AI agents can increasingly act in roles that were previously performed by people, including searching, evaluating options, making or recommending decisions, communicating, negotiating, booking, purchasing and taking other actions on behalf of an individual or organisation. This changes the nature of AI governance because an AI system may no longer simply produce an output for a person to consider; it may exercise delegated authority and act within a business or transactional environment.
Hospitality organisations therefore need to govern both AI agents acting on their behalf and AI agents acting on behalf of guests, partners, vendors or other external parties. An organisation's own agents may interact directly with people, systems, vendors and other AI agents, while external agents may interact with the organisation's booking, pricing, service or other operational systems as a substitute for human decision-making.
Organisations should establish clear governance over agent identity, delegated authority, permissions, boundaries, actions and accountability, including how authority is granted, limited, monitored and withdrawn. Where agents interact with other agents or automated systems, the organisation should ensure that identity and authority remain attributable and that an agent cannot acquire greater authority merely through delegation or interaction with another agent. AI-to-AI interaction should therefore remain within defined governance boundaries, with appropriate mechanisms to detect unexpected behaviour, escalate decisions, require human intervention where necessary, and interrupt or stop agent activity that exceeds its authorised role.
The fundamental governance question is not simply what an AI agent can do, but what it has been authorised to do, on whose behalf, within what boundaries, and with what consequences if it acts incorrectly.
Source: Singapore IMDA Model AI Governance Framework for Agentic AI — reference 9 →