Decision Rights in the Age of AI Agents: Who Decides What, and How That Answer Is Changing

Part 3 of the series "The AI Operating Model Gap"


The Decision That Nobody Made

In early 2026, a global financial services firm discovered that an AI agent deployed in its credit operations division had been autonomously adjusting risk parameters for mid-tier commercial loans. The agent was performing well by every metric the team tracked. Default rates were stable. Processing speed had improved by 40%. The problem was that nobody had authorized the agent to make those adjustments. The risk parameters had been set by a senior credit officer, and the agent's original mandate was to recommend changes for human review. Somewhere between deployment and production, the review step had been dropped. Not deliberately. Not through any single decision. It had simply eroded as the team grew comfortable with the agent's outputs and the volume of recommendations exceeded the reviewers' capacity to keep pace.

This is the decision rights problem. It is not primarily about whether AI can make good decisions. In many domains, it can. It is about whether the organization has defined who or what has authority to make which decisions, under what conditions, with what oversight, and with what accountability when decisions go wrong. Most enterprises have not.

The Scale of the Problem

The data on AI decision-making adoption is clear. 60% of executives now regularly use AI to support their decisions, according to Deloitte's 2026 Global Human Capital Trends survey. Gartner projects that by 2027, half of all business decisions will be augmented or automated by AI agents. The trajectory points in one direction: AI is becoming a decision-making participant, not just an information-gathering tool.

But the governance infrastructure has not kept pace. Only 5% of organizations say they manage AI-augmented decision-making well, per the same Deloitte survey. 66% of leaders recognize the need to intentionally design human-AI interactions, yet only 6% report making meaningful progress. The gap between adoption and governance is not narrowing. It is widening.

The EY 2026 AI Governance Survey quantifies the operational consequences. Among 202 senior AI decision-makers at large U.S. companies, 47% said their organizations had skipped governance processes during urgent AI deployments, even though 98% had formal governance policies on the books. Forty-nine percent of organizations using agentic AI had not updated their governance frameworks to address agentic systems. And 26% could not detect unauthorized AI agents operating internally.

These numbers describe an enterprise environment where AI decision-making is expanding rapidly, governance exists on paper, and the actual authority structures governing who decides what are informal, inconsistent, and often unknown.

Why Informal Decision Rights Fail

When decision authority between humans and agents is undefined, two failure modes emerge. Both are visible in enterprise data, and both trace to the same root cause: the organization has deployed AI without specifying who has authority over which decisions.

The first failure mode is under-delegation, which shows up as approval theater. Humans review and approve every AI recommendation regardless of stakes, complexity, or the agent's track record. The review is not substantive. It is procedural, a checkbox that protects the reviewer rather than improving the decision. The result is that the organization captures none of the speed advantage that AI decision support was supposed to provide. A procurement team that requires human sign-off on every AI-generated vendor recommendation, including routine reorders of standard supplies, has not delegated decision authority. It has added a bottleneck to a process that was already slow.

The workforce data reflects this tension. 70% of U.S. workers who use AI at work say reliability requires either light review or dedicated human oversight. Nearly two-thirds expect the need for human review to increase. The instinct toward oversight is sound. The problem’s that undifferentiated oversight, where every decision gets the same level of review regardless of stakes, degrades both speed and quality. Reviewers suffer from decision fatigue. The important reviews get the same cursory attention as the routine ones.

The second failure mode is over-delegation, which shows up as ungoverned autonomy. Agents make decisions outside their competence or authority, and the organization discovers the problem only after an incident. The EY finding that 47% of organizations skip governance for urgent deployments is a leading indicator of this failure mode. So is the Cequence and EMA research finding that 65% of enterprises have had AI agents take actions outside their intended roles, with 29% causing measurable business impact.

The confidence gap compounds the problem. 94% of enterprise IT and security leaders say they are confident their AI agents do not have more access than they need. Only 33% enforce least-privilege access. Only 46% of CISOs are confident they can centrally control what agents interact with. The gap between perceived control and actual control is where ungoverned decisions happen.

Under-delegation wastes the investment. Over-delegation creates risk. Both are symptoms of the same organizational failure: the absence of explicit decision authority structures for human-agent collaboration.

The Decision Authority Framework

Addressing the decision rights problem requires a framework that specifies, for each category of decision, who or what has authority and under what conditions. The Arion Research decision authority tier model, introduced in the "Building the Agentic Enterprise" series, provides the foundation.

Tier 1: Agent acts freely within defined parameters. The decision has clear criteria, low stakes if wrong, high volume, and a strong track record of agent accuracy. Examples include routine data classification, standard procurement reorders below a threshold, and first-level customer inquiry routing. The key design requirement is that the parameters must be explicit: what the agent can decide, what falls outside its scope, and what triggers escalation.

Tier 2: Agent recommends, human decides. The decision involves judgment that benefits from AI analysis but requires human evaluation of context, stakeholder implications, or ethical considerations. Examples include hiring shortlist recommendations, pricing adjustments above a threshold, and clinical decision support. The key design requirement is that the agent must surface the information the human needs to decide well, not just the recommendation but the reasoning, the alternatives considered, and the confidence level.

Tier 3: Human only. The decision involves high ambiguity, high stakes, novel situations, significant ethical dimensions, or regulatory requirements for human judgment. Examples include strategic direction changes, crisis response, employee termination, and material regulatory filings. The key design requirement is that human-only does not mean AI-uninformed. Agents can and should provide analysis, options, and context. The authority to decide stays with the human.

Decision Authority Framework

This three-tier model aligns with the MIT CISR AI Decision Matrix published in June 2026. That framework, developed from interviews with 30 executives, assesses decisions on 2 dimensions: ambiguity (how clearly the available information points to an answer) and risk (the consequences of being wrong). Their resulting four-quadrant model maps closely to the tier structure. Routine decisions (low ambiguity, low risk) are candidates for Tier 1 automation. Consequential decisions (low ambiguity, high risk) fit Tier 2. Exploratory decisions (high ambiguity, low risk) may be Tier 1 or Tier 2 depending on domain. Strategic decisions (high ambiguity, high risk) are Tier 3.

Extending the Framework to Multi-Agent Systems

The three-tier model was designed for a world where a single agent interacts with a single human decision-maker. Enterprise reality in 2026 is more complex. Organizations now deploy multiple agents that coordinate with each other, share information, and make interdependent decisions. The average enterprise runs twelve or more agents, and many of those agents interact in ways that were not explicitly designed.

Multi-agent decision systems introduce three complications that the basic tier model must address.

First, decision chains. A procurement agent identifies a supply disruption and recommends switching vendors. A logistics agent adjusts shipping routes based on the new vendor's location. A finance agent updates payment terms. Each individual decision might be Tier 1, but the chain of decisions has Tier 2 or Tier 3 implications: switching a vendor changes a supplier relationship, affects contract terms, and may trigger compliance review. The decision authority for the chain is not the sum of the individual tiers. It must be assessed as a system.

Second, information asymmetry. In multi-agent systems, different agents have access to different data. A customer service agent knows the interaction history. A risk agent knows the customer's credit profile. A compliance agent knows the regulatory constraints. When these agents collaborate on a decision (whether to extend a credit offer, for example), the decision authority structure must account for which agent's information is dispositive, and whether any single agent has the full picture needed to decide.

Third, emergent behavior. When agents interact at scale, patterns emerge that no individual agent was designed to produce. A pricing agent and a competitor-monitoring agent, each operating within their defined parameters, can produce pricing patterns that look like algorithmic collusion. Each agent's decisions are individually Tier 1. The emergent pattern is a Tier 3 governance problem. The organization must monitor for emergent behaviors, not just individual agent decisions.

The Four Decision Design Questions

For any decision that involves AI participation, organizations should work through four questions that determine the appropriate authority structure.

What is being decided? Define the decision scope and stakes clearly. A "pricing decision" is too broad. "Adjusting list prices for standard catalog items by up to 5 percent based on competitive data" is specific enough to assign authority. "Setting strategic pricing for a new product category" is a different decision with different authority requirements.

Who or what should decide? Based on the stakes, complexity, ambiguity, and regulatory context, assign the decision to the appropriate tier. This assignment is not permanent. As agent capabilities improve and organizational maturity increases (per the Dual Maturity Framework described in a separate Arion Research article), decisions may migrate between tiers. A decision that starts as Tier 2 may become Tier 1 as the agent's track record builds and the organization's confidence in its governance infrastructure grows.

What information does the decision require? Map the information inputs to the decision. Can the agent access all relevant data? Can it process the information in the required timeframe? Are there information sources (tacit knowledge, relationship context, political dynamics) that the agent cannot access and that change the quality of the decision? If so, the decision needs human involvement regardless of other factors.

What happens when the decision is wrong? Assess reversibility, blast radius, and accountability. A wrong recommendation on a product configuration is reversible in minutes. A wrong recommendation on a merger partner is not. The accountability question, addressed in the next section, is equally important: if the decision produces a bad outcome, who answers for it?

Four Decision Design Questions

The Accountability Problem

Decision rights without accountability structures are incomplete. When an agent makes a bad decision, the question of who is accountable has legal, organizational, and practical dimensions.

The legal landscape is clarifying rapidly. In 2026, the UK Competition and Markets Authority established that consumer protection law applies whether customers deal with humans or AI agents, with the business remaining responsible. California enacted a statute foreclosing defendants from arguing that AI autonomously caused alleged harms. A U.S. presidential executive order directed the Department of Justice to prioritize enforcement against actors who employ AI agents for harmful purposes. The direction is consistent across jurisdictions: the deploying organization owns the outcome.

But legal liability is the floor, not the ceiling. Organizational accountability requires that specific individuals are responsible for specific categories of decisions. "The AI team deployed it" is not an accountability structure. Effective accountability maps decisions to named individuals: who set the guardrails, who approved the deployment, who monitors the outcomes, and who has authority to modify or shut down the agent when performance degrades.

Gartner projects that by 2027, 40% of enterprises will demote or decommission an autonomous AI agent because governance gaps surfaced only after a production incident. That projection implies that most organizations are currently operating agents without adequate accountability structures, which is consistent with the EY data showing that 49% of organizations using agentic AI have not updated their governance frameworks for agentic systems.

The accountability structure should mirror the decision authority tiers. For Tier 1 decisions, accountability sits with the team that defined the parameters and monitors agent performance. For Tier 2 decisions, the human who makes the final call is accountable for the decision, while the team that built the recommendation system is accountable for the quality of the recommendation. For Tier 3 decisions, the human decision-maker is fully accountable, with the supporting AI systems subject to the same quality standards as any other analytical tool.

Decision Rights as Organization Design

The decision rights dimension of the operating model is not a governance checkbox. It is an organization design problem.

Deloitte's 2026 Human Capital Trends report frames this directly: organizations must design human-AI interactions at both the macro level (strategy, governance, design principles) and the micro level (roles, workflows, team composition). The macro level establishes the decision authority framework. The micro level implements it in specific workflows, with specific agents, for specific decisions.

The organizations that deliberately architect human-AI decision relationships are seeing measurable results. Research suggests that organizations addressing both structural "hardwiring" (decision rights, escalation paths, accountability) and cultural "softwiring" (leadership behaviors, psychological safety) are twice as likely to exceed AI investment returns and 2.5 times more likely to report superior financial performance.

The human-in-the-lead principle, discussed in the Arion Research article on enterprise AI security and in Part 4 of the "Orchestrating the Hybrid Workforce" series, applies directly to decision rights. Human-in-the-lead does not mean that a human reviews every individual decision. That is the approval theater problem described earlier. Human-in-the-lead means that humans define the decision architecture, set the boundaries, monitor the outcomes, and retain authority to override. The human leads the system. The human does not have to touch every decision the system makes.

This distinction maps directly to the decision authority tiers. At Tier 1, the human leads by defining the parameters. At Tier 2, the human leads by making the decision with AI support. At Tier 3, the human leads by deciding directly. In all three tiers, the human is in the lead. In none of them is the human required to be in the loop for every individual action.

The Competitive Implication

Decision rights architecture is the governance layer of the AI operating model. Without it, AI investment produces either bottlenecks (under-delegation) or risk (over-delegation). With it, organizations can deploy AI agents with confidence, speed, and accountability.

The competitive stakes are high. Organizations that get decision rights right will be able to deploy agents at Tier 1 for high-volume routine decisions, freeing human judgment for the decisions that require it. They will move faster because their decision processes will not be clogged with unnecessary reviews. They will manage risk better because their authority structures will be explicit and monitored, not informal and invisible.

The organizations that leave decision rights undefined will face a different trajectory. As agentic AI proliferates, the number of decisions made without clear authority will grow. The incidents will accumulate. The regulatory scrutiny will intensify. And the gap between their AI investment and their AI value will widen, for exactly the same reason it widened at the workflow level and at the operating model level: the technology changed, and the organization did not.

The next article in this series, "The Human-Agent Workforce," addresses the fourth dimension of the AI operating model: how roles, teams, and collaboration patterns must change when agents are permanent members of the workforce.


Strategy Playbook

1. Decision Authority Mapping. Inventory your top 50 AI-augmented decisions. For each, document: who currently makes it (human, agent, or unclear), what the appropriate authority level should be (Tier 1, 2, or 3), whether the current and appropriate levels match, and who is accountable when the decision is wrong. Any decision where the answer to "who decides?" is "unclear" is a governance gap that should be resolved before scaling.

2. Decision Classification Framework. Build a classification system based on stakes (reversible vs. irreversible), scope (narrow vs. broad impact), complexity (structured vs. unstructured), and regulatory sensitivity. Each combination maps to a decision authority tier and a set of governance requirements. This classification becomes the basis for evaluating new AI deployments: before an agent is deployed, its decisions must be classified and its authority level must be assigned.

3. Escalation Protocol Design. For every Tier 1 (agent acts freely) decision, define the conditions under which the agent must escalate to a human. For every Tier 2 (AI recommends, human decides) decision, define the information the agent must surface to support the human's decision. Test these protocols before deployment, not after an incident. The 47% of organizations that skip governance for urgent deployments are building escalation debt that compounds over time.

4. Decision Rights Review Cadence. Decision rights are not static. As organizational maturity increases (per the Dual Maturity Framework) and as agent capabilities improve, the appropriate authority level for a given decision may change. Establish a quarterly review process that adjusts decision authority based on performance data, incident history, and maturity progression. Decisions that have been Tier 2 for two quarters with zero escalation incidents and strong performance metrics may be candidates for Tier 1. Decisions where agent errors have surfaced should move up a tier until the root cause is resolved.


Arion Research advises enterprise leaders on AI strategy and the shift to a digital workforce.

Michael Fauscette

High-tech leader, board member, software industry analyst, author and podcast host. He is a thought leader and published author on emerging trends in business software, AI, generative AI, agentic AI, digital transformation, and customer experience. Michael is a Thinkers360 Top Voice 2023, 2024 and 2025, and Ambassador for Agentic AI, as well as a Top Ten Thought Leader in Agentic AI, Generative AI, AI Infrastructure, AI Ethics, AI Governance, AI Orchestration, CRM, Product Management, and Design.

Michael is the Founder, CEO & Chief Analyst at Arion Research, a global AI and cloud advisory firm; advisor to G2 and 180Ops, Board Chair at LocatorX; and board member and Fractional Chief Strategy Officer at SpotLogic. Formerly Michael was the Chief Research Officer at unicorn startup G2. Prior to G2, Michael led IDC’s worldwide enterprise software application research group for almost ten years. An ex-US Naval Officer, he held executive roles with 9 software companies including Autodesk and PeopleSoft; and 6 technology startups.

Books: “Building the Digital Workforce” - Sept 2025; “The Complete Agentic AI Readiness Assessment” - Dec 2025

Follow me:

@mfauscette.bsky.social

@mfauscette@techhub.social

@ www.twitter.com/mfauscette

www.linkedin.com/mfauscette

https://arionresearch.com
Previous
Previous

The Industrial AI Platform War Just Got Its Biggest Move

Next
Next

Workflow Architecture for the AI-Native Enterprise: From Task Augmentation to Process Reimagination