People Are Already Giving AI Authority. Who Decides Where It Stops?
EY's second Global AI Sentiment Study surveyed 18,152 people across 23 markets and found that a meaningful minority have already let AI act on their behalf without a human in the loop, including buying things and moving money. The question that actually matters is not whether people trust it. It is where that authority begins, where it ends, and what has to happen before the agent acts.
Event analysed: . This analysis was published on 21 August 2026.
EY's second annual Global AI Sentiment Study, published 26 March 2026, surveyed 18,152 people across 23 markets and found that 16% had used AI systems that acted on their behalf without human intervention in the previous six months. Within that figure, 10% had used an AI agent to buy a product on their behalf, 11% had let AI manage finances or banking tasks with little or no human involvement, and a separate 11% had let AI automatically refill a shopping cart and complete the purchase. EY frames this as decision making authority migrating from humans to systems, moving from low risk assistance toward more consequential territory including finance, health and transport. Moona Intelligence's reading is that the more useful question is not whether people trust these systems. It is what defines the boundary of the authority they have already given them: what task, what resource, what amount, what recipient, and whether that authority still holds at the exact moment an action is about to execute, not only when it was first granted.
For two years, almost every public conversation about AI has circled one question: do people trust it. EY's newest Global AI Sentiment Study, published in March 2026, quietly answers a more consequential one. A meaningful share of people are no longer only asking AI what to do. They are letting it act, and checking afterward, if at all.
EY surveyed 18,152 people across 23 markets and asked what they had actually used AI for in the six months before the study closed, not what they said they trusted. Sixteen percent said they had already used AI systems that acted on their behalf without human intervention. Ten percent had used an AI agent to buy a product on their behalf. Eleven percent had let AI manage finances or carry out banking tasks with little or no human involvement. A separate eleven percent had let AI automatically refill a shopping cart and complete the purchase, without a person approving that specific transaction. None of that is a future scenario EY is forecasting. It already happened, inside the window the survey measured.
That is the part worth sitting with. Public debate about AI is still mostly organized around trust, safety and responsible use, framed as though the open question is whether we should eventually let AI act on our behalf. EY's own numbers say a meaningful minority already has. So the interesting question was never whether we trust AI enough to let it act. It is what defines the boundary of the authority we have already given it.
The numbers matter because the actions matter
It would be easy to read 16% as a small number and move on. I think that reading misses the point of the study. EY reports that more than eight in ten respondents, 84%, used AI at all in the same six month window. Sixteen percent acting without human intervention is not a fringe behavior against that base. It is a meaningful minority of a population that is already using AI at near universal rates, doing something categorically different from asking a question and reading the answer.
Read in sequence, those figures trace a progression that the phrase artificial intelligence adoption tends to flatten. Asking AI for a recommendation is one thing. Delegating a task to it is a second thing. Watching it take an action is a third. Watching it take a consequential action, one that spends money or moves it, is a fourth, and it is qualitatively different from the first three. A bad recommendation gets ignored. A settled purchase or a completed transfer has already changed something in the world, and undoing it is a separate, harder problem than deciding it should not have happened.
EY's own framing agrees with that reading. The study describes decision making authority as migrating from humans to systems, and characterizes what started as low risk assistance as evolving into something far more consequential, explicitly naming finance, health and transport as the areas AI use is moving toward. Raj Sharma, EY's Global Managing Partner for Growth and Innovation, put the underlying shift plainly: a growing minority is already delegating decisions to AI, while many more are relying on it as an assistant in everyday life. That is EY's language, not Moona Intelligence's. What Moona Intelligence adds is a reading of what it implies: the interesting shift is not that AI got more capable. It is that a measurable number of people have already moved from asking to delegating, in exactly the categories, money and purchasing, where a wrong action is hardest to reverse.
Trust is too vague once AI can act
Here is where I think the public conversation is asking the wrong question. Do people trust AI is not precise enough once AI can act, because trust is not one setting a person turns up or down. It is a set of boundaries that shift by context, and most of them are never stated out loud until something crosses one.
Consider what a reasonable person might actually authorize, as an illustration of the shape of the problem rather than a claim about what EY's respondents specifically said. Someone might be entirely comfortable letting an agent book a restaurant table, and just as clearly uncomfortable letting the same agent transfer a large sum of money. Someone might authorize a purchase under a modest amount without hesitation, and withhold authorization for a recurring payment or a purchase from a merchant it has never dealt with before. None of that is a contradiction. It is scope. The person is not expressing a single level of trust in AI in general. They are drawing a boundary around a specific class of action, a specific resource, and a specific amount, and the boundary is doing all the actual work.
This is also where the vocabulary Moona Intelligence uses in this category earns its place, not as a glossary but as a way of separating things that keep getting collapsed into one word. Capability is whether an agent can technically perform an action. Access is whether it holds the credentials or connection to a resource. Delegated authority is whether a person or organization has actually empowered it to take some class of action on their behalf. Contextual authority is narrower still: whether this particular action, against this particular resource, for this particular task, at this particular moment, still falls inside that authority. EY's survey is evidence for the third category, at scale. It says nothing, and does not claim to say anything, about the fourth, and the fourth is where most of what actually goes wrong tends to live.
What delegated authority actually has to specify
Once a person delegates a class of action to an agent rather than approving each instance of it, the delegation has to answer more questions than most authorizations in practice ever state explicitly. What task is covered. Against which resource. In which environment. Up to what amount. To which recipient. Within what window of time. In what sequence relative to other actions. For how long the authorization itself remains valid. Under what identity the action is taken. Whether any category of action still requires a separate human approval regardless of amount. And whether the current state of the world still matches the state the authorization assumed.
Naming those dimensions is category analysis, not a description of what any particular product, Moona included, currently supports across the board. The point is narrower: most real world delegations, including almost certainly the ones behind EY's 16%, were not specified with anything like that precision. A person turns a setting on. The setting rarely says up to what amount, for how long, or under what conditions it stops applying. The authority exists. Its boundary mostly does not, at least not anywhere it could be checked later.
The moment of execution is where the real question lives
This is where Moona Intelligence's argument in this category has consistently landed, and EY's evidence sharpens rather than changes it. An instruction given in advance, whatever form it took, whether a setting toggled once or a broader mandate given to an assistant, does not by itself answer whether one specific action should execute right now. Context can change between the moment authority was granted and the moment an agent is about to act on it. The resource being acted on can be different from the one originally in view. The amount can be different. An action can be entirely normal in general and still wrong for this particular task. Another action may already have happened earlier in the same sequence, changing what the next one should be allowed to do. The authorization itself may simply have expired. And the agent that was originally delegated the task may have handed part of the work to another agent, which does not automatically inherit the same limits the first one was given.
Moona Intelligence has argued before that instructions written in advance cannot substitute for a check performed at the moment an action is about to execute, because the person writing the instruction cannot see the environment the agent will actually encounter. EY's numbers are a population scale version of the same gap. A person who turned on autonomous purchasing, or authorized an assistant to manage banking tasks, authorized a category of behavior at one point in time. Whether the agent should still be inside that authority for this specific purchase, today, is a separate question the original authorization cannot answer on its own.
The same gap shows up wherever an authorization is meant to cover a stretch of time rather than a single instance, and wherever one agent hands part of a task to another, since a second agent acting under delegated authority does not automatically carry the first one's limits with it. Moona Intelligence has also written about what happens when authorization has to survive a chain of agents before a payment actually settles, which is the sharpest version of this problem: authority that was real at the start of the chain can attenuate, or be misrepresented, before it reaches the action it was meant to govern. And simply watching what an agent does after the fact is not the same control as being able to stop it before it acts. The useful question was never whether the agent, in general, was trusted. It is whether this action was authorized at the moment it was about to happen, not whether some earlier instruction technically covered it.
The evidence problem
Once authority is genuinely delegated rather than approved instance by instance, a second problem follows the first one, and it is worth stating carefully as Moona Intelligence's own reading rather than as something EY or any regulator has specified. Neither EY's study nor any regulation Moona Intelligence is aware of requires the following model. It is what seems to follow once delegation at this scale is real, not a claim about what current law demands.
Organizations that let AI act on a person's behalf will increasingly need to be able to reconstruct, after the fact, what action was attempted, under whose authority, against which resource, under what context, whether an additional approval was required for that class of action, what decision was actually made, and whether execution occurred at all. A log that only says a transaction happened, for a given amount, to a given recipient, at a given time, answers what happened. It does not, by itself, answer whether that specific action was still inside the authority the person had actually given, at the moment it executed. That distinction, between a record of an event and evidence of why it was authorized, is one Moona Intelligence has examined closely in the specific case of agent payments, and in the broader case of reconstructing what an agent did after something has already gone wrong. EY's study does not reach this question at all. It measures that delegation is happening. It does not measure whether anyone involved can currently answer for it afterward.
What this actually means
AI adoption is usually described as a story about capability: models getting better at reasoning, at using tools, at completing longer tasks with less supervision. EY's evidence points at something adjacent and, to my reading, more consequential. It is not only that AI is getting more capable. It is that a measurable and growing share of people are handing it authority, the authority to buy, to pay, to manage money, before almost anyone, including the people doing the delegating, has clearly defined where that authority begins, where it ends, and what has to happen immediately before the agent acts.
Once authority has actually moved from a person to a system, asking whether people trust the system stops being the operative question. The operative question is whether that authority is bounded before a consequential action happens, not discovered to have been exceeded afterward. That is the category Moona Intelligence exists to understand, and EY's study is the clearest population scale evidence yet that the question is no longer theoretical.
Sources
This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.
