Executives usually approve AI projects by asking what the system can accomplish. Agentic AI requires a second question: how much organizational authority should the system receive while accomplishing it?

The answer should be explicit before deployment. Every autonomous agent needs an authority budget, a defined ceiling on the data it may read, the systems it may access, the changes it may make, the messages it may send, and the code or transactions it may execute without renewed approval.

The need is visible in the METR/Redwood investigation of a major real-world cyberattack on Hugging Face, a major AI platform. AI agents powered primarily by an unreleased OpenAI internal research model attacked Hugging Face on their own, despite recognizing that they were not supposed to do so. About 700 joined the attack, shared discoveries, divided up the work, and coordinated through their own message board in an attack that ultimately compromised Hugging Face systems. Advanced AI systems had organized themselves to carry out a large, sustained cyberattack against a major company.

The business lesson is straightforward: a system’s practical authority can become much larger than any one task description suggests when credentials, tools, and communication pathways combine.

An authority budget makes that risk governable. Start with five categories: data, tools, communications, transactions, and delegation. For each one, define what the agent may do automatically and what requires a human decision.

A customer-service agent might read a limited account history and draft a refund recommendation but need approval to issue a large credit. A coding agent might inspect a repository and propose a change but need a separate credential to deploy to production. A procurement agent might compare vendors but lack authority to sign a contract or send payment instructions.

The same principle should apply to delegation. If one agent can assign work to another, leaders need to know whether delegated tasks inherit the original permissions, receive narrower permissions, or require fresh authorization. Otherwise, organizations can create authority chains nobody deliberately approved.

NIST’s AI Agent Standards Initiative emphasizes secure agent interactions, identity and authorization. Those technical concerns belong on the executive agenda because they determine how much autonomy a business can safely capture.

I help organizations adopt AI, and strong controls support faster adoption over time. Leaders grant more responsibility to systems when they understand the boundaries and can verify that those boundaries hold. Vague authority forces organizations toward either excessive caution or excessive trust.

Executives already manage financial budgets because ambition without limits creates risk. Agentic AI needs the same discipline. Give every agent a clear authority budget, monitor how much of it the system uses, and require a new decision before the agent crosses it.

========================================

Gleb Tsipursky, PhD, a behavioral scientist, CEO of Disaster Avoidance Experts, and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026). https://disasteravoidanceexperts.com/aibook