An AI Policy Is Only the Beginning. What Happens When AI Systems Act on Behalf of the Organization?
In recent years, dedicated AI regulation has begun to take shape around the world, alongside existing laws that may already apply, directly or indirectly, to different uses of AI. In the European Union, for example, the AI Act creates a framework of obligations relating to, among others, risk management, documentation, transparency and human oversight, some of which already apply while others will come into effect at a later stage.
In Israel, too, there is a growing discussion about how organizations should govern their use of artificial intelligence. In May 2026, the first version of the Guide for the Responsible Use of Artificial Intelligence in the Public Sector was published by the National Digital Agency, in collaboration with the Ministry of Justice's Counseling and Legislation Department. Among other things, the Guide proposes an organizational policy addressing the allocation of roles and responsibilities, approval processes for the use of AI tools, controls, incident management, training and employee guidelines.
Private organizations are also beginning to adopt AI use policies, examining, among other things, the uses, tools, outputs, exposure, controls, and what is permitted and prohibited.
This is an important starting point. Even where there is no general requirement to adopt an AI policy, an organization using these tools should know which systems are being used, what information is being provided to them, who is authorized to use them, what outputs they produce, what requires approval, and what requires human oversight.
But as the tools being used progress from writing, summarizing and searching to performing actions, managing processes and making decisions, another question arises:
Human oversight addresses questions such as who reviews, who approves, and when intervention is required. It does not necessarily answer an earlier question: what judgment should a system acting on behalf of the organization apply in the first place?
As AI agents are given greater autonomy, it may no longer be enough to define what is permitted and what is prohibited. Organizations may also need to consider how to make explicit considerations that were previously applied intuitively by employees and managers: What level of risk is acceptable? How should exceptions be handled? When is escalation required? What constitutes an acceptable standard of quality?
Similar questions are at the center of the emerging discussion around codifying judgment in organizations using AI agents.
The discussion is beginning to move from the question of how to govern the use of AI to how to govern the judgment delegated to it. In a June article published in Harvard Business Review, Teach Your AI How You Make Decisions, Jen Stave, Ryan Kurt and John Winsor argue that as AI agents are given more complex work, organizations need to make their decision-making processes more explicit.
The next stage of AI governance may therefore not be another provision in an AI policy, but an additional layer of governance: defining the judgment an organization is prepared to delegate to a system, the boundaries of that judgment, and the points at which the decision must return to a human.
A working document — not legal advice. Use alongside counsel.
A working document — not legal advice. Use alongside counsel.
