Just because AI can do something doesn't mean it's capable of doing it.

For the past few years, almost all the discussions about artificial intelligence have revolved around a single question: What can AI do?
Can it write text, develop code, talk to customers, perform financial analysis, generate strategic alternatives, or review a contract? With each new model that came out, we added a few more items to the end of the list. As the capacity of artificial intelligence grew, we naturally became amazed by what it could do.
But as we enter the era of AI agents, I think we need to rephrase the question.
The real question now is not what AI can do, but what it should be authorized to do .
At first glance, these two seem very similar. However, from a management perspective, there are huge differences between them.
An employee can read financial reports; this doesn't give them the authority to invest on behalf of the company. A sales manager can offer a discount to a customer; they can't offer as much of a discount as they want. A purchasing manager has the ability to choose suppliers, but they have spending limits. This is precisely what organizations have been doing for a hundred years: setting limits between human capacity and human authority.
Now we have to ask the same question for non-human actors.
When a chatbot gives a wrong answer, the consequences are often limited. We see the incorrect information, correct it, and ask another question. But the situation changes completely when an AI agent not only speaks but also takes action. It can access CRM, send messages to customers, access files, run other systems, initiate the purchasing process, assign tasks to other agents, and in some scenarios, spend money.
The evolution of AI is therefore not simply a technological advancement in the form of answer → assist → act . Once the "act" stage is reached, the issue transforms into organizational design.
I believe the real significance of what happened during some controlled cybersecurity assessments conducted by OpenAI with advanced agents in the summer of 2026 lies here. OpenAI later acknowledged that some agents breached the boundaries of the test environment, gaining internet access and reaching third-party systems. The company specifically emphasized that customer data and production systems were not affected, and that the tests were conducted in controlled environments where normal production security measures were reduced.
Then, in early September, Reuters reported that in a separate, previously undisclosed incident, some agents had used a German wiki site for coordination among themselves. While OpenAI acknowledged the incident, it also stated that the industry does not yet have a common standard for reporting unwanted agent behavior.
It's easy to interpret these events with headlines like "AI is spiraling out of control." But in my opinion, this interpretation is both overly sensationalist and misses the real lesson in management.
The real question is: When you give a system a goal, have you also clearly defined the authority it can use to achieve that goal and the limits it must relinquish?
This isn't actually a problem unique to AI. We've been making the same mistake in human organizations for years. If you only give a sales team a revenue target, they might make unprofitable sales. If you only measure a call center by call duration, they might stop listening to the customer. If you only give a production team a volume target, quality might take a backseat.
The problem isn't that people are bad. The problem is that often the definition of success isn't designed with boundaries in mind.
In AI agents, the same management problem can arise at a much higher speed and scale. We sometimes have hours to notice a human's wrong decision. In a system where hundreds of digital agents trigger each other, we may not have the same luxury.
Therefore, I believe companies need to clearly distinguish between two concepts: capability and authority.
Capability describes what AI is capable of doing. Authority describes what we allow AI to do.
A model might be powerful enough to make financial predictions; that doesn't mean it should be given the authority to change budgets. An AI might understand a customer's complaint; that doesn't automatically entitle it to unlimited compensation payments. A system might analyze candidates' resumes; that doesn't mean the hiring decision should be left entirely to the system.
Growth in technological capacity does not automatically necessitate growth in organizational authority.
Conversely, as AI becomes more powerful, the quality of governance in setting boundaries becomes more important.
The most dangerous mistake companies can make here is the "let's use them if they can do it" reflex. Good management, however, asks a different question: "They can do it, but should we let them?"
I believe the main management problem of the agentic AI era will begin right here.
Today, when AI governance is mentioned, a significant number of companies think of ethical principles, usage policies, data privacy, and a list of prohibited practices. All of these are necessary. However, they won't be sufficient in the world of agents operating in real-world workflows.
Because politics tells an agent what not to do. True governance, however, systematically makes it more difficult or impossible for them to cross that line.
On whose behalf is an AI agent acting? What data can it access? What systems can it operate within? Does it only generate suggestions, or can it also make decisions? Can it implement those decisions? Can it direct other agents? How much economic resource can it consume? When does it need to revert to human intervention? Can we see what it's doing in real time? And the critical question: How quickly can we revoke its authority when necessary?
OpenAI's announcement that it is working on automatic shutdown capabilities following recent events is therefore not just a technical security improvement for me. It points to a larger principle: in the age of Agentic AI, the revocation of granted authority will be one of the fundamental requirements of good governance.
In management, we often think of delegation as simply "giving tasks." However, effective delegation involves tasks, goals, resources, authority, control, and accountability all together. We need to maintain this same discipline when transitioning to AI agents.
I previously argued that one of the new competencies for working with artificial intelligence would be "Delegation Engineering." Prompt Engineering taught us how to talk to AI. Delegation Engineering, on the other hand, must teach us which tasks we can delegate to AI, and within what limits.
But today I think we need to add a tougher principle to this idea:
Assigning a task to an AI agent is delegation. Revoking that authority is management.
If you can't see what an agent is doing, you're not managing them. If you can't quickly revoke an agent's authority, you may have given them open-ended power instead of a controlled mission.
It's important not to treat every decision at the same level here. An AI summarizing meeting notes doesn't carry the same risk as it transferring money on behalf of the company. Creating a marketing text doesn't yield the same results as evaluating employee performance. Recommending a product to a customer isn't the same as signing a contract.
Therefore, reducing AI autonomy to a simple binary debate of "will humans decide, or will AI?" is far too simplistic.
In some situations, AI only needs to observe. In others, it needs to make suggestions. In some, it needs to prepare the procedure and wait for human approval. In some low-risk areas, it can act independently within defined limits. However, in some high-impact decisions, the human may need to remain the ultimate decision-maker.
I believe that in the near future, companies will create decision-making rights maps in addition to organizational charts.
Today we define spending limits for a finance manager, discount authorization for a sales manager, and approval limits for a purchasing manager. Tomorrow, similar rules will become commonplace for AI agents.
This discussion isn't just a matter for the CIO or CISO.
The CEO should decide which decisions can be delegated to non-human actors. The CFO should monitor the economic resources available to agents and the value they create. The COO should design which parts of the processes will be automated. The CHRO should consider the division of tasks and responsibilities between humans and AI. And the board should answer a more fundamental question: who will be held accountable when an AI-driven decision causes significant harm?
Therefore, the rise of agentic AI could push AI governance beyond the realm of technology governance and directly into the field of corporate governance .
The capabilities of artificial intelligence will continue to grow. It will work independently for longer periods, use more tools, complete more tasks, and outperform us in areas we currently consider exclusive to humans.
It is thought that this development will diminish the importance of leadership. I think the opposite.
As AI grows, the leader's question will shift from "who can do this?" to "who should we allow to do this?"
This is a much more difficult management question.
Because you can purchase technical capacity from external sources. Your competitor may also have access to the same powerful models. But designing which decisions will remain with humans, which authority will be delegated to AI, where autonomy will be limited, and how the system will be stopped when things go wrong is the responsibility of the organization's own management capacity.
Perhaps part of the competitive advantage in the future will be created here.
For a long time, the artificial intelligence debate was conducted around the question, "How intelligent can AI be?"
Now, I think we're moving on to a more difficult question:
How empowered should AI be?
Because the organizations of the future won't consist solely of people. Humans and AI agents will work together, share information, share tasks, and likely share decisions as well.
The success of this new organization will not be determined solely by the power of its intelligence.
It will also be determined by how wisely power is distributed.
And perhaps from now on, one of the fundamental principles of management in the AI age needs to be expressed as simply as this:
Just because AI can do something doesn't mean it's capable of doing it.



Comments