top of page

AI Governance Is Becoming Agent Governance

Models generate. Agents act. Governance must follow the action.



By 2027, Gartner expects 40 percent of enterprises to demote or decommission autonomous AI agents. Not because the agents stopped working. Because of governance gaps that surfaced only after a production incident. The analyst behind the forecast, Shiva Varma, put the cause plainly. Enterprises treat agent governance as a binary, either locked down or fully trusted, and that is the root of the failure.


That number deserves a second look, because a different Gartner forecast is easy to confuse with it. In June 2025, Gartner predicted that more than 40 percent of agentic AI projects would be canceled by the end of 2027, citing escalating costs, unclear business value, and inadequate risk controls. The two are not the same. One is about projects that never reach production. The other is about agents that reach production, run for a while, and then get pulled back because no one designed the controls to hold them. The second problem is the one worth your attention.

The Governance Object Changed Because The Object Started Acting



For years, AI governance meant model governance. Fairness, explainability, validation, bias, drift, data lineage, human review, regulatory mapping. That work still matters. But agentic AI changes what governance is pointed at.

A model produces an answer. An agent initiates work. It calls tools, reaches into systems, updates records, triggers workflows, talks to customers, and hands tasks to other agents. The governance object moves from output to authority.


The most important word in Gartner’s definition of an AI governance platform is not responsible. It is agents. Gartner describes these platforms as systems that centrally define, approve, and enforce responsible AI policies across AI use cases, applications, and agents. Once software acts under delegated enterprise authority, governance cannot stop at policies, assessments, and documentation.


The question is no longer only whether the model is acceptable. It is what the enterprise has authorized the agent to do.

Model Governance is Necessary and Not Sufficient

Model governance asks whether the model is fit for purpose. Agent governance asks whether the system is fit to act. Those are different questions, and the second does not reduce to the first.



A model-risk review examines performance, bias, explainability, drift, training data, and monitoring. An agent adds questions a model review never had to answer. What tools can it invoke? What systems can it reach? What transactions can it start? What decisions can it make on its own? When must it escalate, and how does anyone stop it?


This is why agent risk is contextual. The same model can be low-risk answering questions and high-risk the moment it is wired to a CRM with write access. Gartner is precise on the point. Failures cluster when organizations fail to distinguish between an agent’s ability to act and the scope of access it is granted. A weak model with write access can do more damage than a strong model with none.

Agent Governance is Delegated Authority Governance

An enterprise agent is not a feature. It is software operating under a mandate. That mandate is explicit or implicit, governed or unmanaged, narrow or broad, revocable or effectively permanent. In most organizations, no one has written it down.


Agent governance is, at its core, the governance of delegated authority.


That is where the governance conversation must move. Agent governance is, at its core, the governance of delegated authority. It must settle who or what the agent is, what business purpose it is authorized to pursue, which tasks and systems are in bounds, what data and tools it can touch, how much autonomy it holds, when it must stop and ask, what gets logged, and how its authority can be narrowed or removed.


The enterprise does not simply deploy an agent. It delegates authority to it. An agent without an owner is not automation. It is unmanaged authority.

Runtime Governance Stops Being Optional

Traditional governance runs on point-in-time review. Approve the use case, document the control, test the model, record the decision, monitor on a schedule. For agents, that cadence is too slow.



Gartner has said as much. AI governance platforms, in its description, enforce policy at runtime, monitor continuously, detect anomalies, and prevent misuse, because point-in-time audits are not enough once AI systems make autonomous decisions and handle sensitive data. The Varma forecast lands on the same point from the other direction. The agents that get demoted are caught by production incidents, not by review boards. A control that operates only before deployment cannot catch behavior that emerges after it.


A log does not solve this on its own. A log is evidence after the fact. The platform must observe, constrain, escalate, and intervene while the agent is working.

The Control Stack for Agents

A credible agent governance model needs layers, and Gartner has already published much of the scaffolding. Its proportional-governance approach sorts agents by how much they can do and matches the controls to the tier.


At the lowest tier sit observe agents, with read-only access and output visible only to the requester. Summarization, retrieval, code explanation. Controls stay light and targeted. Above them, advise agents generate recommendations and drafts while a human reviews and executes. Higher still, agents that can write data, send communications, or change configurations, but only after explicit human approval for each action. At the top, autonomous agents that execute on their own. Gartner reserves its heaviest controls for this tier: continuous monitoring, enforced guardrails, rapid rollback, and circuit breakers that halt the agent when it crosses a threshold.


Wrap that tiering in the rest of the stack. An agent registry that records the agent, its owner, purpose, model, tools, data, and environment. A distinct non-human identity, so the agent’s actions are not hiding inside a human user’s account. Permission boundaries that define what it can read, write, and trigger. Runtime policy enforcement. Human intervention points for high-consequence actions. An audit trail that captures tool calls, prompts, decisions, exceptions, and handoffs. And revocation, the ability to pause, narrow, or terminate authority on demand.


This is where AI governance stops looking like policy administration and starts looking like access governance, operational resilience, and security. If an agent can act, it needs an identity. If it has an identity, it needs permissions. If it has permissions, it needs a way to take them back.

Human in the Loop is Not a Control by itself

Many organizations still treat human approval as the primary control. That works for low-volume, high-significance decisions. It breaks the moment agents generate a steady stream of approval requests or run background tasks inside complex workflows.



The problem is not whether humans matter. It is where the human belongs in the design. Humans should set the mandate, the risk appetite, the boundaries, the escalation rules, and the accountability. They should not be asked to hand-approve every low-level action, because that is how you get fatigue and rubber-stamping. Gartner makes the same point inside its approval tier. Human review counts only if it stays a meaningful control. A reviewer clicking approve forty times an hour is not a control. It is a formality with a person attached.

The Platform Market will be Judged on Agents

The market is moving toward this. Gartner’s definition already reaches past use cases and applications to agents, and its 2026 Magic Quadrant for AI Governance Platforms, published in June, frames these systems as the place where trust, risk, security, and runtime control converge for AI.


ServiceNow AI Control Tower is one read on where the category is heading. ServiceNow positions it to find every AI agent, model, and identity running across the enterprise, govern their risk, enforce compliance, monitor runtime performance, measure AI value, and connect that control back to the workflow and the CMDB. The enhanced capabilities are still maturing. ServiceNow has the expanded offering in its Innovation Lab as of May, with general availability expected in August, so the positioning runs a little ahead of the production reality.


The acquisitions around it sharpen the thesis without collapsing into a single product. Veza brings identity and access governance, AI-native visibility into who and what has access across human, machine, and AI agent identities. Armis brings connected-asset visibility and cyber exposure across OT, IoT, and cloud. Moveworks strengthens the agentic front door and the employee work experience. ServiceNow ties the Armis and Veza pieces together in a separate May launch, Autonomous Security & Risk, built to govern every AI agent, identity, and connected asset.


That acquisition path is worth sitting with. A governance vendor buying identity intelligence and asset visibility is not chasing better responsible-AI documentation. It is building toward a different question. Which agent has access to what, through which identity, against which asset, under what authority, and with what ability to intervene or revoke.


The platform question is no longer whether you can document responsible AI. It is whether you can govern delegated action across the enterprise.

The Operating Model must Assign Ownership

None of this sits cleanly inside the AI office. Agents touch workflows, systems, customers, employees, vendors, data, and regulated processes, which means the decision rights must be shared. The business owner defines the outcome and carries accountability for it. Technology owns architecture, integration, and performance. Risk and compliance set the controls, the risk appetite, and the evidence expectations. Security and identity govern permissions, credentials, and revocation. Data and privacy govern use, retention, and exposure. Audit checks whether any of it is designed and operating the way the documents claim.


Agent governance fails the same way every time. Everyone assumes someone else owns the agent.

From Responsible AI to Responsible Delegation

AI governance is becoming agent governance because the risk has moved. It is no longer confined to whether a model produces a good or fair output. The harder question is what the enterprise has allowed software to do in its name, and whether it can prove control while the software is doing it.



That is why identity, permissions, scope, runtime enforcement, logs, intervention, and revocation are becoming the working vocabulary of AI governance. The 40 percent that Gartner expects enterprises to pull back over the next two years will not be saved by better model documentation. They will be undone by authority no one scoped and no one could revoke in time.


Models generate. Agents act. Governance must follow the action. Agentic AI does not just ask for responsible AI. It asks for responsible delegation.

About the Author


Alan L. Paris is an AI and financial services expert with deep experience in risk, compliance, and AI governance. He previously led Financial Services Risk and Compliance Architecture at ServiceNow and currently serves as an Adjunct Professor at the University of San Francisco School of Management.


bottom of page