You may have started hearing the term Agentic AI.
Unlike tools such as ChatGPT that generally wait for you to ask a question, an AI agent can be given a goal and allowed to take actions to achieve it.
That could include accessing systems, searching information, updating records, sending emails, contacting customers or triggering other processes.
Exciting? Absolutely.
But there’s an important question organisations need to ask before somebody enthusiastically switches one on:
Who is accountable for what the AI agent does?
Because it isn’t the AI.
The risk you may not realise you’ve accepted
Imagine somebody in your organisation connects an AI agent to your CRM, Microsoft 365 environment or customer database.
They give it permission to read information, update records and communicate with customers.
Suddenly this isn’t simply an AI tool helping an employee.
You’ve effectively created a digital worker with access to organisational systems and data.
So who decided:
- what information it can access?
- what actions it can take?
- when a human must approve something?
- how its activity will be monitored?
- what happens if it gets something wrong?
- and who can switch it off?
If the answer is “we hadn’t really thought about that”, you may already have a governance problem.
AI doesn’t remove accountability
One principle is worth remembering:
You can delegate a task to AI. You cannot delegate accountability to it.
If an AI agent mishandles personal data, sends inappropriate communications, makes an incorrect decision or takes an action it shouldn’t have taken, the organisation may still have to explain what happened and why appropriate controls weren’t in place.
That makes Agentic AI a business governance issue not simply an IT issue.
Before giving an AI agent the keys…
At a minimum, organisations should know:
What is it allowed to do?
Define its purpose and boundaries.
What can it access?
Give it only the systems and information it genuinely needs.
What can it do without permission?
Decide where human approval is required.
Can we see what it has done?
Make sure important activity is logged and monitored.
When must it stop and ask a human?
Create clear escalation points.
Can we stop it quickly?
There should always be a way of suspending an agent if something goes wrong.
And if personal data is involved, your existing data protection obligations haven’t disappeared simply because AI is doing the processing.
Don’t wait until somebody asks, “Who approved this?”
Agentic AI could be hugely valuable. Used well, it could remove repetitive work and allow people to concentrate on the things humans do best.
But organisations shouldn’t discover after something has gone wrong that an AI agent had access or authority nobody realised it had been given.
So if Agentic AI is starting to appear in conversations in your organisation, ask one question early:
“Before we let it do anything, who is responsible for governing what it is allowed to do?”
Because with Agentic AI, capability without governance can very quickly become accountability without warning.
AskMrsWatson.com, because it’s OK to ask!