Urgent.News

What's breaking now, across thousands of outlets.

AI

Why "I approve" can become the most dangerous button in enterprise AI

Autonomous AI demands governance, identity controls, and accountability beyond human approval.

Why "I approve" can become the most dangerous button in enterprise AI

In the world of enterprise AI, the button labeled "I approve" may soon prove to be the most dangerous. At 2 a.m., an automated agent identifies an issue on the network, traces it to a misconfigured policy, and rectifies it—all without alerting anyone. The network resumes its normal function. Upon waking, a human examines the agent's daily report, a summary of all changes made, complete with links to logs, audit trails, reasoning, and the root cause.

Once satisfied, the human moves on. This illustrates the concept of Human-on-the-Loop, where humans review the output of AI agents and make final decisions. However, this approach can become problematic if not properly controlled. In another scenario, at 4 a.m., a DIY-built remediation agent detects a problem, traces it to a misconfigured policy, and makes the necessary fixes.

The network stabilizes, and again, nobody is notified. In the morning, a human reviews the logs and assumes the issue has been resolved, moving on without fully understanding the extent of the agent's actions. The critical difference lies in the lack of transparency in the DIY scenario. The logs only reveal part of the story, failing to disclose the agent's broader changes that were unintended and the decisions behind those changes.

This represents a shift toward Human-on-the-Loop without the necessary safeguards. Organizations are moving too quickly in embracing agentic AI, both in terms of governance and evaluating autonomous systems. The notion of "I approve" is an illusion, as reviewing every action does not automatically create accountability. Humans should focus on evaluating outcomes, ensuring systems operate within their intended boundaries, and providing feedback to improve performance over time.

Approval can become a mere ritual, devoid of meaning. As systems prove reliable and the number of alerts grows, humans may start treating intervention as unnecessary, further eroding accountability. Furthermore, the transition from executing tasks to reading before approving marks a fundamental change in the daily work of professionals.

Attribution is not synonymous with provenance. While logs record what an agent did, they provide little insight into why or what influenced the decision. When issues arise, understanding the reasoning behind the actions becomes crucial. Non-human identities and the evolving network population complicate matters further. AI agents querying systems, making configuration changes, or routing traffic require credentials, policies, guardrails, explainability, and audit trails similar to human operators.

However, most organizations have yet to adapt identity frameworks for AI agents, leading to shadow access and potential security risks. Treating each agent as a principal with bounded permissions, time-limited access, and a clear revocation path, along with comprehensive documentation of allowed actions and reasons, is essential.

Autonomy should not be granted freely; it must be earned through incremental capabilities and strict adherence to established limits.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in AI

More from Monday 24 August →