BylinesArtificial Intelligence

Building Governance and Accountability for Autonomous AI Decision-Making

Because Today's Authentication Methods Verify Identity and Permission at the Point of Login But Cannot Verify Intent

Organisations must establish transparent and robust governance frameworks for autonomous Artificial Intelligence (AI) agents. As Malaysia’s National Guidelines on AI Governance and Ethics stresses, this must clearly define what decisions these agents are permitted to make and the thresholds within which they can operate. That requires being able to clearly define the limits of the agent’s executive powers and pinpoint who authorises its decisions, all without slowing down the operational speed of businesses while enforcing the limits imposed on the agents.

This is the critical distinction between authentication, which answers who logged into the system, and authorisation, which answers who approved a specific action. Traditional identity systems authenticate credentials but do not establish a trustworthy link between a consequential AI action and the verified individual who authorised it.

Biometric identity verification provides that trusted link by confirming that a real, authorised person is present at the point of granting authority, rather than relying on existing sessions or delegated permissions. Combined with risk-based verification, organisations should implement situational, context-aware security measures that adapt to the level of risk. For example, low-stakes, routine approvals may be set up to proceed seamlessly, while high-value financial authorisations can be designed to require biometric verification beforehand. The organisations can then ensure accountability is preserved through clear and auditable chains of responsibility and that transactions are tied to a real human.

Digital Identity Verification: Enabling Secure and Responsible Agentic AI

Digital identity verification will play a foundational role in enabling secure and responsible adoption of agentic AI, because the entire trust chain begins and ends with a real person. As organisations deploy more AI agents to handle functions such as finance, procurement, and customer service autonomously, identity verification becomes the cornerstone for maintaining trust in those systems, especially with greater regulatory scrutiny from the likes of the National AI Office.

Today’s authentication methods verify identity and permission at the point of login. What they cannot verify is intent: whether a human with the authority to make a specific decision actually chose to make it.  A stolen password, a hijacked session, or an AI agent acting on old permissions can all pass a login check.

This is the gap that only biometric verification, with liveness detection, can close—proving a real person, not a credential, agent or deepfake, authorised a specific action as it happened.

As agentic AI takes on more autonomous decision-making, organisations will need both layers working together: establish who someone is and confirm that they, specifically, and no one else, made a given decision in real time. Without this combination, organisations face heightened risks of unauthorised delegation of authority, excessive AI permissions, and decisions that cannot be attributed to a verified individual, particularly as AI agents operate across multiple enterprise systems.

Finding the Right Balance Between Human Oversight and AI Autonomy

Equally important is maintaining a clear and auditable record of who authorised what, when, and why. Organisations need to know, for every consequential agent action, which verified individual granted approval or delegated authority. There is no room for compromise here as auditability is crucial to creating a trustworthy chain of responsibility in support of compliance and accountability, without introducing unnecessary friction into lower-risk operations.

Effective human oversight and governance must be risk-based and event-driven so that speed is not hampered by compliance, nor does agility circumvent accountability. Applying robust biometric verification,  when additional assurance is required, is the best way to ensure this, empowering organisations to adopt agentic AI fully knowing that human authority remains anchored to the actions that matter most.

Addressing New Cybersecurity and Fraud Risks as AI Agents Evolve

Despite reported cyber incidents dropping 7% between 2025’s last two quarters, CyberSecurity Malaysia has warned that tactics, techniques, and targets are actively evolving. The agency’s concern comes amid the development of more convincing deepfakes, the proliferation of synthetic identities, and the rise in AI-assisted social engineering, which have also become more accessible and thus have substantially complicated the threat landscape.

AI agents amplify these threats, and the potential impact of identity compromise is a bigger risk today than ever before Now, when an attacker gains control of a trusted identity or delegated authority, autonomous agents can execute actions rapidly and across multiple enterprise systems, magnifying the scale of fraud or operational damage far beyond what a human attacker could achieve alone. Organisations deploying agentic AI cannot afford to trust the technology by default; they need a way to verify that a real, authorised human is behind every consequential decision an agent carries out.

The foundation of secure AI agent adoption is the certainty that every consequential action originates from verified human intent. As Malaysia accelerates its digital transformation, the integrity of identity verification will be fundamental to the secure deployment of autonomous systems. Organisations that strengthen identity assurance today will be better positioned to embrace AI innovation while staying ahead of increasingly sophisticated AI-enabled fraud.

Dominic Forrest

Chief Technology Officer, iProov

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *