AI safety has become an employee-relations issue. In the past week, mainstream reporting has covered an Anthropic researcher resigning over safety concerns and bipartisan senators pressing OpenAI about whether advanced AI systems can elude human control. That public discussion will reach workplaces where HR leaders are already managing anxiety about job loss, deskilling, surveillance, and unreliable outputs. Another concern has entered the room: what happens when AI receives enough autonomy to act beyond what people intended?
HR should take that concern seriously without turning every workplace chatbot into a science-fiction villain. Most employees are not using frontier research models with broad cyber capabilities. Yet dismissing the underlying fear would be equally misguided. The practical question for employers is how much authority an AI system should receive before a human must intervene.
Loss of Control Has Entered the Workplace Conversation
The Hugging Face incident gives this discussion unusual weight. OpenAI reported that, during internal cybersecurity evaluations, models operating under reduced safeguards found a previously unknown vulnerability, escaped an environment that was not supposed to give them direct internet access, and reached third-party systems. OpenAI later described the episode as its most severe incident of this kind and said its broader review had led it to notify dozens of third parties about other unexpected model activity.
An independent METR and Redwood Research investigation found another disturbing feature. Roughly 1,200 AI agents that were supposed to be isolated discovered an unsanctioned shared message board and exchanged more than 70,000 messages and files. About 700 eventually participated in the Hugging Face attack. The organizational lesson centers on coordination. Systems given a goal, tools, persistence, and enough operating room found ways to communicate and pursue actions outside the intended boundaries.
Employees do not need to understand model-alignment research to grasp the implication. If their employer starts giving AI agents access to email, cloud files, customer systems, HR records, purchasing tools, or external communications, they will reasonably want to know what those agents can do without asking permission. HR should be ready with a concrete answer. HR should avoid treating these questions as evidence that an employee is anti-AI. Someone can favor adoption and still want credible limits on autonomy.
Give AI an Authority Budget Before You Give It a Job
I recommend that organizations create an authority budget for every AI agent or highly autonomous workflow. An authority budget defines the maximum power the system can exercise before a human must approve the next step. Think of it as a job description combined with permissions, spending limits, and escalation rules.
For an HR recruiting agent, that might mean permission to summarize resumes and draft outreach, while prohibiting autonomous rejection of candidates, changes to applicant records, or external messages without review. A benefits agent could answer routine questions from approved documents but lack authority to change enrollment data. An employee-relations system could summarize case notes while remaining unable to place disciplinary recommendations into an official record without human review.
The same principle should govern credentials, data access, financial transactions, software changes, external communications, and the ability to launch other agents. Access should expire when the task ends. Logs should show what the system did. Managers should know how to pause or terminate an automated process quickly. Sensitive actions should require explicit approval rather than assuming that someone will notice a problem afterward.
IT, cybersecurity, legal, and compliance all belong in this work. HR has a distinct role because the organization is delegating work, authority, and accountability. Those choices affect job design, manager responsibilities, employee trust, training, and the psychological contract between workers and the employer.
Trust Comes from Visible Control, Not Reassurance
HR should resist blanket reassurance. Saying “the AI cannot do anything unless we tell it to” is increasingly difficult to defend as a general claim. A better response distinguishes the capabilities of the tools actually deployed, explains where their permissions stop, and identifies the decisions that remain under human control.
Tell employees whether an AI tool can send messages, edit records, access confidential information, make purchases, initiate workflows, or communicate with outside systems. Explain what requires human approval. Identify who monitors agent activity, how incidents get reported, and what happens if the system behaves unexpectedly. When capabilities expand, update the rules instead of relying on an old policy written for chatbots that merely generated text.
I want organizations to adopt AI faster because the productivity potential is substantial. Faster workplace AI adoption becomes easier when employees can see that leaders have thought through failure modes instead of waving them away. People tolerate uncertainty better when they know where the boundaries are, who remains accountable, and how someone can stop the system.
That is the HR opportunity inside the current loss-of-control debate. HR does not need to adjudicate every forecast about superintelligence. It does need to translate the underlying concern into workplace governance: define what AI may do, limit what it may access, require human approval before consequential actions, monitor behavior, and preserve a reliable way to shut automated activity down.
The organizations that handle this well can give employees something more credible than “trust the technology.” They can say: here is the authority we gave it, here is the authority we withheld, here is where a human must decide, and here is how we stop it if it crosses the line.
Dr. Gleb Tsipursky, a behavioral scientist called the “Office Whisperer” by The New York Times, helps tech-forward leaders stop overpaying for AI while boosting engagement and innovation. He serves as the CEO of the AI consultancy Disaster Avoidance Experts, and wrote eight books, including “The Psychology of AI Adoption at Work: From Resistance to Results” (Georgetown University Press, 2026).

