How much should AI really be allowed to decide?
AI governance has long been a matter of policies, risk classification and regulatory compliance. But as AI moves beyond generating content and recommendations and starts performing tasks autonomously, the playing field changes. According to Gartner, 33 percent of enterprise software applications are expected to include agentic AI by 2028, up from less than 1 percent in 2024. By the same year, at least 15 percent of day-to-day work decisions are predicted to be made autonomously by AI agents, compared with essentially none in 2024. Organisations therefore need to decide not only how AI may be used, but what it should actually be allowed to do – and when a human needs to step in.

When an AI agent is given access to internal systems, data and tools, it can perform tasks that previously required human action. In marketing, generative AI can move beyond supporting ideation to producing and adapting content for different audiences. In software development, agents can write and test code. In cybersecurity, they can detect anomalies and recommend – or in some cases carry out – actions in response.
This creates a new governance question: where should we draw the line between what AI can do autonomously and what still requires human judgement?
Making a suggestion is one thing. Taking action is another.
During the first wave of generative AI, accountability was relatively straightforward. A model generated an output and a human decided what to do with it.
Agentic AI changes that relationship.
A system that can plan a task, use different tools and execute several steps independently has a very different ability to affect the business. The technical difference between allowing AI to draft a customer email and allowing it to send that email may seem small, but from an accountability perspective it is significant. The same applies to the difference between identifying a security risk and automatically changing a production system in response to it.
The more autonomous a system becomes, the more important it is to define what authority it should actually have.
This is also where AI governance starts to move beyond policy documents and into system architecture. The EU AI Act illustrates this clearly. Under Article 14, high-risk AI systems must be designed so that they can be effectively overseen by humans during use, with built-in capabilities that allow people to understand the system’s output, intervene, interrupt or stop it, and override or disregard its recommendations. Article 26 goes further by requiring organisations deploying such systems to assign human oversight to individuals with the necessary competence, training and authority. In other words, oversight cannot exist only as a principle – someone needs to own it. Permissions, access to data, the tools an agent can use and the actions that require approval all need to be designed into the system from the outset.
AI governance is no longer just a tech issue
This is not an isolated technology question. The same shift is already taking place across organisations, even if the risks look different depending on the function.
For a development team, the question might be which environments a coding agent is allowed to work in and when a human needs to approve changes. In cybersecurity, it could be which actions an AI system is authorised to take when it detects a potential threat. In HR, the line might sit between using AI to compile information and allowing it to influence decisions about people.
Marketing faces its own version of the same challenge. Generative AI is already being used for text, images, video, personalisation and campaign optimisation. As production becomes faster and more automated, it also becomes less realistic for every individual output to go through the same manual review process as before.
That does not make human oversight less important. It does mean organisations need to become much more precise about where it actually matters.
Humans can’t review everything
“Human-in-the-loop” has become a common principle for responsible AI. It makes sense as a starting point, but it says relatively little about how an organisation should actually operate.
If every step in an automated process requires human approval, much of the value of automation quickly disappears. If there are too few control points, on the other hand, problems may only be discovered after the system has already acted.
An agent that compiles information carries a different level of risk from one that can alter customer data. AI-generated material for internal use does not necessarily require the same controls as communications published externally under the company’s brand. A system that recommends an action needs different governance from one that can execute that action itself.
Control points therefore need to reflect what the system has access to, the potential consequences if something goes wrong, and how easily an action can be detected, stopped and reversed.
The goal is not maximum human control. It is the right control at the right time.
A policy can’t stop an AI agent
This also changes who needs to be involved when organisations build and scale AI.
Legal teams need to interpret regulation and requirements, including the human oversight obligations set out in Articles 14 and 26 of the EU AI Act. Security teams need to understand the threat landscape and the technical safeguards required. Software development and architecture teams need to translate those requirements into actual systems and permissions. And the business needs to understand its processes well enough to determine which decisions can be automated and where human judgement remains essential.
No single function can solve this alone.
That is also why AI governance risks falling short when it is treated as a standalone compliance project. A policy can state that sensitive decisions require human oversight, but someone still needs to define what that means in a particular workflow – and build the system so that the control actually happens.
As AI becomes part of an organisation’s infrastructure, governance needs to become part of the same design process.
Clearer boundaries can give AI greater freedom
For many organisations, the next challenge is not finding more use cases for AI. The experiments are already happening, and the technology is rapidly becoming both more capable and more deeply integrated into the tools we use every day. The harder question is which solutions can successfully move from experimentation into real-world operations – and that transition is far from guaranteed. Gartner predicts that more than 40 percent of agentic AI projects will be cancelled by the end of 2027, often because of escalating costs, unclear business value and governance challenges.
This is where AI, cybersecurity, software development and business understanding come together. To scale an AI solution, organisations need to understand both the value it creates and the consequences its actions may have. The right restrictions, permissions and control points then need to be built into the solution.
That does not necessarily mean less automation. On the contrary, clear mandates can make it possible to give AI greater autonomy because the organisation knows where the boundaries are and what should happen when something deviates from the expected path.
As AI moves from helping people do their jobs to performing parts of those jobs itself, governance will increasingly become less about general principles and more about concrete decisions within individual systems and processes.
The question is no longer simply whether an organisation is ready to use AI.
It is how much freedom it is ready to give it.
Ready to give AI greater autonomy?
At HiQ, we help organisations take AI from ideas and experiments to solutions that work in real-world operations. By combining expertise in AI, software development, cybersecurity and business development, we help identify the right use cases, design secure AI and agentic solutions, and build the right control points in from the start.
Want to explore where AI could take on greater responsibility in your organisation – without losing control? Let’s talk.