← All Posts

When AI Agents Act: The Board's New Delegation and Accountability Imperative

June 29, 2026

When AI Agents Act: The Board's New Delegation and Accountability Imperative

In February 2026, OpenAI introduced "Customer Actions" and tool-calling capabilities in ChatGPT Team and Enterprise versions. This feature allows organizations to grant AI models access to internal data and enable action through application programming interfaces—meaning the system can now update records, send messages, and change configurations once appropriate permissions and integrations are in place. Vendors are rapidly deploying this "copilot" pattern across human resources platforms, electronic health record systems, and educational technology, creating environments where AI initiates operational changes rather than merely drafting text. For boards overseeing hospitals, schools, and corporations, this shift raises a fundamental governance question: when an AI agent can act autonomously, who bears fiduciary responsibility for those actions, and how does the board ensure appropriate oversight?

From Advisor to Operator: How AI Tool-Calling Reshapes Board Oversight

Traditional board oversight of technology focused on systems that supported human decision-making. An electronic health record helped clinicians document care; an HR platform processed employee data under human direction; a learning management system delivered content selected by teachers. In each case, the board could reasonably assume that a named human ultimately authorized any action affecting patients, employees, or students.

AI tool-calling changes this dynamic fundamentally. When an AI system can read data, evaluate options based on training, and execute actions through connected APIs, the technology transitions from advisor to operator. A hospital board must now consider whether an AI agent adjusting medication dosing recommendations or scheduling parameters operates under the same oversight framework as a clinician's decision. A school board must determine whether an AI system that automatically flags student records for intervention requires the same governance as a teacher's professional judgment. A corporate board must decide what level of AI-initiated financial transactions falls within acceptable risk parameters.

The fiduciary duty of care does not disappear with this technological shift. If anything, it intensifies. Boards must now explicitly define which categories of decisions may be delegated to AI agents, which require human approval before execution, and which must remain entirely within human authority. This is not merely a technical configuration—it is a governance decision with legal and ethical implications that the board cannot delegate to IT staff alone.

Who Is Accountable When an Agent Acts? Liability Gaps in the Delegation Chain

When an AI-initiated action causes harm—a patient receives incorrect dosing due to an AI-adjusted protocol, an employee is incorrectly terminated based on AI-generated recommendations, or a student record is improperly disclosed—determining liability becomes complex. The vendor that provided the AI tool typically includes terms of service limiting accountability for outcomes. The organization that configured the system may claim the AI acted autonomously. The board that approved "AI-enabled" operations may face claims that it failed to ensure adequate safeguards.

This liability gap creates genuine exposure for boards. Consider a scenario where an AI agent in an HR system automatically adjusts compensation based on performance metrics, inadvertently implementing pay discrimination. The board that authorized AI-driven compensation decisions without explicit human review thresholds may face claims of negligent oversight. The absence of clear liability frameworks in many jurisdictions does not shield boards from accountability—it merely increases uncertainty about where responsibility ultimately rests.

Boards must address this gap proactively through explicit policy. Delegation authority to AI agents should be documented with clear boundaries. Human-in-the-loop requirements should specify not merely that a human "reviews" AI recommendations but that human approval is required before execution for defined categories of actions. Liability assignment should be addressed in vendor contracts, with explicit allocation of responsibility for AI-caused harms.

Auditing the Invisible: Designing Board-Level Controls for Autonomous AI Actions

Effective governance of AI agents requires mechanisms that make autonomous actions visible and reviewable. This means boards must mandate audit trails that capture not merely what decision was made but what data the AI accessed, what reasoning it applied, and what action it initiated. These logs must be designed for board-level review, not merely technical debugging.

Human-in-the-loop thresholds should be calibrated by risk level. Low-risk actions such as automatically generating routine communications may proceed without pre-approval but with post-hoc review. High-risk actions affecting patient safety, employment status, or financial thresholds should require human approval before execution. The board should define these thresholds explicitly and review them periodically as AI capabilities expand.

Vendor update cycles present a particular challenge. When OpenAI or other providers expand agent capabilities—such as adding new forms of tool-calling or "customer actions"—organizations may find their AI systems can suddenly perform actions that were not possible when the board approved the deployment. Boards should require notification protocols that alert governance committees when vendor updates expand agent autonomy, with mandatory re-review of delegation policies within a defined timeframe.

For hospital boards, the immediate action is to require disclosure of all AI tool-calling deployments in clinical systems, with explicit human approval requirements for any action affecting patient care. For school boards, the action is to audit learning platforms for autonomous record modification capabilities and establish clear boundaries on which student data AI may access and modify without educator approval. For corporate and nonprofit boards, the action is to map all AI-initiated financial and operational transactions and establish tiered approval requirements based on risk.

The governance imperative is not simply attention to AI but active specification of what AI may do, under what conditions, and with what oversight. Boards that treat AI deployment as a technical matter to be resolved by staff are abdicating their fiduciary responsibility in an environment where technology can now act without waiting for human authorization.