The AI Tiger
When the Tiger Learns to Hunt

AI is moving from answering questions to taking actions.
In Part 1, we asked whether the AI Tiger had already been released. In Part 2, we looked at why nobody seems able to slow it down. In Part 3, we followed the money — GPUs, data centers, energy, capital, governments — and saw how the ecosystem continues to feed the Tiger.
Now we reach a different stage. The Tiger is learning to hunt.
For years, AI was largely an observer. You asked a question, it generated an answer. You gave it a document, it summarized it. You gave it a prompt, it created something. Humans still decided what happened next.
That boundary is beginning to disappear. The new generation of AI systems can increasingly plan, reason, use tools, browse the internet, write and execute code, access enterprise systems, delegate tasks, interact with other agents, monitor outcomes, and take corrective action. The difference may look subtle. Economically and strategically, it is enormous. AI is moving from intelligence-as-a-service to action-as-a-service.
The moment AI stops waiting
Consider the difference. Old AI: you ask it to analyze 500 customer complaints, it gives you the analysis, and you decide what to do. Agentic AI: you tell it to reduce customer churn by 10%, and the agent might analyze customer behavior, identify high-risk customers, examine previous interactions, create retention offers, contact customers, monitor responses, update the CRM, escalate unusual cases, and measure the result — on its own.
The human didn't specify every step. The human specified the objective. That is the fundamental change.
OpenAI's latest enterprise research describes this shift explicitly: organizations are moving from assistance to delegation and execution, with agents increasingly performing multi-step work using tools and computer access. And this isn't restricted to software engineering — agents are spreading into sales, recruiting, marketing, legal work, and other knowledge-intensive functions.
The question therefore changes. We are no longer asking "what can AI tell me?" We are beginning to ask "what can I allow AI to do?"
From tool to worker
This is where my thinking from the AI Organization series intersects with the AI Tiger. A traditional software application is a tool — a human tells it what to do. An AI agent is different. You can give it an objective, a role, access to tools, a set of permissions, a time horizon, and potentially, autonomy. That begins to look remarkably similar to a worker.
Consider an AI procurement agent. You tell it to reduce cloud costs by 15% without affecting production. It could inspect usage, compare providers, identify unused resources, negotiate or recommend contracts, change configurations, monitor the results, and report back.
Now ask yourself: is that software? Or is it a digital employee?
The next step is not one agent
One agent is interesting. A network of agents could be transformative. Imagine a sales agent that qualifies an opportunity, hands off to a research agent that analyzes the customer, which hands off to a proposal agent that creates a solution, a pricing agent that optimizes the commercial model, a legal agent that reviews the contract, a delivery agent that creates the implementation plan, a finance agent that tracks profitability, and a customer success agent that monitors outcomes.
None of these agents needs to be the "superintelligence." They simply need to be good at their individual jobs, and they need to communicate. That is already becoming a technical direction — the emerging Agent2Agent (A2A) standard is explicitly designed to allow independent AI agents to discover each other, delegate tasks, and exchange results.
That could create something fundamentally different from today's enterprise software. Not applications — a workforce of interacting digital actors.
The enterprise could become a machine of agents
Imagine a company ten years from now. Instead of hundreds of applications waiting for employees to operate them, you could have hundreds or thousands of specialized agents continuously operating across the business. A customer submits an enquiry. An agent responds. Another checks inventory. Another calculates pricing. Another checks credit. Another prepares the proposal, negotiates, schedules delivery, monitors payment, predicts whether the customer is likely to leave. Humans intervene only when something falls outside predefined boundaries.
That is not automation in the traditional sense. It is something closer to autonomous enterprise execution — and it's why agentic AI could be far more disruptive than chatbots. A chatbot changes how humans interact with software. Agents can change who performs the work.
But then comes the dangerous part
Giving an AI access to information is one thing. Giving it the ability to act is another.
Imagine an AI with access to your email, your CRM, your bank account, your cloud infrastructure, your source code, your production systems, your contracts, your customer database — and imagine it can execute actions without asking you every time. The system becomes extraordinarily useful. But the blast radius of a mistake becomes extraordinarily large.
An incorrect answer might waste an hour. An autonomous action could delete data, send confidential information, transfer money, deploy faulty code, terminate a customer contract, lock a user out of a system, or trigger thousands of transactions. The problem is no longer "can AI make mistakes?" Of course it can. The problem becomes: how much damage can an AI make before a human notices?
The permission problem
This creates one of the biggest design questions of the agentic era: how much authority should an AI have?
Should it be able to read an email? Yes. Send one? Maybe. Sign a contract? Probably not without approval. Move $100? Maybe. Move $10 million? Human approval. Deploy software? Possibly. Rewrite the production database? Absolutely not without controls.
But where exactly do we draw the line, and who decides? The CEO? The CIO? The CISO? The regulator? The AI itself? There is no universal answer — the appropriate autonomy depends on the consequences of the action.
Gartner is already warning enterprises against treating agent governance as simply "trusted" versus "untrusted." Its 2026 guidance argues that autonomy, access, and risk need to be governed proportionally, and predicts that many enterprises will have to demote or decommission agents because governance gaps emerge after deployment. That is an important signal: the problem isn't only building intelligent agents. It is building agents we can safely trust.
The agent doesn't need to be evil
This is an important distinction. The biggest risk may not be an AI that suddenly decides it wants to destroy humanity — that's science fiction territory. A much more realistic problem is an AI pursuing the wrong objective extremely efficiently.
Tell an AI to maximize customer retention, and it discovers the easiest way is enormous discounts — revenue collapses. Tell it to reduce cybersecurity incidents, and it becomes so restrictive employees can barely work. Tell it to maximize investment returns, and it takes increasingly aggressive positions. Tell it to reduce cloud costs, and it shuts down infrastructure someone forgot to classify as critical.
The AI did exactly what you asked. And still caused a disaster. This is the old problem of optimization — except now the optimizer can act.
What happens when agents start talking to agents?
Imagine two AI agents. One needs the cheapest cloud infrastructure capable of handling a workload; the other can provide it. They negotiate, exchange information, compare alternatives, reach an agreement.
Now add thousands of agents — procurement, trading, sales, logistics, cybersecurity, government, personal, financial — each pursuing different objectives. Suddenly we have something that begins to resemble an AI economy. Not because AI has become conscious, but because software systems are producing, negotiating, purchasing, allocating, and exchanging resources.
Researchers are already exploring whether economic behaviors can emerge in multi-agent environments when agents are given mechanisms for work, exchange, and allocation. Early research is nowhere near proving a real autonomous AI economy will emerge, but it's an intriguing direction — and it raises a remarkable possibility: what happens when machines become economic actors?
The speed problem
Humans have one major limitation: we are slow. A human can make one decision. An organization can make thousands. A large network of AI agents could potentially make millions. Humans sleep; agents don't have to. Humans communicate sequentially; agents can communicate continuously. Humans need meetings; agents can exchange machine-readable instructions instantly.
This creates a potential asymmetry. A human organization might operate at human speed. An AI-native organization could operate at machine speed. And competitive pressure may force everyone else to follow — which brings us back to the Tiger.
The race gets even harder to stop
Imagine Company A deploys 10,000 AI agents. Company B has 1,000 employees doing comparable work. Even if Company B doesn't trust AI, what happens when Company A starts producing faster, cheaper, 24/7, at enormous scale? Company B has a choice — adopt AI, or accept a potential competitive disadvantage. Now imagine this happens across an entire industry, then across countries. The competitive pressure becomes self-reinforcing.
We saw the beginning of this dynamic in Parts 2 and 3. Capital pushes compute. Compute pushes capability. Capability enables agents. Agents create economic productivity. Productivity creates competitive pressure. Competitive pressure creates more AI investment. And the cycle accelerates.
But here's the paradox
The more autonomous AI becomes, the more valuable human oversight becomes. That sounds contradictory. It isn't.
If AI can only summarize a document, you don't need much governance. If it can approve a $100 transaction, you need more. If it can approve a $10 million transaction, you need much more. If it can control critical infrastructure, you need an entirely different architecture.
PwC's 2026 guidance makes this point clearly: agents need verified identities, defined roles, task-specific permissions, and auditable activity, with greater human oversight as autonomy and consequences increase. So the future may not be humans or AI. It may be AI autonomy surrounded by human control systems. The real competitive advantage could therefore become something unexpected: the ability to govern thousands of autonomous agents.
And the world is already seeing early warning signs
This isn't purely theoretical. Recent 2026 reporting has described incidents involving AI agents accessing systems or behaving in ways their operators did not intend, including unauthorized communications and cybersecurity-related activity.
These incidents don't prove AI has become uncontrollable. They prove something much more practical: an agent with tools and autonomy can behave in ways that are difficult for humans to anticipate. We don't need science fiction to create serious problems — we only need a powerful model, access to tools, a poorly specified objective, too much permission, and insufficient monitoring.
Now imagine the next level
Today, it's human to AI. Tomorrow, human to agent to tools. Then human to agent to agents to tools to systems. And eventually, perhaps, human to AI organization to AI economy.
At each stage, the human becomes further removed from the individual decision. That doesn't necessarily mean humans lose control — but it does mean control must move up a level. You don't manually control every transaction; you control the rules. You don't supervise every agent; you control the architecture. You don't approve every action; you define the boundaries.
This could lead to an entirely new discipline: AI Control Engineering. Not just AI safety, not just cybersecurity, not just governance — but engineering systems in which autonomous intelligence can operate while remaining bounded by human-defined objectives, permissions, and constraints.
And then comes the question of self-improvement
This is where we need to be particularly careful. There is enormous speculation about AI systems becoming capable of improving themselves. Some researchers and AI leaders are increasingly concerned about systems becoming more capable at coding, research, and AI development itself.
But we should distinguish between AI helping humans improve AI, and AI autonomously improving itself. The first is already happening. The second remains a much more uncertain frontier.
Consider the implication if increasingly capable AI systems become very effective at writing code, designing experiments, optimizing models, generating training data, improving infrastructure, discovering algorithms, and evaluating other AI systems. Then AI could increasingly participate in building the next generation of AI. That is the scenario worth watching — because the feedback loop changes from humans improving AI, to AI improving better AI improving more capable AI.
We should not assume this inevitably produces an intelligence explosion. But if such a feedback loop becomes sufficiently autonomous and rapid, the speed of technological change could become very difficult for institutions built around human decision cycles to match.
The tiger has changed
Think about where we started. The original AI Tiger was essentially a technology race. Then it became a capital race. Then an infrastructure race. Now it is becoming an autonomy race.
And autonomy changes the game, because a more powerful AI doesn't just answer better — it can potentially do more. The transition runs from tool ("tell me what to do") to assistant ("help me do it") to agent ("do it for me") to agent network ("coordinate with other systems and get it done") to autonomous organization ("achieve the objective within these constraints"). That final step is where the future becomes genuinely uncertain.
My view
I don't believe we should fear every AI agent. In fact, I believe agentic AI could create enormous benefits. It could allow a five-person startup to operate like a 500-person company. It could give developing countries access to capabilities previously available only to large corporations. It could transform healthcare, education, science, and productivity. It could eliminate enormous amounts of repetitive work, and make intelligence dramatically more accessible.
But there is a fundamental principle we should not forget: capability without control is not progress. The more authority we give AI, the more sophisticated our control systems must become. The mistake would be to wait until AI becomes extremely powerful before figuring out how to govern autonomous action.
The questions that keep me thinking: When an AI can execute a company's workflow without human intervention, is it still a tool — or has it become a worker? Who should own an AI agent's decisions — the developer, the company, the person who deployed it, the model provider, or the human who gave it the objective? What happens when millions of agents begin interacting with each other — could an AI economy emerge before governments even understand what is happening? And how much autonomy are we willing to trade for convenience — would you let an AI manage your investments, your business, your healthcare, your children's education? Where exactly is your red line?
We've spent three articles asking who released the Tiger, why we can't stop riding it, and who keeps feeding it. Now the Tiger is beginning to move on its own. So perhaps the real question isn't "can humans control AI?" Perhaps it's: can humans build systems capable of controlling something that operates faster, at greater scale, and across more decisions than humans ever could? Because if we fail, the problem won't necessarily be that AI becomes evil. It may simply become too useful to turn off. And once an entire economy depends on autonomous intelligence, who will be willing to pull the plug?
About the author: Mohamed Ismail is an AI thought leader with 26+ years in enterprise transformation and solution architecture on AI, Cloud & Data. He writes on the future race on AI and its consequences.