Skip to content

The AI Agent Era Is Here. Who Gave the Machines Authority?

The AI Agent Era Is Here. Who Gave the Machines Authority?

Tomorrow, Sam Altman will take the stage at OpenAI DevDay in San Francisco. The most consequential announcement may not be a new model.

It may be an agent.

0:00
/0:12

OpenAI has not confirmed it, but reporting ahead of DevDay points to a new agent platform codenamed Aeon, potentially a continuously running personal assistant designed to compete in a category that barely existed a year ago and is suddenly becoming one of the most contested markets in technology. OpenAI has confirmed the September 29 event and a keynote from Altman, but not Aeon itself.

The rumor is revealing even if the product never appears onstage.

For the past several years, AI companies competed to build the model you wanted to talk to. Now they are competing to build the agent you are willing to let act for you.

That is a much bigger transition.

A chatbot answers a question. An agent books the flight, calls the restaurant, pays the bill, updates the spreadsheet, sends the email, schedules the meeting, changes the reservation, or asks another agent to finish the job.

The difference is not simply intelligence.

It is authority.

And that is where the next great AI battle begins.

From Artificial Intelligence to Artificial Agency

We have spent much of the AI boom measuring intelligence.

Can a model write better than a person? Code faster? Analyze a financial statement? Pass a professional exam? Solve increasingly difficult reasoning benchmarks?

Those questions made sense when AI largely produced information and humans remained responsible for what happened next.

Agents change that relationship.

Ask an AI assistant to find a flight to New York and it might compare schedules and recommend an itinerary. Give a capable personal agent the same assignment and it can check your calendar, remember your airline and seat preferences, book the ticket, add it to your itinerary, notify the people you are meeting, arrange transportation and modify the trip later if your plans change.

The model required to recommend the trip and the model required to book it may not be dramatically different.

What changes is the discretion we give it.

We are moving from artificial intelligence to artificial agency: software that does not merely help people understand the world, but increasingly acts within it on their behalf.

That shift matters commercially too.

As intelligence becomes more abundant and models become easier to substitute, winning may depend less on having the best model on a particular Tuesday and more on creating new behavior, gaining distribution and becoming the platform people use to get things done.

That is one of the most useful insights in a recent a16z analysis of OpenAI's strategy: the durable advantage may come from creating new categories of customer behavior and achieving distribution rather than relying on model-level switching costs, which remain relatively weak.

ChatGPT itself was an example. The breakthrough was not simply that a model could generate text. Hundreds of millions of people learned a new behavior: describe almost any problem to a machine and expect something useful back.

Agents could produce the next behavioral shift.

Instead of describing a problem and expecting an answer, we delegate a problem and expect a result.

The Personal Agent Race Is Already Here

The market is taking shape quickly, and the leading products already illustrate different versions of where this could go.

Meta's Muse is the clearest mass-market consumer push. Muse can send email, book travel, fill out forms, shop, remember personal context and work on tasks after the user leaves the application. Meta built it around a dedicated secure virtual machine and lets users determine which services it can access and whether it may read from or act within them. Sensitive actions such as purchases require approval, and users can see an audit trail of what Muse has done.

Muse is also moving beyond the phone. At Meta Connect, the company announced that Muse is coming to its AI glasses, giving people a hands-free way to interact with the agent throughout the day. Meta's stated direction is telling: a family of devices through which people can connect with their personal agent wherever they are.

Instinct approaches the opportunity from a more personal, conversational direction. Its agent can now place phone calls, act as a concierge, manage its own email identity and coordinate with other people's agents through a trusted network. That means the agent can call a restaurant that does not take online reservations, follow up with a business, create accounts needed to complete a task or coordinate plans with someone else's assistant.

Then there is Grok Bot, positioned more directly around work. Bloomberg reported that it reached more than 400,000 weekly users within roughly a month of launch. The broader product is designed less like a chatbot and more like an always-on employee that can answer emails, work across business systems, process invoices and organize work.

The contrast is useful.

Muse wants to act across your consumer life.

Instinct wants to become a deeply personal representative.

Grok Bot wants to become a persistent coworker.

OpenAI may soon enter with Aeon.

Different products, same underlying shift: software is moving from something we operate to something we authorize.

Everyone Gets a Chief of Staff

The easiest way to understand the appeal of the personal agent may be to stop thinking about chatbots entirely.

Think of it as giving everyone a chief of staff.

A great executive assistant does not wait for instructions before every action. They learn preferences. They understand relationships. They coordinate with other assistants. They know what can be handled without escalating it and what requires a decision.

Most importantly, they reduce interruption.

That is what makes the emerging personal-agent use cases so compelling.

Did we order more paper towels? What forms are due at school? Which gate does my flight leave from? When does the return window close? When did I last see that friend? What do we have in the refrigerator, and what could we make tonight?

None of those tasks requires superintelligence.

What makes an agent valuable is context plus authority.

It knows the flight because it can see the itinerary. It knows your preferences because it remembers previous decisions. It knows whether dinner works because it can understand calendars. It knows which school email matters because it can separate the permission slip from the fundraising announcement.

The real change comes when you stop asking.

The gate changes and your agent tells you. The return window closes Friday and the pickup is arranged. You have not seen a close friend in months and your agent identifies a night that works for both of you. Your mother mentioned a cookbook in March and it resurfaces before her birthday.

For decades, we have opened applications, navigated interfaces and told computers what to do.

Agents reverse some of that relationship. The system maintains context, notices what matters and acts within boundaries established beforehand.

The best personal agent may therefore be the technology we spend the least time looking at.

From Attention to Delegation

That represents a significant change in the economics of technology.

For decades, consumer software competed for attention.

Search engines wanted queries. Social networks wanted engagement. Streaming companies wanted viewing time. Applications wanted daily active users.

Agents compete for something else.

A good agent may become more valuable precisely because you interact with it less. You establish preferences and boundaries, then trust it to handle the routine work.

The interface moves from attention to delegation.

And delegation is more consequential than engagement.

When we delegate something to another person, we give them discretion. We do not specify every step. We are effectively saying: handle this, use your judgment, and involve me when necessary.

That is what makes a great human assistant valuable.

It is also what makes an agent powerful.

The potential moat in personal AI therefore may not be intelligence alone. Models will continue improving. Price-performance gaps will move. Developers will increasingly switch models depending on the task.

What is much harder to reproduce is a relationship in which millions of people have learned to trust a platform to act for them.

Once an agent understands your preferences, relationships, routines and boundaries, the switching cost begins to look less like moving from one model to another and more like replacing someone who knows how your life works.

The scarce asset could become trusted delegation.

From Apps to Ambient Agency

This is why the personal-agent race will probably become a contest over more than applications.

Many of the most useful everyday interactions barely require a screen.

Check me in.

Which gate am I going to?

Tell me when it is time to leave.

What's next on my calendar?

Remind me what I need for school tomorrow.

Tell me about the building I'm standing in front of.

These are naturally ambient and often voice-first.

Useful personal agents also need continuity. They have to understand what is happening across the day rather than what occurred during a single chat session.

That gives operating systems and devices an important role. Hardware provides presence and context. Operating systems sit between applications, identity, sensors, communications, permissions and data.

Meta bringing Muse to its AI glasses is an early example. The agent is moving out of the chat window and into the physical flow of the day.

The smartphone made computing something we carried everywhere.

The personal agent could make computing something that is acting everywhere on our behalf.

That also raises the stakes.

When AI lived inside an application, there was usually a clear moment when someone chose to use it.

An ambient agent can remain continuously present. It can watch for relevant events, remember instructions and initiate actions days or months after the original conversation.

Delegation stops being episodic.

It becomes persistent.

We Gave the Internet Our Data. Agents Want Our Authority.

A search engine knows what you search for. A social network knows what you engage with. An ecommerce company knows what you buy. Your phone knows where you go.

A sophisticated personal agent could eventually understand all of it: your communications, calendar, finances, travel, family, relationships, preferences, professional responsibilities and health information.

But the important difference from the technology platforms that came before it is not simply how much an agent knows.

It can act on what it knows.

We spent the internet era worrying, correctly, about what companies could do with our data.

The agentic era adds another question: what can machines do with our authority?

Knowing my calendar is one thing. Changing it is another.

Knowing my bank balance is one thing. Moving money is another.

Knowing my medical history is one thing. Calling a physician's office and changing an appointment is another.

Knowing who my colleagues are is one thing. Communicating with them as my representative is another.

Privacy still matters enormously.

But privacy asks: Who gets my information?

Agency asks: What are they allowed to do with it?

Your Personal Agent May Become Your Authority Layer

The personal-agent market may not produce a single agent that is best at everything.

A more likely architecture is a general agent surrounded by specialized agents.

A travel agent understands airlines, hotels and itineraries. A financial agent understands investments and taxes. A medical agent understands health records. A parenting agent understands schools and family logistics.

Your personal agent becomes the intermediary between those specialists and your life.

More importantly, it could become your authority layer.

A medical agent should not need your bank account. A financial agent should not need your family photos. A travel agent may need your passport information, calendar and payment authorization, but it probably does not need access to your medical records.

Your personal agent could selectively provide another agent only the information and authority necessary to complete an assignment.

That creates a chain:

You → Personal Agent → Specialized Agent → External Agent

Tell your agent to plan spring break, and one instruction could trigger a travel agent to research destinations, an airline agent to find flights, a hotel agent to negotiate a reservation and a payment agent to complete the transaction.

A simple human request has become a chain of delegated authority spanning multiple machines and companies.

Who authorized whom?

What information traveled down the chain?

How much could each agent spend?

Could one agent delegate its authority to another?

When did that authority expire?

Those questions move us beyond privacy and cybersecurity.

They are questions of governance.

The First Agent Border Disputes Are Already Appearing

Muse has already provided an early example of another problem the agentic economy will have to solve.

According to reporting provided around Muse's launch, Amazon blocked the agent from accessing its store, arguing that Meta's agent was not authorized to operate there.

That dispute is significant because it exposes an important distinction.

You may authorize your agent to act for you. That does not automatically require another institution to recognize the agent's authority.

If I authorize my agent to buy something on my behalf, what obligation does a retailer have to accept that agent? How does the retailer verify that the delegation is genuine? What terms govern the interaction? Who is liable when the agent misunderstands an offer or violates a site's rules?

The internet has standards for moving information.

The agentic internet will need standards for recognizing delegated authority.

That may eventually become as fundamental as identity itself.

Now Bring the Same Problem Into the Corporation

The enterprise version is even more consequential.

A procurement agent can negotiate with suppliers. A finance agent can monitor cash. A sales agent can communicate with prospects. A cybersecurity agent can respond to threats. An investor-relations agent can answer shareholder questions. A software engineering agent can write, test and deploy code.

Agents can also increasingly collaborate with other agents.

Grok Bot's Team Bots illustrate the direction. Shared agents can operate from common context, use plugins and credentials, remember what they learn, coordinate work in tools such as Slack and launch other agents to complete tasks.

In one described engineering workflow, a Team Bot coordinated work across project systems and cloud coding agents. The significance is not the particular product. It is the organizational architecture it points toward.

The enterprise begins to include people managing agents, agents coordinating people, and agents directing other agents.

The familiar corporate chain of authority begins to change.

For generations, it looked roughly like:

Shareholders → Board → Management → Employees

Now it can become:

Shareholders → Board → Management → Employees → Agents

And eventually:

Shareholders → Board → Management → Agents → Agents

Corporate governance was not designed around that final chain.

After Shadow IT and Shadow AI Comes Shadow Agency

Corporations have spent centuries developing systems for governing human authority.

Employees have roles. Executives have delegated authorities. Managers have approval thresholds. Bank accounts have signatories. Procurement teams have spending limits. Boards have committee charters.

Behind nearly every consequential corporate action sits an answer to one question:

Who is authorized to do what on behalf of whom?

Agents need to fit into that architecture.

Consider a procurement agent instructed to reduce technology costs.

Can it negotiate with vendors?

Can it disclose confidential pricing?

Can it switch suppliers?

Can it commit $10,000?

$1 million?

Can it enter a multiyear contract?

Can it ask another agent to negotiate part of the agreement?

Those are not model-performance questions.

They are questions of delegated authority.

Companies have already dealt with shadow IT, when employees adopted software outside approved processes. Then came shadow AI.

The next challenge is shadow agency: agents operating across an enterprise with identities, credentials, data access and authority that leadership cannot fully see.

Recent EY research suggests the gap is already emerging. Ninety-one percent of surveyed senior AI executives at large organizations said they were piloting or deploying agentic AI, while 85% said at least some agents were executing actions without real-time human involvement. Nearly half said their governance frameworks had not been updated for agentic AI, and more than a quarter said they could not detect unauthorized agents operating internally.

That is not simply an AI policy problem.

It is a control problem.

Every Agent Needs a Mandate

The obvious answer is to keep a human in the loop.

That will not scale.

If agents perform millions of routine actions across an enterprise, humans cannot meaningfully approve each one. Governance has to move from approving individual actions to defining the boundaries within which machines may act.

Organizations already understand this idea.

Employees have job descriptions. Executives have delegated authorities. Procurement teams have spending limits. Boards have committee charters.

Agents need the machine-readable equivalent.

Call it an Agent Mandate.

An Agent Mandate defines whom the agent represents, why it exists, what systems and information it may use, what decisions it may make, how much it may spend, which actions are prohibited, when it must escalate, whether it may delegate authority, who remains accountable and when that authority expires.

The concept itself is not revolutionary.

The implementation is.

An agent's mandate cannot live only in a PDF reviewed once a year. It needs to become machine-readable, continuously enforceable and independently verifiable.

Access Is Not Authority

This distinction will become increasingly important as the agent infrastructure stack develops.

Technology companies are creating identities for agents. Cybersecurity companies are building agent security. Enterprise platforms are developing orchestration systems. Payment networks are creating infrastructure for agentic commerce.

All of those layers matter.

None answers the central governance question:

Was the agent legitimately authorized to take this action?

Identity establishes who the agent is.

Authentication determines whether that identity is genuine.

Permissions establish which systems the agent can technically access.

Security protects the interaction.

Observability records what happened.

Governance determines what the agent was legitimately empowered to do, on whose behalf, under what conditions and with whose accountability.

We already understand this distinction with humans.

A corporate executive may have authenticated access to the company's banking systems without having authority to wire $100 million to acquire another company.

Access and authority are not the same thing.

They cannot be the same thing for agents.

Cybersecurity has long operated around the principle of least privilege: give someone only the access necessary to perform the job.

The agentic enterprise needs an additional principle: least agency.

Give an agent only the authority necessary to fulfill its mandate, for only as long as necessary, with explicit limits on its ability to pass that authority to another agent.

What Boardroom Leaders Should Do Now

Boards do not need to approve individual agent decisions, and directors do not need to become AI engineers. But they should expect management to answer one question clearly:

What authority have we delegated to machines?

That question should lead to several immediate actions.

Inventory agents, not just models. Management should know which consequential agents operate across the enterprise, who owns them, what systems and data they can access, and what actions they can perform. A model inventory is no longer enough once AI can act.

Map machine authority. Identify where agents can communicate externally, move money, modify systems, access sensitive information, make consequential decisions or otherwise bind the organization. Focus on discretion, not simply AI usage.

Establish Agent Mandates. Consequential agents should have a defined principal, purpose, scope, authority, constraints, escalation requirements, accountable executive and expiration or review mechanism.

Apply least agency. Technical access should not automatically confer broad authority. Give agents only the discretion required to perform their mandate, for only the period during which it is needed.

Govern agent-to-agent delegation. Management should understand whether agents can create, instruct or authorize other agents and how authority changes as it travels through those chains.

Prepare for personal agents entering the workplace. Employees will increasingly bring their own agents into corporate communications, meetings, workflows and information environments. Personal agents may become the next BYOD and shadow-AI challenge.

Require evidence, not assurances. Management should be able to demonstrate what an agent was authorized to do, what it actually did, which controls operated and who remained accountable.

Make governance continuous. Agents operate continuously. Their models, permissions, tools and environments change. Governance cannot remain an annual policy exercise. It has to become part of the operating infrastructure of the enterprise.

The Question That Comes After Intelligence

Tomorrow, OpenAI may introduce Aeon. It may call it something else. It may announce something entirely different.

The product details will matter for the competitive landscape.

They matter less for the larger story.

That story is already underway.

Technology is moving from attention to delegation.

For decades, the most valuable consumer platforms competed for our clicks, searches, screen time and engagement.

The next generation will compete for something more consequential: our trust and our authority.

The agent that ultimately matters most may not be the one we spend the most time looking at.

It may be the one we trust enough that we no longer have to look.

The one that understands what matters. The one that handles the routine decisions. The one that communicates, negotiates and transacts in our name. The one that knows when it can act and when it must ask.

Inside corporations, the same change will unfold at enormous scale.

The enterprise architecture of the last generation was built around human authority exercised through software.

The next will increasingly include machine authority exercised on behalf of people and institutions.

We are already building the models, devices, identity systems, payment rails and protocols that will make that world possible.

Now we need to build the governance infrastructure that will make it trustworthy.

Because when my agent encounters your agent, it will not be enough to know which model is smarter.

We will need to know:

Who do you represent?

What are you authorized to do?

Where did that authority come from?

Can you delegate it?

And can you prove it?

The first chapter of AI was about what machines could know.

The next was about what they could create.

The chapter opening now is about what we allow them to do in our names.

That is the question boards, executives and consumers need to start asking before agents become invisible parts of everyday life.

The defining governance challenge of the agentic age will not be governing intelligence.

It will be governing authority.

Steven Wolfe Pereira

Steven Wolfe Pereira

Steven Wolfe Pereira is Founder & CEO of Alpha, an AI governance intelligence company serving boards and executives. Former C-suite executive at Datalogix / Oracle, Neustar, and Quantcast; board member, startup advisor and Forbes contributor.

All articles

More in AI Agents

See all

More from Steven Wolfe Pereira

See all