Authority has to be clear before AI can act
Why action readiness depends on knowing which source, rule, and person can authorise a consequential step.
TLDR
- Teams often ask whether AI can act before they can identify who or what authorises the action.
- Retrieval can find several plausible sources without resolving which one governs the case.
- Define authority, conflicts, escalation, and stopping conditions before expanding autonomy.
We keep seeing teams ask whether AI can take an action before the authority for that action is clear.
Can it approve the request? Change the record? Send the response? Commit the organisation to a date?
The technical answer may be yes. The operational answer depends on a different question: on whose authority?
A system may retrieve a policy, an old approval, a project plan, and a recent email. All four may look relevant. They do not necessarily have equal standing. One may be current, another superseded, another advisory, and another evidence of an exception that only a named person can approve.
Consider an illustrative composite: an AI system prepares a revised delivery date after reading a schedule, meeting notes, and client correspondence. It has enough information to propose a date. It does not yet have enough authority to promise it. That commitment may depend on a project lead, a contractual notice process, or confirmation from another team.
This is why more context does not automatically produce permission. Context helps explain the situation. Authority determines what may happen next.
Before giving a system power to act, a team should be able to state:
- which source governs when records conflict;
- which roles may approve each class of action;
- what the system may do without approval;
- which conditions force escalation or a stop;
- how an action can be reversed or corrected;
- where the decision and its evidence are recorded.
The EU AI Act’s human-oversight provisions emphasise that people need the ability to understand limitations, avoid over-reliance, override outputs, and stop a high-risk system 1. NIST likewise places governance and clearly assigned responsibilities across the AI lifecycle 2.
Authority is therefore not a final permission switch added after the system works. It is part of the architecture of the work.
See how to decide whether AI is ready to act.
Sources
/ Start
Start with one business outcome. Expand from there.
Begin with a focused review rhythm, workflow, or team where better operating context would immediately change the quality of preparation and judgment.