Skip to content
AI Governance

Agentic AI Governance: Who's Accountable When an AI Agent Makes a Bad Call?

Eric Anderson
Eric Anderson

The shift from generating text to taking action

A chatbot that gives bad advice is a quality problem. An AI agent that autonomously sends an email, modifies a record, approves a transaction, or executes a workflow step is a different category of risk entirely — because the harm isn't limited to what was said, it's whatever the action actually did. As organizations move from AI that drafts to AI that acts, the governance question changes from "was the output accurate" to "who is accountable for what the system did, and can that action be traced, reviewed, and reversed."

Four accountability questions every agentic AI deployment needs answered before launch

1. What is this agent actually authorized to do, and who set that boundary?

Permission scope should be explicit and as narrow as the task requires — an agent authorized to draft a customer email is a different risk profile than one authorized to send it without review. Vague or overly broad authorization is the single most common root cause when an agentic deployment goes wrong.

2. Is there a human in the loop, and at which step?

"Human in the loop" means something different depending on whether the human reviews before the action, is notified after it, or isn't involved at all for low-risk, reversible actions. All three can be appropriate — but the choice should be a deliberate governance decision, not a default left to however the tool shipped.

3. Is there an audit trail that would hold up to scrutiny?

When something goes wrong, the first question is what the agent actually did and why. That requires logging the agent's reasoning or decision inputs, not just the final action — a log that only shows "email sent" doesn't answer why it was sent to that recipient with that content.

4. What does the vendor's contract actually say about liability?

Standard SaaS terms were written for software that doesn't take autonomous action on an organization's behalf. Before deploying an agent that touches customer data, financial systems, or external communications, the contract's liability, indemnification, and error-correction terms deserve the same scrutiny as the technology itself — and in most current AI vendor agreements, they haven't caught up to what the product now does.

Governance has to precede capability, not follow it

The organizations getting this right are defining the permission boundaries, review points, and contract terms before broad deployment — not after an agent has already taken an action nobody planned for. This is a governance and vendor-contract review, not a purely technical one, and it's the kind of assessment MALA runs as part of AI infrastructure advisory. Talk to an advisor before your first agentic deployment goes into production, not after.

Share this post