AI now has permission to act
A chatbot hallucinates and gets something wrong, and we end up with an embarrassing answer and maybe some PR fallout. An AI Operations agent gets something wrong, and it can query a database, call an API, modify a cloud role, trigger a workflow, order pizza with pineapple on it, or send our mistake out to customers at machine speed.
That's quite an upgrade in consequences.
Critically, Moffatt v. Air Canada (2024) provides “persuasive authority” for a principle that is becoming increasingly important for international business: an AI system isn’t a separate legal person that can absorb liability for its own mistakes. Responsibility remains with the person, business, or organization that deploys, controls, or relies on it, with liability determined under existing laws, including negligence, contract, consumer protection, and product liability.
- According to insurance broker Everywhen, mistakes made by artificial intelligence are among the biggest risks facing professional indemnity, with 41% of the organizations they surveyed citing AI mistakes as the number one factor, ahead of cyber risks at 35%.
AI is rapidly becoming an insurance black spot underwriters won’t touch, with risks still poorly understood, difficult to price, and potentially very costly. With limited historical data and unclear liability, insurers are responding with stricter conditions, much higher premiums, or more commonly by declining coverage altogether.
Responsible AI has traditionally centered on fairness, transparency, privacy, accuracy, accountability, and human oversight. Those principles remain essential. But the arrival of autonomous and agentic systems (and associated legal frameworks and AI cybersecurity standards) has added another question:
What is this AI actually allowed to do?
- The Stanford 2026 AI Index recorded 362 documented AI incidents during 2025, up from 233 in 2024. AI-specific governance roles grew 17%, while organizations reporting no responsible AI policies fell from 24% to 11%.
We're clearly taking responsible AI more seriously, and so we should. Unfortunately, AI isn't waiting for us to finish the small print in an AI governance framework, with over 75% of organizations utilizing AI in at least one function [Qualtrics].
What responsible AI means in 2026
Responsible AI is the practice of designing, deploying, and operating AI so that it behaves reliably, fairly, securely, transparently, and within defined organizational boundaries.
That equates to six core principles:
- Fairness: AI should treat people equitably and avoid unjustified bias or discrimination based on characteristics such as race, gender, age, disability, or background.
- Accountability: Organizations and responsible teams must remain accountable for how AI systems are designed, deployed, monitored, and used — including the outcomes they produce.
- Transparency: People should be able to understand when AI is being used, what role it plays in a decision, and, where appropriate, the factors or reasoning behind that decision.
- Reliability and Safety: AI systems should perform consistently within defined limits, handle failures safely, resist manipulation and cyberattacks, and be tested for foreseeable risks.
- Privacy and Security: AI systems should protect personal and sensitive data, use it appropriately, and apply strong safeguards against unauthorized access, misuse, or exposure.
- Inclusiveness: AI should be designed so that people with different needs, abilities, backgrounds, and circumstances can use and benefit from it without unnecessary exclusion.
As above, responsible AI now intersects directly with access governance. AI increasingly interacts with SaaS applications, repositories, cloud infrastructure, email, business data, and production systems. This makes shadow AI, unmanaged integrations, API tokens, service accounts, and SaaS sprawl part of responsible AI governance.
If an AI system has access, that access needs a reason, an owner, boundaries, and an end date.
Responsible AI must include security
Security isn't a separate concern to be bolted onto responsible AI afterward.
- Stanford found that models performing well on standard safety tests became less safe when subjected to adversarial jailbreak attempts. In June 2026, NIST (National Institute of Standards and Technology) similarly argued for continuous monitoring and updating rather than treating AI security as a one-time hardening exercise.
AI's blast radius increasingly depends on permissions. An agent compromised through prompt injection is dangerous. An agent compromised by prompt injection poses a serious risk, but one operating with permanent production-admin privileges is orders of magnitude more dangerous.
“Trustworthy AI requires AI security… At the end of the day, there is always a human responsible for whatever the AI’s behavior is.”
- AI and Trust, Bruce Schneier, author, security technologist, Harvard lecturer
We need to apply the same principle of least privilege we use elsewhere: give an identity only the permissions necessary to perform its task. That includes non-human identity management for service accounts, tokens, workloads, automation, and AI agents.
Agentic AI changes responsible AI
The security model changes once AI starts acting autonomously:
Prompt → decision → tool → credential → system → action.
Every arrow introduces another trust relationship in a web of invisible trust chains.
- McKinsey's 2026 AI Trust Maturity Survey found that nearly two-thirds of organizations see security and risk concerns as their biggest barrier to scaling agentic AI. Some 74% identify AI inaccuracy as a highly relevant risk, and 72% cite cybersecurity.
Yet only about 30% have reached higher levels of maturity in strategy, governance, and agentic AI controls, which is why agent access control is increasingly critical. Prompts express intent. Permissions define capability.
- NIST's 2026 work on AI agent identity and authorization specifically highlights the risks created when agents gain access to tools, applications, and data.
- OWASP's Top 10 for Agentic Applications 2026 likewise identifies identity and privilege abuse as a major agentic risk.
Responsible AI therefore needs access control, not just responsible prompts.
From responsible principles to responsible permissions
A practical model starts with six questions.
- What is it?
Inventory every model, application, integration, and agent, including orphaned agents. - Who owns it?
Every AI identity and workflow needs accountable human ownership. - What can it access?
Map permissions across cloud, SaaS, APIs, data, and other agents. This is basic cloud infrastructure entitlement management. - What does it actually need?
Remove unnecessary privileges and continuously watch for privilege drift. - When should privilege exist?
Replace permanent access with temporary, task-specific elevation. AI security increasingly depends on making privileged access short-lived. - Can we prove what happened?
Requests, approvals, permissions, actions, and revocation should produce usable evidence.
This is where zero standing privilege (ZSP) is especially relevant to AI. An agent shouldn't hold powerful permissions all week because it might have needed them for five minutes on Tuesday.
Where risk is predictable, access automation can enforce those policies at machine speed. Where actions involve sensitive data, destructive operations, privilege escalation, or production changes, human approval belongs in the loop.
For AWS (Amazon Web Services), Azure, Google Cloud Platform (GCP), and SaaS environments, the same objective applies: least privilege in AWS or anywhere else shouldn't stop when the identity happens to be synthetic. In fact, it becomes more important.
Responsible AI is becoming enforceable AI
Responsible AI is becoming less about ethics and more operational.
We still need fairness, transparency, privacy, accuracy, and accountability. But when AI can act across real infrastructure, good intentions aren't sufficient controls. We need to know what it can reach, what authority it has, why it has it, when that authority expires, and whether we can take it away instantly. Because the defining responsible AI question of 2026 may no longer be “Can we trust the model?” It may be “What happens when we can't?”
Further reading and champions of responsible AI
Responsible AI is championed globally by major technology leaders, cross-industry consortia, and academic institutions working to embed ethics, safety, and accountability into machine learning. Key figures and groups leading these efforts include:
Technology leaders
- Satya Nadella: Microsoft has made responsible AI a formal engineering and governance discipline, built around fairness, reliability, privacy, security, transparency, inclusiveness, and accountability.
- Sundar Pichai: Google continues to frame AI development around formal AI Principles, lifecycle governance, safety testing, post-launch monitoring, and remediation.
- Fei-Fei Li: Stanford HAI co-founder and one of the leading advocates for human-centered AI, emphasizing trustworthy systems that preserve human agency and social benefit.
- Yoshua Bengio: Turing Award winner and chair of the International AI Safety Report, leading global research into general-purpose AI capabilities, systemic risks, and safety controls.
Organizations and institutions
- Stanford Institute for Human-Centered AI: Major academic center researching responsible, trustworthy, and human-centered AI across technology, policy, economics, and society.
- OECD AI Policy Observatory: Maintains the OECD AI Principles, the first intergovernmental standard promoting trustworthy, human-centered AI that respects democratic values and human rights.
- NIST: Develops practical AI risk-management and security guidance, including work on agent identity, authorization, monitoring, and trustworthy AI deployment.
- Responsible AI UK: UK-wide research program connecting universities, industry, government, and civil society to advance responsible AI research and adoption.
- Partnership on AI: Independent multi-stakeholder nonprofit bringing technology companies, academics, civil society, and policymakers together to develop practical approaches to responsible AI.
- International AI Safety Report: A global scientific collaboration involving more than 100 experts and backed by over 30 countries and international organizations, assessing emerging AI capabilities and risks.
Give responsible AI responsible access
Responsible AI needs more than policies and guardrails. We help discover human and non-human identities, reveal excessive permissions, reduce standing privilege, and give AI agents only the access they need, when they need it, with automatic revocation and clear audit evidence. Start your free Trustle trial and see what your AI identities can actually access before they decide to demonstrate it for themselves.




