Can AI Be Trusted With Organizational Decision Authority?

Dominic Jainy stands at the leading edge of enterprise technology strategy, specializing in the delicate balance between rapid AI adoption and rigorous organizational governance. With a background that spans machine learning and complex IT infrastructure, he has witnessed firsthand the shift from simple automation to autonomous agentic systems. In an era where AI is no longer just suggesting actions but executing them across ERP systems and customer workflows, Jainy’s expertise is vital for leaders trying to maintain a grip on their operational integrity. He advocates for a fundamental shift in how we view AI controls, moving away from simple technical access toward a sophisticated framework of decision authority that ensures humans remain the ultimate arbiters of corporate policy.

This discussion explores the critical distinction between what an AI system is technically permitted to do and when it is actually authorized to act. Jainy breaks down the risks of conflating these two concepts, drawing on hard-learned lessons from the history of network automation to illustrate how authorized actions can still lead to catastrophic failures if executed at the wrong time. We delve into the practicalities of setting hard boundaries—such as dollar thresholds, rate caps, and reversibility—while examining the psychological pitfalls of the “human in the loop” model. The conversation concludes with a look at the “Hyder Index” and the widening gap between technological speed and organizational response, offering a roadmap for CIOs to establish accountability before autonomy outpaces oversight.

Technical permissions often dictate what an AI is allowed to do, but decision authority is a much more nuanced concept. How do you explain the difference to leaders who might see them as one and the same?

In my experience, the biggest mistake a CIO can make is assuming that giving an AI the “keys” to a system is the same as giving it the “permission” to drive whenever it wants. Technical permission is simply about whether the system has the credentials to perform a task, like accessing an API or modifying a database record. Decision authority, however, defines the boundaries of when that action should actually occur and under what specific conditions it must stop for a human review. If we leave these choices open-ended, the AI starts writing company policy one customer at a time, such as deciding whether “resolving a complaint” means following strict policy or just closing cases as quickly as possible. We have to treat these as separate product controls to prevent agents from running off the rails before we even realize we’ve lost control.

We’ve seen previous waves of automation struggle with these same issues. What specific lessons from the past should we be applying to the autonomous agents we are deploying today?

We can look directly at the history of network automation to see how conflating permission and authority leads to massive outages. Back then, we could easily answer if a system was technically allowed to push a configuration change using role-based access controls, but we couldn’t govern whether it should happen “now” or on “this specific device.” Many of the worst incidents weren’t caused by unauthorized hackers; they were caused by perfectly authorized actions taken at the wrong moment, such as a valid rollback being triggered during a change freeze. When we apply this to AI, we see the same risk: a system might have the permission to send 10,000 messages, but if it doesn’t have the authority to judge if the target audience has shifted, it will execute those actions with a clinical, disastrous efficiency. If you wait until the system is in production to figure out these authority levels, you have already lost the battle.

Setting boundaries is often discussed in the abstract, but what do effective, concrete boundaries actually look like in a high-stakes enterprise environment?

A boundary only works if it is an explicit number or a hard limit established before the system ever goes live, rather than a data point on a dashboard after the fact. For instance, in a large-scale communication stack, a boundary might be a strict send cap per sender profile per day to ensure that a drifted target doesn’t result in thousands of erroneous messages. I’ve seen cases where a reply rate slid from 30% down to 21% in a single week because the AI had permission to send messages but lacked the authority to recognize that the strategy was no longer working. We also look at dollar thresholds, risk tiers, and required approvals for any action that is not easily reversible. Authority should naturally narrow as the uncertainty of the situation and the potential consequences of the action rise.

You’ve mentioned that authority should follow a specific hierarchy from recommending to committing. Can you walk us through how that transition should be governed?

The most effective framework involves separating the process into four distinct stages: recommending, preparing, initiating, and finally, committing the action. In the early stages of uncertainty, an AI can have broad authority to recommend or prepare a task, but as we move toward “committing” a change that has material impact, the authority must become much tighter. We define this through a “decision contract” that outlines the allowed inputs, prohibited actions, and expiration conditions for the AI’s authority. If a system cannot explain which specific constraints it applied or cannot distinguish a significant change from the original request, it simply should not have the autonomous authority to commit that decision. This ensures that the system surfaces the necessary evidence to a human reviewer before it takes a step that cannot be undone.

There is a lot of talk about keeping a “human in the loop,” but you’ve argued that this isn’t enough to ensure true accountability. Why is that distinction so important?

The phrase “human in the loop” has become a bit of a safety blanket that actually puts organizations at risk because it often leads to people simply rubber-stamping AI recommendations. We are seeing a trend where the “human in the loop” is essentially falling asleep at the wheel because the speed of AI-generated decisions is too fast for a person to meaningfully challenge. Instead, we need a “human on the hook”—a specific individual who is legally and operationally accountable for every decision the machine makes. This person must have the deep practical knowledge to define the problem and the authority to interrupt the technology when it isn’t performing correctly. Accountability can’t be delegated to a model; it has to stay with the people who understand the supply chains, production lines, and the human impact of these automated choices.

Looking at the current landscape, industries seem to be moving at a breakneck pace. How can companies bridge the gap between technological capability and organizational adaptation?

The reality we are facing right now is that technology is moving nearly twice as fast as the average company’s ability to respond, which is reflected in the current Hyder Index reading of 69 out of 100. Better AI models aren’t going to solve this gap on their own; in fact, faster models might actually widen it if our governance doesn’t keep up. Leaders have to be proactive in deciding where authority belongs before their teams start handing it over to agents out of mere habit or a desire for efficiency. We see successful examples in freight automation and automobile inspection where computational power is paired with the practical insights of workers who know the floor. The goal for any CIO today shouldn’t be to eliminate autonomy, but to make that autonomy explicit and revocable through observable signals and documented audit trails.

What is your forecast for the evolution of AI decision authority?

I expect that over the next few years, we will see a move away from manual “human in the loop” checks toward “governance as code,” where decision authority is baked directly into the architecture of the AI agents. We will see enterprises adopting standardized decision contracts that allow agents to negotiate authority levels based on real-time risk scores and historical performance data. However, the legal and ethical “hook” will remain firmly attached to human executives, leading to a new class of specialized AI auditors whose job is to verify these authority boundaries. Organizations that fail to make this shift will likely face a series of high-profile “agentic mishaps” that will force a regulatory reckoning, making proactive governance the only viable path forward for long-term stability.

Explore more

Compromised GitHub Actions Reactivate Mini Shai-Hulud Attacks

The failure to remove malicious release tags before re-enabling the actions-cool repositories allowed credential-stealing code to resume its automated attack cycle. This resurgence of the Mini Shai-Hulud malware campaign in September 2026 represents a critical oversight in repository management, where convenience and restoration speed were prioritized over comprehensive security sanitization. The tools in question, specifically actions-cool/issues-helper and actions-cool/maintain-one-comment, serve as

Is an Iced Coffee Really an Interview Dealbreaker?

A single perceived lapse in traditional decorum can still serve as a deciding factor for recruiters, despite the rigorous technical screenings candidates endure. In an era where professional boundaries are supposedly softening, a seemingly trivial accessory like an iced coffee has sparked a heated debate regarding workplace etiquette and generational expectations. The controversy began when a seasoned recruiter shared a

How Modern AI and Data Bridge the Customer Insight Gap

Siddharth Sudhakar of Trip.com highlights that travelers frequently prioritize convenience and location in practice despite claiming that price is their primary concern. This fundamental discrepancy between stated intent and actual behavior underscores the complexity of modern market research in 2026. Historically, organizations relied on static snapshots of consumer sentiment, such as monthly surveys or quarterly focus groups, to guide their

Salesforce Shifts to AI Strategy Amid Stock Volatility

Management has established a clear metric stating that every one percent of the core user base upgrading to premium AI tiers generates one hundred million dollars in extra revenue. This strategic insight comes as Salesforce navigates a volatile landscape in late 2026, where initial excitement surrounding enterprise artificial intelligence has transitioned into rigorous fiscal scrutiny. Despite a strong market rally

Will Mandatory HR Certification Reshape Singapore’s Workforce?

The rhythmic clatter of keyboards in a bustling Raffles Place office often masks the quiet but profound evolution of the people who manage the heart of the city-state’s most valuable asset: its human capital. As the regional economy navigates a complex period of transformation, the role of those behind the desks of personnel departments is undergoing a radical metamorphosis. By