Skip to Content

The Loop Asia

Insights

Analysis and commentary from The Loop Asia — AI, APIs, and technology leadership across Asia-Pacific.

Thanks for subscribing!

No spam. Unsubscribe any time.

The agency question nobody's put on a board slide yet

An AI Gateway can now judge intent on both sides of a transaction. What's missing isn't the capability to act — it's who's decided how much of it gets to act alone.
June 22, 2025 by
The agency question nobody's put on a board slide yet
Jon Scheele

This deep dive expands on the Loop Asia conversation with Buu Lam, Director of Community Evangelism at F5, recorded at F5 AppWorld in Singapore.


Buu Lam said something during our F5 AppWorld conversation that I keep coming back to — it's a governance problem dressed up as a technical one. Imagine your AI Gateway flags a transaction flow — real money, millions of dollars — as suspicious. Do you let the system stop it automatically?

"How comfortable are we with that level of agency where we need to invoke a human?" Buu's own answer: a human should decide whether to pull the plug on a million-dollar flow. I agree with the instinct. But "invoke a human" is doing a lot of quiet work in that sentence — worth pulling apart before it becomes an incident report.

"Invoke a human" is not a control, it's a placeholder

Every organisation deploying AI-adjacent security tooling has, functionally, already answered Buu's question — they just haven't written it down. Somewhere in a config file there's a threshold for when the system acts alone versus when it waits for a person, and nobody chose it deliberately. It arrived as the vendor's default, or whatever the integration engineer set under deadline pressure. That's fine until the auto-approved flag — no time to page anyone — turns out to have mattered. Then the question isn't why the AI made a mistake, it's who decided it could make that call alone. That's a governance failure, not a model failure, and it lands on whoever owns AI risk — often an underspecified job.

If you signed off on an AI deployment, have this conversation before the tooling goes live: who gets paged, what's the response time, and whether the flow proceeds or fails closed if nobody answers. None of that is a technical decision. It's an accountability decision technical people are currently making by default, because nobody senior enough has claimed it.

Building the escalation framework, not just the gateway

Organisations handling this well treat "human in the loop" as an operating design, not a checkbox: a named role — a specific person or rotation, reachable and empowered to act, not "engineering" as an abstraction — explicit thresholds tied to business impact rather than the vendor's default sensitivity setting quietly defining your risk appetite, and a decision made in advance about what happens when escalation times out. "Wait for a human" without a fallback is itself a decision, usually the wrong one, made by omission.

This is exactly the gap under Blue Connector's Trigger Type 3 — a board mandate to deploy AI with no clear owner of the governance that makes it safe to operate. The technology, in Buu's telling, can genuinely judge intent on both sides of an exchange. What's missing isn't the capability. It's the org chart line that says whose job it is to decide how much of it gets to act alone — a business-and-technology call, not the vendor's and not engineering's alone. Get it wrong quietly, and you'll find out when the flow that mattered didn't get stopped, or the one that didn't matter did.


Deploying AI with no named owner for when it should — and shouldn't — act alone?

Building the escalation framework — who's paged, what the threshold is, what happens on timeout — before the tooling goes live is exactly the governance conversation I help leaders have.

See how I can help →