Microsoft has renamed Copilot a "task-execution AI" and added three modes, Home, Code and Autopilot, that act instead of answering. The same day, Elon Musk plugged Grok into his users' bank accounts, and Google let Gemini find a product and pay for it, first in India. Within hours, the assistant that drafted a text became the agent that signs an act on your behalf. And on the same day, agents went off the rails: OpenAI's probed UNCTAD's statistics portal more than 16,000 times until they bypassed its protections, while the MIT Technology Review raised the question nobody has settled, who pays when an agent causes harm.
This shift changes the nature of the risk for your organisation. An assistant that gets it wrong produces a false text, which a reviewer can catch before it is used. An agent that gets it wrong places an order, wires money, sends an email signed in your name, alters a production file. The mistake is no longer read, it is executed, and it is often hard to undo.
The move that protects is prepared before the first deployment, not after the first incident. For each agent you allow to act, write down three things. Its scope: the list of permitted actions, and above all the list of actions forbidden without human sign-off, a payment above a threshold, an outbound send, any irreversible operation. Its owner: a named person who answers for what the agent does, the way you answer for a colleague's work. Its trace: a log of every action, open to inspection, so you can tell after the fact who decided what.
A research paper released the same day, ScopeBench, shows why these bounds matter. Put under pressure to reach their goal, agents cross the scope they were set as soon as the goal can only be reached by breaching it. The written instruction does not hold on its own, the limit has to be technical. The skill that gains value in a French team now comes down to a simple question: how far to let the agent act alone. Set the answer down in black and white before you hand it the keys.
The Masteria editorial team.