← Wissenstransfer
Einblicke · Nr. 03 August 2026 6 Min. Lesezeit

Wenn die KI nicht mehr rät, sondern handelt

Die meiste Aufmerksamkeit gilt der Frage, was künstliche Intelligenz kann. Für ein Gremium ist eine andere Frage wichtiger: Was darf sie tun?

Bis vor Kurzem war KI ein Ratgeber. Sie schlug etwas vor, ein Mensch entschied, ein Mensch handelte. Das ändert sich gerade grundlegend, an zwei Fronten zugleich — und beide verschieben etwas, das jedes Aufsichtsgremium interessieren sollte: Sie verlagern die Kontrolle weg vom Menschen. Wer die Verschiebung nicht versteht, überwacht ein Unternehmen, das anders funktioniert, als er glaubt.

Erste Front: Agenten, die handeln

Ein KI-Agent beantwortet nicht nur Fragen. Er liest Systeme aus, trifft Entscheidungen, löst Aktionen aus, beauftragt andere Agenten — und arbeitet ganze Vorgänge selbständig ab. In Unternehmensprozesse eingebaut, bearbeitet er eine Reklamation von Anfang bis Ende, wickelt eine Bestellung ab, stimmt Zahlungen ab, steuert IT-Abläufe. Die Effizienz ist beträchtlich, und sie ist echt: Was früher eine Kette von Menschen und Freigaben war, läuft in Minuten durch.

Der Haken steckt genau in dieser Effizienz. Sie entsteht dadurch, dass der Mensch aus der Schleife genommen wird — und der Mensch in der Schleife war die Stelle, an der geprüft, abgewogen und gehaftet wurde. Ein Agent, der handelt, delegiert nicht Arbeit, er delegiert Vollmacht.

Daraus folgen die Fragen, die ein Gremium stellen sollte, bevor es solche Systeme durchwinkt:

  • Was darf der Agent tatsächlich anfassen?

    Jede Berechtigung, die er hat, ist eine Handlung, die er ohne Rückfrage ausführen kann.

    Wo genau darf das System selbständig handeln, und wo endet seine Vollmacht?
  • Was passiert, wenn er irrt — und lässt es sich rückgängig machen?

    Ein falscher Rat bleibt folgenlos, wenn niemand ihm folgt. Eine falsche Handlung hat sofort Folgen. Und Agenten verketten Schritte: Ein kleiner Fehler am Anfang pflanzt sich fort und verstärkt sich.

    Welche Aktionen sind umkehrbar, welche nicht — und wer bemerkt einen Fehler, bevor er sich fortsetzt?
  • Wer haftet, wenn der Agent falsch handelt?

    Das eigene Unternehmen? Der Anbieter des Modells? Diese Frage ist rechtlich vielfach ungeklärt — was sie für ein Gremium nicht kleiner macht, sondern größer.

    Wer trägt die Verantwortung für eine Handlung, die kein Mensch getroffen hat?
  • Kann man nachvollziehen, was der Agent getan hat und warum?

    Ohne diese Nachvollziehbarkeit gibt es keine Aufsicht, nur Vertrauen.

    Können wir im Nachhinein sehen, was das System entschieden hat — und es einem Prüfer erklären?

Der nützlichste Maßstab ist ein menschlicher: Ein Agent, der handelt, ist wie ein neuer Mitarbeiter mit Handlungsvollmacht. Würde man einem neuen Mitarbeiter am ersten Tag Zugriff auf Zahlungen, Kundenkommunikation und Systeme geben — ohne Aufsicht, ohne Probezeit, ohne dass jemand über die Schulter schaut? Bei einem Agenten geschieht genau das oft, weil er als „Software" verbucht wird und nicht als das, was er in Wahrheit ist: ein handelnder Akteur.

Zweite Front: Software, die schneller entsteht, als jemand sie prüft

Die zweite Verschiebung betrifft, wie die Software selbst entsteht, auf der das Unternehmen läuft. Entwickler beschreiben heute in normaler Sprache, was ein Programm tun soll, und die KI schreibt den Code — oft schneller, als ihn noch jemand Zeile für Zeile lesen und verstehen kann. Das Tempo ist real, und der Reiz ist groß: Entwicklungszyklen verkürzen sich, kleinere Teams leisten mehr.

Auch hier steckt der Haken im Tempo. Wenn Code schneller entsteht, als er geprüft wird, wächst im Unternehmen ein Bestand an Software, die niemand mehr vollständig durchdringt. Das rächt sich nicht am ersten Tag, sondern später — wenn etwas ausfällt und keiner weiß, warum; wenn eine Sicherheitslücke im generierten Code steckt, die niemand bemerkt hat; wenn das System geändert werden muss und keiner mehr versteht, wie es funktioniert.

Die Gremienfrage lautet deshalb nicht „nutzt ihr KI in der Entwicklung?" — das ist heute fast überall ja. Sie lautet: Hält die Kontrolle mit dem Tempo Schritt?

Wer prüft, was die KI geschrieben hat, bevor es in Betrieb geht?

Schneller liefern ist nur ein Vorteil, wenn man für das Gelieferte noch einstehen kann. Tempo, das man nicht prüfen kann, ist keine Produktivität — es ist aufgeschobenes Risiko, das als Fortschritt verbucht wird.

Dabei ist der Umgang eine Frage des Maßes, nicht des Prinzips. Für einen wegwerfbaren Prototyp ist schnelle KI-Entwicklung ideal. Für das Kernsystem, auf dem das Geschäft ruht, ist sie ohne strenge Prüf- und Testdisziplin gefährlich. Der Unterschied liegt nicht in der Technik, sondern darin, ob das Unternehmen weiß, welchen von beiden Fällen es gerade vor sich hat.

Der gemeinsame Nenner

Beide Entwicklungen — der handelnde Agent und die im Eiltempo entstehende Software — sind Ausdruck derselben Verschiebung: KI wandert von der Empfehlung zur Handlung, vom Werkzeug zum Akteur. Das ist keine Warnung vor der Technologie. Der Nutzen ist real, und wer ihn ignoriert, verliert. Es ist eine Warnung davor, den Nutzen zu ernten, ohne die Kontrolle mitzudenken.

Für ein Gremium heißt das nicht, KI aufzuhalten. Es heißt, die richtige Frage zur richtigen Zeit zu stellen. Nicht „funktioniert es?" — es funktioniert oft beeindruckend. Sondern:

Wo handelt in unserem Unternehmen inzwischen eine Maschine an der Stelle eines Menschen — und ist die Aufsicht dort mitgewandert, oder ist sie zurückgeblieben?

Wer diese Frage nicht beantworten kann, überwacht nicht mehr das Unternehmen, das er zu überwachen glaubt.

Until recently, AI was an adviser. It proposed something, a human decided, a human acted. That is now changing fundamentally, on two fronts at once — and both shift something every supervisory body should care about: they move control away from people. Anyone who does not understand the shift is overseeing a company that works differently from how they think it does.

First front: agents that act

An AI agent does not merely answer questions. It reads systems, makes decisions, triggers actions, commissions other agents — and works through entire processes on its own. Built into business operations, it handles a complaint from beginning to end, processes an order, reconciles payments, runs IT workflows. The efficiency gain is considerable, and it is real: what used to be a chain of people and approvals now runs through in minutes.

The catch sits inside that very efficiency. It arises because the human is taken out of the loop — and the human in the loop was the point at which things were checked, weighed and answered for. An agent that acts is not delegating work; it is delegating authority.

From that follow the questions a board should ask before waving such systems through:

  • What can the agent actually touch?

    Every permission it holds is an action it can carry out without asking first.

    Where exactly may the system act on its own, and where does its authority end?
  • What happens when it gets something wrong — and can it be undone?

    Bad advice stays harmless as long as nobody follows it. A wrong action has consequences immediately. And agents chain steps together: a small error at the start propagates and compounds.

    Which actions are reversible and which are not — and who notices an error before it carries on?
  • Who is liable when the agent acts wrongly?

    Your own company? The provider of the model? Legally this is unsettled in many respects — which does not make the question smaller for a board, but larger.

    Who carries responsibility for an action no human took?
  • Can anyone trace what the agent did, and why?

    Without that traceability there is no oversight, only trust.

    Can we see after the fact what the system decided — and explain it to an auditor?

The most useful yardstick is a human one: an agent that acts is like a new employee with signing authority. Would you give a new employee access to payments, customer communication and systems on their first day — with no supervision, no probation, nobody looking over their shoulder? With an agent this is often exactly what happens, because it is booked as “software” rather than as what it actually is: an actor that acts.

Second front: software written faster than anyone reviews it

The second shift concerns how the software the company runs on comes into being at all. Developers now describe in ordinary language what a program should do, and the AI writes the code — often faster than anyone can still read and understand it line by line. The speed is real, and the appeal is considerable: development cycles shorten, smaller teams achieve more.

Here too the catch sits in the speed. When code is produced faster than it is reviewed, a body of software grows inside the company that nobody fully understands any more. That does not take its revenge on day one, but later — when something fails and nobody knows why; when a security hole sits in generated code and went unnoticed; when the system has to be changed and nobody understands how it works.

The board's question is therefore not “are you using AI in development?” — today that is a yes almost everywhere. It is: is control keeping pace with the speed?

Who reviews what the AI wrote before it goes into operation?

Delivering faster is only an advantage if you can still stand behind what was delivered. Speed you cannot review is not productivity — it is deferred risk, booked as progress.

How to handle it is a question of degree, not of principle. For a throwaway prototype, fast AI-assisted development is ideal. For the core system the business rests on, it is dangerous without strict review and testing discipline. The difference lies not in the technology but in whether the company knows which of the two cases it is currently dealing with.

The common denominator

Both developments — the acting agent and the software written at speed — express the same shift: AI is moving from recommendation to action, from tool to actor. This is not a warning against the technology. The benefit is real, and those who ignore it will lose. It is a warning against harvesting the benefit without thinking through the control.

For a board that does not mean holding AI back. It means asking the right question at the right time. Not “does it work?” — it often works impressively. But:

Where in our company is a machine now acting in the place of a person — and has oversight moved with it, or has it stayed behind?

Anyone who cannot answer that question is no longer supervising the company they believe they are supervising.