Who can authorise an AI agent to commit the business?
Purchasing agents need a defined authority model before they can place an order, accept terms or change a supplier commitment.
Read the guideAuthority, data provenance, vendor change and human oversight for businesses deploying artificial intelligence.

AI governance starts with a use case and a responsible legal entity. A model is not itself a Data Fiduciary. The organisation determining the purpose and means of personal-data processing may be one. Contract, intellectual-property, consumer, employment and sector rules can apply alongside data-protection law; the relevant obligations depend on the deployment.

Purchasing agents need a defined authority model before they can place an order, accept terms or change a supplier commitment.
Read the guideA service can behave differently even when the subscription, interface and price stay the same.
Read the guideAsk what the supplier can substantiate about the data—not simply whether it describes the model as compliant.
Read the guideAn approval button is not meaningful oversight if the reviewer lacks the evidence, time or authority to disagree.
Read the guidePreserve the system state, contain repeat exposure and assess the actual consequences before assigning liability.
Read the guideApplicable Indian statutes and sector directions are mandatory where their scope is met. NIST AI RMF is a voluntary governance framework, unless particular commitments become binding through a contract or another applicable requirement. Its GOVERN, MAP, MEASURE and MANAGE functions can organise evidence without creating a new Indian legal obligation.