28.8 C
Casper
Friday, September 4, 2026

AI Agents Are Acting on Their Own. Who’s Accountable?

spot_img

Must read

New research finds that a third of firms use AI in critical workflows, but most have never tested what happens when an agent acts on its own.

Optro, an AI-powered GRC intelligence platform, announced the results of a new report, “When AI Leaves the Chat and Enters the Workflow.” As organizations shift from conversational generative AI to autonomous AI agents acting within core workflows, the report argues that the question enterprises spent the past two years answering — can we trust what AI produces? — is no longer the right one. The harder question, it says, is largely unanswered: how do you govern something that acts on its own?

Adoption isn’t waiting for governance to catch up. One in three organizations already use AI in critical resilience workflows, yet agentic AI failure — loss of control or autonomous decision-making errors — is the disruption scenario they test least; 30% have never tested for it at all. Distributed ownership, periodic review cycles and policy-based controls already strain under supervised AI, according to the report, and are structurally unequipped to govern systems acting autonomously at machine speed. The report’s central argument is that the organizations gaining a competitive edge won’t just be the fastest to adopt AI — they’ll be the ones that redesign accountability first.

Also Read: Your AI Pilot Isn’t Failing. Your Data Estate Is.

Key findings from the report include:

Confidence is outpacing control. While 58% of leaders believe their governance controls are keeping pace with AI adoption, only 18% have active risk mitigations in place. In the past 12 months, 40% of organizations reported inaccurate AI outputs, 27% reported data breaches, and 26% reported regulatory action tied to AI use.

“AI decided” isn’t a defense. Regulators expect a named, accountable human behind every decision affecting a customer, market or filing — an expectation the report says hasn’t changed with the rise of agentic systems. Nearly half of security decision-makers now name agentic AI a top security concern, and nearly two-thirds of organizations experienced an AI agent–related incident in the past 12 months, resulting in data exposure, operational disruption or financial loss.

Agents are identities that go uninventoried. Because autonomous agents authenticate, access systems and act independently, the report treats them as non-human identities — ones business units are often deploying without IT’s knowledge. While 85% of organizations have integrated AI into core operations, only a quarter say they have comprehensive visibility into how employees are actually using it.

A Closing Window

The report frames the moment as a closing window rather than a distant risk: organizations that redesign accountability now do so on their own terms; those that wait are more likely to do so later, under enforcement, remediation, or in the aftermath of an incident.

“The reality today is that agentic AI adoption is fast outpacing governance,” said Guru Sethupathy, general manager of AI governance at Optro. “But to harness its potential responsibly, leaders must recognize that governance models designed for static manual processes cannot keep pace with autonomous systems of action. Redesigning governance isn’t about pulling back on innovation — it’s about building the control structure to give organizations the confidence to scale AI faster and more reliably than the competition.”

Optro says it provides the governance infrastructure and automated controls needed to establish clear human accountability without slowing AI adoption. The report also includes agentic-readiness checklists for internal audit, compliance, IT, cybersecurity and AI governance teams.

“When AI Leaves the Chat and Enters the Workflow” is available for download at optro.ai.

Also Read: The End of “Seeing Is Believing”: AI’s New Risk to Children

Methodology

Findings draw on four surveys conducted as part of Optro’s Risk Intelligence program between February 2025 and May 2026, with all surveys conducted online among audit, risk, compliance and governance professionals at the manager level and above.

The first survey (n=403) examined regulatory compliance challenges, AI readiness and shadow AI management among InfoSec and compliance decision-makers across the US, Canada, UK and Germany. The second (n=407) examined AI governance awareness, preparedness and structure among audit, risk and compliance professionals across North America, the UK and Germany, with a minimum quota of 45% internal audit respondents. The third (n=612) examined AI adoption, governance maturity, cybersecurity risk and cross-functional risk integration among audit and GRC leaders across North America, the UK, Ireland and Germany. The fourth (n=506) examined business continuity management maturity, operational resilience and the governance implications of agentic AI among audit, risk, compliance, BCM and InfoSec leaders across North America, the UK, Germany and the UAE.

spot_img

More articles

spot_img

Latest posts