Three items this time, and one question underneath all of them: when software makes a decision or takes an action, who actually said it could? This cycle's blog post asks it about AI agents. Colorado just wrote its own answer into draft rules. And Congress, again, gave a short answer to a long question.
Your AI Agents Already Have More Access Than You Think#
On May 26, Gartner put a name on why so many AI agent projects fail: companies treat every agent the same way, either locked all the way down or trusted all the way through. The Cloud Security Alliance's April research note shows what that costs: 53% of organizations say an AI agent has already exceeded the permissions it was supposed to have, and close to half report a security incident involving an agent in the prior twelve months. Gartner puts the share of organizations with a comprehensive AI governance framework at 8%.
An AI agent is software that does not just answer, it acts. It reads files, sends email, changes records, and calls other software on its own, working toward a goal rather than following a command for each step. Most agents reach those tools through the Model Context Protocol (MCP), a standard connector that works like a universal electrical outlet. Researchers disclosed more than 40 vulnerabilities in MCP implementations between January and April, and the National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) published a joint security advisory on it in June. Anthropic's disclosure last November showed the far end of the scale: a state-linked group talked a coding agent into running most of an espionage campaign by claiming to be a legitimate security firm.
Gartner analyst Shiva Varma put it plainly: treating governance as "either locked down or fully trusted" is "the root cause of failure." Picture giving the summer intern and the CFO the same badge. Neither setting is a policy. Both are the absence of one.
What it changes for you: write down every agent in production, what it can reach, and whether that access is read-only or can change things. Then sort each one into a tier: read-only, limited write with monitoring, or human approval before anything that moves money, changes customer data, or sends something outside the company. The blog post has the full breakdown by company size.
Colorado Rewrote Its AI Law, and the Draft Rules Define "Human Review"#
In May, issue #3 told you Colorado's AI Act was paused. Here is the update. Later that month, Colorado repealed and replaced it with the Automated Decision-Making Technology (ADMT) Act, a narrower law built on disclosure instead of a broad duty of care. It takes effect January 1, 2027. On August 11 the state attorney general proposed the implementing rules, and written comments stay open through an October 26 hearing.
The law covers software that "materially influences" decisions about people's jobs, housing, lending, insurance, education, health care, or government benefits. Deployers must tell people before the software is used. After a denial they have 30 days to explain the decision and offer correction and meaningful human review. The draft rules say what that review means: a reviewer independent of the original decision where feasible, with real subject knowledge, real authority to change the outcome, protection from pressure by managers, and no AI assisting the review itself. The rules also add a "midstream developer" category for companies that build someone else's tool into their own product.
What it changes for you: if you make decisions about Colorado residents in any of those areas with software in the loop, list those decisions now. The core duties come from the statute, not the rules, so they arrive January 1 whether or not the rules are final. If your AI tool comes from a vendor, ask for the documentation the law requires developers to hand over.
The Threat-Sharing Shield Got Another Short Reprieve#
In issue #11 I said the Cybersecurity Information Sharing Act of 2015 would lapse September 30, and suggested asking counsel what changes if it does. Here is the update. The stopgap funding bill the President signed on September 2 extends it to December 11, 2026. That law is what protects companies from liability, and keeps shared data out of public-records requests, when they share threat indicators with the government and with each other.
It is the third short extension in a year, and a long-term renewal is still stuck in the Senate. So you have ten weeks, not a fix.
What it changes for you: don't close the question you opened in September. Ask counsel to write the answer down now, so a December lapse becomes a memo you already have, not a scramble on the day.
One Level Deeper: Your "Human in the Loop" Probably Wouldn't Pass Colorado's Test#
The blog's fix for high-risk agents is a human approval step before any action that moves money, changes customer data, or goes outside the company. That is right. What the blog doesn't cover is that most approval steps are theater, and Colorado just handed us a yardstick for spotting it.
Colorado wrote its review test for decisions about consumers, not for approving agent actions. No law requires it of your agents. But it is the most concrete public definition of real human review available, and it maps cleanly onto agent approvals. Run your approval step through four questions.
First, can the approver say no without paying for it? If rejecting an agent's action means explaining yourself to a manager chasing an automation target, the reviewer has no real authority. Second, does the approver see the evidence, or only the agent's summary of it? Approving a refund from the agent's one-line description is checking the agent's homework using the agent's answer key. Third, what is the approval rate? If a reviewer has approved 99 of the last 100 actions, that is a rubber stamp with a salary. Fourth, is another AI tool doing the reviewing? Colorado's draft bans that for its reviews, and the reason carries over: a second model checking the first is automation, not oversight.
An approval step that fails two of these is a delay, not a control. It will slow the agent down and still let the bad action through.
How This Impacts Your Organization#
The principle doesn't change with company size: software is making decisions and taking actions faster than anyone is writing down who allowed it, and the law is starting to ask for that answer in writing. What changes is how many agents and automated decisions you have, how much damage one bad action can do, and whether you have the people to review them properly.
Large Enterprises (1,000+ employees)
Your real risk is organizational: agents are being built by five teams, automated decisions sit in HR, lending, and customer service, and nobody holds one list. Your leverage is that you can require one. This quarter, put agents and automated decisions about people into a single inventory with a named owner for each, test your human-approval steps against the four questions above, and have legal file a comment on Colorado's rules before October 26 if the "materially influences" definition affects your products.
Mid-Size Organizations (100–999 employees)
You feel this fastest because the person who turned on your first agent also approved its access. The overcorrection to avoid is buying an AI governance platform before you have a one-page list. Three moves: write the list of agents and what each can touch; add a human approval step to anything that moves money or contacts customers, and check the approval rate after a month; and if you screen, lend, or insure Colorado residents with software involved, draft the adverse-decision notice now, since January 1 won't move for you.
Small & Growing Organizations (under 100 employees)
Honest counsel: you probably built no agents, but your software vendors turned some on for you. Spend one afternoon in the settings of the AI tools you use and switch off automatic-action features nobody chose. You are likely not a Colorado deployer unless you make hiring, housing, or lending decisions with software, and if you do, your vendor should be doing most of the documentation work. Ask them in writing. Nothing here requires a purchase.
Curated Links#
- Your AI Agents Already Have More Access Than You Think (companion blog post) — dlegenddigital.com/blog
- Gartner: uniform governance across AI agents will lead to failure — gartner.com/newsroom
- Cloud Security Alliance: the AI agent governance gap — cloudsecurityalliance.org
- NSA/CISA: Model Context Protocol security design considerations — media.defense.gov
- Anthropic: disrupting an AI-orchestrated cyber espionage campaign — anthropic.com
- Colorado attorney general: ADMT Act and Chatbot Safety Act rulemaking — coag.gov/ai
- Colorado attorney general releases proposed ADMT rules — bytebacklaw.com
- Colorado SB 26-189, Automated Decision-Making Technology — leg.colorado.gov
- H.R. 6500 signed into law — whitehouse.gov
- CR extends cyber info-sharing law through December — federalnewsnetwork.com
Three items, one habit: before software decides or acts, someone should have written down that it may. Make the list. Give each entry an owner. Test the human in the loop.
On the blog this cycle: Your AI Agents Already Have More Access Than You Think — the numbers, the MCP problem, and how to tier your agents at every company size.
Hit reply and tell me what you're wrestling with — I read every one.
— Charles Redding, Founder, DLegendDigital