An AI Agent Can Be Stopped. That Does Not Say Who Decides.

Agentic AI platforms can register, constrain, observe, stop, and retire autonomous agents. None of that establishes who holds legitimate authority to decide once an action halts. A hypothetical refund escalation shows why authority, evidence, escalation, and accountability have to be designed rather than assumed.

The screen that halts an action without resolving authority

Consider a hypothetical case. A consumer retailer runs a customer service AI agent that reads inbound complaints, reconciles them against order and shipment records, and answers routine questions. On a Friday evening, the agent evaluates a fourth complaint from the same customer about a third delayed delivery and selects a remedy: full refund plus a goodwill credit. The total exceeds the 500 dollar ceiling the company set for automated settlements. Execution halts. The console displays a request for human approval.

The control worked as designed. What it does not supply is everything that follows.

The company has not established which role may approve a settlement above that ceiling on a Friday night, or what evidence that role must see. It has not said what happens if no one responds before the payment cutoff, who receives the case instead, or how long that transfer may take. It has not determined whether the reviewer may modify the remedy rather than accept or refuse it. And if the refund later proves wrong, the company has not decided whether accountability rests with whoever clicked, the department that deployed the agent, or the executive who set the ceiling in the first place.

An approval screen interrupts execution. It does not, by itself, constitute a decision. The person in front of it may lack the evidence, the time, the mandate, or the alternatives that a decision requires. Human oversight becomes real only when someone with genuine authority is placed in a position where judgment is actually possible.

What agentic AI platform controls do establish

The case for moving controls into the platform is argued in Agentic AI Governance, Risk, and Controls for Business Leaders, published by Bain & Company on July 28, 2026 and written by Richard Fleming, Maria Teresa Tejada, Brendan O'Rourke, and David Allen. This is consulting guidance from a firm that advises on these deployments, and it should be read as a practitioner argument rather than as research or regulation.

Its operational premise is hard to dispute. Autonomous agents open tickets, update records, and trigger workflows thousands of times a day. Case-by-case human review does not scale to that volume, and a policy written in a document takes effect only when someone remembers to consult it. The authors argue that governance belongs in the agentic platform's control plane, the layer that mediates execution, where restrictions apply to every action rather than to the ones someone happens to check.

They organize those controls into five domains. Identity treats each agent like an employee with its own credentials, permissions, autonomy tier, and time limits, recorded in a central registry. Behavior constrains the resources an agent may consume and the actions it may take, containing the blast radius before an incident rather than during one. Context separates instructions from data and applies classification and access discipline to the unstructured material agents read. Observability and evaluation raise the bar above uptime monitoring, requiring verification against the systems the agent actually touched, tamperproof audit trails, and stop and rollback paths that have been tested. Accountability holds that humans still answer to boards, regulators, and customers, and recommends staged exposure before autonomy widens.

Any organization running agents against production systems should build these five capabilities. They are the floor.

Why written AI governance so often fails to change decisions

A parallel argument, made from the organizational side, appears in Stephanie Overby's Why AI governance is failing — and what actually works, published in CIO on July 28, 2026. This is industry journalism assembled from practitioner interviews, company examples, and third-party surveys, and its value lies in the pattern it identifies rather than in independent measurement.

The pattern is that policy coverage and governance effectiveness have decoupled. Most organizations have an AI policy. Far fewer maintain a live inventory of AI systems, classify use cases by risk, embed controls into the workflows people already use, enforce them technically rather than in prose, measure performance against defined evaluation standards, and formally decommission agents they no longer use. The article's sharpest test is whether governance ever changes an outcome. If every initiative that enters the review process emerges approved, what the organization has built is not governance but a notarization service.

The survey figures Overby cites come from third parties rather than from CIO. The Cloud Security Alliance published Autonomous but Not Controlled: AI Agent Incidents Now Common in Enterprises on April 21, 2026, based on 418 responses from IT and security professionals collected online in January 2026, with the research commissioned by Token Security. In that sample, 65 percent had experienced AI agent-related incidents in the previous twelve months, 82 percent had unknown agents running in their infrastructure, and only 21 percent had formal decommissioning processes. Separately, the EY Technology Pulse Poll released on March 4, 2026 found that 78 percent of leaders said AI adoption was outpacing their organization's ability to manage the associated business risks. That poll surveyed 500 US technology-sector business leaders at director level or above in organizations of 5,000 or more employees.

Both are bounded samples. The CSA study was vendor-commissioned and drawn from security professionals; the EY poll covers one industry in one country. They indicate a direction of travel among the organizations surveyed. They are not prevalence estimates for enterprises generally, and nothing in this Insight depends on treating them as such.

What the sources establish, and what they leave open

Read together, these two arguments converge on four points. Controls belong in implementation rather than in documents. Oversight has to extend past deployment approval into operation, suspension, and retirement. Visibility and continuous evaluation are prerequisites. And humans remain accountable regardless of how much execution moves to machines.

An organization that acts on all four gets a great deal. Its agents are registered, permissioned, observed, containable, reversible, and retirable. The question this Insight is concerned with survives every one of those capabilities.

Stopping is a property of the system. Deciding is a property of the institution. The ability to halt an action says nothing about who is entitled to judge whether it should proceed, what that person must be shown, how long they may take, what they may do besides approve or refuse, who receives the case when they cannot act, and who answers for the result. In the refund case, the ceiling functioned perfectly. Nobody had designed what waited on the other side of it.

What Japan's guidance says, and what it does not

Japan's government has named this design problem directly. The Ministry of Internal Affairs and Communications and the Ministry of Economy, Trade and Industry published Version 1.2 of the AI Guidelines for Business on March 31, 2026. The revision introduces a definition of an AI agent, rendered from the Japanese as an AI system that senses its environment and acts autonomously in order to achieve a specified goal.

Because agents act autonomously, the revised text advises organizations to sort the matters requiring judgment by importance, select which of them warrant human involvement, and build mechanisms that interpose human judgment at those points. It also addresses the consequences of connecting agents to other systems, advising appropriate restriction of connected tools and permissions and periodic review of operation histories. The passages summarized here come from the Japanese text and from Japanese professional commentary on the revision; readers who need exact wording should consult the official publication.

Two qualifications matter for anyone outside Japan reading this as precedent. The AI Guidelines for Business are non-binding guidance, catalogued as such in the OECD.AI Policy Observatory, and they sit inside a broader Japanese framework that international practitioners describe as soft law. They create no generally applicable legal duty. The guidance also does not require prior human approval for every action of every AI agent. It asks organizations to identify which decisions are consequential enough to warrant human involvement and to build the mechanism at those specific points.

That is a design instruction, not a compliance checkbox. Which matters are important, whose judgment counts, and at what stage it enters remain for each organization to determine.

Four disciplines, and the question none of them allocates

The question left standing is not neglected by existing disciplines. It simply is not the subject of any of them.

Governance determines the rules by which activity is supervised and how the organization answers for it. It sets standards, assigns oversight functions, and produces evidence, without allocating authority over the individual judgments inside a specific workflow.

Digital transformation determines how work and value delivery change. Redesigned processes move authority as a side effect, but transformation plans rarely state where decision rights land once the process is rebuilt.

Automation determines which processing is handed to machines. Processing and judgment are different objects, and the fact that a step can be automated does not settle whether the judgment inside it may be delegated.

AI ethics determines which values and principles the organization commits to. It does not extend to the operational machinery of approval, suspension, exception, and record that decides which value prevails when two of them conflict on a Friday night.

All four are necessary. The allocation of judgment is simply a different object of design.

Decision Design and its working vocabulary

Decision Design treats the act of judgment itself as the thing being designed. Decision Design is not about improving decisions alone; it is about designing the authority structure within which decisions become institutionally legitimate. It is a proprietary framework rather than a legal standard, a public specification, or an established academic term, and it is offered here as a design discipline that connects governance, transformation, automation, and ethics to the recurring question of who may decide what.

Its central construct is the Decision Boundary, the line separating judgments delegated to an AI agent from judgments a designated human role or institutional body retains. Decision Boundaries are not operational thresholds; they are institutional demarcations of legitimate authority. A monetary ceiling implements a boundary. The boundary is the determination of which role owns the judgment on either side of that number, and why.

Three further terms carry the framework. Decision Authority names the role, not the individual, that holds the right to decide a class of judgment and answers for it. Judgment Architecture is the arrangement of authorities, evidence requirements, conditions, and routes across a workflow. Accountability Continuity is the property that responsibility remains traceable to a role as the work passes between an agent, a reviewer, an escalation point, and a later audit. The Decision Log is the instrument that sustains it. Decision Logs do not merely record outputs; they preserve accountability continuity across distributed judgment processes.

Drawing the boundary around the refund

Applying this to the hypothetical case produces something specific enough to build. The monetary figures below are illustrative. Each organization sets its own according to loss tolerance, reversibility, and customer impact.

The judgment unit and who it touches. The action described as issuing a refund is not one judgment. It contains several: whether the complaint is substantiated, whether responsibility lies with the retailer, the carrier, or the customer, which remedy applies among refund, replacement, partial refund, and credit, what amount, and whether the outcome is a one-time gesture or a change to the commercial relationship. Each affects different parties: the customer, the company's margin, the service representatives who will handle the next complaint of the same shape, and the fraud exposure of the channel itself.

Roles. The agent verifies facts and constructs options. It reconciles order history, shipment records, prior contacts, and contract terms, then presents candidate remedies with supporting evidence, contrary evidence, and a cost breakdown. Reversible low-impact judgments, such as small partial refunds, replacement shipments, and goodwill credits, execute autonomously when conditions hold. Settlements above the ceiling, repeat claims, and cases showing fraud indicators stop at presentation. Changes to commercial terms leave customer service entirely. Authority attaches to roles: amount decisions to the role holding refund authority, suspected fraud to the fraud function, relationship-sensitive accounts to the commercial owner. The accountable party is the role that received the delegation, not whoever happened to be at the console.

Evidence and conditions. The agent may consult order history, shipment records, contract terms, prior contacts, and the refund policy. Other customers' records and personal data outside the purpose are excluded, which is a privacy control and a boundary condition at once. Adoption conditions combine amount with customer impact, reversibility, confidence in fact reconciliation, and fraud signals. A workable pattern retains the 500 dollar line for autonomous execution, but only where the transaction is reversible and the facts reconcile, adds approval by the authorized role up to 5,000 dollars, and allows presentation only above that or whenever fraud indicators appear. Execution stops when supporting data is missing, stale, or inconsistent, when policy and precedent conflict, when the action cannot be reversed, or when claims from one customer or one pattern cluster in a short window.

Exceptions and escalation. Once execution stops, the design must specify the recipient, the deadline, and the contents of the handoff. If the authorized role does not respond within thirty minutes, the case moves to the next role in the chain. Cases facing a payment cutoff carry a shorter clock, because delay is itself a cost. Fraud signals, contract conflicts, and relationship-sensitive accounts each route somewhere different. The handoff carries what the agent consulted, the options it constructed, the reason it stopped, and the time remaining.

Records and review. The Decision Log captures the evidence and its version, the options presented, the policy applied, whether the human role approved, modified, or refused, the stated reason, and the final outcome and amount. What distinguishes it from a system log is that it answers who held which judgment, months later, to an auditor or a regulator. Boundaries are then revised on defined triggers: an incorrect refund, a fraudulent claim that passed, a change to the model or the policy, or evaluation showing autonomous accuracy or override rates outside expectation. An approval rate close to 100 percent, or approval times too short for the evidence to have been read, is a signal that ratification has replaced judgment.

What turns an approval into a decision

The refund case makes the requirement concrete. A reviewer facing that console can render a decision only with what changes and whom it affects, the evidence used and its freshness and gaps, the reasoning for the recommendation and the case against it, the reversibility of the action and the procedure for undoing it, enough time to weigh all of that, the competence the judgment demands, and the authority to approve, refuse, modify, or escalate. Remove any one and what remains is ratification.

The conclusion is not that organizations need more human reviewers. Reversible low-impact judgments should execute autonomously under stated conditions, so that human attention concentrates where values conflict or consequences cannot be undone.

A compact way to start

No organization needs to redesign its entire AI estate at once. One workflow is enough, and the refund case shows what the output looks like.

Back to the screen

Return to the Friday evening console. The ceiling was sound as a control. What was missing was its institutional meaning. Nobody had determined why the line sat at that number, which role assumed the judgment above it, what that role would be shown, or how long it had. Absent those determinations, the screen was not a place where the organization decided anything. It was a place where an action stopped and responsibility hung unassigned.

With the boundary designed, the same screen reads differently. The ceiling now expresses a considered position on reversibility, fraud exposure, and confidence in the facts, owned by the role that holds refund authority. The console presents impact, evidence, contrary evidence, the procedure for reversal, and the remaining time. If that role does not act within thirty minutes, the case escalates on its own. Whether the button is pressed or not, the record shows which role held the judgment.

The capacity to stop an AI agent is necessary and it is not sufficient. Until an organization determines who stands on the other side of the stop, its controls report that something halted without reporting who is answerable. Who decides, how much is delegated to the agent, and where the institution takes the judgment back cannot be settled by a vendor or by a guideline. That line is drawn by the organization, or it is not drawn at all.

FAQ

Does a human-in-the-loop approval step satisfy AI oversight requirements? Not on its own. An approval step interrupts execution, but oversight requires that the reviewing role hold real authority, see sufficient evidence, have adequate time and competence, possess alternatives beyond approve and refuse, and have a defined escalation route. A reviewer lacking these conditions produces ratification rather than judgment.

How does a Decision Boundary differ from a spending or risk threshold? A threshold is a number in a system. A Decision Boundary is the institutional determination of which role owns the judgment on either side of that number, what evidence that role must use, and who remains accountable. The threshold implements the boundary; it does not constitute it.

Are Japan's AI Guidelines for Business legally binding on companies operating there? No. Version 1.2, published on March 31, 2026 by the Ministry of Internal Affairs and Communications and the Ministry of Economy, Trade and Industry, is non-binding guidance intended to prompt voluntary risk management. It does not impose prior human approval on every action of every AI agent. It asks organizations to identify which judgments are important enough to warrant human involvement and to design the mechanism at those points.

Does Decision Design replace AI governance, risk management, or ethics programs? No. It addresses an object none of them allocates: authority over individual judgments inside a specific workflow. Governance rules become conditions attached to named judgments, automation scope becomes the set of judgments permitted to execute autonomously, and ethical commitments become stop conditions with an identified accountable role.

Who is accountable when an AI agent's action produces a bad outcome? The role that held the delegated authority, defined before the action occurred, not the individual who happened to click approve. Assigning accountability to a role rather than to a keystroke is what allows an organization to answer an auditor months later, and it is the purpose of the Decision Log.

References

Decision Design is a judgment architecture framework proposed by Ryoji Morii, founder of Insynergy Inc., for structuring authority, accountability, and decision boundaries in AI-augmented organizations.

Japanese version is available on note.

Open Japanese version →
日本語版を読む (Japanese) →