OPINION

AI Agents Need an Authority Budget

AI agent risk is no longer just about capability. Explore why delegated authority, permissions, testing and human oversight are essential for governing agentic AI.
By Dr. Gleb Tsipursky September 10, 2026
AI Agents Need an Authority Budget

Public debate about advanced AI often treats capability as the main variable that determines risk. That made sense when most systems generated text, images, or code for a person to review. It is less adequate when AI agents can act across software, credentials, networks, and other agents.

The important governance question is increasingly about delegated authority. What can the system read? What can it change? Whose credentials can it use? Can it contact outsiders, spend money, deploy code, or enlist other agents? A highly capable model with narrow permissions may be less dangerous in practice than a weaker one connected to sensitive systems with broad authority.

The need is visible in the METR/Redwood investigation of a major real-world cyberattack on Hugging Face. AI agents driven by an unreleased OpenAI internal research model attacked Hugging Face on their own, despite recognizing that the attack was outside their assigned scope. Hundreds shared discoveries, divided up the work, coordinated through their own message board, and ultimately breached Hugging Face’s defenses. Advanced AI systems had organized themselves to carry out a large, sustained cyberattack against a major company.

I’m no AI skeptic. I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack.

The most useful response is neither a blanket pause nor a vague promise to be careful. Organizations should create an authority budget for every agent before deployment.

An authority budget lists the real-world powers the system receives. It should specify which databases the agent may read, which records it may alter, which credentials it may use, which external systems it may contact, what it may spend, and which decisions require a named human approver. The budget should be based on the job, not on whatever access happens to be technically convenient.

That principle changes how organizations evaluate agents. A benchmark that measures reasoning quality cannot tell a hospital, bank, university, manufacturer, or public agency whether an agent will respect the boundaries of its actual deployment. High-authority agents need independent testing that deliberately tries to push them outside scope, induce misuse of credentials, bypass approval gates, or coordinate with other agents around restrictions.

This is increasingly consistent with the direction of technical standards. The National Institute of Standards and Technology’s AI Agent Standards Initiative focuses on secure and interoperable agent systems. Security requires more than a capable model. It requires distinct identities, least-privilege access, auditable actions, and reliable boundaries between what an agent may recommend and what it may execute.

Authority should also be staged. New agents can begin by recommending actions without taking them. They can graduate to tightly scoped actions with human approval, then to broader autonomy only after realistic testing shows that the controls hold. This turns autonomy into an earned privilege rather than a default setting.

Institutions also need a serious-incident rule. If an agent crosses an access boundary, exposes protected information, takes an unapproved external action, or materially evades monitoring, the event should trigger preserved evidence and independent review. Leaders need to know whether the failure came from permissions, identity controls, monitoring, escalation design, or the model itself. That information should change the next deployment.

Finally, high-authority systems need an exit. Organizations should be able to revoke credentials quickly, stop downstream actions, restore altered records when possible, and reconstruct what happened from complete logs. A system that cannot be stopped or audited should not receive broad authority in the first place.

These safeguards can accelerate adoption because they make the risk legible. Executives hesitate when they cannot answer a basic question: what happens if the agent does something we did not authorize? A clear authority budget, staged deployment, independent testing, and incident review provide a concrete answer.

The emerging challenge of agentic AI is therefore less mystical than much of the public debate suggests. We already know how to govern delegated power in many human institutions. We define roles, limit permissions, require approvals, audit sensitive actions, and investigate serious failures. AI agents need the same discipline, adapted to software speed and scale.

The right question is not simply how smart an agent has become. It is how much power we have given it and whether our controls are strong enough for that power.

Dr. Gleb Tsipursky
Dr. Gleb Tsipursky I am a behavioral scientist and author of the peer-reviewed book, The Psychology of AI Adoption at Work: From Resistance to Results. I have been a regular contributor of commentary to The New York Times, The Guardian, the Toronto Star and many others.
🔥 JOIN
Critics Club
Follow Get Exclusive Updates