Strategic & External Environment · 17 August 2027
The AI governance discipline this series established earlier addressed tools that generate content and recommendations for a human to review and act on. A newer, more consequential category has emerged rapidly since: agentic AI, systems that do not simply suggest an action but plan and execute it directly, often with minimal human involvement in the moment the action happens.
A Genuinely Rapid Shift, With A Striking Governance Gap
Recent industry research found that the substantial majority of organisations have already deployed autonomous AI agents or plan to imminently, yet fewer than half of those organisations have visibility into a complete inventory of the AI agents actually operating within their own systems. This is not a hypothetical future risk. Any association using modern membership platforms, automated communication tools, or AI-enabled software may already have some degree of autonomous action happening inside its operations without the board, or even management, having a clear, complete picture of what these systems are authorised to do.
The Accountability Principle Worth Stating With Absolute Clarity
An easily overlooked temptation exists to treat an autonomous system as though it carries its own accountability for the actions it takes. It does not. An algorithm cannot be held responsible for a flawed decision. The executives who deployed the system, set its operating parameters, and chose the specific boundaries of its autonomy can and must be. This connects directly to the AI governance discipline discussed earlier in this series, and agentic systems make the underlying principle more urgent rather than different: the humans who configured the system's authority remain fully accountable for what that system does with it. Agentic AI does not require an entirely new governance philosophy. It requires the existing principles this series has already established, applied with seriousness to a category of tool that acts rather than merely advises.
The Specific Failure Pattern Worth Naming Directly
A documented, common failure mode in agentic AI deployment is authority creep: a system initially deployed with narrow permissions and close human confirmation requirements has those requirements gradually relaxed and its autonomy incrementally expanded over time, without any single, deliberate decision point where someone considered whether the system's authority should have grown that far. The result is a system now operating with high-stakes decision authority while still being governed with the light oversight appropriate to the cautious pilot it started as. No one made a bad decision. No one made the decision at all, and that is precisely the failure.
- Build and maintain a complete inventory of any AI agents or automated decision-making tools operating within your association's systems, given how easily this visibility gap develops.
- Explicitly define, in writing, what any autonomous AI system is authorised to do, what it must never do, and precisely who is accountable for its actions, rather than allowing this to remain implicit.
- Treat any expansion of an AI system's autonomy as a deliberate decision requiring the same scrutiny as the original deployment, rather than allowing permissions to creep upward incrementally and unnoticed.
- Hold management, not the AI system itself, fully accountable for outcomes, connecting directly to the AI governance discipline discussed earlier in this series, applied now with urgency to systems that act autonomously.
- Maintain logging, audit trails, and emergency stop capability for any AI system with real operational autonomy, ensuring the board can trace exactly what the system did and why if something goes wrong.
Agentic AI represents an evolution in capability, not an evolution in the governance principles required to oversee it responsibly. The board's task remains what it has always been: govern strategy, risk appetite, and accountability, resisting the pull toward operational involvement while ensuring management has built deliberate boundaries around exactly how much autonomy these systems have been given.
This is one of the practical governance topics built into our Association CEO course — alongside the papers, tools and frameworks that turn the principle into your board's actual practice. Explore the course →
— Annie