white textile on brown wooden table

Who Is Writing the Acceptable-Use Policy for the AI?

As AI shifts from suggesting to acting, governance becomes a question of authority, permissions and who decides what an autonomous system is allowed to do.

Taheera Lovell

7/20/20261 min read

AI governance has mostly been designed around a familiar assumption:

The AI suggests and a human decides.

Agentic AI changes that.

An agent can increasingly be given an objective and then work out how to achieve it - choosing tools, taking actions, checking results and adjusting along the way.

Which means the governance question is no longer only: What is the AI allowed to say?

It is: What is the AI allowed to do?

Access data?

Send an email?

Approve a workflow?

Make a purchase?

Change a record?

Interact with another system?

We already understand this principle with humans.

Employees have spending limits, system permissions and approval thresholds because authority needs boundaries.

But an AI agent may operate inside systems, inherit permissions and take actions on someone's behalf.

So who defines its limits?

IT?

Risk?

The vendor?

The employee configuring it?

Or nobody...in which case the real policy may simply be whatever permissions the technology happens to have.

That is governance by default.

Not ideal.

Agentic AI is ultimately a delegation problem.

The useful question may be surprisingly simple: If this system were a new employee, what authority would we actually be comfortable giving it?

Then build the controls around that answer.

I look widely, connect the dots, and help people build organisations that are harder to surprise.