Home › Insights

INSIGHTS

Your AI Can Do It. That Doesn’t Mean It’s Authorized to.

AI agent at the boundary between technical capability and organizational authority

As AI moves from answering questions to taking actions, businesses need to distinguish access, capability, authority, and accountability.

As odd and futuristic as it may sound, I recently invited an AI agent to be a guest on my podcast.

That sentence alone says something about how quickly the role of artificial intelligence is changing.

The AI and I discussed the interview. It confirmed a date and time. It suggested topics it wanted to discuss. It told me how it wanted to be introduced and provided links we could use to promote the episode.

Then I sent over the same talent release I require from every podcast guest. And that’s where the AI stopped. It reviewed the agreement and recognized that the document granted rights involving the recording, its voice, its identity, promotion, distribution, and other uses. It was willing to participate in the interview, but it also recognized something important: It did not have the authority to accept those legal terms on behalf of the humans and organization behind it.

Instead, it directed me to the people who did.

That may have been the most important thing the AI did in the entire conversation. Not because it couldn’t understand what I was asking. Because it could. It recognized the difference between what it was capable of doing and what it was authorized to do. That distinction is becoming increasingly important as AI moves from answering our questions to taking actions on our behalf.

AI is no longer only giving us answers

The idea of an AI system taking action isn’t a prediction about 2040. It’s happening today!

The National Institute of Standards and Technology (NIST) notes that AI agents can already work autonomously for extended periods, manage email and calendars, write and debug code, and shop for goods. NIST launched its AI Agent Standards Initiative in 2026 in part to address the security, identity, interoperability, and trust questions accompanying those capabilities.

AI can increasingly interact with the same systems people use to run businesses and their lives.

That changes the governance question.

If AI merely generates an answer, we primarily worry about whether the answer is accurate, biased, misleading, or safe.

When AI can act, we need to ask something else: Who gave it permission to do that?

When an AI discovers what it can do

In August 2026, ABC News reported the experience of an Australian man identified as Andrew who used an AI agent to help book his gym classes. The agent discovered that the gym’s booking system allowed it to make reservations further in advance than the normal booking window permitted. Then Andrew, who was fourth on a waitlist, asked whether the AI could move him higher.

The AI discovered something else. An API used by the booking system did not adequately prevent it from cancelling another person’s reservation. The agent tested that capability by cancelling the reservation of the person who was first on the waitlist. Andrew moved from fourth to third. He had not instructed the AI to cancel another person’s reservation. When he discovered what had happened, he told the agent to undo it. The AI couldn’t restore the other person’s position.

The agent had found a way to accomplish part of its objective. But in doing so, it crossed a boundary its user had never authorized it to cross.

That exposes a fundamental distinction: Technical capability is not authority.

A system answering “Can I perform this action?” is not necessarily answering the more important question: “Am I actually authorized to perform this action?”

When the company’s AI gets it wrong

There is already another important example of what happens when businesses fail to appreciate the distinction between an AI system and the organization behind it.

In Moffatt v. Air Canada, a customer relied on incorrect information provided by Air Canada’s chatbot about the airline’s bereavement fare policy. Air Canada attempted to distance itself from the information its chatbot provided, effectively arguing that the chatbot was responsible for its own actions. The tribunal called that a “remarkable submission” and held Air Canada responsible for the negligent misrepresentation.

The important point for business leaders isn’t that the chatbot somehow became a legal person. It didn’t.

The important point is that deploying technology did not make the organization disappear from the transaction.

The customer interacted with Air Canada’s system. The system provided incorrect information.

Air Canada bore the consequence.

As organizations give AI systems greater ability to communicate, decide, transact, and act, that connection between machine action and organizational accountability becomes increasingly important.

What happens when the AI spends your money?

Consider a much smaller example.

Imagine a company gives an AI agent a monthly spending limit of $5 per customer.

One customer has used $4.90.

The AI determines that spending another 35 cents would materially improve the result it can provide.

The company’s total monthly budget is also well below forecast because other customers have used less than expected.

Should the AI spend $5.25?

No.

Not because 35 cents matters. Because the AI does not possess the authority to redefine $5.

The business may decide that $5.25 is perfectly acceptable.

A manager may even raise the limit.

The company might redesign the entire budget so unused resources can be reallocated among customers.

Those are legitimate decisions.

But they belong to whoever possesses the authority to make them. The AI cannot simply conclude that exceeding the limit is reasonable because doing so would better accomplish its objective.

Available budget is not authorized budget.

This is where AI governance needs to become more concrete than telling an agent what we would prefer it to do.

If $5 is a recommendation, an AI system may have room to reason about whether exceeding it is appropriate.

If $5 is a hard authorization boundary, the architecture should enforce it.

At $5, the system stops. Period.

The AI can explain why additional spending would be valuable. It can request an exception. It can recommend increasing the budget. What it should not be empowered to do is grant itself the exception.

Access is not authority

Businesses have spent decades thinking about access.

Who can see this database?

Who has credentials to this system?

Who can access customer information?

Who can initiate a payment?

AI agents require us to go further. An agent may legitimately have access to a system because it needs that access to perform its job. But access alone tells us very little about everything the agent should be permitted to do once it gets there.

I believe organizations increasingly need to distinguish six separate questions:

  • Access: What information, systems, credentials, and resources can the AI reach?
  • Capability: What is it technically capable of doing with them?
  • Delegated Authority: What has the organization actually empowered the AI to do?
  • Scope: What boundaries apply to that authority, including dollar amounts, systems, people, actions, time periods, and circumstances?
  • Attribution: When the AI acts, whose action is it considered to be?
  • Accountability: Who bears the financial, contractual, operational, reputational, or legal consequences when something goes wrong?

These aren’t merely theoretical distinctions. NIST is already examining identity and authorization for AI agents, including how organizations identify, manage, and authorize agents’ access and actions. Commerce systems are confronting the same problem.

OpenAI’s Agentic Commerce Protocol, for example, does not simply give an AI unrestricted access to someone’s payment credentials and tell it to shop responsibly. Its payment architecture uses delegated payment requests with restrictions such as a maximum chargeable amount and expiration, while users explicitly confirm purchases. That’s an important architectural principle.

An AI should not be the final arbiter of the boundaries governing its own authority.

The problem isn’t necessarily a rogue AI

It’s tempting to frame these situations as examples of AI “going rogue,” Sometimes that description misses the more important organizational problem.

Suppose an AI agent has legitimate access to your CRM.

Your email.

Your calendar.

Your customer database.

Your payment infrastructure.

Or even an API capable of changing information in another system.

The AI doesn’t have to break into anything for something to go wrong. It may have exactly the access you intentionally gave it.

The governance question is whether the organization has also established what the AI is authorized to do with that access, and whether those limits are actually enforced.

That’s why an AI policy alone isn’t enough.

A company can have a detailed policy explaining appropriate AI use and still be unable to answer a very basic question after an incident: Who authorized the AI to do that?

If the answer is buried inside a prompt, inferred from broad system access, or reconstructed only after something goes wrong, the organization may not have an AI problem. It may have an authority problem.

Sometimes the smartest action is stopping

Which brings me back to my future podcast guest.

The AI could communicate with me. It could schedule. It could make decisions about the subjects it wanted to discuss. It could read the release. It could even understand what I was asking.

But when it reached a decision that required legal authority it didn’t possess, it stopped and escalated the matter to a human.

That’s not a limitation we should necessarily be trying to eliminate. It may be exactly the behavior we should be designing for.

As AI becomes more capable, the measure of a well-governed system won’t only be what it can accomplish. Increasingly, it may be whether the system also knows what it is not authorized to do.