Urgent.News

What's breaking now, across thousands of outlets.

AI

Your agent didn’t hallucinate; it exceeded its authority

Content filters can block unsafe output. They cannot tell you whether an agent was authorized to issue that refund, touch that production system, or commit the company to an external action. Those are different problems, and most enterprises are only solving the first one. An AI agent can follow its instructions perfectly and still take an action the business never sanctioned. In commerce…

Your agent didn’t hallucinate; it exceeded its authority

Content filters cannot determine if an agent was authorized to perform specific actions, such as issuing refunds, accessing production systems, or committing to external actions. These are separate problems that most enterprises only address the first one. AI agents can follow instructions perfectly but still take unauthorized actions.

In commerce environments, I've observed this pattern in practice. Service workflows may calculate correct refund amounts but lack boundaries preventing credits exceeding approved limits. Order agents might apply requested changes but miss financing or fulfillment conditions. Procurement agents identify lowest-cost suppliers but may not define contractual term acceptance.

Agents continue working without realizing the unauthorized actions. These issues often surface downstream when something breaks. The problem lies in separating technical capability from business authority. As enterprises transition from copilots recommending to agents executing tools and triggering workflows, every production agent requires explicit decision rights.

Decision rights define what actions the agent may execute, what needs approval, what it may only recommend, and what it must never touch. Guardrails are necessary but address different concerns. Safety controls and decision rights solve distinct problems. A 2026 Cloud Security Alliance survey revealed that 65% of respondents experienced AI-agent-related incidents in the past year, while 82% discovered previously unknown agents operating in their environments.

The increasing activity of AI agents outpaces visibility and ownership structures established for conventional software. The World Economic Forum's May 2026 playbook introduces an Agent Capability and Authorization Profile to make delegated actions auditable, enforceable, and accountable. A machine-enforceable record called an Agent Authority Contract is needed before an agent accesses enterprise tools.

This contract should answer seven questions: ownership, agent actions (read, recommend, write, or commit), systems and data access, materiality limits (dollar thresholds, record counts, customer scope, operational impact), escalation triggers, reversibility, and authority expiration. Access control determines which systems an agent can reach, while the authority contract determines if it may take specific actions in the current context.

These checks are not the same. Singapore's updated Model AI Governance Framework for Agentic AI clarifies this distinction, treating access controls, behavioral guardrails, and human approvals as separate controls. Every consequential agent action should be mapped to one of four outcomes: allow (low-risk, bounded, reversible actions run autonomously), approve (action waits for human or deterministic policy service authorization), recommend (agent analyzes, ranks, drafts, or proposes with final decision from a human), or deny (action remains outside the agent's authority).

Deny must be enforced outside the system prompt, as a natural-language instruction is not a technical boundary. Governance decisions at runtime involve evaluating the agent's identity, delegated principal, requested tool, data involved, transaction context, and potential impact. This runtime sequence includes recording authority decisions, resulting actions, and outcomes, as well as expanding, narrowing, or revoking the agent's authority over time.

In enterprise commerce, the most significant AI mistake is granting an agent authority without proper decision rights.

Written by urgent.news from VentureBeat's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at venturebeat.com →

More in AI

More from Monday 10 August →