top of page

AI Doesn't Just “Go Rogue.” We Give It Permission.

Writer: OGI - Oscar Gonzalez Iñiguez
OGI - Oscar Gonzalez Iñiguez
Sep 8
5 min read

The real AI risk isn't a machine suddenly deciding to take control. It's giving powerful AI systems too much autonomy without the right intelligence, permissions and governance.


Every few weeks, we see another alarming headline:


“AI went rogue.”


"An AI tried to avoid being shut down. An agent acted against instructions. A model found an unexpected way to accomplish its objective... blah, blah, blah "


It makes wonderful headlines and lots of clicks on social media.


But as someone who has spent years developing AI systems with top AI researchers and highly experienced software engineers—and who is now focused on building Specialized Intelligence Engines for critical business and defence decisions—I think we need to be much more precise about what is actually happening.


AI does not simply wake up one morning and decide to take control.


An AI model cannot independently affect the outside world unless we build a system that lets it do so.


And that distinction matters enormously.


An LLM can generate an answer. It cannot magically execute it.


At its simplest, an AI model works like this:


INPUT → AI MODEL → OUTPUT


Ask it a question, and it generates a response (when using generic AI tools like Claude or ChatGPT).


It may produce an excellent answer. It may produce a terrible one. It may even generate something its developers did not anticipate.


But generating an answer is fundamentally different from taking an action.


For an AI to send an email, modify a database, execute code, place an order, access a business system or control another machine, something else must exist around the model.


The architecture starts looking more like this:


OBJECTIVE → AI → AGENT → TOOLS/APIs → ACTION → RESULT → AI


  • Someone gave the system access to those tools.

  • Someone provided credentials.

  • Someone established permissions.

  • Someone created the execution loop.

  • And someone decided how much autonomy the AI should have.


This is where the conversation about AI risk becomes much more interesting.


Modern AI agents can do things nobody explicitly programmed them to do


There is an important nuance here.


Developers do not necessarily program every action.


Nobody has to write:


IF the AI wants to modify inventory → modify inventory.


Modern agentic systems can be given an objective and a collection of tools. The AI can then decide which tools to use, in what order, and potentially repeat the process until it believes it has achieved the objective.


That is extraordinarily powerful.


It is also where risk emerges.


Imagine giving an AI agent access to:


  • ERP systems

  • corporate databases

  • email

  • financial systems

  • APIs

  • code execution

  • external information

  • other AI agents


Then tell it:


“Maximize the company's cash position.”


The AI might discover a sequence of actions nobody anticipated.


But this doesn't mean the AI magically developed new powers.


We gave it the powers.


The unexpected part is how it decided to use them.


“Rogue AI” is often the wrong description

What we frequently call rogue AI is better described as:

A powerful optimization system pursuing an objective through capabilities humans gave it, producing behaviour humans did not anticipate or intend.

This distinction is important because otherwise we may focus on the wrong problem.


The immediate danger isn't necessarily an AI becoming conscious, developing ambitions and deciding that humans are its enemy.


A system doesn't need consciousness to cause enormous damage.


It only needs:


A poorly defined objective + powerful capabilities + excessive permissions + insufficient controls.


Consider a financial AI instructed:


“Reduce working capital by 25% as quickly as possible.”


Give that system unrestricted authority, and it might find mathematically effective but commercially disastrous solutions:


  • Reduce inventory aggressively.

  • Delay suppliers.

  • Restrict customer credit.

  • Cancel purchases.

  • Cut operating expenses.


Those actions might improve one financial metric while simultaneously damaging sales, suppliers, customers and the long-term health of the company.


The AI doesn't have to hate the company.


It doesn't even have to understand what “hurting the company” means in the human sense.


It simply needs to optimize the wrong objective with too much authority.


That is not science fiction.


That is an intelligence architecture and governance problem.


Autonomy and intelligence are not the same thing


This is a distinction I believe business and technology leaders urgently need to understand.

Giving AI more autonomy does not necessarily make a company more intelligent.


I see three very different architectures emerging.


1. Generative AI


Question → LLM → Answer


The AI generates information.


2. Agentic AI


Objective → AI → Reason → Select Tools → Execute → Observe → Repeat


The AI can execute actions through tools and systems made available to it.


3. Specialized Intelligence


Trusted Data → Business Rules → Analytical Models → AI → Recommendation → Validation → Authority → Action


This third architecture is where I believe mission-critical enterprise AI needs to go.


Because when a CFO asks how to increase EBITDA, the answer shouldn't simply come from what an LLM statistically believes sounds appropriate.


The system should analyze actual financial and operational data.


  • It should calculate the drivers.

  • It should apply financial models.

  • It should understand the company's business rules.

  • It should evaluate scenarios and consequences.

  • It should incorporate the organization's knowledge and experience.


Then AI can help orchestrate all that intelligence to recommend what management should do.


That is fundamentally different from simply giving an AI agent more tools and more autonomy.


Sometimes the smartest AI is the AI that is not allowed to decide


This may sound counterintuitive during today's race toward autonomous agents.


But in finance, defence, industrial operations and other mission-critical environments, I believe this principle will become increasingly important:

AI recommends. Deterministic systems calculate. Policies constrain. Humans authorize critical decisions.

Of course, some decisions can and should be automated.


Others can be automated within clearly defined thresholds.


Some should require human approval.


And certain decisions should always remain under human authority.


The sophisticated part isn't simply making AI autonomous.


It is knowing where autonomy should stop.


This is why I believe the future is Specialized Intelligence


The next competitive advantage in AI won't come simply from access to the most powerful LLM.


Models are becoming increasingly accessible.


Agents are becoming easier to build.


Tools can increasingly be connected to almost anything.


Real differentiation will come from the intelligence architecture around those models.


  • What data should the system trust?

  • Which calculations must be deterministic?

  • Which business rules must always apply?

  • Which models should evaluate the decision?

  • What organizational knowledge should influence it?

  • What actions can AI execute?

  • What requires approval?

  • Who ultimately has authority?


These are the questions we are working on at Accéder as we develop TITAN Specialized Intelligence Engines for financial and defence decision-making.


Because I don't believe the objective should be to create AI that makes every decision for us.

The objective should be much more ambitious:


Build intelligence systems that help humans make extraordinarily complex decisions better, faster and with greater confidence—while keeping authority exactly where it belongs.


So the next time you read that an “AI went rogue,” ask a different question:


What objective was it given, what capabilities did humans give it, what was it allowed to do—and where were the controls?


That is where the real story usually begins.


Have an awesome day!




Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.

2025 Accéder © All Rights Reserved

Designed by alfaROI

bottom of page