← Article Library
OHS Canada

When AI Starts Acting Before Humans Are Ready

Why agentic systems will test governance, oversight, and human capacity faster than traditional AI

Originally published on OHS Canada. This page presents Donald P Andrechek’s original article manuscript.

The next safety shift is not AI that answers

The first wave of artificial intelligence in many workplaces helped people answer questions.

The next wave will start taking action.

That shift should get the attention of every health and safety leader.

Traditional AI may summarize an incident report, draft a procedure, organize inspection notes, translate training material, identify patterns, or help a safety professional compare information faster. Those uses still carry risk, but the system is mostly supporting information work.

Agentic AI changes the condition.

An agentic system can pursue a goal, use tools, move through steps, communicate with other systems, trigger workflows, assign tasks, route information, escalate issues, monitor completion, and influence what happens next.

That is a different safety question.

The issue is no longer only whether AI can help an organization think.

The issue is what happens when AI begins to act inside the organization before the human system is ready to govern those actions.

A workplace does not need a science fiction version of AI to face this risk. It only needs software that can recommend the next step, send the message, open the work order, rank the risk, notify the supervisor, adjust the schedule, flag the worker, close the action, or route the concern without enough human understanding of what has changed.

The risk begins when AI becomes operational. Not when it becomes conscious.

Advice can wait. Action moves.

There is a major difference between advice and action.

Advice can be challenged before it moves. Action has consequences once it begins.

If AI drafts a safety bulletin, a human can review the wording.

If an agent sends the bulletin, assigns training, records completion, updates a dashboard, and escalates non completion to management, the system has moved into operational control.

If AI summarizes an inspection, a safety professional can verify the notes.

If an agent creates corrective actions, assigns owners, sets deadlines, triggers reminders, and closes items when it detects completion, the organization has allowed AI to shape accountability.

If AI identifies fatigue risk, that may support prevention.

If an agent changes schedules, flags workers, changes task assignments, or recommends removing someone from work, the system is no longer only informing safety. It is influencing people’s work lives.

That is why agentic AI requires a stronger governance standard than ordinary AI support tools. The more a system can do, the less acceptable it becomes for leaders to say they thought someone else was watching it.

The human in the loop may not be enough

Many organizations will reassure themselves with one phrase.

A human is still in the loop. That may be true.

It may also be meaningless.

A human in the loop is only real control if the person has enough time, competence, authority, context, and confidence to stop the system. If the supervisor is rushed, the safety department is overloaded, the dashboard looks certain, and the recommended action is already prepared, approval can become a click instead of a judgment.

That is not oversight.

It is consent under pressure.

If the human cannot understand the output, cannot see the data behind it, cannot challenge the recommendation, cannot override the action, or cannot slow the process without consequence, the human is not governing the system.

The human is decorating it.

This is one of the central risks of agentic AI in occupational health and safety. Organizations may create approval points that look responsible in policy but fail under real operating pressure. A checkbox is not judgment.

A review screen is not oversight.

Being copied on an automated action is not governance. The evidence is already moving toward agentic risk

This is not a distant concern.

The 2026 International AI Safety Report describes general purpose AI systems as increasingly capable and examines their risks, including how they can affect human autonomy by shaping information available to people and influencing institutional decisions about them. The report was written by more than 100 independent experts, with an expert advisory panel nominated by more than 30 countries and intergovernmental organizations.

The International Telecommunication Union launched a 2026 initiative focused on trust in AI agents. Reuters reported that the initiative responds to concerns about autonomous systems capable of independently performing tasks such as decision making, scheduling, and financial transactions, including concerns about accountability, human oversight, impersonation, and unauthorized actions.

The Canadian Centre for Occupational Health and Safety has already warned that AI management tools that assign tasks, monitor performance, and set schedules can increase work pace, reduce breaks, contribute to stress and physical strain, increase incident risk, and contribute to burnout. CCOHS also warns that AI worker management can create unhealthy competition and increased isolation when performance results are visible to peers.

CCOHS has also explained that artificial intelligence worker management systems collect real time data from workers and workplaces and use AI based models to make automated or semi automated decisions about task allocation or workload.

The European Union’s AI Act uses a risk based framework for AI developers and deployers and identifies employment and worker management as areas where AI can fall into high risk uses. NIST’s AI Risk Management Framework was developed to help organizations manage risks to individuals, organizations, and society connected to artificial intelligence.

These sources do not say every AI system is unsafe.

They say something more useful for safety leaders.

AI systems are becoming consequential enough that governance cannot trail behind deployment.

Automation becomes authority through workflow

Authority does not always arrive through a formal decision.

Sometimes it arrives through the workflow.

The system recommends the hazard rating.

The system assigns the corrective action.

The system routes the report.

The system ranks the employee.

The system flags the site.

The system schedules the inspection.

The system notifies leadership.

The system closes the task.

At first, people may say the system is only helping. Over time, the workflow becomes the normal path. The organization stops asking whether the action is right and starts asking whether the action was completed.

That is where automation becomes authority.

Not because anyone announced that AI is now in charge.

Because the organization stopped challenging the system that moves work.

In safety, that is a serious risk.

A corrective action is not controlled because a system assigned it.

A hazard is not understood because a dashboard ranked it.

A worker is not protected because a platform flagged risk.

An investigation is not complete because an agent generated the summary.

The real test is whether people can still examine the condition underneath the action.

The agentic gap in safety governance

Most safety management systems were not built for AI that acts.

They were built around people, procedures, supervisors, committees, reports, inspections, training, audits, corrective actions, investigations, and documented responsibilities.

Agentic AI can cut across those structures.

It can move information between systems. It can automate follow up. It can create documentation. It can recommend or trigger actions at scale. It can influence scheduling, escalation, performance review, task assignment, and operational priority.

That may make a safety system look tighter.

It may also create new gaps underneath. Who approved the agent’s authority?

Who defined what it can and cannot do?

Who tested the consequences before deployment?

Who reviews its actions?

Who investigates near misses caused by automation?

Who verifies the data it relies on?

Who can stop it?

Who tells workers when AI influenced a decision affecting them?

Who decides whether an automated action was safety protection or productivity control? If those questions do not have clear answers, the organization has an agentic gap.

The system may be acting.

Governance may still be catching up.

Weak systems will be exposed faster

Agentic AI will not enter perfect organizations.

It will enter real ones.

Organizations with staffing pressure, incomplete procedures, weak reporting, overloaded supervisors, poor worker participation, inconsistent follow through, unclear accountability, poor data quality, production pressure, leadership blind spots, and a history of treating documentation as proof.

Agentic AI may not correct those weaknesses.

It may expose them faster.

It may hide them better.

It may scale them across the organization.

If hazard data is weak, the agent may act on weak data.

If workers have stopped reporting, the agent may mistake silence for reduced risk.

If corrective actions are closed too easily, the agent may accelerate closure.

If supervisors are overloaded, the agent may create more work than people can verify.

If leadership values speed over truth, the agent may become a tool for faster reassurance.

If culture punishes bad news, the agent may learn from data shaped by fear and silence.

The risk is not only that AI will malfunction.

The deeper risk is that AI will function inside a system that was not prepared for the speed, reach, and confidence of automated action.

That is how the system can fail before the AI does.

The invisible escalation problem

Agentic systems can create escalation without visibility.

A concern may be routed. A risk may be scored. A message may be sent. A worker may be flagged. A corrective action may be opened. A supervisor may be notified. A dashboard may change. A pattern may be recorded.

Each step may look small.

Together, those steps may change how the organization treats a person, a crew, a site, a department, or a hazard.

If no one can reconstruct the path from input to action, accountability has already weakened.

In traditional safety systems, an investigation should be able to trace what happened. Who knew what? Who decided what? What evidence was used? What policy applied? What corrective action followed? What verification occurred?

Agentic AI can blur that trail.

The system did something because another system triggered it, because another model interpreted something, because a data point changed somewhere else.

That may be efficient.

It may also be unsafe.

Safety governance requires traceability. If an organization cannot explain how an AI influenced action was generated, reviewed, approved, challenged, corrected, or stopped, it should not use that system for safety critical work.

Worker trust will decide whether the system learns

Agentic AI will affect worker trust.

Workers will ask fair questions.

Is the system watching me?

Is it scoring me?

Is it comparing me?

Is it assigning work based on information I cannot see?

Is it changing my schedule?

Is it influencing discipline?

Is it using my reports against me?

Is it listening when I report risk, or only measuring output?

If workers do not trust how AI is used, they may stop feeding the system the truth it needs.

That is a safety risk.

A safety system depends on workers reporting hazards, near misses, fatigue, violence, pressure, equipment problems, supervision gaps, and workarounds. If workers believe AI monitoring will punish honesty, reporting will decline. If reporting declines, the system becomes less informed. If the system becomes less informed, agentic AI may begin acting on incomplete reality.

That is how automation weakens learning.

Not because the tool cannot process data.

Because the people closest to risk stop trusting what will happen to the data.

What TTP reveals

Truth, Tempo, Preparation, and Capacity Margin provide a disciplined way to examine agentic AI before it becomes embedded in safety critical work.

Truth asks whether reality can still move through the system.

Can workers challenge an AI action? Can supervisors see why an agent made a recommendation? Can safety professionals review the evidence behind an automated escalation? Can leaders admit the agent acted on incomplete data? Can workers know when AI influenced a decision affecting them?

If truth cannot move, agentic AI becomes a faster layer of organizational blindness.

Tempo asks whether the organization can control the speed of automated action.

Does the agent move faster than human review? Does it trigger workflows before people understand the context? Does it accelerate corrective action or merely accelerate closure? Does it increase work pace before capacity is assessed? Does it spread a weak assumption across multiple sites before anyone catches it?

If tempo outruns judgment, speed becomes exposure.

Preparation asks whether readiness exists before reliance.

Are agentic AI use cases defined? Are limits written? Are workers consulted? Are safety critical actions restricted? Are override rights clear? Are logs reviewable? Are errors investigated? Are supervisors trained? Are privacy, discipline, and reporting impacts addressed? Are stop processes in place?

Preparation is not launching an agent.

Preparation is proving the organization can govern what the agent may do.

Capacity Margin asks whether people still have enough room to remain in control.

Do supervisors have time to review agent actions? Do safety professionals have authority to slow deployment? Do workers have safe pathways to challenge automated decisions? Do leaders understand the system enough to govern it? Does AI reduce burden, or create more invisible work? If agentic AI consumes human capacity, it may weaken the safety system while appearing to modernize it.

What organizations must prove first

Organizations do not need to reject agentic AI.

They need to prove readiness before using it in safety critical ways.

First, define where AI is allowed to act and where it is only allowed to advise.

Second, prohibit autonomous action in safety critical areas until human verification, traceability, and stop controls are proven.

Third, require clear logs showing what the agent did, why it acted, what data it used, who reviewed it, and whether the action was challenged.

Fourth, consult workers before agentic systems influence monitoring, scheduling, performance review, task assignment, discipline, or work pace.

Fifth, separate safety protection from productivity control so AI is not presented as safety while functioning mainly as pressure.

Sixth, train supervisors and safety professionals to understand, question, and override agentic outputs.

Seventh, create protected reporting pathways for workers to dispute AI influenced actions.

Eighth, audit agentic systems as part of the safety management system.

Ninth, treat AI related errors, near misses, and unintended consequences as reportable safety learning events.

Tenth, require executive oversight when AI begins to act inside operational workflows.

The standard should be direct.

No agentic AI system should be allowed to act inside a safety system unless the organization can explain its authority, limits, data, oversight, traceability, challenge process, failure mode, and stop mechanism.

Human control must be real

The phrase human in the loop will not be enough for the next stage of AI.

The stronger standard is meaningful human control.

That means a person can understand the action, question the basis for it, see the evidence, slow the process, override the system, protect the worker, and remain accountable for the decision.

Meaningful human control requires more than access to a dashboard.

It requires authority.

It requires time.

It requires competence.

It requires courage.

It requires an organization that does not punish people for stopping the machine when the machine is moving in the wrong direction.

If a worker cannot challenge the AI, control is weak.

If a supervisor cannot explain the AI, control is weak.

If a safety professional cannot stop the AI, control is weak.

If leadership cannot govern the AI, control is weak.

If the organization cannot reconstruct what happened, control is weak.

A system that acts without meaningful human control is not a safety advancement. It is a governance failure waiting for a trigger.

Final reflection

The next safety failure may not begin with a machine breaking, a worker ignoring a rule, or a supervisor missing a hazard.

It may begin with an AI system that did exactly what it was allowed to do. It ranked the risk.

It sent the message.

It assigned the task.

It escalated the concern.

It changed the schedule.

It flagged the worker.

It closed the action.

It moved the system forward.

Only afterward did people ask whether anyone truly understood what had happened.

That is the agentic risk.

AI that answers can distort what people believe.

AI that acts can change what organizations do.

That difference is the line safety leaders cannot afford to miss.

Occupational health and safety cannot wait until agentic systems are already embedded before asking who governs them. By then, the workflows may be built, the habits formed, the dashboards trusted, and human review reduced to a click.

The duty now is to prepare before reliance.

Organizations must prove that truth can still move, tempo can still be controlled, preparation exists beyond vendor promises, and enough capacity margin remains for human beings to stop, challenge, correct, and recover.

Workers deserve more than automated confidence.

They deserve systems where human judgment still has authority.

They deserve safety governance strong enough to control AI before AI starts controlling the work.

Author bio

Don Andrechek is a Canadian health and safety professional, author, and creator of the Truth, Tempo, and Preparation framework. His work focuses on system failure, human capacity, operational tempo, AI readiness, agentic AI risk, and preparedness. He is the author of The Invisible Signals of Failure: Why Strong Systems Fail While Still Looking Strong and three AI focused books: The AI Readiness Lie, The System Will Fail Before the AI Does: Why Human Capacity Is the Real Test of Artificial Intelligence, and The Agentic Risk: Why AI That Acts Will Test Human Systems Faster Than AI That Answers.

Sources reviewed

Sources reviewed for this article include the International AI Safety Report 2026, the Canadian

Centre for Occupational Health and Safety guidance on AI and worker management, the NIST AI Risk Management Framework, the European Union AI Act overview, and recent reporting on international efforts to improve trust and oversight for AI agents. International AI Safety Report 2026: https://internationalaisafetyreport.org/publication/international-ai-safety-report-2026

Reuters reporting on ITU trust in AI agents initiative: https://www.reuters.com/legal/litigation/undigital-tech-agency-launches-initiative-improve-trust-ai-agents-2026-07-09/

Canadian Centre for Occupational Health and Safety, Artificial Intelligence and Workplace Safety:

https://www.ccohs.ca/oshanswers/hsprograms/artificial-intelligence-ai.html

Canadian Centre for Occupational Health and Safety, AI worker management and new technology: https://www.ccohs.ca/newsletters/hsreport/issues/2025/03/ezine.html

European Commission, AI Act overview: https://digital-strategy.ec.europa.eu/en/policies/regulatoryframework-ai

NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework

Continue reading

More writing from Donald P Andrechek

Return to the article library to explore safety, leadership, TTP, human capacity, AI, education, healthcare and systems.

Browse all articles