Business Micro

News Stories

Advertisement

INDIA’S AI SCALE-UP NEEDS PERMISSION BUDGETS FOR AGENTS

By Gleb Tsipursky

India’s AI strategy is increasingly about deployment rather than demonstration. The government-backed India AI Impact Expo describes a national push to move AI from pilots into enterprise roadmaps and to support responsible, scalable implementation across industries. That direction makes sense. The economic value of AI comes from putting it to work.

But agentic AI changes what “putting it to work” means. A chatbot mostly waits for a question. An agent can take a goal, use tools, open files, call services, send messages, modify records, and keep working through a multi-step task. The moment an AI system can act rather than merely advise, access control becomes a business-design question.

A recent METR/Redwood investigation shows why. Agents driven by an unreleased OpenAI research model attacked Hugging Face without human approval even though they recognized that the attack was outside their assigned scope. Hundreds of agents shared discoveries, divided up the work, and coordinated until they breached Hugging Face. The important lesson for ordinary companies is not a science-fiction claim about machines escaping control. It is much more practical: capable agents can combine initiative, tools, credentials, and coordination in ways their operators did not intend.

India does not need to slow adoption in response. It needs a better unit of control.

I’m no AI skeptic. I help organizations adopt AI for a living, and I want adoption to move faster. In my experience, strong safeguards increase trust and make faster adoption possible, while reducing the risk of failures like the Hugging Face attack.

The useful control is a permission budget. Before an agent starts a job, the organization should define the maximum authority available for that task. That budget should specify which systems the agent may enter, which data it may read, which records it may change, how much money it may commit, who it may contact, how long the permission lasts, and which actions require human approval.

This model is stronger than giving an agent broad employee-style access and relying on a prompt that says “only do what is necessary.” Prompts guide behavior. Permissions constrain consequences.

For example, a procurement agent asked to find three suppliers does not need authority to sign a contract. A finance agent reconciling invoices does not need permission to create a new payee. A customer-service agent drafting refunds does not need an unlimited transaction ceiling. A coding agent inspecting a repository does not automatically need production credentials.

The permission budget should also expire. A credential granted for one task should disappear when that task ends rather than becoming a standing entitlement. Short-lived, task-specific authority limits the damage from mistakes, prompt injection, compromised tools, and unintended agent behavior.

This approach aligns with the IndiaAI Mission’s emphasis on safe, responsible, and inclusive AI adoption. It also fits the direction of emerging international standards work. The U.S. National Institute of Standards and Technology has made agent identity, authorization, security evaluations, and auditing central parts of its AI Agent Standards Initiative. India can adapt those ideas to its own scale and needs rather than waiting for a single global rulebook.

Three additional practices should sit around the permission budget. First, organizations deploying powerful agents should independently test what the systems do when instructions conflict, tools return malicious content, or tasks create incentives to exceed scope. Second, serious agent incidents should trigger structured reporting and independent review so companies learn from failures instead of quietly patching them. Third, logs should record the agent’s identity, the human or system that authorized it, the tools and data it accessed, and the actions it took.

These controls should scale with authority. An agent summarizing public documents needs little ceremony. An agent able to transfer funds, alter production systems, access sensitive customer data, or delegate tasks to other agents needs much stronger limits. Regulation and corporate governance should focus on capability and authority rather than the marketing label attached to the model.

India has a chance to make this an adoption advantage. Businesses move faster when leaders know where authority begins and ends, employees understand when humans remain accountable, and customers have evidence that autonomous systems operate inside defined boundaries.

The next phase of AI adoption will not be won by organizations that give agents the broadest possible access. It will be won by organizations that give them enough authority to create value, while making that authority explicit, temporary, observable, and revocable.

========================================

Gleb Tsipursky, PhD, a behavioral scientist, CEO of Disaster Avoidance Experts, and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026). https://disasteravoidanceexperts.com/aibook