Many AI projects follow a similar path. During the POC stage, few people are involved and spending is limited. The team simply wants to confirm whether the technology can deliver value, so it naturally does not want formal management processes slowing down progress. But once the POC produces results and the team prepares to scale the application—bringing customer data, ERP systems, payments, or external communications into scope—the project comes to a standstill. The reason is usually straightforward: the required permissions cannot be obtained, and management is unwilling to give the green light.
The problem is often that governance frameworks have not been established alongside the tools. Early efforts focus exclusively on proving what AI can do. Only when the solution is ready for production does the organization realize that it still lacks clear answers about who is accountable, which data may be used, and how incidents will be investigated. This is also why many successful POCs never make it into production.
The Risks Are Clear, but the Conditions for Approval Are Not Yet in Place
In September 2025, Gartner surveyed 360 IT application leaders. While 74% believed that AI Agents would become a new attack vector, only 13% were highly confident that their organizations had the right governance structures in place. When governance lags behind, only 15% of leaders are willing to consider, pilot, or deploy fully autonomous AI Agents.
An April 2026 survey by the Cloud Security Alliance (CSA), based on responses from 418 enterprises, revealed the same gap: 82% acknowledged that unknown AI Agents were operating within their IT environments, and 65% had experienced an AI Agent-related incident in the previous 12 months. Yet only 21% had established a formal decommissioning process.
From management’s perspective, these concerns are easy to understand. As long as AI Agents are limited to organizing information and offering recommendations, the risks are relatively manageable. Once they can access production systems, write data, or take external action, however, managers need to know whether problems can be investigated, whether the AI Agents can be stopped, and who will be held accountable.
Before Giving Approval, Management Will Ask These Five Questions
Before deciding whether to allow AI Agents to perform work in production, management typically asks five questions: How many AI Agents are currently running? How much are they costing? Where is the data going? How extensive are their permissions? Who is responsible for quality control?
These questions may sound basic, but in practice, most companies struggle to answer them fully. A team may be able to explain what a particular POC does, but not whether it is still running, which data it uses, or who has the authority to shut it down.
Unknown No. 1: How Many AI Agents Are Actually Running?
A company may know how many licenses it has purchased, but not necessarily which automated tasks are currently running, who is responsible for them, or when they were last validated. License counts are procurement records; active AI Agents are assets that require ongoing management. The two should not be treated as the same thing.
At a minimum, every AI Agent should have a record of its purpose, owning department, maintainer, data sources, permitted actions, and current status. Any AI Agent that accesses production data, runs automatically on a schedule, or is made available to other users must be registered and governed. If no one has been responsible for it over an extended period, it should be referred for decommissioning review rather than allowed to continue operating unattended.
Unknown No. 2: Where Is the Money Going?
A single AI Agent platform often serves multiple departments. If costs are visible only as a consolidated bill, it becomes difficult to determine which applications are worth continuing or which task has caused a sudden increase in spending. Costs must be allocated by department, task, and model, with notifications issued as spending approaches budget limits.
Every production task should have a designated budget owner. Each execution should also record which department should be charged, whether the result was successful, and whether the work had to be redone manually. When costs exceed a defined threshold, the organization can reduce execution frequency, switch to a less expensive model, or temporarily return the task to manual processing—instead of waiting until the monthly bill arrives to begin investigating.
Unknown No. 3: Where Did the Data Go?
If the system does not retain records of inputs, outputs, data destinations, and retention periods, the team can only rely on employees’ memories when responding to an audit or investigating an incident. When personnel change, the details they knew may disappear with them.
Governance rules must clarify at least four things: what qualifies as sensitive data, which models may be used, how records must be retained, and what content must never be entered. Before any production task is approved, its data sources, processing services, and output destinations must be mapped. Any change in vendor or model should trigger a new review. Auditors must also be able to use a task ID to retrieve every affected execution record.
Unknown No. 4: How Extensive Are the AI Agent’s Permissions?
AI Agents can rapidly read large volumes of data, make repeated system calls, and even write directly to databases. This differs from people performing actions one record at a time. If permissions are too broad, the potential impact can expand just as rapidly. Every AI Agent must have its own identity and receive only the minimum permissions required to complete its task.
In another 2026 CSA survey, 68% of respondent organizations could not clearly distinguish actions performed by people from those performed by AI Agents, while 74% reported that AI Agents were often granted more permissions than they needed.
In practice, enterprises must manage permissions to read, create, modify, delete, and transmit data externally as separate privileges. Irreversible actions, such as deleting records, making payments, or publishing content externally, must be submitted to designated personnel for approval. Credentials should also have shorter validity periods. At the same time, the system must retain records that clearly identify each action and who approved it, enabling subsequent investigation.
Unknown No. 5: Who Is Responsible for Quality Control When Something Goes Wrong?
When asked the same question about the same data on different days, AI may produce different answers. After policies are updated, an AI Agent may continue citing an outdated version. Even when a person corrects an error, the correction may not be fed back into the system. Without consistent validation and recordkeeping, teams cannot reliably determine whether the current version is truly ready for production.
Every production task must have representative test cases, acceptance criteria, failure records, version information, and designated notification recipients. The task owner should maintain a set of standard cases as well as high-risk exception cases. Tests must be rerun whenever prompts are modified, models are changed, knowledge bases are updated, or permissions are adjusted.
A new version should not be deployed unless it meets the required standards. Manual corrections must also be recorded as failures so that the team knows where problems have occurred and has a clear basis for improving the next version.
What Enterprises Really Lack Are Five Management Foundations
Taken together, these five questions show that what enterprises lack is not model capability, but five management foundations: an asset inventory, cost allocation, data-flow visibility, permission boundaries, and quality records. As long as any one of these remains undefined, management will find it difficult to allow AI Agents to move from “providing recommendations” to “taking action independently.”
The purpose of governance is to give enterprises the confidence to entrust more work to AI Agents. To achieve this, AI Agent platform administrators must have continuous visibility into how many AI Agents are currently running and what stage each one is in; whether usage reports can be broken down by department and purpose to show how much has been spent; which AI Agents can access the public internet and which domains they connect to; and which databases can be accessed and by whom.
The level of detail with which an enterprise can answer these questions reflects the maturity of its governance. Only when management can see the full scope, retrieve the relevant records, and know when to stop an AI Agent can that AI Agent move from POC into production operations.
This article is excerpted from Intellicon Solutions’ white paper, Agent-Ready: AI Applications in Taiwan’s Manufacturing Industry. The full white paper explains how to approach governance approval, workflow integration, and organizational adoption. It also includes a 12-question self-assessment, three of which specifically evaluate governance readiness.
References
- Gartner, Gartner Survey Finds Just 15% of IT Application Leaders Are Considering, Piloting, or Deploying Fully Autonomous AI Agents (2025)
- Cloud Security Alliance, New CSA Survey Reveals 82% of Enterprises Have Unknown AI Agents in Their Environments (2026)
- Cloud Security Alliance, More Than Two-Thirds of Organizations Cannot Clearly Distinguish AI Agent from Human Actions (2026)