Part 1: The Governance Paradox of Agentic AI

2026-07-13
Article Banner

By Dr. Kevin Shepherdson, CEO and Founder of Straits Interactive


For many years, one of the fundamental principles we teach in our data protection programmes with SMU Academy is deceptively simple: “You can delegate the task, but you can never delegate the responsibility”.

It is a principle that organisations frequently overlook when outsourcing the processing of personal data. While a third-party service provider may perform the operational work, the organisation that collected the personal data remains ultimately accountable for ensuring that it is processed lawfully, securely and responsibly. The task may be outsourced, but the responsibility never leaves the organisation.

Today, as organisations race to adopt Agentic AI, I am beginning to see the very same mistake being repeated—only on a much larger scale.

We are no longer asking AI to draft emails, summarise reports or answer questions. Increasingly, we are asking autonomous AI agents to plan, reason, make decisions, call tools, execute workflows, write software and even evaluate their own work.

Welcome to the age of Agentic AI.

The demonstrations are extraordinary. Give an AI agent a goal and it appears to work tirelessly on your behalf. It breaks down complex problems into smaller tasks, searches the web, writes code, invokes APIs, fixes its own mistakes, retries failed steps and eventually returns with a completed solution.

It is easy to watch these demonstrations and reach a seductive conclusion: "If AI can perform the work, perhaps we no longer need the people."

After spending considerable time experimenting with today's generation of autonomous AI development platforms and coding agents, I came away with a very different conclusion. The technology is genuinely impressive.

The hype, however, is causing many organisations to overlook one of the oldest principles of governance.

Ironically, this is precisely what many organisations are beginning to do with Agentic AI—they are delegating not only the task, but also, knowingly or unknowingly, the responsibility.

The CEO Psychosis

One of the biggest risks surrounding Agentic AI is not the technology itself. It is human psychology.

Executives are shown polished demonstrations where an AI agent builds an application, writes thousands of lines of code, analyses data or completes a business process with remarkable speed. The demonstrations are carefully orchestrated. The objective is clear. The data is clean. The environment is controlled. Every dependency behaves exactly as expected.

The result is a dangerous illusion. Box CEO Aaron Levie coined the specific phrase "AI psychosis" (or jokingly "CEO psychosis"). He used it to describe executives who are so detached from day-to-day implementation that they fall for AI hype, mistakenly believing impressive AI demos can automatically handle complex real-world work. It is the tendency to mistake a successful demonstration for organisational readiness.

A happy-path demonstration quietly hides everything that matters in the real world:

1. Incomplete information

2. Conflicting objectives

3. Changing business rules

4. Malicious inputs

5. Regulatory obligations

6. Organisational politics

7. Human judgement

8. Ethical trade-offs

9. Operational failures

An impressive demonstration proves only one thing: The AI succeeded under ideal conditions. It says very little about what happens when reality intervenes.

Jobs Are More Than Tasks

The current narrative surrounding AI displacement often begins with a deceptively simple observation.

1. AI can write marketing copy.

2. AI can generate job advertisements.

3. AI can answer customer enquiries.

4. AI can prepare legal summaries.

Therefore, the argument goes, AI can replace the job. This is where the mistake begins.

A job is not simply a collection of disconnected tasks. It is an interconnected system of responsibilities, judgement, relationships, escalation, accountability and context. Yet this distinction is often ignored when organisations pursue aggressive automation strategies.

The result is no longer theoretical. Job displacement is already happening because some organisations have treated task automation as evidence that the entire job can be removed. In a few cases, companies have had to rethink that assumption after service quality, customer experience or operational outcomes suffered.

Klarna, a global fintech company, is one widely discussed example. After promoting the idea that its AI assistant could do the work of hundreds of customer service agents, the company later moved to reintroduce more human involvement in customer service after concerns about service quality emerged. Its spokesperson reportedly framed the shift clearly: AI provides speed, but human talent provides empathy.

This is the point many organisations miss. AI may complete the visible task. But the human role often carries the invisible responsibility.

Consider a marketing executive. AI can generate:

1. Advertisements

2. Social media campaigns

3. Email marketing

4. Product descriptions

5. Campaign reports

But marketing executives are responsible for something much larger:

1. Brand positioning

2. Customer trust

3. Legal compliance

4. Cultural sensitivity

5. Reputation management

6. Crisis response

7. Strategic direction

The AI may create the advertisement. The executive remains responsible for the consequences.

The task may be delegated. The responsibility cannot.

Agentic AI Changes the Rules

Traditional AI operated largely as an assistant. The workflow was straightforward:
Human → AI → Human Approval

Agentic AI introduces something fundamentally different.

The workflow now resembles:

Human defines the goal

AI plans

AI reasons

AI calls tools

AI evaluates results

AI retries failed actions

AI executes

Human receives the outcome


Notice what disappeared. The human. Not entirely—but from many of the intermediate decisions. The distance between execution and accountability has never been greater.

"The AI Decided" — No, It Didn't

Whenever an autonomous system makes a mistake, we hear the same explanation. "It was the AI that decided." This statement is both convenient and misleading.

The AI did not wake up one morning and invent its own operating principles. Humans determined:

1. Which model would perform the reasoning

2. Which tools the agent could access

3. Which system prompts defined its behaviour

4. Which constraints were imposed

5. Which permissions were granted

6. Which retry limits existed

7. Which costs were acceptable

8. Which safety guardrails were implemented—or omitted

The agent simply operated within the environment humans designed.

The Air Canada chatbot case, which we share in our Apps Design and Prompt Engineering – Customer Service module, illustrates this point clearly. In Moffatt v. Air Canada, a customer relied on incorrect information from Air Canada’s chatbot about bereavement fare refunds. Air Canada was ultimately held responsible for the misinformation provided through its chatbot. The tribunal made the point plainly: the chatbot was still part of Air Canada’s website, and the company remained responsible for the information it provided.

That is the governance lesson.

When organisations say, "the AI decided," they often overlook the fact that every autonomous behaviour was enabled by an earlier human decision. Whether the mistake comes from a static webpage, chatbot, workflow automation or autonomous agent, the accountability does not shift to the machine.

Responsibility has not disappeared. It has merely become harder to see.

No-Code Doesn't Eliminate Engineering. It Hides It.

Today's no-code and low-code platforms are remarkable.

Business professionals can now build applications that previously required entire development teams. AI agents generate databases, workflows, APIs, user interfaces and integrations within minutes.

This is a significant step forward. But it has also created another misconception. Many people assume that because they did not write code, they no longer need to understand how the application works.

The reality is very different. Software engineering has not disappeared. It has simply shifted. Instead of writing code, builders now need to think about:

1. Defining goals

2. Designing workflows

3. Managing context

4. Engineering prompts

5. Configuring guardrails

6. Selecting tools

7. Controlling permissions

8. Handling memory

9. Managing costs

10. Validating outputs

11. Governing autonomous behaviour

In other words, we are replacing programming complexity with governance complexity. The technology has become easier. But the responsibility has not.

Closing Thoughts

As AI agents become more autonomous, it is tempting to believe that responsibility somehow shifts with the task. It doesn't.

Whether an organisation outsources the processing of personal data to a third party, deploys an AI-powered chatbot, or gives an autonomous agent permission to plan, reason and execute workflows, one principle remains unchanged:

You can delegate the task, but you can never delegate the responsibility. The real challenge, therefore, is not deciding whether AI should make more decisions.

It is deciding how those decisions should be governed. Unfortunately, much of today's conversation is still centred on what AI can do rather than what organisations should be accountable for when things go wrong.

That is the governance paradox of Agentic AI. But there is another misconception quietly emerging alongside it.

Many organisations still believe that the future belongs to those with the best AI technology. I believe they are looking in the wrong place.

As AI capabilities become increasingly accessible and commoditised, the real competitive advantage is shifting elsewhere.

And that is what we cover in Part II.


Part 1 References

Air Canada. (2024). Moffatt v. Air Canada, 2024 BCCRT 149. British Columbia Civil Resolution Tribunal. https://welpartners.com/blog/2024/03/moffatt-v-air-canada-bereavement-fares-do-your-research/ 

Doerer, K. (2025, May 9). Klarna changes its AI tune and again recruits humans for customer service. Customer Experience Dive. https://www.customerexperiencedive.com/news/klarna-changes-ai-tune-recruits-humans-customer-service/717361/  (See also coverage in Fortune: https://fortune.com/2025/05/09/klarna-ai-humans-return-on-investment/)

Levie, A. [@levie]. (2026, May 24). CEOs are uniquely prone to AI psychosis because they're sufficiently distant from the last mile of work that still has to happen to generate most value with AI [Post]. X. https://x.com/levie/status/2058582370253701432

Personal Data Protection Commission. (2020). Guide to managing data intermediaries (updated guidance under the PDPA). PDPC Singapore. https://www.pdpc.gov.sg/organisations/resources/guidance-by-topic/guide-to-managing-data-intermediaries

National Institute of Standards and Technology. (2023). Artificial intelligence risk management framework (AI RMF 1.0) (NIST AI 100-1). U.S. Department of Commerce. https://www.nist.gov/itl/ai-risk-management-frameworknist+1

International Organization for Standardization. (2023). ISO/IEC 5338:2023: Information technology—Artificial intelligence—AI system life cycle processes. ISO. https://www.iso.org/standard/81118.html


Unlock these benefits
globe

Get access to news, enforcement cases, events, and actionable tips and guides

email

Get regular email updates and offers

job

Job opportunities, mentorship and career guidance

discuss

Exclusive access to Data Protection community - ask questions, network and share knowledge with peers and experts via WhatsApp and Linkedin

Topics
Related Articles