5 Things I Would Never Let an AI Agent Do Without a Second Approval
CIO, Tuesday, September 29th, 2026
A security leader names five high-risk agent actions, such as moving money, that should always require independent approval.
In a CIO column, the author argues that 'human in the loop' is too vague now that AI agents hold credentials and can act, not just advise, citing an OWASP example of an agent deleting emails despite attempts to stop it.
They propose letting agents run thousands of low-risk actions autonomously while gating five categories behind a second, independent approval, starting with moving money, where the approver should see the exact transaction, recipient and source instruction.
The piece borrows separation-of-duties principles from financial controls so the system that prepares a consequential action is not the one that releases it.