Most organizations are granting AI agents authority faster than they are defining the limits of that authority.
That is the problem.
We have already started treating AI agents as digital workers. That is the right mental model. An agent that can access data, call tools, trigger workflows, generate artifacts, influence decisions, or alter enterprise state is not just another application. It needs identity. It needs boundaries. It needs oversight. It needs evidence. It needs a human owner. It needs a kill switch. That has been the right foundation for agent governance.
But it is not enough.
There is another question that needs to be asked much earlier:
How much damage is this agent allowed to cause before a human must approve the next action?
Not theoretically.
Not in vague risk language.
In actual economic terms.
How much money can it spend?
How many systems can it change?
How many records can it touch?
How much customer impact can it create?
How much privacy exposure can it cause?
How much reputational risk can it accumulate?
If we cannot answer those questions, we have not governed autonomy.