Related Big Read: The blast radius problem: how agentic AI broke the permissions model
Related assets: Agent identity as the control boundary; Shadow agents as shadow workforce risk
An AI assistant gives answers.
An AI agent can act.
That distinction changes the risk balance. A wrong answer can generally be corrected. A flawed execution can delete data, overwrite configuration, send instructions, trigger workflows, move money, expose records, or affect physical systems, all before a human has time to intervene.
This is the Agentic Blast Radius problem.
The organisation is no longer evaluating model quality solely on the responses it can provide. It is also evaluating how the model uses the tools at its disposal and how far delegated authority can extend.
Moving from assistant to agent? Consider these factors to minimise your agentic blast radius
Agentic systems should not be approved on their promise, accuracy, or productivity alone.
They need a pre-deployment review that maps the maximum consequence of valid action. The question is not what the agent is meant to do on a good day. It is what the agent could do with the permissions it has been given.
What to consider before granting execution authority:
Use this diagnostic before granting an AI agent meaningful execution authority. Test the maximum consequence of valid action, not only the agent’s intended use.
Execution scope
Agentic blast radius
Access controls
Human authorisation gates
Verification and testing
Ongoing governance
Sign-off rule
Any unchecked item is an open risk, not a deferred task.
For high-consequence deployments, the completed diagnostic should be placed alongside the deployment approval record. It should include the blast-radius map, worst-case scenario, execution boundary, and revocation path.
If you cannot answer these questions, the agent is not ready for production.