Category: AI Regulation | Reading time: 9 minutes

The shift most governance frameworks have not caught up with

There is a meaningful difference between an AI assistant and an AI agent, and it is not marketing. An assistant waits for your input and produces output you review. An agent acts on its own, across systems, without pausing at each step to ask.

That shift is happening fast. Gartner forecasts that 40% of enterprise applications will embed task-specific AI agents by the end of 2026, up from less than 5% in 2025.1 That is an eightfold jump in a single year, one of the fastest enterprise technology transitions since public cloud.2

These are not chatbots. Gartner's own examples include autonomous cybersecurity response agents that scan network traffic, analyse system logs, and initiate responses without human intervention.3 The agent decides and acts. A human may never see the individual decision.

The governance to match has not kept pace. Only 21% of organisations have a mature governance model for agentic AI, and Gartner expects more than 40% of agentic AI projects to be cancelled by the end of 2027, driven partly by inadequate risk controls.4

The real failure mode: authority creep

The danger with agents is rarely a single catastrophic error. It is gradual, and it is structural.

Here is how it happens in practice. An agent is deployed as decision-support, cautious, with a human confirming each action. It performs well. So the confirmation requirement is relaxed. The autonomy threshold is raised. Each individual adjustment is reasonable on its own. Over time, a system that now has the action authority of a high-risk deployment is still governed as the cautious pilot it started as.

One analysis of agentic systems in production financial services captured the endpoint precisely: authority creep and diffuse accountability are the dominant failure modes, arriving at a state where "no one made a bad decision; no one made the decision at all."5

That sentence is the whole risk. Under an accountability regime like SM&CR, "no one made the decision" is not a defence. It is an admission. The regime requires a named person to be answerable, and an agent that has quietly accumulated authority no one formally granted is a gap pointed straight at whoever holds that responsibility.

Why your existing controls do not cover this

The instinct is to reach for existing identity and access management. It does not fit, for a specific reason.

Traditional IAM was built for humans and for static service accounts. Agents are neither. They are often treated as generic service accounts without dedicated identity, authorisation, or accountability controls.6 The result is a growing population of agents operating with over-permissioned credentials and no clear accountability trail.7

The problems this creates are being catalogued by standards bodies rather than speculated about. In January 2026 Singapore's IMDA published the first comprehensive governance framework for autonomous agents, requiring each agent to carry a verifiable digital identity and an audit trail of which agent acted under whose authorisation.8 In February 2026 NIST launched an AI Agent Standards Initiative, framing the gap directly.6 These are early, and the standards will take years to mature, which means organisations deploying agents today cannot wait for them.9

The shadow-agent problem compounds all of this. You cannot govern what you cannot see, and unsanctioned agents deployed without approval are already a significant share of enterprise AI use.7 Gartner predicts that by 2030 more than 40% of organisations will experience a security or compliance incident from unauthorised AI tools, with 69% of cybersecurity leaders already reporting evidence or suspicion of such use.10

Three controls to review this week

You do not need a complete agentic governance programme to close the most dangerous gaps. Start with three questions, in order of how much exposure they remove.

1. Can you list every agent that can take an action? Not every AI tool. Specifically the ones that can do something: move data, call an API, trigger a transaction, change a record. If you cannot produce that list, that is the first gap, because everything else depends on it. An agent you do not know exists cannot be governed, and shadow agents are exactly the ones operating without oversight.

2. Does every acting agent have a named human owner? Each agent that can take action needs a person accountable for what it does, in the same way a junior employee reports to a manager. If the honest answer for any agent is "the team" or "IT generally," you have diffuse accountability, which is the precondition for "no one made the decision." Assign a name.

3. Can you show the authority each agent actually has, versus what you intended? This is the authority-creep check. For each acting agent, compare the permissions it holds now against what it was originally approved to do. Where they have drifted apart, you have a system governed as a pilot but operating as something more consequential. Document the current authority, and decide deliberately whether it is still appropriate.

These three produce a register, a named owner, and a review record. That is not sophisticated, but it is exactly the evidence an accountability regime asks for, and it is far more than most organisations deploying agents currently hold.

Why this connects to everything else this week

These three stories are one story. The EU AI Act's transparency duties turn on knowing which systems act and who is responsible for them. The FCA's outcomes-based approach demands you can evidence control over AI-driven decisions. Agentic governance is the same discipline applied to the systems that carry the most autonomy and therefore the most risk.

The common thread is accountability that does not dissolve as systems take on more of the work. A regulator, an auditor, or a court will ask the same question in each case: who is responsible for what this system did? The organisations that struggle will be the ones that built impressive autonomy and never assigned the answer.

The bottom line

Agents are moving from tools to actors faster than governance is moving from advisory to operational. The characteristic failure is not a rogue system doing something dramatic. It is authority accumulating quietly until accountability has nowhere to land.

The fix starts with three unglamorous artefacts: a list of what can act, a name against each one, and an honest comparison of granted authority versus intended authority. Do those this week, and you have closed the gap that "no one made the decision" falls through.

References

Further reading

This article is general guidance, not legal advice. How agent accountability maps onto your specific regulatory obligations is a question for your compliance function.

Where does your organisation actually stand?

The SAFE™ AI Readiness Assessment scores you across ten governance domains, including accountability and human oversight, the two that agentic AI stresses most. Under ten minutes, personalised maturity report.

Footnotes

  1. Gartner, Gartner Predicts 40% of Enterprise Apps Will Feature Task-Specific AI Agents by 2026, Up from Less Than 5% in 2025 (press release), 26 August 2025: https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025

  2. Orbilon Tech, AI Agents in Enterprise Apps: Gartner's Bold 2026 Shift (characterising the eightfold single-year jump), June 2026: https://orbilontech.com/ai-agents-in-enterprise-apps/

  3. Software Strategies Blog, Gartner's security forecast (noting Gartner's examples are autonomous response agents, not chatbots), March 2026: https://softwarestrategiesblog.com/2026/03/24/information-security-spending-2026/

  4. Paul Okhrem, Enterprise AI Agents Adoption Statistics 2026 (citing only 21% of organisations with a mature governance model and Gartner's over-40% project cancellation forecast for 2027): https://paul-okhrem.com/enterprise-ai-agents-statistics-2026/

  5. Deontic Policies for Runtime Governance of Agentic AI Systems (arXiv), on authority creep and diffuse accountability as dominant failure modes, including the "no one made the decision at all" formulation: https://arxiv.org/pdf/2606.19464

  6. Cloud Security Alliance, Agentic AI Governance: NIST Standards for Autonomous Systems (on NIST's February 2026 AI Agent Standards Initiative and agents treated as generic service accounts), March 2026: https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/03/governance-nist-ai-agent-standards-agentic-governance-v1-csa-styled.pdf 2

  7. Security Boulevard, A Guide to Agentic AI Risks in 2026 (on over-permissioned agent credentials, shadow agents, and the accountability trail gap), March 2026: https://securityboulevard.com/2026/03/a-guide-to-agentic-ai-risks-in-2026/ 2

  8. Trust Without Trusting: A Recomputable Trust Protocol for Autonomous Agents (arXiv), citing Singapore IMDA's January 2026 Model AI Governance Framework for Agentic AI: https://arxiv.org/pdf/2605.06738

  9. Cloud Security Alliance, as above (noting standards will take years to mature and organisations cannot wait): https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/03/governance-nist-ai-agent-standards-agentic-governance-v1-csa-styled.pdf

  10. Gartner via Infosecurity Magazine, Gartner: 40% of Firms to Be Hit By Shadow AI Security Incidents (2030 prediction; 69% of leaders reporting evidence or suspicion of shadow AI), November 2025: https://www.infosecurity-magazine.com/news/gartner-40-firms-hit-shadow-ai/