Back to perspectives
/Intellicon FDE Team

After a Successful POC: Four Management Challenges in the Second Phase of AI Agent Adoption

A successful POC is relatively easy; the real challenge begins in the second phase. Who can build Agents? Who can scale a skill across the organization? Who monitors spending? How can decisions be traced when something goes wrong? These questions are becoming even more urgent as the EU AI Act implementation timeline advances.

AI導入人機協作EgentWrX
After a Successful POC: Four Management Challenges in the Second Phase of AI Agent Adoption

A POC is usually not difficult. Choose a process with a clearly defined pain point, find two or three colleagues willing to participate, and build a usable AI Agent within two weeks—most companies can manage that. The hard part comes next: when the first Agent becomes thirty and the user base grows from three people to three departments, management challenges begin to emerge. And they are not technical challenges.

Who can build an Agent? Who can scale their approach across the organization? How much was spent this month? At which step was last week’s erroneous shipping notification decided? None of these four questions arise during the POC stage because someone is always there watching. Once the initiative scales, there are no longer enough people to watch everything.

Challenge 1: Who Can Build, and Who Can Shut It Down?

The first Agent is usually built by an enthusiastic colleague. By the tenth, a very practical question emerges: if that person leaves the company, who owns what they built?

EgentWrX ties Agents to a “role,” not to an individual. Each row in the list represents an “owner + role” pairing. The benefit of this design becomes clear during handovers: as long as the role remains, the Agent remains.

Permissions are divided among five built-in, read-only roles that cannot be modified: Owner, Administrator, Unit Manager, Unit Member, and Read-Only Member. In practice, the greatest determinant of risk is not the number of permissions but their scope. Unit-scoped roles can see only their own unit and its subunits. For companies with multiple sites or business units, this should be one of the first settings configured.

Each Agent has a default limit of eight sub-agents. Once that limit is reached, attempts to add another will fail without an error message. During the initial implementation phase, if someone reports that they “can’t add one,” check this number first. As the number of Agents grows, they can easily become unmanageable. We discussed this in Adding More AI Agents Does Not Mean Getting More Done.

Challenge 2: How Does One Person’s Approach Become an Organization-Wide Practice?

The most common outcome of a POC is not the Agent itself. It is that an experienced colleague has translated their decision-making logic into a set of rules. The next questions are: should those rules be scaled across the organization, and who is qualified to determine whether they are correct?

EgentWrX divides this process into two stages. Colleagues can create skills themselves in the front end, but organization-wide distribution requires approval through the back-end review queue. The purpose of this gate is not to add bureaucracy. It is to distinguish “one person’s habit” from “company policy”: the former remains on that individual’s Agent, while only the latter enters the skill library.

Memory accumulates automatically, so it is governed more strictly. Write policies are tiered by scope: memories within a user’s own Agent scope are stored directly; unit-scoped memories require review; and organization-wide memories require either review or approval, depending on the memory type. There is also one fixed exception that cannot be overridden by the policy table: memories containing personal data are always isolated.

The knowledge base has another important boundary. Data can be stored at the unit, project, or Agent level. The difference becomes apparent after an employee leaves: data stored at the unit level does not disappear when the employee departs, while data stored within the individual’s Agent scope does. The default retention period after departure is 90 days, and retention cleanup cannot be undone. The correct offboarding sequence is therefore to transfer ownership first and perform cleanup afterward.

Challenge 3: Who Is Monitoring the Money Being Spent?

EgentWrX divides budgets into four levels: tenant, unit, member, and Agent. Whichever level reaches its limit first blocks further activity. There are two pitfalls here, both hidden in the configuration details.

Setting a limit alone is equivalent to enabling alerts only. The “trigger action” at each level must be set to “block” for work to be stopped. Otherwise, reaching the limit merely generates an alert while work continues. The default alert threshold is 80%.

The AI credential budget is not a fifth-level gate. Exceeding it does not block work; it is reflected only in reports. The actual enforcement gates are the four budget levels described above.

Long-running work is also subject to three fixed values that cannot be adjusted: the system asks whether to continue after 60 minutes, the maximum runtime after continuation is 90 minutes, and the spending limit for a single job is USD 3. In practice, these values set the cost ceiling for any individual run.

Challenge 4: When Something Goes Wrong, Can You Trace It Back to the Exact Step?

This question is not about efficiency. It determines whether you are willing to place an AI Agent in a genuinely business-critical process.

EgentWrX audit logs cover 55 resource types and include a “Verify Integrity” function that recalculates the entire hash chain. During a cybersecurity review, you can demonstrate this directly to the reviewer and then provide the records through the Export Center. One detail is worth proactively explaining to customers’ security teams: when an administrator downloads audit records, the download itself is also recorded in the audit log.

Three limitations should be explained upfront rather than left for customers to discover themselves. First, the workflow option “Human approval required before handoff” cannot be enabled retroactively. Once a transition has been created, it must be removed and recreated to add this requirement. If there is any uncertainty about a step, add human approval from the start. Second, there is no single page that lists every pending transition requiring review across the organization. The overview shows only the total number; each item must then be located individually in the node diagram. Responsibility for “who checks these regularly” must therefore be explicitly assigned to a person. Third, a recurring task is automatically paused after five consecutive failures. It will not resume automatically and must be restarted manually.

Workflows also include execution safeguards. When a workflow is blocked, it usually indicates a problem with the process design; raising the limit is not the solution. This layer is part of the platform’s execution framework. In When Choosing an AI Agent Platform, Don’t Ask Only Which Model It Uses, we explain why it has a greater impact on reliability than model selection.

The Compliance Timeline Is Already Underway

You may choose to defer the four issues above, but the European Union’s timetable will not wait.

The European Union’s Artificial Intelligence Act (EU AI Act) entered into force on August 1, 2024, with obligations applying in stages. According to the timeline published by the European Commission, prohibited practices and AI literacy obligations have applied since February 2, 2025; governance rules and obligations for general-purpose AI models have applied since August 2, 2025; and the Act’s general date of application is August 2, 2026. Deadlines for high-risk systems were postponed through the 2026 legislative amendment known as the Digital Omnibus. The Commission’s page currently states that systems in certain high-risk areas will be subject to the Act from December 2, 2027, while high-risk systems embedded in regulated products will be subject to it from August 2, 2028.

Two of these obligations fall on deployers—the companies using AI—not only on vendors.

AI literacy (Article 4). The provision requires providers and deployers of AI systems to “take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf.” It also requires them to consider those individuals’ technical knowledge, experience, education, and training, as well as the context in which the systems are used. This obligation has applied since February 2025.

Human oversight and log retention (Article 26). Paragraph 2 requires deployers to assign human oversight to natural persons who have the necessary competence, training, and authority and receive the necessary support. Paragraph 6 requires deployers to retain logs automatically generated by high-risk AI systems for a period appropriate to the system’s intended purpose and for at least six months.

This is European Union legislation. Whether it applies directly to your company depends on whether the AI system or its outputs enter the EU market and must be assessed on a case-by-case basis. However, two considerations are directly relevant to Taiwanese manufacturers. First, when European customers incorporate compliance requirements into procurement terms, you must be able to produce evidence of role-based permissions, human approvals, and audit records. Second, audit questionnaires are already adopting a shared vocabulary. Although the U.S. National Institute of Standards and Technology’s AI Risk Management Framework (AI RMF 1.0) is voluntary, its four core functions—Govern, Map, Measure, and Manage—already provide the structure for many customer questionnaires.

The enterprise controls Anthropic listed when announcing Claude Enterprise follow the same pattern: single sign-on and domain management, role-based access control, audit logs, and SCIM.

Governance Is Not a Policy Document; It Is a Set of Configurable Parameters

At most companies, AI governance is a document. A document cannot block an API call that exceeds its budget, nor can it stop someone from writing personal data into shared memory.

To determine whether a platform can support governance, look for three capabilities that can be configured through the interface and recorded: who can do what (roles and scope, not merely usernames and passwords), which actions require human approval (rather than relying on reminders in prompts), and whether past actions can be traced (with records whose integrity can be verified). In EgentWrX, these capabilities correspond to back-end role permissions, the skill review queue and memory write policies, four-level budgets, the audit chain, and the Export Center.

Sequence also matters. Most problems encountered in the second phase result from boundaries that were not established during the first. Configuring the organization and its roles upfront is far easier than working backward through thirty Agents to determine who should have which permissions. This is why Intellicon Solutions divides implementation into a seed-team phase and an organizational-integration phase. The FDE Methodology addresses the first half of this same challenge.

A POC proves that the technology works. The second phase must prove that it can be governed.

FAQ

When will the EU AI Act begin to apply to our company?

The European Union’s Artificial Intelligence Act entered into force on August 1, 2024, and its general date of application is August 2, 2026. Prohibited practices and AI literacy obligations took effect earlier, on February 2, 2025. Following the 2026 legislative amendment, deadlines for high-risk systems were postponed to December 2, 2027, and August 2, 2028. Whether the Act applies directly to your company depends on whether the AI system or its outputs enter the EU market and must be assessed on a case-by-case basis. Even if it does not apply directly, European customers may still incorporate equivalent requirements into their procurement terms. In addition, the AI literacy obligation under Article 4 applies to both providers and deployers. Companies using AI therefore bear their own responsibilities and cannot shift all accountability to their vendors.

How long must AI operational records be retained?

Article 26(6) of the EU AI Act requires deployers of high-risk AI systems to retain logs automatically generated by those systems for a period appropriate to their intended purpose and for at least six months. In practice, setting a retention period longer than the statutory minimum is advisable because audits and customer reviews often look back more than six months.

Can employees build their own AI Agents? Should the company govern them?

Yes, but two situations must be distinguished. Practices used only by an individual can remain on that person’s own Agent, where the risk is limited. If those practices are to become organization-wide rules, they should undergo review. In EgentWrX, skills must be approved through the back-end review queue before they can be distributed more broadly. Memories are governed according to scope: unit-scoped memories require review, while tenant-scoped memories require review or approval. Memories containing personal data are always isolated.

How can we prevent AI usage costs from spiraling out of control?

Setting a limit does not necessarily mean work will be blocked. EgentWrX has four budget levels—tenant, unit, member, and Agent—and whichever level reaches its limit first blocks further activity. However, the “trigger action” at each level must be set to “block” for work to be stopped. Otherwise, the system will only generate an alert, with the default threshold set at 80%. The “AI credential budget” is also not an enforcement gate; exceeding it does not block work.

Should AI governance begin with policy documents or system configuration?

Both are necessary, but configuration should come first. A policy document cannot stop an actual operation. Configure roles and scope, actions requiring human approval, and audit records first. Then write the policy document to explain those settings. Only then will the document refer to controls that actually exist.

References

Enterprise trials are opening in stages

Want every employee to have their own AI teammate?

Places are limited. Our team will be in touch after you register.