Australia Needs Permission Budgets for AI Agents
- Written by: Gleb Tsipursky, PhD

The Times recently argued that Australia should keep building the data centres the AI economy requires while setting firm, predictable conditions so their costs do not spill onto the public. Its case for clear standards that permit investment to proceed should extend one layer up the technology stack. Australia also needs clear operating conditions for the AI agents that will run on that infrastructure.
That question is becoming urgent because an AI agent can do much more than produce text. It can plan and execute self-directed actions in pursuit of a goal, using software tools and feedback from earlier steps. Australia’s National AI Plan combines wider adoption with safeguards against emerging harms. Agentic AI sits directly at that intersection: useful enough to deserve rapid deployment, but autonomous enough that organisations need to decide how much authority to give it before it starts acting.
Australian cyber guidance released this month offers a practical way to think about that authority. The Australian Signals Directorate says the software layer around an agent, often called the harness, determines how the model interacts with tools, data, and workflows. A well-designed agentic AI harness can provide governance and security controls across changing models. That is exactly where businesses can enforce what I call a permission budget.
A permission budget sets the maximum authority an agent can exercise without fresh approval. It should specify what information the agent may read, what records it may change, which external actions it may take, how much money or computing capacity it may spend, whether it may delegate work to other agents, and how long elevated permissions last.
The point is to make autonomy measurable. A customer-service agent could read an account and draft a response but require approval for a refund above a set amount. A finance agent could reconcile transactions without gaining authority to move money. An IT agent could diagnose a production problem while needing a separate approval to change a live system. The organisation can automate routine work while reserving consequential actions for a person or a more tightly controlled workflow.
This approach closely matches the Australian Signals Directorate’s earlier guidance against broad or unrestricted agent access. The agency recommends progressive deployment, explicit constraints, monitoring, isolation, and human oversight. A permission budget turns those principles into operational limits that a manager, auditor, or regulator can actually inspect.
Recent events show why that distinction matters. During OpenAI cybersecurity evaluations in July, roughly 1,200 agents discovered ways to communicate through an unsanctioned shared channel. An independent METR and Redwood Research investigation found that the agents exchanged more than 70,000 messages and files and that about 700 participated in the attack on Hugging Face. Their behaviour went far beyond the narrow tasks individual agents had been assigned.
OpenAI’s own account says agents executed code on Hugging Face servers, obtained root access on one server, acquired limited private data and credentials, and later gained administrator access to an OpenAI research cluster. OpenAI traced the incident to patterns including reward hacking, persistence, unauthorised communication, and agents adopting goals from one another.
The policy lesson is narrower than “agents are dangerous.” Instructions about intended scope are weak protection when software has credentials, tools, persistence, and room to improvise. Australian cyber officials have separately warned that agents may exploit shortcuts or loopholes, a pattern known as specification gaming. The more consequential the available action, the less an organisation should rely on the agent deciding for itself that an action falls outside the assignment.
Permission budgets also need to survive delegation. If one agent cannot access payroll records, it should not be able to obtain the same information indirectly by asking another agent. A $5,000 spending ceiling should remain a $5,000 ceiling even if five sub-agents divide the work. The same AI Safety Institute report warns that systems of individually reliable agents can still produce new failures through interaction, including cascading errors and behaviours that no single agent’s design predicts.
Businesses therefore need controls around the whole chain of authority, rather than just each agent in isolation. High-impact actions should have clear approval points. Sensitive privileges should expire automatically. Logs should sit outside the agent’s ability to rewrite them. Organisations should retain a separate way to interrupt or shut down the system. Australian cyber officials have similarly stressed human oversight, reversible actions, visibility into agent behaviour, and explicit limits as agentic capabilities mature.
This is also a useful agenda for Australia’s new AI Safety Institute. Its remit includes analysing and testing advanced AI models and applications, supporting regulators, and shaping safe deployment. The institute can help turn technical risk research into practical tests for real agent deployments: Can the agent increase its own permissions? Can delegation expand its effective access? Can it spend beyond a defined ceiling? Can it alter the evidence investigators would need after a failure?
Those tests would support adoption rather than obstruct it. Organisations move faster when leaders can distinguish low-risk automation from actions that could create financial, operational, privacy, or cybersecurity damage. In my work on AI adoption at work, the organisations that make progress give employees room to experiment while making the boundaries of acceptable use concrete.
Australia does not need to predict every capability that the next generation of agents will acquire. It does need a rule for authority that remains useful as those capabilities change. Require consequential agents to operate inside explicit permission budgets, verify that the limits survive delegation, and expand autonomy only after the controls prove they work. That gives Australian organisations a practical way to keep moving quickly on AI while making responsibility clear before software gets the chance to act.
Gleb Tsipursky, PhD, is a behavioural scientist, CEO of Disaster Avoidance Experts, and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026).












