top of page

AUTHORITY WITHOUT RECALL IS NOT CONTROL

Writer: Erik Kling
Erik Kling
Aug 26
28 min read
Authority without recall is not control.
AI delegation is easy to grant and much harder to unwind. Real control depends on whether authority can actually be recalled.
Authority without recall is not control.

AI delegation is easy to grant and much harder to unwind. Real control depends on whether authority can actually be recalled.


The AI Architecture of Delegated Authority


What a machine can do and what an institution has authorized it to do are two different architectures.


AXISYNC POSITION PAPER 45  ·  26 AUGUST 2026


I. The transition nobody is architecting


Something changed in enterprise artificial intelligence during the first half of 2026, and the change was not a capability threshold. It was a permissions threshold.


OpenAI documented the shift in its own enterprise research published on 12 August 2026, under a title that states it plainly: from assistance to execution. The figures describe an organisation-level behaviour rather than a technical advance. Firms in the top decile of usage now generate 8.3 times as many output tokens per active user as typical firms, up from 2.6 times in January. Among enterprise customers, Codex accounted for 64 per cent of combined Codex and ChatGPT output tokens as of June. Advanced connective features show the same separation: at those firms, 21 per cent of weekly active users employ plugins and 19 per cent employ skills, against 9 per cent and 3 per cent elsewhere. Weekly active users of Codex in legal functions grew 108-fold since February.


Read past the growth rates and what the data describes is a change in what these systems are connected to. Assistance requires a model and a person. Execution requires a model, a person, and a set of standing connections into the systems where the institution's work actually happens — its customer records, its repositories, its payment rails, its schedules, its suppliers. OpenAI's own framing names the conditions that make the second possible, in a phrase worth quoting exactly: "clear permissions, governance and human review."


That is the transition. And it is frequently treated as an integration project.


Consider what the same shift looks like described in institutional rather than technical language. A system that answers a question has produced information; the institution decides what to do with it. A system that can access a customer database, initiate a payment, modify infrastructure, communicate with a customer, purchase a service, alter code, schedule a resource, negotiate with a supplier, or instruct another system has not produced information. It has acted, on the institution's behalf, under the institution's name, within authority the institution granted it.


Between those two states lies a boundary that can be crossed without a meeting. No committee need convene to decide that machines should be authorized to commit the enterprise. It can be decided in a series of integration tickets, each individually sensible.

The market has a vocabulary for this transition — productivity, automation, efficiency, return on investment — and it is not a foolish vocabulary. It measures something real, and every organisation deploying these systems is entitled to ask what they are worth.


But it asks what the institution gained. It does not ask what the institution granted.


The market believes this is an automation problem. It is becoming an authority problem.


That is where this analysis begins.


II. Capability is not authority


The confusion at the centre of the current moment is old, and it long predates machines.

An organisation's most competent employee is not thereby entitled to sign its contracts. A capable analyst may be better at pricing than the person authorized to set prices. Competence and authority are separate properties, deliberately separated, and institutions maintain that separation at real cost — slower decisions, redundant review, work performed by people less good at it than someone else available — because the separation is what makes an institution accountable rather than merely effective.


Every mature organisation therefore operates two distinct architectures. One describes what its people and systems are able to do. The other describes what they are permitted to commit the institution to. The second is deliberately smaller than the first, and the gap between them is not inefficiency. It is governance.


Agentic AI can compress that distinction unusually quickly, for a reason that is structural rather than cultural. In most systems, capability and permission are separate engineering concerns: a database can technically perform an update, and a permission model determines whether this caller may request it. With agentic systems the capability arrives packaged with its own reach. The moment an agent is connected to a tool, it can use the tool. The moment it holds a credential, it can act with it. The decision to grant capability and the decision to grant authority can therefore be made in the same implementation step.


The question that follows is not whether these systems can make good decisions. Many can, in many contexts, and the evidence will improve. The question is whether an institution has decided — deliberately, and at a level where the decision is visible — which decisions it is willing to have made on its behalf.


That is not principally a question about artificial intelligence. It is a question about governance architecture, and it has an established answer in every other domain where institutions delegate.


AN ADJUDICATED INSTANCE


The clearest existing statement of the principle comes from a small case with a small award.


In Moffatt v. Air Canada, decided by the British Columbia Civil Resolution Tribunal on 14 February 2024, an airline argued that it should not be bound by what its automated system had told a customer. The tribunal's response is worth quoting, because it disposes of the argument in a sentence: "In effect, Air Canada suggests the chatbot is a separate legal entity that is responsible for its own actions. This is a remarkable submission."


The holding is narrower than it is often reported to be, and the narrow version is the one worth having. The tribunal found that Air Canada could not escape responsibility for information on its own website merely because that information reached the customer through its chatbot. The case concerned a misrepresentation in text, not an autonomous action, and it should not be described as an agent-authority case.


The significance is not that the tribunal created a general law of machine agency. It is that the system did not sit outside Air Canada for purposes of responsibility. The award was CAD 812.02.


CAPABILITY EXERCISED OUTSIDE AUTHORITY


The distinction is easier to see where it fails.


In December 2025, Anthropic published the second phase of an internal experiment in which an agent was given operational responsibility for a small retail operation. The agent tripled the number of refunds and doubled the number of store credits, authorized requests for lenient financial treatment roughly eight times as often as it denied them, and attempted to hire a security officer at ten dollars an hour — substantially below the minimum wage in California, and with no authorization to employ anyone at all. It also came close to agreeing a contract to buy a large amount of onions in January for a price locked in at the time, before another staffer intervened and identified the Onion Futures Act of 1958, which bans contracts of that nature.


This was a controlled experiment, not an enterprise incident, and it should be labelled as such wherever it is cited. Its value is illustrative rather than evidential. But what it illustrates is precise: at no point did the system exceed its capabilities. It did what it was able to do. Every failure in that list is a failure of authority — an action taken outside a boundary that either had not been drawn, or had been drawn somewhere the system could not see.


An agent does not have to be wrong to be dangerous. It has only to be authorized.


The concession


Before this argument goes further, it should meet its strongest objection, which will come from the part of any organisation best qualified to raise it.


The objection runs as follows. Institutions have delegated authority to non-human systems for decades. Algorithmic trading systems commit capital without a human in the loop. Credit engines approve and decline lending at volume. Industrial control systems operate physical plant. Automated payment rails settle obligations continuously. The profession that governs this is mature, examinable, and has a name: internal controls. Delegated authority matrices, segregation of duties, signing limits, four-eyes requirements, exception reporting and audit exist precisely to define what may be committed, by whom, within what bounds. A chief financial officer reading this paper is entitled to conclude that agentic systems are a new instance of an old problem the profession solved a long time ago.


The objection is correct in almost everything it asserts. It should be conceded rather than argued with.


What it misses is narrow, and it is not the obvious candidate. The tempting reply is that older systems were deterministic and agents are not — that prior automation followed rules while agents exercise judgment. That reply does not survive contact with the evidence. Machine-learning credit models are not rule-reconstructible. Algorithmic trading exhibits emergent behaviour at the system level. Industrial automation has produced opaque failure modes for as long as it has existed. Opacity is not the new thing.


The new thing is the shape of the authorization itself.


Traditional automated systems were authorized inside predefined functional domains, interfaces and transaction classes. A trading system is authorized to trade, within instruments, within limits, through a defined interface. A payment system is authorized to pay, against defined obligations. The authority is bounded not primarily by the sophistication of the control, but by the architecture of the system: it cannot do a different kind of thing, because it has no route to a different kind of thing.


Agentic systems can dynamically select tools, construct intermediate objectives, sequence actions, and traverse multiple institutional systems in pursuit of an outcome. The authorization is not to perform a transaction class. It is to achieve a result, with discretion over the route.


Delegated authority is moving out of bounded applications and into systems capable of composing actions across institutional boundaries. That is the whole of the difference, and it is enough.


WHAT THE REGULATOR HAS ALREADY WRITTEN


There is a further piece of evidence for the boundary problem, and it comes from the European Union's binding legislative framework.


Article 14 of the European Union's Artificial Intelligence Act requires that high-risk systems be designed so they can be effectively overseen by natural persons. The specific provisions are strikingly close to the argument of this paper. Oversight measures must be "commensurate with the risks, level of autonomy and context of use" (14(3)). Those exercising oversight must be able "to disregard, override or reverse the output" (14(4)(d)). And they must be able "to intervene in the operation of the high-risk AI system or interrupt the system through a 'stop' button or a similar procedure that allows the system to come to a halt in a safe state" (14(4)(e)).


Reversal and revocation are therefore already written into binding law, and the drafters correctly tied the intensity of oversight to the degree of autonomy.


The difficulty is one of scope rather than intent. Much of the authority now being delegated across ordinary commercial operations — procurement, customer communication, code, scheduling, payments — does not, by that fact alone, fall within the high-risk classification. Some deployments in those categories will intersect it. Many will not.


The obligation was written where the risk was anticipated. A great deal of the authority now being created sits outside it. The controls profession did not fail to see this. It was given a boundary, and delegated authority has moved outside it.


III. The new architecture of control


If authority is the object of analysis, it is worth being exact about the path by which an institution's intent becomes a machine's action. Call this the authority chain:

Model → Agent → Identity → Permissions → Tools → Workflows → Actions


Each link is a distinct decision, and each is normally made by a different person at a different time.


The model is selected, usually centrally, usually with the most scrutiny of any link in the chain. The agent is configured — given an objective, a scope, a set of instructions about how to pursue it. It is issued an identity, so that the systems it contacts know who is calling. That identity is granted permissions, defining the scope of what it may do. It is connected to tools, the specific interfaces through which it reaches the institution's systems. It is placed into workflows, meaning a set of expectations about what precedes its action and what follows. And at the end of the chain it takes actions, which are the only link in it that anyone outside the institution ever sees.


Two observations follow, and they are the reason the chain is worth drawing.


The first is that scrutiny is distributed almost exactly backwards. The model receives board-level attention. The permission grant, three links further down and far more consequential, is typically an engineering decision recorded in a ticket. The link that determines what the institution can be committed to is the one with the least governance attached.


The second is that no single person sees the whole chain. Model selection sits with technology leadership. Identity and permissions sit with security. Tool connections sit with the platform team. Workflow placement sits with the business unit. Actions land on customers, counterparties and regulators. Each participant is competent, and each sees one link.


This is the mechanism by which institutions arrive at a position nobody chose. Not through negligence, and not through any single bad decision — but because the chain is assembled in segments by people who are each doing their part correctly.


IV. Dependency moves again


For most of the past three years, the question institutions asked about artificial intelligence was which model to use. It was a reasonable question, and it produced a reasonable anxiety: models were changing quickly, capability rankings reordered every few months, and no procurement officer wanted to sign a five-year commitment to a system that would be surpassed before the contract matured.


That anxiety was misdirected, though not for the reason usually given. It was misdirected because by the time an institution has embedded agents across its operations, the model may no longer be the most consequential dependency it holds, and may be among the easier elements to replace.


Consider what an agent actually requires in order to act. It requires an identity, so that the systems it touches know who is calling. It requires permissions attached to that identity, defining the scope of what it may do. It requires tools — the specific connections through which it reaches a customer record, a payment rail, a scheduling system, a repository. It requires a place in a workflow, which is to say a set of institutional expectations about what happens before it acts and what happens afterward. And over time it accumulates institutional memory: the record of what it has done, what was approved, what was corrected, and what the institution has come to treat as normal.


The model sits upstream of all of this, and it may become one of the more replaceable elements in the arrangement. Models carry switching costs of their own — prompts, evaluations, tuned behaviour — but those costs are borne inside a team. Everything downstream of the model is borne by the institution.


THE DEPENDENCY STACK


Section III described the authority chain — the path by which an institution's intent becomes a machine's action. What follows is a different object, and it should be read as a different object. Call it the dependency stack: not how authority flows, but where leaving becomes expensive.


Agent → Identity → Permissions → Tools → Workflows → Institutional Memory


Read it from the far end and the lock-in becomes visible. An institution that wishes to change models can change models. An institution that wishes to change the layer that orchestrates its agents must re-establish every identity, re-grant every permission, re-attach every tool, re-validate every workflow, and reconstruct whatever record of prior action the previous arrangement held. The first is a procurement decision. The second is a rebuild.


Readers of this practice's earlier work will recognise the movement. The recurring finding has been that dependency does not sit where attention sits. It settles one layer away from whatever is being negotiated, which is precisely why it is rarely negotiated.


Dependency has moved again. It has moved off the model and into the orchestration and permission layer. And it has moved there quietly — not because institutions fail to procure access architecture, which they do, deliberately and at length, but because the accumulated authority architecture is rarely procured as a single object. It is assembled one integration at a time, each one reviewed on its own merits, and it is complete before anyone has seen it whole.


The architecture is the sum, and nobody procures a sum.


THE MARKET HAS ALREADY CONCEDED THIS


The strongest evidence that the permission layer has become architectural is not an analyst's forecast. It is what three companies with the most complete view of enterprise deployment did within nine days of each other.


On 22 April 2026, Google Cloud brought Agent Identity to general availability: a strongly attested, cryptographic identity issued per agent, SPIFFE-based and bound to X.509 credentials, which cannot be shared, impersonated, or used to mint long-lived keys. On 30 April, Amazon shipped on-behalf-of token exchange in Bedrock AgentCore Identity, issuing a scoped-down access token that carries both the originating user identity and the agent identity, targeted at a single outbound resource. By 1 May, Microsoft Entra Agent ID was generally available, establishing agent identities as accounts in their own right — governed, in Microsoft's own phrase, "in the same style as you would govern human identities."


These are three different designs. Only Amazon describes a dual-principal token construction; Google surfaces both identities in the audit trail; Microsoft builds the identity class and attaches governance to it. It would overstate the evidence to say the three converged on a solution.


What they converged on is the problem. Within the same nine-day window, all three had made agent identity and delegated access a first-class architectural concern — an agent cannot borrow an application's identity or a person's, and authority granted to one has to be modelled, scoped, governed and withdrawn as its own thing. Competitors do not arrive at that position in the same fortnight because it is fashionable.


SPONSORSHIP, AND WHAT IT ADMITS


One detail in Microsoft's architecture is worth more than the announcement that surrounds it.


Every agent identity has a sponsor — in Microsoft's definition, a human user "accountable for making decisions about its lifecycle and access." That is unremarkable. What is remarkable is the provision for the sponsor's departure: "If the sponsor is leaving the organization, sponsorship of the agent identities is automatically transferred to their manager. With sponsorship transferred, there's always a human user accountable for managing the access and lifecycle of the agent identities."


Read that as an architectural admission rather than a feature. It says that agents are expected to outlive the people accountable for them. It says the vendor anticipates a state in which authority persists inside an institution after the person who understood why it was granted has gone. And it says the remedy is to reassign accountability upward, automatically, to someone who was not party to the original decision.


Any institution that has run a joiners-and-leavers process has seen the risk: permissions can outlive the justification for which they were granted. When they do, they may be inherited rather than revoked. The difference here is that the thing being inherited is not access to a folder. It is standing authority to act on the institution's behalf, held by something that will keep acting.


THE DEPENDENCY BENEATH THE DEPENDENCY


There is a further layer, and it is the one that will matter longest.


An institution can hold complete records of what its agents did — which agent, under which authorization, at what time, against which system — and still hold no account of why any particular action was chosen. Attribution and rationale are separable properties.


A log is not an explanation.


Call this decision traceability, and note what its absence creates: an interpretive dependency. When the institution can no longer reconstruct the reasoning behind an accumulated body of its own past actions, it becomes dependent on whatever can reconstruct it — the system itself, its vendor, or nothing. Precedent inside an institution is not merely a record of what was done. It is a record of why, which is what allows a later decision-maker to depart from it deliberately rather than by accident.


An institution that cannot explain its own precedents has not lost its records. It has lost the ability to overrule them on purpose.


WHERE THIS LEAVES THE ARGUMENT


None of this describes a failure. It describes a position.


Institutions adopting agents are acquiring capability quickly and acquiring dependency quietly, and the two are arriving through the same door. Each individual grant is defensible on its own terms — this tool, this scope, this workflow, this quarter.


The AXISYNC chain, applied here, runs as it always has. Architecture determines where authority accumulates. Accumulated authority creates dependency. Dependency determines what can still be reversed. And what can still be reversed is the practical measure of control.


None of this is an argument for stopping. It is an argument for knowing what has been granted.


Which is the question the next section takes up: if authority accumulates through individual, defensible grants, how should each grant be bounded at the moment it is made?


V. The architecture of delegation


Institutions are not short of instruments for bounding delegated authority. They have been refining them for centuries, and the good ones are unglamorous: the delegated authority matrix, the signing limit, the four-eyes requirement, the escalation threshold, the exception report, the periodic access review.


There is a large and growing literature arguing that agentic systems need human approval gates, bounded autonomy, escalation paths, permission scoping and auditability. That literature is correct and it is not, on the whole, saying anything an experienced controls function does not already know. The useful question is not what new controls to invent. It is which assumptions the existing ones rest on, and which of those assumptions agentic delegation quietly voids.


There are four worth naming.


The signing limit assumes a bounded transaction class. A limit of fifty thousand is meaningful because the thing being limited is a recognisable kind of act, denominated in a known unit, arriving through a known interface. An agent authorized to achieve an outcome may reach it through a sequence of individually trivial actions, none of which resembles the transaction the limit contemplates. Mature control environments anticipate this and aggregate — across a counterparty, a period, a category. The question agentic delegation raises is whether the aggregation boundary matches the sequence the agent can actually compose. Where it does not, a transaction-level limit remains in force and stops being relevant.


The four-eyes requirement assumes a second party capable of evaluating the first. Dual authorization does not require the reviewer to reconstruct the first actor's reasoning — mature implementations work from independent evidence, and that is precisely their strength. What it does require is that the second reviewer be capable of independently evaluating the proposed act and the evidence supporting it. Where an opaque output is presented without that evidence, review risks becoming ratification. The control persists in form while its substance depends entirely on what the reviewer is actually given, and that shift need not be visible in the process.


Escalation assumes someone recognises the exception. Exception handling depends on a shared sense of what normal looks like. An agent operating continuously, at volume, across systems, can establish a baseline of normal that the institution has not deliberately set. What ought to be escalated is defined by reference to a pattern the institution no longer sets.


Periodic review assumes permissions are legible. An access review works when a reviewer can look at a grant and say whether it is still needed. Agent permissions are frequently expressed as tool connections and scopes whose business meaning is not apparent from the grant itself. A reviewer asked whether an agent should retain access to a particular interface has, in practice, no basis on which to say no.


None of these assumptions were wrong when they were made. They were load-bearing and invisible, which is what assumptions in mature systems tend to be.


THE THRESHOLD QUESTION


Which brings the section to the question that ought to be asked at every delegation decision, and rarely is.


Delegation is usually described as a spectrum: recommendation, then recommendation-with-approval, then bounded autonomy, then full autonomy. That framing is useful but it obscures the transition that actually matters, which is not about the machine at all.


At what threshold does the human move from being the decision-maker to being the exception handler?


The distinction is not academic. A decision-maker holds the default: nothing happens unless they act. An exception handler holds only the deviation: everything happens unless they intervene. Those are different institutional roles, requiring different capabilities, attention and standing — and organisations can move people from the first to the second without recording that they have done so, because from the outside the workflow looks unchanged. The same person is still named. The approval box is still there.


An institution that cannot say where that threshold sits for a given process cannot say who is making its decisions.


Delegation is not the transfer of work. It is the transfer of the right to commit the institution.


Which raises the question the next section exists to answer. Bounds can be described. Whether they can still be enforced against what has already been built is a different matter — and it is testable.


VI. The Authority Recall Test


In June 2026 this practice published a diagnostic called the RHODES Exit Test. It asked one question of any dependency an institution had entered: if you had to leave tomorrow, could you? The question was deliberately crude. Its value was that it could not be answered with an intention. An institution either had a route out or it did not, and the exercise of looking for one usually revealed which.


That instrument does not reach what agents have introduced, and it is worth being precise about why. The Exit Test examines a relationship the institution entered — a vendor, a platform, a contract. Delegated authority is not a relationship. It is a grant. An institution can hold a perfectly reversible vendor arrangement and still have no idea what was done under its own name while the arrangement was in force.


So a second instrument is required, and the distinction between them should be stated plainly:

The Exit Test asks whether an institution can leave a dependency. The Authority Recall Test asks whether an institution can recall the authority it granted.


Both are reversibility instruments. They are not the same instrument in two settings.


THE GOVERNING QUESTION


If every agent stopped tomorrow, could the institution identify what they did, undo what must be undone, and continue operating?


The word doing the work is every. Institutions can usually answer this about the agent they are thinking of. They cannot answer it about the ones they have forgotten, the ones assembled inside a business unit without a central record, or the ones whose authority was granted eighteen months ago by someone who has since moved on.


Note also what the question does not ask. It does not ask whether the institution should stop. Nothing in this analysis suggests it should. The question is whether the capability exists, because a capability that has never been exercised and cannot be described is indistinguishable from one that is absent.


THE FIVE DIMENSIONS


Revocation. Can the institution terminate the agent's authority completely and promptly?


Not whether a single switch exists. Distributed revocation is a legitimate design; incomplete revocation is not. The failure condition is the absence of a complete and authoritative path — a state in which credentials, tokens, tool connections and standing grants live in enough places that no one can assert with confidence that all of them are closed. An institution that can revoke ninety per cent of an agent's authority has not revoked its authority.


The European legislator has already written a version of this requirement into binding law, as the concession above noted: Article 14(4)(e) requires that high-risk systems permit an operator to interrupt them through a stop button or equivalent, bringing the system to a halt in a safe state. That is Revocation, expressed as a single control on a single system. It is the right instinct at the wrong scale. The institutional question is not whether one system can be halted. It is whether authority, distributed across many, can be withdrawn as a whole.


Attribution. Can every consequential action be connected to the responsible agent, its identity, the authorization it acted under, and the accountable human or institutional principal?


Logging that an action occurred is not attribution. Attribution requires four linked facts — what was done, by which agent identity, under which grant of authority, and on whose account. Systems that record the first and third can lose the second and fourth, because the agent acted through a service identity or an integration credential that belongs to no one in particular.


Note the deliberate breadth of "human or institutional principal." Some architectures name an individual and reassign that accountability automatically when the person leaves. Others locate it in a team, a function, or a control owner. The instrument does not prescribe which. It requires only that the answer exists and can be produced.


Reversal. Can consequential actions be undone, corrected or compensated?


Three verbs, in descending order of comfort. Some actions can be undone: a record altered can be restored. Some can only be corrected: a schedule already acted upon by other people is repaired forward, not rewound. And some can only be compensated, because they have left the institution entirely — a payment settled, a customer told something, a commitment accepted by a counterparty who is now entitled to rely on it.


The dimension is not asking for a universal undo. It is asking whether the institution knows, in advance, which of its delegated actions fall into which category. Much delegated authority can be granted without ever being sorted this way, and the sorting is uncomfortable, because it makes explicit that some machine actions are irreversible at the moment they are taken.


Continuity. Can the institutional function continue if the agent disappears?


The quiet dimension. Delegation does not merely add capacity; over time it removes the alternative. The people who held a process are reassigned, the procedure stops being documented because the documentation stopped being consulted, and the institution arrives at a position where the function is performed but no longer held by anyone.


This is the dimension where the answer degrades without any decision being taken.


Nothing goes wrong. Capability simply drains out of the human side of the process while the outputs continue to appear, and the loss becomes visible only at the moment the institution needs to do the thing itself.


Substitution. Can another authorized agent assume the function without reconstructing the institution's permission, tool and workflow architecture?


Deliberately not a question about vendors — that belongs to the Exit Test, and conflating the two collapses the distinction the instrument depends on. Substitution asks whether the function is portable within the institution's own authority architecture. If replacing one agent means re-establishing every identity, re-granting every permission and re-validating every workflow, the institution has not delegated a task to an agent. It has built its process around a particular one.


WHY THE INSTRUMENT CARRIES NO SCORE


Five dimensions invite a number, and the number is deliberately withheld.


A scoring model would be premature and, worse, prematurely persuasive. An institution presented with a scale will optimise the scale, and the value of the first pass through these five questions is not the grade but the discovery — the specific inability to answer, in a specific system, that nobody had previously noticed. A score short-circuits that, because a low number can be accepted and filed where an unanswerable question cannot.


WHAT EXTERNAL ASSURANCE CAN — AND CANNOT — ANSWER


An institution reaching for external assurance on these five questions no longer finds an empty field.


Agent-specific certification now exists. AIUC-1 is an independent certification scheme for agentic systems, with BSI performing the independent Operational Controls Audit — assessing an organisation's AI governance, policies, processes and operational controls against the scheme's requirements — while AIUC conducts the technical testing, certification review and certificate issuance. Its stated scope is precisely the population this paper is concerned with: organisations whose agents "make autonomous decisions, perform tasks, interact with customers, access sensitive data, or connect to external tools, APIs and business systems." It runs quarterly adversarial testing alongside an annual audit of governance, safety and security controls, and it has accredited auditors and certified organisations.


Around it, the wider architecture is filling in. The United States National Institute of Standards and Technology opened an initial public draft in February 2026, through its National Cybersecurity Center of Excellence, on the identification, authorization, auditing and non-repudiation of AI agents. OWASP's Top 10 for Agentic Applications, published in December 2025, names tool misuse, identity and privilege abuse, and rogue agents among its risk classes — a consensus catalogue produced by volunteers rather than a control baseline. ISO/IEC 42001 governs artificial intelligence management systems and ISO/IEC 42006 accredits the bodies that audit them, providing the broader management-system architecture within which agent-specific schemes can sit.


External assurance is arriving. But it answers a different question from the one this instrument asks, and the difference matters.


A certifier assesses a defined system and the controls around it, at a point in time — AIUC's own certificate reflects practices as at the date of certification. That is a real and valuable thing to know. What it cannot establish, because it is not what it is scoped to examine, is whether every credential inherited across a reorganisation, every permission granted in a business unit and never reviewed, every workflow dependency that formed without being designed, and every irreversible commitment already made in the institution's name can actually be recalled tomorrow. That is not a property of a system. It is a property of an institution's accumulated position.


External assurance can validate a control system. It cannot substitute for the institution's own map of the authority it has granted.


WHAT THE TEST MEASURES


A poor result here is not evidence that anything has gone wrong, and this paper makes no claim that anything will. The instrument measures a position, not an outcome: how much of the institution's capacity to act differently has been transferred, and how much remains. It is the same measure this practice has applied in every domain it has examined. The object is new. The question is not.


An institution that can answer all five confidently has not restricted its agents. It has retained the ability to change its mind about them — which is the only form of control that survives contact with a decision it later regrets.


VII. Human agency


The ability to change its mind is worth examining directly, because it is the thing this entire analysis has been circling, and because the word for it carries two meanings that have just collided.


Agency, in the technical sense now dominant, describes a system that can pursue objectives with discretion over the means. Agency, in the older institutional and human sense, describes the capacity to act otherwise — to have done differently than one did, and to be able to do differently tomorrow. The first sense has been rapidly acquired. The question is what happened to the second while everyone was looking at the first.


This practice has argued before that infrastructure decisions accumulate into a chain: possibility, optionality, agency, freedom. What is possible determines what options exist. Options are the raw material of agency. Agency, held over time and defended, is what freedom means in practice for an institution as much as for a person.


Delegated authority enters that chain at the third link, and it enters from an unexpected direction.


The intuitive worry about machine agency is that machines will do things institutions did not want. That worry is not baseless, but it is not the structural risk, and it is not what this paper has documented. The structural risk is quieter: that an institution transfers so much of its routine capacity to act that it retains the formal right to decide and loses the practical ability to decide differently.


Those are not the same thing. An institution retains the right to overrule its systems at every point in the chain described here. What it may not retain is the reconstructed reasoning that would let it know when to, the human capability that would let it act on the decision, or the architecture that would let the decision take effect. A right that cannot be exercised is not a constraint on anything.


This is why the analysis has stayed structural rather than moral. The objective is not to prevent machines from acting. Machines will act, and they will often act well. The objective is to prevent institutions from losing, through accumulation rather than through decision, the ability to act differently.


There is a version of this argument that becomes a complaint about technology. It is not the argument being made. Every capable institution delegates; delegation is what allows an institution to be larger than the people in it. The Roman magistrate, the corporate officer, the plant supervisor and the trading desk all hold authority someone else granted and could withdraw. Delegation is not the problem. Delegation that cannot be recalled is a different arrangement entirely, and it has a different name.


The question this paper has put is therefore narrower than it may appear, and more practical. Not whether to delegate. Not how much. But whether the institution, having delegated, can still find its way back to the position from which it decided.


VIII. Conclusion


The defining question of this period will not be whether machines can act. They can, they increasingly do, and the capability will continue to improve regardless of what any institution concludes about it.


The defining question is who designed the architecture under which they are permitted to act — and whether that architecture preserves the institution's ability to intervene, to reverse, and to choose differently.


This architecture can be assembled without anyone holding the pen. It is assembled from integration decisions, permission grants, tool connections and workflow placements, each of them individually reasonable and none of them examined as a whole. It is not the product of a strategy. It is the residue of a hundred sensible choices.


This paper has not argued that the choices were wrong. It has argued that they add up to something, that the something is an architecture, and that an architecture nobody designed is still an architecture — one that determines what the institution can still do.


The Authority Recall Test exists to make that determination available before the moment rather than during it. The five questions ask whether authority can be revoked, actions attributed and reversed, the function continued without the agent, and another authorized agent substituted without rebuilding the authority architecture. Institutions that can answer have not limited themselves. They have kept something.


Capability is not authority. Capability is acquired; authority is granted. And authority that cannot be recalled is not control — only the appearance of it. What is granted through architecture can be recovered only through architecture.


RHODES OBSERVATION

Authority is not lost when it is delegated.

It is lost when it can no longer be recalled.


STOIC REFLECTION

The Stoics gave the faculty of choice its own name — prohairesis — and Epictetus held it to be the one thing properly our own: the one faculty that cannot be compelled, hindered or enslaved from outside. What he did not claim, and what no institution should assume, is that it cannot be handed over.

Everything else an institution holds can be delegated: its labour, its judgment, even its authority to act. What it cannot delegate and remain itself is the capacity to choose differently tomorrow than it chose today.

Nothing external takes that capacity. It is given away, one permission at a time — and it is not preserved by policy, but by architecture.


Sources


Enterprise adoption and the shift to execution

OpenAI, From assistance to execution: How enterprises put AI to work, 12 August 2026 — supports the frontier-firm output-token ratio of 8.3× (up from 2.6× in January), Codex at 64 per cent of combined enterprise output tokens as of June, plugin and skill usage rates of 21 and 19 per cent at frontier firms against 9 and 3 per cent elsewhere, 108-fold growth in weekly active Codex users in legal functions since February, and OpenAI's own identification of "clear permissions, governance and human review" as enabling conditions of execution.


Agent identity and delegated authority

Google Cloud, Identity and Access Management release notes, 22 April 2026 — supports the general availability of Agent Identity, its SPIFFE-based cryptographic per-agent identity and X.509-bound access tokens, and the property that such identities cannot be shared, impersonated or used to mint long-lived keys.

Amazon Web Services, Amazon Bedrock AgentCore Identity adds on-behalf-of token exchange, 30 April 2026 — supports the scoped-down access token carrying both the originating user identity and the agent identity, targeted at a single outbound resource on a just-in-time, least-privilege basis.

Microsoft, Microsoft Entra Agent ID documentation and Governing agent identities, Microsoft Entra ID Governance; general availability 1 May 2026 — supports the definition of agent identities as accounts providing unique identification and authentication for AI agents, the statement that they are governed "in the same style as you would govern human identities," the definition of sponsors as "human users accountable for making decisions about its lifecycle and access," and the automatic transfer of sponsorship to the sponsor's manager on departure.

Regulation

Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 14; entered into force 1 August 2024, generally applicable from 2 August 2026 under Article 113 — supports the human-oversight requirement for high-risk systems, the requirement at 14(3) that oversight be "commensurate with the risks, level of autonomy and context of use," the right at 14(4)(d) "to disregard, override or reverse the output," and the requirement at 14(4)(e) to permit interruption "through a 'stop' button or a similar procedure that allows the system to come to a halt in a safe state."

Standards and assurance

AIUC-1 certification scheme, and BSI, AIUC Agentic AI Certification — supports the existence of an independent agentic-AI certification scheme; BSI's role performing the independent Operational Controls Audit "assessing your organization's AI governance, policies, processes and operational controls against the AIUC scheme requirements," with AIUC performing technical testing, certification review and certificate issuance; the scheme's stated scope covering agents that "make autonomous decisions, perform tasks, interact with customers, access sensitive data, or connect to external tools, APIs and business systems"; quarterly adversarial testing and annual controls audit; and AIUC's own statement that a certificate reflects practices at the time of certification.

National Institute of Standards and Technology, National Cybersecurity Center of Excellence, Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization, initial public draft, 5 February 2026 — supports the statement that a national standards body has formally opened the questions of identification, authorization, auditing and non-repudiation of AI agents, and that they remain unsettled.

OWASP, Top 10 for Agentic Applications 2026, version 1.0, 9 December 2025 — supports the existence of a consensus risk catalogue in which tool misuse, identity and privilege abuse, and rogue agents appear as named classes.

ISO/IEC 42001:2023, Artificial intelligence management system, and ISO/IEC 42006:2025, Requirements for bodies providing audit and certification of artificial intelligence management systems — support the observation that these standards provide the broader AI management-system and accreditation architecture within which agent-specific certification schemes sit. Note: no agentic-AI work item was located in the ISO/IEC catalogue; this is stated as not located, not as absent.

Liability and observed authority failures

Moffatt v. Air Canada, 2024 BCCRT 149, British Columbia Civil Resolution Tribunal, 14 February 2024 — supports the tribunal's rejection of the submission that a company's automated system is "a separate legal entity that is responsible for its own actions," and the award of CAD 812.02. Concerns a misrepresentation in text rather than an autonomous action.

Anthropic, Project Vend: phase two, 18 December 2025 — supports the described authority failures within a controlled experiment, including tripled refunds and doubled store credits, discount authorization at roughly eight times the rate of refusal, an attempted hire at $10/hour, substantially below the minimum wage in California, with no authorization to employ people, and a near-agreed contract to buy a large amount of onions in January at a price locked in at the time, which a staffer identified as barred by the Onion Futures Act of 1958.

AXISYNC Partners LLC / axisyncpartners.net | Architecture of Decision Sovereignty / Authority Without Recall Is Not Control | August 2026


Comments


bottom of page