The Four A's · Authority
Governing Agentic AI
How to set decision rights and guardrails for AI that acts on its own.
AI has crossed a line that changes the governance question. Systems no longer only recommend; they plan, decide, and act. The authority to govern software that takes its own actions is not yet defined in most organizations, and the gap is widening faster than the technology.
Research Foundation
- Government and institutional research (NIST)
- AI and governance research (Gartner)
- Organizational and agency theory
- Enterprise transformation field experience
- The Builders Build Framework
Key Takeaways
- Gartner projects that 40 percent of enterprise applications will incorporate task-specific AI agents by the end of 2026, up from under 5 percent in 2025, yet fewer than a quarter of executives can see which agents interact within their environment.
- The NIST AI Risk Management Framework (2023) provides the Govern, Map, Measure, Manage functions, but it does not differentiate systems by their degree of autonomy, leaving a governance gap for agents that act on their own.
- Agentic AI is, structurally, a principal-agent problem. The Four A's locate the answer in Authority: deciding in advance who is accountable for what an autonomous system does, and what it is permitted to do without a human.
The capability arrived before the authority
Through 2025 and 2026, agentic systems moved from demonstrations to production. Gartner projects that by the end of 2026, 40 percent of enterprise applications will include task-specific agents, from under 5 percent a year earlier. NIST, which published the AI Risk Management Framework in 2023, opened a formal request for information on AI agent security in early 2026 and launched an AI Agent Standards Initiative, an acknowledgment that existing frameworks were built for AI that advises, not AI that acts. The result in most enterprises is a capability operating ahead of the decision rights meant to govern it.
This is an old governance problem in a new form
The theory here is not new. Jensen and Meckling formalized the principal-agent problem: when a principal delegates action to an agent whose behavior it cannot fully observe, it must design incentives, monitoring, and limits, or bear the cost of the agent acting against its interest. An autonomous AI agent is precisely such an agent, minus the human judgment that normally fills the gaps. Herbert Simon's work on administrative behavior established that organizations function by defining who may decide what, at what level, with what information. Agentic AI forces that definition to be made explicit, because the system will act on whatever authority it is, or is not, given.
You cannot delegate authority to a system and retain accountability for its actions unless you decided, in advance, exactly where that authority ends.
The Four A's reading
The research and standards establish the problem. The Four A's of Organizational Readiness provide the executive lens, and this is squarely an Authority question. Authority asks who decides what, at what level, with what information. For an agent, the board must decide which actions it may take autonomously, which require a human in the loop, who owns the outcome when it acts, and how its authority is bounded and revoked. Where those decision rights are undefined, the agent inherits ambiguity, and ambiguity at machine speed becomes risk at machine scale. Alignment matters too, because the agent optimizes whatever objective it is given, and Adaptability matters, because governance must learn as the agents do. But the first move is Authority.
Evidence matrix
| Claim | Research | Field evidence | Four A's |
|---|---|---|---|
| Agents are scaling faster than oversight | Gartner (2025-2026); NIST CAISI (2026) | Federal AI governance | Authority |
| Delegated action needs defined accountability | Jensen & Meckling (1976); Simon (1947) | Decision-rights redesign | Authority |
| Existing frameworks ignore degree of autonomy | NIST AI RMF (2023) | Ungoverned agent deployments | Authority |
What boards should do
Before agents scale, define their authority explicitly. For each agent, decide the actions it may take without a human, the thresholds that require escalation, the named owner accountable for its outcomes, and the mechanism to bound and revoke its authority. Map the NIST Govern function onto degree of autonomy rather than treating all AI alike. The technology will keep moving. The governance question is not technical. It is a decision about authority, and it is the board's to make.
