Capability Is Not Authority
What AI can do is a technical fact. What it may do is a human decision.
15 August 2026 · Newsletter issue · Marshall Principle
Most organizations discover artificial intelligence the same way they discover a new employee who already has the keys: the work is underway before anyone wrote a job description.
A model drafts the client letter. An agent fills the CRM. A bot marks the invoice sent. Someone says, “It’s done,” because the screen said so.
That moment is not primarily a technology problem. It is a governance problem with a simple name.
Capability is not authority.
The Marshall Principle
I put the fixed point this way:
Artificial intelligence may assist human decision-making, but responsibility always remains with humans.
Assistance is welcome. Substitution of responsibility is not.
An AI system may be technically able to send email, move money, publish content, or speak in the company’s voice. That ability does not grant permission. Permission is a human decision that must be explicit, assignable, and revocable.
If you cannot name the human who owns the outcome before the action runs, you do not have governance. You have automation with hope attached.
Four states, not one word: “done”
Consequential actions should be describable in four states:
- Intended — a human (or authorized process) decided it should happen
- Attempted — the system started
- Completed — the system reported finished
- Verified — evidence shows the intended outcome actually occurred
Collapsing those four into “the AI said it’s done” is how organizations invent confidence.
A green checkmark is not a bank deposit. A generated dossier is not a client-ready judgment. A graded “ready” pack is not proof a stranger would find it valuable. Assertions are not evidence.
Where small firms actually break
Large enterprises write policies after the second incident. Small firms often skip the first document entirely.
The failures I see look ordinary:
- Staff paste client facts into consumer tools because the tool is convenient
- Leaders treat chat answers as research rather than draft
- Agents are given credentials “to save time,” then nobody owns the send button
- Public pages and AI answers disagree, and nobody is assigned to reconcile source truth
None of that requires science fiction. It requires someone to say: this system may assist; this human remains responsible.
External AI is not your spokesperson
There is a second confusion worth naming.
What ChatGPT, Grok, or Google’s AI Overview says about your firm is an observation about those systems. It is not a statement your organization authorized—unless you deliberately published the underlying source truth and still hold a human accountable for it.
Three layers stay separate:
- Source truth — what you publish and attest to
- AI representation — what models currently say
- Organizational authority — what you actually approved
Treating a model’s summary as your brand book is how reputation drifts without a meeting.
What “implement” looks like (without theater)
A constitution does nothing if operations ignore it. Implementation is boring on purpose:
- Name the human principal before consequential automation
- Separate tools that can act from tools that may act
- Require evidence proportional to materiality (send logs, opens, payments—not vibes)
- Block shipping work that only looks complete (labels without substance)
- Publish what you stand on, so external AI has something true to cite
I published our own constitutional layer as a free public document so visitors—and our own systems—have the same north star:
AI Governance Policy (free) →
Also on magrs.org.
A closing test
Before the next AI-assisted action in your firm, ask three questions:
- Who is the human principal if this goes wrong?
- Was authority granted, or only capability installed?
- What evidence will verify the outcome—not merely report completion?
If those answers are fuzzy, the system is not ready. The human still is. That is the point.
Related reading: The 7 AI Risk Blindspots · Why Most Small Firms Will Adopt AI Before They Realize It · Governance standard · Newsletter