> 

Governed Agentic AI in Energy Trading: How Much Authority Should an AI Agent Have?

In an earlier MidDel article, From Generative AI to Agentic AI: The Next Evolution in Energy Trading Strategy, we explored the transition from AI that responds to a request to AI that can monitor conditions, coordinate multi-step workflows and take action toward a defined objective.

That evolution raises a more difficult question:

Just because an AI agent can take an action, should it be allowed to?

Consider some potential applications across energy trading and control functions.

An AI agent might continuously monitor counterparty credit exposure and recommend a change to a credit limit.

Another might identify an upcoming collateral requirement, assemble the necessary information and initiate a margin workflow.

Another could review a settlement discrepancy, gather supporting evidence and prepare a dispute.

Another might identify a journal entry that should be recorded based on a recurring transaction pattern.

And, eventually, an agent may be capable of executing some of these actions without waiting for a person to initiate each step.

The technology question is increasingly becoming manageable.

The question of governance is how much authority to give it.

That decision should not be binary (e.g., human or autonomous). There is a spectrum of authority between an AI that simply observes activity and one that is permitted to execute actions independently.

For energy companies adopting agentic AI, defining that spectrum may be one of the most important elements of AI governance.

From AI Assistant to AI Actor

Much of the early enterprise use of generative AI has been advisory.

A user asks a question. The AI analyzes information and produces an answer, summary or recommendation. A human remains responsible for deciding what to do next.

Agentic AI changes that model.

An agent can potentially monitor systems continuously, recognize that something requires attention, gather additional information, interact with applications, initiate workflows and take prescribed actions.

That is what makes agentic AI powerful.

It is also what makes governance more important.

In energy trading, an incorrect summary is fundamentally different from an incorrect collateral posting, credit decision, journal entry or trade.

The level of governance should therefore increase as the authority and potential impact of the agent increase.

A useful framework is to think about AI authority through six levels:

Not every agent should progress through all six.

In fact, for many important decisions, the right end state may deliberately remain somewhere in the middle.

Level 1: Observe

At the lowest level of authority, the agent monitors information but does not make decisions or initiate activity.

For example, an agent could continuously monitor:

  • counterparty exposure;
  • collateral utilization;
  • trading limits;
  • settlement status;
  • contract obligations;
  • market and credit indicators; or
  • changes in positions and valuations.

The objective is awareness.

Instead of requiring an analyst to repeatedly check multiple systems, reports or spreadsheets, the agent watches the relevant information continuously.

At this level, the agent is essentially another set of eyes.

The governance risk is comparatively low because the agent is not yet changing data, initiating transactions or making a decision on behalf of the organization.

But even observation requires controls.

What systems can the agent access? What data is it permitted to see? Are entitlements aligned with the person's or function's authority? Is every access logged?

Governance starts before an agent ever takes an action.

Level 2: Analyze

The next level allows the agent to interpret what it observes.

Instead of merely detecting that collateral requirements changed, for example, it might determine:

  • what caused the change;
  • which positions or counterparties contributed;
  • whether the movement is consistent with expected exposure;
  • whether available collateral is sufficient; and
  • whether the situation falls outside normal parameters.

The agent may combine information from an ETRM, credit platform, market data, contracts, forecasts or financial systems to provide context that would otherwise require a person to assemble manually.

This is where agentic AI begins to move beyond conventional alerts.

Traditional systems are often very good at telling us that a threshold was crossed.

AI can potentially help answer the next question:

Why?

But analysis still does not mean authority.

The agent is developing information for a human decision-maker, not making the decision itself.

Level 3: Recommend

At the recommendation level, the agent goes one step further:

Given what I have observed and analyzed, here is what I believe you should do.

Consider credit risk.

A Credit Agent might assemble current exposure, financial information, payment history, market indicators and internal risk flags, then recommend a credit limit for review.

In the governed-AI framework HOC and MidDel are developing for risk and control functions, the recommendation is accompanied by a traceable rationale so the credit professional can review the information and exercise independent judgment.

The distinction is important.

The AI may substantially reduce the work required to prepare a decision without assuming responsibility for the decision itself.

That model can be particularly effective when the decision is material, judgment-intensive or subject to independent control.

Level 4: Prepare

At this stage, an agent is authorized not only to recommend an action but to prepare the workflow needed to execute it.

For example:

Settlement dispute: Identify the exception → investigate likely cause → gather trades, positions and settlement evidence → prepare supporting documentation → draft counterparty communication.

Margin call: Calculate the requirement → validate relevant positions → prepare the call → create supporting information → route it to an authorized reviewer.

Journal entry: Identify the transaction → determine the applicable accounting treatment → prepare the proposed entry → validate the accounts → route it for approval.

This can eliminate a substantial amount of routine processing while preserving an important control:

The agent prepares. The authorized person approves.

A margin or settlement dispute-management example would follow this model by having AI compile evidence and support structured communications while preserving a complete audit trail.

This level may ultimately represent one of the highest-value applications of agentic AI in risk, credit and back-office functions.

AI handles the repetitive work required to get a decision ready.

People retain the judgment required to make it.

Level 5: Act With Approval

The next step is meaningful.

The agent is allowed to take action, but only after an authorized person approves it.

A collateral workflow illustrates the concept well.

An agent might calculate a margin requirement, determine the appropriate collateral source, prepare the posting and present the proposed action to the treasury or credit professional.

Once the human approves, the agent executes the operational steps.

The governed-AI use cases we are working with deliberately place human approval gates around material collateral actions.

The human is no longer performing every step of the process.

But the human still controls the decision point.

This is an important distinction because human-in-the-loop should not mean humans manually redo the AI's work.

If an experienced credit, risk or treasury professional must recreate the entire analysis before approving an action, much of the potential benefit disappears.

Instead, good design should give the reviewer the information required to challenge the recommendation efficiently:

  • what happened;
  • why it matters;
  • what information the agent considered;
  • what action it recommends;
  • what policy or mandate applies;
  • what exceptions were identified; and
  • what will happen if the reviewer approves.

The human's role becomes challenge and authorization, not repetitive processing.

Level 6: Act Autonomously Within Mandate

The highest level of authority does not need to mean unrestricted autonomy.

A better model is bounded autonomy.

The organization establishes a defined mandate within which an agent may act independently.

That mandate might specify:

  • permitted actions;
  • approved systems and data;
  • monetary or exposure thresholds;
  • counterparties;
  • products;
  • confidence requirements;
  • time windows;
  • escalation conditions;
  • exception criteria; and
  • circumstances in which human approval becomes mandatory.

Within those boundaries, the agent can act.

Outside them, it stops and escalates.

This distinction becomes increasingly important as financial infrastructure itself becomes more programmable. In January 2026, CFTC Chairman Michael S. Selig discussed the possibility of AI-driven systems and autonomous software interacting directly with tokenized collateral, monitoring risk and executing predefined strategies within established guardrails. He noted that those remarks represented his own views rather than necessarily those of the Commission.

The concept is instructive, well beyond tokenized collateral:

Autonomy should come with a mandate, not a blank check.

How Do You Decide the Right Level of Authority?

There is no single answer for every agent or workflow.

A useful starting point is to evaluate six factors:

Materiality

How significant is the potential financial or operational impact?

An agent correcting a low-risk reference-data exception is different from one moving millions of dollars of collateral or approving a large counterparty limit.

As materiality increases, so should approval requirements.

Reversibility

If the agent is wrong, how easily can the action be reversed?

Preparing an email draft is readily reversible.

Sending a payment, submitting a market transaction or making a regulatory filing may not be.

Irreversible or difficult-to-reverse actions warrant stronger controls.

Risk

What could go wrong?

Consider financial loss, credit exposure, operational disruption, compliance breaches, inaccurate financial reporting and reputational impact.

The downside warrants consideration as much as the potential efficiency gain.

Regulatory and Control Implications

Does the activity sit within a regulated process, independent risk function, accounting control or segregation-of-duties requirement?

AI does not eliminate those obligations.

In December 2024, CFTC staff issued an advisory reminding CFTC-regulated entities that their existing obligations under the Commodity Exchange Act and CFTC regulations continue to apply as they implement AI.

Similarly, a 2025 CFTC Commissioner summary of regulatory roundtables reported growing AI adoption in trading, risk management, surveillance and compliance, while identifying explainability and governance as important emerging risks. Participants also emphasized post-deployment monitoring and testing.

Technology reliance and degree of automation may change, but the organization's accountability does not disappear with it.

Confidence

How reliable is the agent for this specific task?

Confidence should be evaluated in context rather than assigned to AI generically.

An agent may perform extremely well classifying routine reconciliation breaks and significantly less reliably interpreting a bespoke agreement if not trained in such.

Governance should account for those differences.

Defined Authority

Finally:

Would we clearly delegate this authority to a person in this role?

If the organization cannot define the authority, thresholds and escalation rules for a human, it probably should not delegate them to an AI agent.

This is one of the simplest tests of good agent governance.

Governance Must Be Built into the Agent

Once organizations start allowing AI to take action, governance cannot simply be a policy document sitting outside the technology.

Governance and Control has to be operationalized.

The governed AI model we are using includes several foundational controls.

Role-Based Access Controls

Agents should have only the data and functional permissions required for their assigned task.

Least privilege applies to AI just as it does to people and applications.

Decision Traceability

A material AI-assisted decision should be re-constructable.

Organizations should be able to determine what information was used, which model and version were involved, what policy or mandate applied, what action was recommended or taken and where human approval or escalation occurred.

Human Approval Workflows

Material actions should have explicit approval requirements rather than relying on informal review.

The approval point should be designed into the workflow.

Agent Versioning

Agents will change.

Models, prompts, tools, policies and business rules will evolve over time.

Organizations therefore need controlled deployment, testing, version identification and the ability to roll back changes when appropriate.

Audit Logging

Interactions with data, systems, approvals, overrides, exceptions and actions should be logged at the appropriate level for the business process.

Environment Segregation

AI agents should operate within defined environments and technical boundaries, with appropriate separation between development, testing and production and controlled access to enterprise systems.

These principles align with the broader direction of AI risk management. NIST's voluntary AI Risk Management Framework organizes AI risk management around four functions -- Govern, Map, Measure and Manage -- and treats governance as a cross-cutting function rather than something added after an AI system is deployed.

The Goal Is Not Maximum Autonomy

There can be a tendency to evaluate agentic AI by asking:

How much can we automate?

I think the better question is:

What level of autonomy creates the most value while preserving appropriate control?

For one workflow, the right answer may be observation and analysis.

For another, AI may make a recommendation.

For another, it may prepare the entire action for a human to approve.

And for a well-understood, low-risk, bounded process, the right answer may eventually be autonomous execution within a clearly defined mandate.

The most advanced AI implementation is not necessarily the one with the fewest humans involved.

It is the one that assigns work intelligently between people and agents.

Stronger Controls, Not Weaker Ones

The central premise behind governed AI is that organizations should not have to choose between efficiency and control.

Properly designed agents can continuously monitor activities that people currently review periodically. They can document routine processes consistently, prepare evidence before an exception reaches a reviewer, enforce defined workflows and create a record of actions and approvals.

That creates the possibility of strengthening governance and control beyond what was practical with manual processes alone.

At the same time, some things should not change and remain important.

  • Independent challenge
  • Segregation of Duties
  • Auditability
  • Accountability for exceptions and overrides
  • Human oversight

What changes is how those controls are executed.

Agentic AI allows routine monitoring, evidence gathering and workflow execution to move increasingly to machines, while experienced professionals concentrate on exceptions, judgment and high-impact decisions.

That is a more useful vision of agentic AI than simply removing people from processes.

Start by Defining the Mandate

As energy companies move from AI experimentation toward agentic workflows, one of the first design decisions should therefore be:

What is this agent authorized to do?

Not just:

What is it technically capable of doing?

For every agent, define the mandate, data access, authority level, materiality thresholds, approval requirements and escalation rules before giving it production access.

Then increase authority as the use case, controls and performance justify it.

That progression gives organizations a practical way to capture the benefits of agentic AI without treating autonomy as an all-or-nothing decision.

The future of AI in energy trading will not be determined simply by how intelligent agents become.

It will also depend on how intelligently we govern them.

If your organization is evaluating agentic AI for trading, risk, credit, collateral, settlements or accounting, MidDel Consulting and HOC can help identify high-value use cases and design governed workflows that align agent authority with your existing risk and control framework.