White paper

Why does trust, not intelligence, decide AI at work?

Once AI can act, the main risk moves from a wrong answer to a wrong action. Most agent projects that fail do so on cost, unclear value and weak risk controls, which are control problems and not model problems. Accountable autonomy is the design answer: a person approves what matters, every action is recorded, cost is known before it is spent, and the product says plainly what is real.

  • Sourced
  • Updated 1 Oct 2026

Request early access

In 30 seconds

The argument

AI now acts

The risk moves from wrong answers to wrong actions.

Projects fail on control

Cost, value and risk, not model quality.

Accountable autonomy

A person decides, every action is recorded, cost is known.

From answers to actions

For the first wave of workplace AI, the output was text. A person read it, decided whether it was right, and copied what they wanted into the real system. The person was the control, whether or not anyone called it that.

Agents remove that step. When an AI can call a tool, it can act on its own output: send the email, update the record, post the alert. Every one of those touches a customer, a record or a budget. The question leaders ask changes from "can it do this?" to "can I trust it to?"

Why agent projects stall

40%+

of agentic AI projects predicted to be canceled by the end of 2027, citing cost, unclear value and weak risk controls.

Source: Gartner, June 2025

82%

of surveyed enterprises reported AI agents running in their environment that they did not know about.

Source: Cloud Security Alliance survey, commissioned by a security vendor, April 2026. 418 IT and security professionals

The reasons given for cancellation are escalating costs, unclear business value and inadequate risk controls. None is a model-quality problem. Each is a question of control:

  • Cost becomes a problem when nobody can see or cap what the AI spends before it spends it.
  • Value stays unclear when there is no record of what the AI actually did.
  • Risk is unmanaged when an AI can act in customer-facing systems without a person deciding.

Five principles

  1. A person decides. Actions with consequences outside the system wait for a named approver by default. Routine work can run on its own once a team allows it, one step at a time.
  2. Show the work. Every run, change and approval can be traced to who, what, when and why, in a record that cannot be edited after the fact.
  3. Cost in the open. The customer can see and cap what AI work will cost before it happens, in units a business can plan with.
  4. Say what is real. Every screen, number and claim states whether it is live, sample or planned.
  5. Work with what they have. Join the existing tools instead of replacing them, and let people leave with their data.

A reference design

Principles only count if the design enforces them. This is the path every AI action takes, enforced on the server so a change in the interface cannot bypass it.

The path every AI action takes An agent proposes an action. Policy decides. Low-risk actions run in the connected system. High-risk actions wait for a named person. Prohibited actions are blocked. Every outcome goes on the record. low risk Agentproposes an action Policylimits, risk, budget Connected systemthe action runs Recordwho, what, cost Named approverhigh risk: a person decides Blockedprohibited, still recorded
  1. 1Agent proposes an actionFor example, send a follow-up email.
  2. 2Policy decidesChecks the agent's limits, risk and budget.
  3. 3Run, ask or blockLow risk runs. High risk waits for a named approver. Prohibited is blocked.
  4. 4RecordedWho, what, when, approver and cost go on the record.
The reference design: the route every action takes, enforced on the server.
ControlWhat it preventsMFDIO today
Approval by defaultAn AI emailing a customer or changing a record uncheckedEmail, chat and connected-system writes wait for a named approver Today
Emergency stopA runaway processAn Owner or Admin pauses all AI work Today
Spend limitsA surprise billWarn, ask or stop; overage off by default Today
Append-only record"Who did this?" with no answerEvery change, approval and run recorded with who and when Today
Separation between organizationsOne customer seeing another's dataEach organization's data is kept apart Today
Policy for agents built elsewhereUnmanaged agents outside the platformAgents built outside MFDIO in the register Roadmap

Cost you can plan

Raw usage prices change often and mean little to a finance lead. MFDIO measures AI work in Work Units: one stable meter for a business to plan with, while the real provider cost is tracked underneath. Every charge is recorded per action so it can be explained line by line.

Honesty as a property of the system

Many AI products are demonstrated on sample data that looks real. That is harmless in a demo and damaging in production, where a leader may act on a number that was never measured. Treat honesty as something the system enforces: label sample data where it appears, hide screens that depend on data that is not connected yet, and show a failed AI call as a failure.

What to ask any vendor

The buyer's checklist turns these ideas into ten questions. Ask them of MFDIO too.

Limits of this paper

MFDIO is in invite-only early access and is pre-revenue. Some capabilities are on the roadmap and labeled as such; see what works today. MFDIO does not hold SOC 2 or ISO 27001 today. Market figures are analyst or survey estimates and vary between sources. The benefits described are design goals until pilots confirm them.

Sources

  1. Cloud Security Alliance, "Autonomous but Not Controlled: AI Agent Incidents Now Common in Enterprises", 21 April 2026 (418 IT and security professionals; commissioned by a security vendor)
  2. Gartner, June 2025: over 40% of agentic AI projects predicted to be canceled by the end of 2027; a third of enterprise software to include agentic AI by 2028
  3. MFDIO product facts: checked against the product on 1 October 2026

Published . Last updated . Written by the MFDIO team.

Put the argument to work

Early access is invite-only.

Request early access