Saudi Arabia is about to host two major global conversations on artificial intelligence. The UNESCO Global Forum on the Ethics of AI will take place in Riyadh from September 14 to 17, followed alongside the fourth Global AI Summit from September 15 to 17. Both events put responsible innovation and AI governance at the centre of the debate.
That makes Riyadh an appropriate place to raise a question that is becoming increasingly important for governments and businesses: how much authority should we give artificial intelligence?
Until recently, much of the AI debate focused on what models could say or create. The next challenge is what they are allowed to do.
When AI moves from answering to acting
The distinction matters because AI is increasingly moving beyond the role of an assistant. Newer AI systems — often called AI agents — can perform tasks rather than simply provide answers. Depending on the permissions they receive, they may access databases, send messages, use software, make purchases, change records or interact with other digital systems. An AI tool that summarizes a report carries relatively limited operational risk. An AI system allowed to approve a transaction, change sensitive information or operate inside a company’s network creates a very different level of exposure. The underlying technology may be similar. What changes is its authority.
A recent incident involving Hugging Face provides an unusually clear example. METR and Redwood Research reported in August that roughly 1,200 AI agents, which were intended to operate independently, found a way to communicate through an unauthorized shared message board. They exchanged more than 70,000 messages and files, and roughly 700 participated in activity targeting Hugging Face. Researchers found that some agents joined even after recognizing that the activity went beyond their assigned tasks.
Hugging Face separately reported that an autonomous AI agent gained unauthorized access to part of its production infrastructure and moved further into internal systems. The company said no public user-facing models, datasets or Spaces were tampered with. The important conclusion is not that AI suddenly became malicious in a human sense. It is simpler: when software receives autonomy, access and the ability to take actions, mistakes or unexpected behaviour can have consequences far beyond a chatbot giving a wrong answer.
A simple test of AI authority
This does not argue for slowing AI adoption. In fact, clearer safeguards may make adoption easier by giving companies, employees and regulators greater confidence about what AI can and cannot do.
Saudi Arabia has an opportunity to help turn that principle into something practical. SDAIA is already developing standards for human AI capabilities. In August, it opened registration for national AI Professional Badges, with applicants assessed under a standardized three-level framework intended to provide employers with a reliable measure of professional competence.
If skills can be assessed against a standard, AI authority could be assessed as well. Before deploying an AI system, an organization could ask five straightforward questions: What information can it see? What can it change? What tools can it use? Who can it communicate with? And what decisions can it make without human approval?
These questions are understandable well beyond the technology sector. An AI system reading public information is not equivalent to one accessing medical records. Drafting an email is different from sending it automatically. Recommending a payment is different from approving one.
As authority increases, safeguards should increase with it. More powerful systems may require tighter permissions, human approval for consequential decisions, detailed records of their actions, limits on spending or external communication, and the ability to shut off access quickly. The same principle should apply to testing. A company should not ask only whether an AI system performs well. It should ask what could happen when that system is combined with the actual authority it will receive inside the organization.
From ethical principles to practical rules
The broader question is how AI governance moves from principles to everyday practice. UNESCO describes its Riyadh forum as an effort to advance practical implementation of ethical AI governance, while SDAIA has emphasized responsible and ethical use as part of Saudi Arabia’s AI agenda.
An authority-based approach could provide one answer.
It may also make economic sense. Businesses are more likely to expand automation when executives know who remains accountable, security teams understand what AI can access and employees know which decisions still require a person.
The real test for AI governance, therefore, may not be whether governments can define what responsible AI means in principle. It will be whether they can translate those principles into rules that work when AI starts taking real actions in the real economy.
Saudi Arabia wants to play a larger role in shaping global AI governance. Treating AI authority as a measurable level of risk could be a practical contribution: allowing organizations to move quickly with AI without giving machines more power than institutions are ready to control.

Gleb Tsipursky, PhD, is a behavioral scientist, author and CEO of Disaster Avoidance Experts. His work has appeared in Harvard Business Review, The Guardian, Fast Company and other international publications. He is the author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026).


