tech_surveillance1386 wordsRead on Arc Codex

How much should you authorise your AI agent to do?

Agentic AI means that leaders must now decide how knowledge, authority and action are distributed between people and machines. Mark Dawson highlights a new teaching case where agents are treated not as software but as teammates. This metaphor forces leaders to ask: what is this agent allowed to do and learn, and what happens to that knowledge afterwards? Artificial intelligence has entered a new phase. The first wave of generative AI in organisations was largely about assistance: drafting text, summarising information, generating code, producing reports and helping people work faster. But this next phase is different. AI has now become agentic. Agentic AI does not wait for a prompt and produce an answer. It can act across workflows, connect to tools, co-ordinate tasks, make recommendations, trigger actions and work with a degree of persistence. The direction of travel is increasingly clear: AI is moving from something people use to something people work alongside. That shift has profound implications for leadership. A new teaching case, developed by Niki Panteli and Reena Pathak of the Cyber Leadership Forum, offers a useful way to think through this shift. The case follows Maya Mercer, the head of Cyber Defence at the fictional Meridian Water & Power, a British critical national infrastructure operator. Over two years, Ms Mercer’s team moves from a fragmented, alert-saturated security operations centre to one supported by three custom multi-agent systems: one for incident analysis, one for detection engineering and one for threat intelligence. The case culminates in a decision. With strong early results and growing executive enthusiasm for becoming a “frontier” organisation, should Ms Mercer allow the incident-analysis agent to move from “recommend” to “act”, allowing it to take limited containment actions without waiting for human approval? Or should she hold the system at human-in-the-loop oversight while the organisational foundations continue to mature? This is a teaching case about cybersecurity. But its significance is much wider. It captures a leadership dilemma that many organisations are now facing: how far, and how fast, should leaders delegate organisational action to artificial agents? A new way of working The case is valuable because it avoids both technological hype and technological rejection. It does not present AI as a magic productivity solution. Nor does it treat it simply as a threat to human work. Instead, it shows the practical work of responsible leadership: defining the right problem, building the data and process foundations, creating guardrails, measuring value and risk, addressing job anxiety and deciding what kind of human judgement must remain in place. A traditional model of leadership assumed that managers co-ordinated human expertise, organisational resources and institutional knowledge. Tools supported that work, but they did not themselves become participants in organisational decision-making. Agentic AI unsettles that assumption. When AI systems generate recommendations, interact with one another, monitor workflows, trigger actions and require oversight, leadership is no longer only about managing people who use tools. It is about governing hybrid systems of human and artificial agency. This is why the case’s central metaphor – agents as teammates – is so important. In Meridian, the agents are not treated as ordinary software. They are given job descriptions, access controls, performance expectations and review processes. They are onboarded, coached and gradually trusted. Model upgrades are treated almost like promotions, prompting a fresh review of permissions, risks and responsibilities. Some firms already operate like this. It does not mean pretending that agents are people. Doing that would be a mistake. AI agents are not moral subjects. They cannot be accountable in the way that humans are accountable. But the teammate metaphor does important organisational work. It forces leaders to ask: what is this agent allowed to do? What does it need to know? Who supervises it? What counts as good performance? What happens when it fails? When should trust be extended, and when should it be withdrawn? These are leadership questions, not technical questions. The fifth discourse The case also helps us understand the wider implications of what I call the fifth, or algorithmic, discourse. The four discourses developed by Jacques Lacan, a French psychoanalyst working in the 1960s, offered a way of thinking about how authority, knowledge and subjectivity are organised in social life. My work extends this framework to the contemporary organisation, where knowledge is increasingly produced, circulated and authorised through algorithmic systems. In this discourse, AI is not just a tool for accessing knowledge. It becomes part of the machinery through which organisations decide what counts as knowledge, what requires action and what can be trusted. The Meridian case makes this visible. The AI agents do not simply provide information to human analysts. They help triage incidents, manage detection rules, ingest threat intelligence, generate hypotheses, recommend call-outs and prepare the ground for possible automated containment. Knowledge is not merely held by human experts and then applied through technology. It is increasingly co-produced through human-agent systems. This also connects to a wider strategic shift in how organisations create and protect value. Satya Nadella, the chief executive of Microsoft, has has argued that firms will increasingly need to compound two forms of capital. The first is human capital, the judgement, expertise, relationships and pattern recognition of people. The second is “token capital”, the proprietary AI capability, workflows and learning systems an organisation builds and owns. In that framing, agentic AI is not simply a labour-saving tool; it becomes part of an organisational learning loop. Every investigation, escalation, override, detection rule, failed hypothesis and human correction can become a signal that improves the system. The leadership challenge is therefore not only whether agents should be allowed to act, but whether the organisation is deliberately capturing, governing and protecting the knowledge created through human-agent collaboration. If that learning loop is not owned and governed by the organisation, the value of its expertise may leak into tools, suppliers or models it does not fully control. This changes the work of leadership again. Leaders must not only decide what agents may do; they must decide what agents are allowed to learn, what knowledge is retained, what must remain explainable and how human judgement continues to shape the system over time. The firms that succeed will be those that treat agentic AI not as a shortcut around human expertise, but as a disciplined way of compounding it. This is the deeper leadership challenge: agentic AI does not eliminate judgement; it changes where judgement is located. The decision facing Mercer is not whether AI is useful. The case has already established that it is. Triage is faster, false positives are down, analysts have more time for proactive threat hunting and the organisation can measure real operational gains. The harder question is whether a system that has proved useful as an adviser should now be allowed to act. That distinction (from recommend to act) may become one of the defining leadership thresholds of the agentic AI era. When AI recommends, humans can still imagine themselves as the final site of judgement. When AI acts, even within limits, the organisation has delegated part of its agency to a system. That delegation may be justified, but it must be designed. It requires audit trails, confidence scoring, independent verification, clear thresholds, rollback procedures, human override, regulatory engagement and ongoing attention to workforce trust. The teaching case, which will be included in an MBA curriculum taught at Lancaster, makes this dilemma especially clear. The strongest answer is not a simple yes or no. It is conditional. Leaders may move towards autonomy, but only through narrow, reversible steps; only where the blast radius is limited; only where confidence thresholds are meaningful; only where humans can intervene; and only where the organisation can explain what happened after the event. This is responsible leadership in the fifth discourse. It is not anti-AI. It is not nostalgic about a world in which human experts made all decisions unaided. But neither does it collapse judgement into automation. It recognises that as algorithmic systems become more capable, the task of leadership becomes more demanding. Leaders must now decide how knowledge, authority and action are distributed between people and machines. This article gives the views of the author, not the position of LSE Business Review or the London School of Economics. You are agreeing with our comment policy when you leave a comment. Image credit: Taris Tonsa provided by Shutterstock.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.