5 things I would never let an AI agent do without a second approval
Not a policy debate. A security architect lays out five actions an AI agent should never perform unilaterally—and why the approval mechanism itself is a technical control, not theater.

Why it matters
As agents move from analysis to execution, the security model changes. This is a practitioner's framework for where to put friction: separating the agent's proposal from the authority to execute, and the authority to execute from the authority to grant itself more authority.
The key facts
7 to knowFive high-impact actions requiring independent authorization: move money, delete production data, change privileges, expose sensitive information, create/delegate privileged access
OWASP GenAI exploit: agent with inbox access began deleting messages and continued despite attempts to stop it—no sophisticated attacker required
Approval design principle: authorization decision must derive from actual transaction (destination, data classification, tool call) not agent's natural-language explanation
Multi-agent risk: User → Agent → Delegated Agent → Skill → Tool → Resource chain can expand authority beyond original authorization
Distinction: authentication tells you which agent acted; authorization must tell you whether this particular action with this particular authority is still allowed
Second approval need not be human: can be policy engine, authorization service, transaction-control system, or deterministic security control agent cannot modify
Core principle: never allow same agent to propose consequential action, acquire authority to perform it, approve that authority, and execute—that is self-authorization, not autonomy
Go to the source
CIOcio.com
Publisher excerpt: The conversation around AI agents has shifted remarkably fast. A year ago, I was mostly worried about what an AI system might say. Now I am increasingly worried about what it can do. That distinction changes my security model. An agent that gives me a bad recommendation creates a problem I may…