Mission Intelligence Systems

The Four A's · Authority

Governing Agentic AI

How to set decision rights and guardrails for AI that acts on its own.

AI has crossed a line that changes the governance question. Systems no longer only recommend; they plan, decide, and act. The authority to govern software that takes its own actions is not yet defined in most organizations, and the gap is widening faster than the technology.

Research Foundation

  • Government and institutional research (NIST)
  • AI and governance research (Gartner)
  • Organizational and agency theory
  • Enterprise transformation field experience
  • The Builders Build Framework

Key Takeaways

  • Gartner projects that 40 percent of enterprise applications will incorporate task-specific AI agents by the end of 2026, up from under 5 percent in 2025, yet fewer than a quarter of executives can see which agents interact within their environment.
  • The NIST AI Risk Management Framework (2023) provides the Govern, Map, Measure, Manage functions, but it does not differentiate systems by their degree of autonomy, leaving a governance gap for agents that act on their own.
  • Agentic AI is, structurally, a principal-agent problem. The Four A's locate the answer in Authority: deciding in advance who is accountable for what an autonomous system does, and what it is permitted to do without a human.

The capability arrived before the authority

Through 2025 and 2026, agentic systems moved from demonstrations to production. Gartner projects that by the end of 2026, 40 percent of enterprise applications will include task-specific agents, from under 5 percent a year earlier. NIST, which published the AI Risk Management Framework in 2023, opened a formal request for information on AI agent security in early 2026 and launched an AI Agent Standards Initiative, an acknowledgment that existing frameworks were built for AI that advises, not AI that acts. The result in most enterprises is a capability operating ahead of the decision rights meant to govern it.

This is an old governance problem in a new form

The theory here is not new. Jensen and Meckling formalized the principal-agent problem: when a principal delegates action to an agent whose behavior it cannot fully observe, it must design incentives, monitoring, and limits, or bear the cost of the agent acting against its interest. An autonomous AI agent is precisely such an agent, minus the human judgment that normally fills the gaps. Herbert Simon's work on administrative behavior established that organizations function by defining who may decide what, at what level, with what information. Agentic AI forces that definition to be made explicit, because the system will act on whatever authority it is, or is not, given.

You cannot delegate authority to a system and retain accountability for its actions unless you decided, in advance, exactly where that authority ends.

The Four A's reading

The research and standards establish the problem. The Four A's of Organizational Readiness provide the executive lens, and this is squarely an Authority question. Authority asks who decides what, at what level, with what information. For an agent, the board must decide which actions it may take autonomously, which require a human in the loop, who owns the outcome when it acts, and how its authority is bounded and revoked. Where those decision rights are undefined, the agent inherits ambiguity, and ambiguity at machine speed becomes risk at machine scale. Alignment matters too, because the agent optimizes whatever objective it is given, and Adaptability matters, because governance must learn as the agents do. But the first move is Authority.

Evidence matrix

ClaimResearchField evidenceFour A's
Agents are scaling faster than oversightGartner (2025-2026); NIST CAISI (2026)Federal AI governanceAuthority
Delegated action needs defined accountabilityJensen & Meckling (1976); Simon (1947)Decision-rights redesignAuthority
Existing frameworks ignore degree of autonomyNIST AI RMF (2023)Ungoverned agent deploymentsAuthority

What boards should do

Before agents scale, define their authority explicitly. For each agent, decide the actions it may take without a human, the thresholds that require escalation, the named owner accountable for its outcomes, and the mechanism to bound and revoke its authority. Map the NIST Govern function onto degree of autonomy rather than treating all AI alike. The technology will keep moving. The governance question is not technical. It is a decision about authority, and it is the board's to make.

DF

About the Author

Dan Flynn

Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build

Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and produced a documented 1,033% improvement in delivery velocity by changing organizational conditions: not people.

His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.