Governing AI agents: keeping control when the AI acts

The moment everything changes

Until recently, AI in a company was a tool. You asked a question, the model produced a suggestion, and a human decided whether to take it. The human was always the last step.

With an AI agent, that last step falls away.

An agent plans, reaches for tools, and completes multi-step tasks on its own. It does not check with you before it sends an invoice, changes a record, or fires off a reply to a customer. It reasons, decides, and acts. In our experience, most companies underestimate exactly this jump. They treat the agent like a slightly smarter chatbot. But it is an employee with no contract, no role description, and no manager.

Implement Consulting Group put it well: the governance question shifts from "Is the model accurate?" to "Can we keep control, accountability, and trust?" That sounds like a detail. It is the whole difference.

Why the old rules no longer hold

Classic AI control rested on two assumptions. First: a human looks at every result before it takes effect. Second: the system can only reach what you tightly grant it.

Both assumptions break with an agent. It runs continuously, not on demand. It combines tools you granted one by one into actions you never planned that way. And several agents sometimes coordinate among themselves, with no human in between.

You can no longer check every single step. This is not a convenience, it is arithmetic: a system that performs a hundred actions in seconds cannot be controlled with one approval per action. So you have to build the control somewhere else, into the boundaries the agent is allowed to act within at all.

The uncomfortable number from the field

There is one thing almost every company gets wrong, and it has nothing to do with technology.

According to the State of AI survey by Implement Consulting Group (2026), only about 20 percent of firms have an end-to-end AI roadmap. Just as many have none at all. Over half say their AI policies feel disconnected from daily operations. And important decisions about investment and risk often fall outside any formal body.

Translated: most deploy agents before anyone has defined who answers for them. It is like giving a new employee access to accounting on day one with nobody being their boss. With a human, nobody would do that. With an agent, it happens all the time.

The three questions that are enough for an SME

Implement's framework has seven dimensions, from normative principles through guardrails to cost control. For a corporation with its own compliance department, that is right. For an SME, it is too much at once.

We boiled it down to three questions. Before an agent goes into production at your place, you have to be able to answer them. If you cannot answer even one, the agent is not ready.

Three questions before an AI agent goes live: who owns it, what may it access, and how do you notice failure

Who owns this agent?

Every agent needs a named human who is responsible. Not "IT", not "the project team". One person. That person decides what the agent may do and carries it when something goes wrong. Implement says it bluntly: rules without owners are process without authority. An agent with no owner is an ownerless tool acting in your name.

What may it access?

An agent should be allowed exactly as much as needed, and not one click more. Which systems, which data, which actions? May it only read, or also write? May it move money, or only make suggestions? This is the same logic as access rights for people, and it is the most effective lever you have. An agent that can only read cannot do damage, no matter how badly it goes off the rails.

How do you notice when it goes wrong?

If you cannot check every step, you at least have to notice when something runs off course. That means: the agent logs what it does. There is a line at which it stops and asks a human. And someone looks at it regularly, not only when a customer complains. The outsourcing reflex does not work here. Even when the agent comes from a vendor, the accountability stays with you. Technology can be outsourced, liability cannot.

Governance is not the brake

The biggest error is seeing governance as the thing that slows innovation down. Over half of the survey respondents experience security and compliance exactly that way, as a slowdown rather than an enabler.

That is understandable and still backwards.

Clear boundaries are what let you have the agent act at all. Without them you have to hold your breath at every action and end up controlling everything yourself anyway, which makes the agent useless. With them you can let it run, because you know it stays inside a fence. The companies that scale AI agents successfully do not have the fewest rules. They have the clearest. How to set up that framework in general we described in AI Governance. Why the human stays the bottleneck despite agents is in The human bottleneck.

The simplest entry point

Do not start with the riskiest agent. Start with a small, manageable case where a mistake does not hurt. An agent that summarises internal documents does less damage than one that talks to customers.

On that harmless case you learn what your three answers look like in practice. You see what the log has to look like, where the stop line sensibly sits, how often someone should look. And then you take the same structure for the next, bigger agent. That is how you build trust and evidence before you give an agent real responsibility. It is exactly the pragmatic path that AI agents in the company describes too.

The one question before every agent

Before the next AI agent goes live at your place, ask a single question in the room: if this agent does something stupid tomorrow, who notices, how fast, and who answers for it?

If the room goes quiet, the agent is not ready. Not because the technology is missing, but because the accountability is.

And if you are realising that agents are already running at your company that nobody can answer this question for: that is a good moment to tidy up, before it turns into an incident. That is exactly where we help.