The EU AI Act became fully applicable on August 2, 2026. It does not directly regulate Taiwanese companies, but it does regulate their European customers and the brands they supply—and contractual requirements will flow down the supply chain. That same month, Deloitte published a survey of 501 U.S. business executives: 72% of organizations were held back by the lack of a unified, accessible data foundation, while 70% struggled to trust and govern AI Agent.
These two developments point to the same conclusion: the criteria for selecting an enterprise AI Agent platform have changed. Three years ago, the question was whether the model was accurate. Today, the questions are who can do what, whether actions can be traced, and whether the system can stop things when something goes wrong.
Why “Which Model Should We Choose?” Is No Longer the Main Question
Model capabilities are now a rapidly moving baseline. The model that leads today may be replaced six months from now, but the platform’s permission structure, knowledge-base segmentation, and audit logs will not change with it. We discussed this in When Choosing an AI Agent Platform, Don’t Ask Only Which Model It Uses: the model is a component; what determines success or failure is the layer around it.
Governance frameworks take the same view. NIST’s AI Risk Management Framework (AI RMF 1.0, released on January 26, 2023) divides risk management into four functions: Govern, Map, Measure, and Manage. Of these four, only Measure is directly related to model performance. The other three concern organizational structures and processes. The European Commission’s requirements for high-risk AI systems follow the same logic, explicitly calling for “logging of activity to ensure traceability of results” and “appropriate human oversight measures”—records and human oversight, not model scores.
That is why not one question in the following checklist is about the model. All nine are about boundaries.
Nine Questions to Bring to the Meeting
The questions are ordered by how quickly a wrong answer will cause pain, not by importance.
1. Are Front-End and Admin Permissions Managed by the Same System?
You need to hear a clear “yes” or “no.” If they are separate systems, ask whether the same person can be granted access to only one of them. This determines whether a department head can manage usage within their own unit without being able to change company-wide policies. With only one permission system, you will inevitably grant either too much access or too little.
The cost of an unclear answer: Three months into implementation, you discover that “the people who can change the settings” and “the people who should change the settings” are not the same group—and fixing it requires reassigning everyone’s roles.
2. Who Can Roll Out an AI Skill Across the Company?
It is a good thing when employees turn their own methods into reusable skills. The question is what happens next: can they press a button and apply that rule across the entire company? Ask whether there is a review gate, who conducts the review, and what happens if the skill is rejected.
The cost of an unclear answer: One department’s exceptional practice becomes the company-wide default. It is usually discovered only after another department follows it and something goes wrong.
3. Can the Knowledge Base Be Segmented by Organization, Keeping HR Data Separate From Sales Quotes?
Do not merely ask whether the platform “supports permissions.” Ask what unit it uses for segmentation: individual, department, or project. Then ask one more question: can the same document belong to two scopes at once, and who decides where it belongs?
The cost of an unclear answer: Salary structures or customer negotiation records appear in the search results of people who should not see them. Incidents like this do not generate error messages. They simply get discovered one day.
4. What Happens to an Employee’s AI Assets When They Leave?
This is one of the least frequently asked questions, yet it is among the first issues companies encounter. Ask what happens to the knowledge they uploaded, the skills they created, and the automated schedules they configured. Do these remain or disappear after departure? Is there a retention period? Once deleted, can they be restored?
The cost of an unclear answer: A senior salesperson leaves, and the quoting logic accumulated by their Agent over two years disappears with their account. Or the opposite happens: their personal notes remain in the system and continue to appear in other people’s searches. We have encountered both scenarios.
5. Can You Insert a Human Approval Step Midway Through a Process?
Ask three things: whether an approval gate can be configured, whether it can be added later, and who is authorized to release a blocked process. The second question is particularly important. If an approval gate can be configured only when a workflow is created, adding one later may require dismantling and rebuilding the entire workflow.
The cost of an unclear answer: An automated process sends out incorrect information while no one is watching. What has been sent cannot be recalled, and companies usually realize they need an approval gate only after this has happened.
6. Which External Services Can the AI Access, and Can You Configure an Allowlist?
Ask about the default setting: is everything allowed by default and blocked individually, or is everything denied by default and approved individually? These two defaults have very different cybersecurity implications. Also ask whether the security team can export a list of every external destination the system may connect to directly from the interface.
The cost of an unclear answer: You must compile the list manually during a security review, and the next time someone adds an integration, that list becomes outdated.
7. Can Budgets Be Set at Multiple Levels, and Does Exceeding Them Trigger a Block or a Notification?
Ask how many levels are supported—company, department, individual, and individual Agent—and then ask the most important question: what is the default action when a limit is exceeded? The word “limit” means different things in different systems. Some systems block further usage, while others merely send a notification. Make sure you know which one it is.
The cost of an unclear answer: Halfway through the month, you receive a notification saying that one department has already consumed three times its budget.
8. Can Audit Logs Be Exported, and Can You Prove They Have Not Been Altered?
Exporting is the baseline requirement. The second part is what matters. If someone with sufficient permissions can quietly modify an audit log, its value during security reviews and dispute investigations is close to zero. Ask whether the platform provides an integrity-verification mechanism.
The cost of an unclear answer: When a customer or auditor requests activity records, all you can provide is a file that cannot prove its own authenticity. “Traceability” is precisely what the EU requires for high-risk systems.
9. Cloud, On-Premises, or Hybrid?
This is usually the first question asked in a meeting, but it appears last here for a reason: if a platform cannot clearly answer the previous eight questions, deploying it on-premises will not make those answers any clearer. Deployment location determines where the data resides. It does not determine who can act on it.
The cost of an unclear answer: You treat on-premises deployment as a security solution, only to purchase a system installed in your own data center where anyone can still publish a knowledge base to the entire company.
A One-Sentence Test
After asking all nine questions, consider the overall pattern. If most answers are “individual users can configure that themselves,” you are buying a tool. If most answers are “your administrators decide that in the admin console,” you are buying a platform. Both have appropriate use cases, but only the latter can support company-wide adoption at scale.
This is also why process readiness matters more than technical readiness. In Deloitte’s survey, 74% of organizations believed that nearly half of their processes would need to be redesigned around AI Agent within four years. Yet only 16% currently said their business processes were ready, while another 5% described themselves as highly prepared. We discuss this further in 74% Need to Redesign Their Processes, but Only One in Five Are Ready.
The EgentWrX Approach
For the nine questions above, some platforms place the controls in the admin backend, while others leave them to individual users. With EgentWrX, Intellicon Solutions has chosen to put all of them in the Admin Console. Administrators define the boundaries, while front-end users focus solely on producing work outcomes.
Permissions are managed through two genuinely independent systems: User App permissions govern the front end, while Admin Console permissions govern the backend. A user with only front-end permissions will be denied access to the backend. Employees can create their own skills in the front end, but rolling them out across the company requires approval through the backend review queue. Knowledge-base scopes are divided into three types: organizational unit, project, and Agent. One practical distinction is worth remembering: data stored within an organizational-unit scope does not disappear when an employee leaves, while data stored within a personal Agent scope does. The default retention period after departure is 90 days, and cleanup actions cannot be reversed once executed. The standard practice is therefore to transfer ownership before the employee leaves.
There is one limitation to the workflow setting that requires human approval before a handoff, and we disclose it proactively to customers: it cannot be added retroactively. The relevant workflow segment must be removed and rebuilt, so an approval gate should be included from the beginning whenever there is uncertainty. The outbound allowlist denies all connections by default and approves domains individually. The “Security” tab in the integration settings provides the exact list the security team needs. Integrations connected to internal databases are read-only and cannot write data.
Budgets can be set at four levels: tenant, organizational unit, member, and Agent. Usage is blocked as soon as any one level reaches its limit, but the “trigger action” must be set to “block” for the system to actually stop usage. Setting only a limit produces an alert rather than a hard stop. Audit logs cover 55 resource types, and the “Verify Integrity” function can recalculate the entire hash chain on the spot. The act of an administrator downloading audit records is itself recorded in the audit log.
The risk described in Question 2—one person’s practice becoming the company-wide default—takes a similar form when work is delegated among subagents. In Deploying More AI Agent Does Not Mean Getting More Work Done, we explain why adding more hands does not necessarily produce more results.
FAQ
How should enterprises compare AI Agent platforms? What criteria should they evaluate?
Evaluate governance capabilities before model capabilities. In practice, there are nine criteria: separation of front-end and admin permissions, review mechanisms for rolling out skills, segmentation and isolation of knowledge bases, handling of assets when employees leave, human approval gates within workflows, allowlists for external connections, multi-level budgets and overage behavior, audit-log exports and integrity verification, and deployment models. Model capabilities change every six months. These nine factors do not.
What is the difference between an AI Agent platform and a general-purpose AI chat tool?
The difference comes down to three things: whether it can retain company rules over the long term through knowledge bases and persistent memory, whether it can turn repetitive work into repeatable tasks, and whether human approval can be inserted midway through a process instead of letting it run to completion without oversight. Without the third capability, it is simply a chat window that is better at retrieving information.
Does the EU AI Act affect Taiwanese companies?
The Act entered into force on August 1, 2024, and became fully applicable on August 2, 2026. It uses four risk categories: unacceptable risk, high risk, transparency risk, and minimal or no risk. Taiwanese companies are not directly subject to its jurisdiction, but its requirements for high-risk systems—including traceable activity records and appropriate human oversight—will reach the supply chain through the contractual terms of European customers. In addition, the AI literacy obligation under Article 4 applies to both providers and deployers, meaning users of AI systems also bear responsibility.
When selecting a platform, will our data be used to train models?
Ask this question at two levels: the platform itself and the model provider connected behind it. For example, OpenAI’s API documentation states that data is not used to train models by default unless the customer explicitly opts in. Abuse-monitoring logs are retained for up to 30 days by default, and eligible organizations may apply for Zero Data Retention. At the platform level, ask whether these settings are passed through unchanged or whether the platform retains an additional copy of the data.
Can small and medium-sized businesses without an IT department use this checklist?
Yes, but the order should be adjusted. Companies without dedicated IT staff usually encounter Questions 2, 4, and 7 first: uncontrolled skill rollouts, assets disappearing when employees leave, and runaway usage. Questions 1, 3, and 8 can be addressed more seriously once the organization grows beyond three departments. We discuss the appropriate order of evaluation in Enterprise AI Anxiety Is Not the Same as Genuine Demand.
References
- The path to agentic transformation — Deloitte Insights, August 12, 2026. The survey covered 501 U.S. business leaders ranging from senior managers to C-suite executives and was conducted between April and June 2026. The figures cited in this article—72%, 70%, 74%, 16%, and 5%—all come from this report.
- AI Risk Management Framework — National Institute of Standards and Technology (NIST). AI RMF 1.0 was released on January 26, 2023. Its four core functions are Govern, Map, Measure, and Manage, and it is explicitly described as being “intended for voluntary use.”
- Regulatory framework for AI — European Commission. This source describes the four risk categories and the obligations for high-risk systems, including “adequate risk assessment and mitigation systems,” “logging of activity to ensure traceability of results,” and “appropriate human oversight measures.” The Act entered into force on August 1, 2024, and became applicable on August 2, 2026.
- Article 4: AI Literacy — EU AI Act Explorer, maintained by the Future of Life Institute. Article 4 requires providers and deployers to ensure that their staff possess a sufficient level of AI literacy.
- Data controls in the OpenAI API — Official OpenAI developer documentation. It states that API data is “not used to train or improve OpenAI models (unless you explicitly opt in)” and that abuse-monitoring logs are retained for up to 30 days.
