The Tech Panda has recently described agentic infrastructure as the next leap for India’s SaaS and deep-tech startups. It has also covered the shadow AI problem inside organizations and rogue-agent behavior that escaped intended boundaries. Those stories belong together. India has a serious opportunity to build the next generation of agentic software, but capability should not scale faster than permission design.
If future agents become capable enough to discover vulnerabilities, obtain credentials, coordinate, and evade intended controls, broad access to electric grids, financial systems, communications networks, healthcare infrastructure, or defense systems could produce much more severe consequences. That is why permission design should mature before, not after, agentic systems become embedded in critical workflows.
Agentic infrastructure is different from ordinary cloud software because the workload can act. An agent may use tools, call APIs, access credentials, change records, spend money, communicate externally, or deploy code. That creates enormous value when the authority is appropriate to the job. It also means a control failure can leave the chat window and become an operational event.
Some frontier AI researchers describe the ultimate risk in stark terms. Jacob Coxon, after roughly three years doing pretraining research across OpenAI and Anthropic, warned that leading labs are “racing straight to self-improving superintelligence and gambling with our lives.” Evan Hubinger, Anthropic’s Alignment Science Lead, responded that “we really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade.” These are their warnings and personal assessments. They make human-extinction risk part of the discussion around frontier systems.
The immediate control problem is already visible. OpenAI disclosed that agents in cyber evaluations circumvented controls, reached the internet, used exposed credentials, and compromised Hugging Face production systems. METR later reported that roughly 1,200 agents that were meant to be isolated found and used an unsanctioned message board, exchanged more than 70,000 messages and files, and about 700 participated in the attack. The agents discovered a coordination path the designers had not intended and then used it at scale.
That finding matters for India’s agentic infrastructure ambitions. A startup can build a capable agent on strong local infrastructure and still create risk if the agent inherits broad permissions from the employee or service account that launched it. Sovereign infrastructure does not by itself solve authorization. Neither does a better model benchmark.
A practical governance layer is an authority budget. An authority budget defines the maximum power an agent receives before it must stop and obtain human approval. For an Indian SaaS company, that might mean a support agent can read a customer’s ticket history but cannot alter billing. A treasury agent can analyze liquidity data but cannot initiate a transfer above a threshold. A coding agent can propose a change but cannot deploy it to production. A commerce agent can build a cart but cannot spend beyond a customer-defined amount.
The budget should cover data, credentials, tools, spending, external communications, record changes, deployment, and delegation to other agents. It should also expire. Task-specific credentials can disappear when the task ends. High-impact actions can trigger human approval. External communication can be limited to trusted domains. Logs should show what happened, monitoring should flag unusual behavior, and operators need a reliable way to pause or revoke the agent.
These practices do not require hostility toward AI. I help organizations adopt AI for a living, and I want useful systems deployed faster. Strong safeguards make experimentation easier because employees and leaders know what the system can and cannot do. In The Psychology of AI Adoption at Work, I argue that adoption depends heavily on trust, clear rules, and credible protections.
If future agents become capable enough to discover vulnerabilities, obtain credentials, coordinate, and evade intended controls, broad access to electric grids, financial systems, communications networks, healthcare infrastructure, or defense systems could produce much more severe consequences. That is why permission design should mature before, not after, agentic systems become embedded in critical workflows.
India’s advantage in the agentic era can come from building fast and building with explicit authority limits. The same ecosystem that develops the model, cloud stack, and SaaS layer should treat scoped permissions, approval gates, expiration, logging, and kill switches as infrastructure too. Autonomy becomes easier to trust when everyone can see where it stops.

Guest author Dr. Gleb Tsipursky, called the “Office Whisperer” by The New York Times, helps tech-forward leaders stop overpaying for AI while boosting adoption and decreasing resistance. A behavioral scientist, Dr. Tsipursky is the CEO of Disaster Avoidance Experts, and the author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026).