A company deploys an AI agent to manage software purchases. Procurement tells it to reduce costs. The business tells it to close quickly. Security requires specific protections. Finance imposes spending limits. Legal prohibits certain contractual terms.
Whose instruction controls?
For a human employee, the answer is often worked out through meetings, relationships, experience, and occasional escalation. People recognize conflicts, negotiate internally, and locate someone with enough authority to make the final decision.
An AI agent needs something more explicit.
As agents begin purchasing, negotiating, renewing, paying, and making commitments, companies will face a governance problem that is easy to mistake for a technical one. Someone must decide what the agent may do, which rules it must follow, and what happens when legitimate instructions from different functions conflict.
B2B transactions rarely belong to a single department. A software purchase may involve procurement’s pricing objectives, finance’s budget controls, security’s technical requirements, privacy’s data restrictions, legal’s contracting positions, and the business owner’s operational needs.
Each function may reasonably believe its requirements are controlling. Each may configure its own system, policy, or approval process. If those instructions are passed to an agent without a clear hierarchy, the agent does not receive governance. It receives a collection of competing preferences.
Consider a supplier offering a substantial discount if the company signs by Friday. Procurement favors acceptance because the price meets its target. The business wants the product immediately. Legal identifies a liability provision outside the approved range, while privacy concludes that the proposed data use violates company policy.
Should the agent reject the deal, escalate it, or accept it because the commercial benefit is unusually strong? The answer cannot be derived from the contract alone. It depends on corporate decision rights.
Companies already have mechanisms for allocating authority. Boards delegate to executives. Executives assign spending limits. Policies identify required approvals. Legal, security, privacy, finance, and procurement each control portions of the process.
The difficulty is that these systems often developed separately. A delegation-of-authority schedule may address spending without addressing contract risk. A procurement workflow may permit a purchase that privacy policy prohibits. A negotiation playbook may allow a fallback position that requires approval under a separate security process.
Human employees often notice these gaps and route around them. Agents may apply the rules exactly as written, including the contradictions.
This is why AI governance cannot belong exclusively to the technology team. Technology can implement the agent’s rules, but it should not silently determine the company’s priorities or resolve conflicts among functions. Those are organizational decisions with legal, financial, and operational consequences.
Nor can legal claim ownership of every decision. Legal may define prohibited commitments and required protections, but the business owns many commercial tradeoffs. Finance controls certain expenditures. Security and privacy possess expertise that legal cannot replace. Effective governance requires clear ownership of specific decisions and an agreed method for resolving conflicts among them.
In-house lawyers can help design that structure. They are accustomed to thinking about delegated authority, fiduciary responsibility, regulatory accountability, and enforceable commitments. They also understand that a company may be bound by an action even when its internal approval process failed.
The practical questions are straightforward, even when the answers are not. Who may authorize the agent to act? Which function owns each category of rule? Which requirements are absolute, and which can be overridden? Who has override authority? What must be documented? When rules conflict, what is the hierarchy?
Companies should answer those questions before agents begin making consequential decisions. Otherwise, the hierarchy will emerge accidentally through system configurations, workflow defaults, or whichever department implemented its controls first.
Agentic commerce will not eliminate internal governance. It will make vague governance harder to hide.
Before asking what an AI agent can do, companies need to decide who has the authority to tell it.
Olga V. Mack is the CEO of TermScout, where she builds legal systems that make contracts faster to understand, easier to operate, and more trustworthy in real business conditions. Her work focuses on how legal rules allocate power, manage risk, and shape decisions under uncertainty. A serial CEO and former General Counsel, Olga previously led a legal technology company through acquisition by LexisNexis. She teaches at Berkeley Law and is a Fellow at CodeX, the Stanford Center for Legal Informatics. She has authored several books on legal innovation and technology, delivered six TEDx talks, and her insights regularly appear in Forbes, Bloomberg Law, VentureBeat, TechCrunch, and Above the Law. Her work treats law as essential infrastructure, designed for how organizations actually operate.
The post Who Owns The Rules For An AI Agent? appeared first on Above the Law.
A company deploys an AI agent to manage software purchases. Procurement tells it to reduce costs. The business tells it to close quickly. Security requires specific protections. Finance imposes spending limits. Legal prohibits certain contractual terms.
Whose instruction controls?
For a human employee, the answer is often worked out through meetings, relationships, experience, and occasional escalation. People recognize conflicts, negotiate internally, and locate someone with enough authority to make the final decision.
An AI agent needs something more explicit.
As agents begin purchasing, negotiating, renewing, paying, and making commitments, companies will face a governance problem that is easy to mistake for a technical one. Someone must decide what the agent may do, which rules it must follow, and what happens when legitimate instructions from different functions conflict.
B2B transactions rarely belong to a single department. A software purchase may involve procurement’s pricing objectives, finance’s budget controls, security’s technical requirements, privacy’s data restrictions, legal’s contracting positions, and the business owner’s operational needs.
Each function may reasonably believe its requirements are controlling. Each may configure its own system, policy, or approval process. If those instructions are passed to an agent without a clear hierarchy, the agent does not receive governance. It receives a collection of competing preferences.
Consider a supplier offering a substantial discount if the company signs by Friday. Procurement favors acceptance because the price meets its target. The business wants the product immediately. Legal identifies a liability provision outside the approved range, while privacy concludes that the proposed data use violates company policy.
Should the agent reject the deal, escalate it, or accept it because the commercial benefit is unusually strong? The answer cannot be derived from the contract alone. It depends on corporate decision rights.
Companies already have mechanisms for allocating authority. Boards delegate to executives. Executives assign spending limits. Policies identify required approvals. Legal, security, privacy, finance, and procurement each control portions of the process.
The difficulty is that these systems often developed separately. A delegation-of-authority schedule may address spending without addressing contract risk. A procurement workflow may permit a purchase that privacy policy prohibits. A negotiation playbook may allow a fallback position that requires approval under a separate security process.
Human employees often notice these gaps and route around them. Agents may apply the rules exactly as written, including the contradictions.
This is why AI governance cannot belong exclusively to the technology team. Technology can implement the agent’s rules, but it should not silently determine the company’s priorities or resolve conflicts among functions. Those are organizational decisions with legal, financial, and operational consequences.
Nor can legal claim ownership of every decision. Legal may define prohibited commitments and required protections, but the business owns many commercial tradeoffs. Finance controls certain expenditures. Security and privacy possess expertise that legal cannot replace. Effective governance requires clear ownership of specific decisions and an agreed method for resolving conflicts among them.
In-house lawyers can help design that structure. They are accustomed to thinking about delegated authority, fiduciary responsibility, regulatory accountability, and enforceable commitments. They also understand that a company may be bound by an action even when its internal approval process failed.
The practical questions are straightforward, even when the answers are not. Who may authorize the agent to act? Which function owns each category of rule? Which requirements are absolute, and which can be overridden? Who has override authority? What must be documented? When rules conflict, what is the hierarchy?
Companies should answer those questions before agents begin making consequential decisions. Otherwise, the hierarchy will emerge accidentally through system configurations, workflow defaults, or whichever department implemented its controls first.
Agentic commerce will not eliminate internal governance. It will make vague governance harder to hide.
Before asking what an AI agent can do, companies need to decide who has the authority to tell it.
Olga V. Mack is the CEO of TermScout, where she builds legal systems that make contracts faster to understand, easier to operate, and more trustworthy in real business conditions. Her work focuses on how legal rules allocate power, manage risk, and shape decisions under uncertainty. A serial CEO and former General Counsel, Olga previously led a legal technology company through acquisition by LexisNexis. She teaches at Berkeley Law and is a Fellow at CodeX, the Stanford Center for Legal Informatics. She has authored several books on legal innovation and technology, delivered six TEDx talks, and her insights regularly appear in Forbes, Bloomberg Law, VentureBeat, TechCrunch, and Above the Law. Her work treats law as essential infrastructure, designed for how organizations actually operate.
The post Who Owns The Rules For An AI Agent? appeared first on Above the Law.

