AI Is Making Decisions at Work. Most Companies Have No Rules for That.

Stephen Wilson, field CTO at HashiCorp, says businesses are giving AI tools real operational independence while still applying the loose oversight they used when AI only answered questions.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: A modern open-plan office at dusk, rows of glowing monitors showing abstract dashboard interfaces
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Most companies still govern AI tools as they did when AI only answered questions, not when it acts on its own.
  • Stephen Wilson, field chief technology officer at HashiCorp, an IBM company, identifies three stages of AI use: assistant, agent, operator.
  • At the operator stage, AI can run an entire marketing campaign with no human approving individual decisions for hours.
  • Wilson says governance must scale at the same pace as AI independence, covering data access, identity and audit trails.
  • Organisations that skip this step risk AI accessing sensitive data or publishing unapproved content with no way to trace what happened.

When your company's AI could only answer questions, the risk felt containable. Now that it can book meetings, post to social media and move money, the rules need to change. Most haven't.

That is the central warning from Stephen Wilson, field chief technology officer at HashiCorp (an IBM company), who spoke with CSO Online about a governance gap already widening.

Why does it matter how much independence an AI has?

More independence means more potential damage when something goes wrong. Wilson maps AI use across three stages, each carrying a different risk profile.

The first is AI as an assistant. A person types a prompt, reads the output and decides what to do. Humans remain close to every step. The main risk is careless data handling: a staff member might paste an API key or a confidential client record into a chat window without thinking.

The second is AI as an agent. A person sets a goal and steps back. The tool completes multiple steps independently, possibly handing work to a second AI before a human sees anything. Nobody watches each individual step. Wilson says organisations here must give AI a proper, traceable identity with limited permissions rather than borrowed human credentials.

The third is AI as an operator. This is where AI takes on entire projects. Wilson gives a direct example: a business asks an AI system to design and execute a full marketing campaign. Two hours later, the social posts and publishing schedule are done, with no human having approved any single decision along the way.

"The level of governance and identity and auditing have to increase as your level of oversight decreases," Wilson told CSO Online.

Our coverage of context manipulation attacks against agentic browsers on 2 July shows exactly what is at stake when those controls are absent: poisoned inputs caused AI agents to quietly exfiltrate stored credentials.

The practical risk is concrete. An operator-stage AI could publish the wrong message, access records it should not reach, or act on bad information, with no clean audit trail showing exactly what it did or why.

Wilson's sharpest point is structural. Governing AI should scale the way governing people does: one employee needs one set of rules, a team needs clearer processes, a full business unit needs formal controls and audit logs. AI is following that same curve, only faster.

Should you worry?

Most organisations are still somewhere between stage one and stage two. Wilson notes that even at the assistant stage, a user with elevated access can inject privileged credentials into a prompt without realising the exposure. The operator stage makes that risk systemic rather than individual.

The window to build proper controls is open now. Once autonomous workflows become routine, retrofitting governance is significantly harder. Build the identity, access and audit infrastructure before the AI asks for permission to act.

© 2026 Threat Vectr