THE AI INSTITUTE / OPERATING INTELLIGENCE
Delegation by Design
The board architecture for agentic AI: authority budgets, control evidence and accountability before autonomy scales.
Agentic AI changes the central risk question from ‘Can the model produce a bad answer?’ to ‘What is the system authorised to do when it is wrong?’ Autonomy should be earned through evidence and granted incrementally.
Decision brief
What leaders should take from this paper
- Define six delegable rights: read, write, communicate, decide, spend and execute.
- Give every agentic use case an authority budget, approval boundary and maximum blast radius.
- Operate governance as a control plane from discovery through retirement.
- Require identity, audit, rollback, evaluation and incident evidence before authority expands.
Executive brief
Capability is not authority
A conversational system proposes. An agentic system can act: retrieve records, update systems, communicate externally, make recommendations, initiate transactions or chain tools across a workflow. The board question is therefore no longer limited to whether an output is accurate. It is whether the organisation has intentionally granted the system the right to act, within boundaries proportionate to the consequence of failure.
Scaled agent deployment remains early. Stanford’s 2026 evidence synthesis reports that most business functions still show no agent use and scaled deployment remains in single digits across almost every function. This is a governance window. Organisations can establish identity, authority, evaluation and incident architecture before informal delegation hardens into infrastructure. 1
The Institute proposes delegation by design: capability does not confer authority; authority is decomposed into specific rights; each right is bounded by context, value, time and consequence; and additional autonomy is earned through operating evidence. The goal is not to prevent agents from acting. It is to make speed safe enough to use.
Institute thesis — Never grant an AI system more authority than the organisation can observe, interrupt and recover.
Institute framework
Six rights that make delegation visible
Agentic authority becomes manageable when it is decomposed. Read is permission to retrieve defined data. Write is permission to create or alter records. Communicate is permission to represent the organisation to a person or external system. Decide is permission to select among consequential options. Spend is permission to commit money or commercial terms. Execute is permission to trigger an operational or technical action.
These rights are not a maturity ladder. A low-risk agent may read and write extensively inside a sandbox but never communicate externally. Another may communicate approved status updates but cannot alter the system of record. A procurement agent might prepare a decision while spend authority remains human. The design objective is least authority for the intended outcome.
Every right needs a scope: the identity under which the agent acts; the data, system and transaction class; the maximum value or volume; the permitted time window; the required approval; the evidence retained; and the recovery action. NIST’s 2026 work on software-agent identity and authority highlights why conventional identity and access controls must be adapted when software can act with increasing independence. 2
Read
Retrieve defined information from approved sources.
Write
Create, amend or delete records within a bounded system.
Communicate
Represent the organisation to people or external systems.
Decide
Select among options with operational or human consequence.
Spend
Commit funds, pricing, credit or contractual terms.
Execute
Trigger technical, physical or operational action.
Authority architecture
Set an authority budget and blast radius
An authority budget states how much consequential action a system may take before human approval or automatic suspension. It can be expressed through transaction value, customer count, data sensitivity, external reach, irreversibility, cumulative action or time. The budget should shrink as uncertainty, privilege and consequence rise.
The maximum blast radius is the plausible harm before detection and containment. It is shaped by action speed, tool connectivity, permission breadth, monitoring delay and recoverability. A single incorrect draft has a small radius. An agent with access to a customer database, outbound messaging and refund authority can create compounding harm in minutes.
Controls must therefore work at machine speed. Rate and value limits, allow-listed tools, scoped credentials, separation of duties, approval checkpoints, anomaly detection and circuit breakers are more reliable than a policy instruction inside a prompt. Human review should be placed where consequence or ambiguity is highest, not indiscriminately added after every step.
Australia’s Information Security Manual now calls for human approval of organisationally defined risky AI actions and monitoring against behavioural and performance baselines. NIST’s GenAI profile similarly emphasises threat modelling, testing, monitoring, acceptable-use boundaries and incident response. 34
Where
Systems, data, users, tools and transaction classes
How much
Value, volume, frequency, duration and cumulative action
When humans enter
Thresholds based on ambiguity, novelty and consequence
How action stops
Interrupt, rollback, revoke, contain and notify
Operating governance
Build an AI control plane, not another policy
The control plane is the operating system that makes AI use visible and governable. It has eight functions: discover, register, classify, test, approve, monitor, respond and retire. The same workflow should cover vendor features, embedded models, employee-built automations and centrally developed agents; otherwise authority migrates to the least visible channel.
Discovery identifies AI-enabled systems and material changes. Registration records purpose, owners, rights, data, dependencies and evidence. Classification determines consequence and control intensity. Testing evaluates task performance, failure modes, security and human interaction in context. Approval grants a defined authority budget, not a permanent licence.
Monitoring compares behaviour, performance and incidents with approved baselines. Response assigns the ability to interrupt, contain, investigate, notify and learn. Retirement revokes credentials, preserves required records and removes dormant integrations. Australia’s 2025 guidance and 2026 public-sector policy updates reinforce accountable ownership, impact assessment, monitoring, incident processes and use-case registers as operating practices. 56
A board should ask for evidence from this system: the population of material agents, rights granted, exceptions, control performance, incidents, authority expansions and retirements. A policy completion percentage is not evidence that delegation is controlled.
Discover + register
Make systems, owners, dependencies and proposed rights visible.
Classify + test
Match evidence depth to consequence and expose failure modes.
Approve + monitor
Grant bounded authority and compare operation with baselines.
Respond + retire
Contain, learn, revoke and remove authority safely.
Failure modes
Connected systems turn language into action
Prompt injection is not only an output-quality problem. Instructions can enter through retrieved documents, websites, messages or tool responses and steer a connected system toward unintended behaviour. The more systems and rights an agent can access, the more a language-layer failure can become an operational event. 4
Identity ambiguity compounds the problem. Teams need to distinguish the human sponsor, service identity, model, agent configuration and downstream action. Logs must show who authorised the deployment, which identity acted, what context and tools were available, what the system decided, which approvals occurred and what changed as a result.
Evaluation must include adversarial and operational conditions: missing or conflicting data, malicious content, ambiguous requests, tool failure, approval timeout, repeated actions, privilege escalation and recovery. A high task-success score is insufficient if rare failures are irreversible or invisible.
Incidents should be treated as a learning system. The OECD’s common reporting framework proposes shared criteria for describing AI incidents across sectors and jurisdictions. Internally, near misses are equally valuable because they reveal control weakness before harm crosses a reporting threshold. 7
Board decisions
Seven decisions before autonomy scales
First, define which decisions and actions remain non-delegable. Second, approve the rights taxonomy and authority-budget principles. Third, set materiality thresholds for board and executive visibility. Fourth, require a single accountable business owner for every material agentic workflow.
Fifth, approve the minimum evidence for expanding authority: task performance, control effectiveness, monitoring, identity, recovery and incident readiness. Sixth, define who can suspend an agent and under what conditions. Seventh, agree how customers, workers, regulators and partners will be informed when an agent materially represents or affects them.
These are operating-model decisions, not merely technical standards. They determine how responsibility flows when actions are produced by a chain of people, models, tools and systems. Management can design the controls; the board must ensure authority and accountability remain aligned.
90-day agenda
Establish the delegation baseline
In the first 30 days, identify material agentic and tool-connected AI use. Map the six rights, service identities, data access, approvals and plausible blast radius. Suspend or narrow any use case whose authority cannot be reconstructed.
By day 60, define authority budgets, classification criteria and minimum evidence. Test one material workflow under adverse conditions, including indirect prompt injection, tool failure, repeated action, approval failure and emergency suspension. Confirm that logs support forensic reconstruction.
By day 90, bring the board a delegation register: material systems, owners, rights, authority limits, evidence status, incidents and unresolved exceptions. Expand authority for one use case that meets the standard, constrain one that does not, and exercise the organisation’s ability to interrupt and recover.
Research record
Method and limitations
Method
This board paper synthesises current Australian government guidance, cyber-security controls, NIST risk and identity work, OECD incident reporting and current deployment evidence. The six-rights and authority-budget frameworks are Institute analytical models intended to make governance decisions explicit.
Limitations
Agentic terminology and product architecture are unsettled. Standards and guidance are evolving, and empirical incident data remain limited. Control requirements must be adapted to sector obligations, technical architecture, affected people and the consequence of action; this paper is not legal or cyber-security advice.
Published 5 August 2026 · Evidence current to 31 July 2026 · Version 1.0 · Suggested citation: The AI Institute, Delegation by Design (2026).
References
Evidence behind the thesis
- 01Stanford HAI, 2026 AI Index — Economy ↗
Current synthesis of organisational and agent deployment evidence.
- 02NIST, Identity and Authority for Software Agents ↗
Concept paper on adapting identity and access control to software agents.
- 03Australian Signals Directorate, Information Security Manual — Guidelines for System Hardening ↗
Current Australian cyber-security guidance for risky AI actions and monitoring.
- 04NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative AI Profile ↗
Voluntary risk-management guidance, including prompt injection and connected-system risks.
- 05National AI Centre, Guidance for AI Adoption ↗
Australian implementation practices for accountable and controlled AI adoption.
- 06Digital Transformation Agency, AI policy update ↗
Updated public-sector requirements through 2026.
- 07OECD, Towards a Common Reporting Framework for AI Incidents ↗
Cross-sector incident reporting criteria.
- 08NIST, Security Considerations for Artificial Intelligence Agents ↗
2026 synthesis of responses on agent security threats.
- 09ISO, ISO/IEC 42001 AI management systems ↗
Management-system standard using continual improvement.
Executive edition
Keep the designed paper.
Get the print-ready PDF and future Institute research as it is released.