Risk in the Agent Era
The governance challenge with AI agents is not the first agent. It is the hundredth. Agents do the work rather than assist with it, and organisations need an operating model that can scale with them.
A couple of years ago, most AI conversations started in roughly the same place.
Someone had seen ChatGPT. IT had heard about Microsoft Copilot. Claude was all over the news. A pilot was proposed. The organisation wanted to understand the risks before deciding what to do next.
Fast forward to today and the conversation has changed. Most organisations are no longer asking whether AI belongs in the workplace. The question is increasingly where it goes next.
For many, that next step is agents. Not AI that answers questions. AI that performs work.
And that changes the governance conversation entirely.
What makes agents different?
We've all become comfortable with AI assistants. Whether it's Microsoft 365 Copilot, ChatGPT or Claude, the interaction is broadly the same.
You ask a question. The AI assistant provides an answer. You decide what happens next.
That model is now evolving.
Instead of asking AI to help with a task, organisations are beginning to give AI the task itself. An agent can retrieve information, interact with systems, trigger workflows, update records and continue working until the objective has been completed.
The difference sounds subtle. In reality, it's significant. An assistant helps somebody do their job. An agent increasingly does the job on their behalf.
The risk isn't what most organisations think it is
When agents first appear, most organisations focus on the individual use case.
- Can this agent be trusted?
- Should it have access to this system?
- What happens if it makes a mistake?
Those are sensible questions. They're just not usually the most important ones.
The most significant governance challenge isn't the first agent. It's what happens after the first agent succeeds. Because successful agents create demand.
One team finds a useful use case. Another team wants one too. A third department starts experimenting. Someone connects an agent to a line-of-business application. Another connects one to a workflow. A pilot becomes a programme. A programme becomes a platform.
And that is where the real governance challenge begins.
The challenge isn't one agent. It's one hundred.
The organisations we're speaking to are rarely worried about the first few agents.
The first few are usually well understood. They've been reviewed. They have sponsors. People know why they exist. The challenge comes later. It comes when adoption accelerates.
Over time, organisations stop managing a handful of individual agents and start managing an estate. That's a fundamentally different problem.
Questions that felt simple become surprisingly difficult to answer.
- How many agents do we actually have?
- Who owns them?
- Which ones are business critical?
- Which systems do they access?
- Which agents have changed since they were approved?
- What happens if the person who built one leaves?
- Which agents should be retired?
Once an organisation reaches that point, the conversation is no longer about technology.
It's about governance. It's about ownership. It's about having an operating model that can scale.
Why governance matters
Governance has a branding problem. People hear the word and think bureaucracy.
In reality, good governance is usually what allows organisations to move faster. Without governance, every new agent becomes a debate.
With governance, people understand where agents should be built, who owns them and what level of oversight is required.
The organisations that seem to be scaling agents most successfully aren't necessarily taking more risk. They've simply established enough structure to move with confidence.
The Tenzing Agent Governance Framework
Through our work helping organisations adopt Microsoft AI, we've found that successful agent governance tends to be built across seven connected capabilities:
- Secure Citizen Development
- Just Enough Access
- Human Oversight
- Enduring Data Protection
- Managed Lifecycle
- Complete Visibility
- Attack Resistance
Together these provide a framework, underpinned by an AI Governance Council, for scaling agents without accumulating issues.
Looking ahead
Most organisations are still early in their agent journey. Some are experimenting. Some are building. Some are already starting to scale.
Wherever they are, the same reality applies. The challenge isn't building the first agent. The challenge is understanding what happens when you've built the hundredth.
The organisations that establish an agent operating model now will move faster tomorrow.
The ones that wait will eventually find themselves trying to retrofit governance into an estate that has already grown beyond what they can easily see.
30-Minute Agent Governance Review
If you're exploring Copilot Studio, building agents or trying to understand what governance should look like in practice, we offer a 30-minute Agent Governance Review. You'll leave with practical recommendations and a clearer path forward.
Speak with Our AdvisorsYour Path to Secure AI Starts Here.
