The agent era didn’t arrive with a clear announcement. It crept in through Salesforce Agentforce, through Microsoft’s Copilot Actions, through a dozen enterprise software vendors quietly adding ‘agentic’ to their feature lists sometime in 2025. By mid-2026, the question isn’t whether autonomous AI agents are being used in real business workflows - they clearly are - it’s whether anyone deploying them has seriously thought through what they’re authorised to do.
This isn’t a hypothetical governance problem. Agents that can browse, write, send emails, execute code, and interface with APIs are already operating inside companies that haven’t written a single internal policy about them. The gap between capability and governance here is wider than it was with any previous enterprise software wave, because agents don’t wait for a human to click a button. That’s the point of them.
The technical community tends to frame this as an alignment problem - getting the model to do what you intend. But the more immediate issue is organisational. Who approved the agent’s scope? What happens when it takes an action that falls just outside its intended boundary - like cc’ing someone on an email it wasn’t supposed to send, or querying a database it technically had credentials to access? These aren’t catastrophic failures. They’re the mundane, low-drama mistakes that accumulate quietly and create liability.
Enterprise vendors have a financial incentive to underplay this. Selling ‘autonomous’ as a feature is easier than selling ‘autonomous within a carefully reviewed permission framework your legal team should probably sign off on.’ The marketing and the reality are running in opposite directions.

The Accountability Gap
When a human employee makes a bad call, there’s a clear chain of responsibility. When an agent does, that chain gets murky fast. Was it the model? The integration layer? The person who configured the agent’s instructions three months ago and has since left the company?
This is where the current deployment pace creates genuine organisational risk, not theoretical AI-risk-paper risk. The companies that will handle this era best are probably the ones treating agent onboarding the way they treat employee onboarding - with defined roles, limited initial access, and a documented escalation path. Most aren’t doing that yet.
The tools are real. The workflows are real. The policies are, at most companies, still a draft in someone’s Google Doc.