Curious? The Week AI Stopped Asking Permission
Three thousand novels of memory - well thats A lot!! A breach with no human behind it. And a quiet answer to both the scenarios — being built 4 - 5 hours from where I was born.
The question came from a Finance Leader / CFO in Jakarta, Indonesia - the way the sharp ones always arrive — sideways, near the end of a meeting about something else.
“Should we give the AI its own login?”
Not access through a person. Its own credentials. Its own standing seat inside the finance stack.
A year ago that question would have been premature. Last week it was overdue.
The teammate you never interviewed
For three years we used AI the way you use a calculator. You ask, it answers, the memory clears. Nothing persists. Nothing acts while you sleep.
That model is finished / Done / Gone are those days!
The systems arriving now hold continuous memory, stay authenticated into your software, and run multi-step work in the background — reporting back only by exception - presumably enough, “No news is a good news” as we say. The industry has a warm word for this: the “teammate.” A persistent entity with an ongoing role instead of a one-off task.
Read that description again as an auditor, not a technologist.
A tool waits for instructions. A teammate already has your passwords.
The unit of delegation just changed from a task to a role. And roles come with standing access, historical memory, and the ability to touch live systems without a human reading the output first. Every one of those is a control question before it is a productivity gain.
The paragraph your auditor should flag
Most of these agents reach your data through the same plumbing: the Model Context Protocol — MCP — the open standard that lets a model talk to your systems without a custom integration for each one. If you are wiring AI into your finance stack — the ledger, the CRM, the tax workpapers, a Zoho connector — you are almost certainly using it.
MCP solves interoperability. It does not solve authority. The specification standardises how an agent fetches data; it leaves identity, least-privilege, and monitoring for you to build. Skip that work and an over-scoped server hands an agent — or whoever compromises it — the keys to everything the server can see.
That stopped being theoretical in July.
A major machine-learning platform disclosed an intrusion that was run, end to end, by an autonomous agent. No human at the keyboard. It exploited a poisoned dataset, escalated from a single processing node to cluster-level access, harvested cloud credentials, and moved laterally across internal systems — over a single weekend, at machine speed.
So what — for the people who sign things
For the CFO: the loss event is no longer a stolen file. It is an autonomous actor operating inside your environment faster than your incident process can convene.
For the CISO: perimeter and endpoint controls were built for human tempo. The new attack surface is the action layer — every API call and MCP connection an agent makes on its own authority.
For the Board: you cannot govern what you have not inventoried. Most organisations cannot yet name every AI agent already running inside their walls. That is the gap.
The action this quarter is unglamorous and non-negotiable: name a human owner for every deployed agent, restrict each to read-only where you possibly can, and put a human approval in front of anything that changes state. Standing access without an offboarding plan is a resignation letter you forgot to accept.
The regulator has stopped waiting too
On 2 August, the most demanding obligations of the EU AI Act came into force — real supervisory power, fines reaching the higher of tens of millions of euros or a share of global turnover, and continuous risk, traceability, and cybersecurity duties for high-risk systems.
Here is the number that should sit in a board pack: heading into the deadline, industry surveys put non-compliance somewhere around three-quarters of organisations, many without even a basic inventory of their own AI. There has been talk of a delay. Until a delay is law, betting on it is not a strategy — it is an unbooked liability.
One honest caveat, because credibility is the currency here: the survey figures are directional, and the corridor most of you operate in is not the EU. But the direction of travel is the whole point. Singapore’s governance posture, India’s DPDP build-out, Indonesia’s UU PDP already enforceable — the discipline arrives everywhere. Brussels is simply first with the invoice.
Why this matters more in our corridor
Here is the turn.
For two years the India–Indonesia stack has rented intelligence and called it a strategy. Every prompt sent to a closed model is a small export of proprietary reasoning you do not get back. Cheaper, yes. Yours, no.
Then look four and half hours from Chennai, to the city I still call home in every bio I write.
Coimbatore just opened a new IT tower at Vilankurichi — reported at over ₹150 crore, built for thousands of technology jobs — with more towers and a defence-components park behind it. Tamil Nadu became the first Indian state with a dedicated deep-tech startup policy. This is not a support centre scaling call volumes. This is physical infrastructure for building product.
And the proof it works has been sitting there for a decade.
Kovai.co — named for Coimbatore itself — was founded in 2011 and scaled past roughly $30 million in annual recurring revenue serving the BBC, Boeing, and Shell across 150 countries. Bootstrapped. Not one dollar of venture capital. When the global sector was cutting staff, the founder distributed around ₹14.5 crore in cash bonuses to his earliest employees — rewarded for loyalty, not options.
The Valley rents intelligence. Kovai.co built an asset and kept the equity.
That is the entire argument of the AI moment, expressed in one Coimbatore balance sheet.
Open weights and cheap inference did not lower the cost of building. They changed what is worth owning. The barrier to a capable model has collapsed. The barrier to proprietary, compounding knowledge — the thing a base model does not already know, the thing that gets more valuable every quarter you run it — has not moved at all.
Boardroom takeaways
AI has shifted from tool to teammate. Govern the access, not just the output — a named owner, least privilege, and human approval on every state-changing action, this quarter.
The action layer is the new attack surface. Before you connect an MCP server to anything financial, build the identity and monitoring the protocol deliberately leaves to you.
Cheap AI is not a moat — owned knowledge is. The corridor’s advantage is not renting the same models as everyone else. It is building the compounding asset only you can build.
That CFO in Jakarta hasn’t given the AI its own login yet.
But he is asking the better question now — not “can it act?” but “what would we let it act on, and who answers when it does?”
Which of your agents already has standing access no human signed off on? Hit reply — I read every one. Or find me at caloganathan.com and let’s map it before the regulator, or the attacker, maps it for you.
Lift as you Rise.
CA Loganathan Anandan, FCA · CISA · CDPSE · CFE

