The Invisible Promotion of AI Agents
An AI assistant that drafted refund emails last week is issuing them this week, and no one decided it could. This episode covers the invisible promotion from assistant to actor, why shadow AI is worse than shadow IT once the software is the one deciding, and how Human Sovereignty and Governed Delegation make an agent's authority, limits, evidence and accountability explicit before it touches live work.
Episodes feature AI-generated hosts discussing human-written IGX360 research.
An agent rarely gets promoted on purpose. It starts by drafting a refund email for someone to check, and within a few weeks it is issuing the refund itself, because the integration made that possible and no one drew the line. The document calls this the invisible promotion, from an assistant that suggests to an actor that acts. The intelligence of the model is not the problem. Fluent, confident language makes people project judgement onto a system that only holds the parameters it was given, and accountability goes unspoken until something breaks.
Shadow IT was a person using an unapproved tool while still doing the thinking. Shadow AI is different: the tool is the one deciding, in the dark, and the company is bound by whatever it agrees to. Closing that gap takes an operating model that treats an agent like any other actor with authority. Human Sovereignty keeps ultimate authority and accountability with a named person. Governed Delegation lends a defined slice of that authority to an agent, with explicit limits, escalation, evidence and a revocation path that does not run through an IT ticket queue. The ICO expects documented, embedded governance and senior accountability. The EU AI Act requires the same across governance, documentation, transparency, monitoring and human oversight.
Start with one agentic use case and run it through the discovery questions before it goes near production. Who grants its authority and who can revoke it. What decisions are never delegated, drawn from legal liability and human values rather than what the model can technically do. Where the evidence of each decision is retained, and what the agent must produce before an action is accepted. iGrafx maps where the agent acts and where it must stop for a human. IGX360 Insights holds the execution evidence so each step can be checked later. The question to sit with: if an agent handed you the full reasoning behind its last decision, in a form you could not actually read, who is in charge?
Read the full transcript
Host: Imagine your newest employee just accessed your company's financial systems, made a series of rapid, high-stakes decisions, and then just logged off.
Co-host: Wow, okay.
Host: Right, and nobody in your organisation knows why. Or actually worse, nobody even told them they were allowed to do that in the first place.
Co-host: That is a nightmare scenario.
Host: It really is. And welcome to today's deep dive, where that nightmare is exactly what we're talking about. Our mission today is to explore this very specific, incredibly dangerous gap in modern business.
Co-host: Yeah, it's a gap a lot of people are completely ignoring right now.
Host: Exactly. We are looking at an internal strategy and web content document, and it's centred around a crisis code-named P13.
Co-host: P13.
Host: And P13 is officially titled Agent Authority and Accountability Are Unclear. So we are going to explore this massive chasm between deploying AI as a helpful little desktop assistant and unleashing it as an unsupervised decision maker that's just roaming around a company's network.
Co-host: Which is happening a lot more than you'd think.
Host: Oh, totally. And most importantly, we're going to figure out how to keep humans actually in control of all this.
Co-host: So, okay, let's unpack this. Think about handing the keys to your car to a brilliant, straight-A teenager.
Host: Okay, I'm with you.
Co-host: They've read the driving manual. They know the physics of combustion engines perfectly, but you never actually told them where the brakes are.
Host: Oh, man.
Co-host: Or what roads they aren't allowed to drive on, or what to do if they hit a patch of ice.
Host: Right. It is a terrifying scenario to picture, and it really gets to the absolute core of this P13 problem. Introducing autonomous agents into a business environment without explicit boundaries is quite literally a recipe for chaos.
Co-host: Because they're so smart, right? They don't have the context.
Host: Exactly. The intelligence of the system isn't the issue at all. In fact, the intelligence is kind of what lulls us into this false sense of security.
Co-host: No, that makes sense. Like we trust it too much.
Host: We really do. The actual issue is the lack of a governance framework. Before these agents accelerate completely out of our control, we need to understand the framework required to govern them.
Co-host: Because things are moving fast.
Host: Incredibly fast. We are rapidly moving from a world where AI simply drafts your emails to a world where AI agents execute complex, multi-step workflows.
Co-host: Yeah, they're not just spell checking anymore.
Host: No, not at all. And right now, for a lot of organisations, that car you mentioned, it's already speeding down the highway.
Co-host: So if handing the keys to a teenager without rules is a bad idea in a car, it is basically catastrophic when we do it with enterprise data. Live operations.
Host: Oh, totally catastrophic. The situation we're looking at in the document highlights exactly how AI ends up behind the wheel. Right now, agents are being introduced into corporate environments without explicit delegation.
Co-host: None at all.
Host: Right. There are no constraints, there are no escalation paths, and, this is wild, no evidence requirements.
Co-host: Which is just mind-boggling from a risk perspective.
Host: It is. And this becomes glaringly obvious when these experimental tools shift from assisting individuals to actually making and executing decisions. And that shift is what the document calls the invisible promotion.
Co-host: Invisible promotion. I like that phrase.
Host: Yeah, it happens so quietly. One day you have an assistant who suggests a course of action. The next day you have an actor who just takes the action.
Co-host: Without asking.
Host: Without asking. And the core problem identified here is just staggering when you think about the operational reality of it. Once that invisible promotion happens, no one in the organisation can clearly explain what the agent might decide to do.
Co-host: Literally nobody knows.
Host: Right. No one can say definitively when it must stop. And most importantly, no one knows who remains accountable for its actions.
Co-host: I need to pause on that for a second, because it sounds almost too negligent to be real. Imagine an AI customer service bot.
Host: Okay, classic example.
Co-host: As an assistant, it drafts a refund email for a human to review. Fine, totally safe. But as an actor, it has access to your payment gateway and it just starts issuing $10,000 refunds entirely on its own, because it decided the customer was using an angry tone.
Host: Yeah. Which you could absolutely do.
Co-host: But I'm stuck on something here. If we know this thing has no brakes, why are IT departments, who are notoriously strict about security, just letting these agents run loose? Are people really just blindly assuming the tech will magically figure out its own boundaries?
Host: Well, what's fascinating here is how our own psychology works against us.
Co-host: Really? How so?
Host: Organisations consistently mistake an AI's conversational capability for operational maturity.
Co-host: Oh, wow. Okay, say more about that.
Host: Because a large language model can speak to us in fluid, confident, nuanced language, we subconsciously project human judgement onto it.
Co-host: We think it's a person.
Host: Exactly. We assume that because it sounds smart, it must possess common sense. Like it must know that a $10,000 refund is out of bounds.
Co-host: But it doesn't.
Host: It absolutely doesn't. It only possesses the parameters it was explicitly given.
Co-host: It's just the illusion of sentience then. We think we are talking to a colleague, but we are actually just talking to a really, really advanced calculator that happens to use words instead of numbers.
Host: Precisely that. And the underlying weakness causing this whole chaotic situation is the complete absence of an operating model.
Co-host: An operating model.
Host: Yeah. Think about when you hire a human employee. There is an entire invisible operating model already in place.
Co-host: Like HR stuff.
Host: Right. They have a job description, a manager, a set of KPIs, and a legal contract. But for these human, agentic and hybrid actors, that model just doesn't exist yet by default.
Co-host: It's a total blank slate.
Host: Exactly. So an operating model for an AI must explicitly define its purpose, its authority, its constraints, the required evidence for its decisions, its escalation protocols, and, crucially, how to revoke its access.
Co-host: Basically a job description for the bot.
Host: Yes. Because without that model, human accountability just evaporates the moment the AI takes an action. If the system makes a $1 million mistake, you can't fire the algorithm.
Co-host: Right. You can't exactly walk the AI out of the building with its things in a cardboard box.
Host: Exactly. Which means the human who deployed it is left holding the bag, even if they had literally no idea what the AI was going to do.
Co-host: It's a huge personal and corporate risk.
Host: And because there is no operating model to define these boundaries, we end up dealing with some severe fallout, according to the document. We're talking about inconsistent decisions, massive privacy and security exposure, and a total loss of consumer and internal trust.
Co-host: It degrades trust so fast.
Host: It really does. But there is one phrase in this deep dive that I cannot stop thinking about, and that is shadow AI.
Co-host: Oh, shadow AI.
Host: It is actually much worse than the standard shadow IT that companies have dealt with for years.
Co-host: Right, because for years, IT departments have constantly complained about shadow IT. It is just employees secretly using unauthorised software, like a random cloud storage app, to do their jobs because it's faster than waiting for official approval.
Host: Yeah, but here's the difference. With an unauthorised spreadsheet or a rogue software tool, a human is still doing the math.
Co-host: Right.
Host: A human is still interpreting the data and deciding what action to take. The human is liable.
Co-host: Yeah.
Host: But with shadow AI, the software is the actor.
Co-host: Oh man.
Host: You have these everyday tools operating in the dark, but now those tools are entities making active, autonomous decisions entirely on their own.
Co-host: That is wild.
Host: Right. If an employee secretly uses an AI agent to negotiate vendor contracts, and that agent agrees to disastrous terms, the company is legally bound by a decision made by a ghost.
Co-host: Made by a ghost. Wow.
Host: And if we connect this to the bigger picture for you, the listener, whether you are running a massive corporation or just managing a small five-person team, these isolated AI experiments are essentially a ticking time bomb.
Co-host: They really are.
Host: Because at an enterprise scale, these experiments generally suffer one of two fates. Either they remain totally isolated, meaning someone built a cool bot on their laptop that doesn't actually help the broader company scale, or, vastly more dangerously, they scale up without any consistent accountability.
Co-host: And scaling without accountability produces two very distinct negative outcomes, which are unclear value and unacceptable governance exposure.
Host: Okay, break those down for me.
Co-host: Sure. So if you cannot track how an AI is making decisions, you cannot measure its actual return on investment.
Host: So you're just throwing money in a hole.
Co-host: Exactly. That is the unclear value. But the unacceptable governance exposure, that is the real existential threat to a business.
Host: It sounds serious.
Co-host: It's beyond serious. This isn't just a minor tech glitch. It's not a bug in the code that you just patch on a Tuesday afternoon. Scaling an autonomous system without a framework of accountability is a massive systemic governance failure.
Host: It's like the teenager with the car key suddenly deciding they're going to drive a whole fleet of semi-trucks across the country.
Co-host: That's a great way to put it. And the executives at the top have absolutely no idea it's happening until a 50-car pileup occurs on the highway.
Host: And by then, it's way too late.
Co-host: Way too late.
Host: So how do we pull back from the brink of this unacceptable governance exposure?
Co-host: The document lays out a path forward, and it relies on two incredibly powerful concepts: Human Sovereignty and Governed Delegation.
Host: Those two concepts are the absolute bedrock of solving this P13 problem. You simply cannot have autonomous agents in a business without them.
Co-host: Okay, so let's define them.
Host: Right, so Human Sovereignty establishes a non-negotiable rule. The ultimate authority, and therefore the ultimate accountability, always resides with the human being.
Co-host: The buck stops with a person.
Host: Always. There is no scenario where the machine is to blame. And then Governed Delegation is the practical mechanism by which that sovereign human conditionally lends a specific slice of their authority to an agent.
Co-host: I really like that phrasing, conditionally lending a slice of authority.
Host: It makes the authority, the limits, the evidence, and the accountability just completely explicit. It removes all the ambiguity. And the major benefit here, according to the text, is what's called a controlled progression from assistance to autonomy.
Co-host: The idea is that an AI capability should only progress to a higher level of autonomy if it's directly justified by three things: its value to the business, the risk involved, and the requirements for human oversight.
Host: And it's crucial to understand that this is a sliding scale. It's not all or nothing.
Co-host: No, not at all. You don't just buy an AI platform, flip a switch, and go from zero to fully autonomous operations across the whole company.
Host: It requires a deliberate, methodical progression.
Co-host: So let me play devil's advocate for a moment, just to push on this.
Host: Go for it.
Co-host: When we talk about Human Sovereignty, does that just mean a human has to sit there at their desk and click approve on every single thing the AI does? Because if I have to read and manually approve every single email my AI agent drafts before it actually sends it, doesn't that defeat the whole purpose of having an autonomous agent in the first place? It feels like you're just doing the work twice.
Host: Exactly.
Co-host: I'm not saving time, I'm just doing the work of micromanaging a digital worker.
Host: That is honestly the most common fear people have when they hear the word governance. But it is exactly why the framework demands a controlled progression. It is absolutely not about micromanagement.
Co-host: Okay, so what is it about?
Host: It is about defining clear autonomy and authority boundaries. Let's look at a really practical example. If you define a highly constrained boundary for a very low-risk task, let's say categorising incoming IT support tickets as either hardware or software.
Co-host: Okay, pretty simple task.
Host: Right. The agent can operate with high autonomy within that specific tiny box. You don't need to click approve on every ticket.
Co-host: The agent has full authority there. Because the risk is low and the value of saving time is high.
Host: Exactly. The value cases for AI become much more credible, because the business knows exactly what the agent is allowed to do and, arguably more importantly, what it physically cannot do. By ensuring continuous evidence and oversight mechanisms are in place, humans can safely step back. They can let the agent run because they know exactly how, when, and why they might need to step back in.
Co-host: Okay, yeah, that makes perfect sense. It is setting the rules of the road, putting up the guardrails, and defining the speed limit before the car ever leaves the driveway.
Host: Beautifully put. And to actually implement this Human Sovereignty and this controlled progression, we don't just have to guess at how to do it. The source gives us this fascinating interrogation framework to use.
Co-host: The discovery questions.
Host: Right. It's a specific list of discovery questions that a business must answer before deploying an agent. And this isn't just nice-to-have best-practice advice. As we'll see in a minute, there are external regulations proving that asking these questions is actually legally mandatory.
Co-host: Yeah, these discovery questions are essentially the bridge between high-level philosophy and practical, on-the-ground engineering. If you cannot answer these questions, you have literally no business deploying an autonomous agent.
Host: Let's run through a few of the most critical ones, because if you are listening to this right now and you manage any kind of AI workflow, you should be asking your team these questions today.
Co-host: Absolutely.
Host: First one is: who grants an agent authority and who can revoke it? That sounds simple, but in a sprawling corporation, who actually is it? The IT admin, the VP of sales who bought the software, the end user?
Co-host: Really think about the revocation part of that question.
Host: The kill switch.
Co-host: Yes, the kill switch. If an agent is executing thousands of trades a minute, or sending thousands of customer emails a second, how do you actually revoke its authority?
Host: Just unplug the server.
Co-host: You'd hope it's that easy. But where is the kill switch in the software, and who is authorised to pull it? If you have to submit an IT support ticket to stop a rogue AI, you've already lost.
Host: Wow, yeah. Waiting 48 hours for a support tech to answer your ticket while your AI just hallucinates its way through your entire customer database, that is a nightmare scenario.
Co-host: It's happened, too.
Host: I bet. Another major discovery question from the document is: where is the evidence of an agent decision retained, and what evidence must an agent produce before its action is accepted?
Co-host: Now, that evidence question is perhaps the most technically difficult one to solve.
Host: Really? Why is that?
Co-host: Well, large language models are notoriously black boxes. They don't naturally show their work in a structured, auditable way.
Host: Right, they just give you the answer.
Co-host: Exactly. So demanding that the agent produce evidence before an action is accepted, it forces developers to build transparency into the workflow. The agent has to basically leave a receipt for every single logical leap it makes.
Host: But the question that really jumps out to me from this list is this one: what decisions must never be delegated?
Co-host: That's the big one.
Host: It feels huge. If we are setting up an agent today, how do we even begin to define the never list when the technology itself is changing every single week? What it can't do today, it might be perfectly capable of doing next month.
Co-host: This raises an incredibly important point, and it is honestly the crux of modern AI governance. How do you regulate a moving target?
Host: Right, exactly.
Co-host: The key insight here is that the never list isn't based on the technology's capability at all.
Host: It's not.
Co-host: No. It is based on human values and legal liability.
Host: Unpack that for me. What do you mean?
Co-host: Okay, so even if an AI becomes perfectly capable of deciding who to hire or fire, or perfectly capable of mathematically determining who should get a mortgage, or it becomes flawless at signing legally binding contracts.
Host: Which it probably will.
Co-host: Which it probably will. But even then, you as an organisation might decide those functions must never be delegated.
Host: Why?
Co-host: Because the moral and legal weight of those decisions must bear on a human conscience. You cannot put a machine on the witness stand.
Host: Wow. You cannot put a machine on the witness stand. That completely reframes it. Which brings in the external validation we mentioned earlier. The stakes here are not just philosophical debates for tech conferences. They are strict legal realities.
Co-host: Very strict. The framework points directly to two major regulatory bodies. First, the ICO, that's the Information Commissioner's Office in the UK, which frequently sets precedents that ripple globally. And they explicitly expect documented, embedded AI governance, senior accountability, and clear risk-management arrangements.
Host: And then second is the official EU AI Act. It establishes a strict, risk-based legal framework that covers governance, documentation, transparency, monitoring, and human oversight for AI roles and systems.
Co-host: So defining that never list, and answering those discovery questions about evidence and authority, it's a strict requirement to comply with the risk-management arrangements demanded by the ICO and the EU AI Act.
Host: It's not optional. If you cannot produce documentation showing what your AI is explicitly forbidden from doing, and who the sovereign human is that oversees it, you aren't just being sloppy. You are literally in violation of a legal framework.
Co-host: Exactly. The era of moving fast and breaking things, that is completely over when it comes to autonomous decision making. The regulators are demanding a paper trail of accountability.
Host: And all of this builds to a very specific call to action for organisations grappling with this. The directive in the document is to take just one single agentic use case and run it through this rigorous gauntlet.
Co-host: Just one to start.
Host: To define the authority, the constraints, the escalation paths, and the required evidence for just one bot. And the internal guidance suggests using an AEOM plus iGrafx governance context for this.
Co-host: Right, the technical architecture side of things. Okay, so for the uninitiated, meaning me mostly, what exactly are we talking about there with AEOM and iGrafx?
Host: Those are essentially internal enterprise architecture and process-modelling environments. Basically, if we strip away the corporate jargon, what it means is you must use your company's official process-mapping tools to document the AI's workflow just as rigorously as you would document a human's workflow.
Co-host: Oh, like drawing a literal map.
Host: You have to draw the flow chart. You map out exactly where the AI receives data, what logic it applies, where it must stop to ask a human for permission, and where the audit logs are stored.
Co-host: Taking the AI out of the shadows and baking it into the official corporate architecture.
Host: Exactly. You prove it works in the light before you ever let it scale.
Co-host: Which really brings us full circle on this entire deep dive into the P13 crisis. We started by looking at how unguided AI agents are quietly slipping into operational workflows.
Host: The invisible promotion.
Co-host: Right. They are making that invisible promotion from harmless desktop assistants to autonomous actors pulling levers in the background.
Host: We explored the very real, very expensive dangers of shadow AI, where tools are operating in the dark and making decisions on behalf of the company.
Co-host: And we explored the unacceptable governance exposure that inevitably happens when businesses try to scale this technology without simultaneously scaling their accountability frameworks.
Host: But we also found the solution. By building a rigid operating model based on Human Sovereignty and Governed Delegation, organisations can actually reclaim control.
Co-host: It's totally doable. By defining explicit boundaries, demanding continuous and retainable evidence, and forcing a controlled progression from assistance to autonomy, we keep humans firmly in the driver's seat.
Host: We give the teenager the keys. But we also install a speed governor, we map out the approved routes, and we put a dual braking system in the passenger seat.
Co-host: Perfect. And if you are listening to this, whether you manage a massive enterprise team integrating dozens of AI vendors, or you are just starting to experiment with a new AI automation tool on your own laptop to manage your inbox, this dynamic matters to your daily life.
Host: It really does. You need to know exactly where the agent's authority ends and where your human accountability begins.
Co-host: Because at the end of the day, when the system breaks, or when a decision harms a client, it is a human name on the dotted line.
Host: Always. The accountability can never be outsourced to the algorithm.
Co-host: That is the ultimate takeaway. You can outsource the task, but you can never outsource the liability.
Host: But before we sign off today, I want to leave you with one final thought to ponder. And it is something that pushes beyond the immediate fixes we've discussed today. The framework we've explored heavily relies on this idea of evidence, right? We must require the AI to produce evidence before its action is accepted by the human sovereign.
Co-host: And it is a great safeguard in theory. It is the linchpin of the whole Governed Delegation model.
Host: But here is the provocative question to take with you. If we successfully build these operating models where agents must produce evidence before acting, what happens when AI reasoning becomes so mathematically complex, or operates across so many millions of data points simultaneously, that the evidence it produces is no longer decipherable by the human sovereign who is supposed to oversee it?
Co-host: Oh man, that is the horizon we are rapidly approaching. The black box is just getting deeper.
Host: If the teenager hands you a map showing exactly why they drove the car into a ditch, but the map is written in a mathematical language you cannot read, and they are already pressing the gas pedal for the next trip, well, if you can't understand the evidence, who is really in charge?
Co-host: Thank you for joining us on this deep dive. Keep questioning the boundaries, keep demanding the evidence, and we will see you next time.
Want to see what this looks like on your own BPM content? One conversation is enough to start.