Biphoo News

collapse
Home / Daily News Analysis / Why businesses need clearer limits before AI agents are authorized to act

Why businesses need clearer limits before AI agents are authorized to act

Aug 31, 2026  Twila Rosenbaum  5 views
Why businesses need clearer limits before AI agents are authorized to act

The pace of artificial intelligence adoption is outpacing the governance structures meant to contain it. That is the central finding of a sweeping study by IBM, which surveyed 2,000 C-level technology executives across major corporations. The results reveal a troubling statistic: only 11% of executives feel fully prepared for the deployment of AI agents over the following year. Two-thirds of CIOs and CTOs admit they are accountable for AI systems they do not fully control, while 70% say teams are deploying technology faster than IT can track. IBM presents these numbers as evidence of a widening control gap as AI use expands far beyond experimental projects into mission-critical workflows.

AI agents are software programs that use large language models to plan and execute sequences of actions in pursuit of a goal. Unlike simple chatbots, which respond to prompts in a static way, agents reason about their environment, call external tools, and make decisions about the next step. This autonomy is what makes them powerful, but it also introduces new forms of risk. An agent's decision-making process is often opaque, and its actions may have unintended consequences when it operates across multiple systems. Enterprises are beginning to realize that deploying AI agents requires more than just an API key; it demands a governance framework that considers authority, context, and impact.

The control gap is not merely a matter of technical oversight. It is a fundamental issue of trust and authorization. For Madhuri Chandoor, founder of PromptHalo, an AI security and trust infrastructure company, the core problem lies in distinguishing capability from authority. She argues that an AI agent might be technically capable of performing an action, but that does not mean it is authorized to perform it in every context. Her company focuses on inspecting why a specific action is being executed, not just what is being executed. This context-aware approach is intended to give organizations a clearer picture of whether an action aligns with user intent, assigned permissions, and the surrounding circumstances before the system proceeds.

The risks of autonomous action in production environments

Chandoor illustrates the concern with a hypothetical enterprise database task. Imagine an infrastructure-managing AI agent that has been asked to improve application performance. Operating autonomously, it might decide to add or remove an index, or even alter table structures in a production environment. In isolation, those actions can appear technically reasonable. But production environments are not isolated. They affect live transactions, customer data, and dependent processes that were never part of the agent's narrow analysis. 'A technical conclusion can appear reasonable within a narrow focus,' Chandoor notes. 'The context, the situation, and the downstream impact still need to be considered before an action proceeds.'

This scenario is not far-fetched. As AI agents gain access to increasingly sensitive systems, their capacity to cause unintended damage grows. The shift from simple chatbots to large language model-based agents has been dramatic. Earlier chatbots typically operated within predetermined questions and answers, with little ability to influence the surrounding environment. By contrast, modern AI agents work with broader company information and a wider range of tools, thereby expanding the exposed risk surface. Security teams must now consider how incoming requests are interpreted and what level of authority connected systems grant before taking any action.

When per-action limits are not enough

Chandoor introduces a particularly clever example to explain why context spans multiple actions. Suppose an AI agent is authorized to issue refunds up to $50 without human review. A user then requests ten separate refunds of $50 each, instead of one $500 refund that would trigger escalation. Individually, each transaction appears permissible. Collectively, the sequence suggests an intentional effort to avoid the threshold. This is a classic pattern of decomposition, where large actions are broken into smaller, less conspicuous ones. Chandoor argues that reviewing broader session context and behavioral patterns can help identify when an escalation for human review is warranted.

This kind of risk is especially relevant in financial services, where fraud detection has long relied on transaction monitoring. Drawing on two decades in that sector, Chandoor compares her approach with the behavioral profiling used to flag suspicious activity across accounts. She suggests organizations build behavioral profiles for autonomous agents, similar to the profiles they create for human users. Teams would review the resources an agent accesses, the tools it uses, how its activity changes over time, and any actions that appear inconsistent with its assigned role or the specific circumstances of a session.

A framework for authorization and observability

Chandoor emphasizes that questions about authorization should be addressed during both the design phase and operational phase of an AI agent's lifecycle. During design, teams should document the resources an agent may access, the conditions that apply to that access, and the possible downstream effects of particular actions. During operation, organizations need observability gates that allow them to pause or inspect activity. These checkpoints are particularly useful when requests become repeated, unusually broad, or inconsistent with the original purpose assigned to the agent. They can contain the impact of an errant action and determine what additional controls are necessary to secure the underlying systems.

The need for such frameworks is becoming more urgent as AI agents move from proof-of-concept to production. Many organizations are under pressure to innovate with generative AI and agentic tools, but they lack the governance mechanisms to ensure safe deployment. The IBM survey data underscores that gap. Executives admit to a lack of visibility and control, yet the pace of adoption shows no sign of slowing. In an environment where teams are deploying technology faster than IT can track, the risk of unauthorized or harmful actions rises sharply.

Behavioral monitoring for AI agents

Behavioral profiling for AI agents is still an emerging practice, but it builds on well-established principles from cybersecurity and fraud prevention. Banks, for instance, do not simply rely on static access controls; they monitor patterns of behavior to detect anomalies. If an account that routinely makes small purchases suddenly initiates a series of high-value transfers, the system flags it for review. The same logic applies to an AI agent that begins making unusual queries, accessing unexpected datasets, or executing actions outside its normal remit.

The challenge is distinguishing between a genuine anomalous action and one that is simply new. AI agents are designed to learn and adapt, so their behavior may legitimately evolve. This makes the problem of defining a 'normal' baseline difficult. Chandoor's suggested answer is to tie behavior to context: what is the agent's purpose, what resources is it permitted to access, and what is the user's intent? By combining these elements, an organization can create a more nuanced view of whether a particular action should proceed or require human approval.

Responsible AI adoption through verification

Chandoor is careful to position her approach as a support for responsible AI adoption, not a brake on innovation. She favors using agentic automation for analysis and workflow optimization, where the potential for harm is low. But when the impact involves critical decisions and actions, additional verification is necessary. Her slogan, 'Trust, but verify,' captures this balance. Organizations can rely on AI to accelerate work, but they must also put in place mechanisms to verify that its behavior remains aligned with business rules and ethical guidelines.

'Businesses should adopt AI responsibly and verify its behavior throughout the process,' she says. 'Establishing clear accountability ownership across the organizations for AI applications security is essential to operationalise these guardrails.' Without that accountability, even the most sophisticated technical controls will fail. The goal, in her view, is to pursue AI innovation while giving security and accountability the attention they deserve.

The growing use of AI agents in the enterprise reflects a broader trend toward autonomous systems that can execute tasks with minimal human intervention. But autonomy without oversight is a recipe for disaster. By distinguishing between capability and authority, monitoring behavior across sessions, and documenting the limits of an agent's power, organizations can harness the benefits of AI while reducing the risks. The IBM survey shows that the vast majority of executives are not ready for this transition. The question is whether they will take the necessary steps to close the control gap before a high-profile failure forces them to.


Source: TNW | Artificial-intelligence News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy