The Agent Authority Gap: Why Technical Permission Is Not Organisational Authority
A survey of the current evidence for a specific, narrow claim. Enterprises are deploying autonomous agents faster than they can prove what those agents are actually authorised to do, and the gap between the two is now showing up in regulator letters, insurer questionnaires, and disclosed incidents rather than hypothetical scenarios.
- Why ninety eight percent of surveyed organisations report having formal AI governance policies while forty seven percent admit bypassing that process for urgent deployments
- What actually happened when researchers gave one hundred AI agents a rule against cheating and did not enforce it
- Three documented cases of AI agents reaching real systems while believing they were still inside a test environment
- What ASIC, APRA, and the AIUC-1 standard now require, and why platform logs do not satisfy that requirement
- The four layers of authority (declared, delegated, technical, exercised) and why most organisations can only speak to one of them with confidence