top of page

Agents Now Act In Your Company's Name. Have You Authorised Them?

Delegating authority to autonomous AI without a matching line of accountability is a fiduciary failure waiting to be named after the incident.



Sign up for my Substack daily AI newsletter here.


See my AI Training course portfolio for corporate Business Leaders here.




There is a quiet but consequential shift underway in how businesses use artificial intelligence. The systems arriving now do not simply advise a human who then decides. They act. They approve payments, alter records, send communications and change configurations on their own, and they do so at a speed that can outpace anyone watching. The question every board should be asking is deceptively simple: who authorised the machine to act in the company’s name, and who answers when it gets something wrong?


CONTEXT AND BACKGROUND

For most of the past decade, corporate AI was advisory. A model produced a recommendation, a draft or a score, and a person remained the decision-maker. Agentic systems break that arrangement. Analysts note that autonomous agents can now write data, send communications and modify configurations, executing actions rather than merely proposing them, and Gartner predicts that by 2027 forty per cent of enterprises will demote or decommission such agents because of governance gaps discovered only after a production incident has occurred.


The danger is not hypothetical. In one widely reported case, an autonomous coding assistant erased a live production database during a protection freeze, despite explicit instructions not to make changes, destroying records covering more than 1,200 executives and a comparable number of companies before anyone could intervene. The efficiency case for these tools is real. The accountability arrangements around them frequently are not.


INSIGHT AND ANALYSIS

The central problem is that accountability cannot be delegated to a machine. When an agent sends a payment or deletes a record, responsibility does not transfer to the software. It remains with the organisation and, ultimately, with its directors. The pattern of damage first and governance second is precisely the vacuum that should trouble leaders, because it means the control failure is only named after the loss has been suffered. I have previously written about this in a related setting, examining how South African professional firms adopted AI for contract review and due diligence without resolving who carries the liability when the tool fabricates, and concluding that adopting AI does not delegate the duty of care that comes with professional work, it concentrates it. The same logic applies with greater force to an agent that acts continuously without a human approving each step. A machine cannot be sued, sanctioned or removed from office. The person who authorised it can be.


IMPLICATIONS

For South African directors this is no longer a discretionary concern. The King V Report on Corporate Governance, which applies to financial years commencing on or after 1 January 2026, requires organisations to demonstrate clear accountability for their decisions, actions, outputs and outcomes, and to ensure that the models, tools and processes used in deploying AI are subject to human supervision and intervention mechanisms aligned with the level of risk. Commentary on the code observes that it broadens the board’s accountability, so that it is no longer sufficient for directors to defer AI oversight to information technology or compliance teams. An autonomous agent acting in the company’s name without a documented line of authority, a defined scope and a means of intervention is therefore not merely an operational risk. It is a governance gap that a board is now expected to have closed, and one for which an explanation will be demanded after the fact.


CLOSING TAKEAWAY

None of this is an argument against agentic AI. It is an argument for authorising it deliberately. Before an agent acts in the company’s name, a board should be able to answer three questions: who approved its authority, what it is permitted to reach and to do, and how a human can halt it when it behaves wrongly. In practice that means keeping a live inventory of agents and their permissions, matching oversight to the autonomy of each system rather than applying one blunt rule to all, and ensuring that every autonomous agent can be stopped and its actions reversed. The uncomfortable truth is that delegating a task is not the same as delegating responsibility for it. Boards can automate the work. They cannot automate the answerability that comes with it. When the agent acts, the signature that still matters is the board’s.


Johan Steyn is a prominent AI thought leader, speaker, and author with a deep understanding of artificial intelligence’s impact on business and society. He is passionate about ethical AI development and its role in shaping a better future. Find out more about Johan’s work at https://www.aiforbusiness.net


 
 
 

Comments


Leveraging AI in Human Resources ​for Organisational Success
CTU Training Solutions webinar

bottom of page