By Giedre Malinauskaite
Every employee in a large organisation operates inside an invisible architecture of authority.
A new joiner receives an identity, a role and access rights. A manager may approve spending up to a certain amount, but not beyond it. Sensitive systems are restricted. Important decisions are logged. Exceptions are escalated. Performance is reviewed.
We have spent decades building these mechanisms because employees are not given authority simply because they are capable of exercising it. Authority is deliberately assigned, limited and accountable.
Now enterprises are introducing a new category of workforce capable of analysing information, making decisions, interacting with systems and increasingly taking action on its own: AI agents.
Yet we are often giving them capability before properly defining their authority.
That may become one of the defining management challenges of the agentic AI era.
From AI access to AI authority
The first generation of enterprise generative AI largely answered questions, summarised documents and produced content. A human usually remained responsible for what happened next. Agents change that equation.
An agent can access a customer record, query inventory, initiate a workflow, recommend a supplier or execute a transaction. Increasingly, multiple agents can work together across functions and systems.
The critical question is therefore shifting from what can this AI do? to what is this AI authorised to do?
This distinction already exists everywhere in well-managed organisations. An employee may technically be capable of accessing a database, but their role determines whether they should. A procurement manager may be competent to approve a SAR 10 million purchase, but only have delegated authority for SAR 1 million. AI needs an equivalent architecture.
That means defining an agent’s identity and role, what data it can access, which systems it can act upon, how much financial or operational authority it has, when approval is required and when a decision must be escalated to a human. It also means maintaining a record of what the agent did and who ultimately owns the outcome.
PwC has argued that AI agents require verified identities, defined roles, task-specific permissions and auditable records. The World Economic Forum has similarly proposed authorization profiles defining what individual agents are empowered to do throughout their lifecycle.
The principle is familiar: delegation without accountability is not empowerment. It is loss of control.
Governance should enable autonomy
The answer is not to surround every AI agent with so many controls that autonomy becomes meaningless.
We do not give every employee identical authority. Responsibility expands according to role, experience, context and consequence. AI should operate on a similar principle.
An agent summarising internal research does not require the same controls as one executing purchases, changing operational parameters or interacting autonomously with customers.
Authority should rise progressively with demonstrated reliability, while controls should rise with consequence.
Low-impact actions can be autonomous. Higher consequence decisions can require approval. Defined thresholds can trigger escalation. Unusual behaviour can suspend authority.
This changes the way we should think about AI governance. It is not simply a brake designed to prevent AI from doing the wrong thing. Done properly, governance is what allows organisations to trust AI to do more.
That distinction will matter as agent adoption accelerates. Deloitte’s 2026 research found that only one in five companies currently has a mature governance model for autonomous agents. Gartner predicts that by 2027, 40 percent of enterprises will demote or decommission autonomous agents because governance gaps emerge after deployment.
The organisation itself must evolve
There is a deeper implication. For more than a century, organisations have designed management systems around human actors. Hierarchies, reporting lines, approval matrices, segregation of duties, performance measures and audit systems all assume that people are the entities exercising organisational authority.
That assumption is beginning to change. The enterprise of the future will contain humans, AI agents and networks of agents working across functions and systems. Some will advise. Some will coordinate. Some will execute. Humans may supervise a small number of consequential decisions while agents handle thousands of others autonomously. This does not mean pretending an AI agent is an employee. It means recognising that the architecture of organisational authority must now account for nonhuman actors.
For Saudi Arabia, this is particularly timely. PwC found that 29 percent of organisations in the Kingdom already use AI to coordinate multiple tasks within structured workflows, compared with 20 percent globally. Saudi organisations also outperform global averages in role-based data and AI access controls.
As the Kingdom builds the infrastructure, platforms, talent and applications required for an AI-powered economy, it has an opportunity to help define what the AI native enterprise looks like.
The next frontier is not simply deploying more intelligent agents. It is building organisations capable of giving those agents the right authority, measuring their performance, constraining their actions and keeping humans accountable for the systems they put to work.
For decades, every growing organisation has eventually had to answer a fundamental management question: who is allowed to decide what?
In the age of AI agents, there is one additional word: who, or what, is allowed to decide what?
The organisations that answer that question well will be the ones ready to move AI from experimentation into the real machinery of the enterprise.
(The author is the Chief Strategy Officer at CNTXT, a Riyadh-based cloud, data, AI and services company.)




