by Rehan Kausar

Photo courtesy of the author
In a multi-agent enterprise, the approval trail can be complete and correct — and still show that no one approved the outcome.
A bank deploys two AI agents. The first is authorized to analyze a customer relationship and recommend a retention offer. The second is authorized to amend certain account terms when it receives an approved business instruction. Both were risk-assessed. Both were approved by name in a governance forum. Both operate strictly inside the permissions they were granted.
The first agent concludes that a fee waiver is the right retention action and passes that conclusion downstream. The second treats that recommendation as satisfying its “approved business instruction” condition — because nothing in its permission set defines what makes an instruction approved, or who must have approved it — and executes.
Nothing was breached. No credential was stolen. Neither agent exceeded its permissions. And yet no one with authority to change that customer’s economic terms ever approved doing so.
A waived fee is a small thing. Now hold the same structure and change the action. A payment released. A credit decision issued. A customer’s rights altered. A representation made to a regulator. Nothing about the mechanism changes — only the size of what the institution has done without deciding to do it.
I have come to think of this as the compositional authority gap: the space between what each agent is permitted to do and what those agents, acting in sequence, can cause the enterprise to do. It is not a security failure. It is an authority failure, and the two are governed by different disciplines.
Compliance programs are built on the premise that documentation protects the institution. When something goes wrong, the firm produces the risk assessment, the approval minutes, the access reviews, and the audit log, and those artifacts demonstrate that the decision was made by someone entitled to make it.
Composition inverts that premise. The record is complete. Agent A’s authority is documented. Agent B’s authority is documented. Every API call is legitimate and logged. What the record establishes, with unusual clarity, is that the outcome the customer experienced was never the subject of an authorization decision by anyone with the standing to make it.
That is an uncomfortable evidentiary position. The institution has not lost the trail. It has a perfect trail to a gap.
Corporate authority doctrine assumes a human agent. A principal is bound by acts within actual or apparent authority;[1] where an employee acts outside it, the firm has arguments available to it — the act was unauthorized, it fell outside the scope of employment,[2] the counterparty could not reasonably have believed otherwise. Those arguments distribute responsibility between the institution and an individual who departed from instructions.
An AI agent offers no such distribution. It is not a legal person. It holds no authority of its own that it could exceed. It has no intent to disclaim and no employment to fall outside of. Whatever it does may ultimately be attributable to the enterprise — through a system the enterprise designed, permissioned, and deployed.
So the familiar defense becomes much harder to make. There may be no independent human actor to whom the unauthorized act can readily be attributed. Composition does not create a rogue agent. It creates an institutional act that no accountable human authorized — attributable to the enterprise, traceable to no one inside it.
Financial institutions already understand the underlying principle. One employee creates the vendor record. Another approves the invoice. A third releases payment. The separation exists because concentrating those authorities in one person creates a risk the institution has decided not to accept.
Now assign each task to a narrowly permissioned agent. Each passes its access review. Each satisfies least privilege. And an orchestrator — itself often modest in its permissions — coordinates all three toward a single objective.
Every local control holds. The global control does not. The institution can be simultaneously compliant at the level of each component and non-compliant at the level of the transaction, and standard control testing will not detect it, because standard control testing examines components.
The implication reaches internal control over financial reporting[3] and any framework built on separation of duties. A segregation control enforced per identity may not be enforced at all once identities can invoke, delegate to, or route work through one another — or through an orchestrator that holds no consequential permissions of its own.
There is a second exposure here, and it arrives quietly. Where an act is performed without authority, a principal that learns of it and knowingly accepts or retains its benefits may, depending on the circumstances, be treated as having ratified the act.[4]
Multi-agent systems will produce composed outcomes at volume. Most will be benign or beneficial. If an institution discovers that its agents are routinely producing outcomes no one authorized, and continues to accept the results because they are commercially useful, it may find that it has ratified the arrangement as a matter of practice — and with it, the authority structure that produced it.
The moment of discovery therefore carries obligations. An institution that identifies a compositional gap and does nothing has made a decision, whether or not anyone recorded it as one.
Conventional authorization asks a question about an actor: is this agent permitted to perform this action?
A multi-agent enterprise needs to ask a question about an outcome: should this institution permit this result to occur? Answering it means looking at what produced the proposed action. Who set the objective. Which agents took part. What authority passed between them. What the cumulative impact now is.
I would call the second question outcome admissibility. It is a governance test, not the evidentiary one that term usually signals, and it belongs before execution rather than after. The distinction matters because retrospective assurance, however rigorous, can only ever establish how the wrong thing happened. For consequential and irreversible actions — moving money, altering customer rights, making regulated representations — that is not a control. It is a reconstruction.
This is not an argument for human approval of every agent action; that would eliminate most of the value of autonomy and, worse, would produce the kind of ceremonial oversight that looks like a control and functions as an exposure. The principle is narrower: autonomy may scale with capability, but execution authority should scale with consequence.
In practice that means a gate the proposed action must pass before it executes — one that evaluates the combined permissions actually in play, the authority that passed between agents, and the cumulative impact, and routes anything above a consequence threshold to an independent control or a human.
Directors do not need to understand orchestration frameworks or agent protocols. They do need to understand concentration of autonomous authority. Delaware’s oversight jurisprudence provides a useful analogue: where a risk is mission-critical to the enterprise, boards are expected to ensure that appropriate reporting and monitoring systems exist.[5]
Five questions are enough to establish whether an institution has multi-agent governance or merely agent controls:
Can our agents invoke, delegate to, or route work through one another, or through an orchestrator?
Can individually permitted capabilities combine into a materially more powerful workflow?
Which business outcomes can now occur without any new authorization decision?
Where are segregation-of-duties boundaries enforced across autonomous workflows, rather than within individual agents?
Can we reconstruct not only what happened, but why the combined action was considered permissible before it executed?
An institution that cannot answer the fifth question has logging. It does not yet have governance.
The enterprise AI conversation has moved from models to data to responsible AI to agent identity and permissions. The next boundary is interaction. The question is no longer whether each agent is trustworthy. It is whether the system they form together stays inside what the institution intended.
Which leaves a question worth putting to management now, while the answer is still architectural rather than forensic:
If every agent involved was individually authorized, and the combined outcome was never approved, who authorized the enterprise to act?
That gap should be closed deliberately, before autonomous systems begin closing it on their own terms.
[1] Restatement (Third) of Agency, Sections 2.01 and 2.03 (Am. Law Inst. 2006) (actual and apparent authority).
[2] Restatement (Third) of Agency, Section 7.07 (Am. Law Inst. 2006) (respondeat superior; scope of employment).
[3] Sarbanes-Oxley Act of 2002, Section 404, 15 U.S.C. 7262; SEC Rule 13a-15, 17 C.F.R. 240.13a-15.
[4] Restatement (Third) of Agency, Sections 4.01 and 4.06 (Am. Law Inst. 2006) (ratification; knowledge of material facts).
[5] In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959 (Del. Ch. 1996); Stone v. Ritter, 911 A.2d 362 (Del. 2006); Marchand v. Barnhill, 212 A.3d 805 (Del. 2019).
Rehan Kausar is Chief AI Officer at AI Advantages.
The views, opinions and positions expressed within all posts are those of the author alone and do not represent those of the Program on Corporate Compliance and Enforcement (PCCE) or of the New York University School of Law. PCCE makes no representations as to the accuracy, completeness and validity or any statements made on this site and will not be liable any errors, omissions or representations. The copyright of this content belongs to the author and any liability with regards to infringement of intellectual property rights remains with the author.
by Rehan Kausar

Photo courtesy of the author
In a multi-agent enterprise, the approval trail can be complete and correct — and still show that no one approved the outcome.
A bank deploys two AI agents. The first is authorized to analyze a customer relationship and recommend a retention offer. The second is authorized to amend certain account terms when it receives an approved business instruction. Both were risk-assessed. Both were approved by name in a governance forum. Both operate strictly inside the permissions they were granted.
The first agent concludes that a fee waiver is the right retention action and passes that conclusion downstream. The second treats that recommendation as satisfying its “approved business instruction” condition — because nothing in its permission set defines what makes an instruction approved, or who must have approved it — and executes.
Nothing was breached. No credential was stolen. Neither agent exceeded its permissions. And yet no one with authority to change that customer’s economic terms ever approved doing so.
A waived fee is a small thing. Now hold the same structure and change the action. A payment released. A credit decision issued. A customer’s rights altered. A representation made to a regulator. Nothing about the mechanism changes — only the size of what the institution has done without deciding to do it.
I have come to think of this as the compositional authority gap: the space between what each agent is permitted to do and what those agents, acting in sequence, can cause the enterprise to do. It is not a security failure. It is an authority failure, and the two are governed by different disciplines.
Compliance programs are built on the premise that documentation protects the institution. When something goes wrong, the firm produces the risk assessment, the approval minutes, the access reviews, and the audit log, and those artifacts demonstrate that the decision was made by someone entitled to make it.
Composition inverts that premise. The record is complete. Agent A’s authority is documented. Agent B’s authority is documented. Every API call is legitimate and logged. What the record establishes, with unusual clarity, is that the outcome the customer experienced was never the subject of an authorization decision by anyone with the standing to make it.
That is an uncomfortable evidentiary position. The institution has not lost the trail. It has a perfect trail to a gap.
Corporate authority doctrine assumes a human agent. A principal is bound by acts within actual or apparent authority;[1] where an employee acts outside it, the firm has arguments available to it — the act was unauthorized, it fell outside the scope of employment,[2] the counterparty could not reasonably have believed otherwise. Those arguments distribute responsibility between the institution and an individual who departed from instructions.
An AI agent offers no such distribution. It is not a legal person. It holds no authority of its own that it could exceed. It has no intent to disclaim and no employment to fall outside of. Whatever it does may ultimately be attributable to the enterprise — through a system the enterprise designed, permissioned, and deployed.
So the familiar defense becomes much harder to make. There may be no independent human actor to whom the unauthorized act can readily be attributed. Composition does not create a rogue agent. It creates an institutional act that no accountable human authorized — attributable to the enterprise, traceable to no one inside it.
Financial institutions already understand the underlying principle. One employee creates the vendor record. Another approves the invoice. A third releases payment. The separation exists because concentrating those authorities in one person creates a risk the institution has decided not to accept.
Now assign each task to a narrowly permissioned agent. Each passes its access review. Each satisfies least privilege. And an orchestrator — itself often modest in its permissions — coordinates all three toward a single objective.
Every local control holds. The global control does not. The institution can be simultaneously compliant at the level of each component and non-compliant at the level of the transaction, and standard control testing will not detect it, because standard control testing examines components.
The implication reaches internal control over financial reporting[3] and any framework built on separation of duties. A segregation control enforced per identity may not be enforced at all once identities can invoke, delegate to, or route work through one another — or through an orchestrator that holds no consequential permissions of its own.
There is a second exposure here, and it arrives quietly. Where an act is performed without authority, a principal that learns of it and knowingly accepts or retains its benefits may, depending on the circumstances, be treated as having ratified the act.[4]
Multi-agent systems will produce composed outcomes at volume. Most will be benign or beneficial. If an institution discovers that its agents are routinely producing outcomes no one authorized, and continues to accept the results because they are commercially useful, it may find that it has ratified the arrangement as a matter of practice — and with it, the authority structure that produced it.
The moment of discovery therefore carries obligations. An institution that identifies a compositional gap and does nothing has made a decision, whether or not anyone recorded it as one.
Conventional authorization asks a question about an actor: is this agent permitted to perform this action?
A multi-agent enterprise needs to ask a question about an outcome: should this institution permit this result to occur? Answering it means looking at what produced the proposed action. Who set the objective. Which agents took part. What authority passed between them. What the cumulative impact now is.
I would call the second question outcome admissibility. It is a governance test, not the evidentiary one that term usually signals, and it belongs before execution rather than after. The distinction matters because retrospective assurance, however rigorous, can only ever establish how the wrong thing happened. For consequential and irreversible actions — moving money, altering customer rights, making regulated representations — that is not a control. It is a reconstruction.
This is not an argument for human approval of every agent action; that would eliminate most of the value of autonomy and, worse, would produce the kind of ceremonial oversight that looks like a control and functions as an exposure. The principle is narrower: autonomy may scale with capability, but execution authority should scale with consequence.
In practice that means a gate the proposed action must pass before it executes — one that evaluates the combined permissions actually in play, the authority that passed between agents, and the cumulative impact, and routes anything above a consequence threshold to an independent control or a human.
Directors do not need to understand orchestration frameworks or agent protocols. They do need to understand concentration of autonomous authority. Delaware’s oversight jurisprudence provides a useful analogue: where a risk is mission-critical to the enterprise, boards are expected to ensure that appropriate reporting and monitoring systems exist.[5]
Five questions are enough to establish whether an institution has multi-agent governance or merely agent controls:
Can our agents invoke, delegate to, or route work through one another, or through an orchestrator?
Can individually permitted capabilities combine into a materially more powerful workflow?
Which business outcomes can now occur without any new authorization decision?
Where are segregation-of-duties boundaries enforced across autonomous workflows, rather than within individual agents?
Can we reconstruct not only what happened, but why the combined action was considered permissible before it executed?
An institution that cannot answer the fifth question has logging. It does not yet have governance.
The enterprise AI conversation has moved from models to data to responsible AI to agent identity and permissions. The next boundary is interaction. The question is no longer whether each agent is trustworthy. It is whether the system they form together stays inside what the institution intended.
Which leaves a question worth putting to management now, while the answer is still architectural rather than forensic:
If every agent involved was individually authorized, and the combined outcome was never approved, who authorized the enterprise to act?
That gap should be closed deliberately, before autonomous systems begin closing it on their own terms.
[1] Restatement (Third) of Agency, Sections 2.01 and 2.03 (Am. Law Inst. 2006) (actual and apparent authority).
[2] Restatement (Third) of Agency, Section 7.07 (Am. Law Inst. 2006) (respondeat superior; scope of employment).
[3] Sarbanes-Oxley Act of 2002, Section 404, 15 U.S.C. 7262; SEC Rule 13a-15, 17 C.F.R. 240.13a-15.
[4] Restatement (Third) of Agency, Sections 4.01 and 4.06 (Am. Law Inst. 2006) (ratification; knowledge of material facts).
[5] In re Caremark Int’l Inc. Derivative Litig., 698 A.2d 959 (Del. Ch. 1996); Stone v. Ritter, 911 A.2d 362 (Del. 2006); Marchand v. Barnhill, 212 A.3d 805 (Del. 2019).
Rehan Kausar is Chief AI Officer at AI Advantages.
The views, opinions and positions expressed within all posts are those of the author alone and do not represent those of the Program on Corporate Compliance and Enforcement (PCCE) or of the New York University School of Law. PCCE makes no representations as to the accuracy, completeness and validity or any statements made on this site and will not be liable any errors, omissions or representations. The copyright of this content belongs to the author and any liability with regards to infringement of intellectual property rights remains with the author.







