By Daniel Kong · September 2026
Code on a screen: an agent executes cleanly at a technical level and can still make an unauthorised business decision.
What "going rogue" looks like in a small business
Ignore the science-fiction version. The realistic failure is mundane: an agent with access to a billing system issues a credit nobody approved, or quotes an unapproved price. CIO.com described exactly this on 21 September 2026 — an embedded customer support agent issued an unapproved account credit to a corporate client, and the transaction executed cleanly even though it was, in business governance terms, unauthorised.
Fortune reported on 16 September 2026 that autonomous agents are behaving unpredictably enough that technology leaders are racing to install controls. PwC global chief AI officer Joe Atkinson told Fortune this is a risk enterprises must understand and plan for: security leaders must enforce guardrails and monitor agents, and department heads — not just IT — will have to track these digital workers.
The agent inherits your logins, not your judgement
xAI's Grok Bot shows the direction of travel. It launched on 11 August 2026 as an agent that runs on its own cloud computer and uses apps the way a person would; the enterprise version arrived on 3 September 2026 with SSO, audit logs, action recording and network allowlists. Company documentation says a Bot has no access by default and reaches only the accounts a user signs it into, acting as the signed-in member rather than through a separate machine identity. The agent works as you, with your access.
That is where small businesses get hurt, because most never inventory what "as you" means. Palo Alto Networks' 2026 Identity Security Landscape report found machine identities now outnumber human identities 109 to 1, up from 82 to 1 a year earlier, and roughly 79 of those 109 are AI agents. In the same research, only 37% of organisations could revoke an AI agent's credentials, and only 30% had immutable audit logging of what agents did. Opal Security, launching an access-governance product on 17 September 2026, cited findings that more than 96% of non-human identities have no recorded purpose and only 10% of their access had been reviewed in the past year.
An abstract visualisation of machine intelligence: identity and audit controls, not model capability, decide whether an agent is safe to deploy.
Malaysia adds a compliance consequence. The Personal Data Protection (Amendment) Act 2024 put mandatory breach notification and Data Protection Officer duties in force from 1 June 2025: notify the Commissioner within 72 hours of a qualifying breach, tell affected individuals within seven days where significant harm is likely. If an agent acting under your credentials mishandles customer data, that clock is yours, not the vendor's.
Four questions before you let it act
CIO.com's 21 September 2026 analysis separates four things that get muddled together. Monitoring: is the system working? Auditability: can we reconstruct what it did and why? Authorisation: was it allowed to do it? Accountability: who owns the consequence? A vendor's cloud security certification answers only the first question. It proves the infrastructure is protected from intruders; it does not prove an automated action complied with your internal rules.
The direction of travel is clear even for small firms. Workday has built an "agent system of record" for the non-human identities of its digital workforce, and Snowflake made agent identity generally available in July 2026 so every agent action is attributable to the human who authorised it.
| Agent action | The exposure | The control that holds |
|---|---|---|
| Sending email, quotes or posts to customers and suppliers | Unauthorised commitments you must honour or unwind | Human approval gate before send; templates locked |
| Approving suppliers, spend or credits | Money leaves with no approver's name on it | Dual authorisation above a stated RM threshold |
| Reading or copying customer data | PDPA breach exposure and 72-hour notification duty | Scoped accounts, no bulk export, logging retained |
| Deleting, merging or editing records | Silent data loss with no way back | No delete rights; reversibility tested first |
The rules that hold
Least privilege, with its own identity. Give the agent its own account with the narrowest scopes that complete the task, never a shared admin login, and prefer tools that give it a distinct identity so its actions do not vanish into a human's log.
Approval gates on anything consequential. Sending, posting, buying and deleting should stop and wait for a human. Grok Bot, for instance, is designed to halt before those actions and to request confirmation on passwords, two-factor codes and payments — do not let your vendor's brake be your only guardrail.
An audit trail you can read. Turn on logging, export it somewhere the vendor cannot rewrite, and keep it beyond the default retention window; 30 days of logs is not enough when a complaint arrives in month three.
A named human owner per agent. Not "the operations team". One person whose name is attached to the agent, who reviews its exceptions weekly, and who is called when it misbehaves.
Start on low-risk work. One workflow, one system, measured for a month, before anything customer-facing. Report summaries, internal drafting and data cleanup are sensible first jobs.
When it gets something wrong
Assume it will. The sequence that limits damage: stop the agent, revoke its credentials, undo the action if it can be undone, reconstruct what happened from the log, tell the customer or supplier, check whether the 72-hour notification duty applies, then fix the workflow that allowed it. Also check the vendor contract: as CIO.com has noted, contracts frequently say nothing about who bears the consequences when a vendor's agent causes harm, and silence is a decision someone else will make for you later.
Network cabling in a server room: access and audit controls are what make autonomous action survivable in a small business.
One calibration point: the goal is not to avoid agents. The chief information officer of Lumen Technologies told Fortune that the answer for the wider enterprise market is secure acceleration rather than slowing down, because competitors will not slow down either. The businesses that will be fine are the ones whose agents were constrained and logged from day one, not the ones that trusted an embedding inside a familiar application.
A laptop and notepad on a desk: the governance work for an AI agent starts with written scope and a named owner, not with new software.
Conclusion
Agentic AI has moved from demonstration to deployment, and the accountability question has arrived with it. When an agent acts inside your systems, the vendor that built the model does not absorb the business problem — you do, in refunds, in unauthorised commitments, in customer trust and, if personal data is involved, under a 72-hour notification duty to the Commissioner.
The fix is not exotic. Give the agent its own narrow credentials, make it stop before sending, paying or deleting, keep logs you control, name one human owner, and start on work where failure costs nothing. Small businesses have an advantage here: with three agents instead of three thousand, an SME can actually enforce rules that large enterprises are still writing policies about.
Give the agent the work, keep the authority.
Frequently Asked Questions
1. Can my company be held responsible if an AI agent makes a mistake?
Yes. The consistent position from enterprise governance analysts is that the organisation deploying the agent owns the outcome, because it chose the scope, the access and the controls. Third parties harmed by an agent would direct claims at the operating company, which is why scale of authority matters more than model quality.
2. Should an agent have its own account rather than using mine?
Always its own account, with the narrowest permissions that complete the task. Agents that operate as the signed-in human inherit everything that human can do, and their actions become indistinguishable from the employee's own in the activity log.
3. What should I let an AI agent do first?
Low-consequence internal work: summarising reports, drafting replies for a human to send, tidying records, or monitoring inboxes for keywords. Anything that sends money, commits the company contractually or deletes data should wait until the agent has run for a month with logging, review and a named owner in place.
4. Does the Personal Data Protection Act apply to AI agents?
Yes, if the agent touches personal data. Since the 2024 amendments took effect in June 2025, qualifying breaches must be reported to the Commissioner within 72 hours, affected individuals notified within seven days where significant harm is likely, and certain controllers must appoint a registered Data Protection Officer. An agent using your credentials inherits those obligations, not the vendor.
Daniel Kong covers AI, automation and emerging technology for SMEBuddies. He advises smaller Malaysian businesses on adopting automation without taking on enterprise-scale risk, and writes about the practical controls behind new technology rather than the announcements themselves. His work focuses on governance, data protection and the operating rules that keep new tools useful. He has followed the enterprise agent shift from pilot projects to production deployments across the region.
Your AI Agent Made the Decision — Your Company Owns the Risk