Blog Zscaler
Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta
When Your Team Includes Non-Humans, Leadership Changes
The question many are asking is what might more capable AI do? Recent conversations now frame AI in terms of agency, not just intelligence because there’s little to no doubt around the latter. Where the doubt creeps in, particularly in an enterprise setting, is the loss of control when autonomous actors begin exploring beyond current guardrails.
So, I’d say, the better question is what must leaders do differently? Let’s put aside conjecture on what AI might become. The more immediate challenge is deciding what leadership must become when non-human actors participate in decision-making at work.
Managing the unmanageable
Before agentic arrived on the scene, the human-AI workplace relationship was much simpler and more predictable. We made the decisions, generative models carried out our instructions. But agents introduce initiative: they can trigger workflows and influence outcomes.
The fact is we’re introducing a level of unpredictability in enterprise ecosystems built for predictability. We've imbued this technology with the non-deterministic attributes of a human and given it enormous, unprecedented reach, knowing full well that it can act very quickly. All of this power and freedom means we don't have full visibility into where our agentic systems are embedded and what they can do, when they could break away from our guardrails, and how far they could go when they do. In other words, agentic makes risk much harder to judge: the impact has become unbounded and the probability is less certain (not that it was all that certain to begin with). This new dynamic should change the way we think about and manage risk.
The problem is that authority appears to be easier to assign than accountability. One deployed agent may find the need to interact with another agent that is already interacting with a third agent. When a decision is made and an outcome produced, there’s no clear way to answer a few of the most foundational questions: Who requested the task? Who approved the decision? Who authorized the follow-on action? Who owns the outcome?
The issue isn't that the agent, in finding the most efficient pathway to meet its goal, made a bad decision. It’s the fact that when responsibility becomes distributed, verifying chains of authenticity becomes complicated and accountability becomes blurred. And, if accountability becomes harder to establish, leaders will need a more precise way to govern what humans and agents are allowed to do.
Define before delegate
Authentication asks whether a human or machine is who it claims to be. Authorization asks a more pertinent question in the agentic age: what is this user, agent or human, allowed to do? Control needs to become less about letting a trusted identity through the door and more about continuously limiting the actions that each human, machine or agent is permitted to take. Further, the more fine-grained and specific authorization is, the better. And if there’s one thing we’re seeing from the reaction to and analysis of the Hugging Face incident, it’s that we need to far better understand the individual and collective behavior of agents. With insight into agents’ incentives, their motivations and their use of resources in even the simplest of environments, we’ll be in a better position to judge what they should be allowed to do.
Too many organizations begin their AI journey asking which models they should deploy. They really should focus on the outcomes they want they want, enterprise culture and, most importantly, which decisions they are comfortable delegating as these models become more and more autonomous in their actions. Understanding this also gives insight into the privileges and scope the enterprise is unwilling to delegate: these are the rules for agentic engagement. And, you’ll notice, it’s a business decision that should happen before the technology deployment.
More than that, it’s a strategic choice. Two companies can deploy the exact same model, with the same technical security controls in place, but roll out entirely different governance decisions. These decisions will be uniquely shaped around their risk appetite, commercial priorities and objectives. For example, consider how the same Data Loss Protection (DLP) control would be managed by a defense contractor versus a law firm. The contractor would block access to plans for a weapons system at all costs; the law firm simply wants to monitor and manage the flow of information. Same control, different governance policy. Why? Because if a defense counterpart across enemy lines can build the same jet, you’re talking about a threat to national security, but if a peer law firm steals your data, you can take legal action to stop it from being used. The difference in DLP governance is outcome-driven and cultural: shaped by attitudes to acceptable risk and control.
The future may well see non-human contributors become a normal part of the workforce. But the real leadership challenge isn't deciding whether to work alongside agents. It's deciding where authority ends, where accountability begins, and how those boundaries are maintained as humans and agents increasingly work more seamlessly together.
Leadership's job now is not simply to govern technology. It's to ensure predictability, accountability and responsibility remains clear, even when the workforce is no longer entirely human.
Agentic AI is both a risk to manage and a force to harness. For enterprise guidance on reducing the risks and reaping the rewards, including a deployment checklist and agent performance framework - read the white paper.
Questo post è stato utile?
Esclusione di responsabilità: questo articolo del blog è stato creato da Zscaler esclusivamente a scopo informativo ed è fornito "così com'è", senza alcuna garanzia circa l'accuratezza, la completezza o l'affidabilità dei contenuti. Zscaler declina ogni responsabilità per eventuali errori o omissioni, così come per le eventuali azioni intraprese sulla base delle informazioni fornite. Eventuali link a siti web o risorse di terze parti sono offerti unicamente per praticità, e Zscaler non è responsabile del relativo contenuto, né delle pratiche adottate. Tutti i contenuti sono soggetti a modifiche senza preavviso. Accedendo a questo blog, l'utente accetta le presenti condizioni e riconosce di essere l'unico responsabile della verifica e dell'uso delle informazioni secondo quanto appropriato per rispondere alle proprie esigenze.
Ricevi gli ultimi aggiornamenti dal blog di Zscaler nella tua casella di posta
Inviando il modulo, si accetta la nostra Informativa sulla privacy.



