Three business professionals collaborating with digital devices in a modern office, representing responsible AI, AI agents, and enterprise innovation.

Building Defensible Speed With AI Agents

Julie DeMuth Mellendorf, Corey Minard, Jacqueline Tomei
8/20/2026

Governance over AI agents helps organizations accelerate automation while strengthening accountability and trust. 

An AI agent can open the ticket, pull the customer record, approve the refund, update the account, send the confirmation, and close the matter before anyone reviews a word of it. That speed promises greater efficiency, lower costs, and new organizational capacity. It also changes the legal question. When the refund is wrong, the notice reaches the wrong person, the system changes an employee’s access, or the agent appears to commit the business to something it never intended, the thrill of impressive technology gives way to a critical question: Who authorized this action?

The first phase of AI governance focused on generative AI output, such as drafts, summaries, research, and analyses that typically received human-in-the-loop review. That human checkpoint often defined the boundary of the legal exposure. The next phase of AI governance focuses on AI agents because they do more than generate content. They execute tasks. They send messages, update systems, route work, trigger workflows, approve transactions, escalate disputes, renew subscriptions, modify access rights, and make representations that customers, employees, vendors, regulators, or counterparties might rely on.

Organizations use different labels, such as “AI agents,” “digital workers,” “copilots,” “assistants,” or “autonomous workflows.” But the core legal issue remains the same: authority. If an AI agent can access data, use company credentials, invoke tools, communicate externally, move money, or change a business outcome, it is operating inside the business and exercising organizational authority. That authority requires governance.

The issue is authority, not autonomy

It is tempting to say AI has outrun the law. In some areas, that might be true. However, regarding the issues that create enterprise exposure, existing law already provides the answer. Contract formation, agency, consumer protection, employment, privacy, and sector-specific regulation already supply the tools to assign responsibility when an automated system acts.

The defense that claims “the machine acted on its own” has a poor track record. In Moffatt v. Air Canada, 2024 BCCRT 149, the airline argued that its customer service chatbot was, in effect, responsible for its own statements. The tribunal rejected that argument and held the airline liable for the chatbot’s misleading answer to a customer who relied on it. That ruling does not bind U.S. courts, but the underlying principle holds up everywhere. A business is accountable for the systems it chooses to deploy.

U.S. courts reached a similar result decades ago in a computer-processing context with State Farm Mutual Automobile Insurance Co. v. Bockhorst, 453 F.2d 533 (10th Cir. 1972), in which the 10th Circuit rejected an insurer’s attempt to avoid responsibility for a policy reinstatement its computer system generated from incomplete information. The court held the insurer bound by the outcome anyway. Automating an action does not move responsibility for it outside the organization.

The practical reframe for leaders is that an AI agent is not a new legal person sitting beyond the company’s reach, but it is one of the ways the company acts. “No one decided this; the system did," is not a defense. In front of a regulator or a court, that’s an admission that no one held clear responsibility for what the system was permitted to do.

Organizations must show who approved the agent’s authority, what limits applied, what controls were in place, what evidence was preserved, and who was accountable when it acted. Such accountability underscores the need for legal and risk professionals to help design the operating model before deployment, when governance can be built in, rather than reconstructing it after an incident.

Enabling defensible speed

The legal and risk team does not need to become the office of “no” for AI agents. The opposite is true. If the business is going to use agents to improve speed, quality, and scale, they have an enabling role. The goal is not to block automation. The goal is to make automation defensible.

A governed AI-enabled workforce is a real advantage because it has the capacity to yield fewer manual bottlenecks, produce more consistently, offer faster service, and free people up for higher value work. But speed only becomes an advantage if the organization can trust, explain, and defend how it was achieved.

The transformation opportunity is to move the business from informal experimentation to accountable automation. That operating model must answer five questions:

  • What is the AI agent allowed to do?
  • Who approved that authority?
  • What actions require human review?
  • What record will prove what happened?
  • Who owns the system when something goes wrong?

If those questions are unanswered, the organization is scaling ambiguity, not AI transformation.

A practical playbook

Most AI policies were written for tools that assist people. AI agents require governance for tools that act on behalf of people. A drafting assistant that helps prepare an internal memo does not carry the risk of an agent approving a refund, changing benefits eligibility, modifying access rights, submitting information to a regulator, or accepting contract terms in the company’s name. One produces a work product for review, and the other exercises operational authority.

Following are seven controls organizations can implement to create an architecture that enables AI agents to operate at speed without leaving accountability behind.

  • Building an inventory. Organizations should identify where AI agents, copilots, and vendor-enabled tools are already acting, or preparing to act, on their behalf. Many will be in customer service, HR, procurement, finance, or IT without specifically being labeled as “AI agents.”
  • Cleaning up data. AI agents will act on the information they have access to, whether or not it is up to date. If documented processes do not reflect what the organization does today or old versions conflict with current information, AI agents might take incorrect or inconsistent steps over time.
  • Assigning ownership and authority. Every agent should have a named business owner, a defined purpose, and a documented scope of authority regarding what systems it might touch, what data it might use, what workflows it might trigger, and what it should not do.
  • Controlling the point of consequence. The decisive controls are the points where a recommendation becomes an action, such as when the agent can sign, send, pay, file, approve, deny, change eligibility, alter access, or make a representation. Those moments belong behind defined limits, thresholds, and approval gates.
  • Preserving the evidence. If an agent takes a consequential action, the organization must be able to reconstruct what the agent did, when, what data it used, which tool or system it called, what threshold applied, whether a person reviewed it, and who owned the authority behind it. Organizations should build the log before they need it in a deposition.
  • Testing before granting authority. For higher risk use cases, organizations should run the AI agent in shadow mode first. They can let the AI agent observe, recommend, and simulate while a human still decides. Then they can compare the AI agent’s recommendations against human decisions, find the gaps, and define escalation and shutdown criteria before it is allowed to act on its own.
  • Treating vendor agents as delegated authority. If a vendor’s agent acts in the organization’s name, stating “the contract should address it” is a placeholder, not a control. Delegated authority must be addressed specifically, and the contract should include indemnification obligations that cover the AI agent’s autonomous actions, not just the vendor’s negligence. It should also allocate regulatory liability when the AI agent’s conduct triggers an enforcement action; provide audit and log access rights that can be exercised during an incident; carve out consequential acts that matter most from the liability cap; establish data-processing terms that limit what the AI agent may access; and require cooperation in investigations on the organization’s timeline, not the vendor’s.

When employees and customers are involved, the stakes change

The exposure is often densest in areas where agents touch employees, applicants, and customers. Organizations already are deploying AI agents in exactly these functions: recruiting, onboarding, task allocation, performance monitoring, claims handling, eligibility review, and access management. That concentration of AI use is no coincidence, as these also are the functions where employment law, privacy law, anti-discrimination law, consumer protection, and AI-specific regulation converge. Increasingly, those legal obligations apply directly to the deployer, not just the developer.

Examples are already visible. The EU AI Act requires high-risk AI systems to be designed for effective human oversight and imposes obligations on deployers of high-risk systems, including competent human oversight, log-retention obligations, and notice to workers and their representatives when high-risk AI systems are used in the workplace. New York City’s Local Law 144 has required bias audits and notices for certain automated employment decision tools since 2023. Colorado enacted the first comprehensive state AI law in 2024; after a federal court temporarily blocked enforcement in April 2026, the legislature repealed and replaced it in May 2026 with a narrower regime focused on automated decision-making technology used in consequential decisions. These three examples bear out the idea that specific obligations will keep moving, but duty to govern these systems will not.

One distinction deserves particular attention. Even when a human stays in the loop, the critical question is whether that person exercises independent judgment or simply ratifies the system's recommendations. The law increasingly evaluates the substance of human oversight, not merely its presence. For higher impact uses, governance should include a documented risk assessment, appropriate notice and disclosure, genuine human oversight, an appeal or escalation path, data minimization, access limits, and records sufficient to explain a decision after the fact. The goal is not to avoid these uses but to deploy them in ways that are transparent, controlled, and aligned with the organization’s obligations and its values.

Proactive pressure testing

A policy looks complete until the first real failure. Organizations should run a tabletop exercise on a single agent gone wrong. For example, an AI agent sends the wrong customer notice, pays the wrong party, denies the right claim for the wrong reason, accepts a contractual term it should not have, or changes an access permission it should not have touched.

Organizations should then ask:

  • Who detects the issue?
  • Who owns the response?
  • Can we stop the AI agent immediately?
  • Can we identify everyone affected?
  • Can we reconstruct what happened, and preserve the record?
  • Can we show who approved the agent’s authority and what controls were applied?

Pressure testing and tabletop exercises can surface gaps in ownership, logging, escalation, contracting, and shutdown authority faster than any policy review. They also provide a concrete way to support transformation while making the risk visible before it becomes a loss.

Defensible speed is the advantage

AI agents are a new operating layer inside the enterprise. They are not too risky to use, but they are too consequential to deploy casually.

A governed AI-enabled workforce can help an organization move faster, serve customers better, and create meaningful capacity. Governance turns speed into a durable business advantage by making AI-enabled decisions explainable, legally supportable, operationally monitored, subject to effective board oversight, and defensible when challenged by regulators, customers, employees, or the courts.

AI agent governance falls short when it is treated as a technology deployment alone. It touches legal, risk, cybersecurity, compliance, procurement, human resources, finance, and operations, not just technology. Crowe specialists help organizations translate broad principles of accountability and oversight into the practical instruments that can hold up under scrutiny, including agent inventories, authority maps, risk tiers, approval gates, logging requirements, vendor contract controls, tabletop exercises, and review protocols.

AI agents can operate with substantial autonomy, but organizational accountability does not diminish as AI agent autonomy increases. Establishing clear authority and governance before deployment enables organizations to build AI-enabled workforces that can scale while remaining trustworthy and defensible.

Mitigate AI risk with AI governance
If your company uses AI, you need an AI governance plan. We can help.

Contact us


Our team specializes in helping companies build robust, future-ready AI governance. Contact us to get started.

Julie DeMuth Mellendorf
Julie DeMuth Mellendorf
Studio Quality and Risk Management Leader
Corey Minard
Corey Minard
Senior Manager, Risk Consulting
Jacqueline Tomei
Jacqueline Tomei
Risk Consulting

Related insights