Cobo Agentic Wallet

From What AI Agents Can Do to What They Are Allowed to Do

Discussions at Europe’s TechBBQ conference and an IBM survey point to a widening gap between AI-agent deployment and organizational control. As agents gain the ability to act across enterprise systems, companies are being urged to define authority, improve visibility, and preserve meaningful human oversight.

Cobo Newsroom
Cobo NewsroomAug 30, 2026
Key takeaways
  • Conversations at TechBBQ focused increasingly on who controls AI, rather than only on what more capable models can do.
  • An IBM survey of 2,000 C-level technology executives found that only 11% felt fully prepared for AI-agent deployment expected over the following year.
  • About two-thirds of CIOs and CTOs said they were accountable for AI systems they did not fully control, while 70% said deployment was moving faster than IT could track.
  • PromptHalo founder Madhuri Chandoor argues that capability and authority must be treated as separate questions: an agent’s ability to perform an action does not by itself establish permission to do so.
  • Sequential actions can potentially bypass limits that appear effective when applied to each individual request, making behavioral monitoring and contextual review important.
  • In workflows involving enterprise data, payments, or institutional custody, layered permissions, human review, emergency suspension, and auditability are central to responsible automation.

News illustration

Summary

Discussions at Europe’s TechBBQ conference and an IBM survey point to a widening gap between AI-agent deployment and organizational control. As agents gain the ability to act across enterprise systems, companies are being urged to define authority, improve visibility, and preserve meaningful human oversight.

The question is shifting from capability to control

At TechBBQ in Copenhagen, the European AI conversation repeatedly returned to a question that is more fundamental than model performance: who is actually in control of AI systems, and what should those systems be permitted to do without direct human intervention?

According to TechCrunch’s coverage, investors, founders, and operators were discussing more than new products, funding, or technical progress. AI agents were an underlying theme across the conference, but the emphasis was increasingly on agency, human judgment, and technological sovereignty. The conference theme, “Emerging from Agency,” captured that shift. In this context, agency is not simply the ability of a machine to take an action. It is also about who defines the limits of that action, who can interrupt it, and who is accountable when the result is wrong.

The issue has a distinctly European strategic dimension. TechCrunch reported that Anthropic’s AI models Mythos and Fable had earlier become unavailable to users outside Europe. The incident prompted parts of Europe’s technology ecosystem to consider what it means to own the models and infrastructure supporting the current AI wave, rather than relying on capabilities supplied by companies based in the United States or China.

The reported reaction was mixed. One startup executive said the incident seriously disrupted a software team, while another treated it as manageable in the short term. That difference matters because it reflects two separate questions. One is whether a company can find a temporary substitute when a model or service becomes unavailable. The other is whether it has durable control over the systems on which its products and operations depend.

Capability is not authority

The control problem is also visible inside individual organizations. The Next Web cited an IBM study of 2,000 C-level technology executives. Only 11% of respondents said they felt fully prepared for AI-agent deployment expected over the following year. Around two-thirds of CIOs and CTOs said they were accountable for AI systems they did not fully control, and 70% said teams were deploying technology faster than IT could track.

Those findings point to a governance gap, not merely a problem with model accuracy. An AI assistant that summarizes documents presents a different control challenge from an agent that can modify a database, call an internal service, respond to customers, or trigger a financial workflow. Once an agent can act across systems, an organization must understand not only whether an action is technically possible, but also whether it is authorized in that particular context.

Madhuri Chandoor, founder of PromptHalo, described the distinction as one between capability and authority. An agent may have the technical ability to perform an operation, but that does not mean the operation is permitted under the user’s intent, the task’s scope, or the organization’s policies. Authorization therefore needs to account for context, not just tool access.

That distinction is important because conventional access controls often describe what an account can do in general terms. They may not explain whether a specific action is appropriate at a particular moment, for a particular purpose, or in combination with other actions. An infrastructure-management agent asked to improve application performance, for example, could take steps that appear consistent with its broad remit while still creating an unacceptable downstream effect. The relevant governance question is not only “what did the agent change?” but also “why did it change it, what information supported the decision, and what might the change cause next?”

The limits of single-action controls

The Next Web also described a hypothetical refund-splitting example to illustrate how agents could work around limits that are applied only to individual requests. If a system prohibits a refund above a certain threshold, several separate requests may each appear compliant while producing an aggregate outcome that conflicts with the original control objective.

This type of failure would not necessarily require an agent to deliberately evade a rule. It could arise from an incomplete task definition, limited context retention, or an instruction that prioritizes completion over the broader purpose of a restriction. A policy that looks sound at the level of one API call may therefore be inadequate when the agent is able to plan and execute a sequence of calls.

Chandoor’s proposed response is to consider behavioral profiling for AI agents, drawing on practices used in financial fraud monitoring. The goal would be to observe patterns such as request frequency, sequencing, access expansion, unusual combinations of tools, and deviations from the assigned task. That approach would supplement static permissions with an assessment of whether behavior is consistent with expected use.

Behavioral monitoring is not a replacement for authorization. It can, however, help organizations identify situations in which individually permitted actions become questionable when viewed together. It also creates a basis for escalation, temporary suspension, or additional human review before a sequence produces material consequences.

Visibility must come before autonomy

The IBM findings suggest that many organizations may not yet have a complete view of where agents are being deployed. If technology is being introduced faster than IT can track, an enterprise may lack a reliable inventory of active agents, their data access, the tools they can call, and the people or teams responsible for them. A formal AI policy is difficult to enforce when the organization does not know which systems are operating under that policy.

A workable control framework should be able to answer several basic questions. What systems and data can the agent access? Under what conditions is that access valid? Who or what process granted the permission? What inputs did the agent use when it acted? Can the action trigger another system or workflow? Who can pause, revoke, or override the agent if its behavior diverges from expectations?

These questions become more consequential when agents are connected to payment operations, customer accounts, corporate funds, or institutional custody workflows. An automated system should not be treated as having unrestricted business authority simply because it can technically initiate an operation. Segmented permissions, transaction and frequency limits, human approval for higher-impact actions, emergency controls, and durable audit records are among the mechanisms organizations may use to reduce the effect of mistakes or unauthorized behavior. The appropriate design will depend on the system, the risk profile, and applicable legal and regulatory requirements.

Sovereignty includes the ability to interrupt

The discussion at TechBBQ also broadens the meaning of AI sovereignty. Sovereignty is not limited to whether Europe develops its own models. It also concerns control over the infrastructure, data flows, deployment environments, and service dependencies that allow AI systems to operate.

That perspective links strategic autonomy with operational authorization. At the strategic level, organizations and regions need options if a model provider, cloud platform, or critical service changes its policies or becomes unavailable. At the operational level, organizations need the ability to understand, limit, and interrupt what an agent is doing. A company may have access to a powerful model and still lack meaningful control if it cannot revoke permissions quickly, reconstruct the agent’s decisions, or operate its key processes without an external service.

The emerging message from the European discussion and the IBM findings is not that companies should abandon AI agents. Rather, broader capability should not automatically translate into broader autonomy. Enterprises may need to move from a “connect first, govern later” approach toward one that defines authority, observability, escalation paths, and human intervention before extending an agent’s permissions.

For institutional systems in particular, trust will depend less on whether an agent can complete a task in a demonstration and more on whether its actions remain bounded in production. Clear authorization, continuous visibility, contextual monitoring, and the ability to stop or reverse a workflow are becoming prerequisites for allowing AI agents to participate in critical operations. The central question is therefore no longer simply what AI can do. It is what an organization can prove the AI was authorized to do—and how quickly a human can take back control when circumstances change.

Source: link

AIREGULATIONS

About Cobo

Cobo is an institutional digital asset infrastructure provider founded in 2017. The Cobo Agentic Wallet extends Cobo's MPC custody platform to autonomous onchain agents.

Press inquiries: [email protected] · Media kit, executive bios, and additional materials available on request.
Agentic Economy by Cobo

Get this in your inbox every Friday.

The weekly newsletter from the Cobo team — unpacking the most consequential stories in crypto, AI & payments through the lens of institutional custody.