⚡ Quick Summary
Published by the World Economic Forum in collaboration with Capgemini, this insight report is the third and final paper in a three-part series on AI agents. It introduces the Agent Capability and Authorization Profile (ACAP) as a deployment-level authorization instrument that connects enterprise delegation policy, system design and operational oversight in a single repeatable workflow. Its central claim is that authorization, not capability, is now the critical bottleneck for adoption.
The playbook has three building blocks: agent guidelines that define enterprise policy for delegated agency, enforceable authorization profiles, and a phased adoption life cycle from pilot to scale. Chapter 1 sets out shared terminology for autonomy, authority, consequential events, operational context and boundaries, allocates decision rights, defines deployment context tiers and covers the human–agent operating model. Chapter 2 details the ACAP, maintained as a living document with seven sections (A–G), through three phases — system design and assessment, prepare and deploy, and monitor and improve — each ending in a phase gate. An appendix provides a summary playbook and an execution framework table naming actions, owners and evidence.
🧩 What’s Covered
The report moves from enterprise policy to deployment-level authorization.
- Foreword and executive summary: frames the gap between what agents can do and what they are authorized to do, and notes that because many agents share a foundation model, a single model-level vulnerability can propagate across an entire agent estate.
- Agent guidelines (Chapter 1): defines shared terms (autonomy, authority, consequential events, operational context, boundaries) and allocates decision rights across adopters, developers, subject matter experts, risk and legal functions, supervisors and HR; sets deployment criteria distinguishing agents from pre-scripted automation; covers sequencing of early use cases.
- Deployment contexts (sections 1.5, 1.6): three context tiers — single-organization, multi-organization single-platform, and multi-platform cross-boundary — plus supervision limits such as attention fatigue, automation bias and the "supervision paradox".
- The ACAP (Chapter 2): seven sections A–G covering identity and scope, operating context, authority and consequential events, controls and enforcement, evaluation evidence and promotion gates, monitoring and change log, and sign-offs and re-authorization cadence; contrasted with model cards, system cards and agent cards.
- Phase 1 – system design and assessment (2.2): role and context definition, architectural specification (orchestration, tool boundaries, memory, logging, fail-safes), risk and impact classification aligned to the enterprise risk taxonomy, and governance decisions including the consequential events register.
- Phase 2 – prepare and deploy (2.3): implementing non-bypassable controls, sandbox validation with adversarial and edge-case testing, naming production roles, and the transition to live operation.
- Phase 3 – monitor and improve (2.4): production observation, drift and insider-threat signals, the improvement plan, controlled change to sections C–E and G, and decommissioning.
- Appendix and endnotes: Figure 6 end-to-end life cycle, Table 2 execution framework with completion criteria, primary owners and evidence, and 31 endnote references.
💡 Why it matters?
Organizations can often describe what an agent is capable of but lack a consistent way to decide what it is authorized to do in a specific workflow. The ACAP gives governance, risk, engineering and audit functions a shared artefact for that decision: scope, authority, checkpoints, evidence and accountable owners in one record, with phase gates that make release conditional on defined criteria and promotion gates that tie authority expansion to evidence. It is designed to operate within existing risk management practice — the report names ISO 42001, the NIST AI RMF and the Agentic AI Risk-Management Standards Profile — and notes that modular sections can supply documented evidence of human oversight under Article 14 of the EU AI Act.
❓ What’s Missing
The playbook presents itself as an early contribution that will require revision as the technology matures, and states that it does not offer universal answers. It does not define a universal conflict resolution mechanism for cases where agents from different organizations operate under misaligned authorization models. Its treatment of agent identity, discovery protocols and the proposed "agent passport" is descriptive and forward-looking. The ACAP is not yet machine-readable policy-as-code; that evolution is described as an ambition. Risk tiers, thresholds and evaluation criteria are left for each organization to set, so no completed, filled-in ACAP example appears, and no jurisdiction-specific legal analysis is provided.
👥 Best For
Deployment owners and adoption leads defining an agent's mandate before production; risk, compliance and legal teams mapping agent authorization onto an existing enterprise risk taxonomy; engineering and platform teams implementing enforceable controls, IAM scoping and monitoring; subject matter experts and supervisors who interpret behavioural signals; and auditors seeking versioned evidence of delegated authority.
📄 Source Details
AI Agents in Action: A Playbook for Trusted Adoption, Authorization and Scaling, an insight report published by the World Economic Forum in collaboration with Capgemini, dated May 2026. It is the third in a three-part series on AI agents and runs to 38 pages. The foreword is signed by Volker Darius (Capgemini Invent), Cathy Li and Stephan Mergenthaler (World Economic Forum); a contributors section lists working group participants and production staff. The text extraction covered all 38 pages. No URL for this document itself is printed in it.