AI agents need boundaries, not just a good demo
Microsoft's September 2026 responsible AI update raises a useful business question: when an AI can take actions, who decides what it is allowed to do?

Microsoft's September 1 responsible AI update discusses adapting governance for increasingly capable AI systems, including agent identities, tool permissions, evaluation and monitoring. It is a transparency and governance update, not a universal product launch.
The important question is not only what an agent can do. It is what happens when it should not do it.
Give every action a clear boundary.
A useful operating model starts with three things a team can explain without technical jargon.
Permission
Which records can the agent read or change, and for which business purpose?
Approval
Which decisions must wait for a person before money, customer commitments or data are affected?
Accountability
Who can review its actions, investigate a mistake and pause the workflow?
From model quality to operational control
Microsoft describes an evolving responsible AI framework and evaluation work, including tools for red teaming and agent testing. Its discussion also covers runtime checks and monitoring of agent behaviour.
Start with one useful, reversible task
Begin with assistance. Add authority only where the process justifies it.
Consider a hypothetical lead-handling workflow. An initial version could summarise incoming enquiries and suggest the right department. A person would check the recommendation. Only after assessing real examples would we consider allowing limited updates to the pipeline.
Plan the awkward cases, too
What happens if a message is ambiguous, a service is unavailable or two people edit the same record? We would test these cases before extending the workflow. A useful fallback may simply be to stop and assign the task to a person.
Connect the workflow before expanding the automation
We build integrations around clear responsibilities and business rules. A well-defined connection between systems is often the foundation an AI-assisted process needs.
Explore automation and integrationsClear answers, without the jargon.
01Does an AI agent need unrestricted system access?+
No. Our recommendation is the opposite: limit access to the specific task and require approval for consequential actions.
02Can an agent work with an existing CRM?+
Potentially, depending on the CRM's interfaces, permissions and data quality. We would assess those constraints before promising an integration.
03Do these principles require Microsoft products?+
No. This article uses Microsoft's report as a starting point. Our recommendations about ownership, permissions and fallback apply to project design regardless of the chosen provider.

Andrew Matia - LineWeb
Founder of LineWeb. I write about the practical side of websites, systems, automation and search: the decisions that make a business easier to run and clearer to find.
Read the founder storyWhich repetitive task should we look at first?
Show us the process, its exceptions and the systems involved. We can help define a useful first version, with clear limits and a person responsible for the result.