Until recently, AI at work mostly gave advice. A person read the advice and decided. If the advice was wrong, a person still had a chance to catch it.
AI agents change this. An agent does not only suggest a refund. It issues the refund. It does not only draft the supplier email. It sends it. It does not only flag an invoice. It approves or rejects it.
When the AI acts, the moment of human judgment moves. It is no longer only at the point of each decision. Much of it moves to the start, when someone decides what the agent may do.
The decision before the decisions
Before an agent starts work, someone has to answer a few plain questions.
- What is it allowed to do? Which tasks, for which customers, up to what amount?
- What is it not allowed to do? Which cases must always go to a person?
- When must it stop and ask? What signals mean "escalate"?
- Who owns the result? When the agent makes a mistake, which named person answers for it?
- How will we know it is working? What will we check, how often, and who will look?
These questions feel like admin. They are not. They are the most important human decisions in the whole arrangement. An agent will make thousands of decisions inside the limits a person sets once. If the limits are wrong, every one of those decisions carries the error.
What the frameworks say
Regulators have started to describe this responsibility.
Singapore's agentic-AI framework, published by IMDA in May 2026, lists defining permitted use cases among leaders' responsibilities. IMDA presents the framework as guidance. The direction is clear: deciding what an agent may do is a leadership task, not a technical setting.
In Europe, the AI Act goes further for some systems. Article 26(2) requires deployers to give oversight to people with the competence, training and authority to do it. Article 14(4)(b) requires high-risk systems to let the people overseeing them stay aware of automation bias. Both apply to Annex III systems from 2 December 2027.
These rules are context, not a checklist. But they point to the same idea. Oversight is a human skill, and it starts before the system acts.
Why people skip this step
In practice, the limits are often set in a hurry. The supplier has a default setting. The project team wants to go live this month. The pilot went well, so the limits from the pilot are kept for the full rollout.
There is also a quieter reason. Setting limits means admitting the agent will sometimes be wrong. In a meeting full of excitement about a new tool, that can feel negative. So the hard questions are left for later, and later is after the first incident.
What leaders can do
- Make the limits a decision, not a default. A named leader should approve the agent's permitted uses in writing.
- Name an owner for every agent. Not a team, a person. Someone who answers when it goes wrong.
- Set the conditions to stop. Decide in advance which signals pause the agent, and who can restart it.
- Review the limits on a date. Agents and business conditions change. Put a review in the calendar, for example after the first quarter.
- Keep human responsibilities human. Some decisions affect people in ways a person must own. Write them down and keep them out of the agent's reach.
The value of an agent comes from letting it act. The safety of an agent comes from the limits someone set before it did. Both are leadership work.
Sources
- IMDA (20 May 2026). Model AI Governance Framework for Agentic AI, v1.5. PDF.
- Regulation (EU) 2024/1689, Article 14 and Article 26, with dates set by Regulation (EU) 2026/1744. Article 14, Article 26, European Commission.



