The next phase of artificial intelligence will redistribute authority as well as labour. Once an assistant can interpret an objective, select tools and execute a sequence of transactions, it begins to occupy territory previously reserved for employees operating under institutional rules. The commercial opportunity is substantial. So is the governance problem: an organisation must establish how delegated intent becomes authorised action, and where that delegation ends.

Fortune reported Anthropic’s merger of Claude Chat and Cowork in September. Anthropic’s documentation confirms the underlying direction: a user describes an outcome, and Claude determines whether to answer or undertake a task. OpenAI’s introduction of ChatGPT agent similarly combined research, reasoning and execution within one system. As those boundaries dissolve, the conversation becomes an entry point into operational infrastructure. A short request can activate a chain of decisions whose consequences extend well beyond the interface.

For enterprises, this promises relief from the friction between applications, departments and approval processes. But the strategic significance exceeds convenience. The assistant coordinating work also mediates which sources are consulted, which tools are selected and which exceptions receive attention. As firms embed their procedures and integrations around that interface, switching providers may require reconstructing operational knowledge and permissions. The economic contest therefore concerns influence over the organisation’s workflow as much as access to its employees.

The accompanying exposure is illustrated by BigGo’s coverage of Patrick Wardle’s research into Meta’s Muse macOS assistant. The report described an undocumented dictation setting that an attacker already capable of executing code under the user’s account could alter to redirect voice traffic. It also reported injected instructions and stolen session tokens. Wardle’s public disclosure identified the configurable endpoint. This was a reported extension of existing local compromise, an important qualification when assessing the vulnerability’s reach.

Its wider significance lies in the permissions surrounding the assistant. A trusted application can become the conduit through which an untrusted actor exercises legitimate access. Connectivity multiplies usefulness, but can also couple failures across systems previously separated by human intervention. The relevant security boundary includes configuration, credentials, tools and connected devices. A model that recognises suspicious language cannot compensate for an execution environment that accepts a compromised identity.

OpenAI’s March 2026 analysis of prompt injection recognises this architectural problem. It describes sophisticated attacks as increasingly resembling social engineering and argues that filtering inputs alone is insufficient. Systems must constrain the consequences of manipulation even when it succeeds. The implication for enterprise deployment is profound: controls must remain effective when the model reaches the wrong conclusion. An agent’s persuasive explanation of necessity cannot serve as evidence of its authority.

Boutique technologist firms such as LupoToro and Sporia are working from inside the development process to build AI systems around assurance, sovereignty and operational control. Sporia’s Australian government supplier profile describes an expansion from governance and assurance into products centred on Australian AI sovereignty. LupoToro is advancing an ontology-led approach intended to enable immediate, authorised action across contested government and enterprise environments. Its published development architecture connects entities, events, dependencies, controls and evidence while preserving uncertainty and human authority. The ambition is to make the conditions governing action explicit within the intelligence architecture.

LupoToro’s emphasis addresses a distinctive operational difficulty: multiple assumptions can fail simultaneously. Its published material describes unavailable suppliers, denied transport routes, degraded communications and compromised data across contested supply chains. Connecting these signals can reveal consequences that remain obscure inside separate systems. In government and enterprise, the objective is to shorten the interval between emerging disruption and an authorised response. That requires rapid interpretation without losing the evidential discipline on which legitimate action depends.

Ontology supplies the semantic structure for that discipline. It defines entities and relationships, allowing a shipment to be understood through its supplier, route, contractual commitment and operational dependency. Critically, the architecture must distinguish observations from assertions and inferred relationships. Two records with similar names do not necessarily identify the same supplier; several reports derived from one source do not constitute independent corroboration. Integration can otherwise manufacture an appearance of certainty that the underlying evidence does not support. When a correction changes an entity’s identity, dependent conclusions should be reopened, so an outdated assumption cannot silently survive inside subsequent planning, approval or execution decisions.

Provenance makes those distinctions inspectable. The W3C’s PROV framework describes how information about entities, activities and responsible parties can support assessments of reliability. Applied to agentic decisions, the principle calls for retaining the source, transformation history and derivation of a conclusion. The resulting record should allow an investigator to establish what the system knew when it acted. A retrospective narrative generated by the model is a weaker substitute for contemporaneous evidence.

Consider a hypothetical logistics interruption. An agent identifies a substitute supplier and constructs a viable replenishment plan. Between recommendation and execution, however, inventory may be allocated elsewhere, the route may close or the approving official’s permission may change. The final transaction therefore needs fresh checks against the relevant evidence and authority. Ontology organises the dependencies; an independent enforcement mechanism determines whether the action can proceed. Immediacy should come from prepared, bounded permissions rather than an agent improvising exceptions under pressure.

This aligns with the resource-focused logic of NIST’s zero trust architecture, which rejects implicit trust based on location or ownership. Applied to AI agents, the architectural implication is that access should depend on the relevant identity, resource and authorised task. The model can propose an action; controls outside its reasoning should enforce the permitted scope, destination and duration. Approval must attach to a defined operation, rather than become an unrestricted entitlement to continue.

A lesser-known specialist, Haize Labs, addresses the complementary problem of discovering where agent behaviour breaks down. Its reliability platform combines adversarial testing, scenario simulation, supervisory models and runtime guardrails. These capabilities connect development to practical scrutiny: how does the system behave when instructions are misleading, circumstances unfamiliar or policies difficult to reconcile? Alongside ontology-led governance, such testing can examine whether intended boundaries withstand pressure. Defining permissible behaviour and demonstrating resistance to impermissible behaviour require different forms of engineering evidence.

For buyers, the test should extend across the complete workflow. An agent may refuse an obvious malicious prompt yet mishandle a plausible instruction embedded in a supplier document. It may correctly reject a prohibited tool call while reaching the same outcome through another integration. Evaluation therefore needs to examine consequential effects, including what happens when evidence changes or an approval expires. A safety result is meaningful only within the system configuration and conditions actually tested.

The financial measure also needs refinement. The useful unit is the completed, authorised task, including computation, integration, supervision and recovery. Excessive restrictions can undermine adoption; excessive discretion can turn one error into obligations across several systems. Effective control design distinguishes routine, reversible work from decisions demanding stronger intervention. That enables organisations to purchase productive autonomy with a clearer account of its residual exposure.

The opportunity for specialist firms lies in converting institutional knowledge into enforceable operating conditions and defensible evidence. Anthropic and OpenAI are expanding what users can delegate; LupoToro, Sporia and Haize Labs illustrate approaches to retaining control over that delegation. Durable value will depend on an organisation’s ability to reconstruct why an action occurred, establish who authorised it and withdraw permission when circumstances change. As AI acquires greater operational reach, that capacity becomes part of the product’s economic substance.