← All posts

AI for Norwegian boards

AI autonomy: set limits on commitments, not just model capability

How Norwegian boards can define what AI may prepare, change or commit, and ensure human approval means more than clicking a button.

A procurement manager holding an approval stamp above an order awaiting a decision.

An assistant that drafts a purchase order and an agent that sends it can use the same model. They expose the company to different consequences. The meaningful dividing line is often the commitment the system can make, rather than how impressive its reasoning appears.

For a Norwegian board, I would describe AI autonomy in the language already used for delegated authority: what may be done, for whom, within which limits, and who can stop it? A company should be able to explain that boundary without naming a model.

Separate four kinds of authority

My proposed distinction is between reading, preparing, changing and committing. Reading a restricted file creates a confidentiality exposure. Preparing a recommendation creates a reliance risk. Changing an internal record affects the next person's work. Sending an offer, paying money or determining an individual's outcome can create consequences outside the company's immediate control.

Those categories are a discussion aid, not a legal classification or an automatic ladder to climb. An agent should receive only the authority needed for its actual task. A successful drafting pilot is not evidence that unattended payments are safe.

Write a decision boundary people can apply

Consider a hypothetical Norwegian marine-equipment supplier. An agent may compare an approved supplier list with stock needs and prepare a reorder. Management proposes allowing it to place orders automatically below NOK 10,000.

The limit looks reassuring until the agent places twenty related orders or changes the delivery address. A spending threshold needs an aggregate period, permitted counterparties, an approved destination and rules for unusual combinations. The same applies to customer discounts: a small percentage can still be a material commitment on a large contract.

A usable mandate might say that the agent can prepare orders but cannot add suppliers, amend bank details or send an order before a designated employee approves the actual contents. If later evidence supports limited automatic ordering, management should define and test the additional boundary separately.

Ask whether the control can actually prevent the action

  • Can the system's permissions enforce the limit even if its generated explanation is wrong?
  • Does approval show the amount, recipient, source evidence and intended action, rather than an opaque recommendation?
  • Can the reviewer reject or change the proposal without unreasonable pressure to approve everything?
  • Are repeated actions and cumulative exposure visible, including actions spread across connected systems?
  • Can someone withdraw the agent's access promptly, and is there a tested route to reconcile completed actions?

These are assurance questions. The board sets the level of exposure it is willing to consider; management designs and demonstrates the controls. Higher impact calls for stronger evidence than a dashboard of successful routine cases.

People’s rights do not disappear inside a workflow

Where personal data are involved, GDPR Article 22 addresses decisions based solely on automated processing that have legal or similarly significant effects, with specified exceptions and safeguards. Article 35 requires a data protection impact assessment where processing is likely to create high risk to people's rights and freedoms. A company policy permitting AI does not override those requirements.

This is especially relevant when a proposed efficiency measure moves into recruitment, employee assessment, credit or access to important services. A nominal human approver should not be used to disguise what is effectively an automated decision. Obtain a specific legal and operational assessment of that use case.

For the wider Norwegian context, the government's 4 August 2026 announcement described a plan for renewed consultation and an ambition to submit the KI law to Parliament in spring 2027. That announcement is not proof that the law is in force. Existing obligations must be assessed independently.

Make expanded authority a fresh decision

The control that matters is often outside the prompt: a permission, a transaction rule, a separation of roles or a human decision made with usable evidence. Ask management to bring back proposals when the agent gains new data, tools or external authority, not merely when the licence is renewed.

Use the incident response guide to test the stop-and-recover process. Authority is only meaningfully bounded when the organisation can recognise a breach of the boundary and respond.

Sources and scope

Sources checked on 11 October 2026. The four-part authority model, questions and marine-supplier scenario are my recommendations and a hypothetical example. Sector-specific duties and the facts of each use case require separate assessment.