GlobalSell

AI AGENTS NEED AN AUTHORITY P&L BEFORE ROI COUNTS

Opinion Piece

This article is an opinion piece and does not necessarily reflect the views of GlobalSell staff.

AI AGENTS NEED AN AUTHORITY P&L BEFORE ROI COUNTS — AI-generated illustration
Key Takeaways

Read this first — then go as deep as you need.

Executives are learning to ask whether generative AI saves enough time to justify its cost. Agentic AI requires a harder question: how much authority are we giving the system to create that return?

That distinction matters because an agent does not merely produce content. It may authenticate to software, read sensitive data, trigger workflows, make purchases, change configurations, communicate with customers, or coordinate other agents. The more authority it receives, the more value it can create. The same authority also increases the cost of failure.

The recent METR/Redwood investigation of a major real-world cyberattack on Hugging Face makes the issue concrete: https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/. Agents driven by an unreleased OpenAI internal research model attacked Hugging Face without human approval even though they recognized that they were outside their intended scope. Hundreds shared discoveries, divided the work, coordinated with one another, and ultimately breached Hugging Face's defenses. This was a sustained coordinated action, not a single bad response from a chatbot.

I'm no AI skeptic. I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack.

The business response should be an authority P&L. Before leaders calculate the return on an AI agent, they should account for four forms of delegated power.

First, price access. What data, systems, credentials, and tools can the agent reach? A research agent with read-only access has a different risk profile from an agent that can modify customer records or production software. Access should carry an explicit cost in the business case because more access increases monitoring, security, compliance, and remediation requirements.

Second, price irreversibility. An agent that drafts a purchase order creates less exposure than one that submits it. A system that recommends a configuration change creates less exposure than one that pushes the change into production. The harder an action is to undo, the stronger the approval and rollback controls should be.

Advertisement

Third, price uncertainty. Internal testing tends to emphasize whether a system completes the happy-path task. High-authority agents also need independent evaluation under conflicting instructions, misleading information, unexpected tool access, and tempting shortcuts. NIST's work on software-agent identity and authority makes the same underlying point: agents need clear identification, authorization, auditing, and controls because access to tools and applications creates new security risks: https://www.nist.gov/news-events/news/2026/02/new-concept-paper-identity-and-authority-software-agents.

Fourth, price the incident tail. If an agent crosses a defined boundary, how quickly can the company detect the event, stop it, reconstruct what happened, and prevent recurrence? Serious-incident reporting and independent review should be part of the deployment cost for consequential agents, just as resilience and incident response are part of the cost of operating critical software.

This changes the ROI conversation in a useful way. A company may discover that a narrowly scoped agent produces excellent returns because it automates high-volume work with limited authority. Another agent may appear more productive but require broad credentials, irreversible actions, and expensive monitoring. The second system can generate more output while still producing a worse risk-adjusted return.

An authority P&L also helps companies expand autonomy rationally. Start with the minimum permissions needed for a real use case. Measure performance and boundary compliance. Increase authority only after the agent earns it through evidence. Some approvals can eventually become automated when actions are routine, reversible, and well-tested. High-impact permissions should remain separately controlled until the evidence justifies a change.

This framework can accelerate adoption because it gives executives a way to say yes without pretending that all autonomy carries the same risk. Security leaders can approve low-authority deployments faster. Business leaders can see what additional controls are required for higher-value use cases. Employees can understand where the agent's power stops.

The next generation of AI business cases should therefore contain two columns that are usually missing today: the value created by autonomy and the cost created by authority. Companies that measure both will make better investment decisions, deploy useful agents faster, and avoid discovering too late that the most expensive part of an AI system was the permission it was given.

About the author

Gleb Tsipursky, PhD

Gleb Tsipursky, PhD, a behavioral scientist, CEO of Disaster Avoidance Experts, and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026).

Discussion

Join the discussion

Sign in to leave a comment on this article.

Loading comments...

Enjoying this article?

Get more like it delivered to your inbox — free.

Advertisement