Every existing control assumes a human checkpoint. A drafting assistant produces text a person reviews and sends. But an agent can chain dozens of tool calls — query a database, score a customer, approve a limit, trigger a transfer — in seconds, with no natural pause for review.
The same shadow-AI dynamics already straining institutions (two-thirds of staff using AI, fewer than one in five firms with a policy) become exponentially riskier when the tool can take consequential actions, not just generate words. Regulators have seen it coming.
RBI's FREE-AI framework centres human oversight, accountability and explainability — principles that get harder, not easier, when decisions are autonomous and multi-step.
The CBUAE's 2026 guidance explicitly preserves effective human oversight and consumer opt-out for high-impact automated decisions.
DIFC's proposed amendments introduce the idea of Autonomous Systems Officers — a named human accountable for autonomous processing. The regulatory message across India and the Gulf is consistent: autonomy does not dilute accountability; it concentrates it.
Governing an agent requires controls that drafting tools never needed: scoped permissions (what tools and accounts can the agent touch, and up to what value?); hard action limits with mandatory human approval above a threshold; a complete, immutable audit trail of every step the agent took and why; pre-deployment red-teaming for prompt injection and goal misalignment; and a kill switch with a tested rollback.
Treat each agent as you would a junior employee with system access — onboarded, permissioned, supervised and logged. The institutions that win the agentic era will be the ones that can prove, after the fact, exactly what their agents did.