Key Takeaways:
- Most organizations plan to scale agentic AI but lack the governance to manage it safely
- Over 80% of enterprises have already experienced unintended or unauthorized actions by AI agents
- Traditional cybersecurity models focus on data protection, not autonomous decision-making
- A new governance approach is needed—one that includes identity management, continuous monitoring, and cross-functional oversight
- Integration, data quality, and culture remain major barriers to safe and effective agent deployment
The Governance Gap
Enterprise interest in agentic AI—AI systems capable of initiating and executing tasks with autonomy—is surging. But according to recent industry surveys, a majority of IT and business leaders admit they don’t yet have adequate governance frameworks in place. This mismatch between adoption and oversight is creating real risks.
While 98% of surveyed organizations say they plan to increase AI agent use over the next year, only 44% report having formal policies to guide that growth. And 80% say they’ve already experienced at least one incident involving an unintended action from an AI agent.
These incidents range from benign workflow mistakes to more serious issues, such as unauthorized access to systems, misconfigured automation, and improper data handling. In short, the agents are acting—but in ways few organizations fully understand or control.
What Makes Agentic AI So Risky?
AI agents are fundamentally different from traditional AI applications. Instead of generating insights or responding to prompts, they initiate actions. That means they touch systems, make decisions, and interact with people and processes—often across multiple departments or tools.
This shift creates new threat surfaces. For example, a well-meaning agent might reset a user’s credentials in response to a vague request, reconfigure a pricing algorithm incorrectly, or send a document to the wrong department. Each of these actions can bypass traditional security checkpoints because the system wasn’t designed to detect intent, only access.
The risks aren’t just technical. They’re organizational. In most companies, no single team is responsible for agent governance. Compliance teams focus on policy. Security teams monitor logs. Product teams build features. But agents blur all those lines.
Treating Agents Like Employees
One of the leading ideas emerging from the enterprise AI field is to manage agents like employees. That means assigning them unique identities, tracking their activity across systems, and enforcing permissions based on role and context—not just technical access.
This approach offers several benefits:
- Accountability: Every action can be traced back to a known agent identity
- Observability: Behaviors can be monitored in real-time, with alerts for deviations
- Auditability: Organizations can reconstruct events and evaluate outcomes
But very few companies have these systems in place. Most agent deployments today rely on basic API credentials, static rules, or informal testing. Without robust governance, autonomy becomes a liability.
Three Pillars of Agent-Ready Governance
For organizations to move safely and confidently into the agentic AI era, three foundational changes are needed:
1. Identity-Based Access for Agents
AI agents should be assigned user-like credentials with specific scopes and roles. This allows organizations to apply least-privilege principles and monitor agent behavior as they would with any employee.
2. Real-Time Monitoring and Intervention
Continuous monitoring is essential. That includes behavior-based alerts, policy-aware guardrails, and the ability to pause or shut down agent operations mid-task if anomalies are detected.
3. Integrated Risk and Compliance Frameworks
Governance must be embedded at every stage—from design and training to deployment and post-action analysis. That includes incorporating ethical reviews, bias testing, and operational assessments alongside traditional risk reviews.
Infrastructure and Data Challenges
Even when governance models are sound, technical friction often slows implementation.
- Legacy systems may lack the interfaces agents need to act safely or meaningfully.
- Unstructured or siloed data can confuse AI agents or generate hallucinations.
- Monitoring tools are often fragmented, unable to provide a centralized view of agent behavior.
Many companies are building pilots, but few have reached full production-scale deployments. Not because the agents aren’t capable—but because the foundations are still catching up.
Cultural Hurdles Are Just as Big
Deploying agentic AI isn’t just a technical project—it’s a business transformation. That means cultural change, too.
- Leadership must understand the strategic and ethical stakes of AI autonomy
- Legal and compliance teams must be integrated into design processes early
- Employees must be trained to understand how to work alongside—or oversee—agents
Without this shift, even the best tools may be applied in ways that introduce unforeseen risk.
Conclusion: Autonomy Without Oversight Is a Formula for Failure
Agentic AI holds enormous promise, from automating workflows to accelerating decision-making. But giving software the ability to act independently comes with new responsibilities.
Companies that view AI agents as just another tool—or treat governance as an afterthought—are likely to encounter costly errors, compliance failures, or operational surprises.
The organizations that will succeed are those that:
- Govern agents like workforce participants, not software features
- Build robust pipelines for testing, monitoring, and control
- Embed ethics, compliance, and accountability from the start
Learn how AI Agents can supercharge your company’s profits and productivity at TMC’s AI Agent Event in Sept 29-30, 2025 in DC.

Rich Tehrani serves as CEO of TMC and chairman of ITEXPO #TECHSUPERSHOW Feb 10-12, 2026 and is CEO of RT Advisors and is a Registered Representative (investment banker) with and offering securities through Four Points Capital Partners LLC (Four Points) (Member FINRA/SIPC). He handles capital/debt raises as well as M&A. RT Advisors is not owned by Four Points.
The above is not an endorsement or recommendation to buy/sell any security or sector mentioned. No companies mentioned above are current or past clients of RT Advisors.
The views and opinions expressed above are those of the participants. While believed to be reliable, the information has not been independently verified for accuracy. Any broad, general statements made herein are provided for context only and should not be construed as exhaustive or universally applicable.
Portions of this article may have been developed with the assistance of artificial intelligence, which may have contributed to ideation, content generation, factual review, or editing.
Agentic AI isn’t coming. It’s here. And readiness isn’t optional—it’s foundational.






