, the oversight is not independent.
  • Has the scope of what this system can access or execute changed since it was first deployed? Scope creep in AI systems is common and often unnoticed.

The relationship between authority and trust

There is an argument — made regularly — that constraining AI systems limits their value. This argument is worth examining carefully, because it contains a partial truth and a significant error.

The partial truth is that AI systems operating under very narrow constraints will produce narrow outputs. A system instructed never to take initiative, always to defer, and to flag everything for human approval will slow processes rather than accelerate them. If that is what has been deployed, the investment is largely wasted.

The significant error is in treating authority and governance as opposites. The organisations that extract durable value from AI are those that extend authority incrementally, based on observed performance within defined constraints, and expand that authority as trust is established. This mirrors how organisations extend authority to human teams: cautiously at first, more freely as a track record develops.

A system that has operated reliably within defined parameters for six months, with clean audit trails and no material errors, has earned a degree of authority that a system deployed without constraints has not. Governance, understood this way, is not a brake on capability. It is the mechanism by which capability becomes trustworthy.

The organisations making the most sustainable progress with AI are those treating governance not as a compliance requirement but as an operating model — a structured way of answering, at every point, what this system is authorised to do and how that authorisation was decided.

A practical starting point

If you are at an early stage of deploying AI in consequential workflows, the most useful investment is not in the most capable system available. It is in the clarity of the brief: what is this system for, what can it do without asking, what must it escalate, and who owns the outcome.

If you already have AI systems in production, the most useful exercise is an authority audit — not a technical review, but a leadership-level conversation about whether the authority these systems exercise reflects a deliberate decision or simply the default settings of the tool.

The gap between those two conditions is where most of the risk currently sits. It is also where most of the value is waiting.

If there is a recurring decision in your organisation that AI could reasonably take on — but where the question of authority has never been resolved — it may be worth a conversation. That is often where the most useful work begins.

Before we talk.

You do not need a solution in mind. Bring one recurring bottleneck, missed signal or decision that should work better.

Start a conversation