Michael Engle is Cofounder at 1Kosmos and was previously head of InfoSec at Lehman Brothers and Cofounder of Bastille Networks.gettyOver the past year, nearly every conversation I've had about governing AI agents has ended with the same proposal: keep a human in the loop.The idea is intuitive. If an autonomous agent wants to approve a payment, access sensitive data or modify critical infrastructure, a person should review the action before it happens. It feels like responsible governance. But "human-in-the-loop," as the phrase is usually meant, describes a specific and increasingly narrow mechanism: a person approving individual actions, one at a time. That's a model built for a different era.As organizations move from AI assistants to autonomous agents that execute work across enterprise applications, the volume and velocity of decisions scale dramatically. A single business process may involve multiple specialized agents interacting across identity systems, SaaS applications, cloud platforms, APIs and other agents, generating hundreds or thousands of machine decisions behind what appears to be a single workflow.The Human BottleneckIn that environment, per-action approval goes from being a safeguard to a constraint. Every additional approval introduces another dependency into a process designed to operate at machine speed. Eventually, organizations are forced to choose between maintaining the control they envisioned and achieving the efficiency that justified deploying autonomous systems in the first place.Most discussions about AI governance focus on individual decisions. Should this action be approved? Should this workflow pause? Should this request be escalated? Those are reasonable questions, but they assume the primary object of governance is the agent's next action.I think it's something else entirely. What we're really governing is delegated authority.Every autonomous agent exists because someone defined its purpose and delegated it to act on behalf of a person, team or business process. Long before the first API call, the most important governance decision has already been made: what authority the agent should possess.That distinction fundamentally changes governance, replacing approval of individual actions with continuous validation that an agent is operating within the authority intentionally delegated by a verified human.Moving Beyond Static ControlsTraditional identity architectures assume authentication establishes authority until credentials expire. Autonomous agents challenge that narrative because they continuously adapt to changing context, invoke additional services and make decisions based on information that didn't exist when they were deployed.An agent may authenticate successfully while operating under authority that no longer reflects the organization's intent. The individual who delegated authority may have changed roles, ownership may have shifted, or the underlying business policy may no longer apply.That's why AI governance has to move beyond authentication and static authorization, and become a continuous evaluation of delegated authority.Implementing Runtime AuthorizationInstead of relying on humans to review an endless stream of individual decisions, organizations need an orchestration layer that continuously evaluates whether an agent's requested action still falls within the authority originally delegated to it. Runtime authorization evaluates policy, business context, workload identity, ownership and risk continuously rather than treating authorization as a one-time configuration exercise.While most actions never require human intervention because they remain inside clearly established boundaries, the exceptions still do.That’s why enterprises should design governance models where humans set the terms the loop runs on."Human oversight" is already the language regulators use in the EU AI Act, and it's what NIST—and DORA—map to. But in most implementations, oversight stops at documentation: a policy is written, a dashboard is built and a person watches. But oversight has to be enforced at runtime, not merely documented.In this model, people aren't asked to supervise every autonomous decision. They're responsible for establishing the conditions under which autonomous decisions are allowed to occur. They define delegation boundaries, escalation policies, acceptable risk and the circumstances under which authority should automatically be withdrawn.It works more like a command structure than like an approval queue. A commander sets intent and boundaries in advance; subordinates act autonomously within them; only exceptions escalate. The authority is expressed once, up front, and then enforced continuously, not renegotiated at every step.Technology then becomes the mechanism for continuously enforcing those decisions.That enforcement begins with establishing the human source of authority. If autonomous systems act on behalf of people, organizations need high assurance that the individual establishing governance policies and delegating authority is who they claim to be. Phishing-resistant authentication and verified identity become the root of trusted authority.From there, runtime authorization, workload identity, orchestration, short-lived credentials and automated revocation all serve the same objective: ensuring autonomous systems continue operating only while the authority behind them remains valid.This also changes what auditability means.Knowing Why Activity Was Allowed, Not Just DeniedHistorically, security investigations have focused on explaining why access was denied or why a policy blocked a request. With autonomous systems, organizations need to explain why an action was permitted.Why was this agent allowed to access customer records? Why was this financial transaction approved? Why was privileged infrastructure modified without human intervention?This requires governance capable of showing who delegated authority, what policies were in effect, how those policies were evaluated at runtime and why the system concluded the action remained within approved boundaries.Beyond satisfying auditors, this model enables organizations to build confidence that autonomous systems are behaving as expected, even when humans are no longer participating in every decision.The future of AI governance will be defined by how precisely organizations can articulate, delegate, continuously validate and revoke the authority under which autonomous decisions are made at runtime.​Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?