AI Agents Challenge Traditional Enterprise Governance Models

AI agents are gaining autonomy across enterprise systems, creating new governance and cybersecurity challenges. New research outlines a three-phase framework for managing AI-agent access, risk, monitoring, and accountability.

Key Highlights

  • AI agents are creating new governance challenges: Their ability to autonomously access systems and execute actions requires a different approach from traditional IT and AI governance.

  • Organizations face emerging risks: Shadow AI, excessive permissions, runtime changes, capability mismatches, and unclear ownership can increase enterprise security and operational risk.

  • A three-phase governance framework offers a path forward: Info-Tech recommends establishing guardrails and decision rights, defining a risk-based governance model, and operationalizing ongoing monitoring and accountability.

As enterprises deploy AI agents that can independently access systems, execute tasks, and make decisions, traditional IT approval and governance processes are struggling to keep pace.

New research from Info-Tech Research Group, Govern Enterprise AI Agents While Preserving Innovation, examines the governance challenges created by agentic AI and recommends a three-phase approach for managing agent autonomy, system access, monitoring, and accountability.

Unlike conventional software or earlier AI tools that primarily generate information for human review, AI agents can take actions across enterprise systems. That shift introduces new questions about who owns an agent, what it is permitted to access, how its behavior is monitored, and when human intervention is required.

"AI agents cannot be governed like traditional IT assets or earlier AI models because they do more than generate outputs; they act across systems," says Altaz Valani, Principal Advisory Director at Info-Tech Research Group.

Valani continues, "Many people will have multiple agents working for them, but AI agents cannot be governed the way we govern humans because they move quicker and lack emotions, conscience, and consequences."

The research argues that organizations need to move beyond one-time approvals and establish governance that continues throughout an agent's operational life. That includes visibility into which agents exist, who owns them, what systems and data they can access, and the degree of autonomy they have.

Key Governance Challenges

Info-Tech identifies several gaps that can emerge as organizations expand their use of AI agents:

  • Shadow AI: Employees or business units may create or deploy agents outside sanctioned tools and processes, leaving IT and security teams unaware of their existence.
  • Capability mismatch: An agent's level of autonomy and system access may not be matched by appropriate validation, controls, or monitoring.
  • Runtime drift: Changes to tools, prompts, permissions, or other configurations can gradually alter an agent's scope or behavior after its initial approval.
  • Unmanaged access: Excessive permissions or service-account privileges can give agents access to systems and data beyond what is necessary for their intended functions.
  • Ambiguous ownership: Organizations may lack clearly defined responsibility when an autonomous agent makes an error or causes harm.

These challenges make agentic AI governance as much an operational and accountability issue as a technology issue. For IT and security leaders, the focus shifts from simply determining whether an AI application is approved to understanding what an agent can do while it is operating.

A Three-Phase Approach

Info-Tech's research recommends three phases for establishing governance of enterprise AI agents.

Phase 1: Establish Governance Authority and Guardrails

Organizations should establish an agentic AI governance mandate, clarify decision rights, and agree on a limited set of enforceable principles and guardrails. The goal is to establish boundaries for agent autonomy and access before deployment expands.

Phase 2: Define the Governance Model

Governance and technical teams should map the agent lifecycle and identify agents wherever they are created or deployed. Agents can then be classified according to risk, with monitoring requirements and intervention procedures established for each risk tier.

Phase 3: Operationalize Oversight and Accountability

Business owners, technical owners, AI governance teams, and enterprise risk leaders should establish clear accountability, define performance and risk metrics, and provide executive visibility through reporting and dashboards. Organizations can then roll out the governance model in phases based on risk and organizational readiness.

The research also includes practical governance resources, such as an Agentic AI Governance Playbook, an example governance charter, an executive dashboard for monitoring AI agents, and an agentic AI governance glossary.

As autonomous AI becomes more deeply integrated into enterprise workflows, organizations face a governance challenge that differs from conventional software management. Rather than relying solely on approval at the point of deployment, organizations will need ongoing visibility into what agents can access, how they behave, and when their actions require human intervention.

Source: Info-Tech Research Group


Stay Connected with ISE Magazine 

Subscribe to our newsletters and magazine for the latest telecom insights, explore the current issue for in-depth features and strategies, and register for upcoming webinars to learn directly from industry leaders.

This piece was created with the help of generative AI tools and edited by our content team for clarity and accuracy.
Sign up for our eNewsletters
Get the latest news and updates