Agentic AI is moving rapidly from experimentation into operational business workflows. Futurum Group’s AI Platforms Decision Maker Survey, which included 820 respondents in the first half of 2026, found that 72 per cent of organizations were piloting or deploying agentic AI. It also found that 55 per cent identified agent reliability and hallucination management as a leading adoption challenge, while 53 per cent pointed to data privacy and security.¹
The enthusiasm is real. So is the hesitation.
In May 2026, Gartner predicted that by 2027, 40 per cent of enterprises would demote or decommission autonomous AI agents because governance gaps were discovered only after production incidents. Gartner warned that treating agent governance as a choice between complete restriction and complete trust creates avoidable failure.²
Governance done well does not simply constrain agentic AI. It creates the conditions for agents to operate safely, earn stakeholder confidence and scale sustainably.
The governance gap is significant
OutSystems’ 2026 State of AI Development research, based on a global survey of approximately 1,900 IT leaders, found that 97 per cent were exploring agentic AI strategies. However, only 12 per cent had implemented a centralized platform for managing agent sprawl.³
This difference illustrates a broader operational problem. Many organizations are experimenting with agents faster than they are creating consistent controls for identity, access, monitoring, testing and accountability.
Projects can stall even when the underlying technology works. Business leaders, security teams, legal advisers and customers may be unwilling to rely on agents whose authority, behavior and decision history cannot be clearly explained.
Design workflows with appropriate human checkpoints
Human oversight should be based on the consequences of an action, not on a blanket rule applied to every agent.
Stanford Digital Economy Lab’s Enterprise AI Playbook found that the appropriate level of human oversight depends on error tolerance, regulatory requirements and task complexity. It also found that escalation-based models can work particularly well for high-volume, recoverable tasks, while approval models are better suited to regulated or high-stakes work.⁴
A practical governance model can classify agent actions into three tiers.
Tier 1 auto-execute
Low-risk and reversible actions can run without a human approval step. Examples include retrieving approved information, drafting internal content, categorising requests and summarising service tickets.
The agent should still operate within defined data, system and logging boundaries.
Tier 2 notify and confirm
Medium-risk actions should trigger a lightweight approval process. Examples might include sending an external communication, updating a customer record or changing a workflow status.
The reviewer should receive enough context to understand what the agent proposes, why it proposes it and what systems or records will be affected.
Tier 3 escalate and pause
High-impact, regulated or difficult-to-reverse actions should pause until an authorized person approves them.
Examples may include processing payments, changing access permissions, executing legal agreements, making employment decisions or modifying sensitive production systems.
The agent’s recommendation, evidence, approval decision and final action should all be recorded.
There is no benefit in removing human involvement from a high-consequence decision simply to make a workflow appear frictionless.
Set permissions and boundaries that hold
One of the most important governance principles is separating an agent’s technical capability from its authority to act.
Agents should not automatically inherit the broad access of the employee, developer or team that created them. Instead, each agent should receive only the data, tools and actions required for its approved purpose.
A least-privilege approach should include:
- A distinct identity for each production agent
- Task-specific permissions
- Time-limited or revocable credentials
- Restrictions on sensitive data and systems
- Clear delegation from an accountable human owner
- Monitoring for unusual access or behaviour
- Regular reviews of permissions and inactive agents
Microsoft’s 2026 agent governance capabilities reflect this direction. Copilot Studio can provision Microsoft Entra Agent IDs for new agents, while Microsoft Agent 365 provides centralized visibility into agent inventory, permissions, behaviour and activity. Microsoft Entra Conditional Access can also apply access policies to agent identities before access tokens are issued.
These capabilities can support governance, but technology alone does not determine which permissions are appropriate. Organizations still need clearly defined owners, risk classifications and approval policies.
Apply identity and accountability to every agent
Governments and standards bodies are also focusing on agent identity, authorisation and traceability.
Singapore’s Infocomm Media Development Authority launched its Model AI Governance Framework for Agentic AI in January 2026 and updated it in May following feedback and contributions from more than 50 organizations. The framework recommends controls such as agent identity management, access controls, traceability and meaningful human accountability.5
In the United States, NIST launched its AI Agent Standards Initiative in February 2026 to encourage secure and interoperable agent standards. Related NIST work is examining how organizations can distinguish agent identities from human identities, limit agent authority, manage delegation and preserve accountability for automated actions.6
The direction is clear. An enterprise agent should not be an anonymous process operating through an unmonitored shared account. It should have an identifiable purpose, defined authority, accountable owner and reviewable history.
Build confidence with cautious stakeholders
Technical controls are necessary, but they are not sufficient.
Resistance to agentic AI is often cultural and organisational rather than purely technical. Finance, legal, security and operational leaders may have previously seen automation programs create uncontrolled complexity, inaccurate outputs or unclear accountability.
Their caution should be treated as useful risk information, not as an obstacle to innovation.
Four practices can help build confidence.
Start in a controlled environment
Allow stakeholders to observe an agent working with realistic data in a sandbox or read-only environment before it receives permission to take consequential actions.
This provides evidence of how the agent behaves without exposing the organization to unnecessary operational risk.
Make the first outcome measurable
Choose a well-defined, frequent and recoverable task. Measure results such as time saved, accuracy, escalation rates, resolution times and human intervention.
A measurable outcome is more persuasive than a broad claim that an agent has improved productivity.
Establish cross-functional governance early
Create a group that includes business, technology, security, privacy, legal, risk and operational stakeholders before a serious incident occurs.
Its role should include setting risk tiers, assigning ownership, approving high-impact use cases and reviewing performance and incidents.
Maintain complete and usable audit trails
When a stakeholder asks what an agent did, the organization should be able to provide a clear answer.
Logs should capture the agent’s identity, instructions, data sources, tool calls, proposed actions, approvals, outputs and resulting system changes.
Audit information should be understandable to business and risk stakeholders, not only to developers.
Monitor agents after deployment
Governance cannot end when an agent enters production.
Agent behavior can change as models, prompts, tools, permissions, data sources and connected systems are updated. A workflow that passed testing at launch may develop new risks after one of its dependencies changes.
Production governance should therefore include:
- Continuous performance and reliability monitoring
- Testing after model, prompt or tool changes
- Alerts for unusual behavior or access patterns
- Defined escalation and shutdown procedures
- Periodic permission reviews
- Incident reporting and root-cause analysis
- Business outcome and risk reporting
Monitoring should examine both whether an agent completed its task and whether it completed the task within its authorized boundaries.
The stakes run both ways
Gartner’s forecast that 40 per cent of enterprises may demote or decommission autonomous agents is a warning, but it also points to an opportunity.²
Organizations that establish proportional human checkpoints, task-scoped permissions, distinct agent identities, meaningful monitoring and transparent accountability will be better positioned to move successful agents into production.
Those that treat governance as documentation to be added after deployment are more likely to discover their weaknesses through an operational, security or compliance incident.
The objective is not unrestricted autonomy. It is controlled autonomy that can be observed, explained and trusted.
Ready to move from agentic AI enthusiasm to sustainable agentic AI governance?
Insentra’s AI practice helps organizations design governance checkpoints, permission frameworks and stakeholder trust programs for enterprise AI. Explore Insentra’s AI strategy resources through AI Momentum to follow developments in agentic AI, governance and responsible adoption.
Sources
- Futurum Group, “Can Enterprise AI Agents Deliver Value Without Breaking Governance and Trust?”
- Gartner, “Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure”
- OutSystems, “State of AI Development 2026” and related research announcement.
- Stanford Digital Economy Lab, “The Enterprise AI Playbook”, 2026.
- Singapore IMDA, “Model AI Governance Framework for Agentic AI”
- NIST, “AI Agent Standards Initiative” and “Software and AI Agent Identity and Authorization” concept paper,






