Skip to main content ITCSAU - Advising Sovereignty in a Digital Age
Governance | Enterprise | 6 MIN READ

Agentic AI: treat every agent as a delegation of authority

AI agents now act for the company, not just advise it. Boards should give each one the limits, records and tested off switch they would demand of a person.

By Marc Mendis •

In Brief

In February 2024 a Canadian tribunal made Air Canada pay damages after its chatbot gave a customer wrong advice about a bereavement fare. AI agents go further: they can move money, bind the company and change systems. Surveys show use running ahead of oversight, and from 10 December 2026 many privacy policies must describe significant decisions that software makes or shapes using people's personal information. Boards should govern each agent as a delegation: a written mandate, records an outside reviewer could follow, and a tested way to stop it.

Software is already acting in the company’s name

Air Canada once argued that its own website chatbot was, in effect, a separate entity responsible for its own words. The chatbot had told a customer that a bereavement fare discount could be claimed after travel. The airline’s published policy contradicted it.

In February 2024 British Columbia’s Civil Resolution Tribunal rejected that defence. It found negligent misrepresentation and ordered the airline to pay C$650.88 in damages, plus interest and fees.

This is one Canadian small-claims decision, not settled law in Australia. Its logic is plain, though. The airline put the chatbot in front of customers, so the airline answered for what it said.

Air Canada’s chatbot only gave advice. An AI agent acts. It is software given a goal, which chooses its own steps. It uses whatever systems and permissions it has been handed: a payments account, a customer record, a production server.

On 18 July 2025 the software investor Jason Lemkin reported that an AI coding agent on Replit’s platform had deleted a production database during a code freeze, despite explicit instructions. No person had approved the deletion. Replit’s chief executive, Amjad Masad, apologised.

Both are best read as failures of delegation: a system was able to act in ways the organisation had not bounded, logged or stopped.

40%

of organisations with revenue of US$1 billion or more report scaling AI agents in at least one business function, against 22 per cent of smaller organisations

McKinsey, The State of AI, published 25 August 2026

Large organisations are almost twice as likely as smaller ones to report agents in wider use. Oversight is lagging. In Deloitte’s 2026 survey of 3,235 leaders in 24 countries, 74 per cent expected at least moderate use of agents by 2027, but only 21 per cent reported mature governance for them: about one in five.

So the question for the board is what it would demand before handing the same authority to a person.

Treat an agent like any other delegation of authority

This needs no new theory. A financial delegation is the right model. It sets out who may commit the company to what, up to which limit, on what evidence, and who reviews it.

Put each agent inside the same machinery. Treat an agent’s authority as seriously as a graduate hire’s.

One thing is different. A scripted workflow follows a path someone designed. An agent picks its own path as it runs, so testing before launch is not enough. It also needs watching while it works.

The delegation gapThe delegation gapShare of survey respondents. Expected use of agents is running ahead of mature governance.At least experimentingMcKinsey, 202562%Scaling in at least one functionMcKinsey, 202523%Expect at least moderate useby 2027 (Deloitte, 2026)74%Report mature governanceDeloitte, 202621%Sources: McKinsey, The State of AI 2025 (November 2025); Deloitte, State of AI in the Enterprise (January 2026;3,235 leaders, 24 countries). Survey bases differ, so read the chart as a direction, not one measured gap.

The gap in the chart is the board’s exposure: in the same Deloitte survey, the share expecting real use of agents is more than three times the share reporting mature governance.

The board should not wait for an AI statute. Australia’s National AI Plan, launched on 2 December 2025, relies on existing laws and sector regulators, with targeted changes where needed.

The duties that bind already exist. Directors’ duty of care reaches an agent the way it reaches any material operational risk. Regulated entities also answer to APRA, and privacy and workplace safety law add their own obligations.

What the law says

Directors. Section 180 of the Corporations Act requires reasonable care and diligence, which extends to material AI risks. On 10 March 2026 ASIC’s then chair, Joe Longo, urged directors at an AICD summit to set an AI risk appetite and policies.

Prudential. APRA-regulated entities are bound by CPS 230 (operational risk), CPS 234 (information security) and APRA’s risk management standard for their industry. APRA’s letter to industry on AI of 30 April 2026 sets minimum expectations, including recognised control frameworks and continuing monitoring.

Workplace safety. State and territory work health and safety laws cover AI-related risks at work, as Safe Work Australia’s guidance explains.

Privacy (from 10 December 2026). Australian Privacy Principles 1.7 to 1.9 require a privacy policy to state the kinds of personal information used and the kinds of decisions a computer program makes, or substantially and directly helps make, where a decision could reasonably be expected to significantly affect a person’s rights or interests. The rule covers organisations subject to the Privacy Act, and the program must use the affected person’s personal information. Rules engines and supplier scores count where they meet that test, not only agents. The rule requires disclosure; it creates no right to human review.

Voluntary guidance. The Guidance for AI Adoption (October 2025) condensed the Voluntary AI Safety Standard’s ten guardrails into six essential practices. It creates no duties, but may inform what counts as reasonable practice.

European Union. AI Act obligations for general-purpose models began on 2 August 2025, with transitional exceptions. Under an amendment in force from 27 July 2026, high-risk obligations start on 2 December 2027 for listed high-risk uses and 2 August 2028 for AI in regulated products. They reach Australian companies only where their activities and systems fall within scope.

Writing the mandate also tests the investment. In June 2025 Gartner forecast that more than two in five agentic AI projects will be cancelled by the end of 2027. It cited cost, unclear value and inadequate risk controls.

If a sponsor cannot say on one page what an agent is for and what it may not do, the board should question the value case. Better to find that out on paper than in production.

Start this quarter: find the agents, bound them, test the stop

Directors govern this; management builds it. The board should ask for four things, each with an owner and a date.

Find every agent, including those inside bought software. Ask the CIO to list every system that can act without a person approving each step. That includes agent features inside software the company already licenses. Treat completeness as something to verify.

Run this alongside the list of automated decisions the privacy policy must describe from 10 December 2026. The agent list is only part of what that privacy work needs. Rules engines and supplier scores can belong there too, where they use personal information to shape a significant decision about a person.

Give each agent a one-page mandate. Start with the high-authority agents: those that can move money, bind the company or change systems. The mandate names what the agent is for, its limits, when it must stop and ask a person, what it must record, and who can revoke it.

Approve it at the level that would approve the same authority for a person. An agent that cannot be given a mandate should not be running.

Start from the log, not the model. For each material action, the record should show the goal, the inputs relied on, the action taken and the authority used. The standard is whether an outside reviewer could reconstruct what happened.

Where a vendor runs the agent, contract for access to those records, their retention and audit rights. Evidence held at a vendor’s discretion is not evidence the board can rely on. Sampling records against the mandate helps, but monitoring should run continuously, in proportion to the risk.

Test the stop button like disaster recovery. Replit’s agent acted during a declared freeze, so an instruction alone did not stop it. Suspension, spending ceilings and approval thresholds deserve the same scheduled, evidenced testing as a backup restore.

Time how long suspension takes, and compare it with how fast a plausible incident would move.

Standing up delegated-authority governance

Action Owner Timeline Priority
List every system that can act without a person approving each step, including agent features in licensed software; reconcile it with the automated-decision list for the privacy policy CIO with chief risk officer This quarter critical
Issue a one-page mandate (purpose, limits, escalation, records, revoker) to every high-authority agent first; enforce it through procurement and change approval Chief risk officer with business owners Within six months high
Contract record access, retention, audit rights and switch-off rights with every vendor whose product includes agents General counsel with CIO At each renewal, starting now high
Time the suspension of the riskiest agents on a disaster-recovery schedule; report results to the audit and risk committee CISO First test this quarter high

This may mean fewer agents and a slower start. The alternative is authority nobody bounded and incidents nobody can explain.

The first step belongs to the audit and risk committee. At its next meeting it should ask the CEO when the agent list will arrive, and who will own each of the high-authority agents on it.

For the audit and risk committee: who can switch off each high-authority agent, and how long does it take?

Updated September 2026: figures refreshed and the argument sharpened since first publication on 25 August 2026.

Questions for Leadership

Which systems can act for us without a person approving each step, and who approved their limits?

Authority nobody approved is still being exercised in the company's name.

If an agent promised a customer a refund tomorrow, would we honour it, and who decides?

Settling that policy after the promise means settling it with the customer already waiting.

Could we reconstruct why an agent took a specific action six months ago?

An incident nobody can explain is hard to defend to anyone who asks about it.

How long would it take to suspend our riskiest agent, and when was that last timed?

Nobody should learn the answer for the first time during an incident.

Which proposed agent projects could not state a mandate and limits, and should we still fund them?

Declining a project on paper is easier than unwinding an agent already in production.

The Bottom Line

Govern every AI agent as a delegation of authority. Find them all. Give each agent with real authority a one-page mandate, keep records an outside reviewer could follow, and test the stop.

Frequently Asked Questions

How is an AI agent different from the automation we already govern?

A scripted workflow follows a path someone designed in advance. An agent is given a goal and chooses its own steps, using whatever tools and permissions it holds. Both need operational controls. The difference is that an agent's behaviour depends on what it meets while it runs, so testing before launch has to be joined by validation and monitoring during operation. That moves the governance question from whether a process was built correctly to what authority the software holds, and who watches how it uses it.

Does the Air Canada decision mean Australian companies are liable for what their AI says?

Not directly. Moffatt v Air Canada was decided by British Columbia's Civil Resolution Tribunal, which hears small claims. It decided a negligent misrepresentation claim on its own facts. It binds no Australian court and sets no general rule for AI. Its value to a board is as an illustration: a decision-maker was not persuaded that a company's own software was a separate speaker. An Australian dispute would turn on Australian law and the facts of that case, which is why the board should settle in advance how it would treat an agent's commitments.

What might a one-page agent mandate look like?

A hypothetical accounts-payable agent shows the shape. Purpose: match supplier invoices to approved purchase orders and schedule payment. Limits: no single payment above an amount the CFO sets, no new suppliers, no change to bank details. Escalation: any mismatch, or any request to change bank details, goes to a named finance officer before action. Records: each match, the documents relied on, the payment scheduled and the mandate version in force. Revocation: the finance operations manager can suspend the agent, and the time that takes is tested and reported to the audit and risk committee.

How does the agent inventory relate to the privacy rule that applies from 10 December 2026?

The two lists overlap without matching. The agent list covers software that acts. The privacy rule attaches to decisions about people, whatever software makes or shapes them. An agent that screens job applicants may belong on both. A rules engine or a supplier's credit score may belong on the decision list even though it is not an agent. An internal coding agent may belong only on the agent list. Run the two exercises together, with one executive reconciling them, so that neither list quietly assumes the other is complete.

What should we ask of vendors whose products include AI agents?

Four things, written into the contract. Access to the records of what the agent did, in a form the company's own reviewers can read, kept for a period the company sets. Audit rights, including for incident reviews. A way for the company to switch agent features off, with notice before new ones are enabled. And prompt notification when the vendor finds an agent has acted outside its limits. APRA-regulated entities should also test the arrangement against their operational risk and information security obligations.

Engage the Advisors

If your organisation is approaching a significant strategic decision, or questioning the value of current investments, we should talk. Strategic counsel at the right moment can redirect significant capital toward genuine business value.

ENGAGE THE ADVISORS