Staying in Charge When AI Does the Work
Who will make it? — condensed edition
Agents do not advise, they commit. This is about the layer that decides whether the why and the what stay with a named human — and what that does to companies and careers.
An agent in a company's treasury is compromised by a poisoned document. With perfect confidence, it prepares a €2.4 million transfer to an account it has never used. It has the access; it could reach the whole treasury. It asks for permission to send. Refused. Not for lack of access, but for lack of a mandate. Nothing moves. The refusal is written down with a person's name and a time, and the security team reads it four minutes later.
That is the difference between a company that has adopted AI and a company that is still in charge of it. This document is about that difference.
The mechanism argued for here is not ours to sell. It is specified in the open as the Human Agency Protocol, MIT-licensed, and this document uses its vocabulary: mandate, ticket, record. Anyone may implement it.
Suveren is one implementation, built by the protocol's authors — so read this as an argument with an interest behind it. It is an argument about the layer, not about any product. If the argument holds and someone else builds it better, the argument still holds.
A chatbot can only advise you. An agent can commit you.
Every piece of work splits into three questions. Why are we doing this? What exactly should happen, and what must never? And how do we get it done?
For as long as there has been work, the jobs were in the how. That is exactly what AI is now taking: completely, and better every year. This is true, and pretending otherwise helps no one.
But look closely at what is taking it. It is not the chatbot, the kind of AI you ask a question and it answers. It is the agent: AI that is given a goal and then acts on it, using the same tools a person would. It reads the inbox and replies. It looks up the order and issues the refund. It writes the code and deploys it. It books, buys, files, and negotiates, step after step, for hours, without anyone watching at each step. A chatbot produces words you then act on. An agent produces the act itself. Every company is now being sold agents, and every employee is already using them. The difference between these two kinds of AI is the entire subject of this document. A chatbot can only ever advise you. An agent can commit you.
The why and the what feel like the light part: a sentence, a signature. In truth they are the whole game. Whoever holds them stays in charge. Whoever hands them over only executes what someone else decided. And that door goes one way. Judgment survives only in use. And the proof of who decided forms around whoever actually did.
This is happening to persons, companies, and societies at once, for the same reasons, and it is happening fast. The companies building these systems say so themselves: they expect machines that outperform humans at most economically valuable work within years, not decades. Whether that takes three years or fifteen, the direction is clear, and it changes the stakes in one specific way. Every increase in capability makes it more tempting to hand over the why and the what. It does nothing to the machine's ability to answer for them. A more capable executor is a more persuasive one. It proposes better goals, frames better options, is right more often. That is exactly what makes deferring to it look like wisdom rather than surrender. Even a system that out-thinks every human on every question cannot be fined, shamed, or made careful, because nothing can happen to it. Capability and accountability are two different axes. Only one of them is rising.
So there is one place where the future gets decided. It sits between the person who wants something and the machine that does it. That is where it is settled whether the why and the what stay with a named human, or drift quietly to a vendor, a policy, or a machine. In engineering, a place like this is called a layer: something every action has to pass through before it happens. Call this one the authority layer. It will exist either way, whether anyone builds it deliberately or not. The only question is who owns it. And the time to decide is now, on the way up, while humans are still visibly needed. Nobody builds an authority layer after the fact, once the executor is already smarter than the people who would have to insist on one.
You ask an AI what to cook. Then what to write in the difficult email. Then whether to take the job. Then whether the friend is worth keeping. Each step is reasonable. By the fourth you are executing a life someone else is directing, with your own hands.
Why people hand it over
People do not surrender authority because they are forced to. They surrender it because it is comfortable.
Milgram showed sixty years ago that ordinary people will do terrible things when a man in a lab coat tells them to. Not from cruelty, but because a person who sees themselves as merely carrying out another's authority stops feeling responsible for the act.1 It is the psychology of every executor, and it is open to anyone who lets a machine hold the why.
With machines it gets worse. AI sounds equally fluent inside and outside its competence. In a study of consultants, those working with AI did dramatically better on tasks the AI could handle, and measurably worse on tasks just beyond it, because the AI sounded equally confident on both sides.2 Put a person with everything at stake next to something with nothing at stake. The machine never hesitates, because nothing can happen to it. The person defers. Not because the machine is wiser, but because it is surer.
And what we hand to tools, we soon cannot do ourselves. Habitual GPS users lose the ability to find their own way; the brain keeps no spare copy of a skill it has outsourced. Neither does judgment. The reverse is measurable too. Nursing-home residents who were given control over small daily choices were more alert, more active, and eighteen months later more of them were alive.3 Autonomy is not a luxury. It is a basic need, and it is the first thing a comfortable executor gives up.
Action with no person behind it
When no one's name is on the act, something worse than a mistake happens: responsibility stops existing. Call it the fog. Action with no person behind it.
The more people who witness an emergency, the less likely any one of them acts. Organizations turn this into a system. Committees decide so that no one has. Policies act so that no one did. Dan Davies calls these accountability sinks: structures built so that when something goes wrong, there is no one to point at.4 Automation thickens the fog in a cruel way. The human placed in the loop to catch the machine's failures is the very person the machine has deskilled.5 And when the failure comes, blame lands on them anyway. They are the "moral crumple zone," absorbing responsibility the way the front of a car absorbs a crash.6
Here is how this happens in practice. To let an agent act in the world, a company gives it access: a login, a key, a token for the payment system, the mailbox, the servers. A key opens the door every time, for anything, and it never asks who is turning it. So the one actor in the building with no stakes gets the one tool where the stakes are highest. When something goes wrong at four in the morning, the boss asks who allowed it. The honest answer is: nobody. A configuration file did, set by someone who left in March. That is the question every auditor, insurer, and regulator is now learning to ask: who approved this specific action? The fog is the state of having no answer.
Why is this a problem now? Organizations have lived with diffused responsibility for a century. The answer: the fog was never complete. The last mile always had a person in it. Every consequential act was performed by someone with a name, a job, and a stomach. Someone who knew what was normal. Who hesitated at what wasn't, and asked "are you sure?" before pressing send. That person carried an unspoken authority layer inside them: they bounded the action, they escalated, and they could be pointed at. That is why everyone self-regulated. The fog sat at the top. It never reached the bottom, because the bottom was made of people who could be fired. An agent removes that person from the act. No name, no hesitation, no fatigue, no witness when it is talked into something, and no one to point at. So the fog now runs unbroken from the boardroom to the bank transfer, ten thousand acts a night. The human executor was quietly doing the accountability work the institution had abdicated. Nobody noticed, until the executor was replaced by one that has no gut.
Making the agent's access smaller does not lift the fog. That problem is being fixed, with narrower keys, a separate identity for each agent, and tighter permissions. But a narrow key used ten thousand times a month, with no human's name on any single use, is still a key with no name on it. The fog is not about how far the agent can reach. It is about whose act it is when it reaches.
The economics of who stays in charge
Companies have employees because supervising outsiders is expensive. You hire people and build hierarchies that relay authority down and check compliance up.9 When a person sets limits once and every action the agent takes is provably inside them, that cost collapses: you check the mandate once, and the ticket proves the rest. The middle layer loses its reason to exist. What survives is the why, the what, and the name.
Underneath sits a darker finding. In most companies, the people who rise are not the most competent. They are the best at attaching themselves to wins and detaching from losses.10 That is not because people are bad. It is what works when nobody can prove who did what. When proof is fuzzy, being good and looking good are interchangeable, and looking good is cheaper to learn. So real competence stays the exception and blame-management the rule. Enforced attribution ends the trade. When every consequential act traces to a name, the career built on dodging dies, and competence becomes the only remaining path.
The stakes are not a cost of this. They are its value. A proof of ability only works if failing would have been costly. A record built where every mistake would have been written down just as permanently cannot be faked, bought, or backdated. If it were riskless, everyone would have one, and it would prove nothing. And none of this is new where stakes are highest. After Enron, CEOs and CFOs had to personally certify their financial statements. Engineers stamp drawings and are liable for the building. Hammurabi held the builder answerable with his life. Civilization has always known the act needs a name. It only forgot when the actor stopped being a person.
The amplified employee, honestly
A company is its people, and the evidence on AI-amplified people is strong: more tasks, faster, at higher quality.2 The largest gains go to the newest workers.11 And in a field experiment at Procter & Gamble, one person with AI matched a two-person team without it.12 The floor is rising. An employee without AI is not standing still. They are sinking, relative to everyone else.
But read it carefully. Every one of these studies measures the assistant mode: the human still does the work, the AI helps, and the human reviews every output. The step where the agent executes and the person only mandates is too new for field experiments. Quoting the consultant numbers as proof of the agent economy is extrapolation. The honest case stands on three legs. First: the assistant studies prove the value at the most supervised end. Second: bounded full delegation has been studied on humans for a century, in mission command, in decentralized firms that outperform in turbulent times,13 in franchising, and it beats both micromanagement and unbounded delegation. Third: the failure record at the unsupported step is already in. Gartner expects over 40% of agentic projects to be canceled by 2027, and names inadequate risk controls as the reason.14 MIT found 95% of enterprise pilots delivering no return, while employees in over 90% of firms ran their own AI in the shadows.15
That last number is the diagnosis. Privately, people adopt fast: 16% already use AI that acts on their behalf, one in nine for unattended banking.16 Why fast at home and slow at work? Because at home they are the authority. At work there is no way to hold bounded authority. So the choice is: ask permission for everything, or use it in the shadows. And they choose the shadows. The gap is not a lag. It measures the missing layer. Mandates are how you legalize the shadow economy you already have.
The studies measure AI making executors faster. The open frontier is AI making authorities larger, and that frontier is exactly where the authority layer sits.
Why limits make you faster
"Work isn't just producing things," the objection goes. "It's communicating, aligning, finding a time to talk." Agreed, completely. Coordination is most of the how; professionals spend well over half their hours in meetings, email, and chat.17 But the objection has just described the most automatable part of all. Finding a slot, confirming a scope, chasing a status: all of it follows a script. Agents eat it first.
Two gains stack. Alone, your agent doesn't make any single exchange faster; the counterparty still takes three days. But it runs forty other threads meanwhile. Tasks don't shorten; your capacity to have them in flight multiplies. Then, as counterparties adopt, the exchanges themselves collapse to seconds. And coordination works like a telephone network: its value comes from who else is on it. Whoever stays off it after critical mass is not slowed but routed around. Ports that didn't containerize lost the shipping.18 Suppliers who wouldn't take electronic orders lost the shelf. A process runs at the speed of its slowest step, and slow nodes get replaced.
Here is the turn. Every alignment an agent performs is a commitment, a scope confirmed or a term conceded, and commitments bind you. Forty threads in flight is already more than any person can supervise. At machine speed you cannot review any of it. The mandate is not the brake on fast coordination. It is the license for it: commit up to this scope, this budget, these dates. Above that, ask me.
And there is an edge. In negotiation, a visible, enforced limit is power: the party who can credibly bind itself wins concessions the merely stubborn cannot.19 Unbounded agents can be pushed and worn down. A mandated agent's no is structural. As your customers' agents start choosing counterparties by what they can verify, the business whose limits are provable is the one they can safely transact with.
The digital-employee fallacy
The largest AI companies plan to rent "digital employees." The word is wrong. An employee holds role authority, draws a salary, and can be held responsible. An agent has none of these. What a vendor rents is execution. That is fine; businesses have always rented execution. What it cannot rent is authority, because authority comes bundled with accountability, and accountability is exactly what the vendor disclaims in its terms of service. The "employee" arrives with a key to your systems and a contract saying whatever it does is your problem.
Cloud providers learned this a decade ago. They could not sell infrastructure until they drew the line: security of the cloud is ours, security in it is yours.20 AI vendors will draw the same line. The moment they do, every customer needs the thing that lets them hold that responsibility rather than merely be assigned it. And if the vendor owns that layer too, the executor, the mandate, and the record, then it knows every consequential decision you make, holds the proof, and sets the renewal price. Renting the how from anyone is fine. Renting the why from anyone is the end of the company.
This is why the layer has to be open, and why it already is. The Human Agency Protocol exists precisely so that no vendor can own the mandate, the ticket, or the record: any compliant implementation can issue tickets, and a ticket issued by one can be checked against a published key by whoever holds it. It is not a safety filter, not a login, not a rulebook the software checks, and not a log you read afterwards. It works alongside all of those, and it is the one thing none of them provide: a name on the act, before the act.
Meta's Project OT, reported by Reuters in August 2026, explored cutting some teams by up to 60% and letting agents take the work, with "agent-assisted analysis" setting daily priorities. Internal data: code changes up 220%, user-facing features up 36%. Incidents up 40%, firefighting up 70%. And an internal warning of unchecked agents performing "large-scale, disruptive actions that humans are unlikely to execute." The second wave was called off hours before the first one went ahead, by a decision no one explained in public. Nobody's name was on the plan. Eight thousand people's names were on the outcome.21
Who will make it
The future sorts people along two lines. Do you hold a what, a decision about what may happen and what must never? And will you put your name on it?
Be precise about the first line, because the comfortable belief is that experts survive by seeing what machines miss. They don't. Patterns are claims about the world, and machines read them better than we do. But a pattern tells you what usually happens. A limit is a decision about what you are willing to have happen. The model can tell you a certain refund is fraudulent three percent of the time. It cannot tell you whether three percent is acceptable, because the data does not contain what your business can survive. So execution was never the seat of value. It only looked that way while execution was scarce, because doing something well was how a person demonstrated judgment. Now the bundle comes apart, and what was always doing the real work stands exposed: someone deciding what may happen, and answering for it. Experience matters enormously, as input to that decision. Never as a substitute.
Those who hold a what and will sign it rise: the quiet expert, revalued the moment attribution becomes verifiable. The small and sovereign, whose portable record fixes the one disadvantage that always beat them. The young and unconnected, who can build in two years what no résumé ever gave them. Those who fall are mostly not villains: the credit-taker, whose skill no longer applies. The confident narrator, whose fluency without a record gets repriced. The supervisory middle, obsolete because the mandate replaced the relay and the ticket replaced the check.
Organizations sort the same way. Hierarchies of supervision dissolve, and hierarchies of accountability replace them: trees of mandates, each node a named person answerable for a scope, under one rule — each mandate may only grant less than it holds. That nesting is an organizing principle today, enforced by how an authority is configured rather than by something a sub-mandate can prove about itself. Making it provable is specified, open work; it is not yet a finished part of the standard, and this document does not claim otherwise.
The bottom line is the one-way door. Keep authority, and the machines make you larger. Give it up, and you do not get it back. The judgment atrophies, the record forms around whoever actually decided, and you discover, too late, that you have been executing someone else's why with your own hands.
She is twenty-six, from nowhere in particular. She takes small mandates: narrow limits, ninety days, asks first almost always. And she signs well. Three years later she has eight hundred tickets and zero outside the limits. The firm that hires her doesn't check her references. It checks her tickets.
What to do on Monday
For a company, four moves. None of them requires buying anything first.
Count the keys.
List every agent that already holds a login, an API key, or a token to anything that moves money, sends messages, or changes systems. Beside each one, write the name of the person who allowed its acts. Wherever you cannot, you have found the fog. Most companies find it in the first hour.
No mandate, no key.
Before any agent touches money, messages, or changes, a named person writes the mandate: purpose, limits, what runs alone, what asks first, expiry. Start narrow. Ninety days. Ask-first by default. Widen the limits as the tickets come back clean. This is also how you bring the shadow AI your staff already use into the open: not by banning it, but by giving people a way to hold bounded authority.
Buy execution, never authority.
Any vendor's agent is fine. Any vendor who wants to own the mandate, the ticket, or the record is not. Ask one question in every procurement: can I check a ticket myself, against a published key, without asking you to confirm it? If the answer is no, the vendor is not renting you the how. They are renting you the why.
Move the org chart from supervision to accountability.
Stop asking managers to check work the agent did. Ask them to hold a scope, sign the mandates inside it, and answer for them. Each mandate may only grant less than the one above it. The middle of the company stops relaying and starts deciding, and it is judged by its record, not its reporting line.
The personal rule
The company needs a gate. A person just needs to remember one thing: whose act it is.
I hold the why and the what. The AI may help with the how. Anything about who I am, what I want, who I keep, asks me first, and I answer myself.
"Draft a reply that says no politely" is a how. "Should I say no?" is a what. The moment you notice you are asking the machine what you should want, that is the four-a.m. moment. Nothing has gone wrong yet. Everything is about to.
Whose act is it?
Ask it of the recipe, the refund, the permit, the pivot, the job, the friend. Today the answer dissolves: the agent's, the vendor's, the policy's, the department's. None of them can be asked why. Under a mandate, the answer is always a name.
People stay in charge. AI does the work. And everyone can prove it. That is not a safety feature. It is the decision about who will make it in the coming century, made one ticket at a time, by whoever refuses to hand over the why.
- Milgram, S. (1974). Obedience to Authority. Harper & Row. ↩
- Dell'Acqua, F., et al. (2023). Navigating the jagged technological frontier. HBS Working Paper 24-013. ↩
- Langer, E. J., & Rodin, J. (1976). JPSP, 34(2); Rodin & Langer (1977). JPSP, 35(12). ↩
- Davies, D. (2024). The Unaccountability Machine. Profile Books. ↩
- Bainbridge, L. (1983). Ironies of automation. Automatica, 19(6). ↩
- Elish, M. C. (2019). Moral crumple zones. Engaging Science, Technology, and Society, 5. ↩
- Weber, M. (1922/1978). Economy and Society. University of California Press. ↩
- Bungay, S. (2011). The Art of Action. Nicholas Brealey. ↩
- Coase, R. H. (1937). The nature of the firm. Economica, 4(16). ↩
- Pfeffer, J. (2010). Power. HarperBusiness; Benson, A., Li, D., & Shue, K. (2019). Promotions and the Peter Principle. QJE, 134(4). ↩
- Brynjolfsson, E., Li, D., & Raymond, L. (2025). Generative AI at work. QJE, 140(2). ↩
- Dell'Acqua, F., et al. (2025). The cybernetic teammate. NBER WP 33641; Organization Science (2026). ↩
- Aghion, P., Bloom, N., Lucking, B., Sadun, R., & Van Reenen, J. (2021). Turbulence, firm decentralization, and growth in bad times. AEJ: Applied, 13(1). ↩
- Gartner (2025, June 25). Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027. ↩
- MIT NANDA (2025). The GenAI Divide: State of AI in Business 2025. ↩
- EY (2026, March). AI Sentiment Study, 2nd ed., 18,152 respondents, 23 markets. ↩
- Microsoft (2023). Work Trend Index; Cross, R., Rebele, R., & Grant, A. (2016). Collaborative overload. HBR. ↩
- Levinson, M. (2006). The Box. Princeton University Press. ↩
- Schelling, T. C. (1960). The Strategy of Conflict. Harvard University Press. ↩
- Amazon Web Services. Shared Responsibility Model. ↩
- Paul, K. (2026, August 26). Inside Meta's stalled plan to replace thousands of workers with AI. Reuters. ↩
People stay in charge. AI does the work. And everyone can prove it.
The protocol argued for here is the Human Agency Protocol — MIT-licensed, open to any implementation. Suveren is one of them. See it work on your own use case →