The One-Degree Dispatch

The Word That Moves Authority

2026 · Authority · 3,549 words

The ambiguity in defining "agents" risks shifting unchecked authority into automated systems, jeopardizing enterprise governance and liability.

Permission, not inference, decides who gets paid. That line is not a slogan. It is an operating fact. The enterprise can detect failure in milliseconds and still take hours to authorize an intervention. In the gap, value leaks out between decisions and outcomes, and everyone learns the same lesson. It is safer to meet than to act. The ZDNET piece treated the MIT Agent Index as a warning. It should be read as a mirror. It did not reveal a fringe market. It described mainstream offerings that are already being sold into serious firms. The report behind it cataloged thirty deployed agentic systems and asked a question most buyers never force into daylight. If you claim agency, where is the proof that authority is bounded. A lot of the red in that table came from omission, not confession. A large share of the systems disclosed no internal safety testing. A large share did not disclose meaningful stop options. A large share did not disclose monitoring. Many did not even answer questions when asked. The signal is not that every vendor is reckless. The signal is that the market is still treating delegated authority as a marketing feature instead of a design requirement. The trap is that enterprises are treating the word agent like a capability label. It is not. It is a delegation label. When you call a system an agent, you are not describing what it can do. You are implying what it is allowed to do. That implication changes how humans behave around it. It changes how managers sign off. It changes how boards hear risk. It changes how operators trust or stop a line. It changes who gets blamed when the intervention causes harm. Here is the pivot that explains why the same failure keeps repeating in new forms. “What would have to be true for this outcome to keep repeating.” The answer is uncomfortable because it points back at us, not at the vendors. The outcome repeats because enterprises keep buying language when they need mechanisms. They keep approving pilots that prove intelligence and never prove authority. They keep asking whether the model is accurate and avoid asking who owns the outcome when the model is wrong. They keep deploying systems that compress judgment into narrative, then act surprised when the narrative begins to run the meeting. A fluent narrative often outweighs a correct but fragmented truth. Confidence travels faster than caveat. Coherence feels like understanding. Under time pressure, coherence substitutes for understanding. That is not a failure of anyone’s character. It is a property of organizations. It is also why the problem will compound. When the market sells “agent,” it is selling a story about reduced supervision. Reduced supervision is not agency. It is efficiency. A system that requires fewer check ins may prepare work faster and still wait at the moment that matters. That is why enterprises report improved throughput with no corresponding improvement in outcomes. They mistake motion for movement.

The word agentic emerged to signal something stronger than efficiency. It suggested consequence. It suggested that a system was beginning to do more than assist. But the label has outrun the architecture. Agentic is now often used as reassurance rather than specification. It implies progress without forcing leaders to answer the only question that matters. What decision rights moved, exactly. If no one can answer that clearly, then nothing moved, and the “agent” is theater. If decision rights did move, then you have created a new actor inside your firm. That actor needs the same things any actor needs. Clear authority. Clear constraints. Clear accountability. Clear evidence thresholds. A record of why it acted. A way to stop it when context changes. Without those, you do not have a real agent. You have a generator that produces recommendations the enterprise must interpret and absorb. You also have a new reason to hold more meetings. The irony is painful. The tools sold as a way to remove human intermediation can create more of it when they are not bounded. They add output that must be adjudicated. They add risk that must be shared. They add career exposure that must be diluted in groups. An agent must be able to shape an outcome or it is not an agent. That sentence is not semantics. It is accountability protection. It forces a clean boundary between assistance and delegated action. It forces you to answer whether the system is acting, or whether you are still acting and merely receiving a better narrative. The MIT Agent Index and the ZDNET framing matter because they touched the seam where value either appears or evaporates. If the system cannot cross the inference permission boundary, it cannot produce the economic outcomes being promised. If it does cross, it must do so under enforceable bounds. That seam is where most enterprise value is being lost today. Not because insight is scarce. Because permission is delayed. Not because people are foolish. Because they are rational under career risk. If you cannot prove the mechanism and the authority, the safest move is to align. If you cannot prove the audit trail, the safest move is to share the burden. If the system acts and there is no decision trace, the safest move is to slow everything down. This is why the red table is a leading indicator of a larger failure. It is a symptom of a market that has not yet accepted the real job. The job is not to produce clever outputs. The job is to produce bounded action with responsibility. That requires a different level of disclosure and a different level of design. Some vendors are already learning this, not because they are more ethical, but because it is the only way this category survives. The ZDNET summary pointed out that OpenAI’s own agent includes cryptographic signing of browser requests, which is an attempt to prevent impersonation and to make actions traceable to a specific agent identity. That is not a cosmetic feature. That is a recognition that delegated action requires provenance.

It is also a counterexample that keeps the argument honest. There are domains where permission is already delegated by design. A fraud filter can act under pre approved bounds. A content recommender does not need an executive committee. A credit system can operate under policy and audit rules that are already written. In those cases, improving inference can produce outcome speed because the permission gate is already tightened. The thesis is not that association systems are worthless. The thesis is that association marketed as agency creates false confidence, and false confidence does damage. The tragedy is that the market is blurring the categories at the exact moment that the categories carry legal, financial, and moral consequence. Call a system an assistant and you are asking for help. Call it an agent and you are delegating authority. If you do not treat that as a contract, you will treat it as a feature. Features can be vague. Contracts cannot. The liability trap is already visible. If a system is called an agent and treated like an agent, humans tend to abdicate judgment. When the intervention fails, the humans still own the bill. They owned it the whole time. The marketing just blurred it. That is not a theory. It is how organizations behave under ambiguity. When a tool appears competent, people lean. When it fails, people snap back. The snapback is not just technical. It is governance whiplash. The first failure triggers a crackdown that slows everything further. So yes, it gets worse. It gets worse because the market incentives reward the label more than the mechanism. “Agent” sells because it promises relief from cognitive overload. It promises less intermediation. It promises speed. The sales motion is stronger than the procurement motion because procurement is not built to evaluate delegated authority. Procurement can evaluate features, integration, and pricing. It struggles to evaluate bounded action in open environments, because the evidence required is different. It gets worse because enterprises are tired. They are tired of the committee process. They are tired of decision latency. They are tired of being compared to theater. Pretenders will answer with beautiful language and little identification. Claimers will pivot to branding and speed demos. If you cannot tell the difference, you are doing the work for them. It gets worse because the systems are moving from read to write. When a system summarizes, the harm is often indirect. It can still be serious, because summaries set frames and frames set decisions. But the moment a system can write into a system of record, the harm becomes direct. It can place an order. It can move money. It can change a schedule. It can open access. It can leak data. It can do so at machine speed. The enterprise will still decide at human speed unless permission is redesigned, and the mismatch is where losses appear. It gets worse because language systems compress judgment into narrative at a speed and scale that human organizations were never designed to absorb. They take fragmented signals and render them coherent. They collapse uncertainty into story. They present tradeoffs in ways that

feel resolved even when they are not. Under time pressure, the story that holds together wins. When the story becomes the starting point rather than an input, authority enters systems that were never formally granted it, through repetition and convenience. It gets worse because most firms still do not have decision traces. They have logs. Logs record events. They do not record responsibility. A decision trace is different. A decision trace shows what the system believed, what evidence it used, what invariants bounded it, what alternative actions it rejected, what threshold triggered action, and what rollback authority it held. It is the difference between activity and accountable agency. Logs record activity. Decision traces assign responsibility. If you want to know whether your organization is set up to be harmed by agent theater, you do not need a big maturity model. You need to look at where permission lives. You need to look at whether your firm can delegate under constraints without requiring social consensus every time context changes. Consider the most common enterprise moment. A risk is detected early. Everyone agrees it is real. Someone asks who owns the decision. Someone asks for more proof. The line keeps running. The risk keeps compounding. The cost shows up later as scrap, overtime, missed shipments, and the kind of internal damage nobody tracks until it shows up as turnover and blame. The machine can infer a failure in milliseconds. The system can still take hours to authorize action. That is the problem. Now imagine that same pattern, but the “agent” is allowed to act without asking, and there is no clear evidence threshold, no invariants, no stop rule, no rollback authority, and no decision trace. What happens after the incident is not learning. It is politics. People will fight over the narrative because the system did not produce a record that can settle the dispute. The organization will respond by tightening permission in the wrong places, because it cannot distinguish a bad boundary from a bad actor. That is why the omission of stop options is not a UI problem. It is a governance failure. A stop option is not a button. It is an institutional statement. It says that delegation is conditional. It says that authority can be retracted when signals change. It says that the firm is not granting open ended power. It also says that someone is responsible for deciding when to stop, and that the decision can be made fast. When the MIT table shows missing stop options, it is showing missing contracts. It is showing missing clarity about where authority belongs. That clarity cannot be patched in later by policy memos. Policy memos do not run at execution time. Software does. This is where most enterprises and most institutions are still thinking like it is 2019. They are trying to solve an authority problem with literacy tools. They publish glossaries. They define terms. They hold training sessions. Those efforts are not wrong. They are incomplete in the only

way that matters now. They explain what systems do and avoid specifying what systems are allowed to do. A glossary answers what does this mean. An enterprise must answer what is this system now allowed to do. Those are not adjacent questions. They belong to different operating regimes. The institutions that should know better keep making the same category mistake because it is comfortable. It keeps the conversation safely academic at the precise moment it needs to become architectural. Terms describe behavior while leaving power untouched. They reassure without allocating responsibility. They pathologize users instead of examining systems. They explain limitation while avoiding authority. Language that does not force the authority decision is no longer neutral. It is evasive. So the market keeps drifting. “Agent” becomes a word that implies progress without forcing disclosure. It becomes a word that makes buyers feel modern. It becomes a word that lets vendors sell the idea of delegation without proving bounded authority. It becomes a word that lets leaders avoid redesigning permission because the label suggests the tool will do it. It will not. The risk is not intelligence. The risk is misdelegated authority. If you want to see the mechanism cleanly, treat “agent” as the newest form of the oldest organizational temptation. Responsibility is heavy. People look for ways to share it. Meetings share it. Committees share it. Labels share it. When you call a tool an agent, you can tell yourself the burden moved. If you do not also move decision rights, it did not. If you move decision rights without bounded authority, you moved the burden without the protection. There is a reason the ZDNET summary emphasized that many vendors did not respond to the researchers. Silence is not just bad manners. Silence is a business signal. It says the market still believes it can sell agency without the obligations of agency. It says the market believes buyers will not punish omission. It says the market believes the category can grow on trust without evidence. Enterprises are about to punish omission, but not in a thoughtful way. They will punish it after a public failure. The punishment will be broad. It will slow good actors and bad actors alike. It will be written as policy rather than engineered into execution paths. It will create compliance theater that feels safe and does not create control. If that sounds like an overstatement, ask a simple question. What happens when an “agent” makes a material mistake and you cannot answer, within hours, what it saw, why it acted, who approved the delegation, what invariants bounded it, and who could have stopped it. If you cannot answer those, the firm will not debate learning. It will debate blame. Blame makes people defensive. Defense makes people slow. Slow makes the next incident more likely, because the firm will keep living behind delayed permission while software keeps acting faster.

That loop is the real risk surface. You cannot solve it with better prompts. You cannot solve it with more guardrail language. You solve it by turning the inference permission boundary into a designed boundary, with explicit evidence thresholds, explicit invariants, explicit rollback authority, and decision traces that make accountability visible. If you want to pressure test whether a vendor understands this, you can do it without sounding like you are trying to win an argument. Ask them to describe, in plain language, where their agent stops. Ask them who can stop it, how fast, and under what signals. Ask them what record is written automatically when it acts. Ask them whether that record is sufficient for legal, audit, and operational review. Ask them whether the agent can be proven to be the actor, not an impersonated proxy. Ask them what happens when context changes and the agent’s prior plan is now wrong. If their answer requires a committee meeting, what is the point of the speed they are selling. If their answer is a demo that avoids those questions, they are selling theater. Now the two questions leaders avoid because they cut too close to the bone. Who benefits from ambiguity around “agent.” If the label stays loose, it sells more products, it sells more advisory hours, and it keeps accountability blurred when deployments stall. Who pays for ambiguity. The operator who takes the heat when the tool misfires. The manager who must sign off without proof. The firm that stalls deployments and calls it adoption. The customer who experiences the failure as a breach of trust, not a technical glitch. This is the part most should know better. The firm is not buying a model. It is buying a new actor. Actors require governance. When we skip that truth, we do not get speed. We get a new source of disorder. There is a fair objection that must be addressed cleanly. Some products that do not claim causality can still create real value. A forecasting system can reduce inventory. A classification system can improve inspection. A planning system can compress a cycle time. In those cases, the product is not causal and it can still be useful. There are also domains where permission is already delegated by design, so improved inference can convert to faster outcomes. The thesis is not that every system must sit on the top rung of causal reasoning. The thesis is that the word agent is being used to smuggle authority into systems without enforceable bounds. That smuggling is what will produce the next widely publicized failure. The prediction that follows should make any board uncomfortable, because it is specific enough to be wrong.

Within the next eighteen months, the majority of “agent” deployments inside large enterprises will stall not because the models fail, but because the permission architecture cannot name what the agent is allowed to do, under what invariants, with what evidence, and with what rollback authority. Those stalled systems will still be celebrated as pilots and capability building. The financial value will not show up where the business case said it would. The reason will be called adoption. The reason will be permission. If that prediction is wrong, it will be because leadership learned faster than it usually does. If it is right, it will be because the market kept selling inference as control. Markets do not grade intent. They grade outcomes. That line is harsh because it is true. It is also the only force strong enough to clean up the word agent. The market will not tolerate open ended authority without evidence once the failures are visible and the costs are material. The question is whether enterprises wait for the market to teach them, or whether they decide where authority belongs before technology forces the issue. There is a final reason this gets worse, and it is the most human reason of all. People want relief. They want the burden lifted. They want fewer meetings. They want fewer approvals. They want a way to act without carrying the fear of being the lone decision maker. Agent theater offers that relief as a story. Real agency offers it as a contract. The difference is what the contract requires of leaders. It requires them to stop hiding behind language. It requires them to decide where authority belongs. It requires them to treat definitions as governance instruments, not literacy aids. It requires them to demand mechanism, not marketing. It requires them to build permission architecture tight enough to act and strict enough to stay safe. Permission, not inference, decides who gets paid. The MIT table and the ZDNET warning are not academic. They are a count of how far the market still is from that truth. If leaders keep buying words, they will keep living inside decision latency. If leaders demand bounded authority, the word agent will become expensive to misuse. References This piece is grounded in the supplied reporting that used the MIT Agent Index as its catalyst for warning that many deployed agentic systems disclose little about monitoring, stop options, and safety testing, and that a meaningful share of vendors did not respond to researchers’ questions, as framed in the February 19, 2026 ZDNET analysis, then reinforced by the enterprise mechanism arguments in “Why Definitions Become Architecture” and “Every Year a New Word. Same Missing Value,” which tie legitimacy, decision latency, and the inference permission boundary to the real cost surface where authority drifts and value leaks. It draws its agency standard from “Bearing the Weight of Intention and Goodwill,” which frames agency as entrusted judgment with consequences, not mere automation, and it keeps itself honest by

adopting the counterexample discipline in the same body of work that concedes some association based systems create value when permission is already delegated by design. For conceptual ballast on why organizations default to procedure under risk, why responsibility blurs under ambiguity, and why audited action requires traceable authority, it leans on Herbert A. Simon’s bounded rationality and organizational decision making, Charles Perrow’s “Normal Accidents,” James Reason’s work on error and latent conditions, and classic agency law’s insistence that acting on behalf of another is inseparable from accountability.

Topics: agentic-authority, permission-in-advance, outcome-ownershipOpen in the Radiant ↗All dispatches