Companies are usually good at defining who has authority over what. Employees receive access based on their role, larger decisions require approval, and when something goes wrong there is normally a person who made or authorized the call. Most of those same companies are now handing part of that authority to AI agents, and the rules around it are nowhere near as settled.
Take a sales agent told to move a late-stage prospect toward signature. It follows up, answers questions, and eventually agrees to a delivery date the company cannot meet. No human directly made that decision, which puts the agent forward as the obvious answer. Naming the actor still leaves the question of who authorized it to commit the company to a date.
The agent can make the decision, but it cannot take responsibility for the consequences in any meaningful organizational or legal sense. That responsibility falls to the company and, ultimately, to the people who gave it the authority to act.
Once agents can act, the company owns the fallout
For most of the generative AI era, a human decision separated model output from company action. A coding assistant might suggest a broken fix, but an engineer had to accept the change and push it live. Give that agent authorization to change the code itself, and the mistake reaches production without another person signing off on it.
This is already happening. A Cloud Security Alliance survey of 445 IT and security professionals found that 53 percent of organizations had seen AI agents go beyond the permissions they were supposed to have, and the figure is likely to rise as adoption spreads and companies give agents more room to act independently.
Once an agent can turn its own judgment into a real company action, someone has to own the authority behind it. Otherwise the company may know exactly what the agent did and still have no clear answer as to who was responsible for letting it happen.
The first step is knowing which agent made the call
Before anyone can answer for an agent’s decision, the company has to know which agent made it. That turns out to be difficult once several agents work through the same employee login, API key, or service account. A log may show which credentials touched the system without showing which agent used them or whether the action fell inside the authority it had been given.
In March 2026, an AI agent completed a live transaction in Singapore after booking a ride to Changi Airport. The payment ran on tokenized credentials and a payment token issued uniquely to that agent, which let it act on the customer’s behalf inside the payment system. Companies need the same clarity inside their own walls: an identity for every agent, tied to a human owner, with permissions attached to the agent and a way to change or revoke them when its role changes.
Once the agent is identifiable, the next question is who stands behind it, and that is already a practical concern for executives. An IBM study of 2,000 technology executives found that two-thirds of CIOs and CTOs are held accountable for AI systems they do not fully control. An executive expected to answer for an agent’s actions needs to know which agent acted and who gave it that authority.
Not every agent should get the same freedom
Companies will get more out of agents once they stop treating autonomy as something an agent either has or does not have. A research agent can be given plenty of room to work on its own; if it misreads a competitor’s pricing model or draws the wrong conclusion from a market report, an analyst can challenge the finding before it affects anything outside the team. An agent that can change employee permissions has far more scope to cause damage when something goes wrong. The sensible level of autonomy changes with the work itself, and with how much can go wrong before a person gets another chance to step in.
Singapore’s 2026 agentic AI framework sorts tasks along that line: routine, reversible actions such as password resets are left to the agent under periodic audit; moderate-risk fixes need a human approval before the agent can act; and permission changes, where the damage is hard to undo, stay out of the agent’s hands entirely.
Agents need the same lifecycle discipline as employees
An agent’s role may look perfectly clear on the day it is deployed. Six months later, the person who created it may have moved teams, its workflow may have changed, or the systems it touches may no longer match the job it was built to do. If nobody reviews the setup, the agent may still be able to act inside systems that should have left its scope months earlier.
Companies already have well-established processes for keeping employee access and responsibility aligned with the role. Agents need the same discipline around who owns them, what they can access, and when those permissions should change. If the person responsible for an agent changes roles or leaves the company, ownership has to move with the job, along with a review of the agent’s permissions.
Accountability has to be designed before deployment
By the time an agent has access to customer systems, production code, or company money, the important decisions about accountability should already have been made. Someone needs to own the agent from day one, and ownership on paper is not enough. The company also has to decide what the agent can do without asking, which actions require approval, and what should happen when it encounters a situation outside the scope of its role.
Those rules belong in the workflow itself. Telling a finance agent to “be cautious” leaves the judgment with the agent; a spending limit written into the tool takes it back. An approval step placed in front of a risky action does the same job for decisions no limit can cover. The same goes for escalation and shutdown: who can step in, how quickly an agent can be suspended, and what record will be available afterward to explain what happened.
Controls put in place early give companies the confidence to let agents work independently. Accountability becomes part of how autonomy scales.
Agent autonomy only works when someone owns it
AI agents will soon handle far more work than companies are comfortable handing them today. That comfort will grow once a business can say which agent is acting and where its authority stops.
Agents may eventually feel like coworkers in almost every practical sense, even if the law never treats them that way. Once they can make decisions on a company’s behalf, they need the same clarity around ownership and responsibility that companies already expect from everyone else.

Terence Kwok is the Founder of Humanity, an organization dedicated to rebuilding trust on the internet. He is a visionary technology entrepreneur from Hong Kong and the founder of one of Asia’s first unicorns. With expertise in blockchain, Web3, and technology integration, Kwok’s mission goes beyond technological advancement. Recognized for his insightful vision, Kwok advocates for change that challenges conventions.
Editor’s note: This contributed article has been lightly edited for TNGlobal style and clarity. The views and arguments expressed remain those of the author.
Share your perspective: TNGlobal welcomes contributed insights and expert commentary from across Asia’s technology and innovation ecosystem. Submit a contribution for editorial consideration, or explore more conversations in our TNGlobal INSIDER and TNGlobal Q&A and Interviews archives.
Featured image: Aideal Hwa on Unsplash

