top of page

When Decisions Have No Assurance, AI Risks Everything.

  • ICIT Research
  • 5 hours ago
  • 2 min read

August 2026

By Malcolm Harkins


Decision-making has always been the core function of governance. What has changed is who, or what, is now making the decisions. Artificial intelligence, and particularly agentic AI, has moved from supporting human judgment to making, influencing, and executing decisions across the enterprise, often at machine speed and machine scale.

Traditional governance is built around decision rights: who decides, who approves, how escalation works. That work still has to happen, and it now covers less ground than it is used to. In an AI-driven enterprise, governance has to extend into decision assurance, meaning the organization can demonstrate with evidence that every decision, human or machine, falls inside defined risk tolerances, passes through effective controls, and produces the outcomes it was meant to produce.


This paper covers:

  • Why AI collapses the traditional boundaries between corporate, IT, and cybersecurity governance

  • The shift from decision rights to decision assurance, and how that shift tracks the "Well Built, Well Run, Trustworthy" maturity curve described in the companion paper's 9-Box of AI Trust & Security framework

  • The risk and control continuum organizations need, from visibility and supply chain trust to validation and active defense

  • Why agentic AI is a governance problem before it is a technology upgrade

  • What governance design looks like in an AI-driven enterprise, and why decision assurance earns its keep commercially as well as with regulators


The central thesis is straightforward. Governance is still about decision-making, and it now has to account for machines that participate in, influence, or autonomously make those decisions. Governance sets the intent, and security proves the intent is being met. When decisions have no assurance, AI risks everything.





About ICIT

The Institute for Critical Infrastructure Technology (ICIT) is a nonprofit, nonpartisan, 501(c)3think tank with the mission of modernizing, securing, and making resilient critical infrastructure that provides for people’s foundational needs. ICIT takes no institutional positions on policy matters. Rather than advocate, ICIT is dedicated to being a resource for the organizations and communities that share our mission. By applying a people-centric lens to critical infrastructure research and decision making, our work ensures that modernization and security investments have a lasting, positive impact on society. Learn more at www.icitech.org.



 
 

The Institute for Critical Infrastructure Technology is a non-partisan 501(c)3 not-for-profit organization. 

EIN #47-5294309

Follow Us

  • LinkedIn
  • Youtube

Important Links

 Support

+  Privacy Policy

Get the latest news & expert opinions delivered straight to your inbox

Keeping People at the Center of Critical Infrastructure

© 2026 by The Institute for Critical Infrastructure Technology (ICIT)

bottom of page