Tenzing logoTenzing
    Back to Insights
    AI Governance

    Risk in the Agent Era

    8 min read
    Share:

    The governance challenge with AI agents is not the first agent. It is the hundredth. Agents do the work rather than assist with it, and organisations need an operating model that can scale with them.

    Tenzing title slide reading Risk in the Agent Era, with the line the challenge isn't one agent, it's one hundred, set over a dark navy field of scattered dots.

    A couple of years ago, most AI conversations started in roughly the same place.

    Someone had seen ChatGPT. IT had heard about Microsoft Copilot. Claude was all over the news. A pilot was proposed. The organisation wanted to understand the risks before deciding what to do next.

    Fast forward to today and the conversation has changed. Most organisations are no longer asking whether AI belongs in the workplace. The question is increasingly where it goes next.

    For many, that next step is agents. Not AI that answers questions. AI that performs work.

    And that changes the governance conversation entirely.

    Timeline showing the three phases of AI adoption: Adopt in the early years, Embed today and Act next, where agents take on the work itself.

    What makes agents different?

    We've all become comfortable with AI assistants. Whether it's Microsoft 365 Copilot, ChatGPT or Claude, the interaction is broadly the same.

    You ask a question. The AI assistant provides an answer. You decide what happens next.

    That model is now evolving.

    Instead of asking AI to help with a task, organisations are beginning to give AI the task itself. An agent can retrieve information, interact with systems, trigger workflows, update records and continue working until the objective has been completed.

    The difference sounds subtle. In reality, it's significant. An assistant helps somebody do their job. An agent increasingly does the job on their behalf.

    Side by side comparison of an assistant, which waits to be asked and needs checking at every step, and an agent, which is given a job and completes it end to end.

    The risk isn't what most organisations think it is

    When agents first appear, most organisations focus on the individual use case.

    • Can this agent be trusted?
    • Should it have access to this system?
    • What happens if it makes a mistake?

    Those are sensible questions. They're just not usually the most important ones.

    The most significant governance challenge isn't the first agent. It's what happens after the first agent succeeds. Because successful agents create demand.

    One team finds a useful use case. Another team wants one too. A third department starts experimenting. Someone connects an agent to a line-of-business application. Another connects one to a workflow. A pilot becomes a programme. A programme becomes a platform.

    And that is where the real governance challenge begins.

    The challenge isn't one agent. It's one hundred.

    The organisations we're speaking to are rarely worried about the first few agents.

    The first few are usually well understood. They've been reviewed. They have sponsors. People know why they exist. The challenge comes later. It comes when adoption accelerates.

    Over time, organisations stop managing a handful of individual agents and start managing an estate. That's a fundamentally different problem.

    Questions that felt simple become surprisingly difficult to answer.

    • How many agents do we actually have?
    • Who owns them?
    • Which ones are business critical?
    • Which systems do they access?
    • Which agents have changed since they were approved?
    • What happens if the person who built one leaves?
    • Which agents should be retired?
    Diagram contrasting a pilot of five chosen agents with a much larger grid representing the hundreds of agents across a business that were never planned for.

    Once an organisation reaches that point, the conversation is no longer about technology.

    It's about governance. It's about ownership. It's about having an operating model that can scale.

    Why governance matters

    Governance has a branding problem. People hear the word and think bureaucracy.

    In reality, good governance is usually what allows organisations to move faster. Without governance, every new agent becomes a debate.

    With governance, people understand where agents should be built, who owns them and what level of oversight is required.

    Two panels comparing scattered, unmanaged agents without governance against a neat, ordered grid of agents with governance in place.

    The organisations that seem to be scaling agents most successfully aren't necessarily taking more risk. They've simply established enough structure to move with confidence.

    The Tenzing Agent Governance Framework

    Through our work helping organisations adopt Microsoft AI, we've found that successful agent governance tends to be built across seven connected capabilities:

    • Secure Citizen Development
    • Just Enough Access
    • Human Oversight
    • Enduring Data Protection
    • Managed Lifecycle
    • Complete Visibility
    • Attack Resistance

    Together these provide a framework, underpinned by an AI Governance Council, for scaling agents without accumulating issues.

    Seven pillars of a well governed agent strategy shown as cards, from secure citizen development to attack resistance, sitting above an AI governance council band.

    Looking ahead

    Most organisations are still early in their agent journey. Some are experimenting. Some are building. Some are already starting to scale.

    Wherever they are, the same reality applies. The challenge isn't building the first agent. The challenge is understanding what happens when you've built the hundredth.

    The organisations that establish an agent operating model now will move faster tomorrow.

    The ones that wait will eventually find themselves trying to retrofit governance into an estate that has already grown beyond what they can easily see.

    30-Minute Agent Governance Review

    If you're exploring Copilot Studio, building agents or trying to understand what governance should look like in practice, we offer a 30-minute Agent Governance Review. You'll leave with practical recommendations and a clearer path forward.

    Speak with Our Advisors

    Your Path to Secure AI Starts Here.