Compounding Intelligence

Governance is control, not theatre

AI Authority: Who Signed Off on What the Agent Decides?

Ramp built finance agents that approve low-risk expenses on their own and escalate the judgement calls to a named human. The design decision that made it work draws the line between what the agent decides and who owns the decision.

By Christopher Hughes

21 July 2026

In a growing number of finance teams, an AI agent now approves a low-risk expense on its own and escalates the judgement calls to a named human. Someone drew that line between what the agent decides alone and what a person still owns. Unfortunately, in most organisations no one did, because AI reports to the function that runs the platform, not the one that runs the work.

Agents Now Act, and the Authority Was Never Assigned

An AI agent is not a chatbot. A chatbot answers a question; an agent executes a chain of work and makes a bounded decision inside a scope someone set. That distinction is the test for whether this article is about your organisation yet, and for most it now is.

MIT Sloan Management Review and BCG found in 2025 that 76% of executives view agentic AI (software that plans, acts, and coordinates, rather than one that only responds) as more like a coworker than a tool. [1] A coworker only exercises authority once someone has granted it.

Gartner's 2026 survey of chief executives puts a number on how fast that authority is spreading. 80% expect AI to force a high or medium degree of change to their operational capabilities, and while 54% say automation is limited to specific tasks today, only 13% expect to remain there by the end of 2028. [2] The work an agent does is growing, and so is the authority it carries.

The default wiring sends that authority to the wrong place. Foundry's 2025 survey found that of the organisations employing a Chief AI Officer, 40% report to the chief executive and 24% to the chief information officer, with the chief operating officer not a meaningful reporting line at all. [3] AI answers to the function that owns the platform, and the authority the agent exercises on that platform belongs to whoever owns the work.

The Returns Gap Is the Ownership Gap

The measurable failure of agentic AI is not technical. McKinsey's November 2025 research found that 88% of organisations now use AI regularly in at least one business function, yet only 7% describe their AI deployment as fully scaled across the organisation. [4] Adoption is near universal, scaling is rare, and something structural sits in the gap between them.

Bain's 2026 survey puts a shape on that gap. Responsibility for AI outcomes is split almost evenly across IT, business functions, and central teams, with no clear owner in most organisations, and 37% of companies targeted savings of 11% to 20%, while only 29% reached that level. [5] The gap between the budget and the return is the gap between the many owners and the none.

Gartner puts a forward number on the cost of leaving the line unassigned, and it appears twice for two different reasons. More than 40% of current agentic AI projects will be cancelled by the end of 2027, killed before they deliver value on escalating cost, unclear business case, and inadequate risk controls. [6] No one owned the redesign, the value model, or the authority boundary, so the project never cleared the gap.

Ramp Bounded the Agent's Authority by Design

Ramp, a finance-automation platform, launched Agents for Controllers on 10 July 2025, and it works because the team designed the authority boundary in from the start. [7] The agents review company expenses, approve the low-risk items on their own, and escalate the judgement calls to a human approver with a stated rationale. The human keeps authority over exactly the decisions that need it.

Ramp reports 99% accuracy on what the agents recommend, defined precisely as the share of transactions the agent recommended for approval that a human reviewer also approved. [7] Treat that as a vendor-reported figure: the baseline transaction complexity, the size of the finance team, and Ramp's definition of low risk are not independently disclosed. The load-bearing point survives the caveat, because it describes the shape of the model, not the size of the number.

The role change is concrete in a customer's own words. Richard Gobea, finance manager at Quora, describes it plainly: "Before Ramp agents, we manually reviewed 100% of transactions. Now, Ramp agents take the first pass and flag what actually needs our attention." [7] His team stayed in the loop; the agent just moved the routine cases out of it.

An escalation is only a boundary if the human it reaches can actually overturn the agent. The UK Information Commissioner's Office sets that bar as meaningful human review: the reviewer needs the knowledge, authority, and independence to challenge and change the outcome, not a ceremonial sign-off. [8] Clicking approve without the standing to reject is not a control.

Ramp's Agents for Controllers place the authority boundary at the point of escalation, designed in rather than applied after an incident.

DBS Named the Owner, Not Just the Boundary

Bounding the agent is necessary but not sufficient. A boundary with no one accountable for it is a setting, not a mandate. At DBS, the redesign sits inside a named operating leader's remit: group chief operating officer Derrick Goh, appointed in April 2025 with oversight of both operations and transformation, is directly accountable for it. [9]

The mechanism carries the same authority boundary as Ramp's, placed in a bank's core work. Credit memos are drafted by more than 70 agents and reviewed by credit managers who hold the authority to reject. [9] The agent drafts, a person with standing decides, and an operating executive, not the platform function, owns accountability for the redesign.

An agent that is bounded is not the same thing as an agent whose boundary someone owns. At DBS, the line has an author.

What a Board Should Decide Now

Design the authority boundary before you scale the agent, or you find it after an incident. Klarna automated much of customer support with an agent it said did the work of 700 people, then acknowledged to Reuters ahead of its September 2025 listing that it had "over indexed a little bit" on cost and had spent six months course-correcting. [10] The fix came from redesigning the operating model, and it came after the automation rather than before it.

Capability is running ahead of the authority to trust it. Bain's 2026 data shows most organisations still keep a human approval gate or guardrails on their agents, with fewer than one in ten running fully autonomous in production. [5] Leaders are already sensing that an unowned boundary is a live exposure.

Place ownership of that boundary with the executive who owns how work is done, and measure the mandate on impact, not on agents shipped. The full four-part mandate for that operating leader, and the method for setting it, is in the Modern COO paper on cgh.dev. [11] The agents are already deciding; the question this week is who authorised what they decide.

Key Takeaways

  • Draw the authority boundary before you scale the agent: what it decides alone, what it escalates, and to a named human with the standing to overrule it. Gartner expects more than 40% of organisations to demote or decommission autonomous agents by 2027, after production incidents expose a boundary no one had designed. [12] That is the price of leaving the line unowned.
  • Measure the mandate on workflows redesigned and value delivered, not on agents shipped. The deployment count answers the easy question and hides the one that determines returns.
  • Set the escalation bar at the ICO standard: the human the agent escalates to must have the knowledge, authority, and independence to actually reject its output, not a rubber stamp. [8]

Sources

[1] MIT Sloan Management Review and Boston Consulting Group. "The Emerging Agentic Enterprise." MIT Sloan Management Review, November 2025. https://sloanreview.mit.edu/projects/the-emerging-agentic-enterprise-how-leaders-must-navigate-a-new-age-of-ai/

[2] Gartner. "Gartner Survey Reveals 80% of CEOs Say Artificial Intelligence Will Force Operational Capability Overhauls." Gartner Newsroom, 23 April 2026. https://www.gartner.com/en/newsroom/press-releases/2026-04-23-gartner-survey-reveals-80-percent-of-ceos-say-artificial-intelligence-will-force-operational-capability-overhauls

[3] Foundry / CIO. "CAIOs' role reclaims its position from that of CIO." CIO / State of the CIO Survey 2025, February 2025. https://www.cio.com/article/3845414/caios-role-reclaims-its-position-from-that-of-cio.html

[4] McKinsey & Company. "The State of AI in 2025: Agents, Innovation, and Transformation." McKinsey, 5 November 2025. https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai

[5] Bain & Company. "Your AI Budget Is Growing. Your Returns Aren't. Here's Why." Bain & Company, 1 June 2026. https://www.bain.com/insights/your-ai-budget-is-growing-your-returns-arent-heres-why/

[6] Gartner. "Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027." Gartner Newsroom, 25 June 2025. https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027

[7] Ramp. "Ramp Introduces AI Agents to Automate Finance Operations." PR Newswire, 10 July 2025. https://www.prnewswire.com/news-releases/ramp-introduces-ai-agents-to-automate-finance-operations-302502154.html

[8] Information Commissioner's Office. "Human Review." Data Protection Audit Framework: Artificial Intelligence Toolkit. https://ico.org.uk/for-organisations/advice-and-services/audits/data-protection-audit-framework/toolkits/artificial-intelligence/human-review/

[9] DBS Bank. Operating Model Transformations and 2025 AI outcomes, DBS 2025 Annual Report. https://www.dbs.com/annualreports/2025/i/pdf/dbs-ar-2025.pdf (Group COO appointment, Derrick Goh, effective 1 April 2025. https://www.dbs.com/Bod/gmc-derrick-goh)

[10] Supantha Mukherjee and Echo Wang. "Sweden's Klarna shifts AI focus from cost cuts to growth." Reuters, 10 September 2025. https://money.usnews.com/investing/news/articles/2025-09-10/europes-ai-poster-child-klarna-taps-the-brakes-on-chatbots

[11] Christopher Hughes. "The Modern COO: How Agentic AI Is Forcing Boards to Rethink Governance." cgh.dev, 11 July 2026. https://cgh.dev/thinking/modern-coo/

[12] Gartner. "Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure." Gartner Newsroom, 26 May 2026. https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure