Capability Is Not Authority

What AI can do is a technical fact. What it may do is a human decision.

15 August 2026 · Newsletter issue · Marshall Principle

Most organizations discover artificial intelligence the same way they discover a new employee who already has the keys: the work is underway before anyone wrote a job description.

A model drafts the client letter. An agent fills the CRM. A bot marks the invoice sent. Someone says, “It’s done,” because the screen said so.

That moment is not primarily a technology problem. It is a governance problem with a simple name.

Capability is not authority.

The Marshall Principle

I put the fixed point this way:

Artificial intelligence may assist human decision-making, but responsibility always remains with humans.

Assistance is welcome. Substitution of responsibility is not.

An AI system may be technically able to send email, move money, publish content, or speak in the company’s voice. That ability does not grant permission. Permission is a human decision that must be explicit, assignable, and revocable.

If you cannot name the human who owns the outcome before the action runs, you do not have governance. You have automation with hope attached.

Four states, not one word: “done”

Consequential actions should be describable in four states:

Collapsing those four into “the AI said it’s done” is how organizations invent confidence.

A green checkmark is not a bank deposit. A generated dossier is not a client-ready judgment. A graded “ready” pack is not proof a stranger would find it valuable. Assertions are not evidence.

Where small firms actually break

Large enterprises write policies after the second incident. Small firms often skip the first document entirely.

The failures I see look ordinary:

None of that requires science fiction. It requires someone to say: this system may assist; this human remains responsible.

External AI is not your spokesperson

There is a second confusion worth naming.

What ChatGPT, Grok, or Google’s AI Overview says about your firm is an observation about those systems. It is not a statement your organization authorized—unless you deliberately published the underlying source truth and still hold a human accountable for it.

Three layers stay separate:

Treating a model’s summary as your brand book is how reputation drifts without a meeting.

What “implement” looks like (without theater)

A constitution does nothing if operations ignore it. Implementation is boring on purpose:

I published our own constitutional layer as a free public document so visitors—and our own systems—have the same north star:

AI Governance Policy (free) →
Also on magrs.org.

A closing test

Before the next AI-assisted action in your firm, ask three questions:

  1. Who is the human principal if this goes wrong?
  2. Was authority granted, or only capability installed?
  3. What evidence will verify the outcome—not merely report completion?

If those answers are fuzzy, the system is not ready. The human still is. That is the point.

Related reading: The 7 AI Risk Blindspots · Why Most Small Firms Will Adopt AI Before They Realize It · Governance standard · Newsletter